Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-04 21:31:38 +00:00
parent ebfe02af98
commit 6e74dc3d8f
31 changed files with 480 additions and 62 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27q9-h529-q4g3",
"modified": "2023-12-24T09:30:19Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-24T09:30:19Z",
"aliases": [
"CVE-2023-51767"
],
"details": "OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-24T07:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3r3w-gg47-w53h",
"modified": "2023-12-28T09:30:19Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-28T09:30:19Z",
"aliases": [
"CVE-2023-50038"
],
"details": "There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-28T07:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4frw-j2v5-2xwf",
"modified": "2023-12-26T21:30:33Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-26T21:30:33Z",
"aliases": [
"CVE-2023-5931"
],
"details": "The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T19:15:08Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gj8-gj3v-ccw7",
"modified": "2023-12-21T15:30:32Z",
"modified": "2024-01-04T21:30:22Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-48116"
],
"details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-866h-q63m-66xm",
"modified": "2023-12-28T00:30:20Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-28T00:30:20Z",
"aliases": [
"CVE-2023-49000"
],
"details": "An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-27T22:15:16Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pxx-f34x-f793",
"modified": "2023-12-28T00:30:20Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-28T00:30:20Z",
"aliases": [
"CVE-2023-49003"
],
"details": "An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletools.dialer.activities.DialerActivity.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-27T22:15:16Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-997g-jcpq-8whg",
"modified": "2023-12-28T12:30:17Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-28T12:30:17Z",
"aliases": [
"CVE-2023-50874"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hr4-7jqw-c29q",
"modified": "2023-12-29T15:30:31Z",
"modified": "2024-01-04T21:30:24Z",
"published": "2023-12-29T09:30:26Z",
"aliases": [
"CVE-2023-32095"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mrh-3627-mg6x",
"modified": "2023-12-28T12:30:19Z",
"modified": "2024-01-04T21:30:24Z",
"published": "2023-12-28T12:30:19Z",
"aliases": [
"CVE-2023-50860"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vx6-546g-266v",
"modified": "2023-12-28T12:30:19Z",
"modified": "2024-01-04T21:30:24Z",
"published": "2023-12-28T12:30:19Z",
"aliases": [
"CVE-2023-50851"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgf4-3952-w724",
"modified": "2023-12-28T12:30:19Z",
"modified": "2024-01-04T21:30:24Z",
"published": "2023-12-28T12:30:19Z",
"aliases": [
"CVE-2023-50856"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crwg-2xph-4rc6",
"modified": "2023-12-28T00:30:20Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-28T00:30:20Z",
"aliases": [
"CVE-2023-49001"
],
"details": "An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gurry.kvbrowswer.webview component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-27T22:15:16Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gh6q-hg4q-mm5j",
"modified": "2023-12-26T21:30:33Z",
"modified": "2024-01-04T21:30:23Z",
"published": "2023-12-26T21:30:33Z",
"aliases": [
"CVE-2023-5674"
],
"details": "The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-26T19:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf57-3c97-v2x5",
"modified": "2023-12-28T12:30:18Z",
"modified": "2024-01-04T21:30:24Z",
"published": "2023-12-28T12:30:18Z",
"aliases": [
"CVE-2023-27447"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jvgh-f9m8-mh2r",
"modified": "2023-12-28T12:30:18Z",
"modified": "2024-01-04T21:30:24Z",
"published": "2023-12-28T12:30:18Z",
"aliases": [
"CVE-2023-32513"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfr4-4gq8-693m",
"modified": "2023-12-21T15:30:32Z",
"modified": "2024-01-04T21:30:22Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-48115"
],
"details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmhv-fq76-x3j5",
"modified": "2023-12-21T15:30:32Z",
"modified": "2024-01-04T21:30:22Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-48114"
],
"details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjjc-gg9m-vhv8",
"modified": "2023-12-21T15:30:33Z",
"modified": "2024-01-04T21:30:22Z",
"published": "2023-12-21T15:30:33Z",
"aliases": [
"CVE-2023-7047"
],
"details": "\nInadequate validation of permissions when employing remote tools and \nmacros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and \nearlier permits a user to initiate a connection without proper execution\n rights via the remote tools feature. This affects only SQL data sources.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:14Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"severity": "MODERATE",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More