diff --git a/advisories/unreviewed/2024/03/GHSA-7884-jqrx-4h3v/GHSA-7884-jqrx-4h3v.json b/advisories/unreviewed/2024/03/GHSA-7884-jqrx-4h3v/GHSA-7884-jqrx-4h3v.json index b7a249940d4..1e8c3a15f4a 100644 --- a/advisories/unreviewed/2024/03/GHSA-7884-jqrx-4h3v/GHSA-7884-jqrx-4h3v.json +++ b/advisories/unreviewed/2024/03/GHSA-7884-jqrx-4h3v/GHSA-7884-jqrx-4h3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7884-jqrx-4h3v", - "modified": "2024-03-11T21:31:25Z", + "modified": "2024-11-23T03:31:56Z", "published": "2024-03-11T21:31:25Z", "aliases": [ "CVE-2024-25991" ], "details": "In acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-29jj-mp7x-cw58/GHSA-29jj-mp7x-cw58.json b/advisories/unreviewed/2024/05/GHSA-29jj-mp7x-cw58/GHSA-29jj-mp7x-cw58.json index ca32e76a3fe..d4fefe87622 100644 --- a/advisories/unreviewed/2024/05/GHSA-29jj-mp7x-cw58/GHSA-29jj-mp7x-cw58.json +++ b/advisories/unreviewed/2024/05/GHSA-29jj-mp7x-cw58/GHSA-29jj-mp7x-cw58.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-3hpw-jgp9-h7fc/GHSA-3hpw-jgp9-h7fc.json b/advisories/unreviewed/2024/05/GHSA-3hpw-jgp9-h7fc/GHSA-3hpw-jgp9-h7fc.json index 4bb22923533..a07c2419efa 100644 --- a/advisories/unreviewed/2024/05/GHSA-3hpw-jgp9-h7fc/GHSA-3hpw-jgp9-h7fc.json +++ b/advisories/unreviewed/2024/05/GHSA-3hpw-jgp9-h7fc/GHSA-3hpw-jgp9-h7fc.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-3p6h-hqfc-f464/GHSA-3p6h-hqfc-f464.json b/advisories/unreviewed/2024/05/GHSA-3p6h-hqfc-f464/GHSA-3p6h-hqfc-f464.json index ded41b0fea1..bad5a78e38e 100644 --- a/advisories/unreviewed/2024/05/GHSA-3p6h-hqfc-f464/GHSA-3p6h-hqfc-f464.json +++ b/advisories/unreviewed/2024/05/GHSA-3p6h-hqfc-f464/GHSA-3p6h-hqfc-f464.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-42wm-h4m7-x7g3/GHSA-42wm-h4m7-x7g3.json b/advisories/unreviewed/2024/05/GHSA-42wm-h4m7-x7g3/GHSA-42wm-h4m7-x7g3.json index fc2719b7d66..00323a163a6 100644 --- a/advisories/unreviewed/2024/05/GHSA-42wm-h4m7-x7g3/GHSA-42wm-h4m7-x7g3.json +++ b/advisories/unreviewed/2024/05/GHSA-42wm-h4m7-x7g3/GHSA-42wm-h4m7-x7g3.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5ph8-jx5j-m33j/GHSA-5ph8-jx5j-m33j.json b/advisories/unreviewed/2024/05/GHSA-5ph8-jx5j-m33j/GHSA-5ph8-jx5j-m33j.json index 4cd80cef848..6fd8499b012 100644 --- a/advisories/unreviewed/2024/05/GHSA-5ph8-jx5j-m33j/GHSA-5ph8-jx5j-m33j.json +++ b/advisories/unreviewed/2024/05/GHSA-5ph8-jx5j-m33j/GHSA-5ph8-jx5j-m33j.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-72x4-66p7-wfjr/GHSA-72x4-66p7-wfjr.json b/advisories/unreviewed/2024/05/GHSA-72x4-66p7-wfjr/GHSA-72x4-66p7-wfjr.json index 723baae8ee9..23046a83859 100644 --- a/advisories/unreviewed/2024/05/GHSA-72x4-66p7-wfjr/GHSA-72x4-66p7-wfjr.json +++ b/advisories/unreviewed/2024/05/GHSA-72x4-66p7-wfjr/GHSA-72x4-66p7-wfjr.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7p55-f535-v7g3/GHSA-7p55-f535-v7g3.json b/advisories/unreviewed/2024/05/GHSA-7p55-f535-v7g3/GHSA-7p55-f535-v7g3.json index 04ce7648584..a5c29175e7a 100644 --- a/advisories/unreviewed/2024/05/GHSA-7p55-f535-v7g3/GHSA-7p55-f535-v7g3.json +++ b/advisories/unreviewed/2024/05/GHSA-7p55-f535-v7g3/GHSA-7p55-f535-v7g3.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-7pqw-f6rf-898v/GHSA-7pqw-f6rf-898v.json b/advisories/unreviewed/2024/05/GHSA-7pqw-f6rf-898v/GHSA-7pqw-f6rf-898v.json index 8463679f50c..61be2851d0b 100644 --- a/advisories/unreviewed/2024/05/GHSA-7pqw-f6rf-898v/GHSA-7pqw-f6rf-898v.json +++ b/advisories/unreviewed/2024/05/GHSA-7pqw-f6rf-898v/GHSA-7pqw-f6rf-898v.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-96m9-cfhw-7gq3/GHSA-96m9-cfhw-7gq3.json b/advisories/unreviewed/2024/05/GHSA-96m9-cfhw-7gq3/GHSA-96m9-cfhw-7gq3.json index 13d53e22e7d..7462e906714 100644 --- a/advisories/unreviewed/2024/05/GHSA-96m9-cfhw-7gq3/GHSA-96m9-cfhw-7gq3.json +++ b/advisories/unreviewed/2024/05/GHSA-96m9-cfhw-7gq3/GHSA-96m9-cfhw-7gq3.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9gh9-p2mx-hvv8/GHSA-9gh9-p2mx-hvv8.json b/advisories/unreviewed/2024/05/GHSA-9gh9-p2mx-hvv8/GHSA-9gh9-p2mx-hvv8.json index 388952bd573..5b6ad29e8a9 100644 --- a/advisories/unreviewed/2024/05/GHSA-9gh9-p2mx-hvv8/GHSA-9gh9-p2mx-hvv8.json +++ b/advisories/unreviewed/2024/05/GHSA-9gh9-p2mx-hvv8/GHSA-9gh9-p2mx-hvv8.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json b/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json index d454287181f..4208cb4f8d4 100644 --- a/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json +++ b/advisories/unreviewed/2024/08/GHSA-73q4-cgh7-2r7w/GHSA-73q4-cgh7-2r7w.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-24hh-m38m-8727/GHSA-24hh-m38m-8727.json b/advisories/unreviewed/2024/11/GHSA-24hh-m38m-8727/GHSA-24hh-m38m-8727.json index 25fa521f19a..16212e080a2 100644 --- a/advisories/unreviewed/2024/11/GHSA-24hh-m38m-8727/GHSA-24hh-m38m-8727.json +++ b/advisories/unreviewed/2024/11/GHSA-24hh-m38m-8727/GHSA-24hh-m38m-8727.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json b/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json index e501a8652d7..55d61be356a 100644 --- a/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json +++ b/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json b/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json index 0b65c023e83..a346a6e0862 100644 --- a/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json +++ b/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27r4-945x-jq67", - "modified": "2024-11-20T00:32:14Z", + "modified": "2024-11-23T03:31:57Z", "published": "2024-11-20T00:32:14Z", "aliases": [ "CVE-2018-9412" ], "details": "In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T22:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json b/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json index 5206cf7ebb3..09c30f351a4 100644 --- a/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json +++ b/advisories/unreviewed/2024/11/GHSA-2vrj-cvff-5p56/GHSA-2vrj-cvff-5p56.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vrj-cvff-5p56", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-23T03:31:57Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53069" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: scm: fix a NULL-pointer dereference\n\nSome SCM calls can be invoked with __scm being NULL (the driver may not\nhave been and will not be probed as there's no SCM entry in device-tree).\nMake sure we don't dereference a NULL pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json b/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json index af5492adfdc..02dca039eb0 100644 --- a/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json +++ b/advisories/unreviewed/2024/11/GHSA-3gr8-4rjx-crp8/GHSA-3gr8-4rjx-crp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3gr8-4rjx-crp8", - "modified": "2024-11-20T15:30:52Z", + "modified": "2024-11-23T03:31:58Z", "published": "2024-11-20T15:30:52Z", "aliases": [ "CVE-2024-51208" ], "details": "File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script via the Image Upload Mechanism parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T15:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3hqr-6848-jx5j/GHSA-3hqr-6848-jx5j.json b/advisories/unreviewed/2024/11/GHSA-3hqr-6848-jx5j/GHSA-3hqr-6848-jx5j.json new file mode 100644 index 00000000000..8efdb2ef185 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3hqr-6848-jx5j/GHSA-3hqr-6848-jx5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hqr-6848-jx5j", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7228" + ], + "details": "Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-22806.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7228" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-999" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3mqp-f6x6-jj6x/GHSA-3mqp-f6x6-jj6x.json b/advisories/unreviewed/2024/11/GHSA-3mqp-f6x6-jj6x/GHSA-3mqp-f6x6-jj6x.json new file mode 100644 index 00000000000..daa84d601d9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3mqp-f6x6-jj6x/GHSA-3mqp-f6x6-jj6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mqp-f6x6-jj6x", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7233" + ], + "details": "Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23731.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7233" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-42vv-qrvv-www9/GHSA-42vv-qrvv-www9.json b/advisories/unreviewed/2024/11/GHSA-42vv-qrvv-www9/GHSA-42vv-qrvv-www9.json new file mode 100644 index 00000000000..26ef75fa21d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-42vv-qrvv-www9/GHSA-42vv-qrvv-www9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42vv-qrvv-www9", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9246" + ], + "details": "Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Annotation objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24135.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9246" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1299" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4jrj-98h6-235v/GHSA-4jrj-98h6-235v.json b/advisories/unreviewed/2024/11/GHSA-4jrj-98h6-235v/GHSA-4jrj-98h6-235v.json new file mode 100644 index 00000000000..54945b692ab --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4jrj-98h6-235v/GHSA-4jrj-98h6-235v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jrj-98h6-235v", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7235" + ], + "details": "AVG AntiVirus Free Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.\n. Was ZDI-CAN-22803.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7235" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4xc4-g76g-whxg/GHSA-4xc4-g76g-whxg.json b/advisories/unreviewed/2024/11/GHSA-4xc4-g76g-whxg/GHSA-4xc4-g76g-whxg.json new file mode 100644 index 00000000000..08f0a0273e0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4xc4-g76g-whxg/GHSA-4xc4-g76g-whxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xc4-g76g-whxg", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7241" + ], + "details": "Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the PSANHost service. By creating a junction, an attacker can abuse the service to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23375.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7241" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-57p8-mp3h-7xm4/GHSA-57p8-mp3h-7xm4.json b/advisories/unreviewed/2024/11/GHSA-57p8-mp3h-7xm4/GHSA-57p8-mp3h-7xm4.json new file mode 100644 index 00000000000..d8eb3cc3276 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-57p8-mp3h-7xm4/GHSA-57p8-mp3h-7xm4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57p8-mp3h-7xm4", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-6818" + ], + "details": "IrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23217.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6818" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-970" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json b/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json index b1bbed61186..8d9e938618e 100644 --- a/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json +++ b/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5v6c-5897-pqv6", - "modified": "2024-11-19T21:31:33Z", + "modified": "2024-11-23T03:31:57Z", "published": "2024-11-19T21:31:33Z", "aliases": [ "CVE-2018-9410" ], "details": "In analyzeAxes of FontUtils.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T21:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5v72-g8c6-fhcj/GHSA-5v72-g8c6-fhcj.json b/advisories/unreviewed/2024/11/GHSA-5v72-g8c6-fhcj/GHSA-5v72-g8c6-fhcj.json new file mode 100644 index 00000000000..5f226f03f7a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5v72-g8c6-fhcj/GHSA-5v72-g8c6-fhcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v72-g8c6-fhcj", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7242" + ], + "details": "Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the PSANHost executable. By creating a junction, an attacker can abuse the service to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23402.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7242" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5v77-c82m-jvhp/GHSA-5v77-c82m-jvhp.json b/advisories/unreviewed/2024/11/GHSA-5v77-c82m-jvhp/GHSA-5v77-c82m-jvhp.json new file mode 100644 index 00000000000..2f895f7cbca --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5v77-c82m-jvhp/GHSA-5v77-c82m-jvhp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v77-c82m-jvhp", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7244" + ], + "details": "Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the VPN process. The process does not restrict DLL search to trusted paths, which can result in the loading of a malicious DLL. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23428.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7244" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5vh4-cr62-86w3/GHSA-5vh4-cr62-86w3.json b/advisories/unreviewed/2024/11/GHSA-5vh4-cr62-86w3/GHSA-5vh4-cr62-86w3.json new file mode 100644 index 00000000000..3cba9d35822 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5vh4-cr62-86w3/GHSA-5vh4-cr62-86w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vh4-cr62-86w3", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-7511" + ], + "details": "Trimble SketchUp Pro SKP File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trimble SketchUp Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PSD files embedded in SKP files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-23000.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7511" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5x8w-vv68-5w4w/GHSA-5x8w-vv68-5w4w.json b/advisories/unreviewed/2024/11/GHSA-5x8w-vv68-5w4w/GHSA-5x8w-vv68-5w4w.json new file mode 100644 index 00000000000..f3d107608d6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5x8w-vv68-5w4w/GHSA-5x8w-vv68-5w4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x8w-vv68-5w4w", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8356" + ], + "details": "Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the firmware update process of the VIP microcontroller. The process does not properly verify authenticity of the supplied firmware image before programming it into internal memory. An attacker can leverage this vulnerability to escalate privileges execute arbitrary code in the context of the VIP MCU. Was ZDI-CAN-23758.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8356" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-626w-372f-948x/GHSA-626w-372f-948x.json b/advisories/unreviewed/2024/11/GHSA-626w-372f-948x/GHSA-626w-372f-948x.json new file mode 100644 index 00000000000..42957cce167 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-626w-372f-948x/GHSA-626w-372f-948x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-626w-372f-948x", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-0138" + ], + "details": "NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0138" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5595" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-23T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json b/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json new file mode 100644 index 00000000000..6a0f7314a14 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-655v-g44j-4fc7/GHSA-655v-g44j-4fc7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-655v-g44j-4fc7", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-41761" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41761" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175947" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-23T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json b/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json new file mode 100644 index 00000000000..b8d7ea00878 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6f9c-q4ff-c85g/GHSA-6f9c-q4ff-c85g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f9c-q4ff-c85g", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-11586" + ], + "details": "Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11586" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/pulseaudio/+bug/2078822" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2024-11586" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-23T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6hwj-w495-9pvp/GHSA-6hwj-w495-9pvp.json b/advisories/unreviewed/2024/11/GHSA-6hwj-w495-9pvp/GHSA-6hwj-w495-9pvp.json new file mode 100644 index 00000000000..cf26d6fe699 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6hwj-w495-9pvp/GHSA-6hwj-w495-9pvp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hwj-w495-9pvp", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8355" + ], + "details": "Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment system. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the DeviceManager. When parsing the iAP Serial number, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20112.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8355" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1208" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6jhm-j4gf-hvjx/GHSA-6jhm-j4gf-hvjx.json b/advisories/unreviewed/2024/11/GHSA-6jhm-j4gf-hvjx/GHSA-6jhm-j4gf-hvjx.json new file mode 100644 index 00000000000..6de74d98e10 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6jhm-j4gf-hvjx/GHSA-6jhm-j4gf-hvjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jhm-j4gf-hvjx", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7232" + ], + "details": "Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22963.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7232" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6wqp-v957-w63g/GHSA-6wqp-v957-w63g.json b/advisories/unreviewed/2024/11/GHSA-6wqp-v957-w63g/GHSA-6wqp-v957-w63g.json new file mode 100644 index 00000000000..caa3cb59c9c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6wqp-v957-w63g/GHSA-6wqp-v957-w63g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wqp-v957-w63g", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7510" + ], + "details": "Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19631.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7510" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json b/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json new file mode 100644 index 00000000000..5cc431cce17 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-77mr-3x8w-8f7f/GHSA-77mr-3x8w-8f7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77mr-3x8w-8f7f", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7508" + ], + "details": "Trimble SketchUp Viewer SKP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19575.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7508" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1054" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-78hr-h49h-8p68/GHSA-78hr-h49h-8p68.json b/advisories/unreviewed/2024/11/GHSA-78hr-h49h-8p68/GHSA-78hr-h49h-8p68.json new file mode 100644 index 00000000000..b3e700c5683 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-78hr-h49h-8p68/GHSA-78hr-h49h-8p68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78hr-h49h-8p68", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9112" + ], + "details": "FastStone Image Viewer PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25102.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9112" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1273" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7j59-4397-6j52/GHSA-7j59-4397-6j52.json b/advisories/unreviewed/2024/11/GHSA-7j59-4397-6j52/GHSA-7j59-4397-6j52.json new file mode 100644 index 00000000000..81e5c83f8a4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7j59-4397-6j52/GHSA-7j59-4397-6j52.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j59-4397-6j52", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7237" + ], + "details": "AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to delete a folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22960.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7237" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7vhx-c246-8ghc/GHSA-7vhx-c246-8ghc.json b/advisories/unreviewed/2024/11/GHSA-7vhx-c246-8ghc/GHSA-7vhx-c246-8ghc.json new file mode 100644 index 00000000000..c173c0556e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7vhx-c246-8ghc/GHSA-7vhx-c246-8ghc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vhx-c246-8ghc", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9255" + ], + "details": "Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25174.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9255" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9j99-7q7q-cj5v/GHSA-9j99-7q7q-cj5v.json b/advisories/unreviewed/2024/11/GHSA-9j99-7q7q-cj5v/GHSA-9j99-7q7q-cj5v.json new file mode 100644 index 00000000000..7b68982db56 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9j99-7q7q-cj5v/GHSA-9j99-7q7q-cj5v.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j99-7q7q-cj5v", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-11589" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /expcatedit.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11589" + }, + { + "type": "WEB", + "url": "https://github.com/kevin27392/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285661" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285661" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.445506" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json b/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json new file mode 100644 index 00000000000..b48cf1fac03 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w6j-hvpp-85hf", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8025" + ], + "details": "Nikon NEF Codec Thumbnail Provider NRW File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nikon NEF Codec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of NRW files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19873.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8025" + }, + { + "type": "WEB", + "url": "https://downloadcenter.nikonimglib.com/en/download/sw/259.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1422" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c2q4-8p6c-4c38/GHSA-c2q4-8p6c-4c38.json b/advisories/unreviewed/2024/11/GHSA-c2q4-8p6c-4c38/GHSA-c2q4-8p6c-4c38.json new file mode 100644 index 00000000000..03986235e3b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c2q4-8p6c-4c38/GHSA-c2q4-8p6c-4c38.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2q4-8p6c-4c38", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9252" + ], + "details": "Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24491.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9252" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1304" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f49p-8mpp-whc8/GHSA-f49p-8mpp-whc8.json b/advisories/unreviewed/2024/11/GHSA-f49p-8mpp-whc8/GHSA-f49p-8mpp-whc8.json new file mode 100644 index 00000000000..dd43b9aa191 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f49p-8mpp-whc8/GHSA-f49p-8mpp-whc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f49p-8mpp-whc8", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7229" + ], + "details": "Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22892.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7229" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f4pc-p4v6-gfw6/GHSA-f4pc-p4v6-gfw6.json b/advisories/unreviewed/2024/11/GHSA-f4pc-p4v6-gfw6/GHSA-f4pc-p4v6-gfw6.json new file mode 100644 index 00000000000..5507ed0a552 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f4pc-p4v6-gfw6/GHSA-f4pc-p4v6-gfw6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4pc-p4v6-gfw6", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9247" + ], + "details": "Foxit PDF Reader Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Annotation objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write before the start of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24173.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9247" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f6c7-whgm-qp84/GHSA-f6c7-whgm-qp84.json b/advisories/unreviewed/2024/11/GHSA-f6c7-whgm-qp84/GHSA-f6c7-whgm-qp84.json new file mode 100644 index 00000000000..ee0392aa320 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f6c7-whgm-qp84/GHSA-f6c7-whgm-qp84.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6c7-whgm-qp84", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-50054" + ], + "details": "The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50054" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f9vj-p9hp-2j78/GHSA-f9vj-p9hp-2j78.json b/advisories/unreviewed/2024/11/GHSA-f9vj-p9hp-2j78/GHSA-f9vj-p9hp-2j78.json new file mode 100644 index 00000000000..1dbc8e6bd84 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f9vj-p9hp-2j78/GHSA-f9vj-p9hp-2j78.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9vj-p9hp-2j78", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9250" + ], + "details": "Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24489.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9250" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fhwj-5xrc-3w57/GHSA-fhwj-5xrc-3w57.json b/advisories/unreviewed/2024/11/GHSA-fhwj-5xrc-3w57/GHSA-fhwj-5xrc-3w57.json new file mode 100644 index 00000000000..0ddaf1b3582 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fhwj-5xrc-3w57/GHSA-fhwj-5xrc-3w57.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhwj-5xrc-3w57", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7565" + ], + "details": "SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the unpackageAll function. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-19060.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7565" + }, + { + "type": "WEB", + "url": "https://www.soapui.org/downloads/latest-release/release-notes" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-frf2-9wh6-r8xw/GHSA-frf2-9wh6-r8xw.json b/advisories/unreviewed/2024/11/GHSA-frf2-9wh6-r8xw/GHSA-frf2-9wh6-r8xw.json new file mode 100644 index 00000000000..4b6d0ab956c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-frf2-9wh6-r8xw/GHSA-frf2-9wh6-r8xw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frf2-9wh6-r8xw", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9243" + ], + "details": "Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23932.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9243" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1296" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g9x7-qc89-39p9/GHSA-g9x7-qc89-39p9.json b/advisories/unreviewed/2024/11/GHSA-g9x7-qc89-39p9/GHSA-g9x7-qc89-39p9.json new file mode 100644 index 00000000000..08a98159493 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g9x7-qc89-39p9/GHSA-g9x7-qc89-39p9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9x7-qc89-39p9", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7391" + ], + "details": "ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability.\n\nThe specific flaw exists within the Wi-Fi setup logic. By connecting to the device over Bluetooth Low Energy during the setup process, an attacker can obtain Wi-Fi credentials. An attacker can leverage this vulnerability to disclose credentials and gain access to the device owner's Wi-Fi network. Was ZDI-CAN-21454.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7391" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json b/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json index 7cb779f50cd..9fd3b903f6d 100644 --- a/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json +++ b/advisories/unreviewed/2024/11/GHSA-gh8c-2875-38xv/GHSA-gh8c-2875-38xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gh8c-2875-38xv", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-11-23T03:31:57Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53076" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gts-helper: Fix memory leaks for the error path of iio_gts_build_avail_scale_table()\n\nIf per_time_scales[i] or per_time_gains[i] kcalloc fails in the for loop\nof iio_gts_build_avail_scale_table(), the err_free_out will fail to call\nkfree() each time when i is reduced to 0, so all the per_time_scales[0]\nand per_time_gains[0] will not be freed, which will cause memory leaks.\n\nFix it by checking if i >= 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json b/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json index 1ac2aae3a3d..7f3d20a866a 100644 --- a/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json +++ b/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghhj-rq38-j6jp", - "modified": "2024-11-20T21:30:50Z", + "modified": "2024-11-23T03:31:58Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-48986" ], "details": "An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. Certain events cause a callback, the logic for which allocates a buffer (the length of which is determined by looking up the event type in a table). The subsequent write operation, however, copies the amount of data specified in the packet header, which may lead to a buffer overflow. This bug is trivial to exploit for a denial of service but is not certain to suffice to bring the system down and can generally not be exploited further because the exploitable buffer is dynamically allocated.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-gv5m-rffc-c6x7/GHSA-gv5m-rffc-c6x7.json b/advisories/unreviewed/2024/11/GHSA-gv5m-rffc-c6x7/GHSA-gv5m-rffc-c6x7.json new file mode 100644 index 00000000000..39884b1bb16 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gv5m-rffc-c6x7/GHSA-gv5m-rffc-c6x7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv5m-rffc-c6x7", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-47138" + ], + "details": "The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47138" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h285-56q5-4xv2/GHSA-h285-56q5-4xv2.json b/advisories/unreviewed/2024/11/GHSA-h285-56q5-4xv2/GHSA-h285-56q5-4xv2.json new file mode 100644 index 00000000000..746bb310229 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h285-56q5-4xv2/GHSA-h285-56q5-4xv2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h285-56q5-4xv2", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7253" + ], + "details": "NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within nxnode.exe. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.\n\n. Was ZDI-CAN-24039.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7253" + }, + { + "type": "WEB", + "url": "https://kb.nomachine.com/TR07V11184" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h924-f4ph-m885/GHSA-h924-f4ph-m885.json b/advisories/unreviewed/2024/11/GHSA-h924-f4ph-m885/GHSA-h924-f4ph-m885.json new file mode 100644 index 00000000000..6a8e9664e16 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h924-f4ph-m885/GHSA-h924-f4ph-m885.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h924-f4ph-m885", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9113" + ], + "details": "FastStone Image Viewer TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of TGA files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25140.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9113" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1274" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hc88-rhv5-92jq/GHSA-hc88-rhv5-92jq.json b/advisories/unreviewed/2024/11/GHSA-hc88-rhv5-92jq/GHSA-hc88-rhv5-92jq.json new file mode 100644 index 00000000000..51cdc74878f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hc88-rhv5-92jq/GHSA-hc88-rhv5-92jq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc88-rhv5-92jq", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-47407" + ], + "details": "A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47407" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfvj-fmq3-mpxw/GHSA-hfvj-fmq3-mpxw.json b/advisories/unreviewed/2024/11/GHSA-hfvj-fmq3-mpxw/GHSA-hfvj-fmq3-mpxw.json new file mode 100644 index 00000000000..a33a397b393 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hfvj-fmq3-mpxw/GHSA-hfvj-fmq3-mpxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfvj-fmq3-mpxw", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9260" + ], + "details": "IrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SID files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23280.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9260" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfx9-j834-cmxw/GHSA-hfx9-j834-cmxw.json b/advisories/unreviewed/2024/11/GHSA-hfx9-j834-cmxw/GHSA-hfx9-j834-cmxw.json new file mode 100644 index 00000000000..cc51b35ca08 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hfx9-j834-cmxw/GHSA-hfx9-j834-cmxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfx9-j834-cmxw", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7240" + ], + "details": "F-Secure Total Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of F-Secure Total. User interaction on the part of an administrator is required to exploit this vulnerability.\n\nThe specific flaw exists within the WithSecure plugin hosting service. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23005.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7240" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hqpm-rxgj-829q/GHSA-hqpm-rxgj-829q.json b/advisories/unreviewed/2024/11/GHSA-hqpm-rxgj-829q/GHSA-hqpm-rxgj-829q.json new file mode 100644 index 00000000000..467057ac867 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hqpm-rxgj-829q/GHSA-hqpm-rxgj-829q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqpm-rxgj-829q", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9256" + ], + "details": "Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25267.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9256" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1309" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hwfx-3gvr-3fcv/GHSA-hwfx-3gvr-3fcv.json b/advisories/unreviewed/2024/11/GHSA-hwfx-3gvr-3fcv/GHSA-hwfx-3gvr-3fcv.json new file mode 100644 index 00000000000..a4a313925d9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hwfx-3gvr-3fcv/GHSA-hwfx-3gvr-3fcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwfx-3gvr-3fcv", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-6821" + ], + "details": "IrfanView CIN File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of CIN files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23260.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6821" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-973" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hxrx-xf7q-22cr/GHSA-hxrx-xf7q-22cr.json b/advisories/unreviewed/2024/11/GHSA-hxrx-xf7q-22cr/GHSA-hxrx-xf7q-22cr.json new file mode 100644 index 00000000000..95c6b0e9961 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hxrx-xf7q-22cr/GHSA-hxrx-xf7q-22cr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxrx-xf7q-22cr", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9767" + ], + "details": "IrfanView SID File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SID files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23277.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9767" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hxwv-g46m-hj5c/GHSA-hxwv-g46m-hj5c.json b/advisories/unreviewed/2024/11/GHSA-hxwv-g46m-hj5c/GHSA-hxwv-g46m-hj5c.json new file mode 100644 index 00000000000..01a2bdbbbfd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hxwv-g46m-hj5c/GHSA-hxwv-g46m-hj5c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxwv-g46m-hj5c", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9248" + ], + "details": "Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24300.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9248" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1302" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json b/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json new file mode 100644 index 00000000000..b9d8bc1a733 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxxf-235m-72v3", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-11394" + ], + "details": "Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25012.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11394" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1515" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j5ch-jjpm-qq89/GHSA-j5ch-jjpm-qq89.json b/advisories/unreviewed/2024/11/GHSA-j5ch-jjpm-qq89/GHSA-j5ch-jjpm-qq89.json new file mode 100644 index 00000000000..156a3d25e3d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j5ch-jjpm-qq89/GHSA-j5ch-jjpm-qq89.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5ch-jjpm-qq89", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9245" + ], + "details": "Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-23966.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9245" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1297" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j5jf-wf2j-j88q/GHSA-j5jf-wf2j-j88q.json b/advisories/unreviewed/2024/11/GHSA-j5jf-wf2j-j88q/GHSA-j5jf-wf2j-j88q.json new file mode 100644 index 00000000000..dcfa2deb019 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j5jf-wf2j-j88q/GHSA-j5jf-wf2j-j88q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5jf-wf2j-j88q", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9254" + ], + "details": "Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25173.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9254" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1307" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jj24-4w7r-ffch/GHSA-jj24-4w7r-ffch.json b/advisories/unreviewed/2024/11/GHSA-jj24-4w7r-ffch/GHSA-jj24-4w7r-ffch.json new file mode 100644 index 00000000000..66d7a576701 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jj24-4w7r-ffch/GHSA-jj24-4w7r-ffch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj24-4w7r-ffch", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9258" + ], + "details": "IrfanView SID File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SID files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23276.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9258" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1370" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json b/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json index 13d50f87b80..144dc71928a 100644 --- a/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json +++ b/advisories/unreviewed/2024/11/GHSA-jrrp-pvfv-xjh3/GHSA-jrrp-pvfv-xjh3.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jx3w-xgxj-7c49/GHSA-jx3w-xgxj-7c49.json b/advisories/unreviewed/2024/11/GHSA-jx3w-xgxj-7c49/GHSA-jx3w-xgxj-7c49.json new file mode 100644 index 00000000000..ff2b1eadacd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jx3w-xgxj-7c49/GHSA-jx3w-xgxj-7c49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx3w-xgxj-7c49", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7239" + ], + "details": "VIPRE Advanced Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Anti Malware Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22314.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7239" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json b/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json index 4c8a2e0008e..e155ad8e84e 100644 --- a/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json +++ b/advisories/unreviewed/2024/11/GHSA-m2w9-hmqh-m77h/GHSA-m2w9-hmqh-m77h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2w9-hmqh-m77h", - "modified": "2024-11-19T18:31:06Z", + "modified": "2024-11-23T03:31:57Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-53043" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp i2c: handle NULL header address\n\ndaddr can be NULL if there is no neighbour table entry present,\nin that case the tx packet should be dropped.\n\nsaddr will usually be set by MCTP core, but check for NULL in case a\npacket is transmitted by a different protocol.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m3pv-jrfq-7xp6/GHSA-m3pv-jrfq-7xp6.json b/advisories/unreviewed/2024/11/GHSA-m3pv-jrfq-7xp6/GHSA-m3pv-jrfq-7xp6.json new file mode 100644 index 00000000000..a95105de2ed --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m3pv-jrfq-7xp6/GHSA-m3pv-jrfq-7xp6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3pv-jrfq-7xp6", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7243" + ], + "details": "Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the PSANHost executable. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23413.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7243" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m49r-9xj2-m9q5/GHSA-m49r-9xj2-m9q5.json b/advisories/unreviewed/2024/11/GHSA-m49r-9xj2-m9q5/GHSA-m49r-9xj2-m9q5.json new file mode 100644 index 00000000000..3f150bdd102 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m49r-9xj2-m9q5/GHSA-m49r-9xj2-m9q5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m49r-9xj2-m9q5", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7238" + ], + "details": "VIPRE Advanced Security SBAMSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Anti Malware Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22238.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7238" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m7qm-rwvv-3j56/GHSA-m7qm-rwvv-3j56.json b/advisories/unreviewed/2024/11/GHSA-m7qm-rwvv-3j56/GHSA-m7qm-rwvv-3j56.json new file mode 100644 index 00000000000..7c513d62af8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m7qm-rwvv-3j56/GHSA-m7qm-rwvv-3j56.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7qm-rwvv-3j56", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-52034" + ], + "details": "An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52034" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m8m3-v647-2hvv/GHSA-m8m3-v647-2hvv.json b/advisories/unreviewed/2024/11/GHSA-m8m3-v647-2hvv/GHSA-m8m3-v647-2hvv.json new file mode 100644 index 00000000000..e8c0e9eeb4e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m8m3-v647-2hvv/GHSA-m8m3-v647-2hvv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8m3-v647-2hvv", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7230" + ], + "details": "Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22893.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7230" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1000" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mq9q-3729-crjx/GHSA-mq9q-3729-crjx.json b/advisories/unreviewed/2024/11/GHSA-mq9q-3729-crjx/GHSA-mq9q-3729-crjx.json new file mode 100644 index 00000000000..c2667bc4e4c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mq9q-3729-crjx/GHSA-mq9q-3729-crjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq9q-3729-crjx", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8358" + ], + "details": "Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the UPDATES_ExtractFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23422.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8358" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mxvq-xmr3-fr4w/GHSA-mxvq-xmr3-fr4w.json b/advisories/unreviewed/2024/11/GHSA-mxvq-xmr3-fr4w/GHSA-mxvq-xmr3-fr4w.json new file mode 100644 index 00000000000..ad74957de98 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mxvq-xmr3-fr4w/GHSA-mxvq-xmr3-fr4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxvq-xmr3-fr4w", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7234" + ], + "details": "AVG AntiVirus Free AVGSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the AVG Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22260.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7234" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json b/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json index 45fc63128ff..6fa9105750c 100644 --- a/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json +++ b/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-p9fm-4qxq-635g/GHSA-p9fm-4qxq-635g.json b/advisories/unreviewed/2024/11/GHSA-p9fm-4qxq-635g/GHSA-p9fm-4qxq-635g.json new file mode 100644 index 00000000000..93399640e74 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p9fm-4qxq-635g/GHSA-p9fm-4qxq-635g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9fm-4qxq-635g", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7352" + ], + "details": "PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23550.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7352" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q4pq-w3xm-6vp6/GHSA-q4pq-w3xm-6vp6.json b/advisories/unreviewed/2024/11/GHSA-q4pq-w3xm-6vp6/GHSA-q4pq-w3xm-6vp6.json new file mode 100644 index 00000000000..11b72572794 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q4pq-w3xm-6vp6/GHSA-q4pq-w3xm-6vp6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4pq-w3xm-6vp6", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-6819" + ], + "details": "IrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PSP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23219.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6819" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-971" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q4ww-jp52-p32r/GHSA-q4ww-jp52-p32r.json b/advisories/unreviewed/2024/11/GHSA-q4ww-jp52-p32r/GHSA-q4ww-jp52-p32r.json new file mode 100644 index 00000000000..e29a99fe23b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q4ww-jp52-p32r/GHSA-q4ww-jp52-p32r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4ww-jp52-p32r", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7231" + ], + "details": "Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22894.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7231" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q8f8-792j-48fx/GHSA-q8f8-792j-48fx.json b/advisories/unreviewed/2024/11/GHSA-q8f8-792j-48fx/GHSA-q8f8-792j-48fx.json new file mode 100644 index 00000000000..9c2d338db17 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q8f8-792j-48fx/GHSA-q8f8-792j-48fx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8f8-792j-48fx", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7236" + ], + "details": "AVG AntiVirus Free icarus Arbitrary File Creation Denial of Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AVG AntiVirus Free. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the AVG Installer. By creating a symbolic link, an attacker can abuse the update functionality to create a file. An attacker can leverage this vulnerability to create a persistent denial-of-service condition on the system. Was ZDI-CAN-22942.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7236" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qgx5-5h35-jw4r/GHSA-qgx5-5h35-jw4r.json b/advisories/unreviewed/2024/11/GHSA-qgx5-5h35-jw4r/GHSA-qgx5-5h35-jw4r.json new file mode 100644 index 00000000000..a7a09668f76 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qgx5-5h35-jw4r/GHSA-qgx5-5h35-jw4r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgx5-5h35-jw4r", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9244" + ], + "details": "Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-23933.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9244" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1298" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxhm-xw2r-6r75/GHSA-qxhm-xw2r-6r75.json b/advisories/unreviewed/2024/11/GHSA-qxhm-xw2r-6r75/GHSA-qxhm-xw2r-6r75.json new file mode 100644 index 00000000000..b334b0139ae --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qxhm-xw2r-6r75/GHSA-qxhm-xw2r-6r75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxhm-xw2r-6r75", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-6871" + ], + "details": "G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of autostart tasks. The issue results from incorrect permissions set on folders. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22629.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6871" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1486" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json b/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json new file mode 100644 index 00000000000..96ad1d8ccf9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxrp-vhvm-j765", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-11392" + ], + "details": "Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-24322.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11392" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1513" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r2hp-qw2c-hfpf/GHSA-r2hp-qw2c-hfpf.json b/advisories/unreviewed/2024/11/GHSA-r2hp-qw2c-hfpf/GHSA-r2hp-qw2c-hfpf.json new file mode 100644 index 00000000000..353ee6ab4be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r2hp-qw2c-hfpf/GHSA-r2hp-qw2c-hfpf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2hp-qw2c-hfpf", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9259" + ], + "details": "IrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SID files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23278.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9259" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r557-c6rf-9q6w/GHSA-r557-c6rf-9q6w.json b/advisories/unreviewed/2024/11/GHSA-r557-c6rf-9q6w/GHSA-r557-c6rf-9q6w.json new file mode 100644 index 00000000000..633522493bc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r557-c6rf-9q6w/GHSA-r557-c6rf-9q6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r557-c6rf-9q6w", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7392" + ], + "details": "ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the connection handling of the Bluetooth Low Energy interface. The issue results from limiting the number of active connections to the product. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-21455.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7392" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-410" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json b/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json index 5eaf40d4960..7be529547c8 100644 --- a/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json +++ b/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8wg-wr62-xwrv", - "modified": "2024-11-20T21:30:50Z", + "modified": "2024-11-23T03:31:58Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-48982" ], "details": "An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assumed to be greater than or equal to 3, but the software doesn't ensure that this is the case. Supplying a length less than 3 leads to a buffer overflow in a buffer that is allocated later. It is simultaneously possible to cause another integer overflow by supplying large length values because the provided length value is increased by a few bytes to account for additional information that is supposed to be stored there. This bug is trivial to exploit for a denial of service but is not certain to suffice to bring the system down and can generally not be exploited further because the exploitable buffer is dynamically allocated.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rcqh-96hr-hv69/GHSA-rcqh-96hr-hv69.json b/advisories/unreviewed/2024/11/GHSA-rcqh-96hr-hv69/GHSA-rcqh-96hr-hv69.json index 3f13a725d66..c8dc42aa880 100644 --- a/advisories/unreviewed/2024/11/GHSA-rcqh-96hr-hv69/GHSA-rcqh-96hr-hv69.json +++ b/advisories/unreviewed/2024/11/GHSA-rcqh-96hr-hv69/GHSA-rcqh-96hr-hv69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcqh-96hr-hv69", - "modified": "2024-11-19T03:31:07Z", + "modified": "2024-11-23T03:31:57Z", "published": "2024-11-19T03:31:07Z", "aliases": [ "CVE-2024-50268" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd()\n\nThe \"*cmd\" variable can be controlled by the user via debugfs. That means\n\"new_cam\" can be as high as 255 while the size of the uc->updated[] array\nis UCSI_MAX_ALTMODES (30).\n\nThe call tree is:\nucsi_cmd() // val comes from simple_attr_write_xsigned()\n-> ucsi_send_command()\n -> ucsi_send_command_common()\n -> ucsi_run_command() // calls ucsi->ops->sync_control()\n -> ucsi_ccg_sync_control()", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:28Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rg23-vpf8-9ppw/GHSA-rg23-vpf8-9ppw.json b/advisories/unreviewed/2024/11/GHSA-rg23-vpf8-9ppw/GHSA-rg23-vpf8-9ppw.json new file mode 100644 index 00000000000..b19093cfac7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rg23-vpf8-9ppw/GHSA-rg23-vpf8-9ppw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg23-vpf8-9ppw", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7509" + ], + "details": "Trimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19576.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7509" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rm8x-rgrx-p9v7/GHSA-rm8x-rgrx-p9v7.json b/advisories/unreviewed/2024/11/GHSA-rm8x-rgrx-p9v7/GHSA-rm8x-rgrx-p9v7.json new file mode 100644 index 00000000000..9e6b1f1e861 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rm8x-rgrx-p9v7/GHSA-rm8x-rgrx-p9v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm8x-rgrx-p9v7", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8359" + ], + "details": "Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the REFLASH_DDU_FindFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23420.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8359" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmmv-vvpx-42cw/GHSA-rmmv-vvpx-42cw.json b/advisories/unreviewed/2024/11/GHSA-rmmv-vvpx-42cw/GHSA-rmmv-vvpx-42cw.json new file mode 100644 index 00000000000..bee355dbe77 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmmv-vvpx-42cw/GHSA-rmmv-vvpx-42cw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmmv-vvpx-42cw", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9249" + ], + "details": "Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24301.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9249" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1301" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmx6-f935-2738/GHSA-rmx6-f935-2738.json b/advisories/unreviewed/2024/11/GHSA-rmx6-f935-2738/GHSA-rmx6-f935-2738.json index 7c57c646624..1f97ff638c6 100644 --- a/advisories/unreviewed/2024/11/GHSA-rmx6-f935-2738/GHSA-rmx6-f935-2738.json +++ b/advisories/unreviewed/2024/11/GHSA-rmx6-f935-2738/GHSA-rmx6-f935-2738.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-v583-6v29-vvg5/GHSA-v583-6v29-vvg5.json b/advisories/unreviewed/2024/11/GHSA-v583-6v29-vvg5/GHSA-v583-6v29-vvg5.json new file mode 100644 index 00000000000..741b4509acd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v583-6v29-vvg5/GHSA-v583-6v29-vvg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v583-6v29-vvg5", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8360" + ], + "details": "Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the REFLASH_DDU_ExtractFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23421.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8360" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1192" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v855-95x4-c338/GHSA-v855-95x4-c338.json b/advisories/unreviewed/2024/11/GHSA-v855-95x4-c338/GHSA-v855-95x4-c338.json new file mode 100644 index 00000000000..9eab436d106 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v855-95x4-c338/GHSA-v855-95x4-c338.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v855-95x4-c338", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-6822" + ], + "details": "IrfanView CIN File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of CIN files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23261.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6822" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-974" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v9gw-2mh9-343m/GHSA-v9gw-2mh9-343m.json b/advisories/unreviewed/2024/11/GHSA-v9gw-2mh9-343m/GHSA-v9gw-2mh9-343m.json new file mode 100644 index 00000000000..206c02536f3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v9gw-2mh9-343m/GHSA-v9gw-2mh9-343m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9gw-2mh9-343m", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7245" + ], + "details": "Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Hydra Sdk Windows Service. The issue lies in the lack of proper permissions set on a folder created by the service. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23429.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7245" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vjmj-84v8-m369/GHSA-vjmj-84v8-m369.json b/advisories/unreviewed/2024/11/GHSA-vjmj-84v8-m369/GHSA-vjmj-84v8-m369.json new file mode 100644 index 00000000000..15dc2fb3adf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vjmj-84v8-m369/GHSA-vjmj-84v8-m369.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjmj-84v8-m369", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9253" + ], + "details": "Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24492.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9253" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vpwx-h6w7-p6j9/GHSA-vpwx-h6w7-p6j9.json b/advisories/unreviewed/2024/11/GHSA-vpwx-h6w7-p6j9/GHSA-vpwx-h6w7-p6j9.json new file mode 100644 index 00000000000..298cf02f30a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vpwx-h6w7-p6j9/GHSA-vpwx-h6w7-p6j9.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpwx-h6w7-p6j9", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-11590" + ], + "details": "A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file /forget_password_process.php. The manipulation of the argument unm leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11590" + }, + { + "type": "WEB", + "url": "https://github.com/1ighttack/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285662" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285662" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.445580" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vqfg-w42j-3w23/GHSA-vqfg-w42j-3w23.json b/advisories/unreviewed/2024/11/GHSA-vqfg-w42j-3w23/GHSA-vqfg-w42j-3w23.json new file mode 100644 index 00000000000..2e8881c6d49 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vqfg-w42j-3w23/GHSA-vqfg-w42j-3w23.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqfg-w42j-3w23", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-11630" + ], + "details": "A vulnerability has been found in E-Lins H685, H685f, H700, H720, H750, H820, H820Q, H820Q0 and H900 up to 3.2 and classified as critical. This vulnerability affects unknown code of the component OEM Backend. The manipulation leads to hard-coded credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11630" + }, + { + "type": "WEB", + "url": "https://github.com/I3eg1nner/iot-vuln/blob/main/E-lins/Hard-Coded%20Credential%20Vulnerability%20in%20E-Lins%20Routers.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285916" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285916" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.444738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vxc5-94ff-325x/GHSA-vxc5-94ff-325x.json b/advisories/unreviewed/2024/11/GHSA-vxc5-94ff-325x/GHSA-vxc5-94ff-325x.json new file mode 100644 index 00000000000..8327f6d183b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vxc5-94ff-325x/GHSA-vxc5-94ff-325x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxc5-94ff-325x", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9114" + ], + "details": "FastStone Image Viewer GIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of GIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25145.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9114" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json b/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json new file mode 100644 index 00000000000..23bcf1d63b9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wc63-rvqh-4rvx/GHSA-wc63-rvqh-4rvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc63-rvqh-4rvx", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9261" + ], + "details": "IrfanView SID File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SID files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23283.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9261" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json b/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json new file mode 100644 index 00000000000..0fed2a4beb7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrfc-pvp9-mr9g", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-11393" + ], + "details": "Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25191.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11393" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1514" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrjx-5994-mvxh/GHSA-wrjx-5994-mvxh.json b/advisories/unreviewed/2024/11/GHSA-wrjx-5994-mvxh/GHSA-wrjx-5994-mvxh.json new file mode 100644 index 00000000000..f24d7401408 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrjx-5994-mvxh/GHSA-wrjx-5994-mvxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrjx-5994-mvxh", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-0122" + ], + "details": "NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. A successful exploit of this vulnerability may lead to partial denial of service and confidential information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0122" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5570" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-23T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x2hc-pc6q-48fm/GHSA-x2hc-pc6q-48fm.json b/advisories/unreviewed/2024/11/GHSA-x2hc-pc6q-48fm/GHSA-x2hc-pc6q-48fm.json new file mode 100644 index 00000000000..fb9127aaf62 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x2hc-pc6q-48fm/GHSA-x2hc-pc6q-48fm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2hc-pc6q-48fm", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-6820" + ], + "details": "IrfanView AWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of AWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23232.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6820" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-972" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x4vr-gr9r-q7v6/GHSA-x4vr-gr9r-q7v6.json b/advisories/unreviewed/2024/11/GHSA-x4vr-gr9r-q7v6/GHSA-x4vr-gr9r-q7v6.json new file mode 100644 index 00000000000..5d8e62ef540 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x4vr-gr9r-q7v6/GHSA-x4vr-gr9r-q7v6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4vr-gr9r-q7v6", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-8357" + ], + "details": "Visteon Infotainment App SoC Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.\n\nThe specific flaw exists within the configuration of the application system-on-chip (SoC). The issue results from the lack of properly configured hardware root of trust. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the boot process. Was ZDI-CAN-23759.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8357" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1326" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x822-p2w4-gp4c/GHSA-x822-p2w4-gp4c.json b/advisories/unreviewed/2024/11/GHSA-x822-p2w4-gp4c/GHSA-x822-p2w4-gp4c.json new file mode 100644 index 00000000000..711f0825010 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x822-p2w4-gp4c/GHSA-x822-p2w4-gp4c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x822-p2w4-gp4c", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-45369" + ], + "details": "The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45369" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xm38-wpcw-48cj/GHSA-xm38-wpcw-48cj.json b/advisories/unreviewed/2024/11/GHSA-xm38-wpcw-48cj/GHSA-xm38-wpcw-48cj.json new file mode 100644 index 00000000000..7da4d830c73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xm38-wpcw-48cj/GHSA-xm38-wpcw-48cj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm38-wpcw-48cj", + "modified": "2024-11-23T03:31:59Z", + "published": "2024-11-23T03:31:59Z", + "aliases": [ + "CVE-2024-9251" + ], + "details": "Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24490.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9251" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1306" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xv64-q73j-cvqp/GHSA-xv64-q73j-cvqp.json b/advisories/unreviewed/2024/11/GHSA-xv64-q73j-cvqp/GHSA-xv64-q73j-cvqp.json new file mode 100644 index 00000000000..533952f74b8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xv64-q73j-cvqp/GHSA-xv64-q73j-cvqp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv64-q73j-cvqp", + "modified": "2024-11-23T03:31:58Z", + "published": "2024-11-23T03:31:58Z", + "aliases": [ + "CVE-2024-7227" + ], + "details": "Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7227" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-22T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xwgw-3mc5-w4qf/GHSA-xwgw-3mc5-w4qf.json b/advisories/unreviewed/2024/11/GHSA-xwgw-3mc5-w4qf/GHSA-xwgw-3mc5-w4qf.json index a108f2fbdbc..5ea8f47f9b6 100644 --- a/advisories/unreviewed/2024/11/GHSA-xwgw-3mc5-w4qf/GHSA-xwgw-3mc5-w4qf.json +++ b/advisories/unreviewed/2024/11/GHSA-xwgw-3mc5-w4qf/GHSA-xwgw-3mc5-w4qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xwgw-3mc5-w4qf", - "modified": "2024-11-20T12:30:35Z", + "modified": "2024-11-23T03:31:58Z", "published": "2024-11-20T12:30:35Z", "aliases": [ "CVE-2024-10872"