Publish Advisories

GHSA-3wxf-8h2q-7rqj
GHSA-943v-r8pv-7467
GHSA-cj4r-8g68-rx5f
GHSA-f6vg-w657-ph8f
GHSA-fv3c-xwjm-jfxw
GHSA-gmxg-c36j-9c9p
GHSA-hpmh-cxvp-vj39
GHSA-hwv4-85rj-4xm9
GHSA-j8pf-3mrg-4487
GHSA-jg3h-w3vp-mwf6
GHSA-m974-g65c-pfc6
GHSA-qf96-mmrf-rj2q
GHSA-rvgj-6xhm-fmfh
GHSA-vrp7-hqrc-f29q
GHSA-w64x-j9r3-q79q
GHSA-xx3g-v5fx-v7w6
This commit is contained in:
advisory-database[bot]
2024-01-16 09:31:18 +00:00
parent 2124c3e62c
commit 6c52e37c32
16 changed files with 593 additions and 1 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wxf-8h2q-7rqj",
"modified": "2024-01-16T09:30:19Z",
"published": "2024-01-16T09:30:19Z",
"aliases": [
"CVE-2023-52098"
],
"details": "Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52098"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T09:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-943v-r8pv-7467",
"modified": "2024-01-16T09:30:19Z",
"published": "2024-01-16T09:30:19Z",
"aliases": [
"CVE-2023-52107"
],
"details": "Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52107"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T09:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj4r-8g68-rx5f",
"modified": "2024-01-16T09:30:19Z",
"published": "2024-01-16T09:30:19Z",
"aliases": [
"CVE-2023-52108"
],
"details": "Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52108"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T09:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6vg-w657-ph8f",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-52110"
],
"details": "The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52110"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fv3c-xwjm-jfxw",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-52111"
],
"details": "Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52111"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gmxg-c36j-9c9p",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-44117"
],
"details": "Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44117"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hpmh-cxvp-vj39",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-4566"
],
"details": "Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4566"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-290"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwv4-85rj-4xm9",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2011-10005"
],
"details": "A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250716.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-10005"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.250716"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.250716"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/17354"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8pf-3mrg-4487",
"modified": "2024-01-16T09:30:19Z",
"published": "2024-01-16T09:30:19Z",
"aliases": [
"CVE-2023-52115"
],
"details": "The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52115"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T09:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg3h-w3vp-mwf6",
"modified": "2024-01-16T09:30:19Z",
"published": "2024-01-16T09:30:19Z",
"aliases": [
"CVE-2023-52116"
],
"details": "Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52116"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T09:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m974-g65c-pfc6",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-52112"
],
"details": "Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52112"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qf96-mmrf-rj2q",
"modified": "2024-01-16T09:30:19Z",
"published": "2024-01-16T09:30:19Z",
"aliases": [
"CVE-2023-52114"
],
"details": "Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52114"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T09:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvgj-6xhm-fmfh",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-44112"
],
"details": "Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44112"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vrp7-hqrc-f29q",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-52109"
],
"details": "Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52109"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-345"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w64x-j9r3-q79q",
"modified": "2024-01-16T06:30:31Z",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T06:30:31Z",
"aliases": [
"CVE-2023-22527"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xx3g-v5fx-v7w6",
"modified": "2024-01-16T09:30:18Z",
"published": "2024-01-16T09:30:18Z",
"aliases": [
"CVE-2023-52113"
],
"details": "launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52113"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T08:15:09Z"
}
}