From 6164c53b5334833856e27ebecce7c10c9c53b968 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 21:31:56 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-prfm-p99w-7gm2.json | 9 ++-- .../GHSA-vfqq-mj6j-2rqq.json | 11 +++-- .../GHSA-5pq7-gc86-75cp.json | 9 ++-- .../GHSA-9hf6-6h22-3j9h.json | 6 ++- .../GHSA-h747-q33x-7xxp.json | 6 ++- .../GHSA-mxxm-vx4c-x8w7.json | 6 ++- .../GHSA-hm3j-qgpw-pj98.json | 6 ++- .../GHSA-q285-mcqv-8j69.json | 11 +++-- .../GHSA-2g9x-g93g-hv56.json | 9 ++-- .../GHSA-2w8j-8xc6-4wcx.json | 9 ++-- .../GHSA-2x76-3pw6-mf42.json | 3 +- .../GHSA-3878-g84c-f27c.json | 9 ++-- .../GHSA-3mjq-gr7r-h6x3.json | 39 +++++++++++++++++ .../GHSA-425w-xhjg-hfcm.json | 11 +++-- .../GHSA-6pq4-p6m9-6r69.json | 39 +++++++++++++++++ .../GHSA-74c9-85j4-4phg.json | 3 +- .../GHSA-78mr-78x2-c4q9.json | 11 +++-- .../GHSA-79xj-76v6-3wgv.json | 9 ++-- .../GHSA-87q3-4f3j-74q7.json | 39 +++++++++++++++++ .../GHSA-8vf7-6fh2-6qw4.json | 43 +++++++++++++++++++ .../GHSA-998p-xc25-r3jq.json | 9 ++-- .../GHSA-9fff-xfgg-j657.json | 3 +- .../GHSA-cf5c-g77m-p395.json | 3 +- .../GHSA-cjjp-gcwg-8fxm.json | 9 ++-- .../GHSA-j8fq-9f7x-5883.json | 11 +++-- .../GHSA-m2g7-375g-3wg3.json | 11 +++-- .../GHSA-p9hh-6xrm-344h.json | 3 +- .../GHSA-pww8-r4pc-9m94.json | 11 +++-- .../GHSA-qgch-26fj-87r3.json | 9 ++-- .../GHSA-vj8f-r84j-pcvr.json | 35 +++++++++++++++ .../GHSA-vjhv-x2xp-g8gh.json | 11 +++-- .../GHSA-vwqj-2j54-46q6.json | 39 +++++++++++++++++ .../GHSA-w4c2-j77v-wmg3.json | 11 +++-- .../GHSA-wm6c-245h-h448.json | 39 +++++++++++++++++ .../GHSA-wv42-8m6m-mmvp.json | 3 +- .../GHSA-wx4c-59w2-pw86.json | 11 +++-- .../GHSA-wxqq-8jjm-6pjm.json | 11 +++-- .../GHSA-x3p6-wwcw-9gmv.json | 11 +++-- .../GHSA-xwm4-236h-gr55.json | 11 +++-- .../GHSA-xx28-hqvc-mm7j.json | 11 +++-- 40 files changed, 457 insertions(+), 93 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json create mode 100644 advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json diff --git a/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json b/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json index 6cdd56e4074..c580aa83b44 100644 --- a/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json +++ b/advisories/unreviewed/2024/03/GHSA-prfm-p99w-7gm2/GHSA-prfm-p99w-7gm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prfm-p99w-7gm2", - "modified": "2024-03-20T15:32:32Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-03-20T15:32:32Z", "aliases": [ "CVE-2024-22083" ], "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T05:15:45Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json b/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json index f905248f8c4..4f0059d414f 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json +++ b/advisories/unreviewed/2024/04/GHSA-vfqq-mj6j-2rqq/GHSA-vfqq-mj6j-2rqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfqq-mj6j-2rqq", - "modified": "2024-04-07T09:30:29Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-04-07T09:30:29Z", "aliases": [ "CVE-2023-52717" ], "details": "Permission verification vulnerability in the lock screen module.\nImpact: Successful exploitation of this vulnerability will affect availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T09:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5pq7-gc86-75cp/GHSA-5pq7-gc86-75cp.json b/advisories/unreviewed/2024/05/GHSA-5pq7-gc86-75cp/GHSA-5pq7-gc86-75cp.json index a1f9e6ceb2f..68f7cc53912 100644 --- a/advisories/unreviewed/2024/05/GHSA-5pq7-gc86-75cp/GHSA-5pq7-gc86-75cp.json +++ b/advisories/unreviewed/2024/05/GHSA-5pq7-gc86-75cp/GHSA-5pq7-gc86-75cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pq7-gc86-75cp", - "modified": "2024-06-29T06:31:38Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-05-05T21:30:31Z", "aliases": [ "CVE-2024-34509" ], "details": "dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T20:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9hf6-6h22-3j9h/GHSA-9hf6-6h22-3j9h.json b/advisories/unreviewed/2024/05/GHSA-9hf6-6h22-3j9h/GHSA-9hf6-6h22-3j9h.json index 4491ed981aa..48275acf5b4 100644 --- a/advisories/unreviewed/2024/05/GHSA-9hf6-6h22-3j9h/GHSA-9hf6-6h22-3j9h.json +++ b/advisories/unreviewed/2024/05/GHSA-9hf6-6h22-3j9h/GHSA-9hf6-6h22-3j9h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hf6-6h22-3j9h", - "modified": "2024-09-07T00:31:28Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-30802" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30802" }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-30802.md" + }, { "type": "WEB", "url": "https://github.com/WarmBrew/web_vul/blob/main/TTX.md" diff --git a/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json b/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json index 77c667bc770..9e1018f8716 100644 --- a/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json +++ b/advisories/unreviewed/2024/07/GHSA-h747-q33x-7xxp/GHSA-h747-q33x-7xxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h747-q33x-7xxp", - "modified": "2024-07-09T18:30:43Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-07-05T18:34:18Z", "aliases": [ "CVE-2024-39178" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39178" }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-39178.md" + }, { "type": "WEB", "url": "https://github.com/WarmBrew/web_vul/blob/main/Maipu/MyPower%20vc8100/MyPower_vc8100.md" diff --git a/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json b/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json index cd6be219cf1..2e0c2d6ff53 100644 --- a/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json +++ b/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mxxm-vx4c-x8w7", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-42676" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42676" }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-42676.md" + }, { "type": "WEB", "url": "https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZupload.md" diff --git a/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json b/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json index 2f31a7b427c..0d3ba6ead49 100644 --- a/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json +++ b/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm3j-qgpw-pj98", - "modified": "2024-10-11T15:30:32Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-10-09T15:32:18Z", "aliases": [ "CVE-2024-9680" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1923344" }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-51" diff --git a/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json b/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json index 2e8b223bdfd..816b073b6c1 100644 --- a/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json +++ b/advisories/unreviewed/2024/10/GHSA-q285-mcqv-8j69/GHSA-q285-mcqv-8j69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q285-mcqv-8j69", - "modified": "2024-10-17T06:30:32Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-10-17T06:30:32Z", "aliases": [ "CVE-2024-49593" ], "details": "In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can result in execution of a stored XSS payload. NOTE: if you wish to use the WP Engine alternative update mechanism for the free version of ACF, then you can follow the process shown at the advancedcustomfields.com blog URL within the References section below.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-17T04:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2g9x-g93g-hv56/GHSA-2g9x-g93g-hv56.json b/advisories/unreviewed/2024/11/GHSA-2g9x-g93g-hv56/GHSA-2g9x-g93g-hv56.json index ebf15e669cb..78a702b434b 100644 --- a/advisories/unreviewed/2024/11/GHSA-2g9x-g93g-hv56/GHSA-2g9x-g93g-hv56.json +++ b/advisories/unreviewed/2024/11/GHSA-2g9x-g93g-hv56/GHSA-2g9x-g93g-hv56.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g9x-g93g-hv56", - "modified": "2024-11-17T06:30:46Z", + "modified": "2024-11-18T21:30:46Z", "published": "2024-11-17T06:30:46Z", "aliases": [ "CVE-2024-52872" ], "details": "In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-17T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2w8j-8xc6-4wcx/GHSA-2w8j-8xc6-4wcx.json b/advisories/unreviewed/2024/11/GHSA-2w8j-8xc6-4wcx/GHSA-2w8j-8xc6-4wcx.json index 169019b28ab..756bfb69d24 100644 --- a/advisories/unreviewed/2024/11/GHSA-2w8j-8xc6-4wcx/GHSA-2w8j-8xc6-4wcx.json +++ b/advisories/unreviewed/2024/11/GHSA-2w8j-8xc6-4wcx/GHSA-2w8j-8xc6-4wcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2w8j-8xc6-4wcx", - "modified": "2024-11-13T21:30:34Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-13T21:30:34Z", "aliases": [ "CVE-2024-40443" ], "details": "SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2x76-3pw6-mf42/GHSA-2x76-3pw6-mf42.json b/advisories/unreviewed/2024/11/GHSA-2x76-3pw6-mf42/GHSA-2x76-3pw6-mf42.json index 6247f756ea1..a77cd75df57 100644 --- a/advisories/unreviewed/2024/11/GHSA-2x76-3pw6-mf42/GHSA-2x76-3pw6-mf42.json +++ b/advisories/unreviewed/2024/11/GHSA-2x76-3pw6-mf42/GHSA-2x76-3pw6-mf42.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-3878-g84c-f27c/GHSA-3878-g84c-f27c.json b/advisories/unreviewed/2024/11/GHSA-3878-g84c-f27c/GHSA-3878-g84c-f27c.json index 445992249c3..63bb7fb5406 100644 --- a/advisories/unreviewed/2024/11/GHSA-3878-g84c-f27c/GHSA-3878-g84c-f27c.json +++ b/advisories/unreviewed/2024/11/GHSA-3878-g84c-f27c/GHSA-3878-g84c-f27c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3878-g84c-f27c", - "modified": "2024-11-17T06:30:46Z", + "modified": "2024-11-18T21:30:46Z", "published": "2024-11-17T06:30:46Z", "aliases": [ "CVE-2024-52871" ], "details": "In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-17T04:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json b/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json new file mode 100644 index 00000000000..36fab43c482 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3mjq-gr7r-h6x3/GHSA-3mjq-gr7r-h6x3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mjq-gr7r-h6x3", + "modified": "2024-11-18T21:30:47Z", + "published": "2024-11-18T21:30:47Z", + "aliases": [ + "CVE-2024-50848" + ], + "details": "An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50848" + }, + { + "type": "WEB", + "url": "https://github.com/Wh1teSnak3/CVE-2024-50848" + }, + { + "type": "WEB", + "url": "https://www.trados.com/product/worldserver" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-425w-xhjg-hfcm/GHSA-425w-xhjg-hfcm.json b/advisories/unreviewed/2024/11/GHSA-425w-xhjg-hfcm/GHSA-425w-xhjg-hfcm.json index 31dab16ea8b..8f83c6f357b 100644 --- a/advisories/unreviewed/2024/11/GHSA-425w-xhjg-hfcm/GHSA-425w-xhjg-hfcm.json +++ b/advisories/unreviewed/2024/11/GHSA-425w-xhjg-hfcm/GHSA-425w-xhjg-hfcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-425w-xhjg-hfcm", - "modified": "2024-11-18T06:30:36Z", + "modified": "2024-11-18T21:30:46Z", "published": "2024-11-18T06:30:36Z", "aliases": [ "CVE-2024-52947" ], "details": "A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the \"Upgrade session\" plugin has been enabled by an admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json b/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json new file mode 100644 index 00000000000..a300ef605d7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6pq4-p6m9-6r69/GHSA-6pq4-p6m9-6r69.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pq4-p6m9-6r69", + "modified": "2024-11-18T21:30:47Z", + "published": "2024-11-18T21:30:47Z", + "aliases": [ + "CVE-2024-50849" + ], + "details": "Cross-Site Scripting (XSS) in the \"Rules\" functionality in WordServer 11.8.2 allows a remote authenticated attacker to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50849" + }, + { + "type": "WEB", + "url": "https://github.com/Wh1teSnak3/CVE-2024-50849" + }, + { + "type": "WEB", + "url": "https://www.trados.com/product/worldserver" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-74c9-85j4-4phg/GHSA-74c9-85j4-4phg.json b/advisories/unreviewed/2024/11/GHSA-74c9-85j4-4phg/GHSA-74c9-85j4-4phg.json index 780082a617a..8c4dea6aaf6 100644 --- a/advisories/unreviewed/2024/11/GHSA-74c9-85j4-4phg/GHSA-74c9-85j4-4phg.json +++ b/advisories/unreviewed/2024/11/GHSA-74c9-85j4-4phg/GHSA-74c9-85j4-4phg.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-78mr-78x2-c4q9/GHSA-78mr-78x2-c4q9.json b/advisories/unreviewed/2024/11/GHSA-78mr-78x2-c4q9/GHSA-78mr-78x2-c4q9.json index f8285a791d9..54c1fd89536 100644 --- a/advisories/unreviewed/2024/11/GHSA-78mr-78x2-c4q9/GHSA-78mr-78x2-c4q9.json +++ b/advisories/unreviewed/2024/11/GHSA-78mr-78x2-c4q9/GHSA-78mr-78x2-c4q9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78mr-78x2-c4q9", - "modified": "2024-11-13T00:30:48Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2021-27701" ], "details": "SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a CSRF token and request validation. An attacker can Add/Modify any random user data by sending a crafted CSRF request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-79xj-76v6-3wgv/GHSA-79xj-76v6-3wgv.json b/advisories/unreviewed/2024/11/GHSA-79xj-76v6-3wgv/GHSA-79xj-76v6-3wgv.json index 3067baa4aa5..cf197ef2c97 100644 --- a/advisories/unreviewed/2024/11/GHSA-79xj-76v6-3wgv/GHSA-79xj-76v6-3wgv.json +++ b/advisories/unreviewed/2024/11/GHSA-79xj-76v6-3wgv/GHSA-79xj-76v6-3wgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79xj-76v6-3wgv", - "modified": "2024-11-08T18:30:50Z", + "modified": "2024-11-18T21:30:44Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50209" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Add a check for memory allocation\n\n__alloc_pbl() can return error when memory allocation fails.\nDriver is not checking the status on one of the instances.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json b/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json new file mode 100644 index 00000000000..4c54d3043a6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-87q3-4f3j-74q7/GHSA-87q3-4f3j-74q7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87q3-4f3j-74q7", + "modified": "2024-11-18T21:30:46Z", + "published": "2024-11-18T21:30:46Z", + "aliases": [ + "CVE-2024-48294" + ], + "details": "A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48294" + }, + { + "type": "WEB", + "url": "https://github.com/Nero22k/Disclosures/tree/main/Wondershare%20PDF%20Reader" + }, + { + "type": "WEB", + "url": "https://pdf.wondershare.com/pdf-reader.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json b/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json new file mode 100644 index 00000000000..b1c0c393c8a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8vf7-6fh2-6qw4/GHSA-8vf7-6fh2-6qw4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vf7-6fh2-6qw4", + "modified": "2024-11-18T21:30:46Z", + "published": "2024-11-18T21:30:46Z", + "aliases": [ + "CVE-2024-50919" + ], + "details": "Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50919" + }, + { + "type": "WEB", + "url": "https://gist.github.com/microvorld/516552dcef65acc2d1ab0fb969cd34a3" + }, + { + "type": "WEB", + "url": "https://github.com/JPressProjects/jpress" + }, + { + "type": "WEB", + "url": "https://github.com/microvorld/CVE-2024/blob/main/jpress.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-998p-xc25-r3jq/GHSA-998p-xc25-r3jq.json b/advisories/unreviewed/2024/11/GHSA-998p-xc25-r3jq/GHSA-998p-xc25-r3jq.json index 1433b90dba6..dac56a205c0 100644 --- a/advisories/unreviewed/2024/11/GHSA-998p-xc25-r3jq/GHSA-998p-xc25-r3jq.json +++ b/advisories/unreviewed/2024/11/GHSA-998p-xc25-r3jq/GHSA-998p-xc25-r3jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-998p-xc25-r3jq", - "modified": "2024-11-08T18:30:49Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-11-07T12:30:34Z", "aliases": [ "CVE-2024-50148" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: fix wild-memory-access in proto_unregister\n\nThere's issue as follows:\n KASAN: maybe wild-memory-access in range [0xdead...108-0xdead...10f]\n CPU: 3 UID: 0 PID: 2805 Comm: rmmod Tainted: G W\n RIP: 0010:proto_unregister+0xee/0x400\n Call Trace:\n \n __do_sys_delete_module+0x318/0x580\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nAs bnep_init() ignore bnep_sock_init()'s return value, and bnep_sock_init()\nwill cleanup all resource. Then when remove bnep module will call\nbnep_sock_cleanup() to cleanup sock's resource.\nTo solve above issue just return bnep_sock_init()'s return value in\nbnep_exit().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9fff-xfgg-j657/GHSA-9fff-xfgg-j657.json b/advisories/unreviewed/2024/11/GHSA-9fff-xfgg-j657/GHSA-9fff-xfgg-j657.json index 0530370d73e..0e87c573262 100644 --- a/advisories/unreviewed/2024/11/GHSA-9fff-xfgg-j657/GHSA-9fff-xfgg-j657.json +++ b/advisories/unreviewed/2024/11/GHSA-9fff-xfgg-j657/GHSA-9fff-xfgg-j657.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-cf5c-g77m-p395/GHSA-cf5c-g77m-p395.json b/advisories/unreviewed/2024/11/GHSA-cf5c-g77m-p395/GHSA-cf5c-g77m-p395.json index 45d4b10c631..31d53f3cd2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-cf5c-g77m-p395/GHSA-cf5c-g77m-p395.json +++ b/advisories/unreviewed/2024/11/GHSA-cf5c-g77m-p395/GHSA-cf5c-g77m-p395.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-cjjp-gcwg-8fxm/GHSA-cjjp-gcwg-8fxm.json b/advisories/unreviewed/2024/11/GHSA-cjjp-gcwg-8fxm/GHSA-cjjp-gcwg-8fxm.json index c188e360f74..1dc608cb3ac 100644 --- a/advisories/unreviewed/2024/11/GHSA-cjjp-gcwg-8fxm/GHSA-cjjp-gcwg-8fxm.json +++ b/advisories/unreviewed/2024/11/GHSA-cjjp-gcwg-8fxm/GHSA-cjjp-gcwg-8fxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjjp-gcwg-8fxm", - "modified": "2024-11-07T12:30:34Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-11-07T12:30:34Z", "aliases": [ "CVE-2024-50144" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: fix unbalanced rpm put() with fence_fini()\n\nCurrently we can call fence_fini() twice if something goes wrong when\nsending the GuC CT for the tlb request, since we signal the fence and\nreturn an error, leading to the caller also calling fini() on the error\npath in the case of stack version of the flow, which leads to an extra\nrpm put() which might later cause device to enter suspend when it\nshouldn't. It looks like we can just drop the fini() call since the\nfence signaller side will already call this for us.\n\nThere are known mysterious splats with device going to sleep even with\nan rpm ref, and this could be one candidate.\n\nv2 (Matt B):\n - Prefer warning if we detect double fini()\n\n(cherry picked from commit cfcbc0520d5055825f0647ab922b655688605183)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j8fq-9f7x-5883/GHSA-j8fq-9f7x-5883.json b/advisories/unreviewed/2024/11/GHSA-j8fq-9f7x-5883/GHSA-j8fq-9f7x-5883.json index 0c4440f8d31..cbfc3eee616 100644 --- a/advisories/unreviewed/2024/11/GHSA-j8fq-9f7x-5883/GHSA-j8fq-9f7x-5883.json +++ b/advisories/unreviewed/2024/11/GHSA-j8fq-9f7x-5883/GHSA-j8fq-9f7x-5883.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8fq-9f7x-5883", - "modified": "2024-11-15T00:31:51Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-15T00:31:51Z", "aliases": [ "CVE-2024-51156" ], "details": "07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T22:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m2g7-375g-3wg3/GHSA-m2g7-375g-3wg3.json b/advisories/unreviewed/2024/11/GHSA-m2g7-375g-3wg3/GHSA-m2g7-375g-3wg3.json index 12dac8b4b20..5c90d610537 100644 --- a/advisories/unreviewed/2024/11/GHSA-m2g7-375g-3wg3/GHSA-m2g7-375g-3wg3.json +++ b/advisories/unreviewed/2024/11/GHSA-m2g7-375g-3wg3/GHSA-m2g7-375g-3wg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2g7-375g-3wg3", - "modified": "2024-11-14T18:30:37Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-14T18:30:37Z", "aliases": [ "CVE-2024-48284" ], "details": "A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary scripts via the searchkey parameter in a POST HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-p9hh-6xrm-344h/GHSA-p9hh-6xrm-344h.json b/advisories/unreviewed/2024/11/GHSA-p9hh-6xrm-344h/GHSA-p9hh-6xrm-344h.json index 77b59a8d69d..a36eb0b276e 100644 --- a/advisories/unreviewed/2024/11/GHSA-p9hh-6xrm-344h/GHSA-p9hh-6xrm-344h.json +++ b/advisories/unreviewed/2024/11/GHSA-p9hh-6xrm-344h/GHSA-p9hh-6xrm-344h.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json b/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json index 1eb97ab50a6..84cfab6342a 100644 --- a/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json +++ b/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pww8-r4pc-9m94", - "modified": "2024-11-16T00:31:51Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-16T00:31:51Z", "aliases": [ "CVE-2024-50983" ], "details": "FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qgch-26fj-87r3/GHSA-qgch-26fj-87r3.json b/advisories/unreviewed/2024/11/GHSA-qgch-26fj-87r3/GHSA-qgch-26fj-87r3.json index e5f47b7a05f..59835d992e9 100644 --- a/advisories/unreviewed/2024/11/GHSA-qgch-26fj-87r3/GHSA-qgch-26fj-87r3.json +++ b/advisories/unreviewed/2024/11/GHSA-qgch-26fj-87r3/GHSA-qgch-26fj-87r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qgch-26fj-87r3", - "modified": "2024-11-08T06:30:49Z", + "modified": "2024-11-18T21:30:44Z", "published": "2024-11-08T06:30:49Z", "aliases": [ "CVE-2024-50211" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: refactor inode_bmap() to handle error\n\nRefactor inode_bmap() to handle error since udf_next_aext() can return\nerror now. On situations like ftruncate, udf_extend_file() can now\ndetect errors and bail out early without resorting to checking for\nparticular offsets and assuming internal behavior of these functions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json b/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json new file mode 100644 index 00000000000..08ee53795d6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vj8f-r84j-pcvr/GHSA-vj8f-r84j-pcvr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj8f-r84j-pcvr", + "modified": "2024-11-18T21:30:47Z", + "published": "2024-11-18T21:30:47Z", + "aliases": [ + "CVE-2024-50804" + ], + "details": "Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the C:\\ProgramData\\MSI\\One Dragon Center\\Data folder", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50804" + }, + { + "type": "WEB", + "url": "https://g3tsyst3m.github.io/cve/msi/Arbitrary-Write-Privilege-Escalation-CVE-2024-50804" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vjhv-x2xp-g8gh/GHSA-vjhv-x2xp-g8gh.json b/advisories/unreviewed/2024/11/GHSA-vjhv-x2xp-g8gh/GHSA-vjhv-x2xp-g8gh.json index 644b5b469a7..f83910f2c69 100644 --- a/advisories/unreviewed/2024/11/GHSA-vjhv-x2xp-g8gh/GHSA-vjhv-x2xp-g8gh.json +++ b/advisories/unreviewed/2024/11/GHSA-vjhv-x2xp-g8gh/GHSA-vjhv-x2xp-g8gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjhv-x2xp-g8gh", - "modified": "2024-11-13T21:30:34Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-13T21:30:34Z", "aliases": [ "CVE-2024-42834" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json b/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json new file mode 100644 index 00000000000..f4aca32837f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vwqj-2j54-46q6/GHSA-vwqj-2j54-46q6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwqj-2j54-46q6", + "modified": "2024-11-18T21:30:46Z", + "published": "2024-11-18T21:30:46Z", + "aliases": [ + "CVE-2024-48293" + ], + "details": "Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48293" + }, + { + "type": "WEB", + "url": "https://github.com/Nero22k/Disclosures/blob/main/QuickHealAV/CVE-2024-48293.md" + }, + { + "type": "WEB", + "url": "https://www.quickheal.com/download-free-antivirus" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w4c2-j77v-wmg3/GHSA-w4c2-j77v-wmg3.json b/advisories/unreviewed/2024/11/GHSA-w4c2-j77v-wmg3/GHSA-w4c2-j77v-wmg3.json index 7daac6d65b6..921529a7945 100644 --- a/advisories/unreviewed/2024/11/GHSA-w4c2-j77v-wmg3/GHSA-w4c2-j77v-wmg3.json +++ b/advisories/unreviewed/2024/11/GHSA-w4c2-j77v-wmg3/GHSA-w4c2-j77v-wmg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w4c2-j77v-wmg3", - "modified": "2024-11-13T00:30:48Z", + "modified": "2024-11-18T21:30:44Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2021-27700" ], "details": "SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another customer dashboard and perform actions like modify user, delete user, etc.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json b/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json new file mode 100644 index 00000000000..45f87511315 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wm6c-245h-h448/GHSA-wm6c-245h-h448.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm6c-245h-h448", + "modified": "2024-11-18T21:30:47Z", + "published": "2024-11-18T21:30:47Z", + "aliases": [ + "CVE-2024-51053" + ], + "details": "An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51053" + }, + { + "type": "WEB", + "url": "https://binqqer.com/posts/CVE-2024-51053" + }, + { + "type": "WEB", + "url": "https://vulners.com/packetstorm/PACKETSTORM:173122" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wv42-8m6m-mmvp/GHSA-wv42-8m6m-mmvp.json b/advisories/unreviewed/2024/11/GHSA-wv42-8m6m-mmvp/GHSA-wv42-8m6m-mmvp.json index 35b1c56626e..8e6198937e4 100644 --- a/advisories/unreviewed/2024/11/GHSA-wv42-8m6m-mmvp/GHSA-wv42-8m6m-mmvp.json +++ b/advisories/unreviewed/2024/11/GHSA-wv42-8m6m-mmvp/GHSA-wv42-8m6m-mmvp.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wx4c-59w2-pw86/GHSA-wx4c-59w2-pw86.json b/advisories/unreviewed/2024/11/GHSA-wx4c-59w2-pw86/GHSA-wx4c-59w2-pw86.json index 186089f3b17..6e5db0f48a8 100644 --- a/advisories/unreviewed/2024/11/GHSA-wx4c-59w2-pw86/GHSA-wx4c-59w2-pw86.json +++ b/advisories/unreviewed/2024/11/GHSA-wx4c-59w2-pw86/GHSA-wx4c-59w2-pw86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx4c-59w2-pw86", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-51037" ], "details": "An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T19:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json b/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json index f491c7fbc61..56b6009cb7d 100644 --- a/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json +++ b/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxqq-8jjm-6pjm", - "modified": "2024-11-07T12:30:34Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-11-07T12:30:34Z", "aliases": [ "CVE-2024-50146" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Don't call cleanup on profile rollback failure\n\nWhen profile rollback fails in mlx5e_netdev_change_profile, the netdev\nprofile var is left set to NULL. Avoid a crash when unloading the driver\nby not calling profile->cleanup in such a case.\n\nThis was encountered while testing, with the original trigger that\nthe wq rescuer thread creation got interrupted (presumably due to\nCtrl+C-ing modprobe), which gets converted to ENOMEM (-12) by\nmlx5e_priv_init, the profile rollback also fails for the same reason\n(signal still active) so the profile is left as NULL, leading to a crash\nlater in _mlx5e_remove.\n\n [ 732.473932] mlx5_core 0000:08:00.1: E-Switch: Unload vfs: mode(OFFLOADS), nvfs(2), necvfs(0), active vports(2)\n [ 734.525513] workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\n [ 734.557372] mlx5_core 0000:08:00.1: mlx5e_netdev_init_profile:6235:(pid 6086): mlx5e_priv_init failed, err=-12\n [ 734.559187] mlx5_core 0000:08:00.1 eth3: mlx5e_netdev_change_profile: new profile init failed, -12\n [ 734.560153] workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\n [ 734.589378] mlx5_core 0000:08:00.1: mlx5e_netdev_init_profile:6235:(pid 6086): mlx5e_priv_init failed, err=-12\n [ 734.591136] mlx5_core 0000:08:00.1 eth3: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12\n [ 745.537492] BUG: kernel NULL pointer dereference, address: 0000000000000008\n [ 745.538222] #PF: supervisor read access in kernel mode\n\n [ 745.551290] Call Trace:\n [ 745.551590] \n [ 745.551866] ? __die+0x20/0x60\n [ 745.552218] ? page_fault_oops+0x150/0x400\n [ 745.555307] ? exc_page_fault+0x79/0x240\n [ 745.555729] ? asm_exc_page_fault+0x22/0x30\n [ 745.556166] ? mlx5e_remove+0x6b/0xb0 [mlx5_core]\n [ 745.556698] auxiliary_bus_remove+0x18/0x30\n [ 745.557134] device_release_driver_internal+0x1df/0x240\n [ 745.557654] bus_remove_device+0xd7/0x140\n [ 745.558075] device_del+0x15b/0x3c0\n [ 745.558456] mlx5_rescan_drivers_locked.part.0+0xb1/0x2f0 [mlx5_core]\n [ 745.559112] mlx5_unregister_device+0x34/0x50 [mlx5_core]\n [ 745.559686] mlx5_uninit_one+0x46/0xf0 [mlx5_core]\n [ 745.560203] remove_one+0x4e/0xd0 [mlx5_core]\n [ 745.560694] pci_device_remove+0x39/0xa0\n [ 745.561112] device_release_driver_internal+0x1df/0x240\n [ 745.561631] driver_detach+0x47/0x90\n [ 745.562022] bus_remove_driver+0x84/0x100\n [ 745.562444] pci_unregister_driver+0x3b/0x90\n [ 745.562890] mlx5_cleanup+0xc/0x1b [mlx5_core]\n [ 745.563415] __x64_sys_delete_module+0x14d/0x2f0\n [ 745.563886] ? kmem_cache_free+0x1b0/0x460\n [ 745.564313] ? lockdep_hardirqs_on_prepare+0xe2/0x190\n [ 745.564825] do_syscall_64+0x6d/0x140\n [ 745.565223] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n [ 745.565725] RIP: 0033:0x7f1579b1288b", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json b/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json index f5e1a7ceb8a..e83807da202 100644 --- a/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json +++ b/advisories/unreviewed/2024/11/GHSA-x3p6-wwcw-9gmv/GHSA-x3p6-wwcw-9gmv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x3p6-wwcw-9gmv", - "modified": "2024-11-13T00:30:48Z", + "modified": "2024-11-18T21:30:44Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2024-48075" ], "details": "A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL 09.09.24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xwm4-236h-gr55/GHSA-xwm4-236h-gr55.json b/advisories/unreviewed/2024/11/GHSA-xwm4-236h-gr55/GHSA-xwm4-236h-gr55.json index e32dd5ef3fb..2909e17a513 100644 --- a/advisories/unreviewed/2024/11/GHSA-xwm4-236h-gr55/GHSA-xwm4-236h-gr55.json +++ b/advisories/unreviewed/2024/11/GHSA-xwm4-236h-gr55/GHSA-xwm4-236h-gr55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwm4-236h-gr55", - "modified": "2024-11-07T12:30:34Z", + "modified": "2024-11-18T21:30:43Z", "published": "2024-11-07T12:30:34Z", "aliases": [ "CVE-2024-50147" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix command bitmask initialization\n\nCommand bitmask have a dedicated bit for MANAGE_PAGES command, this bit\nisn't Initialize during command bitmask Initialization, only during\nMANAGE_PAGES.\n\nIn addition, mlx5_cmd_trigger_completions() is trying to trigger\ncompletion for MANAGE_PAGES command as well.\n\nHence, in case health error occurred before any MANAGE_PAGES command\nhave been invoke (for example, during mlx5_enable_hca()),\nmlx5_cmd_trigger_completions() will try to trigger completion for\nMANAGE_PAGES command, which will result in null-ptr-deref error.[1]\n\nFix it by Initialize command bitmask correctly.\n\nWhile at it, re-write the code for better understanding.\n\n[1]\nBUG: KASAN: null-ptr-deref in mlx5_cmd_trigger_completions+0x1db/0x600 [mlx5_core]\nWrite of size 4 at addr 0000000000000214 by task kworker/u96:2/12078\nCPU: 10 PID: 12078 Comm: kworker/u96:2 Not tainted 6.9.0-rc2_for_upstream_debug_2024_04_07_19_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nWorkqueue: mlx5_health0000:08:00.0 mlx5_fw_fatal_reporter_err_work [mlx5_core]\nCall Trace:\n \n dump_stack_lvl+0x7e/0xc0\n kasan_report+0xb9/0xf0\n kasan_check_range+0xec/0x190\n mlx5_cmd_trigger_completions+0x1db/0x600 [mlx5_core]\n mlx5_cmd_flush+0x94/0x240 [mlx5_core]\n enter_error_state+0x6c/0xd0 [mlx5_core]\n mlx5_fw_fatal_reporter_err_work+0xf3/0x480 [mlx5_core]\n process_one_work+0x787/0x1490\n ? lockdep_hardirqs_on_prepare+0x400/0x400\n ? pwq_dec_nr_in_flight+0xda0/0xda0\n ? assign_work+0x168/0x240\n worker_thread+0x586/0xd30\n ? rescuer_thread+0xae0/0xae0\n kthread+0x2df/0x3b0\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x2d/0x70\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork_asm+0x11/0x20\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xx28-hqvc-mm7j/GHSA-xx28-hqvc-mm7j.json b/advisories/unreviewed/2024/11/GHSA-xx28-hqvc-mm7j/GHSA-xx28-hqvc-mm7j.json index a5d45a3b7e7..389b0ecf2de 100644 --- a/advisories/unreviewed/2024/11/GHSA-xx28-hqvc-mm7j/GHSA-xx28-hqvc-mm7j.json +++ b/advisories/unreviewed/2024/11/GHSA-xx28-hqvc-mm7j/GHSA-xx28-hqvc-mm7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx28-hqvc-mm7j", - "modified": "2024-11-13T21:30:34Z", + "modified": "2024-11-18T21:30:45Z", "published": "2024-11-13T21:30:34Z", "aliases": [ "CVE-2023-38920" ], "details": "Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T20:15:16Z"