From 6dc56617b8822d95907e313572e516d9076b808f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Sep 2024 03:32:07 +0000 Subject: [PATCH] Publish Advisories GHSA-4jrr-pcvg-6fp6 GHSA-mg6f-mx33-mrj2 GHSA-w7x5-g6gj-cxw9 GHSA-wxhj-ww34-v87f GHSA-5p86-7v4g-7f7r GHSA-fxvw-v786-822p GHSA-j5wg-h8jh-fx4v GHSA-w8v6-gxpj-3qp5 GHSA-wwx9-cp3m-5v66 GHSA-vcc9-8549-687w GHSA-46j9-q72c-3w95 GHSA-7vm7-mp89-q7c7 GHSA-48wc-9j2c-rwp5 GHSA-7whw-68xg-fr5c GHSA-cwqr-9j7q-r9xh GHSA-q4q2-r8qr-qgwm --- .../GHSA-4jrr-pcvg-6fp6.json | 2 +- .../GHSA-mg6f-mx33-mrj2.json | 2 +- .../GHSA-w7x5-g6gj-cxw9.json | 2 +- .../GHSA-wxhj-ww34-v87f.json | 2 +- .../GHSA-5p86-7v4g-7f7r.json | 2 +- .../GHSA-fxvw-v786-822p.json | 2 +- .../GHSA-j5wg-h8jh-fx4v.json | 2 +- .../GHSA-w8v6-gxpj-3qp5.json | 2 +- .../GHSA-wwx9-cp3m-5v66.json | 2 +- .../GHSA-vcc9-8549-687w.json | 2 +- .../GHSA-46j9-q72c-3w95.json | 2 +- .../GHSA-7vm7-mp89-q7c7.json | 2 +- .../GHSA-48wc-9j2c-rwp5.json | 6 ++- .../GHSA-7whw-68xg-fr5c.json | 11 ++++-- .../GHSA-cwqr-9j7q-r9xh.json | 9 +++-- .../GHSA-q4q2-r8qr-qgwm.json | 38 +++++++++++++++++++ 16 files changed, 68 insertions(+), 20 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-q4q2-r8qr-qgwm/GHSA-q4q2-r8qr-qgwm.json diff --git a/advisories/unreviewed/2021/11/GHSA-4jrr-pcvg-6fp6/GHSA-4jrr-pcvg-6fp6.json b/advisories/unreviewed/2021/11/GHSA-4jrr-pcvg-6fp6/GHSA-4jrr-pcvg-6fp6.json index f9ff13393a5..5ea58a8cb78 100644 --- a/advisories/unreviewed/2021/11/GHSA-4jrr-pcvg-6fp6/GHSA-4jrr-pcvg-6fp6.json +++ b/advisories/unreviewed/2021/11/GHSA-4jrr-pcvg-6fp6/GHSA-4jrr-pcvg-6fp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jrr-pcvg-6fp6", - "modified": "2023-10-10T12:32:08Z", + "modified": "2024-09-17T03:30:41Z", "published": "2021-11-23T00:00:50Z", "aliases": [ "CVE-2019-5640" diff --git a/advisories/unreviewed/2022/08/GHSA-mg6f-mx33-mrj2/GHSA-mg6f-mx33-mrj2.json b/advisories/unreviewed/2022/08/GHSA-mg6f-mx33-mrj2/GHSA-mg6f-mx33-mrj2.json index 6d33819411e..4d5e116faaf 100644 --- a/advisories/unreviewed/2022/08/GHSA-mg6f-mx33-mrj2/GHSA-mg6f-mx33-mrj2.json +++ b/advisories/unreviewed/2022/08/GHSA-mg6f-mx33-mrj2/GHSA-mg6f-mx33-mrj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mg6f-mx33-mrj2", - "modified": "2022-08-19T00:00:20Z", + "modified": "2024-09-17T03:30:41Z", "published": "2022-08-18T00:00:19Z", "aliases": [ "CVE-2022-1401" diff --git a/advisories/unreviewed/2023/01/GHSA-w7x5-g6gj-cxw9/GHSA-w7x5-g6gj-cxw9.json b/advisories/unreviewed/2023/01/GHSA-w7x5-g6gj-cxw9/GHSA-w7x5-g6gj-cxw9.json index d0a70a3aebc..e663d10e1b1 100644 --- a/advisories/unreviewed/2023/01/GHSA-w7x5-g6gj-cxw9/GHSA-w7x5-g6gj-cxw9.json +++ b/advisories/unreviewed/2023/01/GHSA-w7x5-g6gj-cxw9/GHSA-w7x5-g6gj-cxw9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-wxhj-ww34-v87f/GHSA-wxhj-ww34-v87f.json b/advisories/unreviewed/2023/01/GHSA-wxhj-ww34-v87f/GHSA-wxhj-ww34-v87f.json index a7c8036d43d..fb8fafeefe8 100644 --- a/advisories/unreviewed/2023/01/GHSA-wxhj-ww34-v87f/GHSA-wxhj-ww34-v87f.json +++ b/advisories/unreviewed/2023/01/GHSA-wxhj-ww34-v87f/GHSA-wxhj-ww34-v87f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-5p86-7v4g-7f7r/GHSA-5p86-7v4g-7f7r.json b/advisories/unreviewed/2023/04/GHSA-5p86-7v4g-7f7r/GHSA-5p86-7v4g-7f7r.json index 40a969e20d2..185b2be64c2 100644 --- a/advisories/unreviewed/2023/04/GHSA-5p86-7v4g-7f7r/GHSA-5p86-7v4g-7f7r.json +++ b/advisories/unreviewed/2023/04/GHSA-5p86-7v4g-7f7r/GHSA-5p86-7v4g-7f7r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json b/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json index 8a19e174b4e..d5359b89ce7 100644 --- a/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json +++ b/advisories/unreviewed/2023/04/GHSA-fxvw-v786-822p/GHSA-fxvw-v786-822p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json b/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json index 47bd630c4e9..44b7c1d2c14 100644 --- a/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json +++ b/advisories/unreviewed/2023/04/GHSA-j5wg-h8jh-fx4v/GHSA-j5wg-h8jh-fx4v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-w8v6-gxpj-3qp5/GHSA-w8v6-gxpj-3qp5.json b/advisories/unreviewed/2023/04/GHSA-w8v6-gxpj-3qp5/GHSA-w8v6-gxpj-3qp5.json index 94b836ffcbd..cadf66f13bc 100644 --- a/advisories/unreviewed/2023/04/GHSA-w8v6-gxpj-3qp5/GHSA-w8v6-gxpj-3qp5.json +++ b/advisories/unreviewed/2023/04/GHSA-w8v6-gxpj-3qp5/GHSA-w8v6-gxpj-3qp5.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-wwx9-cp3m-5v66/GHSA-wwx9-cp3m-5v66.json b/advisories/unreviewed/2023/04/GHSA-wwx9-cp3m-5v66/GHSA-wwx9-cp3m-5v66.json index 8a9e71b89b8..ae43e722dfd 100644 --- a/advisories/unreviewed/2023/04/GHSA-wwx9-cp3m-5v66/GHSA-wwx9-cp3m-5v66.json +++ b/advisories/unreviewed/2023/04/GHSA-wwx9-cp3m-5v66/GHSA-wwx9-cp3m-5v66.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json b/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json index 700b34b25a3..e48c5499c36 100644 --- a/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json +++ b/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vcc9-8549-687w", - "modified": "2024-04-04T05:30:40Z", + "modified": "2024-09-17T03:30:43Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-2807" diff --git a/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json b/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json index 8bda2f0d1d8..a39200e686c 100644 --- a/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json +++ b/advisories/unreviewed/2023/10/GHSA-46j9-q72c-3w95/GHSA-46j9-q72c-3w95.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json b/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json index cb26e2aefdd..866971fce5e 100644 --- a/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json +++ b/advisories/unreviewed/2023/10/GHSA-7vm7-mp89-q7c7/GHSA-7vm7-mp89-q7c7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json b/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json index d4ecec4320f..3cc137140b3 100644 --- a/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json +++ b/advisories/unreviewed/2024/09/GHSA-48wc-9j2c-rwp5/GHSA-48wc-9j2c-rwp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48wc-9j2c-rwp5", - "modified": "2024-09-06T06:31:41Z", + "modified": "2024-09-17T03:30:44Z", "published": "2024-09-06T06:31:41Z", "aliases": [ "CVE-2024-39585" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39585" }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228355/dsa-2024-376-security-update-for-dell-networking-os10-vulnerability" + }, { "type": "WEB", "url": "https://www.dell.com/support/kbdoc/en-us/000228357/dsa-2024-377-security-update-for-dell-networking-os10-vulnerability" diff --git a/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json b/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json index 590382dbc8c..42229b39391 100644 --- a/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json +++ b/advisories/unreviewed/2024/09/GHSA-7whw-68xg-fr5c/GHSA-7whw-68xg-fr5c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7whw-68xg-fr5c", - "modified": "2024-09-16T18:31:21Z", + "modified": "2024-09-17T03:30:45Z", "published": "2024-09-16T18:31:21Z", "aliases": [ "CVE-2024-44623" ], "details": "An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-16T16:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json b/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json index c60a368eddb..fceb9ea5a4a 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json +++ b/advisories/unreviewed/2024/09/GHSA-cwqr-9j7q-r9xh/GHSA-cwqr-9j7q-r9xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwqr-9j7q-r9xh", - "modified": "2024-09-16T14:37:26Z", + "modified": "2024-09-17T03:30:45Z", "published": "2024-09-16T14:37:26Z", "aliases": [ "CVE-2024-8039" ], "details": "Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-732" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-14T04:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q4q2-r8qr-qgwm/GHSA-q4q2-r8qr-qgwm.json b/advisories/unreviewed/2024/09/GHSA-q4q2-r8qr-qgwm/GHSA-q4q2-r8qr-qgwm.json new file mode 100644 index 00000000000..a9accbd6d99 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q4q2-r8qr-qgwm/GHSA-q4q2-r8qr-qgwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4q2-r8qr-qgwm", + "modified": "2024-09-17T03:30:45Z", + "published": "2024-09-17T03:30:45Z", + "aliases": [ + "CVE-2024-8110" + ], + "details": "Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer.\nIf a computer on which the affected product is installed receives a large number of UDP broadcast packets in a short period, occasionally that computer may restart.\nIf both the active and standby computers are restarted at the same time, the functionality on that computer may be temporarily unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8110" + }, + { + "type": "WEB", + "url": "https://web-material3.yokogawa.com/1/36276/files/YSAR-24-0003-E.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-252" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T02:15:49Z" + } +} \ No newline at end of file