mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-3wxf-8h2q-7rqj GHSA-943v-r8pv-7467 GHSA-cj4r-8g68-rx5f GHSA-f6vg-w657-ph8f GHSA-fv3c-xwjm-jfxw GHSA-gmxg-c36j-9c9p GHSA-hpmh-cxvp-vj39 GHSA-hwv4-85rj-4xm9 GHSA-j8pf-3mrg-4487 GHSA-jg3h-w3vp-mwf6 GHSA-m974-g65c-pfc6 GHSA-qf96-mmrf-rj2q GHSA-rvgj-6xhm-fmfh GHSA-vrp7-hqrc-f29q GHSA-w64x-j9r3-q79q GHSA-xx3g-v5fx-v7w6
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3wxf-8h2q-7rqj",
|
||||
"modified": "2024-01-16T09:30:19Z",
|
||||
"published": "2024-01-16T09:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52098"
|
||||
],
|
||||
"details": "Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52098"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T09:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-943v-r8pv-7467",
|
||||
"modified": "2024-01-16T09:30:19Z",
|
||||
"published": "2024-01-16T09:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52107"
|
||||
],
|
||||
"details": "Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52107"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T09:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cj4r-8g68-rx5f",
|
||||
"modified": "2024-01-16T09:30:19Z",
|
||||
"published": "2024-01-16T09:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52108"
|
||||
],
|
||||
"details": "Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52108"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T09:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f6vg-w657-ph8f",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52110"
|
||||
],
|
||||
"details": "The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52110"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fv3c-xwjm-jfxw",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52111"
|
||||
],
|
||||
"details": "Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52111"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-287"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gmxg-c36j-9c9p",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44117"
|
||||
],
|
||||
"details": "Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44117"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-290"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hpmh-cxvp-vj39",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-4566"
|
||||
],
|
||||
"details": "Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4566"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-290"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hwv4-85rj-4xm9",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2011-10005"
|
||||
],
|
||||
"details": "A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250716.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-10005"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.250716"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.250716"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.exploit-db.com/exploits/17354"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j8pf-3mrg-4487",
|
||||
"modified": "2024-01-16T09:30:19Z",
|
||||
"published": "2024-01-16T09:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52115"
|
||||
],
|
||||
"details": "The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52115"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T09:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jg3h-w3vp-mwf6",
|
||||
"modified": "2024-01-16T09:30:19Z",
|
||||
"published": "2024-01-16T09:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52116"
|
||||
],
|
||||
"details": "Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52116"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T09:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m974-g65c-pfc6",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52112"
|
||||
],
|
||||
"details": "Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52112"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:09Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qf96-mmrf-rj2q",
|
||||
"modified": "2024-01-16T09:30:19Z",
|
||||
"published": "2024-01-16T09:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52114"
|
||||
],
|
||||
"details": "Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52114"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T09:15:07Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rvgj-6xhm-fmfh",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-44112"
|
||||
],
|
||||
"details": "Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44112"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-200"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vrp7-hqrc-f29q",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52109"
|
||||
],
|
||||
"details": "Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52109"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-345"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:08Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w64x-j9r3-q79q",
|
||||
"modified": "2024-01-16T06:30:31Z",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T06:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2023-22527"
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xx3g-v5fx-v7w6",
|
||||
"modified": "2024-01-16T09:30:18Z",
|
||||
"published": "2024-01-16T09:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-52113"
|
||||
],
|
||||
"details": "launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52113"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-01-16T08:15:09Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user