diff --git a/advisories/unreviewed/2022/05/GHSA-f57w-r4hj-rw7w/GHSA-f57w-r4hj-rw7w.json b/advisories/unreviewed/2022/05/GHSA-f57w-r4hj-rw7w/GHSA-f57w-r4hj-rw7w.json index 25b5525edf7..613aa57c69d 100644 --- a/advisories/unreviewed/2022/05/GHSA-f57w-r4hj-rw7w/GHSA-f57w-r4hj-rw7w.json +++ b/advisories/unreviewed/2022/05/GHSA-f57w-r4hj-rw7w/GHSA-f57w-r4hj-rw7w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f57w-r4hj-rw7w", - "modified": "2022-05-24T17:35:00Z", + "modified": "2024-12-12T18:30:49Z", "published": "2022-05-24T17:35:00Z", "aliases": [ "CVE-2020-25014" ], "details": "A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json b/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json index 9a3a90caa76..6532ce5ccf6 100644 --- a/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json +++ b/advisories/unreviewed/2024/02/GHSA-5f6g-q8f6-3c5x/GHSA-5f6g-q8f6-3c5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5f6g-q8f6-3c5x", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-12T18:30:49Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47032" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7915: fix tx skb dma unmap\n\nThe first pointer in the txp needs to be unmapped as well, otherwise it will\nleak DMA mapping entries", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5wjx-fx3x-22c6/GHSA-5wjx-fx3x-22c6.json b/advisories/unreviewed/2024/02/GHSA-5wjx-fx3x-22c6/GHSA-5wjx-fx3x-22c6.json index 678a6bf444a..808e6497ba8 100644 --- a/advisories/unreviewed/2024/02/GHSA-5wjx-fx3x-22c6/GHSA-5wjx-fx3x-22c6.json +++ b/advisories/unreviewed/2024/02/GHSA-5wjx-fx3x-22c6/GHSA-5wjx-fx3x-22c6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5wjx-fx3x-22c6", - "modified": "2024-05-01T18:30:35Z", + "modified": "2024-12-12T18:30:49Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-52442" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate session id and tree id in compound request\n\n`smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session()\nwill always return the first request smb2 header in a compound request.\nif `SMB2_TREE_CONNECT_HE` is the first command in compound request, will\nreturn 0, i.e. The tree id check is skipped.\nThis patch use ksmbd_req_buf_next() to get current command in compound.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T08:15:45Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gx59-vpv8-598f/GHSA-gx59-vpv8-598f.json b/advisories/unreviewed/2024/02/GHSA-gx59-vpv8-598f/GHSA-gx59-vpv8-598f.json index 27e7d76826f..baec59f9887 100644 --- a/advisories/unreviewed/2024/02/GHSA-gx59-vpv8-598f/GHSA-gx59-vpv8-598f.json +++ b/advisories/unreviewed/2024/02/GHSA-gx59-vpv8-598f/GHSA-gx59-vpv8-598f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gx59-vpv8-598f", - "modified": "2024-02-23T15:30:36Z", + "modified": "2024-12-12T18:30:49Z", "published": "2024-02-23T15:30:36Z", "aliases": [ "CVE-2023-52453" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume\n\nWhen the optional PRE_COPY support was added to speed up the device\ncompatibility check, it failed to update the saving/resuming data\npointers based on the fd offset. This results in migration data\ncorruption and when the device gets started on the destination the\nfollowing error is reported in some cases,\n\n[ 478.907684] arm-smmu-v3 arm-smmu-v3.2.auto: event 0x10 received:\n[ 478.913691] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000310200000010\n[ 478.919603] arm-smmu-v3 arm-smmu-v3.2.auto: 0x000002088000007f\n[ 478.925515] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000\n[ 478.931425] arm-smmu-v3 arm-smmu-v3.2.auto: 0x0000000000000000\n[ 478.947552] hisi_zip 0000:31:00.0: qm_axi_rresp [error status=0x1] found\n[ 478.955930] hisi_zip 0000:31:00.0: qm_db_timeout [error status=0x400] found\n[ 478.955944] hisi_zip 0000:31:00.0: qm sq doorbell timeout in function 2", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-23T15:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json b/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json index 4e76d022ae6..7794baa9ff9 100644 --- a/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json +++ b/advisories/unreviewed/2024/02/GHSA-xhhv-vj84-84fm/GHSA-xhhv-vj84-84fm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xhhv-vj84-84fm", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-12T18:30:49Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47033" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7615: fix tx skb dma unmap\n\nThe first pointer in the txp needs to be unmapped as well, otherwise it will\nleak DMA mapping entries", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2vrm-jm55-jg94/GHSA-2vrm-jm55-jg94.json b/advisories/unreviewed/2024/03/GHSA-2vrm-jm55-jg94/GHSA-2vrm-jm55-jg94.json index bfc61280fbe..39bd892490b 100644 --- a/advisories/unreviewed/2024/03/GHSA-2vrm-jm55-jg94/GHSA-2vrm-jm55-jg94.json +++ b/advisories/unreviewed/2024/03/GHSA-2vrm-jm55-jg94/GHSA-2vrm-jm55-jg94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vrm-jm55-jg94", - "modified": "2024-06-25T21:31:11Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2023-52491" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run\n\nIn mtk_jpeg_probe, &jpeg->job_timeout_work is bound with\nmtk_jpeg_job_timeout_work.\n\nIn mtk_jpeg_dec_device_run, if error happens in\nmtk_jpeg_set_dec_dst, it will finally start the worker while\nmark the job as finished by invoking v4l2_m2m_job_finish.\n\nThere are two methods to trigger the bug. If we remove the\nmodule, it which will call mtk_jpeg_remove to make cleanup.\nThe possible sequence is as follows, which will cause a\nuse-after-free bug.\n\nCPU0 CPU1\nmtk_jpeg_dec_... |\n start worker\t |\n |mtk_jpeg_job_timeout_work\nmtk_jpeg_remove |\n v4l2_m2m_release |\n kfree(m2m_dev); |\n |\n | v4l2_m2m_get_curr_priv\n | m2m_dev->curr_ctx //use\n\nIf we close the file descriptor, which will call mtk_jpeg_release,\nit will have a similar sequence.\n\nFix this bug by starting timeout worker only if started jpegdec worker\nsuccessfully. Then v4l2_m2m_job_finish will only be called in\neither mtk_jpeg_job_timeout_work or mtk_jpeg_dec_device_run.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2xhh-m3cf-854c/GHSA-2xhh-m3cf-854c.json b/advisories/unreviewed/2024/03/GHSA-2xhh-m3cf-854c/GHSA-2xhh-m3cf-854c.json index f9f8f621add..179b0e79c43 100644 --- a/advisories/unreviewed/2024/03/GHSA-2xhh-m3cf-854c/GHSA-2xhh-m3cf-854c.json +++ b/advisories/unreviewed/2024/03/GHSA-2xhh-m3cf-854c/GHSA-2xhh-m3cf-854c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xhh-m3cf-854c", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-12-12T18:30:49Z", "published": "2024-03-06T09:30:28Z", "aliases": [ "CVE-2023-52599" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in diNewExt\n\n[Syz report]\nUBSAN: array-index-out-of-bounds in fs/jfs/jfs_imap.c:2360:2\nindex -878706688 is out of range for type 'struct iagctl[128]'\nCPU: 1 PID: 5065 Comm: syz-executor282 Not tainted 6.7.0-rc4-syzkaller-00009-gbee0e7762ad2 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106\n ubsan_epilogue lib/ubsan.c:217 [inline]\n __ubsan_handle_out_of_bounds+0x11c/0x150 lib/ubsan.c:348\n diNewExt+0x3cf3/0x4000 fs/jfs/jfs_imap.c:2360\n diAllocExt fs/jfs/jfs_imap.c:1949 [inline]\n diAllocAG+0xbe8/0x1e50 fs/jfs/jfs_imap.c:1666\n diAlloc+0x1d3/0x1760 fs/jfs/jfs_imap.c:1587\n ialloc+0x8f/0x900 fs/jfs/jfs_inode.c:56\n jfs_mkdir+0x1c5/0xb90 fs/jfs/namei.c:225\n vfs_mkdir+0x2f1/0x4b0 fs/namei.c:4106\n do_mkdirat+0x264/0x3a0 fs/namei.c:4129\n __do_sys_mkdir fs/namei.c:4149 [inline]\n __se_sys_mkdir fs/namei.c:4147 [inline]\n __x64_sys_mkdir+0x6e/0x80 fs/namei.c:4147\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x45/0x110 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\nRIP: 0033:0x7fcb7e6a0b57\nCode: ff ff 77 07 31 c0 c3 0f 1f 40 00 48 c7 c2 b8 ff ff ff f7 d8 64 89 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 b8 53 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffd83023038 EFLAGS: 00000286 ORIG_RAX: 0000000000000053\nRAX: ffffffffffffffda RBX: 00000000ffffffff RCX: 00007fcb7e6a0b57\nRDX: 00000000000a1020 RSI: 00000000000001ff RDI: 0000000020000140\nRBP: 0000000020000140 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000286 R12: 00007ffd830230d0\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n\n[Analysis]\nWhen the agstart is too large, it can cause agno overflow.\n\n[Fix]\nAfter obtaining agno, if the value is invalid, exit the subsequent process.\n\n\nModified the test from agno > MAXAG to agno >= MAXAG based on linux-next\nreport by kernel test robot (Dan Carpenter).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json b/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json index 4cc8f3af7f6..930776067aa 100644 --- a/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json +++ b/advisories/unreviewed/2024/03/GHSA-448c-qhpp-cmmf/GHSA-448c-qhpp-cmmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-448c-qhpp-cmmf", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-26611" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: fix usage of multi-buffer BPF helpers for ZC XDP\n\nCurrently when packet is shrunk via bpf_xdp_adjust_tail() and memory\ntype is set to MEM_TYPE_XSK_BUFF_POOL, null ptr dereference happens:\n\n[1136314.192256] BUG: kernel NULL pointer dereference, address:\n0000000000000034\n[1136314.203943] #PF: supervisor read access in kernel mode\n[1136314.213768] #PF: error_code(0x0000) - not-present page\n[1136314.223550] PGD 0 P4D 0\n[1136314.230684] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[1136314.239621] CPU: 8 PID: 54203 Comm: xdpsock Not tainted 6.6.0+ #257\n[1136314.250469] Hardware name: Intel Corporation S2600WFT/S2600WFT,\nBIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019\n[1136314.265615] RIP: 0010:__xdp_return+0x6c/0x210\n[1136314.274653] Code: ad 00 48 8b 47 08 49 89 f8 a8 01 0f 85 9b 01 00 00 0f 1f 44 00 00 f0 41 ff 48 34 75 32 4c 89 c7 e9 79 cd 80 ff 83 fe 03 75 17 41 34 01 0f 85 02 01 00 00 48 89 cf e9 22 cc 1e 00 e9 3d d2 86\n[1136314.302907] RSP: 0018:ffffc900089f8db0 EFLAGS: 00010246\n[1136314.312967] RAX: ffffc9003168aed0 RBX: ffff8881c3300000 RCX:\n0000000000000000\n[1136314.324953] RDX: 0000000000000000 RSI: 0000000000000003 RDI:\nffffc9003168c000\n[1136314.336929] RBP: 0000000000000ae0 R08: 0000000000000002 R09:\n0000000000010000\n[1136314.348844] R10: ffffc9000e495000 R11: 0000000000000040 R12:\n0000000000000001\n[1136314.360706] R13: 0000000000000524 R14: ffffc9003168aec0 R15:\n0000000000000001\n[1136314.373298] FS: 00007f8df8bbcb80(0000) GS:ffff8897e0e00000(0000)\nknlGS:0000000000000000\n[1136314.386105] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[1136314.396532] CR2: 0000000000000034 CR3: 00000001aa912002 CR4:\n00000000007706f0\n[1136314.408377] DR0: 0000000000000000 DR1: 0000000000000000 DR2:\n0000000000000000\n[1136314.420173] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7:\n0000000000000400\n[1136314.431890] PKRU: 55555554\n[1136314.439143] Call Trace:\n[1136314.446058] \n[1136314.452465] ? __die+0x20/0x70\n[1136314.459881] ? page_fault_oops+0x15b/0x440\n[1136314.468305] ? exc_page_fault+0x6a/0x150\n[1136314.476491] ? asm_exc_page_fault+0x22/0x30\n[1136314.484927] ? __xdp_return+0x6c/0x210\n[1136314.492863] bpf_xdp_adjust_tail+0x155/0x1d0\n[1136314.501269] bpf_prog_ccc47ae29d3b6570_xdp_sock_prog+0x15/0x60\n[1136314.511263] ice_clean_rx_irq_zc+0x206/0xc60 [ice]\n[1136314.520222] ? ice_xmit_zc+0x6e/0x150 [ice]\n[1136314.528506] ice_napi_poll+0x467/0x670 [ice]\n[1136314.536858] ? ttwu_do_activate.constprop.0+0x8f/0x1a0\n[1136314.546010] __napi_poll+0x29/0x1b0\n[1136314.553462] net_rx_action+0x133/0x270\n[1136314.561619] __do_softirq+0xbe/0x28e\n[1136314.569303] do_softirq+0x3f/0x60\n\nThis comes from __xdp_return() call with xdp_buff argument passed as\nNULL which is supposed to be consumed by xsk_buff_free() call.\n\nTo address this properly, in ZC case, a node that represents the frag\nbeing removed has to be pulled out of xskb_list. Introduce\nappropriate xsk helpers to do such node operation and use them\naccordingly within bpf_xdp_adjust_tail().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:19Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4rwf-mvg8-5p8w/GHSA-4rwf-mvg8-5p8w.json b/advisories/unreviewed/2024/03/GHSA-4rwf-mvg8-5p8w/GHSA-4rwf-mvg8-5p8w.json index 9d69a43706c..2ebef442bc4 100644 --- a/advisories/unreviewed/2024/03/GHSA-4rwf-mvg8-5p8w/GHSA-4rwf-mvg8-5p8w.json +++ b/advisories/unreviewed/2024/03/GHSA-4rwf-mvg8-5p8w/GHSA-4rwf-mvg8-5p8w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rwf-mvg8-5p8w", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-06T09:30:29Z", "aliases": [ "CVE-2023-52604" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nFS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree\n\nSyzkaller reported the following issue:\n\nUBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:2867:6\nindex 196694 is out of range for type 's8[1365]' (aka 'signed char[1365]')\nCPU: 1 PID: 109 Comm: jfsCommit Not tainted 6.6.0-rc3-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106\n ubsan_epilogue lib/ubsan.c:217 [inline]\n __ubsan_handle_out_of_bounds+0x11c/0x150 lib/ubsan.c:348\n dbAdjTree+0x474/0x4f0 fs/jfs/jfs_dmap.c:2867\n dbJoin+0x210/0x2d0 fs/jfs/jfs_dmap.c:2834\n dbFreeBits+0x4eb/0xda0 fs/jfs/jfs_dmap.c:2331\n dbFreeDmap fs/jfs/jfs_dmap.c:2080 [inline]\n dbFree+0x343/0x650 fs/jfs/jfs_dmap.c:402\n txFreeMap+0x798/0xd50 fs/jfs/jfs_txnmgr.c:2534\n txUpdateMap+0x342/0x9e0\n txLazyCommit fs/jfs/jfs_txnmgr.c:2664 [inline]\n jfs_lazycommit+0x47a/0xb70 fs/jfs/jfs_txnmgr.c:2732\n kthread+0x2d3/0x370 kernel/kthread.c:388\n ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n \n================================================================================\nKernel panic - not syncing: UBSAN: panic_on_warn set ...\nCPU: 1 PID: 109 Comm: jfsCommit Not tainted 6.6.0-rc3-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/04/2023\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e7/0x2d0 lib/dump_stack.c:106\n panic+0x30f/0x770 kernel/panic.c:340\n check_panic_on_warn+0x82/0xa0 kernel/panic.c:236\n ubsan_epilogue lib/ubsan.c:223 [inline]\n __ubsan_handle_out_of_bounds+0x13c/0x150 lib/ubsan.c:348\n dbAdjTree+0x474/0x4f0 fs/jfs/jfs_dmap.c:2867\n dbJoin+0x210/0x2d0 fs/jfs/jfs_dmap.c:2834\n dbFreeBits+0x4eb/0xda0 fs/jfs/jfs_dmap.c:2331\n dbFreeDmap fs/jfs/jfs_dmap.c:2080 [inline]\n dbFree+0x343/0x650 fs/jfs/jfs_dmap.c:402\n txFreeMap+0x798/0xd50 fs/jfs/jfs_txnmgr.c:2534\n txUpdateMap+0x342/0x9e0\n txLazyCommit fs/jfs/jfs_txnmgr.c:2664 [inline]\n jfs_lazycommit+0x47a/0xb70 fs/jfs/jfs_txnmgr.c:2732\n kthread+0x2d3/0x370 kernel/kthread.c:388\n ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:304\n \nKernel Offset: disabled\nRebooting in 86400 seconds..\n\nThe issue is caused when the value of lp becomes greater than\nCTLTREESIZE which is the max size of stree. Adding a simple check\nsolves this issue.\n\nDave:\nAs the function returns a void, good error handling\nwould require a more intrusive code reorganization, so I modified\nOsama's patch at use WARN_ON_ONCE for lack of a cleaner option.\n\nThe patch is tested via syzbot.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5gh8-jmm4-99ww/GHSA-5gh8-jmm4-99ww.json b/advisories/unreviewed/2024/03/GHSA-5gh8-jmm4-99ww/GHSA-5gh8-jmm4-99ww.json index 38ec5661baf..e3f37547516 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gh8-jmm4-99ww/GHSA-5gh8-jmm4-99ww.json +++ b/advisories/unreviewed/2024/03/GHSA-5gh8-jmm4-99ww/GHSA-5gh8-jmm4-99ww.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json b/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json index 97921378242..8b1d5a31064 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json +++ b/advisories/unreviewed/2024/03/GHSA-5gxq-j292-75cc/GHSA-5gxq-j292-75cc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gxq-j292-75cc", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-26617" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: move mmu notification mechanism inside mm lock\n\nMove mmu notification mechanism inside mm lock to prevent race condition\nin other components which depend on it. The notifier will invalidate\nmemory range. Depending upon the number of iterations, different memory\nranges would be invalidated.\n\nThe following warning would be removed by this patch:\nWARNING: CPU: 0 PID: 5067 at arch/x86/kvm/../../../virt/kvm/kvm_main.c:734 kvm_mmu_notifier_change_pte+0x860/0x960 arch/x86/kvm/../../../virt/kvm/kvm_main.c:734\n\nThere is no behavioural and performance change with this patch when\nthere is no component registered with the mmu notifier.\n\n[akpm@linux-foundation.org: narrow the scope of `range', per Sean]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:19Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5qqm-68gx-7hgc/GHSA-5qqm-68gx-7hgc.json b/advisories/unreviewed/2024/03/GHSA-5qqm-68gx-7hgc/GHSA-5qqm-68gx-7hgc.json index e210be2469c..c0791f8d4bd 100644 --- a/advisories/unreviewed/2024/03/GHSA-5qqm-68gx-7hgc/GHSA-5qqm-68gx-7hgc.json +++ b/advisories/unreviewed/2024/03/GHSA-5qqm-68gx-7hgc/GHSA-5qqm-68gx-7hgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qqm-68gx-7hgc", - "modified": "2024-03-13T18:31:33Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1541" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6p64-gpr7-7mjm/GHSA-6p64-gpr7-7mjm.json b/advisories/unreviewed/2024/03/GHSA-6p64-gpr7-7mjm/GHSA-6p64-gpr7-7mjm.json index e7c7f15501a..f6fc6784640 100644 --- a/advisories/unreviewed/2024/03/GHSA-6p64-gpr7-7mjm/GHSA-6p64-gpr7-7mjm.json +++ b/advisories/unreviewed/2024/03/GHSA-6p64-gpr7-7mjm/GHSA-6p64-gpr7-7mjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p64-gpr7-7mjm", - "modified": "2024-03-06T09:30:29Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-06T09:30:29Z", "aliases": [ "CVE-2024-26626" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmr: fix kernel panic when forwarding mcast packets\n\nThe stacktrace was:\n[ 86.305548] BUG: kernel NULL pointer dereference, address: 0000000000000092\n[ 86.306815] #PF: supervisor read access in kernel mode\n[ 86.307717] #PF: error_code(0x0000) - not-present page\n[ 86.308624] PGD 0 P4D 0\n[ 86.309091] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ 86.309883] CPU: 2 PID: 3139 Comm: pimd Tainted: G U 6.8.0-6wind-knet #1\n[ 86.311027] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.11.1-0-g0551a4be2c-prebuilt.qemu-project.org 04/01/2014\n[ 86.312728] RIP: 0010:ip_mr_forward (/build/work/knet/net/ipv4/ipmr.c:1985)\n[ 86.313399] Code: f9 1f 0f 87 85 03 00 00 48 8d 04 5b 48 8d 04 83 49 8d 44 c5 00 48 8b 40 70 48 39 c2 0f 84 d9 00 00 00 49 8b 46 58 48 83 e0 fe <80> b8 92 00 00 00 00 0f 84 55 ff ff ff 49 83 47 38 01 45 85 e4 0f\n[ 86.316565] RSP: 0018:ffffad21c0583ae0 EFLAGS: 00010246\n[ 86.317497] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\n[ 86.318596] RDX: ffff9559cb46c000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 86.319627] RBP: ffffad21c0583b30 R08: 0000000000000000 R09: 0000000000000000\n[ 86.320650] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001\n[ 86.321672] R13: ffff9559c093a000 R14: ffff9559cc00b800 R15: ffff9559c09c1d80\n[ 86.322873] FS: 00007f85db661980(0000) GS:ffff955a79d00000(0000) knlGS:0000000000000000\n[ 86.324291] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 86.325314] CR2: 0000000000000092 CR3: 000000002f13a000 CR4: 0000000000350ef0\n[ 86.326589] Call Trace:\n[ 86.327036] \n[ 86.327434] ? show_regs (/build/work/knet/arch/x86/kernel/dumpstack.c:479)\n[ 86.328049] ? __die (/build/work/knet/arch/x86/kernel/dumpstack.c:421 /build/work/knet/arch/x86/kernel/dumpstack.c:434)\n[ 86.328508] ? page_fault_oops (/build/work/knet/arch/x86/mm/fault.c:707)\n[ 86.329107] ? do_user_addr_fault (/build/work/knet/arch/x86/mm/fault.c:1264)\n[ 86.329756] ? srso_return_thunk (/build/work/knet/arch/x86/lib/retpoline.S:223)\n[ 86.330350] ? __irq_work_queue_local (/build/work/knet/kernel/irq_work.c:111 (discriminator 1))\n[ 86.331013] ? exc_page_fault (/build/work/knet/./arch/x86/include/asm/paravirt.h:693 /build/work/knet/arch/x86/mm/fault.c:1515 /build/work/knet/arch/x86/mm/fault.c:1563)\n[ 86.331702] ? asm_exc_page_fault (/build/work/knet/./arch/x86/include/asm/idtentry.h:570)\n[ 86.332468] ? ip_mr_forward (/build/work/knet/net/ipv4/ipmr.c:1985)\n[ 86.333183] ? srso_return_thunk (/build/work/knet/arch/x86/lib/retpoline.S:223)\n[ 86.333920] ipmr_mfc_add (/build/work/knet/./include/linux/rcupdate.h:782 /build/work/knet/net/ipv4/ipmr.c:1009 /build/work/knet/net/ipv4/ipmr.c:1273)\n[ 86.334583] ? __pfx_ipmr_hash_cmp (/build/work/knet/net/ipv4/ipmr.c:363)\n[ 86.335357] ip_mroute_setsockopt (/build/work/knet/net/ipv4/ipmr.c:1470)\n[ 86.336135] ? srso_return_thunk (/build/work/knet/arch/x86/lib/retpoline.S:223)\n[ 86.336854] ? ip_mroute_setsockopt (/build/work/knet/net/ipv4/ipmr.c:1470)\n[ 86.337679] do_ip_setsockopt (/build/work/knet/net/ipv4/ip_sockglue.c:944)\n[ 86.338408] ? __pfx_unix_stream_read_actor (/build/work/knet/net/unix/af_unix.c:2862)\n[ 86.339232] ? srso_return_thunk (/build/work/knet/arch/x86/lib/retpoline.S:223)\n[ 86.339809] ? aa_sk_perm (/build/work/knet/security/apparmor/include/cred.h:153 /build/work/knet/security/apparmor/net.c:181)\n[ 86.340342] ip_setsockopt (/build/work/knet/net/ipv4/ip_sockglue.c:1415)\n[ 86.340859] raw_setsockopt (/build/work/knet/net/ipv4/raw.c:836)\n[ 86.341408] ? security_socket_setsockopt (/build/work/knet/security/security.c:4561 (discriminator 13))\n[ 86.342116] sock_common_setsockopt (/build/work/knet/net/core/sock.c:3716)\n[ 86.342747] do_sock_setsockopt (/build/work/knet/net/socket.c:2313)\n[ 86.343363] __sys_setsockopt (/build/work/knet/./include/linux/file.h:32 /build/work/kn\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7vjh-prmq-cfm3/GHSA-7vjh-prmq-cfm3.json b/advisories/unreviewed/2024/03/GHSA-7vjh-prmq-cfm3/GHSA-7vjh-prmq-cfm3.json index 122c15613ea..9689104d84f 100644 --- a/advisories/unreviewed/2024/03/GHSA-7vjh-prmq-cfm3/GHSA-7vjh-prmq-cfm3.json +++ b/advisories/unreviewed/2024/03/GHSA-7vjh-prmq-cfm3/GHSA-7vjh-prmq-cfm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7vjh-prmq-cfm3", - "modified": "2024-06-26T00:31:35Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2023-52493" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: host: Drop chan lock before queuing buffers\n\nEnsure read and write locks for the channel are not taken in succession by\ndropping the read lock from parse_xfer_event() such that a callback given\nto client can potentially queue buffers and acquire the write lock in that\nprocess. Any queueing of buffers should be done without channel read lock\nacquired as it can result in multiple locks and a soft lockup.\n\n[mani: added fixes tag and cc'ed stable]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json b/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json index 07702af4072..f28618371fe 100644 --- a/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json +++ b/advisories/unreviewed/2024/03/GHSA-99h3-vvc6-h7gh/GHSA-99h3-vvc6-h7gh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99h3-vvc6-h7gh", - "modified": "2024-03-11T18:31:08Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:08Z", "aliases": [ "CVE-2023-52487" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix peer flow lists handling\n\nThe cited change refactored mlx5e_tc_del_fdb_peer_flow() to only clear DUP\nflag when list of peer flows has become empty. However, if any concurrent\nuser holds a reference to a peer flow (for example, the neighbor update\nworkqueue task is updating peer flow's parent encap entry concurrently),\nthen the flow will not be removed from the peer list and, consecutively,\nDUP flag will remain set. Since mlx5e_tc_del_fdb_peers_flow() calls\nmlx5e_tc_del_fdb_peer_flow() for every possible peer index the algorithm\nwill try to remove the flow from eswitch instances that it has never peered\nwith causing either NULL pointer dereference when trying to remove the flow\npeer list head of peer_index that was never initialized or a warning if the\nlist debug config is enabled[0].\n\nFix the issue by always removing the peer flow from the list even when not\nreleasing the last reference to it.\n\n[0]:\n\n[ 3102.985806] ------------[ cut here ]------------\n[ 3102.986223] list_del corruption, ffff888139110698->next is NULL\n[ 3102.986757] WARNING: CPU: 2 PID: 22109 at lib/list_debug.c:53 __list_del_entry_valid_or_report+0x4f/0xc0\n[ 3102.987561] Modules linked in: act_ct nf_flow_table bonding act_tunnel_key act_mirred act_skbedit vxlan cls_matchall nfnetlink_cttimeout act_gact cls_flower sch_ingress mlx5_vdpa vringh vhost_iotlb vdpa openvswitch nsh xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat xt_addrtype xt_conntrack nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcg\nss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_ib ib_uverbs ib_core mlx5_core [last unloaded: bonding]\n[ 3102.991113] CPU: 2 PID: 22109 Comm: revalidator28 Not tainted 6.6.0-rc6+ #3\n[ 3102.991695] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 3102.992605] RIP: 0010:__list_del_entry_valid_or_report+0x4f/0xc0\n[ 3102.993122] Code: 39 c2 74 56 48 8b 32 48 39 fe 75 62 48 8b 51 08 48 39 f2 75 73 b8 01 00 00 00 c3 48 89 fe 48 c7 c7 48 fd 0a 82 e8 41 0b ad ff <0f> 0b 31 c0 c3 48 89 fe 48 c7 c7 70 fd 0a 82 e8 2d 0b ad ff 0f 0b\n[ 3102.994615] RSP: 0018:ffff8881383e7710 EFLAGS: 00010286\n[ 3102.995078] RAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000000\n[ 3102.995670] RDX: 0000000000000001 RSI: ffff88885f89b640 RDI: ffff88885f89b640\n[ 3102.997188] DEL flow 00000000be367878 on port 0\n[ 3102.998594] RBP: dead000000000122 R08: 0000000000000000 R09: c0000000ffffdfff\n[ 3102.999604] R10: 0000000000000008 R11: ffff8881383e7598 R12: dead000000000100\n[ 3103.000198] R13: 0000000000000002 R14: ffff888139110000 R15: ffff888101901240\n[ 3103.000790] FS: 00007f424cde4700(0000) GS:ffff88885f880000(0000) knlGS:0000000000000000\n[ 3103.001486] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 3103.001986] CR2: 00007fd42e8dcb70 CR3: 000000011e68a003 CR4: 0000000000370ea0\n[ 3103.002596] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 3103.003190] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 3103.003787] Call Trace:\n[ 3103.004055] \n[ 3103.004297] ? __warn+0x7d/0x130\n[ 3103.004623] ? __list_del_entry_valid_or_report+0x4f/0xc0\n[ 3103.005094] ? report_bug+0xf1/0x1c0\n[ 3103.005439] ? console_unlock+0x4a/0xd0\n[ 3103.005806] ? handle_bug+0x3f/0x70\n[ 3103.006149] ? exc_invalid_op+0x13/0x60\n[ 3103.006531] ? asm_exc_invalid_op+0x16/0x20\n[ 3103.007430] ? __list_del_entry_valid_or_report+0x4f/0xc0\n[ 3103.007910] mlx5e_tc_del_fdb_peers_flow+0xcf/0x240 [mlx5_core]\n[ 3103.008463] mlx5e_tc_del_flow+0x46/0x270 [mlx5_core]\n[ 3103.008944] mlx5e_flow_put+0x26/0x50 [mlx5_core]\n[ 3103.009401] mlx5e_delete_flower+0x25f/0x380 [mlx5_core]\n[ 3103.009901] tc_setup_cb_destroy+0xab/0x180\n[ 3103.010292] fl_hw_destroy_filter+0x99/0xc0 [cls_flower]\n[ 3103.010779] __fl_delete+0x2d4/0x2f0 [cls_flower]\n[ 3103.0\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json b/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json index 73d4e2f4648..c87fcff1ad7 100644 --- a/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json +++ b/advisories/unreviewed/2024/03/GHSA-9p58-h634-47q5/GHSA-9p58-h634-47q5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-284" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-9ph4-wxwh-x4xm/GHSA-9ph4-wxwh-x4xm.json b/advisories/unreviewed/2024/03/GHSA-9ph4-wxwh-x4xm/GHSA-9ph4-wxwh-x4xm.json index 10d26bb587d..e8aa5f9f02d 100644 --- a/advisories/unreviewed/2024/03/GHSA-9ph4-wxwh-x4xm/GHSA-9ph4-wxwh-x4xm.json +++ b/advisories/unreviewed/2024/03/GHSA-9ph4-wxwh-x4xm/GHSA-9ph4-wxwh-x4xm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9pv7-rcfr-x287/GHSA-9pv7-rcfr-x287.json b/advisories/unreviewed/2024/03/GHSA-9pv7-rcfr-x287/GHSA-9pv7-rcfr-x287.json index 93dc62de325..bfb303e8304 100644 --- a/advisories/unreviewed/2024/03/GHSA-9pv7-rcfr-x287/GHSA-9pv7-rcfr-x287.json +++ b/advisories/unreviewed/2024/03/GHSA-9pv7-rcfr-x287/GHSA-9pv7-rcfr-x287.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pv7-rcfr-x287", - "modified": "2024-03-25T09:32:35Z", + "modified": "2024-12-12T18:30:51Z", "published": "2024-03-25T09:32:35Z", "aliases": [ "CVE-2021-47150" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fec: fix the potential memory leak in fec_enet_init()\n\nIf the memory allocated for cbd_base is failed, it should\nfree the memory allocated for the queues, otherwise it causes\nmemory leak.\n\nAnd if the memory allocated for the queues is failed, it can\nreturn error directly.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T09:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9r7q-crgf-5r23/GHSA-9r7q-crgf-5r23.json b/advisories/unreviewed/2024/03/GHSA-9r7q-crgf-5r23/GHSA-9r7q-crgf-5r23.json index 3b0e3af6e23..959b475e35b 100644 --- a/advisories/unreviewed/2024/03/GHSA-9r7q-crgf-5r23/GHSA-9r7q-crgf-5r23.json +++ b/advisories/unreviewed/2024/03/GHSA-9r7q-crgf-5r23/GHSA-9r7q-crgf-5r23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9r7q-crgf-5r23", - "modified": "2024-03-25T12:30:51Z", + "modified": "2024-12-12T18:30:51Z", "published": "2024-03-25T12:30:51Z", "aliases": [ "CVE-2021-47158" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: sja1105: add error handling in sja1105_setup()\n\nIf any of sja1105_static_config_load(), sja1105_clocking_setup() or\nsja1105_devlink_setup() fails, we can't just return in the middle of\nsja1105_setup() or memory will leak. Add a cleanup path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c76f-cr24-9g74/GHSA-c76f-cr24-9g74.json b/advisories/unreviewed/2024/03/GHSA-c76f-cr24-9g74/GHSA-c76f-cr24-9g74.json index 3ec934bb896..990ab71649e 100644 --- a/advisories/unreviewed/2024/03/GHSA-c76f-cr24-9g74/GHSA-c76f-cr24-9g74.json +++ b/advisories/unreviewed/2024/03/GHSA-c76f-cr24-9g74/GHSA-c76f-cr24-9g74.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c76f-cr24-9g74", - "modified": "2024-03-25T09:32:35Z", + "modified": "2024-12-12T18:30:51Z", "published": "2024-03-25T09:32:35Z", "aliases": [ "CVE-2021-47151" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: qcom: bcm-voter: add a missing of_node_put()\n\nAdd a missing of_node_put() in of_bcm_voter_get() to avoid the\nreference leak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T09:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c7cm-2h42-m8x5/GHSA-c7cm-2h42-m8x5.json b/advisories/unreviewed/2024/03/GHSA-c7cm-2h42-m8x5/GHSA-c7cm-2h42-m8x5.json index a7eb3a4c558..4e5bf4d80c1 100644 --- a/advisories/unreviewed/2024/03/GHSA-c7cm-2h42-m8x5/GHSA-c7cm-2h42-m8x5.json +++ b/advisories/unreviewed/2024/03/GHSA-c7cm-2h42-m8x5/GHSA-c7cm-2h42-m8x5.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json b/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json index efc9c31363d..a8c7cf4d521 100644 --- a/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json +++ b/advisories/unreviewed/2024/03/GHSA-cf55-f79q-6cgp/GHSA-cf55-f79q-6cgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cf55-f79q-6cgp", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-26615" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix illegal rmb_desc access in SMC-D connection dump\n\nA crash was found when dumping SMC-D connections. It can be reproduced\nby following steps:\n\n- run nginx/wrk test:\n smc_run nginx\n smc_run wrk -t 16 -c 1000 -d -H 'Connection: Close' \n\n- continuously dump SMC-D connections in parallel:\n watch -n 1 'smcss -D'\n\n BUG: kernel NULL pointer dereference, address: 0000000000000030\n CPU: 2 PID: 7204 Comm: smcss Kdump: loaded Tainted: G\tE 6.7.0+ #55\n RIP: 0010:__smc_diag_dump.constprop.0+0x5e5/0x620 [smc_diag]\n Call Trace:\n \n ? __die+0x24/0x70\n ? page_fault_oops+0x66/0x150\n ? exc_page_fault+0x69/0x140\n ? asm_exc_page_fault+0x26/0x30\n ? __smc_diag_dump.constprop.0+0x5e5/0x620 [smc_diag]\n ? __kmalloc_node_track_caller+0x35d/0x430\n ? __alloc_skb+0x77/0x170\n smc_diag_dump_proto+0xd0/0xf0 [smc_diag]\n smc_diag_dump+0x26/0x60 [smc_diag]\n netlink_dump+0x19f/0x320\n __netlink_dump_start+0x1dc/0x300\n smc_diag_handler_dump+0x6a/0x80 [smc_diag]\n ? __pfx_smc_diag_dump+0x10/0x10 [smc_diag]\n sock_diag_rcv_msg+0x121/0x140\n ? __pfx_sock_diag_rcv_msg+0x10/0x10\n netlink_rcv_skb+0x5a/0x110\n sock_diag_rcv+0x28/0x40\n netlink_unicast+0x22a/0x330\n netlink_sendmsg+0x1f8/0x420\n __sock_sendmsg+0xb0/0xc0\n ____sys_sendmsg+0x24e/0x300\n ? copy_msghdr_from_user+0x62/0x80\n ___sys_sendmsg+0x7c/0xd0\n ? __do_fault+0x34/0x160\n ? do_read_fault+0x5f/0x100\n ? do_fault+0xb0/0x110\n ? __handle_mm_fault+0x2b0/0x6c0\n __sys_sendmsg+0x4d/0x80\n do_syscall_64+0x69/0x180\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nIt is possible that the connection is in process of being established\nwhen we dump it. Assumed that the connection has been registered in a\nlink group by smc_conn_create() but the rmb_desc has not yet been\ninitialized by smc_buf_create(), thus causing the illegal access to\nconn->rmb_desc. So fix it by checking before dump.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:19Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gwhc-573h-jxwh/GHSA-gwhc-573h-jxwh.json b/advisories/unreviewed/2024/03/GHSA-gwhc-573h-jxwh/GHSA-gwhc-573h-jxwh.json index 3398b87c815..00a98622aa6 100644 --- a/advisories/unreviewed/2024/03/GHSA-gwhc-573h-jxwh/GHSA-gwhc-573h-jxwh.json +++ b/advisories/unreviewed/2024/03/GHSA-gwhc-573h-jxwh/GHSA-gwhc-573h-jxwh.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-h9rc-rj87-48r4/GHSA-h9rc-rj87-48r4.json b/advisories/unreviewed/2024/03/GHSA-h9rc-rj87-48r4/GHSA-h9rc-rj87-48r4.json index d0a68842014..3fb2564137d 100644 --- a/advisories/unreviewed/2024/03/GHSA-h9rc-rj87-48r4/GHSA-h9rc-rj87-48r4.json +++ b/advisories/unreviewed/2024/03/GHSA-h9rc-rj87-48r4/GHSA-h9rc-rj87-48r4.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-hm8g-pxh5-8xgx/GHSA-hm8g-pxh5-8xgx.json b/advisories/unreviewed/2024/03/GHSA-hm8g-pxh5-8xgx/GHSA-hm8g-pxh5-8xgx.json index 3452a4b999f..2035e9b9dea 100644 --- a/advisories/unreviewed/2024/03/GHSA-hm8g-pxh5-8xgx/GHSA-hm8g-pxh5-8xgx.json +++ b/advisories/unreviewed/2024/03/GHSA-hm8g-pxh5-8xgx/GHSA-hm8g-pxh5-8xgx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hm8g-pxh5-8xgx", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-06T09:30:28Z", "aliases": [ "CVE-2023-52600" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix uaf in jfs_evict_inode\n\nWhen the execution of diMount(ipimap) fails, the object ipimap that has been\nreleased may be accessed in diFreeSpecial(). Asynchronous ipimap release occurs\nwhen rcu_core() calls jfs_free_node().\n\nTherefore, when diMount(ipimap) fails, sbi->ipimap should not be initialized as\nipimap.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jh2w-vmjx-m29q/GHSA-jh2w-vmjx-m29q.json b/advisories/unreviewed/2024/03/GHSA-jh2w-vmjx-m29q/GHSA-jh2w-vmjx-m29q.json index 75f14dfd3a4..cc2d143a169 100644 --- a/advisories/unreviewed/2024/03/GHSA-jh2w-vmjx-m29q/GHSA-jh2w-vmjx-m29q.json +++ b/advisories/unreviewed/2024/03/GHSA-jh2w-vmjx-m29q/GHSA-jh2w-vmjx-m29q.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-jx32-f9jj-34p6/GHSA-jx32-f9jj-34p6.json b/advisories/unreviewed/2024/03/GHSA-jx32-f9jj-34p6/GHSA-jx32-f9jj-34p6.json index 12c2bec4393..d6072b24fa0 100644 --- a/advisories/unreviewed/2024/03/GHSA-jx32-f9jj-34p6/GHSA-jx32-f9jj-34p6.json +++ b/advisories/unreviewed/2024/03/GHSA-jx32-f9jj-34p6/GHSA-jx32-f9jj-34p6.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-mx9m-w3w5-w7q4/GHSA-mx9m-w3w5-w7q4.json b/advisories/unreviewed/2024/03/GHSA-mx9m-w3w5-w7q4/GHSA-mx9m-w3w5-w7q4.json index e5ec42f0436..d34a0a4ec4f 100644 --- a/advisories/unreviewed/2024/03/GHSA-mx9m-w3w5-w7q4/GHSA-mx9m-w3w5-w7q4.json +++ b/advisories/unreviewed/2024/03/GHSA-mx9m-w3w5-w7q4/GHSA-mx9m-w3w5-w7q4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mx9m-w3w5-w7q4", - "modified": "2024-03-25T09:32:35Z", + "modified": "2024-12-12T18:30:51Z", "published": "2024-03-25T09:32:35Z", "aliases": [ "CVE-2021-47149" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fujitsu: fix potential null-ptr-deref\n\nIn fmvj18x_get_hwinfo(), if ioremap fails there will be NULL pointer\nderef. To fix this, check the return value of ioremap and return -1\nto the caller in case of failure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T09:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json b/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json index b242d471f87..05a8df35ff6 100644 --- a/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json +++ b/advisories/unreviewed/2024/03/GHSA-pj2q-rq9j-ffq5/GHSA-pj2q-rq9j-ffq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pj2q-rq9j-ffq5", - "modified": "2024-06-26T00:31:35Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-26610" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: fix a memory corruption\n\niwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means that\nif we copy to iwl_fw_ini_trigger_tlv::data + offset while offset is in\nbytes, we'll write past the buffer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:19Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pxxv-p7c4-h643/GHSA-pxxv-p7c4-h643.json b/advisories/unreviewed/2024/03/GHSA-pxxv-p7c4-h643/GHSA-pxxv-p7c4-h643.json index b3b173fe2aa..72d1d382902 100644 --- a/advisories/unreviewed/2024/03/GHSA-pxxv-p7c4-h643/GHSA-pxxv-p7c4-h643.json +++ b/advisories/unreviewed/2024/03/GHSA-pxxv-p7c4-h643/GHSA-pxxv-p7c4-h643.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pxxv-p7c4-h643", - "modified": "2024-06-27T15:30:38Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-06T09:30:28Z", "aliases": [ "CVE-2023-52603" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUBSAN: array-index-out-of-bounds in dtSplitRoot\n\nSyzkaller reported the following issue:\n\noop0: detected capacity change from 0 to 32768\n\nUBSAN: array-index-out-of-bounds in fs/jfs/jfs_dtree.c:1971:9\nindex -2 is out of range for type 'struct dtslot [128]'\nCPU: 0 PID: 3613 Comm: syz-executor270 Not tainted 6.0.0-syzkaller-09423-g493ffd6605b2 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1b1/0x28e lib/dump_stack.c:106\n ubsan_epilogue lib/ubsan.c:151 [inline]\n __ubsan_handle_out_of_bounds+0xdb/0x130 lib/ubsan.c:283\n dtSplitRoot+0x8d8/0x1900 fs/jfs/jfs_dtree.c:1971\n dtSplitUp fs/jfs/jfs_dtree.c:985 [inline]\n dtInsert+0x1189/0x6b80 fs/jfs/jfs_dtree.c:863\n jfs_mkdir+0x757/0xb00 fs/jfs/namei.c:270\n vfs_mkdir+0x3b3/0x590 fs/namei.c:4013\n do_mkdirat+0x279/0x550 fs/namei.c:4038\n __do_sys_mkdirat fs/namei.c:4053 [inline]\n __se_sys_mkdirat fs/namei.c:4051 [inline]\n __x64_sys_mkdirat+0x85/0x90 fs/namei.c:4051\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7fcdc0113fd9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffeb8bc67d8 EFLAGS: 00000246 ORIG_RAX: 0000000000000102\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fcdc0113fd9\nRDX: 0000000000000000 RSI: 0000000020000340 RDI: 0000000000000003\nRBP: 00007fcdc00d37a0 R08: 0000000000000000 R09: 00007fcdc00d37a0\nR10: 00005555559a72c0 R11: 0000000000000246 R12: 00000000f8008000\nR13: 0000000000000000 R14: 00083878000000f8 R15: 0000000000000000\n \n\nThe issue is caused when the value of fsi becomes less than -1.\nThe check to break the loop when fsi value becomes -1 is present\nbut syzbot was able to produce value less than -1 which cause the error.\nThis patch simply add the change for the values less than 0.\n\nThe patch is tested via syzbot.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json b/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json index aabaf717735..262c3e71862 100644 --- a/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json +++ b/advisories/unreviewed/2024/03/GHSA-q98h-hc6w-gjhg/GHSA-q98h-hc6w-gjhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q98h-hc6w-gjhg", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-26616" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: scrub: avoid use-after-free when chunk length is not 64K aligned\n\n[BUG]\nThere is a bug report that, on a ext4-converted btrfs, scrub leads to\nvarious problems, including:\n\n- \"unable to find chunk map\" errors\n BTRFS info (device vdb): scrub: started on devid 1\n BTRFS critical (device vdb): unable to find chunk map for logical 2214744064 length 4096\n BTRFS critical (device vdb): unable to find chunk map for logical 2214744064 length 45056\n\n This would lead to unrepariable errors.\n\n- Use-after-free KASAN reports:\n ==================================================================\n BUG: KASAN: slab-use-after-free in __blk_rq_map_sg+0x18f/0x7c0\n Read of size 8 at addr ffff8881013c9040 by task btrfs/909\n CPU: 0 PID: 909 Comm: btrfs Not tainted 6.7.0-x64v3-dbg #11 c50636e9419a8354555555245df535e380563b2b\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 2023.11-2 12/24/2023\n Call Trace:\n \n dump_stack_lvl+0x43/0x60\n print_report+0xcf/0x640\n kasan_report+0xa6/0xd0\n __blk_rq_map_sg+0x18f/0x7c0\n virtblk_prep_rq.isra.0+0x215/0x6a0 [virtio_blk 19a65eeee9ae6fcf02edfad39bb9ddee07dcdaff]\n virtio_queue_rqs+0xc4/0x310 [virtio_blk 19a65eeee9ae6fcf02edfad39bb9ddee07dcdaff]\n blk_mq_flush_plug_list.part.0+0x780/0x860\n __blk_flush_plug+0x1ba/0x220\n blk_finish_plug+0x3b/0x60\n submit_initial_group_read+0x10a/0x290 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n flush_scrub_stripes+0x38e/0x430 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n scrub_stripe+0x82a/0xae0 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n scrub_chunk+0x178/0x200 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n scrub_enumerate_chunks+0x4bc/0xa30 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n btrfs_scrub_dev+0x398/0x810 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n btrfs_ioctl+0x4b9/0x3020 [btrfs e57987a360bed82fe8756dcd3e0de5406ccfe965]\n __x64_sys_ioctl+0xbd/0x100\n do_syscall_64+0x5d/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n RIP: 0033:0x7f47e5e0952b\n\n- Crash, mostly due to above use-after-free\n\n[CAUSE]\nThe converted fs has the following data chunk layout:\n\n item 2 key (FIRST_CHUNK_TREE CHUNK_ITEM 2214658048) itemoff 16025 itemsize 80\n length 86016 owner 2 stripe_len 65536 type DATA|single\n\nFor above logical bytenr 2214744064, it's at the chunk end\n(2214658048 + 86016 = 2214744064).\n\nThis means btrfs_submit_bio() would split the bio, and trigger endio\nfunction for both of the two halves.\n\nHowever scrub_submit_initial_read() would only expect the endio function\nto be called once, not any more.\nThis means the first endio function would already free the bbio::bio,\nleaving the bvec freed, thus the 2nd endio call would lead to\nuse-after-free.\n\n[FIX]\n- Make sure scrub_read_endio() only updates bits in its range\n Since we may read less than 64K at the end of the chunk, we should not\n touch the bits beyond chunk boundary.\n\n- Make sure scrub_submit_initial_read() only to read the chunk range\n This is done by calculating the real number of sectors we need to\n read, and add sector-by-sector to the bio.\n\nThankfully the scrub read repair path won't need extra fixes:\n\n- scrub_stripe_submit_repair_read()\n With above fixes, we won't update error bit for range beyond chunk,\n thus scrub_stripe_submit_repair_read() should never submit any read\n beyond the chunk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:19Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r42v-8ppg-qjqx/GHSA-r42v-8ppg-qjqx.json b/advisories/unreviewed/2024/03/GHSA-r42v-8ppg-qjqx/GHSA-r42v-8ppg-qjqx.json index d9d9c2c00de..5759787248d 100644 --- a/advisories/unreviewed/2024/03/GHSA-r42v-8ppg-qjqx/GHSA-r42v-8ppg-qjqx.json +++ b/advisories/unreviewed/2024/03/GHSA-r42v-8ppg-qjqx/GHSA-r42v-8ppg-qjqx.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-rx3g-7rv4-58vw/GHSA-rx3g-7rv4-58vw.json b/advisories/unreviewed/2024/03/GHSA-rx3g-7rv4-58vw/GHSA-rx3g-7rv4-58vw.json index abb73f2ef8e..73c37ca3e76 100644 --- a/advisories/unreviewed/2024/03/GHSA-rx3g-7rv4-58vw/GHSA-rx3g-7rv4-58vw.json +++ b/advisories/unreviewed/2024/03/GHSA-rx3g-7rv4-58vw/GHSA-rx3g-7rv4-58vw.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-wv5g-rv8w-9x7p/GHSA-wv5g-rv8w-9x7p.json b/advisories/unreviewed/2024/03/GHSA-wv5g-rv8w-9x7p/GHSA-wv5g-rv8w-9x7p.json index afd6e329ad6..8794526b514 100644 --- a/advisories/unreviewed/2024/03/GHSA-wv5g-rv8w-9x7p/GHSA-wv5g-rv8w-9x7p.json +++ b/advisories/unreviewed/2024/03/GHSA-wv5g-rv8w-9x7p/GHSA-wv5g-rv8w-9x7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wv5g-rv8w-9x7p", - "modified": "2024-06-26T00:31:35Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2023-52498" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPM: sleep: Fix possible deadlocks in core system-wide PM code\n\nIt is reported that in low-memory situations the system-wide resume core\ncode deadlocks, because async_schedule_dev() executes its argument\nfunction synchronously if it cannot allocate memory (and not only in\nthat case) and that function attempts to acquire a mutex that is already\nheld. Executing the argument function synchronously from within\ndpm_async_fn() may also be problematic for ordering reasons (it may\ncause a consumer device's resume callback to be invoked before a\nrequisite supplier device's one, for example).\n\nAddress this by changing the code in question to use\nasync_schedule_dev_nocall() for scheduling the asynchronous\nexecution of device suspend and resume functions and to directly\nrun them synchronously if async_schedule_dev_nocall() returns false.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:17Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json b/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json index 41be89647d6..c46d7df628f 100644 --- a/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json +++ b/advisories/unreviewed/2024/03/GHSA-x5f4-w9r3-6rpq/GHSA-x5f4-w9r3-6rpq.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json b/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json index b3b7eccae49..0810b7f14de 100644 --- a/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json +++ b/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcpx-x4rg-25pv", - "modified": "2024-12-03T00:31:29Z", + "modified": "2024-12-12T18:30:50Z", "published": "2024-03-18T18:32:21Z", "aliases": [ "CVE-2024-26050" diff --git a/advisories/unreviewed/2024/09/GHSA-wc8g-qpv4-8j46/GHSA-wc8g-qpv4-8j46.json b/advisories/unreviewed/2024/09/GHSA-wc8g-qpv4-8j46/GHSA-wc8g-qpv4-8j46.json index 63511612c92..5a8f5150d8e 100644 --- a/advisories/unreviewed/2024/09/GHSA-wc8g-qpv4-8j46/GHSA-wc8g-qpv4-8j46.json +++ b/advisories/unreviewed/2024/09/GHSA-wc8g-qpv4-8j46/GHSA-wc8g-qpv4-8j46.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-33rg-9hjg-3559/GHSA-33rg-9hjg-3559.json b/advisories/unreviewed/2024/12/GHSA-33rg-9hjg-3559/GHSA-33rg-9hjg-3559.json index 32ae358f934..71266057cba 100644 --- a/advisories/unreviewed/2024/12/GHSA-33rg-9hjg-3559/GHSA-33rg-9hjg-3559.json +++ b/advisories/unreviewed/2024/12/GHSA-33rg-9hjg-3559/GHSA-33rg-9hjg-3559.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-33rg-9hjg-3559", - "modified": "2024-12-12T15:31:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T15:31:07Z", "aliases": [ "CVE-2024-36498" ], "details": "Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The \"Edit Disclaimer Text\" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL\n\n\n\n\n\n\n\n\n\nhttps://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre\n\nThe stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser. Version 7.40 implemented a fix, but it could be bypassed via URL-encoding the Javascript payload again.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T13:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json b/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json index 7aa38818c84..81b559c17a7 100644 --- a/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json +++ b/advisories/unreviewed/2024/12/GHSA-33vc-jm33-3f35/GHSA-33vc-jm33-3f35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-33vc-jm33-3f35", - "modified": "2024-12-09T03:30:59Z", + "modified": "2024-12-12T18:30:54Z", "published": "2024-12-09T03:30:59Z", "aliases": [ "CVE-2024-55578" ], "details": "Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T03:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json b/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json index 04f751b50e3..e1651bf4a79 100644 --- a/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json +++ b/advisories/unreviewed/2024/12/GHSA-372f-8jhc-h6mp/GHSA-372f-8jhc-h6mp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-372f-8jhc-h6mp", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54501" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted file may lead to a denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-38g9-r8v2-99xr/GHSA-38g9-r8v2-99xr.json b/advisories/unreviewed/2024/12/GHSA-38g9-r8v2-99xr/GHSA-38g9-r8v2-99xr.json index 0c4048a0e42..50fbb16c799 100644 --- a/advisories/unreviewed/2024/12/GHSA-38g9-r8v2-99xr/GHSA-38g9-r8v2-99xr.json +++ b/advisories/unreviewed/2024/12/GHSA-38g9-r8v2-99xr/GHSA-38g9-r8v2-99xr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-38g9-r8v2-99xr", - "modified": "2024-12-09T21:31:02Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-09T21:31:02Z", "aliases": [ "CVE-2024-54932" ], "details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T19:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3cfg-p79p-hp56/GHSA-3cfg-p79p-hp56.json b/advisories/unreviewed/2024/12/GHSA-3cfg-p79p-hp56/GHSA-3cfg-p79p-hp56.json index 60dcd779af7..e325220ca2b 100644 --- a/advisories/unreviewed/2024/12/GHSA-3cfg-p79p-hp56/GHSA-3cfg-p79p-hp56.json +++ b/advisories/unreviewed/2024/12/GHSA-3cfg-p79p-hp56/GHSA-3cfg-p79p-hp56.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3cfg-p79p-hp56", - "modified": "2024-12-12T15:31:09Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T15:31:09Z", "aliases": [ "CVE-2024-54842" ], "details": "A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T15:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3p9v-2c3q-cf4v/GHSA-3p9v-2c3q-cf4v.json b/advisories/unreviewed/2024/12/GHSA-3p9v-2c3q-cf4v/GHSA-3p9v-2c3q-cf4v.json new file mode 100644 index 00000000000..923ab27e2e0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3p9v-2c3q-cf4v/GHSA-3p9v-2c3q-cf4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p9v-2c3q-cf4v", + "modified": "2024-12-12T18:30:55Z", + "published": "2024-12-12T18:30:55Z", + "aliases": [ + "CVE-2024-55099" + ], + "details": "A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55099" + }, + { + "type": "WEB", + "url": "https://github.com/achchhelalchauhan/phpgurukul/blob/main/SQL%20injection%20ONHP-username.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json b/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json index fe68017572e..3174c6b751c 100644 --- a/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json +++ b/advisories/unreviewed/2024/12/GHSA-3q36-3ffw-mmf8/GHSA-3q36-3ffw-mmf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q36-3ffw-mmf8", - "modified": "2024-12-12T06:30:50Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-10568" ], "details": "The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-426h-mq34-gjcg/GHSA-426h-mq34-gjcg.json b/advisories/unreviewed/2024/12/GHSA-426h-mq34-gjcg/GHSA-426h-mq34-gjcg.json new file mode 100644 index 00000000000..bd36604f6fd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-426h-mq34-gjcg/GHSA-426h-mq34-gjcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-426h-mq34-gjcg", + "modified": "2024-12-12T18:30:55Z", + "published": "2024-12-12T18:30:55Z", + "aliases": [ + "CVE-2024-52901" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52901" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177700" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json b/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json new file mode 100644 index 00000000000..79208c9fb39 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5mvv-6ghv-vm4v/GHSA-5mvv-6ghv-vm4v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mvv-6ghv-vm4v", + "modified": "2024-12-12T18:30:55Z", + "published": "2024-12-12T18:30:55Z", + "aliases": [ + "CVE-2024-54810" + ], + "details": "A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54810" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/Pre-School%20Enrollment/SQL%20Injection%20pre-school%20pa.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5qrg-ccrj-6fg3/GHSA-5qrg-ccrj-6fg3.json b/advisories/unreviewed/2024/12/GHSA-5qrg-ccrj-6fg3/GHSA-5qrg-ccrj-6fg3.json index ac56a26299f..3ac5e970efb 100644 --- a/advisories/unreviewed/2024/12/GHSA-5qrg-ccrj-6fg3/GHSA-5qrg-ccrj-6fg3.json +++ b/advisories/unreviewed/2024/12/GHSA-5qrg-ccrj-6fg3/GHSA-5qrg-ccrj-6fg3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qrg-ccrj-6fg3", - "modified": "2024-12-09T21:31:02Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-09T21:31:02Z", "aliases": [ "CVE-2024-54934" ], "details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T19:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json b/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json index d91a840f7d8..d4e51ab81c4 100644 --- a/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json +++ b/advisories/unreviewed/2024/12/GHSA-5w62-ppvg-pwpq/GHSA-5w62-ppvg-pwpq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5w62-ppvg-pwpq", - "modified": "2024-12-12T06:30:50Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-10499" ], "details": "The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-68rw-c4gj-cpcv/GHSA-68rw-c4gj-cpcv.json b/advisories/unreviewed/2024/12/GHSA-68rw-c4gj-cpcv/GHSA-68rw-c4gj-cpcv.json index 5f54b80c2f3..8b47088298c 100644 --- a/advisories/unreviewed/2024/12/GHSA-68rw-c4gj-cpcv/GHSA-68rw-c4gj-cpcv.json +++ b/advisories/unreviewed/2024/12/GHSA-68rw-c4gj-cpcv/GHSA-68rw-c4gj-cpcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68rw-c4gj-cpcv", - "modified": "2024-12-12T15:31:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T15:31:07Z", "aliases": [ "CVE-2024-28142" ], "details": "Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The \"File Name\" page (/cgi/uset.cgi?-cfilename) in the User Settings menu improperly filters the \"file name\" and wildcard character input field. By exploiting the wildcard character feature, attackers are able to store arbitrary Javascript code which is being triggered if the page is viewed afterwards, e.g. by higher privileged users such as admins.\n\n\n\n\n\n\n\n\n\nThis attack can even be performed without being logged in because the affected functions are not fully protected. Without logging in, only the file name parameter of the \"Default\" User can be changed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T13:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json b/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json index c2ef618facf..433b3317086 100644 --- a/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json +++ b/advisories/unreviewed/2024/12/GHSA-699w-2m8p-hw49/GHSA-699w-2m8p-hw49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-699w-2m8p-hw49", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-12T18:30:54Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53108" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Adjust VSDB parser for replay feature\n\nAt some point, the IEEE ID identification for the replay check in the\nAMD EDID was added. However, this check causes the following\nout-of-bounds issues when using KASAN:\n\n[ 27.804016] BUG: KASAN: slab-out-of-bounds in amdgpu_dm_update_freesync_caps+0xefa/0x17a0 [amdgpu]\n[ 27.804788] Read of size 1 at addr ffff8881647fdb00 by task systemd-udevd/383\n\n...\n\n[ 27.821207] Memory state around the buggy address:\n[ 27.821215] ffff8881647fda00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821224] ffff8881647fda80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821234] >ffff8881647fdb00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 27.821243] ^\n[ 27.821250] ffff8881647fdb80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 27.821259] ffff8881647fdc00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821268] ==================================================================\n\nThis is caused because the ID extraction happens outside of the range of\nthe edid lenght. This commit addresses this issue by considering the\namd_vsdb_block size.\n\n(cherry picked from commit b7e381b1ccd5e778e3d9c44c669ad38439a861d8)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json b/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json index 76415e8796f..e210d0cce34 100644 --- a/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json +++ b/advisories/unreviewed/2024/12/GHSA-6p32-cp49-w842/GHSA-6p32-cp49-w842.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p32-cp49-w842", - "modified": "2024-12-12T06:30:51Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:51Z", "aliases": [ "CVE-2024-9428" ], "details": "The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json b/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json index 84233b85614..95d7cc69ed4 100644 --- a/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json +++ b/advisories/unreviewed/2024/12/GHSA-7pg5-v792-9xv2/GHSA-7pg5-v792-9xv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7pg5-v792-9xv2", - "modified": "2024-12-11T18:30:42Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-11T18:30:42Z", "aliases": [ "CVE-2024-28139" ], "details": "The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-250" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-11T16:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-99xq-gh8h-93m3/GHSA-99xq-gh8h-93m3.json b/advisories/unreviewed/2024/12/GHSA-99xq-gh8h-93m3/GHSA-99xq-gh8h-93m3.json index ded61a0c5c2..2bb00a0437e 100644 --- a/advisories/unreviewed/2024/12/GHSA-99xq-gh8h-93m3/GHSA-99xq-gh8h-93m3.json +++ b/advisories/unreviewed/2024/12/GHSA-99xq-gh8h-93m3/GHSA-99xq-gh8h-93m3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99xq-gh8h-93m3", - "modified": "2024-12-12T15:31:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T15:31:07Z", "aliases": [ "CVE-2024-36494" ], "details": "Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T13:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json b/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json index 644658666c5..ced0dfc0630 100644 --- a/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json +++ b/advisories/unreviewed/2024/12/GHSA-c6g8-rch8-xjjv/GHSA-c6g8-rch8-xjjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c6g8-rch8-xjjv", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-12T18:30:54Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53107" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args()\n\nThe \"arg->vec_len\" variable is a u64 that comes from the user at the start\nof the function. The \"arg->vec_len * sizeof(struct page_region))\"\nmultiplication can lead to integer wrapping. Use size_mul() to avoid\nthat.\n\nAlso the size_add/mul() functions work on unsigned long so for 32bit\nsystems we need to ensure that \"arg->vec_len\" fits in an unsigned long.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c9cj-xh7p-qvvr/GHSA-c9cj-xh7p-qvvr.json b/advisories/unreviewed/2024/12/GHSA-c9cj-xh7p-qvvr/GHSA-c9cj-xh7p-qvvr.json index e15b94a688d..411af9111eb 100644 --- a/advisories/unreviewed/2024/12/GHSA-c9cj-xh7p-qvvr/GHSA-c9cj-xh7p-qvvr.json +++ b/advisories/unreviewed/2024/12/GHSA-c9cj-xh7p-qvvr/GHSA-c9cj-xh7p-qvvr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c9cj-xh7p-qvvr", - "modified": "2024-12-09T21:31:02Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-09T21:31:02Z", "aliases": [ "CVE-2024-54925" ], "details": "A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T19:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json b/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json index 2dcad4595cd..47e270aaa30 100644 --- a/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json +++ b/advisories/unreviewed/2024/12/GHSA-c9mr-7r2v-xjc9/GHSA-c9mr-7r2v-xjc9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c9mr-7r2v-xjc9", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-44246" ], "details": "The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json b/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json index 7d2a2238150..e6dbc506ad5 100644 --- a/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json +++ b/advisories/unreviewed/2024/12/GHSA-crvx-jm2p-jmwp/GHSA-crvx-jm2p-jmwp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crvx-jm2p-jmwp", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:05Z", "aliases": [ "CVE-2024-44241" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json b/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json new file mode 100644 index 00000000000..7d5861dd8b7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cvmq-g63x-rjjh/GHSA-cvmq-g63x-rjjh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvmq-g63x-rjjh", + "modified": "2024-12-12T18:30:55Z", + "published": "2024-12-12T18:30:55Z", + "aliases": [ + "CVE-2024-31670" + ], + "details": "rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31670" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/commit/75bac3088b2ec173e22d4be9d525ceacc987cf02" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json b/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json index 7d89e31ddd1..1699f2a0014 100644 --- a/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json +++ b/advisories/unreviewed/2024/12/GHSA-cvp4-7hm2-fv9m/GHSA-cvp4-7hm2-fv9m.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-f9hr-3m6x-jmr5/GHSA-f9hr-3m6x-jmr5.json b/advisories/unreviewed/2024/12/GHSA-f9hr-3m6x-jmr5/GHSA-f9hr-3m6x-jmr5.json index 4ca662197d8..beea75593e6 100644 --- a/advisories/unreviewed/2024/12/GHSA-f9hr-3m6x-jmr5/GHSA-f9hr-3m6x-jmr5.json +++ b/advisories/unreviewed/2024/12/GHSA-f9hr-3m6x-jmr5/GHSA-f9hr-3m6x-jmr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9hr-3m6x-jmr5", - "modified": "2024-12-12T15:31:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T15:31:07Z", "aliases": [ "CVE-2024-47947" ], "details": "Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The \"Edit Disclaimer Text\" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL\n\n\n\n\n\n\n\n\n\nhttps://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre\n\nThe stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T13:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json b/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json index 21c2cdd5cc2..011600c80b0 100644 --- a/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json +++ b/advisories/unreviewed/2024/12/GHSA-hf45-h325-58j2/GHSA-hf45-h325-58j2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hf45-h325-58j2", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54524" ], "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to access arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json b/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json index 94b2ca13592..a407c63dcc0 100644 --- a/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json +++ b/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjmx-m9c7-h485", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54471" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json b/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json index 5b3987fd468..efbebd60ffe 100644 --- a/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json +++ b/advisories/unreviewed/2024/12/GHSA-j4cm-37xq-935g/GHSA-j4cm-37xq-935g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j4cm-37xq-935g", - "modified": "2024-12-12T06:30:50Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-10518" ], "details": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json b/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json index fe3dcf1dce9..ec6b5b464bf 100644 --- a/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json +++ b/advisories/unreviewed/2024/12/GHSA-j4h9-xpvr-4pqq/GHSA-j4h9-xpvr-4pqq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j4h9-xpvr-4pqq", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54529" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:32Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jhvg-7734-cx6x/GHSA-jhvg-7734-cx6x.json b/advisories/unreviewed/2024/12/GHSA-jhvg-7734-cx6x/GHSA-jhvg-7734-cx6x.json index b610601f04f..7db12bb3a9a 100644 --- a/advisories/unreviewed/2024/12/GHSA-jhvg-7734-cx6x/GHSA-jhvg-7734-cx6x.json +++ b/advisories/unreviewed/2024/12/GHSA-jhvg-7734-cx6x/GHSA-jhvg-7734-cx6x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jhvg-7734-cx6x", - "modified": "2024-12-09T21:31:01Z", + "modified": "2024-12-12T18:30:54Z", "published": "2024-12-09T21:31:01Z", "aliases": [ "CVE-2022-29974" ], "details": "AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in certain ASUS devices.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T19:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json b/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json index cb172995b22..0a34f8c4afa 100644 --- a/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json +++ b/advisories/unreviewed/2024/12/GHSA-jw8x-5w8f-9hrm/GHSA-jw8x-5w8f-9hrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jw8x-5w8f-9hrm", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54492" ], "details": "This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json b/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json index 2faecdffdc5..b42dd53d0ac 100644 --- a/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json +++ b/advisories/unreviewed/2024/12/GHSA-jx47-v2mx-xmc3/GHSA-jx47-v2mx-xmc3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jx47-v2mx-xmc3", - "modified": "2024-12-12T06:30:50Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-10010" ], "details": "The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json b/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json index 34801ce4c8b..f4c33171e74 100644 --- a/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json +++ b/advisories/unreviewed/2024/12/GHSA-mxx8-w72q-6w75/GHSA-mxx8-w72q-6w75.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mxx8-w72q-6w75", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-44242" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json b/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json index 7b95cf9e794..2e63fd2633c 100644 --- a/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json +++ b/advisories/unreviewed/2024/12/GHSA-p9v3-8f7q-wffx/GHSA-p9v3-8f7q-wffx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p9v3-8f7q-wffx", - "modified": "2024-12-12T06:30:51Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:51Z", "aliases": [ "CVE-2024-9881" ], "details": "The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json b/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json index 49ec682583e..ef0b351eb4a 100644 --- a/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json +++ b/advisories/unreviewed/2024/12/GHSA-pp8g-vm2j-rjp3/GHSA-pp8g-vm2j-rjp3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pp8g-vm2j-rjp3", - "modified": "2024-12-12T03:33:03Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:03Z", "aliases": [ "CVE-2024-12382" ], "details": "Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T01:40:28Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json b/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json index fb3414b1e2f..0606185e36f 100644 --- a/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json +++ b/advisories/unreviewed/2024/12/GHSA-rhjp-3r26-6vqh/GHSA-rhjp-3r26-6vqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rhjp-3r26-6vqh", - "modified": "2024-12-12T06:30:50Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-10517" ], "details": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json b/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json index 64d2ac78449..bf6b56e4ae5 100644 --- a/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json +++ b/advisories/unreviewed/2024/12/GHSA-vqvq-ggf5-9h68/GHSA-vqvq-ggf5-9h68.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vqvq-ggf5-9h68", - "modified": "2024-12-12T06:30:51Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T06:30:51Z", "aliases": [ "CVE-2024-9641" ], "details": "The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T06:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json b/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json index 8f2bab88399..0f6604029c3 100644 --- a/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json +++ b/advisories/unreviewed/2024/12/GHSA-w5q3-762f-g235/GHSA-w5q3-762f-g235.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5q3-762f-g235", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54476" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json b/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json index d26dc4308ab..877b05b4017 100644 --- a/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json +++ b/advisories/unreviewed/2024/12/GHSA-w64q-ccr3-358g/GHSA-w64q-ccr3-358g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w64q-ccr3-358g", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54502" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w6w4-cwx3-j2qh/GHSA-w6w4-cwx3-j2qh.json b/advisories/unreviewed/2024/12/GHSA-w6w4-cwx3-j2qh/GHSA-w6w4-cwx3-j2qh.json new file mode 100644 index 00000000000..3386f744bcd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w6w4-cwx3-j2qh/GHSA-w6w4-cwx3-j2qh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6w4-cwx3-j2qh", + "modified": "2024-12-12T18:30:55Z", + "published": "2024-12-12T18:30:55Z", + "aliases": [ + "CVE-2024-47238" + ], + "details": "Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47238" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000227595/dsa-2024-355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-12T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json b/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json index 98e81436323..b0d4fd73eaa 100644 --- a/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json +++ b/advisories/unreviewed/2024/12/GHSA-wcqr-6gj6-96wc/GHSA-wcqr-6gj6-96wc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wcqr-6gj6-96wc", - "modified": "2024-12-12T03:33:06Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54495" ], "details": "The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json b/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json index d0aac57a990..76082f5a409 100644 --- a/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json +++ b/advisories/unreviewed/2024/12/GHSA-wm24-225r-44gm/GHSA-wm24-225r-44gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wm24-225r-44gm", - "modified": "2024-12-12T03:33:07Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54514" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T02:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json b/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json index 94145b2a4cf..4c375736125 100644 --- a/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json +++ b/advisories/unreviewed/2024/12/GHSA-xcmh-fgq9-r6jc/GHSA-xcmh-fgq9-r6jc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcmh-fgq9-r6jc", - "modified": "2024-12-12T03:33:03Z", + "modified": "2024-12-12T18:30:55Z", "published": "2024-12-12T03:33:03Z", "aliases": [ "CVE-2024-12381" ], "details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-12T01:40:28Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xhx6-w3cj-3336/GHSA-xhx6-w3cj-3336.json b/advisories/unreviewed/2024/12/GHSA-xhx6-w3cj-3336/GHSA-xhx6-w3cj-3336.json index 3f0d3759202..44458746f11 100644 --- a/advisories/unreviewed/2024/12/GHSA-xhx6-w3cj-3336/GHSA-xhx6-w3cj-3336.json +++ b/advisories/unreviewed/2024/12/GHSA-xhx6-w3cj-3336/GHSA-xhx6-w3cj-3336.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xhx6-w3cj-3336", - "modified": "2024-12-09T21:31:01Z", + "modified": "2024-12-12T18:30:54Z", "published": "2024-12-09T21:31:01Z", "aliases": [ "CVE-2024-54918" ], "details": "Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T19:15:15Z"