diff --git a/advisories/unreviewed/2024/03/GHSA-2x3m-8px8-74hr/GHSA-2x3m-8px8-74hr.json b/advisories/unreviewed/2024/03/GHSA-2x3m-8px8-74hr/GHSA-2x3m-8px8-74hr.json index aeb08c2f47b..2bdd01e7682 100644 --- a/advisories/unreviewed/2024/03/GHSA-2x3m-8px8-74hr/GHSA-2x3m-8px8-74hr.json +++ b/advisories/unreviewed/2024/03/GHSA-2x3m-8px8-74hr/GHSA-2x3m-8px8-74hr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-75" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json b/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json index 613e1957710..09aa3061422 100644 --- a/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json +++ b/advisories/unreviewed/2024/03/GHSA-c6qx-hfcq-g673/GHSA-c6qx-hfcq-g673.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6qx-hfcq-g673", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-03-20T15:32:47Z", "aliases": [ "CVE-2024-28584" ], "details": "Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the J2KImageToFIBITMAP() function when reading images in J2K format.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T06:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c739-p55r-6fq2/GHSA-c739-p55r-6fq2.json b/advisories/unreviewed/2024/03/GHSA-c739-p55r-6fq2/GHSA-c739-p55r-6fq2.json index 940bcc98092..71fb466db55 100644 --- a/advisories/unreviewed/2024/03/GHSA-c739-p55r-6fq2/GHSA-c739-p55r-6fq2.json +++ b/advisories/unreviewed/2024/03/GHSA-c739-p55r-6fq2/GHSA-c739-p55r-6fq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c739-p55r-6fq2", - "modified": "2024-03-18T15:30:50Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-03-18T15:30:49Z", "aliases": [ "CVE-2024-28547" ], "details": "Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T14:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cfx4-q2wp-rc2c/GHSA-cfx4-q2wp-rc2c.json b/advisories/unreviewed/2024/03/GHSA-cfx4-q2wp-rc2c/GHSA-cfx4-q2wp-rc2c.json index 076aced8bc9..cbedbc15ff7 100644 --- a/advisories/unreviewed/2024/03/GHSA-cfx4-q2wp-rc2c/GHSA-cfx4-q2wp-rc2c.json +++ b/advisories/unreviewed/2024/03/GHSA-cfx4-q2wp-rc2c/GHSA-cfx4-q2wp-rc2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfx4-q2wp-rc2c", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20029" ], "details": "In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477406; Issue ID: MSV-1010.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2wv3-6pw9-m6hw/GHSA-2wv3-6pw9-m6hw.json b/advisories/unreviewed/2024/04/GHSA-2wv3-6pw9-m6hw/GHSA-2wv3-6pw9-m6hw.json index 68203b8eaef..203025a8b18 100644 --- a/advisories/unreviewed/2024/04/GHSA-2wv3-6pw9-m6hw/GHSA-2wv3-6pw9-m6hw.json +++ b/advisories/unreviewed/2024/04/GHSA-2wv3-6pw9-m6hw/GHSA-2wv3-6pw9-m6hw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-33qx-4qqq-fc86/GHSA-33qx-4qqq-fc86.json b/advisories/unreviewed/2024/04/GHSA-33qx-4qqq-fc86/GHSA-33qx-4qqq-fc86.json index 8d1c700d1a1..e29496879a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-33qx-4qqq-fc86/GHSA-33qx-4qqq-fc86.json +++ b/advisories/unreviewed/2024/04/GHSA-33qx-4qqq-fc86/GHSA-33qx-4qqq-fc86.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json b/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json index 9c9b0fda7b1..2ba877886fc 100644 --- a/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json +++ b/advisories/unreviewed/2024/04/GHSA-64qx-rv33-fw3r/GHSA-64qx-rv33-fw3r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64qx-rv33-fw3r", - "modified": "2024-04-06T21:30:35Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-04-06T21:30:35Z", "aliases": [ "CVE-2024-28741" ], "details": "Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-06T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-69jm-3pf7-932c/GHSA-69jm-3pf7-932c.json b/advisories/unreviewed/2024/04/GHSA-69jm-3pf7-932c/GHSA-69jm-3pf7-932c.json index cbd0c72872c..8d298f2246c 100644 --- a/advisories/unreviewed/2024/04/GHSA-69jm-3pf7-932c/GHSA-69jm-3pf7-932c.json +++ b/advisories/unreviewed/2024/04/GHSA-69jm-3pf7-932c/GHSA-69jm-3pf7-932c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-cj2r-9qx3-cf53/GHSA-cj2r-9qx3-cf53.json b/advisories/unreviewed/2024/04/GHSA-cj2r-9qx3-cf53/GHSA-cj2r-9qx3-cf53.json index bf26febdd3e..b44eb763149 100644 --- a/advisories/unreviewed/2024/04/GHSA-cj2r-9qx3-cf53/GHSA-cj2r-9qx3-cf53.json +++ b/advisories/unreviewed/2024/04/GHSA-cj2r-9qx3-cf53/GHSA-cj2r-9qx3-cf53.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json b/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json index c4270a1fc04..189d26be98b 100644 --- a/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json +++ b/advisories/unreviewed/2024/04/GHSA-h458-4c82-j96q/GHSA-h458-4c82-j96q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h458-4c82-j96q", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52539" ], "details": "Permission verification vulnerability in the Settings module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m67v-rhjq-4r57/GHSA-m67v-rhjq-4r57.json b/advisories/unreviewed/2024/04/GHSA-m67v-rhjq-4r57/GHSA-m67v-rhjq-4r57.json index 2433a7eeb24..2749f3cfc8f 100644 --- a/advisories/unreviewed/2024/04/GHSA-m67v-rhjq-4r57/GHSA-m67v-rhjq-4r57.json +++ b/advisories/unreviewed/2024/04/GHSA-m67v-rhjq-4r57/GHSA-m67v-rhjq-4r57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m67v-rhjq-4r57", - "modified": "2024-05-05T18:30:33Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-04-30T15:30:37Z", "aliases": [ "CVE-2024-33308" ], "details": "An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact Feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json b/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json index 9ae5c2c65b6..e256d533f5f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json +++ b/advisories/unreviewed/2024/04/GHSA-pxfw-cxx3-vxv8/GHSA-pxfw-cxx3-vxv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxfw-cxx3-vxv8", - "modified": "2024-04-08T15:30:32Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-04-08T15:30:32Z", "aliases": [ "CVE-2024-28066" ], "details": "In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1391" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json b/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json index 12208ef882f..c1cee5f91bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json +++ b/advisories/unreviewed/2024/04/GHSA-r8hh-gm8p-9j5x/GHSA-r8hh-gm8p-9j5x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8hh-gm8p-9j5x", - "modified": "2024-04-26T00:30:35Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-04-26T00:30:35Z", "aliases": [ "CVE-2024-31610" ], "details": "File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-25T22:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-42xq-25q2-4fv9/GHSA-42xq-25q2-4fv9.json b/advisories/unreviewed/2024/05/GHSA-42xq-25q2-4fv9/GHSA-42xq-25q2-4fv9.json index cc0982f40bf..bc3a0f375f6 100644 --- a/advisories/unreviewed/2024/05/GHSA-42xq-25q2-4fv9/GHSA-42xq-25q2-4fv9.json +++ b/advisories/unreviewed/2024/05/GHSA-42xq-25q2-4fv9/GHSA-42xq-25q2-4fv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42xq-25q2-4fv9", - "modified": "2024-05-22T18:30:40Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-22T18:30:40Z", "aliases": [ "CVE-2024-33228" ], "details": "An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T16:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4m89-pj37-27gm/GHSA-4m89-pj37-27gm.json b/advisories/unreviewed/2024/05/GHSA-4m89-pj37-27gm/GHSA-4m89-pj37-27gm.json index e03fb3989a3..0d897908dd9 100644 --- a/advisories/unreviewed/2024/05/GHSA-4m89-pj37-27gm/GHSA-4m89-pj37-27gm.json +++ b/advisories/unreviewed/2024/05/GHSA-4m89-pj37-27gm/GHSA-4m89-pj37-27gm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4m89-pj37-27gm", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-30801" ], "details": "SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:23:52Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4qq8-w3q5-56jf/GHSA-4qq8-w3q5-56jf.json b/advisories/unreviewed/2024/05/GHSA-4qq8-w3q5-56jf/GHSA-4qq8-w3q5-56jf.json index e79314ce7a4..5ed604cde69 100644 --- a/advisories/unreviewed/2024/05/GHSA-4qq8-w3q5-56jf/GHSA-4qq8-w3q5-56jf.json +++ b/advisories/unreviewed/2024/05/GHSA-4qq8-w3q5-56jf/GHSA-4qq8-w3q5-56jf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qq8-w3q5-56jf", - "modified": "2024-05-31T06:30:28Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-31T06:30:28Z", "aliases": [ "CVE-2024-36246" ], "details": "Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch \"20240527\" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-31T06:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-79f2-582m-m8p8/GHSA-79f2-582m-m8p8.json b/advisories/unreviewed/2024/05/GHSA-79f2-582m-m8p8/GHSA-79f2-582m-m8p8.json index e93b209f51c..2200ac60230 100644 --- a/advisories/unreviewed/2024/05/GHSA-79f2-582m-m8p8/GHSA-79f2-582m-m8p8.json +++ b/advisories/unreviewed/2024/05/GHSA-79f2-582m-m8p8/GHSA-79f2-582m-m8p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79f2-582m-m8p8", - "modified": "2024-05-01T21:30:37Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-01T21:30:37Z", "aliases": [ "CVE-2024-25458" ], "details": "An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0903 allows a remote attacker to obtain sensitive information via a crafted request to a UDP port.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json b/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json index f6197cdc16d..fb50547ded5 100644 --- a/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json +++ b/advisories/unreviewed/2024/05/GHSA-c39h-h953-m887/GHSA-c39h-h953-m887.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c39h-h953-m887", - "modified": "2024-05-20T18:31:22Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-20T18:31:22Z", "aliases": [ "CVE-2024-34948" ], "details": "An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to cause a Denial of Service (DoS) when attempting to make TCP connections.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json b/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json index 2a8170d2e41..6771259149d 100644 --- a/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json +++ b/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx9m-x7w8-76m2", - "modified": "2024-05-22T15:31:01Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-22T15:31:01Z", "aliases": [ "CVE-2024-33220" ], "details": "An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-782" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T15:15:28Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json b/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json index 350ef309f81..bafa308f56f 100644 --- a/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json +++ b/advisories/unreviewed/2024/05/GHSA-m82c-2r7m-qgcj/GHSA-m82c-2r7m-qgcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m82c-2r7m-qgcj", - "modified": "2024-05-18T00:30:40Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-05-15T18:30:36Z", "aliases": [ "CVE-2024-25743" ], "details": "In the Linux kernel through 6.7.2, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T18:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json b/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json index 1b54cf25902..0adeb7ff28d 100644 --- a/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json +++ b/advisories/unreviewed/2024/06/GHSA-6q7g-3wxj-hvcw/GHSA-6q7g-3wxj-hvcw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-89" + "CWE-89", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8wgj-qwf7-w6vx/GHSA-8wgj-qwf7-w6vx.json b/advisories/unreviewed/2024/06/GHSA-8wgj-qwf7-w6vx/GHSA-8wgj-qwf7-w6vx.json index b8688b72285..484c671f340 100644 --- a/advisories/unreviewed/2024/06/GHSA-8wgj-qwf7-w6vx/GHSA-8wgj-qwf7-w6vx.json +++ b/advisories/unreviewed/2024/06/GHSA-8wgj-qwf7-w6vx/GHSA-8wgj-qwf7-w6vx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wgj-qwf7-w6vx", - "modified": "2024-06-07T15:30:40Z", + "modified": "2024-08-15T18:31:43Z", "published": "2024-06-07T15:30:40Z", "aliases": [ "CVE-2024-36789" ], "details": "An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-521" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T15:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c224-2hcr-f33x/GHSA-c224-2hcr-f33x.json b/advisories/unreviewed/2024/06/GHSA-c224-2hcr-f33x/GHSA-c224-2hcr-f33x.json index 57f0a22bccc..5ea022d7a17 100644 --- a/advisories/unreviewed/2024/06/GHSA-c224-2hcr-f33x/GHSA-c224-2hcr-f33x.json +++ b/advisories/unreviewed/2024/06/GHSA-c224-2hcr-f33x/GHSA-c224-2hcr-f33x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c224-2hcr-f33x", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32917" ], "details": "In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gx3x-r4gq-w2r8/GHSA-gx3x-r4gq-w2r8.json b/advisories/unreviewed/2024/06/GHSA-gx3x-r4gq-w2r8/GHSA-gx3x-r4gq-w2r8.json index f44913f1d8e..2a693c5a99b 100644 --- a/advisories/unreviewed/2024/06/GHSA-gx3x-r4gq-w2r8/GHSA-gx3x-r4gq-w2r8.json +++ b/advisories/unreviewed/2024/06/GHSA-gx3x-r4gq-w2r8/GHSA-gx3x-r4gq-w2r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx3x-r4gq-w2r8", - "modified": "2024-06-17T00:31:07Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-06-17T00:31:07Z", "aliases": [ "CVE-2024-6041" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-r4hf-xj4x-88wm/GHSA-r4hf-xj4x-88wm.json b/advisories/unreviewed/2024/06/GHSA-r4hf-xj4x-88wm/GHSA-r4hf-xj4x-88wm.json index 09ddf3fce80..3534a85f3d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-r4hf-xj4x-88wm/GHSA-r4hf-xj4x-88wm.json +++ b/advisories/unreviewed/2024/06/GHSA-r4hf-xj4x-88wm/GHSA-r4hf-xj4x-88wm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-rwwf-8mqh-966g/GHSA-rwwf-8mqh-966g.json b/advisories/unreviewed/2024/06/GHSA-rwwf-8mqh-966g/GHSA-rwwf-8mqh-966g.json index 156902b200c..18c885e71a9 100644 --- a/advisories/unreviewed/2024/06/GHSA-rwwf-8mqh-966g/GHSA-rwwf-8mqh-966g.json +++ b/advisories/unreviewed/2024/06/GHSA-rwwf-8mqh-966g/GHSA-rwwf-8mqh-966g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwwf-8mqh-966g", - "modified": "2024-06-17T00:31:07Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-06-17T00:31:07Z", "aliases": [ "CVE-2024-6042" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/07/GHSA-3p5v-9pqp-m2pp/GHSA-3p5v-9pqp-m2pp.json b/advisories/unreviewed/2024/07/GHSA-3p5v-9pqp-m2pp/GHSA-3p5v-9pqp-m2pp.json index 61f2ae9464e..3a2ff5af222 100644 --- a/advisories/unreviewed/2024/07/GHSA-3p5v-9pqp-m2pp/GHSA-3p5v-9pqp-m2pp.json +++ b/advisories/unreviewed/2024/07/GHSA-3p5v-9pqp-m2pp/GHSA-3p5v-9pqp-m2pp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p5v-9pqp-m2pp", - "modified": "2024-07-01T15:32:36Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-01T15:32:36Z", "aliases": [ "CVE-2024-6050" ], "details": "Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:Green" diff --git a/advisories/unreviewed/2024/07/GHSA-47wg-8627-3f57/GHSA-47wg-8627-3f57.json b/advisories/unreviewed/2024/07/GHSA-47wg-8627-3f57/GHSA-47wg-8627-3f57.json index 76909e5022d..306e84b9978 100644 --- a/advisories/unreviewed/2024/07/GHSA-47wg-8627-3f57/GHSA-47wg-8627-3f57.json +++ b/advisories/unreviewed/2024/07/GHSA-47wg-8627-3f57/GHSA-47wg-8627-3f57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47wg-8627-3f57", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40806" ], "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing a maliciously crafted file may lead to unexpected app termination.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -85,9 +88,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json b/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json index c4d78e56748..68b0df6f222 100644 --- a/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json +++ b/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-552v-q4m3-2x72", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40786" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6hq7-9r57-p64g/GHSA-6hq7-9r57-p64g.json b/advisories/unreviewed/2024/07/GHSA-6hq7-9r57-p64g/GHSA-6hq7-9r57-p64g.json index 3b6d3cac138..05aa17e05d5 100644 --- a/advisories/unreviewed/2024/07/GHSA-6hq7-9r57-p64g/GHSA-6hq7-9r57-p64g.json +++ b/advisories/unreviewed/2024/07/GHSA-6hq7-9r57-p64g/GHSA-6hq7-9r57-p64g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hq7-9r57-p64g", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40785" ], "details": "This issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to a cross site scripting attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -77,9 +80,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json b/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json index 6b45ded606b..444a1bebe9f 100644 --- a/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json +++ b/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j6x-9hgr-mv7c", - "modified": "2024-08-13T18:31:13Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40779" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -81,9 +84,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8959-rwwf-97hm/GHSA-8959-rwwf-97hm.json b/advisories/unreviewed/2024/07/GHSA-8959-rwwf-97hm/GHSA-8959-rwwf-97hm.json index 6d3c2ce5286..9c26fe897d2 100644 --- a/advisories/unreviewed/2024/07/GHSA-8959-rwwf-97hm/GHSA-8959-rwwf-97hm.json +++ b/advisories/unreviewed/2024/07/GHSA-8959-rwwf-97hm/GHSA-8959-rwwf-97hm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8959-rwwf-97hm", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40817" ], "details": "The issue was addressed with improved UI handling. This issue is fixed in macOS Sonoma 14.6, Safari 17.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9pqp-f42q-m2gc/GHSA-9pqp-f42q-m2gc.json b/advisories/unreviewed/2024/07/GHSA-9pqp-f42q-m2gc/GHSA-9pqp-f42q-m2gc.json index 394ee41eee0..73a65bfa350 100644 --- a/advisories/unreviewed/2024/07/GHSA-9pqp-f42q-m2gc/GHSA-9pqp-f42q-m2gc.json +++ b/advisories/unreviewed/2024/07/GHSA-9pqp-f42q-m2gc/GHSA-9pqp-f42q-m2gc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9pqp-f42q-m2gc", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40809" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, visionOS 1.3, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -79,7 +82,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c4vv-jj8j-5j6c/GHSA-c4vv-jj8j-5j6c.json b/advisories/unreviewed/2024/07/GHSA-c4vv-jj8j-5j6c/GHSA-c4vv-jj8j-5j6c.json index db01b6d9362..4e59c8101ca 100644 --- a/advisories/unreviewed/2024/07/GHSA-c4vv-jj8j-5j6c/GHSA-c4vv-jj8j-5j6c.json +++ b/advisories/unreviewed/2024/07/GHSA-c4vv-jj8j-5j6c/GHSA-c4vv-jj8j-5j6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4vv-jj8j-5j6c", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40823" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-f6gg-484j-ch5h/GHSA-f6gg-484j-ch5h.json b/advisories/unreviewed/2024/07/GHSA-f6gg-484j-ch5h/GHSA-f6gg-484j-ch5h.json index 112012553d7..73e1aab1ffb 100644 --- a/advisories/unreviewed/2024/07/GHSA-f6gg-484j-ch5h/GHSA-f6gg-484j-ch5h.json +++ b/advisories/unreviewed/2024/07/GHSA-f6gg-484j-ch5h/GHSA-f6gg-484j-ch5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6gg-484j-ch5h", - "modified": "2024-07-01T15:32:36Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-01T15:32:36Z", "aliases": [ "CVE-2024-38953" ], "details": "phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T14:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g4wx-99hh-6pg8/GHSA-g4wx-99hh-6pg8.json b/advisories/unreviewed/2024/07/GHSA-g4wx-99hh-6pg8/GHSA-g4wx-99hh-6pg8.json index 2ea8a0e3169..8155d1f43ca 100644 --- a/advisories/unreviewed/2024/07/GHSA-g4wx-99hh-6pg8/GHSA-g4wx-99hh-6pg8.json +++ b/advisories/unreviewed/2024/07/GHSA-g4wx-99hh-6pg8/GHSA-g4wx-99hh-6pg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g4wx-99hh-6pg8", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40818" ], "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. An attacker with physical access may be able to use Siri to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-h2w2-6422-x7h5/GHSA-h2w2-6422-x7h5.json b/advisories/unreviewed/2024/07/GHSA-h2w2-6422-x7h5/GHSA-h2w2-6422-x7h5.json index 4bb5f7f6e28..49cdf2e7e1c 100644 --- a/advisories/unreviewed/2024/07/GHSA-h2w2-6422-x7h5/GHSA-h2w2-6422-x7h5.json +++ b/advisories/unreviewed/2024/07/GHSA-h2w2-6422-x7h5/GHSA-h2w2-6422-x7h5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2w2-6422-x7h5", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40812" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, visionOS 1.3, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -79,7 +82,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j4fg-qq64-7f65/GHSA-j4fg-qq64-7f65.json b/advisories/unreviewed/2024/07/GHSA-j4fg-qq64-7f65/GHSA-j4fg-qq64-7f65.json index 4a6389c8eeb..8b384ad4602 100644 --- a/advisories/unreviewed/2024/07/GHSA-j4fg-qq64-7f65/GHSA-j4fg-qq64-7f65.json +++ b/advisories/unreviewed/2024/07/GHSA-j4fg-qq64-7f65/GHSA-j4fg-qq64-7f65.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4fg-qq64-7f65", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40807" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json b/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json index c88fa232407..0635ca3966d 100644 --- a/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json +++ b/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j573-cwg3-wh35", - "modified": "2024-08-13T18:31:13Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40780" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -81,9 +84,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mxhg-mc93-9g8m/GHSA-mxhg-mc93-9g8m.json b/advisories/unreviewed/2024/07/GHSA-mxhg-mc93-9g8m/GHSA-mxhg-mc93-9g8m.json index 64b3d117301..b4e9418e751 100644 --- a/advisories/unreviewed/2024/07/GHSA-mxhg-mc93-9g8m/GHSA-mxhg-mc93-9g8m.json +++ b/advisories/unreviewed/2024/07/GHSA-mxhg-mc93-9g8m/GHSA-mxhg-mc93-9g8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxhg-mc93-9g8m", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40815" ], "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.6.8, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, macOS Sonoma 14.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p9cw-wmxq-f279/GHSA-p9cw-wmxq-f279.json b/advisories/unreviewed/2024/07/GHSA-p9cw-wmxq-f279/GHSA-p9cw-wmxq-f279.json index 61fd1fea3e8..a11fad88541 100644 --- a/advisories/unreviewed/2024/07/GHSA-p9cw-wmxq-f279/GHSA-p9cw-wmxq-f279.json +++ b/advisories/unreviewed/2024/07/GHSA-p9cw-wmxq-f279/GHSA-p9cw-wmxq-f279.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9cw-wmxq-f279", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40813" ], "details": "A lock screen issue was addressed with improved state management. This issue is fixed in watchOS 10.6, iOS 17.6 and iPadOS 17.6. An attacker with physical access may be able to use Siri to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json b/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json index 751cdb80814..51e90cb995f 100644 --- a/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json +++ b/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r54r-9gw2-2w5v", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40822" ], "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 10.6, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9. An attacker with physical access to a device may be able to access contacts from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wmm6-xq62-rq3v/GHSA-wmm6-xq62-rq3v.json b/advisories/unreviewed/2024/07/GHSA-wmm6-xq62-rq3v/GHSA-wmm6-xq62-rq3v.json index ead26db1e3f..cf1cd999f2a 100644 --- a/advisories/unreviewed/2024/07/GHSA-wmm6-xq62-rq3v/GHSA-wmm6-xq62-rq3v.json +++ b/advisories/unreviewed/2024/07/GHSA-wmm6-xq62-rq3v/GHSA-wmm6-xq62-rq3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmm6-xq62-rq3v", - "modified": "2024-07-30T03:30:53Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40816" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. A local attacker may be able to cause unexpected system shutdown.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json b/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json new file mode 100644 index 00000000000..4e1430fc229 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22qx-rv28-v9m8", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42943" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42943" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromAdvSetWan_PPPOEPassword.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-25q3-mc3p-85jx/GHSA-25q3-mc3p-85jx.json b/advisories/unreviewed/2024/08/GHSA-25q3-mc3p-85jx/GHSA-25q3-mc3p-85jx.json new file mode 100644 index 00000000000..43606c48a9a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-25q3-mc3p-85jx/GHSA-25q3-mc3p-85jx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25q3-mc3p-85jx", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-22219" + ], + "details": "XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22219" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/articles/release-notes-highlights" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22218--cve-2024-22219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json b/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json new file mode 100644 index 00000000000..832a96ab27a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2p7q-76m8-h2pg/GHSA-2p7q-76m8-h2pg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p7q-76m8-h2pg", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42843" + ], + "details": "Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42843" + }, + { + "type": "WEB", + "url": "https://github.com/ganzhi-qcy/cve/issues/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json b/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json index 18b50f85d16..2f8686168d7 100644 --- a/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json +++ b/advisories/unreviewed/2024/08/GHSA-2pc2-wxgf-m9mm/GHSA-2pc2-wxgf-m9mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pc2-wxgf-m9mm", - "modified": "2024-08-06T15:30:52Z", + "modified": "2024-08-15T18:31:45Z", "published": "2024-08-06T15:30:52Z", "aliases": [ "CVE-2024-33990" diff --git a/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json b/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json index 0b29a5f03be..77c1f8795e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json +++ b/advisories/unreviewed/2024/08/GHSA-38wc-99fv-jfwv/GHSA-38wc-99fv-jfwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38wc-99fv-jfwv", - "modified": "2024-08-15T15:30:57Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:57Z", "aliases": [ "CVE-2024-7831" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_cooliris.md" }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.274729" diff --git a/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json b/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json new file mode 100644 index 00000000000..848906551b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j4q-cm56-9492", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42948" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42948" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromPptpUserSetting.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json b/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json new file mode 100644 index 00000000000..afa20714333 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3p4h-pcqj-f7fx/GHSA-3p4h-pcqj-f7fx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p4h-pcqj-f7fx", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42987" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the modino parameter in the fromPptpUserAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42987" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromPptpUserAdd.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json b/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json new file mode 100644 index 00000000000..6e21398c4d9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p9r-c4f8-vv7m", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42946" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42946" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromVirtualSer.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json b/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json new file mode 100644 index 00000000000..03f586ed1d9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f38-rjhv-hc58", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42944" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42944" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromNatlimit.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json b/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json new file mode 100644 index 00000000000..c358baca1cf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m24-c4vx-fjj8", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42984" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42984" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromP2pListFilter.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json b/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json new file mode 100644 index 00000000000..b66f1aa45c5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wq9-96x8-3hq5", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42981" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42981" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromPptpUserSetting.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6267-jhgq-8f4c/GHSA-6267-jhgq-8f4c.json b/advisories/unreviewed/2024/08/GHSA-6267-jhgq-8f4c/GHSA-6267-jhgq-8f4c.json new file mode 100644 index 00000000000..b34140a1a78 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6267-jhgq-8f4c/GHSA-6267-jhgq-8f4c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6267-jhgq-8f4c", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-40704" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40704" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/298277" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7160853" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json b/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json new file mode 100644 index 00000000000..4bd355702b7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6744-v55g-mhwj", + "modified": "2024-08-15T18:31:44Z", + "published": "2024-08-15T18:31:44Z", + "aliases": [ + "CVE-2024-39708" + ], + "details": "An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy a crafted DLL file to a temporary directory (used by .NET Shadow Copies) such that privilege escalation can occur if the core agent service loads that file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39708" + }, + { + "type": "WEB", + "url": "https://docs.delinea.com/online-help/privilege-manager/release-notes/12.0.1-combined.htm" + }, + { + "type": "WEB", + "url": "https://www.cyberark.com/resources/threat-research-blog/identity-crisis-the-curious-case-of-a-delinea-local-privilege-escalation-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-28T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json b/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json new file mode 100644 index 00000000000..8db7011bee4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6cg9-52c8-r76r/GHSA-6cg9-52c8-r76r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cg9-52c8-r76r", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42967" + ], + "details": "Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42967" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/TOTOLINK/LR350/ExportSettings.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json b/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json new file mode 100644 index 00000000000..976485b3bec --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g7p-7w92-r3v3", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-31798" + ], + "details": "Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31798" + }, + { + "type": "WEB", + "url": "https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p" + }, + { + "type": "WEB", + "url": "https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json b/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json new file mode 100644 index 00000000000..ad3275b05c9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pr8-g9pq-xmj3", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42969" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42969" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromSafeMacFilter%20_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-75jf-52jg-qqh4/GHSA-75jf-52jg-qqh4.json b/advisories/unreviewed/2024/08/GHSA-75jf-52jg-qqh4/GHSA-75jf-52jg-qqh4.json new file mode 100644 index 00000000000..45b2f6d3fa8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-75jf-52jg-qqh4/GHSA-75jf-52jg-qqh4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jf-52jg-qqh4", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-32231" + ], + "details": "Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32231" + }, + { + "type": "WEB", + "url": "https://github.com/stashapp/stash/pull/4865" + }, + { + "type": "WEB", + "url": "https://github.com/stashapp" + }, + { + "type": "WEB", + "url": "https://github.com/stashapp/stash" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json b/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json new file mode 100644 index 00000000000..7f7dd72b1b6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-765j-3jm5-8cf6", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42941" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42941" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromAdvSetWan_pptpPPW.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json b/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json new file mode 100644 index 00000000000..814f8dea97c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84mw-hccv-m82r", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42949" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42949" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromqossetting_qos.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json b/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json new file mode 100644 index 00000000000..3f6f3380e7a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8547-j8j2-79v8", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42940" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42940" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromP2pListFilter.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json b/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json index c0a7e46383d..cd8f1cfd328 100644 --- a/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json +++ b/advisories/unreviewed/2024/08/GHSA-9hr8-jgq4-7m7w/GHSA-9hr8-jgq4-7m7w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hr8-jgq4-7m7w", - "modified": "2024-08-06T15:30:52Z", + "modified": "2024-08-15T18:31:45Z", "published": "2024-08-06T15:30:52Z", "aliases": [ "CVE-2024-33991" diff --git a/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json b/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json new file mode 100644 index 00000000000..bcd2bf23355 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q7g-3c57-wvv7", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42954" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42954" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromwebExcptypemanFilter.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json b/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json index 8ddccaf04a7..62c786e4c60 100644 --- a/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json +++ b/advisories/unreviewed/2024/08/GHSA-c2p2-p654-9c4p/GHSA-c2p2-p654-9c4p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2p2-p654-9c4p", - "modified": "2024-08-15T15:30:57Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:57Z", "aliases": [ "CVE-2024-7828" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_set_cover.md" }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.274726" diff --git a/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json b/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json new file mode 100644 index 00000000000..2d00233101d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c62c-fvgv-j4v4", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42950" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42950" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromSafeClientFilter_Go.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json b/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json new file mode 100644 index 00000000000..3bcebd5ebc1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c75r-v5wg-3gmj", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42976" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42976" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromSafeClientFilter_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cpfp-m5qw-c4r3/GHSA-cpfp-m5qw-c4r3.json b/advisories/unreviewed/2024/08/GHSA-cpfp-m5qw-c4r3/GHSA-cpfp-m5qw-c4r3.json new file mode 100644 index 00000000000..9ae8a4bab33 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cpfp-m5qw-c4r3/GHSA-cpfp-m5qw-c4r3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpfp-m5qw-c4r3", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42681" + ], + "details": "Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42681" + }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/issues/3516" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json b/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json new file mode 100644 index 00000000000..3eade713ff5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cprr-85rg-mjvr", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42985" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42985" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromNatlimit.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f5ch-pqm5-5632/GHSA-f5ch-pqm5-5632.json b/advisories/unreviewed/2024/08/GHSA-f5ch-pqm5-5632/GHSA-f5ch-pqm5-5632.json new file mode 100644 index 00000000000..d7393093bda --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f5ch-pqm5-5632/GHSA-f5ch-pqm5-5632.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5ch-pqm5-5632", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-40705" + ], + "details": "IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40705" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/298279" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7160855" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-405" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json b/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json new file mode 100644 index 00000000000..1530b21c41f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f994-q776-gghm", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42980" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42980" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/frmL7ImForm.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json b/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json new file mode 100644 index 00000000000..60dc5d5f8ee --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fj4q-r9h6-xhrg/GHSA-fj4q-r9h6-xhrg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj4q-r9h6-xhrg", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42978" + ], + "details": "An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42978" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/telnet.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json b/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json index 5dc4a07db97..e76af92b0f0 100644 --- a/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json +++ b/advisories/unreviewed/2024/08/GHSA-ggq6-w6jr-x8x2/GHSA-ggq6-w6jr-x8x2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggq6-w6jr-x8x2", - "modified": "2024-08-06T15:30:52Z", + "modified": "2024-08-15T18:31:45Z", "published": "2024-08-06T15:30:52Z", "aliases": [ "CVE-2024-33993" diff --git a/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json b/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json index b119ff7f723..0b3dbfb7995 100644 --- a/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json +++ b/advisories/unreviewed/2024/08/GHSA-gv8w-244w-5xfq/GHSA-gv8w-244w-5xfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gv8w-244w-5xfq", - "modified": "2024-08-15T15:30:57Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:57Z", "aliases": [ "CVE-2024-7830" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_move_photo.md" }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.274728" diff --git a/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json b/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json new file mode 100644 index 00000000000..6dc8c0311ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h7cf-jrwx-94cj/GHSA-h7cf-jrwx-94cj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7cf-jrwx-94cj", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42982" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42982" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromVirtualSer.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json b/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json new file mode 100644 index 00000000000..f496f52e101 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hhrv-84gm-4q6x/GHSA-hhrv-84gm-4q6x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhrv-84gm-4q6x", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-22217" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22217" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/articles/release-notes-highlights" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22217" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json b/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json index aa89369c99a..3ddebe24a7c 100644 --- a/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json +++ b/advisories/unreviewed/2024/08/GHSA-j22w-7r9x-5g74/GHSA-j22w-7r9x-5g74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j22w-7r9x-5g74", - "modified": "2024-08-06T15:30:52Z", + "modified": "2024-08-15T18:31:45Z", "published": "2024-08-06T15:30:52Z", "aliases": [ "CVE-2024-33989" diff --git a/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json b/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json index 4530c55e12c..683472fc78c 100644 --- a/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json +++ b/advisories/unreviewed/2024/08/GHSA-j2xh-32vh-pwww/GHSA-j2xh-32vh-pwww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2xh-32vh-pwww", - "modified": "2024-08-15T15:30:57Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:57Z", "aliases": [ "CVE-2024-7829" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_del_photo.md" }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.274727" diff --git a/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json b/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json new file mode 100644 index 00000000000..240fac8d790 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j828-57c8-xr27", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42968" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42968" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromSafeMacFilter_Go.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json b/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json new file mode 100644 index 00000000000..f3a63ae7b09 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6q3-mcjx-5646", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42955" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42955" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromSafeClientFilter_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json b/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json new file mode 100644 index 00000000000..6e5bbcf565c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mccv-36h3-rfv5", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-31799" + ], + "details": "Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31799" + }, + { + "type": "WEB", + "url": "https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p" + }, + { + "type": "WEB", + "url": "https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json b/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json new file mode 100644 index 00000000000..e3c82518ff1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcrq-g49g-vf4v", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42942" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42942" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/frmL7ImForm.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json b/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json new file mode 100644 index 00000000000..0e5da7ac958 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx5j-m2q8-9rc2", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42952" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42952" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromqossetting_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json b/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json index 7bf3b352ccd..cd6be219cf1 100644 --- a/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json +++ b/advisories/unreviewed/2024/08/GHSA-mxxm-vx4c-x8w7/GHSA-mxxm-vx4c-x8w7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxxm-vx4c-x8w7", - "modified": "2024-08-15T15:30:58Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-42676" ], "details": "File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T14:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json b/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json new file mode 100644 index 00000000000..9089c05f9dc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p332-vhv3-xv9m/GHSA-p332-vhv3-xv9m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p332-vhv3-xv9m", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42966" + ], + "details": "Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42966" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/TOTOLINK/N350R/ExportSettings.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json b/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json index e9509e7b9c4..323592c82ec 100644 --- a/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json +++ b/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcmw-xjj4-jxjp", - "modified": "2024-08-15T15:30:58Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-42678" ], "details": "Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T14:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json b/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json new file mode 100644 index 00000000000..ceb14877c96 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4q3-6vr4-qq23", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-22218" + ], + "details": "XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22218" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/articles/release-notes-highlights" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22218--cve-2024-22219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json b/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json new file mode 100644 index 00000000000..9de1df9e81c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q967-hxp7-f2rc/GHSA-q967-hxp7-f2rc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q967-hxp7-f2rc", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42977" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42977" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromqossetting_qos.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json b/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json new file mode 100644 index 00000000000..e3489fc6a99 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qffp-wwcx-j425/GHSA-qffp-wwcx-j425.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qffp-wwcx-j425", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42986" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42986" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromAdvSetWan_PPPOEPassword.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json b/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json index dccc9a7bd69..3e9bb5483e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json +++ b/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwhw-rpr6-7qq8", - "modified": "2024-08-06T12:30:32Z", + "modified": "2024-08-15T18:31:45Z", "published": "2024-08-06T12:30:32Z", "aliases": [ "CVE-2024-33976" diff --git a/advisories/unreviewed/2024/08/GHSA-rrc8-qmq6-vv7c/GHSA-rrc8-qmq6-vv7c.json b/advisories/unreviewed/2024/08/GHSA-rrc8-qmq6-vv7c/GHSA-rrc8-qmq6-vv7c.json index 0aaabc446be..6774830047d 100644 --- a/advisories/unreviewed/2024/08/GHSA-rrc8-qmq6-vv7c/GHSA-rrc8-qmq6-vv7c.json +++ b/advisories/unreviewed/2024/08/GHSA-rrc8-qmq6-vv7c/GHSA-rrc8-qmq6-vv7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rrc8-qmq6-vv7c", - "modified": "2024-08-01T09:30:49Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-08-01T09:30:49Z", "aliases": [ "CVE-2024-5678" diff --git a/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json b/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json new file mode 100644 index 00000000000..7c9b41a2e94 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4x2-xrc6-7q7j", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42953" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPW parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42953" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromWizardHandle_PPW.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json b/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json new file mode 100644 index 00000000000..533eaf3739d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr5q-96fr-9g77", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42951" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42951" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromWizardHandle_mit_pptpusrpw.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json b/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json new file mode 100644 index 00000000000..b536118a473 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv44-rh9q-4cc8", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42974" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42974" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromwebExcptypemanFilter.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w295-57vq-q8v3/GHSA-w295-57vq-q8v3.json b/advisories/unreviewed/2024/08/GHSA-w295-57vq-q8v3/GHSA-w295-57vq-q8v3.json new file mode 100644 index 00000000000..ad81523ba96 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w295-57vq-q8v3/GHSA-w295-57vq-q8v3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w295-57vq-q8v3", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2023-37228" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37228" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json b/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json index 4a2f07c505c..9d101be0f70 100644 --- a/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json +++ b/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w532-q68f-hxv4", - "modified": "2024-08-06T12:30:32Z", + "modified": "2024-08-15T18:31:44Z", "published": "2024-08-06T12:30:32Z", "aliases": [ "CVE-2024-33975" diff --git a/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json b/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json index 88fb05ee754..f2c175f7802 100644 --- a/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json +++ b/advisories/unreviewed/2024/08/GHSA-wcjv-6xqv-vm87/GHSA-wcjv-6xqv-vm87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wcjv-6xqv-vm87", - "modified": "2024-08-15T15:30:58Z", + "modified": "2024-08-15T18:31:51Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-7832" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_fullscreen_photos.md" }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.274730" diff --git a/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json b/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json new file mode 100644 index 00000000000..31579554dcb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp6j-mqr7-v2hf", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42983" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42983" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromAdvSetWan_pptpPPW.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json b/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json new file mode 100644 index 00000000000..84cdc936088 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq55-fhp8-6jh8", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42945" + ], + "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42945" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/fromAddressNat_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json b/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json new file mode 100644 index 00000000000..de182ed4a6f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wxwq-v4jc-6x96/GHSA-wxwq-v4jc-6x96.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxwq-v4jc-6x96", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42947" + ], + "details": "An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42947" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1201/telnet.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json b/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json new file mode 100644 index 00000000000..d64e0d66b45 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg38-j8ww-g8hg", + "modified": "2024-08-15T18:31:52Z", + "published": "2024-08-15T18:31:52Z", + "aliases": [ + "CVE-2024-42979" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42979" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/frmL7ProtForm.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json b/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json new file mode 100644 index 00000000000..5de689d8c8c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh57-2h8m-3798", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-42973" + ], + "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42973" + }, + { + "type": "WEB", + "url": "https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/Tenda/FH1206/fromSetIpBind.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xhmg-mv86-w89p/GHSA-xhmg-mv86-w89p.json b/advisories/unreviewed/2024/08/GHSA-xhmg-mv86-w89p/GHSA-xhmg-mv86-w89p.json new file mode 100644 index 00000000000..e77f03ecf9f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xhmg-mv86-w89p/GHSA-xhmg-mv86-w89p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhmg-mv86-w89p", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-31905" + ], + "details": "IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 289858.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31905" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/289858" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7160961" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json b/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json index 142302ea2a2..aa16b0f7a57 100644 --- a/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json +++ b/advisories/unreviewed/2024/08/GHSA-xq4j-rv6r-ch63/GHSA-xq4j-rv6r-ch63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq4j-rv6r-ch63", - "modified": "2024-08-06T15:30:52Z", + "modified": "2024-08-15T18:31:45Z", "published": "2024-08-06T15:30:52Z", "aliases": [ "CVE-2024-33992" diff --git a/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json b/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json new file mode 100644 index 00000000000..52e50c12fcd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xw3h-6c4j-mqhw/GHSA-xw3h-6c4j-mqhw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw3h-6c4j-mqhw", + "modified": "2024-08-15T18:31:51Z", + "published": "2024-08-15T18:31:51Z", + "aliases": [ + "CVE-2024-31800" + ], + "details": "Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31800" + }, + { + "type": "WEB", + "url": "https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p" + }, + { + "type": "WEB", + "url": "https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T17:15:17Z" + } +} \ No newline at end of file