Publish Advisories

GHSA-22fj-xvpx-pqm9
GHSA-3f3f-5w2h-wvgq
GHSA-5fhj-x7g6-jh74
GHSA-8987-77qq-2wwv
GHSA-8pgv-qg6f-4chf
GHSA-h9vw-2v4g-wcq8
GHSA-rx6j-p5q4-cqf9
GHSA-vwrj-5xvr-9v9x
GHSA-w8pm-g6gf-4v9x
GHSA-w9xw-437c-59ch
GHSA-wf3c-fh77-x5hq
GHSA-895h-3m6x-8h8x
GHSA-h8cg-wwvx-fmhj
GHSA-h93h-6948-g84m
GHSA-j225-cvw7-qrx7
GHSA-m892-r7q3-ww6c
This commit is contained in:
advisory-database[bot]
2024-01-05 06:31:33 +00:00
parent 49bb230e0e
commit 7036faccc1
16 changed files with 202 additions and 10 deletions
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-74"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f3f-5w2h-wvgq",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:18Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-52135"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5fhj-x7g6-jh74",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:19Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-44088"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8987-77qq-2wwv",
"modified": "2023-12-29T15:30:32Z",
"modified": "2024-01-05T06:30:18Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-51541"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pgv-qg6f-4chf",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:19Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-44089"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9vw-2v4g-wcq8",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:19Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-41815"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rx6j-p5q4-cqf9",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:18Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-41813"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vwrj-5xvr-9v9x",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:19Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-41814"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w8pm-g6gf-4v9x",
"modified": "2023-12-29T12:30:41Z",
"modified": "2024-01-05T06:30:18Z",
"published": "2023-12-29T12:30:41Z",
"aliases": [
"CVE-2023-51372"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w9xw-437c-59ch",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:18Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-51396"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf3c-fh77-x5hq",
"modified": "2023-12-29T12:30:42Z",
"modified": "2024-01-05T06:30:19Z",
"published": "2023-12-29T12:30:42Z",
"aliases": [
"CVE-2023-50837"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-895h-3m6x-8h8x",
"modified": "2024-01-05T06:30:19Z",
"published": "2024-01-05T06:30:19Z",
"aliases": [
"CVE-2024-22086"
],
"details": "handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22086"
},
{
"type": "WEB",
"url": "https://github.com/hayyp/cherry/issues/1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T04:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8cg-wwvx-fmhj",
"modified": "2024-01-05T06:30:19Z",
"published": "2024-01-05T06:30:19Z",
"aliases": [
"CVE-2024-22088"
],
"details": "Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22088"
},
{
"type": "WEB",
"url": "https://github.com/chendotjs/lotos/issues/7"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T04:15:07Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h93h-6948-g84m",
"modified": "2024-01-05T06:30:19Z",
"published": "2024-01-05T06:30:19Z",
"aliases": [
"CVE-2023-51277"
],
"details": "nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51277"
},
{
"type": "WEB",
"url": "https://github.com/tuxu/nbviewer-app/commit/dc1e4ddf64c78e13175a39b076fa0646fc62e581"
},
{
"type": "WEB",
"url": "https://developer.apple.com/documentation/security/notarizing_macos_software_before_distribution/resolving_common_notarization_issues#3087731"
},
{
"type": "WEB",
"url": "https://github.com/tuxu/nbviewer-app/compare/0.1.5...0.1.6"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=c0nawqA_bdI"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T05:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j225-cvw7-qrx7",
"modified": "2024-01-05T06:30:19Z",
"published": "2024-01-05T06:30:19Z",
"aliases": [
"CVE-2023-52323"
],
"details": "PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52323"
},
{
"type": "WEB",
"url": "https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst"
},
{
"type": "WEB",
"url": "https://pypi.org/project/pycryptodomex/#history"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T04:15:07Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m892-r7q3-ww6c",
"modified": "2024-01-05T06:30:19Z",
"published": "2024-01-05T06:30:19Z",
"aliases": [
"CVE-2024-22087"
],
"details": "route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22087"
},
{
"type": "WEB",
"url": "https://github.com/foxweb/pico/issues/31"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-05T04:15:07Z"
}
}