diff --git a/advisories/unreviewed/2023/06/GHSA-668g-fp7v-3973/GHSA-668g-fp7v-3973.json b/advisories/unreviewed/2023/06/GHSA-668g-fp7v-3973/GHSA-668g-fp7v-3973.json index 0a8b9c5cfd2..d6cee183434 100644 --- a/advisories/unreviewed/2023/06/GHSA-668g-fp7v-3973/GHSA-668g-fp7v-3973.json +++ b/advisories/unreviewed/2023/06/GHSA-668g-fp7v-3973/GHSA-668g-fp7v-3973.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-6977-5wcp-rwxf/GHSA-6977-5wcp-rwxf.json b/advisories/unreviewed/2023/06/GHSA-6977-5wcp-rwxf/GHSA-6977-5wcp-rwxf.json index 5b9f59e9332..719bc5b12df 100644 --- a/advisories/unreviewed/2023/06/GHSA-6977-5wcp-rwxf/GHSA-6977-5wcp-rwxf.json +++ b/advisories/unreviewed/2023/06/GHSA-6977-5wcp-rwxf/GHSA-6977-5wcp-rwxf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-hh22-x765-p7q6/GHSA-hh22-x765-p7q6.json b/advisories/unreviewed/2023/06/GHSA-hh22-x765-p7q6/GHSA-hh22-x765-p7q6.json index d7fe2030b50..b72f24f45bb 100644 --- a/advisories/unreviewed/2023/06/GHSA-hh22-x765-p7q6/GHSA-hh22-x765-p7q6.json +++ b/advisories/unreviewed/2023/06/GHSA-hh22-x765-p7q6/GHSA-hh22-x765-p7q6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json b/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json index 0411199d472..52d3a2e7a2f 100644 --- a/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json +++ b/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-296f-9hr7-4mwq/GHSA-296f-9hr7-4mwq.json b/advisories/unreviewed/2024/11/GHSA-296f-9hr7-4mwq/GHSA-296f-9hr7-4mwq.json new file mode 100644 index 00000000000..1e983a2e1e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-296f-9hr7-4mwq/GHSA-296f-9hr7-4mwq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-296f-9hr7-4mwq", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-52951" + ], + "details": "Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52951" + }, + { + "type": "WEB", + "url": "https://omadaidentity.com" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/omada" + }, + { + "type": "WEB", + "url": "https://sec-consult.com/vulnerability-lab/advisory/stored-cross-site-scripting-in-omada-identity" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json b/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json index aab08d96f88..a54dfa6cf25 100644 --- a/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json +++ b/advisories/unreviewed/2024/11/GHSA-3r9h-5xmh-8j4q/GHSA-3r9h-5xmh-8j4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3r9h-5xmh-8j4q", - "modified": "2024-11-26T15:31:03Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-26T15:31:03Z", "aliases": [ "CVE-2024-11708" ], "details": "Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T14:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5h68-q459-xxm7/GHSA-5h68-q459-xxm7.json b/advisories/unreviewed/2024/11/GHSA-5h68-q459-xxm7/GHSA-5h68-q459-xxm7.json index a60ee6bb574..540c7b17884 100644 --- a/advisories/unreviewed/2024/11/GHSA-5h68-q459-xxm7/GHSA-5h68-q459-xxm7.json +++ b/advisories/unreviewed/2024/11/GHSA-5h68-q459-xxm7/GHSA-5h68-q459-xxm7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h68-q459-xxm7", - "modified": "2024-11-19T03:31:08Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-19T03:31:08Z", "aliases": [ "CVE-2024-50291" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: add missing buffer index check\n\ndvb_vb2_expbuf() didn't check if the given buffer index was\nfor a valid buffer. Add this check.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:31Z" diff --git a/advisories/unreviewed/2024/11/GHSA-678g-9vjx-fwpj/GHSA-678g-9vjx-fwpj.json b/advisories/unreviewed/2024/11/GHSA-678g-9vjx-fwpj/GHSA-678g-9vjx-fwpj.json new file mode 100644 index 00000000000..e97e8eacf2d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-678g-9vjx-fwpj/GHSA-678g-9vjx-fwpj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-678g-9vjx-fwpj", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-53635" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata POST request parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53635" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/COVID19/Reflected%20Cross%20Site%20Scripting.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json b/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json new file mode 100644 index 00000000000..4328e4c1af5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8737-h7fg-9xgj", + "modified": "2024-11-27T15:31:46Z", + "published": "2024-11-27T15:31:46Z", + "aliases": [ + "CVE-2024-53920" + ], + "details": "In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53920" + }, + { + "type": "WEB", + "url": "https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.html" + }, + { + "type": "WEB", + "url": "https://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92" + }, + { + "type": "WEB", + "url": "https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4" + }, + { + "type": "WEB", + "url": "https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg%40mail.gmail.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8pc5-29j8-pcjq/GHSA-8pc5-29j8-pcjq.json b/advisories/unreviewed/2024/11/GHSA-8pc5-29j8-pcjq/GHSA-8pc5-29j8-pcjq.json new file mode 100644 index 00000000000..f6f470c6818 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8pc5-29j8-pcjq/GHSA-8pc5-29j8-pcjq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pc5-29j8-pcjq", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-46055" + ], + "details": "OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46055" + }, + { + "type": "WEB", + "url": "https://github.com/b1d0ws/CVEs/blob/main/CVE-2024-46055.md" + }, + { + "type": "WEB", + "url": "https://github.com/davidguva/OpenVidReview" + }, + { + "type": "WEB", + "url": "https://github.com/davidguva/OpenVidReview/blob/main/views/admin.ejs" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json b/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json index 1cb5dd77b9f..7a48c599c8f 100644 --- a/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json +++ b/advisories/unreviewed/2024/11/GHSA-9g2q-259c-66mq/GHSA-9g2q-259c-66mq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g2q-259c-66mq", - "modified": "2024-11-26T15:31:02Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-26T15:31:02Z", "aliases": [ "CVE-2024-11699" ], "details": "Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T14:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9qwc-r24c-26j3/GHSA-9qwc-r24c-26j3.json b/advisories/unreviewed/2024/11/GHSA-9qwc-r24c-26j3/GHSA-9qwc-r24c-26j3.json index 7f7ee9c3466..5b7cc1f5b42 100644 --- a/advisories/unreviewed/2024/11/GHSA-9qwc-r24c-26j3/GHSA-9qwc-r24c-26j3.json +++ b/advisories/unreviewed/2024/11/GHSA-9qwc-r24c-26j3/GHSA-9qwc-r24c-26j3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qwc-r24c-26j3", - "modified": "2024-11-19T03:31:09Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-19T03:31:09Z", "aliases": [ "CVE-2024-50302" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: zero-initialize the report buffer\n\nSince the report buffer is used by all kinds of drivers in various ways, let's\nzero-initialize it during allocation to make sure that it can't be ever used\nto leak kernel memory via specially-crafted report.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:32Z" diff --git a/advisories/unreviewed/2024/11/GHSA-c97r-q93g-fc5c/GHSA-c97r-q93g-fc5c.json b/advisories/unreviewed/2024/11/GHSA-c97r-q93g-fc5c/GHSA-c97r-q93g-fc5c.json new file mode 100644 index 00000000000..d7d77406107 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c97r-q93g-fc5c/GHSA-c97r-q93g-fc5c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c97r-q93g-fc5c", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-53603" + ], + "details": "A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53603" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/COVID19/SQL%20Injection%20vulnerability.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fm8p-9649-2gq7/GHSA-fm8p-9649-2gq7.json b/advisories/unreviewed/2024/11/GHSA-fm8p-9649-2gq7/GHSA-fm8p-9649-2gq7.json index 05e9790191d..f210bf1f9db 100644 --- a/advisories/unreviewed/2024/11/GHSA-fm8p-9649-2gq7/GHSA-fm8p-9649-2gq7.json +++ b/advisories/unreviewed/2024/11/GHSA-fm8p-9649-2gq7/GHSA-fm8p-9649-2gq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fm8p-9649-2gq7", - "modified": "2024-11-19T03:31:08Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-19T03:31:08Z", "aliases": [ "CVE-2024-50298" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: allocate vf_state during PF probes\n\nIn the previous implementation, vf_state is allocated memory only when VF\nis enabled. However, net_device_ops::ndo_set_vf_mac() may be called before\nVF is enabled to configure the MAC address of VF. If this is the case,\nenetc_pf_set_vf_mac() will access vf_state, resulting in access to a null\npointer. The simplified error log is as follows.\n\nroot@ls1028ardb:~# ip link set eno0 vf 1 mac 00:0c:e7:66:77:89\n[ 173.543315] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004\n[ 173.637254] pc : enetc_pf_set_vf_mac+0x3c/0x80 Message from sy\n[ 173.641973] lr : do_setlink+0x4a8/0xec8\n[ 173.732292] Call trace:\n[ 173.734740] enetc_pf_set_vf_mac+0x3c/0x80\n[ 173.738847] __rtnl_newlink+0x530/0x89c\n[ 173.742692] rtnl_newlink+0x50/0x7c\n[ 173.746189] rtnetlink_rcv_msg+0x128/0x390\n[ 173.750298] netlink_rcv_skb+0x60/0x130\n[ 173.754145] rtnetlink_rcv+0x18/0x24\n[ 173.757731] netlink_unicast+0x318/0x380\n[ 173.761665] netlink_sendmsg+0x17c/0x3c8", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:31Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json b/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json index 4f215918471..844006af3e5 100644 --- a/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json +++ b/advisories/unreviewed/2024/11/GHSA-jxv2-pgjw-vg3v/GHSA-jxv2-pgjw-vg3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxv2-pgjw-vg3v", - "modified": "2024-11-26T15:31:03Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-26T15:31:03Z", "aliases": [ "CVE-2024-53975" ], "details": "Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T14:15:21Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m253-89wr-92m7/GHSA-m253-89wr-92m7.json b/advisories/unreviewed/2024/11/GHSA-m253-89wr-92m7/GHSA-m253-89wr-92m7.json index a5a11df9894..0c8f658d8ff 100644 --- a/advisories/unreviewed/2024/11/GHSA-m253-89wr-92m7/GHSA-m253-89wr-92m7.json +++ b/advisories/unreviewed/2024/11/GHSA-m253-89wr-92m7/GHSA-m253-89wr-92m7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m253-89wr-92m7", - "modified": "2024-11-19T03:31:08Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-19T03:31:08Z", "aliases": [ "CVE-2024-50296" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash when uninstalling driver\n\nWhen the driver is uninstalled and the VF is disabled concurrently, a\nkernel crash occurs. The reason is that the two actions call function\npci_disable_sriov(). The num_VFs is checked to determine whether to\nrelease the corresponding resources. During the second calling, num_VFs\nis not 0 and the resource release function is called. However, the\ncorresponding resource has been released during the first invoking.\nTherefore, the problem occurs:\n\n[15277.839633][T50670] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020\n...\n[15278.131557][T50670] Call trace:\n[15278.134686][T50670] klist_put+0x28/0x12c\n[15278.138682][T50670] klist_del+0x14/0x20\n[15278.142592][T50670] device_del+0xbc/0x3c0\n[15278.146676][T50670] pci_remove_bus_device+0x84/0x120\n[15278.151714][T50670] pci_stop_and_remove_bus_device+0x6c/0x80\n[15278.157447][T50670] pci_iov_remove_virtfn+0xb4/0x12c\n[15278.162485][T50670] sriov_disable+0x50/0x11c\n[15278.166829][T50670] pci_disable_sriov+0x24/0x30\n[15278.171433][T50670] hnae3_unregister_ae_algo_prepare+0x60/0x90 [hnae3]\n[15278.178039][T50670] hclge_exit+0x28/0xd0 [hclge]\n[15278.182730][T50670] __se_sys_delete_module.isra.0+0x164/0x230\n[15278.188550][T50670] __arm64_sys_delete_module+0x1c/0x30\n[15278.193848][T50670] invoke_syscall+0x50/0x11c\n[15278.198278][T50670] el0_svc_common.constprop.0+0x158/0x164\n[15278.203837][T50670] do_el0_svc+0x34/0xcc\n[15278.207834][T50670] el0_svc+0x20/0x30\n\nFor details, see the following figure.\n\n rmmod hclge disable VFs\n----------------------------------------------------\nhclge_exit() sriov_numvfs_store()\n ... device_lock()\n pci_disable_sriov() hns3_pci_sriov_configure()\n pci_disable_sriov()\n sriov_disable()\n sriov_disable() if !num_VFs :\n if !num_VFs : return;\n return; sriov_del_vfs()\n sriov_del_vfs() ...\n ... klist_put()\n klist_put() ...\n ... num_VFs = 0;\n num_VFs = 0; device_unlock();\n\nIn this patch, when driver is removing, we get the device_lock()\nto protect num_VFs, just like sriov_numvfs_store().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:31Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json b/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json new file mode 100644 index 00000000000..26cf600865f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m36q-xm37-vj27/GHSA-m36q-xm37-vj27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m36q-xm37-vj27", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-53604" + ], + "details": "A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53604" + }, + { + "type": "WEB", + "url": "https://github.com/Santoshcyber1/CVE-wirteup/blob/main/Phpgurukul/COVID19/SQL%20Injection%20vulnerability%20mo.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json b/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json new file mode 100644 index 00000000000..a34c414dd9f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq65-5wvg-p275", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-46054" + ], + "details": "OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46054" + }, + { + "type": "WEB", + "url": "https://github.com/b1d0ws/CVEs/blob/main/CVE-2024-46054.md" + }, + { + "type": "WEB", + "url": "https://github.com/davidguva/OpenVidReview" + }, + { + "type": "WEB", + "url": "https://github.com/davidguva/OpenVidReview/blob/main/routes/upload.js" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rj72-j8c2-fwx3/GHSA-rj72-j8c2-fwx3.json b/advisories/unreviewed/2024/11/GHSA-rj72-j8c2-fwx3/GHSA-rj72-j8c2-fwx3.json new file mode 100644 index 00000000000..93534130754 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rj72-j8c2-fwx3/GHSA-rj72-j8c2-fwx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj72-j8c2-fwx3", + "modified": "2024-11-27T15:31:45Z", + "published": "2024-11-27T15:31:45Z", + "aliases": [ + "CVE-2024-36464" + ], + "details": "When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36464" + }, + { + "type": "WEB", + "url": "https://support.zabbix.com/browse/ZBX-25630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rprq-p34w-2rvp/GHSA-rprq-p34w-2rvp.json b/advisories/unreviewed/2024/11/GHSA-rprq-p34w-2rvp/GHSA-rprq-p34w-2rvp.json index 9137ef6a42d..cb410d572a8 100644 --- a/advisories/unreviewed/2024/11/GHSA-rprq-p34w-2rvp/GHSA-rprq-p34w-2rvp.json +++ b/advisories/unreviewed/2024/11/GHSA-rprq-p34w-2rvp/GHSA-rprq-p34w-2rvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rprq-p34w-2rvp", - "modified": "2024-11-19T03:31:08Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-19T03:31:08Z", "aliases": [ "CVE-2024-50297" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: xilinx: axienet: Enqueue Tx packets in dql before dmaengine starts\n\nEnqueue packets in dql after dma engine starts causes race condition.\nTx transfer starts once dma engine is started and may execute dql dequeue\nin completion before it gets queued. It results in following kernel crash\nwhile running iperf stress test:\n\nkernel BUG at lib/dynamic_queue_limits.c:99!\n\nInternal error: Oops - BUG: 00000000f2000800 [#1] SMP\npc : dql_completed+0x238/0x248\nlr : dql_completed+0x3c/0x248\n\nCall trace:\n dql_completed+0x238/0x248\n axienet_dma_tx_cb+0xa0/0x170\n xilinx_dma_do_tasklet+0xdc/0x290\n tasklet_action_common+0xf8/0x11c\n tasklet_action+0x30/0x3c\n handle_softirqs+0xf8/0x230\n\n\nStart dmaengine after enqueue in dql fixes the crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:31Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vhw5-84xr-rjmq/GHSA-vhw5-84xr-rjmq.json b/advisories/unreviewed/2024/11/GHSA-vhw5-84xr-rjmq/GHSA-vhw5-84xr-rjmq.json index f181f54645e..354c1383bae 100644 --- a/advisories/unreviewed/2024/11/GHSA-vhw5-84xr-rjmq/GHSA-vhw5-84xr-rjmq.json +++ b/advisories/unreviewed/2024/11/GHSA-vhw5-84xr-rjmq/GHSA-vhw5-84xr-rjmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhw5-84xr-rjmq", - "modified": "2024-11-27T12:31:53Z", + "modified": "2024-11-27T15:31:45Z", "published": "2024-11-27T12:31:53Z", "aliases": [ "CVE-2024-52323" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false,