diff --git a/advisories/unreviewed/2022/05/GHSA-538h-6rv2-wmj3/GHSA-538h-6rv2-wmj3.json b/advisories/github-reviewed/2022/05/GHSA-538h-6rv2-wmj3/GHSA-538h-6rv2-wmj3.json similarity index 57% rename from advisories/unreviewed/2022/05/GHSA-538h-6rv2-wmj3/GHSA-538h-6rv2-wmj3.json rename to advisories/github-reviewed/2022/05/GHSA-538h-6rv2-wmj3/GHSA-538h-6rv2-wmj3.json index 2bbba4df973..41b4e1d8cdc 100644 --- a/advisories/unreviewed/2022/05/GHSA-538h-6rv2-wmj3/GHSA-538h-6rv2-wmj3.json +++ b/advisories/github-reviewed/2022/05/GHSA-538h-6rv2-wmj3/GHSA-538h-6rv2-wmj3.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-538h-6rv2-wmj3", - "modified": "2022-05-14T02:24:33Z", + "modified": "2023-07-31T20:28:04Z", "published": "2022-05-14T02:24:33Z", "aliases": [ "CVE-2016-3214" ], + "summary": "ChakraCore RCE Vulnerability", "details": "The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-3199.", "severity": [ { @@ -14,20 +15,42 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "NuGet", + "name": "Microsoft.ChakraCore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.3.0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3214" }, + { + "type": "WEB", + "url": "https://github.com/chakra-core/ChakraCore/commit/0b9f3cdd57cb09388fcf898edc537169c45a7345" + }, { "type": "WEB", "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-068" }, { "type": "WEB", - "url": "http://www.securitytracker.com/id/1036099" + "url": "https://web.archive.org/web/20211129115034/http://www.securitytracker.com/id/1036099" } ], "database_specific": { @@ -35,8 +58,8 @@ "CWE-119" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-07-31T20:28:04Z", "nvd_published_at": "2016-06-16T01:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-q6mv-8vh9-4ggj/GHSA-q6mv-8vh9-4ggj.json b/advisories/github-reviewed/2022/05/GHSA-q6mv-8vh9-4ggj/GHSA-q6mv-8vh9-4ggj.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-q6mv-8vh9-4ggj/GHSA-q6mv-8vh9-4ggj.json rename to advisories/github-reviewed/2022/05/GHSA-q6mv-8vh9-4ggj/GHSA-q6mv-8vh9-4ggj.json index 6280d24267d..6540bb589c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q6mv-8vh9-4ggj/GHSA-q6mv-8vh9-4ggj.json +++ b/advisories/github-reviewed/2022/05/GHSA-q6mv-8vh9-4ggj/GHSA-q6mv-8vh9-4ggj.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q6mv-8vh9-4ggj", - "modified": "2022-05-14T02:24:16Z", + "modified": "2023-07-31T20:27:14Z", "published": "2022-05-14T02:24:16Z", "aliases": [ "CVE-2016-3248" ], + "summary": "ChakraCore RCE Vulnerability", "details": "The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-3259.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "NuGet", + "name": "Microsoft.ChakraCore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.0.0" + } + ] + } + ] + } ], "references": [ { @@ -31,11 +50,11 @@ }, { "type": "WEB", - "url": "http://www.securityfocus.com/bid/91578" + "url": "https://web.archive.org/web/20210125172707/http://www.securityfocus.com/bid/91578" }, { "type": "WEB", - "url": "http://www.securitytracker.com/id/1036283" + "url": "https://web.archive.org/web/20211202003833/http://www.securitytracker.com/id/1036283" } ], "database_specific": { @@ -43,8 +62,8 @@ "CWE-119" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-07-31T20:27:14Z", "nvd_published_at": "2016-07-13T01:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-wm27-49x2-mg9q/GHSA-wm27-49x2-mg9q.json b/advisories/github-reviewed/2022/05/GHSA-wm27-49x2-mg9q/GHSA-wm27-49x2-mg9q.json similarity index 57% rename from advisories/unreviewed/2022/05/GHSA-wm27-49x2-mg9q/GHSA-wm27-49x2-mg9q.json rename to advisories/github-reviewed/2022/05/GHSA-wm27-49x2-mg9q/GHSA-wm27-49x2-mg9q.json index 90aeba8d350..c81d2afd413 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm27-49x2-mg9q/GHSA-wm27-49x2-mg9q.json +++ b/advisories/github-reviewed/2022/05/GHSA-wm27-49x2-mg9q/GHSA-wm27-49x2-mg9q.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-wm27-49x2-mg9q", - "modified": "2022-05-14T02:24:15Z", + "modified": "2023-07-31T20:26:29Z", "published": "2022-05-14T02:24:15Z", "aliases": [ "CVE-2016-3259" ], + "summary": "ChakraCore RCE Vulnerability", "details": "The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-3248.", "severity": [ { @@ -14,13 +15,39 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "NuGet", + "name": "Microsoft.ChakraCore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.0.0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3259" }, + { + "type": "WEB", + "url": "https://github.com/chakra-core/ChakraCore/pull/1291" + }, + { + "type": "WEB", + "url": "https://github.com/chakra-core/ChakraCore/commit/17f3d4a4852dcc9e48de7091685b1862afb9f307" + }, { "type": "WEB", "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-084" @@ -31,11 +58,11 @@ }, { "type": "WEB", - "url": "http://www.securityfocus.com/bid/91581" + "url": "https://web.archive.org/web/20210125172712/http://www.securityfocus.com/bid/91581" }, { "type": "WEB", - "url": "http://www.securitytracker.com/id/1036283" + "url": "https://web.archive.org/web/20211202003833/http://www.securitytracker.com/id/1036283" } ], "database_specific": { @@ -43,8 +70,8 @@ "CWE-119" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-07-31T20:26:29Z", "nvd_published_at": "2016-07-13T01:59:00Z" } } \ No newline at end of file