From 6e70085549a449dd3c2686b85d356ba80dd848ec Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 30 Oct 2024 21:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8h46-5m9h-7553.json | 22 +++++++- .../GHSA-mjjj-6p6j-chqm.json | 2 +- .../GHSA-p4w7-mqq9-4jc7.json | 2 +- .../GHSA-p882-2j97-m4hp.json | 2 +- .../GHSA-6347-pxpp-244g.json | 11 ++-- .../GHSA-92f7-c7hw-58cr.json | 2 +- .../GHSA-h4pg-prwh-f695.json | 9 ++-- .../GHSA-r6xh-2p9x-84pq.json | 2 +- .../GHSA-vpg2-32g8-56wf.json | 2 +- .../GHSA-x6p5-7c22-qrq6.json | 3 +- .../GHSA-4pmx-grr5-rmvm.json | 9 ++-- .../GHSA-63p7-87m3-8c9v.json | 9 ++-- .../GHSA-8x54-9cjv-7vch.json | 9 ++-- .../GHSA-m9jj-4rp8-mm96.json | 11 ++-- .../GHSA-qg9g-p9q2-wjvw.json | 2 +- .../GHSA-5x2g-c9gv-xwq2.json | 9 ++-- .../GHSA-8p54-55f6-pg9j.json | 3 +- .../GHSA-9qrm-8x3f-j2vq.json | 11 ++-- .../GHSA-9vgp-pjm3-97c6.json | 11 ++-- .../GHSA-r3qr-6c5q-pr77.json | 11 ++-- .../GHSA-xrpr-8xpg-cf34.json | 11 ++-- .../GHSA-9cr4-w78w-p2qr.json | 11 ++-- .../GHSA-wwvg-j77r-54mx.json | 9 ++-- .../GHSA-ffh4-92gv-qvv5.json | 2 +- .../GHSA-g4f7-w5wq-j7fw.json | 2 +- .../GHSA-gmvw-8mpv-xh3v.json | 11 ++-- .../GHSA-r596-778h-jppv.json | 9 ++-- .../GHSA-rx6g-pr26-7gxj.json | 2 +- .../GHSA-8382-wrqg-hqw9.json | 2 +- .../GHSA-q7r3-4mvp-9f9p.json | 2 +- .../GHSA-qp2p-hqhr-hrw4.json | 2 +- .../GHSA-rjwc-235r-8986.json | 9 ++-- .../GHSA-3w7r-v4fr-r43w.json | 2 +- .../GHSA-53h7-ghj7-7gh9.json | 2 +- .../GHSA-ch37-5p65-5r4w.json | 2 +- .../GHSA-chqm-2p4j-9jph.json | 11 ++-- .../GHSA-mcm9-3rfg-2mqm.json | 4 +- .../GHSA-xw3h-6c4j-mqhw.json | 3 +- .../GHSA-cwr9-w5qw-fr62.json | 2 +- .../GHSA-g385-hxmr-ghgc.json | 2 +- .../GHSA-2929-7j9v-q6g6.json | 39 ++++++++++++++ .../GHSA-2f7m-hc5g-9cqc.json | 35 ++++++++++++ .../GHSA-3m6c-6c98-23qq.json | 11 ++-- .../GHSA-3q28-538h-7pqq.json | 2 +- .../GHSA-3qpq-hc75-5535.json | 2 +- .../GHSA-425f-273g-699h.json | 11 ++-- .../GHSA-43gj-mj95-qp4h.json | 11 ++-- .../GHSA-46gj-r39x-jc6p.json | 2 +- .../GHSA-4hjf-5mq4-f6c7.json | 11 ++-- .../GHSA-4j29-45vf-qcg5.json | 11 ++-- .../GHSA-4j93-qfwm-6xrv.json | 35 ++++++++++++ .../GHSA-5744-494c-924x.json | 2 +- .../GHSA-5gxq-g22h-vg26.json | 11 ++-- .../GHSA-5m98-v5jj-6cv6.json | 35 ++++++++++++ .../GHSA-5qhh-w7j8-f42j.json | 39 ++++++++++++++ .../GHSA-72r5-8cg4-8h5f.json | 39 ++++++++++++++ .../GHSA-72vv-fghx-58jc.json | 11 ++-- .../GHSA-75pc-2p8w-2hhf.json | 9 ++-- .../GHSA-79wf-qgrg-2p6c.json | 11 ++-- .../GHSA-7m83-4f94-8qqr.json | 11 ++-- .../GHSA-7w36-gg3q-f3vg.json | 39 ++++++++++++++ .../GHSA-84c3-765r-7fjp.json | 35 ++++++++++++ .../GHSA-866g-2qvc-5w35.json | 11 ++-- .../GHSA-8792-j7xc-qcgv.json | 11 ++-- .../GHSA-884x-p7qm-gq3f.json | 11 ++-- .../GHSA-8c74-r7ww-5v4x.json | 11 ++-- .../GHSA-8xq2-3cqg-9xfj.json | 11 ++-- .../GHSA-95jc-3vhv-3739.json | 11 ++-- .../GHSA-9vq2-w47q-3pjh.json | 2 +- .../GHSA-c68x-6hmf-xw2p.json | 35 ++++++++++++ .../GHSA-cq86-p348-qr4p.json | 11 ++-- .../GHSA-cx83-mmj7-4ghv.json | 2 +- .../GHSA-f729-m528-5h64.json | 11 ++-- .../GHSA-f7rc-79mv-v26v.json | 35 ++++++++++++ .../GHSA-f8f6-24mj-36m7.json | 9 ++-- .../GHSA-fqq4-8x5p-9g5p.json | 39 ++++++++++++++ .../GHSA-fv52-m5w8-2242.json | 11 ++-- .../GHSA-fvv3-x64f-px6p.json | 2 +- .../GHSA-fwvx-h53h-63j5.json | 9 ++-- .../GHSA-g76c-5vhc-hqmg.json | 2 +- .../GHSA-g8px-5pqf-j335.json | 11 ++-- .../GHSA-ghqj-2wp8-298g.json | 11 ++-- .../GHSA-gmjx-74cx-5p3f.json | 3 +- .../GHSA-jjpr-6x73-f9v6.json | 9 ++-- .../GHSA-jp7p-mxpw-mf6m.json | 35 ++++++++++++ .../GHSA-m7rv-mgxq-vxph.json | 54 +++++++++++++++++++ .../GHSA-mpp2-2v83-ccjm.json | 39 ++++++++++++++ .../GHSA-p5wf-4fg4-hw2q.json | 9 ++-- .../GHSA-p9cw-g386-7q2x.json | 11 ++-- .../GHSA-pj8w-xcg3-82vx.json | 11 ++-- .../GHSA-pjhx-j53p-c5f5.json | 39 ++++++++++++++ .../GHSA-pxm6-wc5v-cphj.json | 35 ++++++++++++ .../GHSA-qc88-643m-whjm.json | 2 +- .../GHSA-qph8-rvxf-5936.json | 2 +- .../GHSA-r23x-v492-c286.json | 35 ++++++++++++ .../GHSA-r39h-f84x-g77w.json | 11 ++-- .../GHSA-rj6f-j453-ffwx.json | 2 +- .../GHSA-rmrx-hhmg-hqq9.json | 1 + .../GHSA-rq35-f7p2-6pp9.json | 35 ++++++++++++ .../GHSA-rwqj-v7mx-c4x7.json | 39 ++++++++++++++ .../GHSA-v52g-r6cw-2f8h.json | 9 ++-- .../GHSA-v76h-6p79-mvh2.json | 11 ++-- .../GHSA-vpwg-6766-6xgp.json | 11 ++-- .../GHSA-wx35-29xj-r29q.json | 2 +- .../GHSA-x2gv-fj8v-x2rx.json | 11 ++-- .../GHSA-xhx7-6233-wm3w.json | 35 ++++++++++++ .../GHSA-xpm9-95h9-q996.json | 11 ++-- .../GHSA-xr7f-32j7-5fh9.json | 9 ++-- 108 files changed, 1155 insertions(+), 226 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-2929-7j9v-q6g6/GHSA-2929-7j9v-q6g6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5m98-v5jj-6cv6/GHSA-5m98-v5jj-6cv6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-72r5-8cg4-8h5f/GHSA-72r5-8cg4-8h5f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m7rv-mgxq-vxph/GHSA-m7rv-mgxq-vxph.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mpp2-2v83-ccjm/GHSA-mpp2-2v83-ccjm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pjhx-j53p-c5f5/GHSA-pjhx-j53p-c5f5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r23x-v492-c286/GHSA-r23x-v492-c286.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json diff --git a/advisories/github-reviewed/2021/05/GHSA-8h46-5m9h-7553/GHSA-8h46-5m9h-7553.json b/advisories/github-reviewed/2021/05/GHSA-8h46-5m9h-7553/GHSA-8h46-5m9h-7553.json index 9c669283c76..1ee5f8f604b 100644 --- a/advisories/github-reviewed/2021/05/GHSA-8h46-5m9h-7553/GHSA-8h46-5m9h-7553.json +++ b/advisories/github-reviewed/2021/05/GHSA-8h46-5m9h-7553/GHSA-8h46-5m9h-7553.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8h46-5m9h-7553", - "modified": "2021-05-18T23:40:54Z", + "modified": "2024-10-30T21:30:51Z", "published": "2021-05-21T14:20:51Z", "aliases": [ "CVE-2021-29514" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ @@ -142,6 +146,22 @@ { "type": "WEB", "url": "https://github.com/tensorflow/tensorflow/commit/eebb96c2830d48597d055d247c0e9aebaea94cd5" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2021-442.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2021-640.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2021-151.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/tensorflow/tensorflow" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-mjjj-6p6j-chqm/GHSA-mjjj-6p6j-chqm.json b/advisories/unreviewed/2023/07/GHSA-mjjj-6p6j-chqm/GHSA-mjjj-6p6j-chqm.json index 3cedb21dee6..721f3efe34e 100644 --- a/advisories/unreviewed/2023/07/GHSA-mjjj-6p6j-chqm/GHSA-mjjj-6p6j-chqm.json +++ b/advisories/unreviewed/2023/07/GHSA-mjjj-6p6j-chqm/GHSA-mjjj-6p6j-chqm.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-p4w7-mqq9-4jc7/GHSA-p4w7-mqq9-4jc7.json b/advisories/unreviewed/2023/07/GHSA-p4w7-mqq9-4jc7/GHSA-p4w7-mqq9-4jc7.json index b52a03df2ae..35fad71957c 100644 --- a/advisories/unreviewed/2023/07/GHSA-p4w7-mqq9-4jc7/GHSA-p4w7-mqq9-4jc7.json +++ b/advisories/unreviewed/2023/07/GHSA-p4w7-mqq9-4jc7/GHSA-p4w7-mqq9-4jc7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-p882-2j97-m4hp/GHSA-p882-2j97-m4hp.json b/advisories/unreviewed/2023/07/GHSA-p882-2j97-m4hp/GHSA-p882-2j97-m4hp.json index d64fc3029b4..2681f836a4e 100644 --- a/advisories/unreviewed/2023/07/GHSA-p882-2j97-m4hp/GHSA-p882-2j97-m4hp.json +++ b/advisories/unreviewed/2023/07/GHSA-p882-2j97-m4hp/GHSA-p882-2j97-m4hp.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json b/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json index 389f022bd68..534b33dd6b7 100644 --- a/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json +++ b/advisories/unreviewed/2024/02/GHSA-6347-pxpp-244g/GHSA-6347-pxpp-244g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6347-pxpp-244g", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-10-30T21:30:36Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-26466" ], "details": "A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:27:59Z" diff --git a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json index 3468974b916..dabe272ea09 100644 --- a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json +++ b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json @@ -76,7 +76,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-h4pg-prwh-f695/GHSA-h4pg-prwh-f695.json b/advisories/unreviewed/2024/02/GHSA-h4pg-prwh-f695/GHSA-h4pg-prwh-f695.json index 51d0dd2d21b..798aca91cde 100644 --- a/advisories/unreviewed/2024/02/GHSA-h4pg-prwh-f695/GHSA-h4pg-prwh-f695.json +++ b/advisories/unreviewed/2024/02/GHSA-h4pg-prwh-f695/GHSA-h4pg-prwh-f695.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4pg-prwh-f695", - "modified": "2024-02-29T03:33:17Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-21722" ], "details": "The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-613" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:03Z" diff --git a/advisories/unreviewed/2024/02/GHSA-r6xh-2p9x-84pq/GHSA-r6xh-2p9x-84pq.json b/advisories/unreviewed/2024/02/GHSA-r6xh-2p9x-84pq/GHSA-r6xh-2p9x-84pq.json index 7c7aa8faeb0..4339e029bce 100644 --- a/advisories/unreviewed/2024/02/GHSA-r6xh-2p9x-84pq/GHSA-r6xh-2p9x-84pq.json +++ b/advisories/unreviewed/2024/02/GHSA-r6xh-2p9x-84pq/GHSA-r6xh-2p9x-84pq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json b/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json index f82b7011525..ebdf763e014 100644 --- a/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json +++ b/advisories/unreviewed/2024/02/GHSA-vpg2-32g8-56wf/GHSA-vpg2-32g8-56wf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json b/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json index a19f7f9c5f4..acf1afbc20e 100644 --- a/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json +++ b/advisories/unreviewed/2024/02/GHSA-x6p5-7c22-qrq6/GHSA-x6p5-7c22-qrq6.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-4pmx-grr5-rmvm/GHSA-4pmx-grr5-rmvm.json b/advisories/unreviewed/2024/03/GHSA-4pmx-grr5-rmvm/GHSA-4pmx-grr5-rmvm.json index 8f0ebf2bafc..ecad6d2a4c1 100644 --- a/advisories/unreviewed/2024/03/GHSA-4pmx-grr5-rmvm/GHSA-4pmx-grr5-rmvm.json +++ b/advisories/unreviewed/2024/03/GHSA-4pmx-grr5-rmvm/GHSA-4pmx-grr5-rmvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pmx-grr5-rmvm", - "modified": "2024-03-07T15:30:38Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-03-07T15:30:38Z", "aliases": [ "CVE-2024-2241" ], "details": "Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T13:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-63p7-87m3-8c9v/GHSA-63p7-87m3-8c9v.json b/advisories/unreviewed/2024/03/GHSA-63p7-87m3-8c9v/GHSA-63p7-87m3-8c9v.json index 3d269eeca71..1b60c8d979e 100644 --- a/advisories/unreviewed/2024/03/GHSA-63p7-87m3-8c9v/GHSA-63p7-87m3-8c9v.json +++ b/advisories/unreviewed/2024/03/GHSA-63p7-87m3-8c9v/GHSA-63p7-87m3-8c9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-63p7-87m3-8c9v", - "modified": "2024-03-25T18:30:57Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2611" ], "details": "A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T12:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json b/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json index f00ed8c0697..985dd42771c 100644 --- a/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json +++ b/advisories/unreviewed/2024/03/GHSA-8x54-9cjv-7vch/GHSA-8x54-9cjv-7vch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8x54-9cjv-7vch", - "modified": "2024-03-21T15:31:55Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-03-21T15:31:55Z", "aliases": [ "CVE-2024-2464" ], "details": "This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions through 5.7.1.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T15:16:54Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m9jj-4rp8-mm96/GHSA-m9jj-4rp8-mm96.json b/advisories/unreviewed/2024/03/GHSA-m9jj-4rp8-mm96/GHSA-m9jj-4rp8-mm96.json index ac6cca9ed73..0d3ad5a86ba 100644 --- a/advisories/unreviewed/2024/03/GHSA-m9jj-4rp8-mm96/GHSA-m9jj-4rp8-mm96.json +++ b/advisories/unreviewed/2024/03/GHSA-m9jj-4rp8-mm96/GHSA-m9jj-4rp8-mm96.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9jj-4rp8-mm96", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23248" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json b/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json index 9414bbc332d..d6107c2fc04 100644 --- a/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json +++ b/advisories/unreviewed/2024/03/GHSA-qg9g-p9q2-wjvw/GHSA-qg9g-p9q2-wjvw.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5x2g-c9gv-xwq2/GHSA-5x2g-c9gv-xwq2.json b/advisories/unreviewed/2024/04/GHSA-5x2g-c9gv-xwq2/GHSA-5x2g-c9gv-xwq2.json index 1685d9e260d..6e567858fb0 100644 --- a/advisories/unreviewed/2024/04/GHSA-5x2g-c9gv-xwq2/GHSA-5x2g-c9gv-xwq2.json +++ b/advisories/unreviewed/2024/04/GHSA-5x2g-c9gv-xwq2/GHSA-5x2g-c9gv-xwq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x2g-c9gv-xwq2", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-04-03T18:30:44Z", "aliases": [ "CVE-2024-2758" ], "details": "Tempesta FW rate limits are not enabled by default. They are either set too large to capture empty CONTINUATION frames attacks or too small to handle normal HTTP requests appropriately.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T18:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json b/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json index a9dd3a31f6f..d790ba75e60 100644 --- a/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json +++ b/advisories/unreviewed/2024/04/GHSA-8p54-55f6-pg9j/GHSA-8p54-55f6-pg9j.json @@ -68,7 +68,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-190" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9qrm-8x3f-j2vq/GHSA-9qrm-8x3f-j2vq.json b/advisories/unreviewed/2024/04/GHSA-9qrm-8x3f-j2vq/GHSA-9qrm-8x3f-j2vq.json index f75e6a1a129..aae891300a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-9qrm-8x3f-j2vq/GHSA-9qrm-8x3f-j2vq.json +++ b/advisories/unreviewed/2024/04/GHSA-9qrm-8x3f-j2vq/GHSA-9qrm-8x3f-j2vq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qrm-8x3f-j2vq", - "modified": "2024-04-01T18:30:56Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-04-01T18:30:56Z", "aliases": [ "CVE-2024-30863" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T16:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9vgp-pjm3-97c6/GHSA-9vgp-pjm3-97c6.json b/advisories/unreviewed/2024/04/GHSA-9vgp-pjm3-97c6/GHSA-9vgp-pjm3-97c6.json index 4300b87ae63..d2ab283a0b3 100644 --- a/advisories/unreviewed/2024/04/GHSA-9vgp-pjm3-97c6/GHSA-9vgp-pjm3-97c6.json +++ b/advisories/unreviewed/2024/04/GHSA-9vgp-pjm3-97c6/GHSA-9vgp-pjm3-97c6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vgp-pjm3-97c6", - "modified": "2024-04-02T18:31:19Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-04-02T18:31:19Z", "aliases": [ "CVE-2024-30807" ], "details": "An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T18:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r3qr-6c5q-pr77/GHSA-r3qr-6c5q-pr77.json b/advisories/unreviewed/2024/04/GHSA-r3qr-6c5q-pr77/GHSA-r3qr-6c5q-pr77.json index af62f2cc56d..2dd44479eb6 100644 --- a/advisories/unreviewed/2024/04/GHSA-r3qr-6c5q-pr77/GHSA-r3qr-6c5q-pr77.json +++ b/advisories/unreviewed/2024/04/GHSA-r3qr-6c5q-pr77/GHSA-r3qr-6c5q-pr77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3qr-6c5q-pr77", - "modified": "2024-04-11T06:30:35Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-04-11T06:30:35Z", "aliases": [ "CVE-2024-30885" ], "details": "Reflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive information via the chklogin.php component .", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T05:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xrpr-8xpg-cf34/GHSA-xrpr-8xpg-cf34.json b/advisories/unreviewed/2024/04/GHSA-xrpr-8xpg-cf34/GHSA-xrpr-8xpg-cf34.json index 9c08e12a3ee..2160765e72c 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrpr-8xpg-cf34/GHSA-xrpr-8xpg-cf34.json +++ b/advisories/unreviewed/2024/04/GHSA-xrpr-8xpg-cf34/GHSA-xrpr-8xpg-cf34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrpr-8xpg-cf34", - "modified": "2024-04-01T03:30:41Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-04-01T03:30:41Z", "aliases": [ "CVE-2024-20050" ], "details": "In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json b/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json index 778c8cff2e3..c9471a0fa17 100644 --- a/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json +++ b/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9cr4-w78w-p2qr", - "modified": "2024-06-10T21:30:35Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-23229" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Ventura 13.6.5, macOS Sonoma 14.4. A malicious application may be able to access Find My data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T14:58:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wwvg-j77r-54mx/GHSA-wwvg-j77r-54mx.json b/advisories/unreviewed/2024/05/GHSA-wwvg-j77r-54mx/GHSA-wwvg-j77r-54mx.json index 528006f2fa2..8fa054be412 100644 --- a/advisories/unreviewed/2024/05/GHSA-wwvg-j77r-54mx/GHSA-wwvg-j77r-54mx.json +++ b/advisories/unreviewed/2024/05/GHSA-wwvg-j77r-54mx/GHSA-wwvg-j77r-54mx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwvg-j77r-54mx", - "modified": "2024-05-17T15:31:10Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-05-17T15:31:10Z", "aliases": [ "CVE-2024-35824" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: lis3lv02d_i2c: Fix regulators getting en-/dis-abled twice on suspend/resume\n\nWhen not configured for wakeup lis3lv02d_i2c_suspend() will call\nlis3lv02d_poweroff() even if the device has already been turned off\nby the runtime-suspend handler and if configured for wakeup and\nthe device is runtime-suspended at this point then it is not turned\nback on to serve as a wakeup source.\n\nBefore commit b1b9f7a49440 (\"misc: lis3lv02d_i2c: Add missing setting\nof the reg_ctrl callback\"), lis3lv02d_poweroff() failed to disable\nthe regulators which as a side effect made calling poweroff() twice ok.\n\nNow that poweroff() correctly disables the regulators, doing this twice\ntriggers a WARN() in the regulator core:\n\nunbalanced disables for regulator-dummy\nWARNING: CPU: 1 PID: 92 at drivers/regulator/core.c:2999 _regulator_disable\n...\n\nFix lis3lv02d_i2c_suspend() to not call poweroff() a second time if\nalready runtime-suspended and add a poweron() call when necessary to\nmake wakeup work.\n\nlis3lv02d_i2c_resume() has similar issues, with an added weirness that\nit always powers on the device if it is runtime suspended, after which\nthe first runtime-resume will call poweron() again, causing the enabled\ncount for the regulator to increase by 1 every suspend/resume. These\nunbalanced regulator_enable() calls cause the regulator to never\nbe turned off and trigger the following WARN() on driver unbind:\n\nWARNING: CPU: 1 PID: 1724 at drivers/regulator/core.c:2396 _regulator_put\n\nFix this by making lis3lv02d_i2c_resume() mirror the new suspend().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:18Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json b/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json index 939a0a403bb..928963aa3cd 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json +++ b/advisories/unreviewed/2024/06/GHSA-ffh4-92gv-qvv5/GHSA-ffh4-92gv-qvv5.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g4f7-w5wq-j7fw/GHSA-g4f7-w5wq-j7fw.json b/advisories/unreviewed/2024/06/GHSA-g4f7-w5wq-j7fw/GHSA-g4f7-w5wq-j7fw.json index cd4ac41c92c..e46b57641e1 100644 --- a/advisories/unreviewed/2024/06/GHSA-g4f7-w5wq-j7fw/GHSA-g4f7-w5wq-j7fw.json +++ b/advisories/unreviewed/2024/06/GHSA-g4f7-w5wq-j7fw/GHSA-g4f7-w5wq-j7fw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-gmvw-8mpv-xh3v/GHSA-gmvw-8mpv-xh3v.json b/advisories/unreviewed/2024/06/GHSA-gmvw-8mpv-xh3v/GHSA-gmvw-8mpv-xh3v.json index 664e3533a17..f177538a457 100644 --- a/advisories/unreviewed/2024/06/GHSA-gmvw-8mpv-xh3v/GHSA-gmvw-8mpv-xh3v.json +++ b/advisories/unreviewed/2024/06/GHSA-gmvw-8mpv-xh3v/GHSA-gmvw-8mpv-xh3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmvw-8mpv-xh3v", - "modified": "2024-06-17T15:30:50Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-06-17T15:30:50Z", "aliases": [ "CVE-2024-6055" ], "details": "Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-212" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T13:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json b/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json index 99e4b441831..61f5823fe91 100644 --- a/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json +++ b/advisories/unreviewed/2024/06/GHSA-r596-778h-jppv/GHSA-r596-778h-jppv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r596-778h-jppv", - "modified": "2024-06-24T15:31:44Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-06-24T15:31:44Z", "aliases": [ "CVE-2024-34030" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: of_property: Return error for int_map allocation failure\n\nReturn -ENOMEM from of_pci_prop_intr_map() if kcalloc() fails to prevent a\nNULL pointer dereference in this case.\n\n[bhelgaas: commit log]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T14:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json b/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json index 058ba2c0219..89d9bbafc13 100644 --- a/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json +++ b/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-552" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8382-wrqg-hqw9/GHSA-8382-wrqg-hqw9.json b/advisories/unreviewed/2024/07/GHSA-8382-wrqg-hqw9/GHSA-8382-wrqg-hqw9.json index fb1bca15c20..9027d7f05b2 100644 --- a/advisories/unreviewed/2024/07/GHSA-8382-wrqg-hqw9/GHSA-8382-wrqg-hqw9.json +++ b/advisories/unreviewed/2024/07/GHSA-8382-wrqg-hqw9/GHSA-8382-wrqg-hqw9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-q7r3-4mvp-9f9p/GHSA-q7r3-4mvp-9f9p.json b/advisories/unreviewed/2024/07/GHSA-q7r3-4mvp-9f9p/GHSA-q7r3-4mvp-9f9p.json index 67e383d06c2..63b4473d3d9 100644 --- a/advisories/unreviewed/2024/07/GHSA-q7r3-4mvp-9f9p/GHSA-q7r3-4mvp-9f9p.json +++ b/advisories/unreviewed/2024/07/GHSA-q7r3-4mvp-9f9p/GHSA-q7r3-4mvp-9f9p.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json b/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json index dffc2a102ef..c99af43f710 100644 --- a/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json +++ b/advisories/unreviewed/2024/07/GHSA-qp2p-hqhr-hrw4/GHSA-qp2p-hqhr-hrw4.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-rjwc-235r-8986/GHSA-rjwc-235r-8986.json b/advisories/unreviewed/2024/07/GHSA-rjwc-235r-8986/GHSA-rjwc-235r-8986.json index b43fe11b854..427d00614fe 100644 --- a/advisories/unreviewed/2024/07/GHSA-rjwc-235r-8986/GHSA-rjwc-235r-8986.json +++ b/advisories/unreviewed/2024/07/GHSA-rjwc-235r-8986/GHSA-rjwc-235r-8986.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rjwc-235r-8986", - "modified": "2024-07-16T18:31:41Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-07-09T15:30:54Z", "aliases": [ "CVE-2024-6601" ], "details": "A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T15:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json b/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json index 97458115fe3..5e5e42d3e23 100644 --- a/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json +++ b/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-459" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json index 9165abb0b29..8aebda60391 100644 --- a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json +++ b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json b/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json index 166ee743d1a..fef6cc050fa 100644 --- a/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json +++ b/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json b/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json index c446d118628..654c6ba3f9f 100644 --- a/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json +++ b/advisories/unreviewed/2024/08/GHSA-chqm-2p4j-9jph/GHSA-chqm-2p4j-9jph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-chqm-2p4j-9jph", - "modified": "2024-08-21T18:31:28Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-08-21T18:31:28Z", "aliases": [ "CVE-2024-42550" ], "details": "A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T17:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json b/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json index aa33babdb98..a1a350efb79 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json +++ b/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcm9-3rfg-2mqm", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-10-30T21:30:37Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2021-26387" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json b/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json index 670dc16dc80..f31220bbc1a 100644 --- a/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json +++ b/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json b/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json index 71338a9e3d2..cc4d2281a07 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json +++ b/advisories/unreviewed/2024/09/GHSA-cwr9-w5qw-fr62/GHSA-cwr9-w5qw-fr62.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g385-hxmr-ghgc/GHSA-g385-hxmr-ghgc.json b/advisories/unreviewed/2024/09/GHSA-g385-hxmr-ghgc/GHSA-g385-hxmr-ghgc.json index 4132a977839..0378e43131b 100644 --- a/advisories/unreviewed/2024/09/GHSA-g385-hxmr-ghgc/GHSA-g385-hxmr-ghgc.json +++ b/advisories/unreviewed/2024/09/GHSA-g385-hxmr-ghgc/GHSA-g385-hxmr-ghgc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2929-7j9v-q6g6/GHSA-2929-7j9v-q6g6.json b/advisories/unreviewed/2024/10/GHSA-2929-7j9v-q6g6/GHSA-2929-7j9v-q6g6.json new file mode 100644 index 00000000000..ccb2acc61d2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2929-7j9v-q6g6/GHSA-2929-7j9v-q6g6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2929-7j9v-q6g6", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48734" + ], + "details": "*Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48734" + }, + { + "type": "WEB", + "url": "https://github.com/ACN-CVEs/CVE-2024-48734/blob/d59cca7b03bce3a516035d1a0f488d67c3d10ae6/Unrestricted%20file%20upload.pdf" + }, + { + "type": "WEB", + "url": "http://sas.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json b/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json new file mode 100644 index 00000000000..0f42eca3e0e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f7m-hc5g-9cqc", + "modified": "2024-10-30T21:30:41Z", + "published": "2024-10-30T21:30:41Z", + "aliases": [ + "CVE-2024-51424" + ], + "details": "An issue in Ethereum v.1.12.2 allows remote attacker to execute arbitrary code via the Owned.setOwner function", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51424" + }, + { + "type": "WEB", + "url": "https://github.com/Wzy-source/Gala/blob/main/CVEs/AURA_0x967d176328948e4db4446b8caf623ff9b47221fb.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3m6c-6c98-23qq/GHSA-3m6c-6c98-23qq.json b/advisories/unreviewed/2024/10/GHSA-3m6c-6c98-23qq/GHSA-3m6c-6c98-23qq.json index e6e961faa50..f3f762bb81c 100644 --- a/advisories/unreviewed/2024/10/GHSA-3m6c-6c98-23qq/GHSA-3m6c-6c98-23qq.json +++ b/advisories/unreviewed/2024/10/GHSA-3m6c-6c98-23qq/GHSA-3m6c-6c98-23qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3m6c-6c98-23qq", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44265" ], "details": "The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An attacker with physical access can input Game Controller events to apps running on a locked device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3q28-538h-7pqq/GHSA-3q28-538h-7pqq.json b/advisories/unreviewed/2024/10/GHSA-3q28-538h-7pqq/GHSA-3q28-538h-7pqq.json index 40c61f4a877..6c25ea45553 100644 --- a/advisories/unreviewed/2024/10/GHSA-3q28-538h-7pqq/GHSA-3q28-538h-7pqq.json +++ b/advisories/unreviewed/2024/10/GHSA-3q28-538h-7pqq/GHSA-3q28-538h-7pqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q28-538h-7pqq", - "modified": "2024-10-16T09:30:31Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-16T09:30:31Z", "aliases": [ "CVE-2024-45714" diff --git a/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json b/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json index 8b83c6ca185..f403a6e36b3 100644 --- a/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json +++ b/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-425f-273g-699h/GHSA-425f-273g-699h.json b/advisories/unreviewed/2024/10/GHSA-425f-273g-699h/GHSA-425f-273g-699h.json index e3398c2eb4b..41a98f4c2bf 100644 --- a/advisories/unreviewed/2024/10/GHSA-425f-273g-699h/GHSA-425f-273g-699h.json +++ b/advisories/unreviewed/2024/10/GHSA-425f-273g-699h/GHSA-425f-273g-699h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-425f-273g-699h", - "modified": "2024-10-28T00:30:48Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-28T00:30:48Z", "aliases": [ "CVE-2024-50613" ], "details": "libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json b/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json index 696367a0d3a..156ce9aa037 100644 --- a/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json +++ b/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-43gj-mj95-qp4h", - "modified": "2024-10-30T15:30:47Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-30T15:30:47Z", "aliases": [ "CVE-2024-51299" ], "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T14:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-46gj-r39x-jc6p/GHSA-46gj-r39x-jc6p.json b/advisories/unreviewed/2024/10/GHSA-46gj-r39x-jc6p/GHSA-46gj-r39x-jc6p.json index 186c9b432cc..e578236543c 100644 --- a/advisories/unreviewed/2024/10/GHSA-46gj-r39x-jc6p/GHSA-46gj-r39x-jc6p.json +++ b/advisories/unreviewed/2024/10/GHSA-46gj-r39x-jc6p/GHSA-46gj-r39x-jc6p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json b/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json index 2e6b58b261b..2c987564c5d 100644 --- a/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json +++ b/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hjf-5mq4-f6c7", - "modified": "2024-10-30T15:30:47Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-30T15:30:47Z", "aliases": [ "CVE-2024-51296" ], "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T14:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json b/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json index 3cbb2143bc4..b0eb8eb7171 100644 --- a/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json +++ b/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j29-45vf-qcg5", - "modified": "2024-10-25T21:31:28Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-25T21:31:28Z", "aliases": [ "CVE-2024-48396" ], "details": "AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json b/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json new file mode 100644 index 00000000000..3d0769b6b4e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j93-qfwm-6xrv", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-51419" + ], + "details": "Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51419" + }, + { + "type": "WEB", + "url": "https://gist.github.com/475bd8bc21c4f4dfc8f26ce35eb6ca28.git" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json b/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json index e795bfdc6ac..e7bd09a96c7 100644 --- a/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json +++ b/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5gxq-g22h-vg26/GHSA-5gxq-g22h-vg26.json b/advisories/unreviewed/2024/10/GHSA-5gxq-g22h-vg26/GHSA-5gxq-g22h-vg26.json index 7af1846029d..a0a7cb7ee73 100644 --- a/advisories/unreviewed/2024/10/GHSA-5gxq-g22h-vg26/GHSA-5gxq-g22h-vg26.json +++ b/advisories/unreviewed/2024/10/GHSA-5gxq-g22h-vg26/GHSA-5gxq-g22h-vg26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gxq-g22h-vg26", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49001" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: fix race when vmap stack overflow\n\nCurrently, when detecting vmap stack overflow, riscv firstly switches\nto the so called shadow stack, then use this shadow stack to call the\nget_overflow_stack() to get the overflow stack. However, there's\na race here if two or more harts use the same shadow stack at the same\ntime.\n\nTo solve this race, we introduce spin_shadow_stack atomic var, which\nwill be swap between its own address and 0 in atomic way, when the\nvar is set, it means the shadow_stack is being used; when the var\nis cleared, it means the shadow_stack isn't being used.\n\n[Palmer: Add AQ to the swap, and also some comments.]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5m98-v5jj-6cv6/GHSA-5m98-v5jj-6cv6.json b/advisories/unreviewed/2024/10/GHSA-5m98-v5jj-6cv6/GHSA-5m98-v5jj-6cv6.json new file mode 100644 index 00000000000..7759de57c63 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5m98-v5jj-6cv6/GHSA-5m98-v5jj-6cv6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m98-v5jj-6cv6", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48346" + ], + "details": "xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48346" + }, + { + "type": "WEB", + "url": "https://github.com/xtreme1-io/xtreme1/issues/284" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json b/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json new file mode 100644 index 00000000000..de794dc7b67 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qhh-w7j8-f42j", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48272" + ], + "details": "D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48272" + }, + { + "type": "WEB", + "url": "https://gist.github.com/stevenyu113228/e264c145d6e6e6b59cf53fddc27409ad#2--predictable-wifi-password-in-d-link-dsl6740c-modem" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-72r5-8cg4-8h5f/GHSA-72r5-8cg4-8h5f.json b/advisories/unreviewed/2024/10/GHSA-72r5-8cg4-8h5f/GHSA-72r5-8cg4-8h5f.json new file mode 100644 index 00000000000..a045f629193 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-72r5-8cg4-8h5f/GHSA-72r5-8cg4-8h5f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72r5-8cg4-8h5f", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48733" + ], + "details": "SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48733" + }, + { + "type": "WEB", + "url": "https://github.com/ACN-CVEs/CVE-2024-48733/blob/ea2da31c3d6e0140edd6a1455e6157b8ba2f7a67/SQL%20injection.pdf" + }, + { + "type": "WEB", + "url": "http://sas.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-72vv-fghx-58jc/GHSA-72vv-fghx-58jc.json b/advisories/unreviewed/2024/10/GHSA-72vv-fghx-58jc/GHSA-72vv-fghx-58jc.json index 81b434de746..d3c10297612 100644 --- a/advisories/unreviewed/2024/10/GHSA-72vv-fghx-58jc/GHSA-72vv-fghx-58jc.json +++ b/advisories/unreviewed/2024/10/GHSA-72vv-fghx-58jc/GHSA-72vv-fghx-58jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72vv-fghx-58jc", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44287" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json b/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json index 90291c855bd..7433909b15d 100644 --- a/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json +++ b/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75pc-2p8w-2hhf", - "modified": "2024-10-18T18:30:37Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-18T18:30:36Z", "aliases": [ "CVE-2023-6080" ], "details": "Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-379" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-18T17:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json index 435fe2a10d3..eca991e6ebc 100644 --- a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json +++ b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79wf-qgrg-2p6c", - "modified": "2024-10-27T06:30:47Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-27T06:30:47Z", "aliases": [ "CVE-2024-50602" ], "details": "An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T05:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json b/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json index 4ac300aa2ba..d7bb6467a5d 100644 --- a/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json +++ b/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m83-4f94-8qqr", - "modified": "2024-10-25T21:31:28Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-25T21:31:28Z", "aliases": [ "CVE-2024-48232" ], "details": "An issue was found in mipjz 5.0.5. In the mipPost method of \\app\\setting\\controller\\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json b/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json new file mode 100644 index 00000000000..f43227b9732 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w36-gg3q-f3vg", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48093" + ], + "details": "Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48093" + }, + { + "type": "WEB", + "url": "https://github.com/yamerooo123/CVE/blob/main/CVE-2024-48093/Description.md" + }, + { + "type": "WEB", + "url": "https://youtu.be/rCYIohrQdxM" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json b/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json new file mode 100644 index 00000000000..4209ffab9dc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84c3-765r-7fjp", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-51242" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51242" + }, + { + "type": "WEB", + "url": "https://github.com/shadia0/Patienc/blob/main/eladmin_ssrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-866g-2qvc-5w35/GHSA-866g-2qvc-5w35.json b/advisories/unreviewed/2024/10/GHSA-866g-2qvc-5w35/GHSA-866g-2qvc-5w35.json index 1971e0f90cb..4236ab451ba 100644 --- a/advisories/unreviewed/2024/10/GHSA-866g-2qvc-5w35/GHSA-866g-2qvc-5w35.json +++ b/advisories/unreviewed/2024/10/GHSA-866g-2qvc-5w35/GHSA-866g-2qvc-5w35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-866g-2qvc-5w35", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-48465" ], "details": "The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8792-j7xc-qcgv/GHSA-8792-j7xc-qcgv.json b/advisories/unreviewed/2024/10/GHSA-8792-j7xc-qcgv/GHSA-8792-j7xc-qcgv.json index c9b332eea66..7cbff3abd6b 100644 --- a/advisories/unreviewed/2024/10/GHSA-8792-j7xc-qcgv/GHSA-8792-j7xc-qcgv.json +++ b/advisories/unreviewed/2024/10/GHSA-8792-j7xc-qcgv/GHSA-8792-j7xc-qcgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8792-j7xc-qcgv", - "modified": "2024-10-28T21:30:36Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:36Z", "aliases": [ "CVE-2024-44301" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-884x-p7qm-gq3f/GHSA-884x-p7qm-gq3f.json b/advisories/unreviewed/2024/10/GHSA-884x-p7qm-gq3f/GHSA-884x-p7qm-gq3f.json index 377956e6fa1..388d214fc33 100644 --- a/advisories/unreviewed/2024/10/GHSA-884x-p7qm-gq3f/GHSA-884x-p7qm-gq3f.json +++ b/advisories/unreviewed/2024/10/GHSA-884x-p7qm-gq3f/GHSA-884x-p7qm-gq3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-884x-p7qm-gq3f", - "modified": "2024-10-28T00:30:48Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-28T00:30:48Z", "aliases": [ "CVE-2024-50615" ], "details": "TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8c74-r7ww-5v4x/GHSA-8c74-r7ww-5v4x.json b/advisories/unreviewed/2024/10/GHSA-8c74-r7ww-5v4x/GHSA-8c74-r7ww-5v4x.json index aaf34c03472..07a57d015d5 100644 --- a/advisories/unreviewed/2024/10/GHSA-8c74-r7ww-5v4x/GHSA-8c74-r7ww-5v4x.json +++ b/advisories/unreviewed/2024/10/GHSA-8c74-r7ww-5v4x/GHSA-8c74-r7ww-5v4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c74-r7ww-5v4x", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-48178" ], "details": "newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json b/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json index 727bfa760f8..ccc966a7480 100644 --- a/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json +++ b/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8xq2-3cqg-9xfj", - "modified": "2024-10-30T18:30:48Z", + "modified": "2024-10-30T21:30:40Z", "published": "2024-10-30T18:30:48Z", "aliases": [ "CVE-2024-51258" ], "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T17:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-95jc-3vhv-3739/GHSA-95jc-3vhv-3739.json b/advisories/unreviewed/2024/10/GHSA-95jc-3vhv-3739/GHSA-95jc-3vhv-3739.json index 3b6c30795ff..361345dc3b1 100644 --- a/advisories/unreviewed/2024/10/GHSA-95jc-3vhv-3739/GHSA-95jc-3vhv-3739.json +++ b/advisories/unreviewed/2024/10/GHSA-95jc-3vhv-3739/GHSA-95jc-3vhv-3739.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95jc-3vhv-3739", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-48195" ], "details": "Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json b/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json index 8dc3dc00a8b..c0af811f854 100644 --- a/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json +++ b/advisories/unreviewed/2024/10/GHSA-9vq2-w47q-3pjh/GHSA-9vq2-w47q-3pjh.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json b/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json new file mode 100644 index 00000000000..b3c0c45e0aa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c68x-6hmf-xw2p", + "modified": "2024-10-30T21:30:41Z", + "published": "2024-10-30T21:30:41Z", + "aliases": [ + "CVE-2024-51425" + ], + "details": "Insecure Permissions vulnerability in Ethereum v.1.12.2 allows a remote attacker to escalate privileges via the WaterToken Contract.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51425" + }, + { + "type": "WEB", + "url": "https://github.com/Wzy-source/Gala/blob/main/CVEs/WaterToken_0x8890963266f895aca11fbe4679a1f9cc472f6531.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cq86-p348-qr4p/GHSA-cq86-p348-qr4p.json b/advisories/unreviewed/2024/10/GHSA-cq86-p348-qr4p/GHSA-cq86-p348-qr4p.json index a89d368bd72..e71307a7397 100644 --- a/advisories/unreviewed/2024/10/GHSA-cq86-p348-qr4p/GHSA-cq86-p348-qr4p.json +++ b/advisories/unreviewed/2024/10/GHSA-cq86-p348-qr4p/GHSA-cq86-p348-qr4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq86-p348-qr4p", - "modified": "2024-10-28T00:30:48Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-28T00:30:48Z", "aliases": [ "CVE-2024-50612" ], "details": "libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json b/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json index 71232c2ae2d..8e43cb34f90 100644 --- a/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json +++ b/advisories/unreviewed/2024/10/GHSA-cx83-mmj7-4ghv/GHSA-cx83-mmj7-4ghv.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-f729-m528-5h64/GHSA-f729-m528-5h64.json b/advisories/unreviewed/2024/10/GHSA-f729-m528-5h64/GHSA-f729-m528-5h64.json index 0b00d5201b9..395e92d455f 100644 --- a/advisories/unreviewed/2024/10/GHSA-f729-m528-5h64/GHSA-f729-m528-5h64.json +++ b/advisories/unreviewed/2024/10/GHSA-f729-m528-5h64/GHSA-f729-m528-5h64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f729-m528-5h64", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44264" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious app may be able to create symlinks to protected regions of the disk.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json b/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json new file mode 100644 index 00000000000..4d666507161 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7rc-79mv-v26v", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-51243" + ], + "details": "The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51243" + }, + { + "type": "WEB", + "url": "https://github.com/shadia0/Patienc/blob/main/eladmin_rce.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f8f6-24mj-36m7/GHSA-f8f6-24mj-36m7.json b/advisories/unreviewed/2024/10/GHSA-f8f6-24mj-36m7/GHSA-f8f6-24mj-36m7.json index 66429834848..58e29515c78 100644 --- a/advisories/unreviewed/2024/10/GHSA-f8f6-24mj-36m7/GHSA-f8f6-24mj-36m7.json +++ b/advisories/unreviewed/2024/10/GHSA-f8f6-24mj-36m7/GHSA-f8f6-24mj-36m7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8f6-24mj-36m7", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44269" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. A malicious app may use shortcuts to access restricted files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json b/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json new file mode 100644 index 00000000000..454b22a50af --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqq4-8x5p-9g5p", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48807" + ], + "details": "Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48807" + }, + { + "type": "WEB", + "url": "https://medium.com/%40KrishnaChaganti/cross-site-scripting-xss-in-appointment-management-system-cve-2024-48807-0f7523be9fa2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/doctor-appointment-management-system-using-php-and-mysql" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json b/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json index 22c30114238..fee31f78caa 100644 --- a/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json +++ b/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv52-m5w8-2242", - "modified": "2024-10-30T15:30:46Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-30T15:30:46Z", "aliases": [ "CVE-2024-51304" ], "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T13:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fvv3-x64f-px6p/GHSA-fvv3-x64f-px6p.json b/advisories/unreviewed/2024/10/GHSA-fvv3-x64f-px6p/GHSA-fvv3-x64f-px6p.json index 13d18a6d0d3..0e2e157d1e3 100644 --- a/advisories/unreviewed/2024/10/GHSA-fvv3-x64f-px6p/GHSA-fvv3-x64f-px6p.json +++ b/advisories/unreviewed/2024/10/GHSA-fvv3-x64f-px6p/GHSA-fvv3-x64f-px6p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fvv3-x64f-px6p", - "modified": "2024-10-16T09:30:31Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-16T09:30:31Z", "aliases": [ "CVE-2024-9061" diff --git a/advisories/unreviewed/2024/10/GHSA-fwvx-h53h-63j5/GHSA-fwvx-h53h-63j5.json b/advisories/unreviewed/2024/10/GHSA-fwvx-h53h-63j5/GHSA-fwvx-h53h-63j5.json index 427aecddcb9..89b218d19a7 100644 --- a/advisories/unreviewed/2024/10/GHSA-fwvx-h53h-63j5/GHSA-fwvx-h53h-63j5.json +++ b/advisories/unreviewed/2024/10/GHSA-fwvx-h53h-63j5/GHSA-fwvx-h53h-63j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fwvx-h53h-63j5", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-48196" ], "details": "An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json b/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json index cfb6b4a2761..593ee06758d 100644 --- a/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json +++ b/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-g8px-5pqf-j335/GHSA-g8px-5pqf-j335.json b/advisories/unreviewed/2024/10/GHSA-g8px-5pqf-j335/GHSA-g8px-5pqf-j335.json index 5634a1b5c0c..887aaa8bb8b 100644 --- a/advisories/unreviewed/2024/10/GHSA-g8px-5pqf-j335/GHSA-g8px-5pqf-j335.json +++ b/advisories/unreviewed/2024/10/GHSA-g8px-5pqf-j335/GHSA-g8px-5pqf-j335.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8px-5pqf-j335", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-42011" ], "details": "The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-ghqj-2wp8-298g/GHSA-ghqj-2wp8-298g.json b/advisories/unreviewed/2024/10/GHSA-ghqj-2wp8-298g/GHSA-ghqj-2wp8-298g.json index 014998cec7a..a9424d5211d 100644 --- a/advisories/unreviewed/2024/10/GHSA-ghqj-2wp8-298g/GHSA-ghqj-2wp8-298g.json +++ b/advisories/unreviewed/2024/10/GHSA-ghqj-2wp8-298g/GHSA-ghqj-2wp8-298g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghqj-2wp8-298g", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44273" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, visionOS 2.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious app may be able to access private information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gmjx-74cx-5p3f/GHSA-gmjx-74cx-5p3f.json b/advisories/unreviewed/2024/10/GHSA-gmjx-74cx-5p3f/GHSA-gmjx-74cx-5p3f.json index a35ee85ac61..6e05161af11 100644 --- a/advisories/unreviewed/2024/10/GHSA-gmjx-74cx-5p3f/GHSA-gmjx-74cx-5p3f.json +++ b/advisories/unreviewed/2024/10/GHSA-gmjx-74cx-5p3f/GHSA-gmjx-74cx-5p3f.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jjpr-6x73-f9v6/GHSA-jjpr-6x73-f9v6.json b/advisories/unreviewed/2024/10/GHSA-jjpr-6x73-f9v6/GHSA-jjpr-6x73-f9v6.json index 4c5194072e7..909b1852f60 100644 --- a/advisories/unreviewed/2024/10/GHSA-jjpr-6x73-f9v6/GHSA-jjpr-6x73-f9v6.json +++ b/advisories/unreviewed/2024/10/GHSA-jjpr-6x73-f9v6/GHSA-jjpr-6x73-f9v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjpr-6x73-f9v6", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44274" ], "details": "The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, watchOS 11.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access to a locked device may be able to view sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json b/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json new file mode 100644 index 00000000000..3380daa8baa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp7p-mxpw-mf6m", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-46531" + ], + "details": "phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46531" + }, + { + "type": "WEB", + "url": "https://github.com/shouvikdutta1998/Vehicle_Record_Management_System" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m7rv-mgxq-vxph/GHSA-m7rv-mgxq-vxph.json b/advisories/unreviewed/2024/10/GHSA-m7rv-mgxq-vxph/GHSA-m7rv-mgxq-vxph.json new file mode 100644 index 00000000000..c904e93b5b8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m7rv-mgxq-vxph/GHSA-m7rv-mgxq-vxph.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7rv-mgxq-vxph", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-10546" + ], + "details": "A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects unknown code of the file /api/sys/ng-alain/getDictItemsByTable/ of the component URL Handler. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10546" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282520" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282520" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.429033" + }, + { + "type": "WEB", + "url": "https://wiki.shikangsi.com/post/share/dfde9afc-8d64-4022-a6ca-3c1a323c5e66" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mpp2-2v83-ccjm/GHSA-mpp2-2v83-ccjm.json b/advisories/unreviewed/2024/10/GHSA-mpp2-2v83-ccjm/GHSA-mpp2-2v83-ccjm.json new file mode 100644 index 00000000000..3b0ddd9ae3e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mpp2-2v83-ccjm/GHSA-mpp2-2v83-ccjm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpp2-2v83-ccjm", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48735" + ], + "details": "Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48735" + }, + { + "type": "WEB", + "url": "https://github.com/ACN-CVEs/CVE-2024-48735/blob/67e86e12393650e1df16c845ceff487d016f31f0/LFI.pdf" + }, + { + "type": "WEB", + "url": "http://sas.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p5wf-4fg4-hw2q/GHSA-p5wf-4fg4-hw2q.json b/advisories/unreviewed/2024/10/GHSA-p5wf-4fg4-hw2q/GHSA-p5wf-4fg4-hw2q.json index b76d7714474..a7d1c18aad6 100644 --- a/advisories/unreviewed/2024/10/GHSA-p5wf-4fg4-hw2q/GHSA-p5wf-4fg4-hw2q.json +++ b/advisories/unreviewed/2024/10/GHSA-p5wf-4fg4-hw2q/GHSA-p5wf-4fg4-hw2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5wf-4fg4-hw2q", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44197" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious app may be able to cause a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-p9cw-g386-7q2x/GHSA-p9cw-g386-7q2x.json b/advisories/unreviewed/2024/10/GHSA-p9cw-g386-7q2x/GHSA-p9cw-g386-7q2x.json index 3582793319a..c70e9d5a845 100644 --- a/advisories/unreviewed/2024/10/GHSA-p9cw-g386-7q2x/GHSA-p9cw-g386-7q2x.json +++ b/advisories/unreviewed/2024/10/GHSA-p9cw-g386-7q2x/GHSA-p9cw-g386-7q2x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9cw-g386-7q2x", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44281" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. Parsing a file may lead to disclosure of user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pj8w-xcg3-82vx/GHSA-pj8w-xcg3-82vx.json b/advisories/unreviewed/2024/10/GHSA-pj8w-xcg3-82vx/GHSA-pj8w-xcg3-82vx.json index 43fa0f205b1..be006112878 100644 --- a/advisories/unreviewed/2024/10/GHSA-pj8w-xcg3-82vx/GHSA-pj8w-xcg3-82vx.json +++ b/advisories/unreviewed/2024/10/GHSA-pj8w-xcg3-82vx/GHSA-pj8w-xcg3-82vx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pj8w-xcg3-82vx", - "modified": "2024-10-28T00:30:48Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-28T00:30:48Z", "aliases": [ "CVE-2024-50610" ], "details": "GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pjhx-j53p-c5f5/GHSA-pjhx-j53p-c5f5.json b/advisories/unreviewed/2024/10/GHSA-pjhx-j53p-c5f5/GHSA-pjhx-j53p-c5f5.json new file mode 100644 index 00000000000..5654b8319ac --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pjhx-j53p-c5f5/GHSA-pjhx-j53p-c5f5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjhx-j53p-c5f5", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48112" + ], + "details": "A deserialization vulnerability in the component \\controller\\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48112" + }, + { + "type": "WEB", + "url": "https://github.com/nn0nkey/nn0nkey/blob/main/Thinkphp/CVE-2024-48112.md" + }, + { + "type": "WEB", + "url": "https://github.com/top-think/think" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json b/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json new file mode 100644 index 00000000000..d103caeaf96 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxm6-wc5v-cphj", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48202" + ], + "details": "icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48202" + }, + { + "type": "WEB", + "url": "https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-48202.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json b/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json index 0da49259838..903d23f8e73 100644 --- a/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json +++ b/advisories/unreviewed/2024/10/GHSA-qc88-643m-whjm/GHSA-qc88-643m-whjm.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json b/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json index bfdee14a8a3..de7b30c6680 100644 --- a/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json +++ b/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-r23x-v492-c286/GHSA-r23x-v492-c286.json b/advisories/unreviewed/2024/10/GHSA-r23x-v492-c286/GHSA-r23x-v492-c286.json new file mode 100644 index 00000000000..6d56e7c313b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r23x-v492-c286/GHSA-r23x-v492-c286.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r23x-v492-c286", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2023-52066" + ], + "details": "http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52066" + }, + { + "type": "WEB", + "url": "https://github.com/karlseguin/http.zig/issues/25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json b/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json index 9e146e9df50..dd7e45c6e66 100644 --- a/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json +++ b/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r39h-f84x-g77w", - "modified": "2024-10-25T21:31:28Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-25T21:31:28Z", "aliases": [ "CVE-2024-48233" ], "details": "mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \\app\\setting\\controller\\ApiAdminSetting.php via the ICP parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rj6f-j453-ffwx/GHSA-rj6f-j453-ffwx.json b/advisories/unreviewed/2024/10/GHSA-rj6f-j453-ffwx/GHSA-rj6f-j453-ffwx.json index b0cb3c1a9ba..969c5dc7b4b 100644 --- a/advisories/unreviewed/2024/10/GHSA-rj6f-j453-ffwx/GHSA-rj6f-j453-ffwx.json +++ b/advisories/unreviewed/2024/10/GHSA-rj6f-j453-ffwx/GHSA-rj6f-j453-ffwx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json b/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json index a3b32d54a5c..b4698765646 100644 --- a/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json +++ b/advisories/unreviewed/2024/10/GHSA-rmrx-hhmg-hqq9/GHSA-rmrx-hhmg-hqq9.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json b/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json new file mode 100644 index 00000000000..c95d7376d44 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq35-f7p2-6pp9", + "modified": "2024-10-30T21:30:41Z", + "published": "2024-10-30T21:30:41Z", + "aliases": [ + "CVE-2024-51427" + ], + "details": "An issue in Ethereum v.1.12.2 allows remote attacker to execute arbitrary code via the PepeGxng smart contract mint function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51427" + }, + { + "type": "WEB", + "url": "https://github.com/Wzy-source/Gala/blob/main/CVEs/PepeGxng_0x5d8d1f28cad84fad8d2fea9fdd4ab5022d23b0fe.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json b/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json new file mode 100644 index 00000000000..b5453af3241 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwqj-v7mx-c4x7", + "modified": "2024-10-30T21:30:40Z", + "published": "2024-10-30T21:30:40Z", + "aliases": [ + "CVE-2024-48271" + ], + "details": "D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48271" + }, + { + "type": "WEB", + "url": "https://gist.github.com/stevenyu113228/e264c145d6e6e6b59cf53fddc27409ad#1--predictable-administrator-credentials-in-d-link-dsl6740c-modem" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v52g-r6cw-2f8h/GHSA-v52g-r6cw-2f8h.json b/advisories/unreviewed/2024/10/GHSA-v52g-r6cw-2f8h/GHSA-v52g-r6cw-2f8h.json index 8b77c18f57b..85ec0ff3588 100644 --- a/advisories/unreviewed/2024/10/GHSA-v52g-r6cw-2f8h/GHSA-v52g-r6cw-2f8h.json +++ b/advisories/unreviewed/2024/10/GHSA-v52g-r6cw-2f8h/GHSA-v52g-r6cw-2f8h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v52g-r6cw-2f8h", - "modified": "2024-10-28T00:30:48Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-28T00:30:48Z", "aliases": [ "CVE-2024-50616" ], "details": "Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json b/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json index a93d0bc9a7a..95830f35e39 100644 --- a/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json +++ b/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v76h-6p79-mvh2", - "modified": "2024-10-30T15:30:47Z", + "modified": "2024-10-30T21:30:40Z", "published": "2024-10-30T15:30:47Z", "aliases": [ "CVE-2024-51301" ], "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T14:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json b/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json index c795a3fdd6e..f312bb72fcf 100644 --- a/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json +++ b/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpwg-6766-6xgp", - "modified": "2024-10-30T15:30:47Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-30T15:30:47Z", "aliases": [ "CVE-2024-51300" ], "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T14:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json b/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json index e09014bf3ae..bfd65b9a7eb 100644 --- a/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json +++ b/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-x2gv-fj8v-x2rx/GHSA-x2gv-fj8v-x2rx.json b/advisories/unreviewed/2024/10/GHSA-x2gv-fj8v-x2rx/GHSA-x2gv-fj8v-x2rx.json index 2fec6ff898b..cf6829960ea 100644 --- a/advisories/unreviewed/2024/10/GHSA-x2gv-fj8v-x2rx/GHSA-x2gv-fj8v-x2rx.json +++ b/advisories/unreviewed/2024/10/GHSA-x2gv-fj8v-x2rx/GHSA-x2gv-fj8v-x2rx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x2gv-fj8v-x2rx", - "modified": "2024-10-29T21:30:53Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-29T21:30:53Z", "aliases": [ "CVE-2024-48461" ], "details": "Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json b/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json new file mode 100644 index 00000000000..1ffebfd54f6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhx7-6233-wm3w", + "modified": "2024-10-30T21:30:41Z", + "published": "2024-10-30T21:30:41Z", + "aliases": [ + "CVE-2024-51426" + ], + "details": "Insecure Permissions vulnerability in Ethereum v.1.12.2 allows a remote attacker to escalate privileges via the _transfer function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51426" + }, + { + "type": "WEB", + "url": "https://github.com/Wzy-source/Gala/blob/main/CVEs/EOTT_0x5fe0971167215aade651f76492f8489e43ceb48a.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xpm9-95h9-q996/GHSA-xpm9-95h9-q996.json b/advisories/unreviewed/2024/10/GHSA-xpm9-95h9-q996/GHSA-xpm9-95h9-q996.json index f0c2ee2909c..77da5b5739b 100644 --- a/advisories/unreviewed/2024/10/GHSA-xpm9-95h9-q996/GHSA-xpm9-95h9-q996.json +++ b/advisories/unreviewed/2024/10/GHSA-xpm9-95h9-q996/GHSA-xpm9-95h9-q996.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xpm9-95h9-q996", - "modified": "2024-10-28T00:30:48Z", + "modified": "2024-10-30T21:30:38Z", "published": "2024-10-28T00:30:48Z", "aliases": [ "CVE-2024-50614" ], "details": "TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-27T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xr7f-32j7-5fh9/GHSA-xr7f-32j7-5fh9.json b/advisories/unreviewed/2024/10/GHSA-xr7f-32j7-5fh9/GHSA-xr7f-32j7-5fh9.json index af193313df8..bf87e72285e 100644 --- a/advisories/unreviewed/2024/10/GHSA-xr7f-32j7-5fh9/GHSA-xr7f-32j7-5fh9.json +++ b/advisories/unreviewed/2024/10/GHSA-xr7f-32j7-5fh9/GHSA-xr7f-32j7-5fh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr7f-32j7-5fh9", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T21:30:39Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44262" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in visionOS 2.1. A user may be able to view sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z"