From 616017f3f40fc20e138227aa5aadff76f628ef67 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 18 Sep 2024 21:32:07 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9m5j-4xx9-44j9.json | 6 ++- .../GHSA-2hjg-246p-2f5p.json | 6 ++- .../GHSA-mhhf-pcpv-xqqq.json | 6 ++- .../GHSA-5m8p-88m5-5qqp.json | 7 ++- .../GHSA-955p-xvq6-xggj.json | 9 ++-- .../GHSA-qx9j-q623-p5fh.json | 9 ++-- .../GHSA-rv96-qgg3-4gv7.json | 9 ++-- .../GHSA-9225-wwj6-c3w3.json | 1 + .../GHSA-6wc2-f8mc-76rv.json | 2 +- .../GHSA-f8h4-8cx8-j35m.json | 2 +- .../GHSA-rqmr-f8r9-69wq.json | 6 ++- .../GHSA-25f3-qj7w-25fw.json | 35 ++++++++++++++ .../GHSA-2wh6-wp88-phq8.json | 43 +++++++++++++++++ .../GHSA-3jrq-ghjr-jwf2.json | 35 ++++++++++++++ .../GHSA-3qv6-5f5f-f89j.json | 1 + .../GHSA-3v74-rm67-6782.json | 11 +++-- .../GHSA-5m5p-hvxj-grxr.json | 11 +++-- .../GHSA-6fv7-9g8h-f3wm.json | 11 +++-- .../GHSA-6mgp-6qqc-4g38.json | 11 +++-- .../GHSA-6mh6-642h-83x7.json | 10 +++- .../GHSA-6p25-v7px-gqph.json | 11 +++-- .../GHSA-7v38-xc68-49j2.json | 2 +- .../GHSA-7x9g-pvv2-c542.json | 6 ++- .../GHSA-84h3-pfxq-r99h.json | 6 ++- .../GHSA-852g-3f6p-43mm.json | 6 ++- .../GHSA-8ccr-ppgf-4r3x.json | 11 +++-- .../GHSA-94j8-54mg-394v.json | 39 ++++++++++++++++ .../GHSA-94r8-x6vr-vvc4.json | 35 ++++++++++++++ .../GHSA-97v4-fg36-6rc2.json | 6 ++- .../GHSA-9rfc-px2m-hwvj.json | 11 +++-- .../GHSA-c9h3-w54v-5g3j.json | 2 +- .../GHSA-cwr9-w5qw-fr62.json | 9 ++-- .../GHSA-f2jx-jjc7-hv9g.json | 3 +- .../GHSA-ff7x-57mx-2mfq.json | 39 ++++++++++++++++ .../GHSA-g2r8-m367-m72p.json | 35 ++++++++++++++ .../GHSA-g2w3-jpfv-qffv.json | 43 +++++++++++++++++ .../GHSA-gf35-p27p-qqwm.json | 6 ++- .../GHSA-gxw8-fmh9-2w53.json | 9 +++- .../GHSA-h92q-fgpp-qhrq.json | 35 ++++++++++++++ .../GHSA-hcmh-526c-3ggp.json | 11 +++-- .../GHSA-j9h9-46cg-gwp9.json | 35 ++++++++++++++ .../GHSA-q247-wj3r-2x97.json | 6 ++- .../GHSA-q898-c98g-f82h.json | 11 +++-- .../GHSA-q9mj-qff3-9v4j.json | 11 +++-- .../GHSA-qc32-xfvc-33fg.json | 11 +++-- .../GHSA-v223-qxqp-w79x.json | 35 ++++++++++++++ .../GHSA-v53g-5fv8-fwj6.json | 35 ++++++++++++++ .../GHSA-vqjm-ch4v-x2f4.json | 46 +++++++++++++++++++ .../GHSA-w599-hr6x-f9qv.json | 39 ++++++++++++++++ .../GHSA-wmq4-q8rm-8vp5.json | 6 ++- .../GHSA-x6xc-qv8r-frvx.json | 2 +- .../GHSA-x7c7-rpwp-w6fw.json | 11 +++-- .../GHSA-xmrg-69jq-mfv5.json | 9 ++-- .../GHSA-xrjg-w5fr-6ph9.json | 11 +++-- 54 files changed, 735 insertions(+), 89 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-2wh6-wp88-phq8/GHSA-2wh6-wp88-phq8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h92q-fgpp-qhrq/GHSA-h92q-fgpp-qhrq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v223-qxqp-w79x/GHSA-v223-qxqp-w79x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v53g-5fv8-fwj6/GHSA-v53g-5fv8-fwj6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vqjm-ch4v-x2f4/GHSA-vqjm-ch4v-x2f4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json diff --git a/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json b/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json index 9cef313dacd..27dda3302a9 100644 --- a/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json +++ b/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m5j-4xx9-44j9", - "modified": "2024-08-07T19:45:30Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-7143" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7143" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6765" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7143" diff --git a/advisories/unreviewed/2022/03/GHSA-2hjg-246p-2f5p/GHSA-2hjg-246p-2f5p.json b/advisories/unreviewed/2022/03/GHSA-2hjg-246p-2f5p/GHSA-2hjg-246p-2f5p.json index 0ef3daf8687..833fbb5fede 100644 --- a/advisories/unreviewed/2022/03/GHSA-2hjg-246p-2f5p/GHSA-2hjg-246p-2f5p.json +++ b/advisories/unreviewed/2022/03/GHSA-2hjg-246p-2f5p/GHSA-2hjg-246p-2f5p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hjg-246p-2f5p", - "modified": "2022-03-17T00:01:29Z", + "modified": "2024-09-18T21:30:37Z", "published": "2022-03-11T00:02:18Z", "aliases": [ "CVE-2022-22834" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://overit.us/products/geocall" + }, + { + "type": "WEB", + "url": "https://www.overit.ai/product/nextgen-fsm" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/03/GHSA-mhhf-pcpv-xqqq/GHSA-mhhf-pcpv-xqqq.json b/advisories/unreviewed/2022/03/GHSA-mhhf-pcpv-xqqq/GHSA-mhhf-pcpv-xqqq.json index 91e69dc1908..477a5400f1d 100644 --- a/advisories/unreviewed/2022/03/GHSA-mhhf-pcpv-xqqq/GHSA-mhhf-pcpv-xqqq.json +++ b/advisories/unreviewed/2022/03/GHSA-mhhf-pcpv-xqqq/GHSA-mhhf-pcpv-xqqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhhf-pcpv-xqqq", - "modified": "2022-03-17T00:01:28Z", + "modified": "2024-09-18T21:30:37Z", "published": "2022-03-11T00:02:17Z", "aliases": [ "CVE-2022-22835" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://overit.us/products/geocall" + }, + { + "type": "WEB", + "url": "https://www.overit.ai/product/nextgen-fsm" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-5m8p-88m5-5qqp/GHSA-5m8p-88m5-5qqp.json b/advisories/unreviewed/2022/05/GHSA-5m8p-88m5-5qqp/GHSA-5m8p-88m5-5qqp.json index b19e87246df..a00aa03e836 100644 --- a/advisories/unreviewed/2022/05/GHSA-5m8p-88m5-5qqp/GHSA-5m8p-88m5-5qqp.json +++ b/advisories/unreviewed/2022/05/GHSA-5m8p-88m5-5qqp/GHSA-5m8p-88m5-5qqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5m8p-88m5-5qqp", - "modified": "2022-05-14T01:52:25Z", + "modified": "2024-09-18T21:30:36Z", "published": "2022-05-14T01:52:25Z", "aliases": [ "CVE-2013-0648" ], "details": "Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json b/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json index 9c5a94d18b8..d393c2c1d1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json +++ b/advisories/unreviewed/2022/05/GHSA-955p-xvq6-xggj/GHSA-955p-xvq6-xggj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-955p-xvq6-xggj", - "modified": "2024-09-18T03:31:06Z", + "modified": "2024-09-18T21:30:37Z", "published": "2022-05-14T01:49:29Z", "aliases": [ "CVE-2014-0502" ], "details": "Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json b/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json index fc129d8cb7f..c4bafed5043 100644 --- a/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json +++ b/advisories/unreviewed/2022/05/GHSA-qx9j-q623-p5fh/GHSA-qx9j-q623-p5fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qx9j-q623-p5fh", - "modified": "2022-05-14T01:49:30Z", + "modified": "2024-09-18T21:30:37Z", "published": "2022-05-14T01:49:30Z", "aliases": [ "CVE-2014-0497" ], "details": "Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -85,7 +88,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-rv96-qgg3-4gv7/GHSA-rv96-qgg3-4gv7.json b/advisories/unreviewed/2022/05/GHSA-rv96-qgg3-4gv7/GHSA-rv96-qgg3-4gv7.json index 066df207980..44f42c083f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv96-qgg3-4gv7/GHSA-rv96-qgg3-4gv7.json +++ b/advisories/unreviewed/2022/05/GHSA-rv96-qgg3-4gv7/GHSA-rv96-qgg3-4gv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rv96-qgg3-4gv7", - "modified": "2022-05-14T01:52:32Z", + "modified": "2024-09-18T21:30:36Z", "published": "2022-05-14T01:52:32Z", "aliases": [ "CVE-2013-0643" ], "details": "The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json b/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json index 54863fe699a..939b53b39fe 100644 --- a/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json +++ b/advisories/unreviewed/2023/06/GHSA-9225-wwj6-c3w3/GHSA-9225-wwj6-c3w3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-326" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json b/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json index 28c97999ff7..26ccd76ff34 100644 --- a/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json +++ b/advisories/unreviewed/2023/10/GHSA-6wc2-f8mc-76rv/GHSA-6wc2-f8mc-76rv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-762" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json b/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json index b8e80b34231..934a104ad62 100644 --- a/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json +++ b/advisories/unreviewed/2023/10/GHSA-f8h4-8cx8-j35m/GHSA-f8h4-8cx8-j35m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8h4-8cx8-j35m", - "modified": "2024-04-04T08:36:29Z", + "modified": "2024-09-18T21:30:38Z", "published": "2023-10-13T00:30:18Z", "aliases": [ "CVE-2023-36843" diff --git a/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json b/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json index 55d511b4d67..cf2ed9e0fc2 100644 --- a/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json +++ b/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rqmr-f8r9-69wq", - "modified": "2024-08-05T15:30:52Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-08-05T15:30:52Z", "aliases": [ "CVE-2024-7383" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7383" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6757" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7383" diff --git a/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json b/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json new file mode 100644 index 00000000000..421d45e99c8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-25f3-qj7w-25fw/GHSA-25f3-qj7w-25fw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25f3-qj7w-25fw", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-46374" + ], + "details": "Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46374" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/CVE-2024-46374.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2wh6-wp88-phq8/GHSA-2wh6-wp88-phq8.json b/advisories/unreviewed/2024/09/GHSA-2wh6-wp88-phq8/GHSA-2wh6-wp88-phq8.json new file mode 100644 index 00000000000..760349ce6f0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2wh6-wp88-phq8/GHSA-2wh6-wp88-phq8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wh6-wp88-phq8", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-43024" + ], + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43024" + }, + { + "type": "WEB", + "url": "https://community.rws.com/product-groups/translation_management/multitrans/w/releases/5112/multitrans-7-releases" + }, + { + "type": "WEB", + "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-43024" + }, + { + "type": "WEB", + "url": "https://github.com/tomdantuma/CVE/tree/main/2024-43024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json b/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json new file mode 100644 index 00000000000..b19e7f5b0cf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3jrq-ghjr-jwf2/GHSA-3jrq-ghjr-jwf2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jrq-ghjr-jwf2", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-40568" + ], + "details": "Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40568" + }, + { + "type": "WEB", + "url": "https://github.com/xiaobye-ctf/My-CVE/tree/main/BTstack/CVE-2024-40568" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json b/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json index a6407f7db51..9efe9442811 100644 --- a/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json +++ b/advisories/unreviewed/2024/09/GHSA-3qv6-5f5f-f89j/GHSA-3qv6-5f5f-f89j.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json b/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json index a4324a4dc90..4a4e7f80d42 100644 --- a/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json +++ b/advisories/unreviewed/2024/09/GHSA-3v74-rm67-6782/GHSA-3v74-rm67-6782.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3v74-rm67-6782", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2023-28451" ], "details": "An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and highly impactful, because the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json b/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json index 45007db740d..0a14e2584f8 100644 --- a/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json +++ b/advisories/unreviewed/2024/09/GHSA-5m5p-hvxj-grxr/GHSA-5m5p-hvxj-grxr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5m5p-hvxj-grxr", - "modified": "2024-09-17T00:31:06Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-17T00:31:06Z", "aliases": [ "CVE-2024-44202" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:52Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json b/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json index 7cb3442afde..f4b980383c8 100644 --- a/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json +++ b/advisories/unreviewed/2024/09/GHSA-6fv7-9g8h-f3wm/GHSA-6fv7-9g8h-f3wm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fv7-9g8h-f3wm", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-44542" ], "details": "SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json b/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json index 4529b1c7d0a..92b43a77da9 100644 --- a/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json +++ b/advisories/unreviewed/2024/09/GHSA-6mgp-6qqc-4g38/GHSA-6mgp-6qqc-4g38.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mgp-6qqc-4g38", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2023-28455" ], "details": "An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium resolvers, launching amplification attacks and causing potential DoS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-406" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json b/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json index 7da7d8a7f09..99a011062c6 100644 --- a/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json +++ b/advisories/unreviewed/2024/09/GHSA-6mh6-642h-83x7/GHSA-6mh6-642h-83x7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mh6-642h-83x7", - "modified": "2024-09-11T12:30:52Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T12:30:52Z", "aliases": [ "CVE-2024-7609" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before 12.34.8.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -21,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7609" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6mh6-642h-83x7" + }, { "type": "WEB", "url": "https://https://www.usom.gov.tr/bildirim/tr-24-1447" diff --git a/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json b/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json index 5c3da95b887..33142489d70 100644 --- a/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json +++ b/advisories/unreviewed/2024/09/GHSA-6p25-v7px-gqph/GHSA-6p25-v7px-gqph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6p25-v7px-gqph", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2023-28456" ], "details": "An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other \"golden model\" software like BIND) and cause potential DoS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-406" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json b/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json index 731a213432c..8dbe6aca4c9 100644 --- a/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json +++ b/advisories/unreviewed/2024/09/GHSA-7v38-xc68-49j2/GHSA-7v38-xc68-49j2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v38-xc68-49j2", - "modified": "2024-09-12T15:33:00Z", + "modified": "2024-09-18T21:30:45Z", "published": "2024-09-12T15:33:00Z", "aliases": [ "CVE-2021-38132" diff --git a/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json b/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json index ea5a0d3468d..aa1f27e31f1 100644 --- a/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json +++ b/advisories/unreviewed/2024/09/GHSA-7x9g-pvv2-c542/GHSA-7x9g-pvv2-c542.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7x9g-pvv2-c542", - "modified": "2024-09-11T15:31:12Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T15:31:12Z", "aliases": [ "CVE-2024-45790" ], "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json b/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json index ba91baa54bd..fef3d452f44 100644 --- a/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json +++ b/advisories/unreviewed/2024/09/GHSA-84h3-pfxq-r99h/GHSA-84h3-pfxq-r99h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84h3-pfxq-r99h", - "modified": "2024-09-11T15:31:12Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T15:31:12Z", "aliases": [ "CVE-2024-27112" ], "details": "A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red" diff --git a/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json b/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json index 0cb6abca380..406c98bf522 100644 --- a/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json +++ b/advisories/unreviewed/2024/09/GHSA-852g-3f6p-43mm/GHSA-852g-3f6p-43mm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-852g-3f6p-43mm", - "modified": "2024-09-11T12:30:52Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T12:30:52Z", "aliases": [ "CVE-2024-45788" ], "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the targeted system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json b/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json index bdf172d0ac9..84a0abe54f2 100644 --- a/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json +++ b/advisories/unreviewed/2024/09/GHSA-8ccr-ppgf-4r3x/GHSA-8ccr-ppgf-4r3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8ccr-ppgf-4r3x", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-44459" ], "details": "A memory allocation issue in vernemq v2.0.1 allows attackers to cause a Denial of Service (DoS) via excessive memory consumption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T20:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json b/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json new file mode 100644 index 00000000000..e05cc269ca5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-94j8-54mg-394v/GHSA-94j8-54mg-394v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94j8-54mg-394v", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-34057" + ], + "details": "Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34057" + }, + { + "type": "WEB", + "url": "https://trianglemicroworks.com/products/source-code-libraries/iec-61850-scl-pages/what%27s-new" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json b/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json new file mode 100644 index 00000000000..b91d7ea027e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-94r8-x6vr-vvc4/GHSA-94r8-x6vr-vvc4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94r8-x6vr-vvc4", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-46377" + ], + "details": "Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46377" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/CVE-2024-46377.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json b/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json index b12832cd3f5..8b79ed4f594 100644 --- a/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json +++ b/advisories/unreviewed/2024/09/GHSA-97v4-fg36-6rc2/GHSA-97v4-fg36-6rc2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97v4-fg36-6rc2", - "modified": "2024-09-11T15:31:12Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T15:31:12Z", "aliases": [ "CVE-2024-27115" ], "details": "A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:Red" diff --git a/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json b/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json index 93fda18b64b..56ed4f4340f 100644 --- a/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json +++ b/advisories/unreviewed/2024/09/GHSA-9rfc-px2m-hwvj/GHSA-9rfc-px2m-hwvj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rfc-px2m-hwvj", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2023-28457" ], "details": "An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json b/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json index 892f01123ec..cf3d0fdc8ad 100644 --- a/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json +++ b/advisories/unreviewed/2024/09/GHSA-c9h3-w54v-5g3j/GHSA-c9h3-w54v-5g3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9h3-w54v-5g3j", - "modified": "2024-09-12T15:33:00Z", + "modified": "2024-09-18T21:30:45Z", "published": "2024-09-12T15:33:00Z", "aliases": [ "CVE-2021-38131" diff --git a/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json b/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json index f048d0659c3..71338a9e3d2 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json +++ b/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwr9-w5qw-fr62", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-44460" ], "details": "An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T20:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json b/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json index 1c4820da2e3..3397e3f6383 100644 --- a/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json +++ b/advisories/unreviewed/2024/09/GHSA-f2jx-jjc7-hv9g/GHSA-f2jx-jjc7-hv9g.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json b/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json new file mode 100644 index 00000000000..75761779342 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff7x-57mx-2mfq", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-39339" + ], + "details": "A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and personally identifiable information (PII). The exposure of such information may have serious implications for user privacy and system integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39339" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1S-d8zyZreYYGSIr4zGww6F2iBfD63v10Z3YVbGnp2es/edit?usp=sharing" + }, + { + "type": "WEB", + "url": "https://mohammedshine.github.io/CVE-2024-39339.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json b/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json new file mode 100644 index 00000000000..aa0570cd670 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g2r8-m367-m72p/GHSA-g2r8-m367-m72p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2r8-m367-m72p", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-46372" + ], + "details": "DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46372" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/CVE-2024-46372.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json b/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json new file mode 100644 index 00000000000..ae523594205 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2w3-jpfv-qffv", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-43025" + ], + "details": "An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43025" + }, + { + "type": "WEB", + "url": "https://community.rws.com/product-groups/translation_management/multitrans/w/releases/5112/multitrans-7-releases" + }, + { + "type": "WEB", + "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-43025" + }, + { + "type": "WEB", + "url": "https://github.com/tomdantuma/CVE/tree/main/2024-43025" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json b/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json index c64bf3efe87..c7f946a8192 100644 --- a/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json +++ b/advisories/unreviewed/2024/09/GHSA-gf35-p27p-qqwm/GHSA-gf35-p27p-qqwm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gf35-p27p-qqwm", - "modified": "2024-09-11T12:30:51Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T12:30:51Z", "aliases": [ "CVE-2024-45786" ], "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to gain unauthorized access to sensitive information belonging to other users.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json b/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json index 8b750564df1..595e9056961 100644 --- a/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json +++ b/advisories/unreviewed/2024/09/GHSA-gxw8-fmh9-2w53/GHSA-gxw8-fmh9-2w53.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxw8-fmh9-2w53", - "modified": "2024-09-11T15:31:12Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T15:31:12Z", "aliases": [ "CVE-2024-27113" ], "details": "An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:M/U:Red" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-h92q-fgpp-qhrq/GHSA-h92q-fgpp-qhrq.json b/advisories/unreviewed/2024/09/GHSA-h92q-fgpp-qhrq/GHSA-h92q-fgpp-qhrq.json new file mode 100644 index 00000000000..24780a62afc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h92q-fgpp-qhrq/GHSA-h92q-fgpp-qhrq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h92q-fgpp-qhrq", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2023-30464" + ], + "details": "CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30464" + }, + { + "type": "WEB", + "url": "https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json b/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json index 13cb48a7fae..a0d316cebf0 100644 --- a/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json +++ b/advisories/unreviewed/2024/09/GHSA-hcmh-526c-3ggp/GHSA-hcmh-526c-3ggp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hcmh-526c-3ggp", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-45182" ], "details": "An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T19:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json b/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json new file mode 100644 index 00000000000..d43f148e68b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j9h9-46cg-gwp9/GHSA-j9h9-46cg-gwp9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9h9-46cg-gwp9", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-46373" + ], + "details": "Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46373" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/CVE-2024-46373.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json b/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json index f0ce0b39858..ffa17b3aafd 100644 --- a/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json +++ b/advisories/unreviewed/2024/09/GHSA-q247-wj3r-2x97/GHSA-q247-wj3r-2x97.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q247-wj3r-2x97", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-6878" ], "details": "Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations.This issue affects Panel: before v2.3.24.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-q898-c98g-f82h/GHSA-q898-c98g-f82h.json b/advisories/unreviewed/2024/09/GHSA-q898-c98g-f82h/GHSA-q898-c98g-f82h.json index 9972eaf2dfe..287fa9c9771 100644 --- a/advisories/unreviewed/2024/09/GHSA-q898-c98g-f82h/GHSA-q898-c98g-f82h.json +++ b/advisories/unreviewed/2024/09/GHSA-q898-c98g-f82h/GHSA-q898-c98g-f82h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q898-c98g-f82h", - "modified": "2024-09-18T18:30:51Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T18:30:51Z", "aliases": [ "CVE-2024-46086" ], "details": "FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T16:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json b/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json index 8937320fa96..251e9aed120 100644 --- a/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json +++ b/advisories/unreviewed/2024/09/GHSA-q9mj-qff3-9v4j/GHSA-q9mj-qff3-9v4j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9mj-qff3-9v4j", - "modified": "2024-09-17T00:31:05Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-17T00:31:05Z", "aliases": [ "CVE-2024-44127" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json b/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json index 24aeb67b0d2..15dc3bc1251 100644 --- a/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json +++ b/advisories/unreviewed/2024/09/GHSA-qc32-xfvc-33fg/GHSA-qc32-xfvc-33fg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc32-xfvc-33fg", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2023-49203" ], "details": "Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accumulation of low-rate DNS queries such that there is a large-sized response in a burst of traffic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-406" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-v223-qxqp-w79x/GHSA-v223-qxqp-w79x.json b/advisories/unreviewed/2024/09/GHSA-v223-qxqp-w79x/GHSA-v223-qxqp-w79x.json new file mode 100644 index 00000000000..68ef26895c3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v223-qxqp-w79x/GHSA-v223-qxqp-w79x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v223-qxqp-w79x", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-46375" + ], + "details": "Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46375" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/CVE-2024-46375.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v53g-5fv8-fwj6/GHSA-v53g-5fv8-fwj6.json b/advisories/unreviewed/2024/09/GHSA-v53g-5fv8-fwj6/GHSA-v53g-5fv8-fwj6.json new file mode 100644 index 00000000000..d7a00e046a4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v53g-5fv8-fwj6/GHSA-v53g-5fv8-fwj6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v53g-5fv8-fwj6", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-46376" + ], + "details": "Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46376" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/CVE-2024-46376.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vqjm-ch4v-x2f4/GHSA-vqjm-ch4v-x2f4.json b/advisories/unreviewed/2024/09/GHSA-vqjm-ch4v-x2f4/GHSA-vqjm-ch4v-x2f4.json new file mode 100644 index 00000000000..15e0f6e6d5e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vqjm-ch4v-x2f4/GHSA-vqjm-ch4v-x2f4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqjm-ch4v-x2f4", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-8287" + ], + "details": "Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8287" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/anbox-cloud/+bug/2077570" + }, + { + "type": "WEB", + "url": "https://discourse.ubuntu.com/t/anbox-cloud-1-23-1-has-been-released/48141" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-8287" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T19:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json b/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json new file mode 100644 index 00000000000..657b65bfbf6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w599-hr6x-f9qv/GHSA-w599-hr6x-f9qv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w599-hr6x-f9qv", + "modified": "2024-09-18T21:30:48Z", + "published": "2024-09-18T21:30:48Z", + "aliases": [ + "CVE-2024-44589" + ], + "details": "Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44589" + }, + { + "type": "WEB", + "url": "https://github.com/Xshacry/iot-vuln/blob/main/d-link/dcs-935l/readme.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json b/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json index 9221565560e..aa5211d231e 100644 --- a/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json +++ b/advisories/unreviewed/2024/09/GHSA-wmq4-q8rm-8vp5/GHSA-wmq4-q8rm-8vp5.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmq4-q8rm-8vp5", - "modified": "2024-09-11T12:30:52Z", + "modified": "2024-09-18T21:30:44Z", "published": "2024-09-11T12:30:52Z", "aliases": [ "CVE-2024-45789" ], "details": "This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body on the vulnerable application.\n\nSuccessful exploitation of this vulnerability could allow the attacker to bypass certain constraints in the registration process leading to creation of multiple accounts.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json b/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json index fc4fbc78978..dc1d297876d 100644 --- a/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json +++ b/advisories/unreviewed/2024/09/GHSA-x6xc-qv8r-frvx/GHSA-x6xc-qv8r-frvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x6xc-qv8r-frvx", - "modified": "2024-09-12T15:33:00Z", + "modified": "2024-09-18T21:30:45Z", "published": "2024-09-12T15:33:00Z", "aliases": [ "CVE-2021-38133" diff --git a/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json b/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json index ca6cd71ca98..c77b50fae0c 100644 --- a/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json +++ b/advisories/unreviewed/2024/09/GHSA-x7c7-rpwp-w6fw/GHSA-x7c7-rpwp-w6fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7c7-rpwp-w6fw", - "modified": "2024-09-16T21:30:38Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-16T21:30:38Z", "aliases": [ "CVE-2024-42794" ], "details": "Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-16T20:15:46Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json b/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json index 4b1bc86f052..2583caf503c 100644 --- a/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json +++ b/advisories/unreviewed/2024/09/GHSA-xmrg-69jq-mfv5/GHSA-xmrg-69jq-mfv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmrg-69jq-mfv5", - "modified": "2024-09-12T21:32:02Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-12T21:32:02Z", "aliases": [ "CVE-2024-36066" ], "details": "The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CMP includes password-based MAC as one of the options for message integrity and authentication (the other option is certificate-based). RFC 4211 section 4.4 requires that password-based MAC parameters use a salt with a random value of at least 8 octets. This helps to inhibit dictionary attacks. Because the standalone CMP client originally was developed as test code, the salt was instead hardcoded and only 6 octets long.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-12T19:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json b/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json index 595abaaa29c..710c09bbae8 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json +++ b/advisories/unreviewed/2024/09/GHSA-xrjg-w5fr-6ph9/GHSA-xrjg-w5fr-6ph9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrjg-w5fr-6ph9", - "modified": "2024-09-18T18:30:51Z", + "modified": "2024-09-18T21:30:48Z", "published": "2024-09-18T18:30:51Z", "aliases": [ "CVE-2024-34399" ], "details": "**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T18:15:06Z"