diff --git a/advisories/unreviewed/2021/12/GHSA-2rh7-96qm-4h8w/GHSA-2rh7-96qm-4h8w.json b/advisories/unreviewed/2021/12/GHSA-2rh7-96qm-4h8w/GHSA-2rh7-96qm-4h8w.json index 9f4931d29a1..107adae14ce 100644 --- a/advisories/unreviewed/2021/12/GHSA-2rh7-96qm-4h8w/GHSA-2rh7-96qm-4h8w.json +++ b/advisories/unreviewed/2021/12/GHSA-2rh7-96qm-4h8w/GHSA-2rh7-96qm-4h8w.json @@ -24,11 +24,16 @@ { "type": "WEB", "url": "https://bugs.chromium.org/p/aomedia/issues/detail?id=2914" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" } ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2021/12/GHSA-3mrv-v95f-r4rx/GHSA-3mrv-v95f-r4rx.json b/advisories/unreviewed/2021/12/GHSA-3mrv-v95f-r4rx/GHSA-3mrv-v95f-r4rx.json index 1f3d8aa4761..653a26febe9 100644 --- a/advisories/unreviewed/2021/12/GHSA-3mrv-v95f-r4rx/GHSA-3mrv-v95f-r4rx.json +++ b/advisories/unreviewed/2021/12/GHSA-3mrv-v95f-r4rx/GHSA-3mrv-v95f-r4rx.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2021/12/GHSA-cw3p-3434-gw6r/GHSA-cw3p-3434-gw6r.json b/advisories/unreviewed/2021/12/GHSA-cw3p-3434-gw6r/GHSA-cw3p-3434-gw6r.json index aacb7ea33f3..91a1f545a93 100644 --- a/advisories/unreviewed/2021/12/GHSA-cw3p-3434-gw6r/GHSA-cw3p-3434-gw6r.json +++ b/advisories/unreviewed/2021/12/GHSA-cw3p-3434-gw6r/GHSA-cw3p-3434-gw6r.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2021/12/GHSA-g8f8-rq6r-4rrh/GHSA-g8f8-rq6r-4rrh.json b/advisories/unreviewed/2021/12/GHSA-g8f8-rq6r-4rrh/GHSA-g8f8-rq6r-4rrh.json index faa5e67dc43..73c5a1b3c65 100644 --- a/advisories/unreviewed/2021/12/GHSA-g8f8-rq6r-4rrh/GHSA-g8f8-rq6r-4rrh.json +++ b/advisories/unreviewed/2021/12/GHSA-g8f8-rq6r-4rrh/GHSA-g8f8-rq6r-4rrh.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2021/12/GHSA-w6cc-5mpf-4rmj/GHSA-w6cc-5mpf-4rmj.json b/advisories/unreviewed/2021/12/GHSA-w6cc-5mpf-4rmj/GHSA-w6cc-5mpf-4rmj.json index 08ea4f73e97..755b07625fa 100644 --- a/advisories/unreviewed/2021/12/GHSA-w6cc-5mpf-4rmj/GHSA-w6cc-5mpf-4rmj.json +++ b/advisories/unreviewed/2021/12/GHSA-w6cc-5mpf-4rmj/GHSA-w6cc-5mpf-4rmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w6cc-5mpf-4rmj", - "modified": "2021-12-04T00:01:10Z", + "modified": "2024-01-31T15:30:17Z", "published": "2021-12-03T00:00:27Z", "aliases": [ "CVE-2020-36129" ], "details": "AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -21,6 +24,10 @@ { "type": "WEB", "url": "https://bugs.chromium.org/p/aomedia/issues/detail?id=2912&q=&can=1" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" } ], "database_specific": { diff --git a/advisories/unreviewed/2021/12/GHSA-w9vw-69gr-j5w3/GHSA-w9vw-69gr-j5w3.json b/advisories/unreviewed/2021/12/GHSA-w9vw-69gr-j5w3/GHSA-w9vw-69gr-j5w3.json index e15ced29550..18afff9c71f 100644 --- a/advisories/unreviewed/2021/12/GHSA-w9vw-69gr-j5w3/GHSA-w9vw-69gr-j5w3.json +++ b/advisories/unreviewed/2021/12/GHSA-w9vw-69gr-j5w3/GHSA-w9vw-69gr-j5w3.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2022/05/GHSA-5r4m-4q9j-5jhh/GHSA-5r4m-4q9j-5jhh.json b/advisories/unreviewed/2022/05/GHSA-5r4m-4q9j-5jhh/GHSA-5r4m-4q9j-5jhh.json index eaf8e723709..43a9a21884a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r4m-4q9j-5jhh/GHSA-5r4m-4q9j-5jhh.json +++ b/advisories/unreviewed/2022/05/GHSA-5r4m-4q9j-5jhh/GHSA-5r4m-4q9j-5jhh.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2022/05/GHSA-867w-fmxg-m2g8/GHSA-867w-fmxg-m2g8.json b/advisories/unreviewed/2022/05/GHSA-867w-fmxg-m2g8/GHSA-867w-fmxg-m2g8.json index 81ec98ac61b..b9f8eb7acea 100644 --- a/advisories/unreviewed/2022/05/GHSA-867w-fmxg-m2g8/GHSA-867w-fmxg-m2g8.json +++ b/advisories/unreviewed/2022/05/GHSA-867w-fmxg-m2g8/GHSA-867w-fmxg-m2g8.json @@ -33,10 +33,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCI33HXH6YSOGC2LPE2REQLMIDH6US4/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXCI33HXH6YSOGC2LPE2REQLMIDH6US4/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2022/05/GHSA-jr38-ch73-ccgx/GHSA-jr38-ch73-ccgx.json b/advisories/unreviewed/2022/05/GHSA-jr38-ch73-ccgx/GHSA-jr38-ch73-ccgx.json index dfe3e4efd8a..ed5dfa29060 100644 --- a/advisories/unreviewed/2022/05/GHSA-jr38-ch73-ccgx/GHSA-jr38-ch73-ccgx.json +++ b/advisories/unreviewed/2022/05/GHSA-jr38-ch73-ccgx/GHSA-jr38-ch73-ccgx.json @@ -33,10 +33,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCI33HXH6YSOGC2LPE2REQLMIDH6US4/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXCI33HXH6YSOGC2LPE2REQLMIDH6US4/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-32" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5490" diff --git a/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json b/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json index 5025a83b6c1..258d2dfb595 100644 --- a/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json +++ b/advisories/unreviewed/2023/09/GHSA-2hcr-79rm-r8rp/GHSA-2hcr-79rm-r8rp.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EYRHTFVN6FTXLZ27IPTNRSXKBAR2SOMA/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213926" diff --git a/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json b/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json index 31f25383162..3e2295aad5c 100644 --- a/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json +++ b/advisories/unreviewed/2023/09/GHSA-6xcr-xqjv-c7jp/GHSA-6xcr-xqjv-c7jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xcr-xqjv-c7jp", - "modified": "2023-09-27T21:30:31Z", + "modified": "2024-01-31T15:30:18Z", "published": "2023-09-27T15:30:34Z", "aliases": [ "CVE-2023-35074" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213936" @@ -74,7 +78,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-27T15:18:52Z" diff --git a/advisories/unreviewed/2023/09/GHSA-84c6-x9x8-7q38/GHSA-84c6-x9x8-7q38.json b/advisories/unreviewed/2023/09/GHSA-84c6-x9x8-7q38/GHSA-84c6-x9x8-7q38.json index 05031a7847f..2ce4a41fa30 100644 --- a/advisories/unreviewed/2023/09/GHSA-84c6-x9x8-7q38/GHSA-84c6-x9x8-7q38.json +++ b/advisories/unreviewed/2023/09/GHSA-84c6-x9x8-7q38/GHSA-84c6-x9x8-7q38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84c6-x9x8-7q38", - "modified": "2023-09-27T18:30:24Z", + "modified": "2024-01-31T15:30:18Z", "published": "2023-09-27T15:30:35Z", "aliases": [ "CVE-2023-39434" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39434" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213937" @@ -54,7 +58,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-27T15:18:56Z" diff --git a/advisories/unreviewed/2023/09/GHSA-p489-ffhp-rw3f/GHSA-p489-ffhp-rw3f.json b/advisories/unreviewed/2023/09/GHSA-p489-ffhp-rw3f/GHSA-p489-ffhp-rw3f.json index fb9d7cd1a7e..f3219e0f3c1 100644 --- a/advisories/unreviewed/2023/09/GHSA-p489-ffhp-rw3f/GHSA-p489-ffhp-rw3f.json +++ b/advisories/unreviewed/2023/09/GHSA-p489-ffhp-rw3f/GHSA-p489-ffhp-rw3f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p489-ffhp-rw3f", - "modified": "2023-09-28T15:30:16Z", + "modified": "2024-01-31T15:30:18Z", "published": "2023-09-27T15:30:36Z", "aliases": [ "CVE-2023-40451" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40451" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213941" @@ -38,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-27T15:19:17Z" diff --git a/advisories/unreviewed/2023/09/GHSA-xq9m-9whg-jv3m/GHSA-xq9m-9whg-jv3m.json b/advisories/unreviewed/2023/09/GHSA-xq9m-9whg-jv3m/GHSA-xq9m-9whg-jv3m.json index edf7d54d521..10b46785ee5 100644 --- a/advisories/unreviewed/2023/09/GHSA-xq9m-9whg-jv3m/GHSA-xq9m-9whg-jv3m.json +++ b/advisories/unreviewed/2023/09/GHSA-xq9m-9whg-jv3m/GHSA-xq9m-9whg-jv3m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq9m-9whg-jv3m", - "modified": "2023-09-28T18:30:44Z", + "modified": "2024-01-31T15:30:18Z", "published": "2023-09-27T15:30:36Z", "aliases": [ "CVE-2023-41074" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213936" @@ -78,7 +82,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-27T15:19:26Z" diff --git a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json index 3ce18a41521..44f138718ad 100644 --- a/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json +++ b/advisories/unreviewed/2023/10/GHSA-294c-hpxh-5qrx/GHSA-294c-hpxh-5qrx.json @@ -61,6 +61,10 @@ "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-October/003430.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20231130-0004/" diff --git a/advisories/unreviewed/2023/10/GHSA-7245-jcxv-7q52/GHSA-7245-jcxv-7q52.json b/advisories/unreviewed/2023/10/GHSA-7245-jcxv-7q52/GHSA-7245-jcxv-7q52.json index 0a7ed62e52d..35df62d7458 100644 --- a/advisories/unreviewed/2023/10/GHSA-7245-jcxv-7q52/GHSA-7245-jcxv-7q52.json +++ b/advisories/unreviewed/2023/10/GHSA-7245-jcxv-7q52/GHSA-7245-jcxv-7q52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7245-jcxv-7q52", - "modified": "2023-10-06T18:30:32Z", + "modified": "2024-01-31T15:30:18Z", "published": "2023-10-06T18:30:32Z", "aliases": [ "CVE-2023-39928" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1831" @@ -42,7 +46,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-06T16:15:13Z" diff --git a/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json b/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json index 2971184a25c..fd7492e95d7 100644 --- a/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json +++ b/advisories/unreviewed/2023/10/GHSA-ch8m-5863-fcr7/GHSA-ch8m-5863-fcr7.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213981" diff --git a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json index 8c08479dcfc..286762e6a52 100644 --- a/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json +++ b/advisories/unreviewed/2023/10/GHSA-jmh8-4h3g-x5g5/GHSA-jmh8-4h3g-x5g5.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213981" diff --git a/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json b/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json index 5715bc994fa..52389eace8e 100644 --- a/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json +++ b/advisories/unreviewed/2023/10/GHSA-m58q-xcxc-4q6h/GHSA-m58q-xcxc-4q6h.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32359" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213981" diff --git a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json index 3f2f071d6ef..5feb67cfca3 100644 --- a/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json +++ b/advisories/unreviewed/2023/10/GHSA-q38f-wwqq-rr3v/GHSA-q38f-wwqq-rr3v.json @@ -113,6 +113,10 @@ "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-October/003430.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20231130-0004/" diff --git a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json index 3a4d9a4f177..f1e95d4c5a4 100644 --- a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json +++ b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json @@ -97,6 +97,10 @@ "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-December/003435.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240125-0003/" diff --git a/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json b/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json index 0c1f6e85456..0c5df152caa 100644 --- a/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json +++ b/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42890" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-33" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214035" @@ -60,6 +64,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Dec/9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/12/18/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json index e8c2f3384a3..13b7ac88f2d 100644 --- a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json +++ b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json @@ -101,6 +101,10 @@ "type": "WEB", "url": "https://lists.x.org/archives/xorg-announce/2023-December/003435.html" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240125-0003/" diff --git a/advisories/unreviewed/2024/01/GHSA-3xpr-x643-29v6/GHSA-3xpr-x643-29v6.json b/advisories/unreviewed/2024/01/GHSA-3xpr-x643-29v6/GHSA-3xpr-x643-29v6.json new file mode 100644 index 00000000000..44864083a55 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3xpr-x643-29v6/GHSA-3xpr-x643-29v6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xpr-x643-29v6", + "modified": "2024-01-31T15:30:19Z", + "published": "2024-01-31T15:30:19Z", + "aliases": [ + "CVE-2024-1085" + ], + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nThe nft_setelem_catchall_deactivate() function checks whether the catch-all set element is active in the current generation instead of the next generation before freeing it, but only flags it inactive in the next generation, making it possible to free the element multiple times, leading to a double free vulnerability.\n\nWe recommend upgrading past commit b1db244ffd041a49ecc9618e8feb6b5c1afcdaa7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1085" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b1db244ffd041a49ecc9618e8feb6b5c1afcdaa7" + }, + { + "type": "WEB", + "url": "https://kernel.dance/b1db244ffd041a49ecc9618e8feb6b5c1afcdaa7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json b/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json index 31f8342d408..74dbd59d24a 100644 --- a/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json +++ b/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json @@ -56,6 +56,14 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/30/9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/31/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/31/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json b/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json new file mode 100644 index 00000000000..01b341acad3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-554m-v42f-hcq9/GHSA-554m-v42f-hcq9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-554m-v42f-hcq9", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2023-5992" + ], + "details": "A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5992" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-5992" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2248685" + }, + { + "type": "WEB", + "url": "https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json b/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json index 91fbca5ae16..67172965e69 100644 --- a/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json +++ b/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mwr-c944-45q4", - "modified": "2024-01-31T12:30:17Z", + "modified": "2024-01-31T15:30:19Z", "published": "2024-01-31T12:30:17Z", "aliases": [ "CVE-2024-22287" diff --git a/advisories/unreviewed/2024/01/GHSA-8jgj-565r-w957/GHSA-8jgj-565r-w957.json b/advisories/unreviewed/2024/01/GHSA-8jgj-565r-w957/GHSA-8jgj-565r-w957.json new file mode 100644 index 00000000000..51adf66aa99 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8jgj-565r-w957/GHSA-8jgj-565r-w957.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jgj-565r-w957", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-22143" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22143" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-spell-check/wordpress-wp-spell-check-plugin-9-17-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c2j8-9924-mr82/GHSA-c2j8-9924-mr82.json b/advisories/unreviewed/2024/01/GHSA-c2j8-9924-mr82/GHSA-c2j8-9924-mr82.json new file mode 100644 index 00000000000..3e87ad1020c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c2j8-9924-mr82/GHSA-c2j8-9924-mr82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2j8-9924-mr82", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-22140" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22140" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profile-builder-pro/wordpress-profile-builder-pro-plugin-3-10-0-csrf-leading-to-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c5g8-87c9-j99r/GHSA-c5g8-87c9-j99r.json b/advisories/unreviewed/2024/01/GHSA-c5g8-87c9-j99r/GHSA-c5g8-87c9-j99r.json new file mode 100644 index 00000000000..c5e03725f39 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c5g8-87c9-j99r/GHSA-c5g8-87c9-j99r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5g8-87c9-j99r", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-1103" + ], + "details": "A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252458 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1103" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/18M55HRrxHQ9Jhph6CwWF-d5epAKtOSHt/edit?usp=drive_link&ouid=105609487033659389545&rtpof=true&sd=true" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252458" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json index f5a1c68cdb7..b18192b1a5e 100644 --- a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json +++ b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json @@ -76,6 +76,14 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/30/9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/31/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/31/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-frvc-f98w-c5hr/GHSA-frvc-f98w-c5hr.json b/advisories/unreviewed/2024/01/GHSA-frvc-f98w-c5hr/GHSA-frvc-f98w-c5hr.json new file mode 100644 index 00000000000..7167e48a38c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-frvc-f98w-c5hr/GHSA-frvc-f98w-c5hr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frvc-f98w-c5hr", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-22136" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder.This issue affects Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder: from n/a through 3.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22136" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/droit-elementor-addons/wordpress-droit-elementor-addons-plugin-3-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json b/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json new file mode 100644 index 00000000000..2f10f77c7ef --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gfh2-2mj9-m2cx/GHSA-gfh2-2mj9-m2cx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfh2-2mj9-m2cx", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-1086" + ], + "details": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.\n\nThe nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT.\n\nWe recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1086" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660" + }, + { + "type": "WEB", + "url": "https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json b/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json index 183592c0e0e..b76f8b93403 100644 --- a/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json +++ b/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvqj-cjp6-grrv", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-31T15:30:19Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52338" ], "details": "A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jcqj-vmgc-332m/GHSA-jcqj-vmgc-332m.json b/advisories/unreviewed/2024/01/GHSA-jcqj-vmgc-332m/GHSA-jcqj-vmgc-332m.json new file mode 100644 index 00000000000..d733c68548f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jcqj-vmgc-332m/GHSA-jcqj-vmgc-332m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcqj-vmgc-332m", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-22304" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For WordPress: from n/a through 2.3.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/freshmail-integration/wordpress-freshmail-for-wordpress-plugin-2-3-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jjqj-xq2v-c8jx/GHSA-jjqj-xq2v-c8jx.json b/advisories/unreviewed/2024/01/GHSA-jjqj-xq2v-c8jx/GHSA-jjqj-xq2v-c8jx.json new file mode 100644 index 00000000000..a3df0253fc0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jjqj-xq2v-c8jx/GHSA-jjqj-xq2v-c8jx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjqj-xq2v-c8jx", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-1112" + ], + "details": "Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1112" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/buffer-overflow-vulnerability-resource-hacker" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json b/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json new file mode 100644 index 00000000000..33651ce35f0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jjr8-97p7-vmmg/GHSA-jjr8-97p7-vmmg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjr8-97p7-vmmg", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2023-6780" + ], + "details": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6780" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-6780" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jrjh-cm7j-j4fh/GHSA-jrjh-cm7j-j4fh.json b/advisories/unreviewed/2024/01/GHSA-jrjh-cm7j-j4fh/GHSA-jrjh-cm7j-j4fh.json new file mode 100644 index 00000000000..236195ca5dc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jrjh-cm7j-j4fh/GHSA-jrjh-cm7j-j4fh.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrjh-cm7j-j4fh", + "modified": "2024-01-31T15:30:19Z", + "published": "2024-01-31T15:30:19Z", + "aliases": [ + "CVE-2024-1087" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2024-1085.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1087" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m5qf-4xvf-462h/GHSA-m5qf-4xvf-462h.json b/advisories/unreviewed/2024/01/GHSA-m5qf-4xvf-462h/GHSA-m5qf-4xvf-462h.json new file mode 100644 index 00000000000..43617565ebb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m5qf-4xvf-462h/GHSA-m5qf-4xvf-462h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5qf-4xvf-462h", + "modified": "2024-01-31T15:30:19Z", + "published": "2024-01-31T15:30:19Z", + "aliases": [ + "CVE-2023-7043" + ], + "details": "Unquoted service path in ESET products allows to \n\ndrop a prepared program to a specific location and run on boot with the \n\nNT AUTHORITY\\NetworkService permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7043" + }, + { + "type": "WEB", + "url": "https://support.eset.com/en/ca8602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json new file mode 100644 index 00000000000..c5453a3e3e0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p5vr-h433-qhqr/GHSA-p5vr-h433-qhqr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5vr-h433-qhqr", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2023-6779" + ], + "details": "An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6779" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-6779" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254395" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json new file mode 100644 index 00000000000..456dae07005 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p6rw-gvvh-q8v4/GHSA-p6rw-gvvh-q8v4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rw-gvvh-q8v4", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2023-6246" + ], + "details": "A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6246" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-6246" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249053" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json b/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json index 7769bd2ba8b..08b42317281 100644 --- a/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json +++ b/advisories/unreviewed/2024/01/GHSA-pcjv-393q-rqf2/GHSA-pcjv-393q-rqf2.json @@ -69,6 +69,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EJBMCWQ54R6ZL3MYU2D2JBW6JMZL7BQW/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/18/1" diff --git a/advisories/unreviewed/2024/01/GHSA-pg22-9hrc-63jf/GHSA-pg22-9hrc-63jf.json b/advisories/unreviewed/2024/01/GHSA-pg22-9hrc-63jf/GHSA-pg22-9hrc-63jf.json new file mode 100644 index 00000000000..c3100714602 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pg22-9hrc-63jf/GHSA-pg22-9hrc-63jf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg22-9hrc-63jf", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-22285" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: from n/a through 1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/frontpage-manager/wordpress-frontpage-manager-plugin-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json b/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json index f9825836011..56b3b9c51dd 100644 --- a/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json +++ b/advisories/unreviewed/2024/01/GHSA-q37p-g696-qhwm/GHSA-q37p-g696-qhwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q37p-g696-qhwm", - "modified": "2024-01-24T00:30:32Z", + "modified": "2024-01-31T15:30:19Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2021-42142" ], "details": "An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attackers to cause a denial of service and false-positive packet drops.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T22:15:16Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rcj8-jx65-7c4r/GHSA-rcj8-jx65-7c4r.json b/advisories/unreviewed/2024/01/GHSA-rcj8-jx65-7c4r/GHSA-rcj8-jx65-7c4r.json index 38a1e52e636..1f764669a66 100644 --- a/advisories/unreviewed/2024/01/GHSA-rcj8-jx65-7c4r/GHSA-rcj8-jx65-7c4r.json +++ b/advisories/unreviewed/2024/01/GHSA-rcj8-jx65-7c4r/GHSA-rcj8-jx65-7c4r.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EJBMCWQ54R6ZL3MYU2D2JBW6JMZL7BQW/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-w668-xcxf-v3gg/GHSA-w668-xcxf-v3gg.json b/advisories/unreviewed/2024/01/GHSA-w668-xcxf-v3gg/GHSA-w668-xcxf-v3gg.json index d10d3f535e3..34ec5910dec 100644 --- a/advisories/unreviewed/2024/01/GHSA-w668-xcxf-v3gg/GHSA-w668-xcxf-v3gg.json +++ b/advisories/unreviewed/2024/01/GHSA-w668-xcxf-v3gg/GHSA-w668-xcxf-v3gg.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EJBMCWQ54R6ZL3MYU2D2JBW6JMZL7BQW/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-30" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json b/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json new file mode 100644 index 00000000000..e41cbb01a7e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xh95-48w4-456m/GHSA-xh95-48w4-456m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh95-48w4-456m", + "modified": "2024-01-31T15:30:19Z", + "published": "2024-01-31T15:30:19Z", + "aliases": [ + "CVE-2024-0589" + ], + "details": "Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0589" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0001/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xwf3-49mf-8pq7/GHSA-xwf3-49mf-8pq7.json b/advisories/unreviewed/2024/01/GHSA-xwf3-49mf-8pq7/GHSA-xwf3-49mf-8pq7.json new file mode 100644 index 00000000000..8f69a40805b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xwf3-49mf-8pq7/GHSA-xwf3-49mf-8pq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwf3-49mf-8pq7", + "modified": "2024-01-31T15:30:20Z", + "published": "2024-01-31T15:30:20Z", + "aliases": [ + "CVE-2024-22291" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/browser-theme-color/wordpress-browser-theme-color-plugin-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xx9p-c4jq-4cff/GHSA-xx9p-c4jq-4cff.json b/advisories/unreviewed/2024/01/GHSA-xx9p-c4jq-4cff/GHSA-xx9p-c4jq-4cff.json index faa79124da6..611b0c18e00 100644 --- a/advisories/unreviewed/2024/01/GHSA-xx9p-c4jq-4cff/GHSA-xx9p-c4jq-4cff.json +++ b/advisories/unreviewed/2024/01/GHSA-xx9p-c4jq-4cff/GHSA-xx9p-c4jq-4cff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx9p-c4jq-4cff", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-31T15:30:19Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52337" ], "details": "An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z"