diff --git a/advisories/unreviewed/2024/03/GHSA-3j8r-26jq-jj7w/GHSA-3j8r-26jq-jj7w.json b/advisories/unreviewed/2024/03/GHSA-3j8r-26jq-jj7w/GHSA-3j8r-26jq-jj7w.json index 25ad6b355c6..8193b3df9d2 100644 --- a/advisories/unreviewed/2024/03/GHSA-3j8r-26jq-jj7w/GHSA-3j8r-26jq-jj7w.json +++ b/advisories/unreviewed/2024/03/GHSA-3j8r-26jq-jj7w/GHSA-3j8r-26jq-jj7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j8r-26jq-jj7w", - "modified": "2024-03-18T00:30:44Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-18T00:30:44Z", "aliases": [ "CVE-2024-23138" ], "details": "A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T00:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4jgg-53cv-7j3q/GHSA-4jgg-53cv-7j3q.json b/advisories/unreviewed/2024/03/GHSA-4jgg-53cv-7j3q/GHSA-4jgg-53cv-7j3q.json index e982e9ea40f..dabf47d71c6 100644 --- a/advisories/unreviewed/2024/03/GHSA-4jgg-53cv-7j3q/GHSA-4jgg-53cv-7j3q.json +++ b/advisories/unreviewed/2024/03/GHSA-4jgg-53cv-7j3q/GHSA-4jgg-53cv-7j3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jgg-53cv-7j3q", - "modified": "2024-03-21T03:36:46Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-21T03:36:46Z", "aliases": [ "CVE-2024-24110" ], "details": "SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:52:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6h99-8764-6j4p/GHSA-6h99-8764-6j4p.json b/advisories/unreviewed/2024/03/GHSA-6h99-8764-6j4p/GHSA-6h99-8764-6j4p.json index 58bfaef21b4..eb171f21708 100644 --- a/advisories/unreviewed/2024/03/GHSA-6h99-8764-6j4p/GHSA-6h99-8764-6j4p.json +++ b/advisories/unreviewed/2024/03/GHSA-6h99-8764-6j4p/GHSA-6h99-8764-6j4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6h99-8764-6j4p", - "modified": "2024-03-13T06:30:51Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-13T06:30:51Z", "aliases": [ "CVE-2024-27440" ], "details": "The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted certificate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T06:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cx37-ffjf-grmp/GHSA-cx37-ffjf-grmp.json b/advisories/unreviewed/2024/03/GHSA-cx37-ffjf-grmp/GHSA-cx37-ffjf-grmp.json index 39fd61dddb6..aec71383325 100644 --- a/advisories/unreviewed/2024/03/GHSA-cx37-ffjf-grmp/GHSA-cx37-ffjf-grmp.json +++ b/advisories/unreviewed/2024/03/GHSA-cx37-ffjf-grmp/GHSA-cx37-ffjf-grmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx37-ffjf-grmp", - "modified": "2024-03-21T06:33:01Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-21T06:33:01Z", "aliases": [ "CVE-2023-48903" ], "details": "Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter \"imgType\" via in uploadCarImages.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v33p-c978-w84h/GHSA-v33p-c978-w84h.json b/advisories/unreviewed/2024/03/GHSA-v33p-c978-w84h/GHSA-v33p-c978-w84h.json index da7b5afc1ea..7c8c0dacff6 100644 --- a/advisories/unreviewed/2024/03/GHSA-v33p-c978-w84h/GHSA-v33p-c978-w84h.json +++ b/advisories/unreviewed/2024/03/GHSA-v33p-c978-w84h/GHSA-v33p-c978-w84h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v33p-c978-w84h", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-13T21:31:02Z", "aliases": [ "CVE-2023-41504" ], "details": "SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T21:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v4m2-682h-94vh/GHSA-v4m2-682h-94vh.json b/advisories/unreviewed/2024/03/GHSA-v4m2-682h-94vh/GHSA-v4m2-682h-94vh.json index d9e2741f160..e84efc5a467 100644 --- a/advisories/unreviewed/2024/03/GHSA-v4m2-682h-94vh/GHSA-v4m2-682h-94vh.json +++ b/advisories/unreviewed/2024/03/GHSA-v4m2-682h-94vh/GHSA-v4m2-682h-94vh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4m2-682h-94vh", - "modified": "2024-03-12T21:31:00Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-12T21:31:00Z", "aliases": [ "CVE-2024-24092" ], "details": "SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T21:15:58Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xhjf-xjwg-rm34/GHSA-xhjf-xjwg-rm34.json b/advisories/unreviewed/2024/03/GHSA-xhjf-xjwg-rm34/GHSA-xhjf-xjwg-rm34.json index 2e0974c8e6c..37b6e450563 100644 --- a/advisories/unreviewed/2024/03/GHSA-xhjf-xjwg-rm34/GHSA-xhjf-xjwg-rm34.json +++ b/advisories/unreviewed/2024/03/GHSA-xhjf-xjwg-rm34/GHSA-xhjf-xjwg-rm34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhjf-xjwg-rm34", - "modified": "2024-03-14T18:30:30Z", + "modified": "2024-08-05T15:30:50Z", "published": "2024-03-14T18:30:30Z", "aliases": [ "CVE-2024-25139" ], "details": "In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T16:15:50Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json b/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json index 1683d4ae6f1..22bd1a2276b 100644 --- a/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json +++ b/advisories/unreviewed/2024/07/GHSA-r8h6-cwxj-rv5j/GHSA-r8h6-cwxj-rv5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8h6-cwxj-rv5j", - "modified": "2024-08-01T15:32:14Z", + "modified": "2024-08-05T15:30:51Z", "published": "2024-07-30T00:34:24Z", "aliases": [ "CVE-2024-3219" @@ -28,31 +28,15 @@ }, { "type": "WEB", - "url": "https://github.com/python/cpython/commit/06fa244666ec6335a3b9bf2367e31b42b9a89b20" + "url": "https://github.com/python/cpython/commit/f071f01b7b7e19d7d6b3a4b0ec62f820ecb14660" }, { "type": "WEB", - "url": "https://github.com/python/cpython/commit/0b65c8bf5367625673eafb92f85046a1b31259f2" + "url": "https://github.com/python/cpython/commit/e319f774f9e766a2b92949444a2d46081df3363a" }, { "type": "WEB", - "url": "https://github.com/python/cpython/commit/220e31adeaaa8436c9ff234cba1398bc49e2bb6c" - }, - { - "type": "WEB", - "url": "https://github.com/python/cpython/commit/2621a8a40ba4b2c68ca564671b7daa5da80a4508" - }, - { - "type": "WEB", - "url": "https://github.com/python/cpython/commit/5df322e91a40909e6904bbdbc0c3a6b6a9eead39" - }, - { - "type": "WEB", - "url": "https://github.com/python/cpython/commit/5f90abaa786f994db3907fc31e2ee00ea2cf0929" - }, - { - "type": "WEB", - "url": "https://github.com/python/cpython/commit/b252317956b7fc035bb3774ef6a177e227f9fc54" + "url": "https://github.com/python/cpython/commit/c5655aa6ad120d2ed7f255bebd6e8b71a9c07dde" }, { "type": "WEB", @@ -60,7 +44,39 @@ }, { "type": "WEB", - "url": "https://github.com/python/cpython/commit/f071f01b7b7e19d7d6b3a4b0ec62f820ecb14660" + "url": "https://github.com/python/cpython/commit/b252317956b7fc035bb3774ef6a177e227f9fc54" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/5f90abaa786f994db3907fc31e2ee00ea2cf0929" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/5df322e91a40909e6904bbdbc0c3a6b6a9eead39" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/3f5d9d12c74787fbf3f5891835c85cc15526c86d" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/31302f5fc24eecd693f0c8aaba7c2840b09b594d" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/2621a8a40ba4b2c68ca564671b7daa5da80a4508" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/220e31adeaaa8436c9ff234cba1398bc49e2bb6c" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/0b65c8bf5367625673eafb92f85046a1b31259f2" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/06fa244666ec6335a3b9bf2367e31b42b9a89b20" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json b/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json new file mode 100644 index 00000000000..02366ac8966 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-296c-8m99-q77p/GHSA-296c-8m99-q77p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-296c-8m99-q77p", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-21481" + ], + "details": "Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21481" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json b/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json new file mode 100644 index 00000000000..485fccc2f21 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rv8-p95w-9w54", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33021" + ], + "details": "Memory corruption while processing IOCTL call to set metainfo.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33021" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2wc7-jrqh-277g/GHSA-2wc7-jrqh-277g.json b/advisories/unreviewed/2024/08/GHSA-2wc7-jrqh-277g/GHSA-2wc7-jrqh-277g.json new file mode 100644 index 00000000000..6399a48e4a6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2wc7-jrqh-277g/GHSA-2wc7-jrqh-277g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wc7-jrqh-277g", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23352" + ], + "details": "Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23352" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2ww8-pj73-gx5x/GHSA-2ww8-pj73-gx5x.json b/advisories/unreviewed/2024/08/GHSA-2ww8-pj73-gx5x/GHSA-2ww8-pj73-gx5x.json new file mode 100644 index 00000000000..c36f511f252 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2ww8-pj73-gx5x/GHSA-2ww8-pj73-gx5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ww8-pj73-gx5x", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-21467" + ], + "details": "Information disclosure while handling beacon probe frame during scan entry generation in client side.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21467" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json b/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json new file mode 100644 index 00000000000..3a01c1f29c5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36w4-5gpx-jw2f", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33025" + ], + "details": "Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33025" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-624f-82hj-x6pc/GHSA-624f-82hj-x6pc.json b/advisories/unreviewed/2024/08/GHSA-624f-82hj-x6pc/GHSA-624f-82hj-x6pc.json new file mode 100644 index 00000000000..8a9b6c65358 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-624f-82hj-x6pc/GHSA-624f-82hj-x6pc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-624f-82hj-x6pc", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23383" + ], + "details": "Memory corruption when kernel driver attempts to trigger hardware fences.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23383" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json b/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json new file mode 100644 index 00000000000..42c31b493fc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6cvr-wmr3-636f/GHSA-6cvr-wmr3-636f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cvr-wmr3-636f", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23353" + ], + "details": "Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23353" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json b/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json new file mode 100644 index 00000000000..c1ca6a13f69 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-727j-8989-82f7", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33015" + ], + "details": "Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33015" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-72x9-mq39-cp23/GHSA-72x9-mq39-cp23.json b/advisories/unreviewed/2024/08/GHSA-72x9-mq39-cp23/GHSA-72x9-mq39-cp23.json new file mode 100644 index 00000000000..b3d7d58619c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-72x9-mq39-cp23/GHSA-72x9-mq39-cp23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72x9-mq39-cp23", + "modified": "2024-08-05T15:30:52Z", + "published": "2024-08-05T15:30:52Z", + "aliases": [ + "CVE-2024-7395" + ], + "details": "An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7395" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/de/en-multiple-vulnerabilities-in-korenix-jetport" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json new file mode 100644 index 00000000000..2db39b8ea6e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c7g-wccp-rrhj", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-7409" + ], + "details": "A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7409" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7409" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2302487" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-662" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7mr2-xj43-vfv8/GHSA-7mr2-xj43-vfv8.json b/advisories/unreviewed/2024/08/GHSA-7mr2-xj43-vfv8/GHSA-7mr2-xj43-vfv8.json new file mode 100644 index 00000000000..62ac4975eb9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7mr2-xj43-vfv8/GHSA-7mr2-xj43-vfv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mr2-xj43-vfv8", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33028" + ], + "details": "Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33028" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7vjh-vmrf-m55g/GHSA-7vjh-vmrf-m55g.json b/advisories/unreviewed/2024/08/GHSA-7vjh-vmrf-m55g/GHSA-7vjh-vmrf-m55g.json index 75154d7d67e..0840d2dee32 100644 --- a/advisories/unreviewed/2024/08/GHSA-7vjh-vmrf-m55g/GHSA-7vjh-vmrf-m55g.json +++ b/advisories/unreviewed/2024/08/GHSA-7vjh-vmrf-m55g/GHSA-7vjh-vmrf-m55g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vjh-vmrf-m55g", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-05T15:30:51Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-6270" ], "details": "The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T06:16:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-87vx-4jgq-hwwm/GHSA-87vx-4jgq-hwwm.json b/advisories/unreviewed/2024/08/GHSA-87vx-4jgq-hwwm/GHSA-87vx-4jgq-hwwm.json new file mode 100644 index 00000000000..ce59d024cd9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-87vx-4jgq-hwwm/GHSA-87vx-4jgq-hwwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87vx-4jgq-hwwm", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33024" + ], + "details": "Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33024" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9cp9-mwf2-v22f/GHSA-9cp9-mwf2-v22f.json b/advisories/unreviewed/2024/08/GHSA-9cp9-mwf2-v22f/GHSA-9cp9-mwf2-v22f.json new file mode 100644 index 00000000000..84507b3b0fb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9cp9-mwf2-v22f/GHSA-9cp9-mwf2-v22f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cp9-mwf2-v22f", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33023" + ], + "details": "Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33023" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9wvr-rr6g-49mj/GHSA-9wvr-rr6g-49mj.json b/advisories/unreviewed/2024/08/GHSA-9wvr-rr6g-49mj/GHSA-9wvr-rr6g-49mj.json new file mode 100644 index 00000000000..a4ba875995b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9wvr-rr6g-49mj/GHSA-9wvr-rr6g-49mj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wvr-rr6g-49mj", + "modified": "2024-08-05T15:30:51Z", + "published": "2024-08-05T15:30:51Z", + "aliases": [ + "CVE-2024-6865" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6865" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f3f9-p99p-62gj/GHSA-f3f9-p99p-62gj.json b/advisories/unreviewed/2024/08/GHSA-f3f9-p99p-62gj/GHSA-f3f9-p99p-62gj.json new file mode 100644 index 00000000000..50516e24901 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f3f9-p99p-62gj/GHSA-f3f9-p99p-62gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3f9-p99p-62gj", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23355" + ], + "details": "Memory corruption when keymaster operation imports a shared key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23355" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json b/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json new file mode 100644 index 00000000000..71ac22992b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4wh-w575-w6c3", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33026" + ], + "details": "Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33026" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fpfv-qqrp-543c/GHSA-fpfv-qqrp-543c.json b/advisories/unreviewed/2024/08/GHSA-fpfv-qqrp-543c/GHSA-fpfv-qqrp-543c.json new file mode 100644 index 00000000000..4d396bdf835 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fpfv-qqrp-543c/GHSA-fpfv-qqrp-543c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpfv-qqrp-543c", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33010" + ], + "details": "Transient DOS while parsing fragments of MBSSID IE from beacon frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33010" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json b/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json new file mode 100644 index 00000000000..146dbfc2916 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gf7m-c4p9-5gvh/GHSA-gf7m-c4p9-5gvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf7m-c4p9-5gvh", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-21459" + ], + "details": "Information disclosure while handling beacon or probe response frame in STA.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21459" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json b/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json new file mode 100644 index 00000000000..87a5952bff8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf35-v6mp-xvp9", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33018" + ], + "details": "Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33018" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jfgv-r9x2-7mhr/GHSA-jfgv-r9x2-7mhr.json b/advisories/unreviewed/2024/08/GHSA-jfgv-r9x2-7mhr/GHSA-jfgv-r9x2-7mhr.json new file mode 100644 index 00000000000..433fccccd36 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jfgv-r9x2-7mhr/GHSA-jfgv-r9x2-7mhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfgv-r9x2-7mhr", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23350" + ], + "details": "Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23350" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jjhp-92wf-mgrg/GHSA-jjhp-92wf-mgrg.json b/advisories/unreviewed/2024/08/GHSA-jjhp-92wf-mgrg/GHSA-jjhp-92wf-mgrg.json new file mode 100644 index 00000000000..f91d07df5b9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jjhp-92wf-mgrg/GHSA-jjhp-92wf-mgrg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjhp-92wf-mgrg", + "modified": "2024-08-05T15:30:52Z", + "published": "2024-08-05T15:30:52Z", + "aliases": [ + "CVE-2024-7396" + ], + "details": "Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7396" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/de/en-multiple-vulnerabilities-in-korenix-jetport" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m233-53wq-fv3v/GHSA-m233-53wq-fv3v.json b/advisories/unreviewed/2024/08/GHSA-m233-53wq-fv3v/GHSA-m233-53wq-fv3v.json new file mode 100644 index 00000000000..5d59f2fceee --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m233-53wq-fv3v/GHSA-m233-53wq-fv3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m233-53wq-fv3v", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33022" + ], + "details": "Memory corruption while allocating memory in HGSL driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33022" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mr9c-hfrq-mwcq/GHSA-mr9c-hfrq-mwcq.json b/advisories/unreviewed/2024/08/GHSA-mr9c-hfrq-mwcq/GHSA-mr9c-hfrq-mwcq.json new file mode 100644 index 00000000000..e58a3a4bb4d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mr9c-hfrq-mwcq/GHSA-mr9c-hfrq-mwcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr9c-hfrq-mwcq", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23382" + ], + "details": "Memory corruption while processing graphics kernel driver request to create DMA fence.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23382" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pf2q-6c5m-pvcj/GHSA-pf2q-6c5m-pvcj.json b/advisories/unreviewed/2024/08/GHSA-pf2q-6c5m-pvcj/GHSA-pf2q-6c5m-pvcj.json new file mode 100644 index 00000000000..892c7daa1f0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pf2q-6c5m-pvcj/GHSA-pf2q-6c5m-pvcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf2q-6c5m-pvcj", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23357" + ], + "details": "Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23357" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json b/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json new file mode 100644 index 00000000000..9903f3b3c5b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv26-xp92-c6p8", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33019" + ], + "details": "Transient DOS while parsing the received TID-to-link mapping action frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33019" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qjxr-j6gg-gh78/GHSA-qjxr-j6gg-gh78.json b/advisories/unreviewed/2024/08/GHSA-qjxr-j6gg-gh78/GHSA-qjxr-j6gg-gh78.json new file mode 100644 index 00000000000..1f92035b74d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qjxr-j6gg-gh78/GHSA-qjxr-j6gg-gh78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjxr-j6gg-gh78", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33012" + ], + "details": "Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33012" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qvm8-hj6f-mrgr/GHSA-qvm8-hj6f-mrgr.json b/advisories/unreviewed/2024/08/GHSA-qvm8-hj6f-mrgr/GHSA-qvm8-hj6f-mrgr.json new file mode 100644 index 00000000000..45e15a97103 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qvm8-hj6f-mrgr/GHSA-qvm8-hj6f-mrgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvm8-hj6f-mrgr", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33027" + ], + "details": "Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33027" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rg7p-8pgf-fcgw/GHSA-rg7p-8pgf-fcgw.json b/advisories/unreviewed/2024/08/GHSA-rg7p-8pgf-fcgw/GHSA-rg7p-8pgf-fcgw.json index c514405094f..ceefcf42f17 100644 --- a/advisories/unreviewed/2024/08/GHSA-rg7p-8pgf-fcgw/GHSA-rg7p-8pgf-fcgw.json +++ b/advisories/unreviewed/2024/08/GHSA-rg7p-8pgf-fcgw/GHSA-rg7p-8pgf-fcgw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rg7p-8pgf-fcgw", - "modified": "2024-08-03T06:30:34Z", + "modified": "2024-08-05T15:30:51Z", "published": "2024-08-03T06:30:34Z", "aliases": [ "CVE-2024-6390" ], "details": "The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-03T06:16:29Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json b/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json new file mode 100644 index 00000000000..55d511b4d67 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rqmr-f8r9-69wq/GHSA-rqmr-f8r9-69wq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqmr-f8r9-69wq", + "modified": "2024-08-05T15:30:52Z", + "published": "2024-08-05T15:30:52Z", + "aliases": [ + "CVE-2024-7383" + ], + "details": "A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7383" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7383" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2302865" + }, + { + "type": "WEB", + "url": "https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/message/LHR3BW6RJ7K4BJBQIYV3GTZLSY27VZO2" + }, + { + "type": "WEB", + "url": "https://lists.libguestfs.org/archives/list/guestfs@lists.libguestfs.org/thread/ENZY4LHLARA3N4C3JUNLPYUCXHFO7BWQ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rv78-75q2-7333/GHSA-rv78-75q2-7333.json b/advisories/unreviewed/2024/08/GHSA-rv78-75q2-7333/GHSA-rv78-75q2-7333.json new file mode 100644 index 00000000000..78ed63c6942 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rv78-75q2-7333/GHSA-rv78-75q2-7333.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv78-75q2-7333", + "modified": "2024-08-05T15:30:52Z", + "published": "2024-08-05T15:30:52Z", + "aliases": [ + "CVE-2024-7397" + ], + "details": "Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7397" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/de/en-multiple-vulnerabilities-in-korenix-jetport" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rw4p-gv82-cmrw/GHSA-rw4p-gv82-cmrw.json b/advisories/unreviewed/2024/08/GHSA-rw4p-gv82-cmrw/GHSA-rw4p-gv82-cmrw.json new file mode 100644 index 00000000000..c15f6a55cf1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rw4p-gv82-cmrw/GHSA-rw4p-gv82-cmrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw4p-gv82-cmrw", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33013" + ], + "details": "Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33013" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json b/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json new file mode 100644 index 00000000000..87f4798fe37 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2v8-fj72-c4fm", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33014" + ], + "details": "Transient DOS while parsing ESP IE from beacon/probe response frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33014" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v3j8-73vp-j87v/GHSA-v3j8-73vp-j87v.json b/advisories/unreviewed/2024/08/GHSA-v3j8-73vp-j87v/GHSA-v3j8-73vp-j87v.json new file mode 100644 index 00000000000..e83dad7e242 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v3j8-73vp-j87v/GHSA-v3j8-73vp-j87v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3j8-73vp-j87v", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23384" + ], + "details": "Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23384" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v7wj-7f24-qm89/GHSA-v7wj-7f24-qm89.json b/advisories/unreviewed/2024/08/GHSA-v7wj-7f24-qm89/GHSA-v7wj-7f24-qm89.json new file mode 100644 index 00000000000..c9d2bd888f2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v7wj-7f24-qm89/GHSA-v7wj-7f24-qm89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7wj-7f24-qm89", + "modified": "2024-08-05T15:30:54Z", + "published": "2024-08-05T15:30:54Z", + "aliases": [ + "CVE-2024-33034" + ], + "details": "Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33034" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vvpw-grj7-vx3c/GHSA-vvpw-grj7-vx3c.json b/advisories/unreviewed/2024/08/GHSA-vvpw-grj7-vx3c/GHSA-vvpw-grj7-vx3c.json new file mode 100644 index 00000000000..4d5546f6f58 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vvpw-grj7-vx3c/GHSA-vvpw-grj7-vx3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvpw-grj7-vx3c", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23356" + ], + "details": "Memory corruption during session sign renewal request calls in HLOS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23356" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w6mm-86qp-2r3q/GHSA-w6mm-86qp-2r3q.json b/advisories/unreviewed/2024/08/GHSA-w6mm-86qp-2r3q/GHSA-w6mm-86qp-2r3q.json new file mode 100644 index 00000000000..19b5e76277d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w6mm-86qp-2r3q/GHSA-w6mm-86qp-2r3q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6mm-86qp-2r3q", + "modified": "2024-08-05T15:30:51Z", + "published": "2024-08-05T15:30:51Z", + "aliases": [ + "CVE-2024-6472" + ], + "details": "Certificate Validation user interface in LibreOffice allows potential vulnerability.\n\n\n\n\nSigned macros are scripts that have been digitally signed by the \ndeveloper using a cryptographic signature. When a document with a signed\n macro is opened a warning is displayed by LibreOffice before the macro \nis executed.\n\nPreviously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.\n\n\nThis issue affects LibreOffice: from 24.2 before 24.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6472" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-6472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json b/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json index da687c83f2a..7ab39b64c20 100644 --- a/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json +++ b/advisories/unreviewed/2024/08/GHSA-w8pg-hrp7-6jch/GHSA-w8pg-hrp7-6jch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8pg-hrp7-6jch", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-05T15:30:51Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-6498" diff --git a/advisories/unreviewed/2024/08/GHSA-x9vg-qjpv-3c38/GHSA-x9vg-qjpv-3c38.json b/advisories/unreviewed/2024/08/GHSA-x9vg-qjpv-3c38/GHSA-x9vg-qjpv-3c38.json new file mode 100644 index 00000000000..37919772278 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x9vg-qjpv-3c38/GHSA-x9vg-qjpv-3c38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9vg-qjpv-3c38", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-23381" + ], + "details": "Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23381" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xh73-ww8f-499f/GHSA-xh73-ww8f-499f.json b/advisories/unreviewed/2024/08/GHSA-xh73-ww8f-499f/GHSA-xh73-ww8f-499f.json new file mode 100644 index 00000000000..94463ff5e74 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xh73-ww8f-499f/GHSA-xh73-ww8f-499f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh73-ww8f-499f", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-21479" + ], + "details": "Transient DOS during music playback of ALAC content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21479" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xhmx-jv3j-5wf8/GHSA-xhmx-jv3j-5wf8.json b/advisories/unreviewed/2024/08/GHSA-xhmx-jv3j-5wf8/GHSA-xhmx-jv3j-5wf8.json new file mode 100644 index 00000000000..b40adbe3fa7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xhmx-jv3j-5wf8/GHSA-xhmx-jv3j-5wf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhmx-jv3j-5wf8", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33011" + ], + "details": "Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33011" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json b/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json new file mode 100644 index 00000000000..0bac43231f5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq4h-4mpj-q5jr", + "modified": "2024-08-05T15:30:53Z", + "published": "2024-08-05T15:30:53Z", + "aliases": [ + "CVE-2024-33020" + ], + "details": "Transient DOS while processing TID-to-link mapping IE elements.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33020" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T15:15:51Z" + } +} \ No newline at end of file