From 6f63f2ffd3dd564d9fcd2ba4c6971818a7284f55 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 7 Aug 2024 03:32:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-25fr-px8w-jvcm.json | 38 +++++++++++++++++++ .../GHSA-2pv6-97qp-x25g.json | 38 +++++++++++++++++++ .../GHSA-3q83-hx7r-8c7j.json | 38 +++++++++++++++++++ .../GHSA-3vf4-qf7v-8hwx.json | 38 +++++++++++++++++++ .../GHSA-5647-wrp8-rxf7.json | 38 +++++++++++++++++++ .../GHSA-57rm-873m-whqg.json | 38 +++++++++++++++++++ .../GHSA-6jr4-fv3f-vmgp.json | 38 +++++++++++++++++++ .../GHSA-6rx3-26m6-vv5h.json | 38 +++++++++++++++++++ .../GHSA-6v5v-396j-6g9j.json | 38 +++++++++++++++++++ .../GHSA-7vcj-8223-g52v.json | 38 +++++++++++++++++++ .../GHSA-8x4g-vr4x-pqmm.json | 38 +++++++++++++++++++ .../GHSA-9hgf-f8w6-mwhq.json | 38 +++++++++++++++++++ .../GHSA-ccp2-8cqw-xhpw.json | 38 +++++++++++++++++++ .../GHSA-fgqh-mx4w-q7rr.json | 38 +++++++++++++++++++ .../GHSA-fvrj-2q48-p9w5.json | 38 +++++++++++++++++++ .../GHSA-gr3c-2gvw-hxhg.json | 38 +++++++++++++++++++ .../GHSA-hphg-jf8m-wgxp.json | 38 +++++++++++++++++++ .../GHSA-j4mv-2m42-3984.json | 38 +++++++++++++++++++ .../GHSA-j67v-m4j7-wgxq.json | 38 +++++++++++++++++++ .../GHSA-mhmv-7727-5cc5.json | 38 +++++++++++++++++++ .../GHSA-mp9p-4683-w5jr.json | 38 +++++++++++++++++++ .../GHSA-p7vm-6mxg-5x54.json | 38 +++++++++++++++++++ .../GHSA-qc23-x2qj-f28q.json | 38 +++++++++++++++++++ .../GHSA-qf2x-cq7r-8263.json | 38 +++++++++++++++++++ .../GHSA-qhmw-cw2v-9499.json | 38 +++++++++++++++++++ .../GHSA-rc9c-w737-83cm.json | 38 +++++++++++++++++++ .../GHSA-v554-w7jh-rvrh.json | 38 +++++++++++++++++++ .../GHSA-vfp6-x7cm-5rv2.json | 38 +++++++++++++++++++ .../GHSA-w2v4-6c2x-p3qm.json | 38 +++++++++++++++++++ .../GHSA-wch3-f7gr-m9gw.json | 38 +++++++++++++++++++ .../GHSA-wjhc-vfrr-5cgr.json | 38 +++++++++++++++++++ .../GHSA-wvw6-xx23-4vmp.json | 38 +++++++++++++++++++ .../GHSA-ww3m-j46v-9wf2.json | 38 +++++++++++++++++++ 33 files changed, 1254 insertions(+) create mode 100644 advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2pv6-97qp-x25g/GHSA-2pv6-97qp-x25g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3q83-hx7r-8c7j/GHSA-3q83-hx7r-8c7j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-57rm-873m-whqg/GHSA-57rm-873m-whqg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6rx3-26m6-vv5h/GHSA-6rx3-26m6-vv5h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8x4g-vr4x-pqmm/GHSA-8x4g-vr4x-pqmm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9hgf-f8w6-mwhq/GHSA-9hgf-f8w6-mwhq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fvrj-2q48-p9w5/GHSA-fvrj-2q48-p9w5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gr3c-2gvw-hxhg/GHSA-gr3c-2gvw-hxhg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j67v-m4j7-wgxq/GHSA-j67v-m4j7-wgxq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mhmv-7727-5cc5/GHSA-mhmv-7727-5cc5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mp9p-4683-w5jr/GHSA-mp9p-4683-w5jr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p7vm-6mxg-5x54/GHSA-p7vm-6mxg-5x54.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qc23-x2qj-f28q/GHSA-qc23-x2qj-f28q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v554-w7jh-rvrh/GHSA-v554-w7jh-rvrh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vfp6-x7cm-5rv2/GHSA-vfp6-x7cm-5rv2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wch3-f7gr-m9gw/GHSA-wch3-f7gr-m9gw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wjhc-vfrr-5cgr/GHSA-wjhc-vfrr-5cgr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wvw6-xx23-4vmp/GHSA-wvw6-xx23-4vmp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json diff --git a/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json b/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json new file mode 100644 index 00000000000..f3a4a4569e6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-25fr-px8w-jvcm/GHSA-25fr-px8w-jvcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25fr-px8w-jvcm", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34633" + ], + "details": "Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34633" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2pv6-97qp-x25g/GHSA-2pv6-97qp-x25g.json b/advisories/unreviewed/2024/08/GHSA-2pv6-97qp-x25g/GHSA-2pv6-97qp-x25g.json new file mode 100644 index 00000000000..32e94ed9dab --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2pv6-97qp-x25g/GHSA-2pv6-97qp-x25g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pv6-97qp-x25g", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34620" + ], + "details": "Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34620" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3q83-hx7r-8c7j/GHSA-3q83-hx7r-8c7j.json b/advisories/unreviewed/2024/08/GHSA-3q83-hx7r-8c7j/GHSA-3q83-hx7r-8c7j.json new file mode 100644 index 00000000000..137846e7a2e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3q83-hx7r-8c7j/GHSA-3q83-hx7r-8c7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q83-hx7r-8c7j", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34606" + ], + "details": "Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34606" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json b/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json new file mode 100644 index 00000000000..703fe7ce581 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3vf4-qf7v-8hwx/GHSA-3vf4-qf7v-8hwx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vf4-qf7v-8hwx", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34632" + ], + "details": "Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34632" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json b/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json new file mode 100644 index 00000000000..aa7907cc053 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5647-wrp8-rxf7/GHSA-5647-wrp8-rxf7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5647-wrp8-rxf7", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34630" + ], + "details": "Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34630" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-57rm-873m-whqg/GHSA-57rm-873m-whqg.json b/advisories/unreviewed/2024/08/GHSA-57rm-873m-whqg/GHSA-57rm-873m-whqg.json new file mode 100644 index 00000000000..ff64380bc89 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-57rm-873m-whqg/GHSA-57rm-873m-whqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57rm-873m-whqg", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34607" + ], + "details": "Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34607" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json b/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json new file mode 100644 index 00000000000..af547464743 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6jr4-fv3f-vmgp/GHSA-6jr4-fv3f-vmgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jr4-fv3f-vmgp", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34631" + ], + "details": "Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34631" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6rx3-26m6-vv5h/GHSA-6rx3-26m6-vv5h.json b/advisories/unreviewed/2024/08/GHSA-6rx3-26m6-vv5h/GHSA-6rx3-26m6-vv5h.json new file mode 100644 index 00000000000..7ad4a8ec141 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6rx3-26m6-vv5h/GHSA-6rx3-26m6-vv5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rx3-26m6-vv5h", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34605" + ], + "details": "Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34605" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json b/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json new file mode 100644 index 00000000000..123766614d3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6v5v-396j-6g9j/GHSA-6v5v-396j-6g9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v5v-396j-6g9j", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34627" + ], + "details": "Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34627" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json b/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json new file mode 100644 index 00000000000..7f3a3cddc39 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7vcj-8223-g52v/GHSA-7vcj-8223-g52v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vcj-8223-g52v", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34628" + ], + "details": "Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34628" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8x4g-vr4x-pqmm/GHSA-8x4g-vr4x-pqmm.json b/advisories/unreviewed/2024/08/GHSA-8x4g-vr4x-pqmm/GHSA-8x4g-vr4x-pqmm.json new file mode 100644 index 00000000000..b760e8f5920 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8x4g-vr4x-pqmm/GHSA-8x4g-vr4x-pqmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x4g-vr4x-pqmm", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34608" + ], + "details": "Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34608" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9hgf-f8w6-mwhq/GHSA-9hgf-f8w6-mwhq.json b/advisories/unreviewed/2024/08/GHSA-9hgf-f8w6-mwhq/GHSA-9hgf-f8w6-mwhq.json new file mode 100644 index 00000000000..d0af73d0cff --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9hgf-f8w6-mwhq/GHSA-9hgf-f8w6-mwhq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hgf-f8w6-mwhq", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34618" + ], + "details": "Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34618" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json b/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json new file mode 100644 index 00000000000..5e59435dd13 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ccp2-8cqw-xhpw/GHSA-ccp2-8cqw-xhpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccp2-8cqw-xhpw", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34623" + ], + "details": "Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34623" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json b/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json new file mode 100644 index 00000000000..e5b7c53806a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fgqh-mx4w-q7rr/GHSA-fgqh-mx4w-q7rr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgqh-mx4w-q7rr", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34629" + ], + "details": "Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34629" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fvrj-2q48-p9w5/GHSA-fvrj-2q48-p9w5.json b/advisories/unreviewed/2024/08/GHSA-fvrj-2q48-p9w5/GHSA-fvrj-2q48-p9w5.json new file mode 100644 index 00000000000..c54c4ba311f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fvrj-2q48-p9w5/GHSA-fvrj-2q48-p9w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvrj-2q48-p9w5", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34616" + ], + "details": "Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34616" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gr3c-2gvw-hxhg/GHSA-gr3c-2gvw-hxhg.json b/advisories/unreviewed/2024/08/GHSA-gr3c-2gvw-hxhg/GHSA-gr3c-2gvw-hxhg.json new file mode 100644 index 00000000000..b19ab4f42df --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gr3c-2gvw-hxhg/GHSA-gr3c-2gvw-hxhg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr3c-2gvw-hxhg", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34610" + ], + "details": "Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34610" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json b/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json new file mode 100644 index 00000000000..c212639152f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hphg-jf8m-wgxp/GHSA-hphg-jf8m-wgxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hphg-jf8m-wgxp", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34635" + ], + "details": "Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34635" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json b/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json new file mode 100644 index 00000000000..81202fb5611 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j4mv-2m42-3984/GHSA-j4mv-2m42-3984.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4mv-2m42-3984", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34634" + ], + "details": "Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34634" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j67v-m4j7-wgxq/GHSA-j67v-m4j7-wgxq.json b/advisories/unreviewed/2024/08/GHSA-j67v-m4j7-wgxq/GHSA-j67v-m4j7-wgxq.json new file mode 100644 index 00000000000..ed0f53a3094 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j67v-m4j7-wgxq/GHSA-j67v-m4j7-wgxq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j67v-m4j7-wgxq", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34609" + ], + "details": "Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34609" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mhmv-7727-5cc5/GHSA-mhmv-7727-5cc5.json b/advisories/unreviewed/2024/08/GHSA-mhmv-7727-5cc5/GHSA-mhmv-7727-5cc5.json new file mode 100644 index 00000000000..0cbc95567c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mhmv-7727-5cc5/GHSA-mhmv-7727-5cc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhmv-7727-5cc5", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34617" + ], + "details": "Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34617" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mp9p-4683-w5jr/GHSA-mp9p-4683-w5jr.json b/advisories/unreviewed/2024/08/GHSA-mp9p-4683-w5jr/GHSA-mp9p-4683-w5jr.json new file mode 100644 index 00000000000..5d19b4ede81 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mp9p-4683-w5jr/GHSA-mp9p-4683-w5jr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp9p-4683-w5jr", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34615" + ], + "details": "Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34615" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p7vm-6mxg-5x54/GHSA-p7vm-6mxg-5x54.json b/advisories/unreviewed/2024/08/GHSA-p7vm-6mxg-5x54/GHSA-p7vm-6mxg-5x54.json new file mode 100644 index 00000000000..5f54bc6a892 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p7vm-6mxg-5x54/GHSA-p7vm-6mxg-5x54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7vm-6mxg-5x54", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34636" + ], + "details": "Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34636" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qc23-x2qj-f28q/GHSA-qc23-x2qj-f28q.json b/advisories/unreviewed/2024/08/GHSA-qc23-x2qj-f28q/GHSA-qc23-x2qj-f28q.json new file mode 100644 index 00000000000..14f3c55e1c8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qc23-x2qj-f28q/GHSA-qc23-x2qj-f28q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc23-x2qj-f28q", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34614" + ], + "details": "Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34614" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json b/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json new file mode 100644 index 00000000000..3ee559e27a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qf2x-cq7r-8263/GHSA-qf2x-cq7r-8263.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf2x-cq7r-8263", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34625" + ], + "details": "Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34625" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json b/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json new file mode 100644 index 00000000000..94b94a3a90e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qhmw-cw2v-9499/GHSA-qhmw-cw2v-9499.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhmw-cw2v-9499", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34624" + ], + "details": "Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34624" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json b/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json new file mode 100644 index 00000000000..2d7639a541b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rc9c-w737-83cm/GHSA-rc9c-w737-83cm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc9c-w737-83cm", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34626" + ], + "details": "Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34626" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v554-w7jh-rvrh/GHSA-v554-w7jh-rvrh.json b/advisories/unreviewed/2024/08/GHSA-v554-w7jh-rvrh/GHSA-v554-w7jh-rvrh.json new file mode 100644 index 00000000000..94d7558a00f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v554-w7jh-rvrh/GHSA-v554-w7jh-rvrh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v554-w7jh-rvrh", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34611" + ], + "details": "Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34611" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vfp6-x7cm-5rv2/GHSA-vfp6-x7cm-5rv2.json b/advisories/unreviewed/2024/08/GHSA-vfp6-x7cm-5rv2/GHSA-vfp6-x7cm-5rv2.json new file mode 100644 index 00000000000..b029c8c9793 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vfp6-x7cm-5rv2/GHSA-vfp6-x7cm-5rv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfp6-x7cm-5rv2", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34612" + ], + "details": "Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34612" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json b/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json new file mode 100644 index 00000000000..2e0c7cd0a9c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w2v4-6c2x-p3qm/GHSA-w2v4-6c2x-p3qm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2v4-6c2x-p3qm", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34622" + ], + "details": "Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34622" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wch3-f7gr-m9gw/GHSA-wch3-f7gr-m9gw.json b/advisories/unreviewed/2024/08/GHSA-wch3-f7gr-m9gw/GHSA-wch3-f7gr-m9gw.json new file mode 100644 index 00000000000..12d72a7157f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wch3-f7gr-m9gw/GHSA-wch3-f7gr-m9gw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wch3-f7gr-m9gw", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34619" + ], + "details": "Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34619" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wjhc-vfrr-5cgr/GHSA-wjhc-vfrr-5cgr.json b/advisories/unreviewed/2024/08/GHSA-wjhc-vfrr-5cgr/GHSA-wjhc-vfrr-5cgr.json new file mode 100644 index 00000000000..b2b194f466e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wjhc-vfrr-5cgr/GHSA-wjhc-vfrr-5cgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjhc-vfrr-5cgr", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34613" + ], + "details": "Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34613" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wvw6-xx23-4vmp/GHSA-wvw6-xx23-4vmp.json b/advisories/unreviewed/2024/08/GHSA-wvw6-xx23-4vmp/GHSA-wvw6-xx23-4vmp.json new file mode 100644 index 00000000000..d148933818d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wvw6-xx23-4vmp/GHSA-wvw6-xx23-4vmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvw6-xx23-4vmp", + "modified": "2024-08-07T03:31:27Z", + "published": "2024-08-07T03:31:27Z", + "aliases": [ + "CVE-2024-34604" + ], + "details": "Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34604" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json b/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json new file mode 100644 index 00000000000..e6033d6a4d6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ww3m-j46v-9wf2/GHSA-ww3m-j46v-9wf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww3m-j46v-9wf2", + "modified": "2024-08-07T03:31:28Z", + "published": "2024-08-07T03:31:28Z", + "aliases": [ + "CVE-2024-34621" + ], + "details": "Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34621" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T02:15:38Z" + } +} \ No newline at end of file