diff --git a/advisories/unreviewed/2023/12/GHSA-22fj-xvpx-pqm9/GHSA-22fj-xvpx-pqm9.json b/advisories/unreviewed/2023/12/GHSA-22fj-xvpx-pqm9/GHSA-22fj-xvpx-pqm9.json index bf5c1a6fb80..1a4dec90e46 100644 --- a/advisories/unreviewed/2023/12/GHSA-22fj-xvpx-pqm9/GHSA-22fj-xvpx-pqm9.json +++ b/advisories/unreviewed/2023/12/GHSA-22fj-xvpx-pqm9/GHSA-22fj-xvpx-pqm9.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-74" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-3f3f-5w2h-wvgq/GHSA-3f3f-5w2h-wvgq.json b/advisories/unreviewed/2023/12/GHSA-3f3f-5w2h-wvgq/GHSA-3f3f-5w2h-wvgq.json index cacea1ea090..61693593ea0 100644 --- a/advisories/unreviewed/2023/12/GHSA-3f3f-5w2h-wvgq/GHSA-3f3f-5w2h-wvgq.json +++ b/advisories/unreviewed/2023/12/GHSA-3f3f-5w2h-wvgq/GHSA-3f3f-5w2h-wvgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f3f-5w2h-wvgq", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:18Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-52135" diff --git a/advisories/unreviewed/2023/12/GHSA-5fhj-x7g6-jh74/GHSA-5fhj-x7g6-jh74.json b/advisories/unreviewed/2023/12/GHSA-5fhj-x7g6-jh74/GHSA-5fhj-x7g6-jh74.json index b43777037a0..b1fabeda75f 100644 --- a/advisories/unreviewed/2023/12/GHSA-5fhj-x7g6-jh74/GHSA-5fhj-x7g6-jh74.json +++ b/advisories/unreviewed/2023/12/GHSA-5fhj-x7g6-jh74/GHSA-5fhj-x7g6-jh74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5fhj-x7g6-jh74", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:19Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-44088" diff --git a/advisories/unreviewed/2023/12/GHSA-8987-77qq-2wwv/GHSA-8987-77qq-2wwv.json b/advisories/unreviewed/2023/12/GHSA-8987-77qq-2wwv/GHSA-8987-77qq-2wwv.json index 6c9f63ae72b..b8962a31d3f 100644 --- a/advisories/unreviewed/2023/12/GHSA-8987-77qq-2wwv/GHSA-8987-77qq-2wwv.json +++ b/advisories/unreviewed/2023/12/GHSA-8987-77qq-2wwv/GHSA-8987-77qq-2wwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8987-77qq-2wwv", - "modified": "2023-12-29T15:30:32Z", + "modified": "2024-01-05T06:30:18Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-51541" diff --git a/advisories/unreviewed/2023/12/GHSA-8pgv-qg6f-4chf/GHSA-8pgv-qg6f-4chf.json b/advisories/unreviewed/2023/12/GHSA-8pgv-qg6f-4chf/GHSA-8pgv-qg6f-4chf.json index 90b2ab52313..0e69c71382d 100644 --- a/advisories/unreviewed/2023/12/GHSA-8pgv-qg6f-4chf/GHSA-8pgv-qg6f-4chf.json +++ b/advisories/unreviewed/2023/12/GHSA-8pgv-qg6f-4chf/GHSA-8pgv-qg6f-4chf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pgv-qg6f-4chf", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:19Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-44089" diff --git a/advisories/unreviewed/2023/12/GHSA-h9vw-2v4g-wcq8/GHSA-h9vw-2v4g-wcq8.json b/advisories/unreviewed/2023/12/GHSA-h9vw-2v4g-wcq8/GHSA-h9vw-2v4g-wcq8.json index 810c884fe1a..d36b38a450a 100644 --- a/advisories/unreviewed/2023/12/GHSA-h9vw-2v4g-wcq8/GHSA-h9vw-2v4g-wcq8.json +++ b/advisories/unreviewed/2023/12/GHSA-h9vw-2v4g-wcq8/GHSA-h9vw-2v4g-wcq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h9vw-2v4g-wcq8", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:19Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-41815" diff --git a/advisories/unreviewed/2023/12/GHSA-rx6j-p5q4-cqf9/GHSA-rx6j-p5q4-cqf9.json b/advisories/unreviewed/2023/12/GHSA-rx6j-p5q4-cqf9/GHSA-rx6j-p5q4-cqf9.json index c3f3b0e5f57..ecd671df87d 100644 --- a/advisories/unreviewed/2023/12/GHSA-rx6j-p5q4-cqf9/GHSA-rx6j-p5q4-cqf9.json +++ b/advisories/unreviewed/2023/12/GHSA-rx6j-p5q4-cqf9/GHSA-rx6j-p5q4-cqf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rx6j-p5q4-cqf9", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:18Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-41813" diff --git a/advisories/unreviewed/2023/12/GHSA-vwrj-5xvr-9v9x/GHSA-vwrj-5xvr-9v9x.json b/advisories/unreviewed/2023/12/GHSA-vwrj-5xvr-9v9x/GHSA-vwrj-5xvr-9v9x.json index d1d29b265b0..cb2cd2ce004 100644 --- a/advisories/unreviewed/2023/12/GHSA-vwrj-5xvr-9v9x/GHSA-vwrj-5xvr-9v9x.json +++ b/advisories/unreviewed/2023/12/GHSA-vwrj-5xvr-9v9x/GHSA-vwrj-5xvr-9v9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwrj-5xvr-9v9x", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:19Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-41814" diff --git a/advisories/unreviewed/2023/12/GHSA-w8pm-g6gf-4v9x/GHSA-w8pm-g6gf-4v9x.json b/advisories/unreviewed/2023/12/GHSA-w8pm-g6gf-4v9x/GHSA-w8pm-g6gf-4v9x.json index bcfeeac13a3..7911d00b5ad 100644 --- a/advisories/unreviewed/2023/12/GHSA-w8pm-g6gf-4v9x/GHSA-w8pm-g6gf-4v9x.json +++ b/advisories/unreviewed/2023/12/GHSA-w8pm-g6gf-4v9x/GHSA-w8pm-g6gf-4v9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8pm-g6gf-4v9x", - "modified": "2023-12-29T12:30:41Z", + "modified": "2024-01-05T06:30:18Z", "published": "2023-12-29T12:30:41Z", "aliases": [ "CVE-2023-51372" diff --git a/advisories/unreviewed/2023/12/GHSA-w9xw-437c-59ch/GHSA-w9xw-437c-59ch.json b/advisories/unreviewed/2023/12/GHSA-w9xw-437c-59ch/GHSA-w9xw-437c-59ch.json index a587f10570f..584527fde23 100644 --- a/advisories/unreviewed/2023/12/GHSA-w9xw-437c-59ch/GHSA-w9xw-437c-59ch.json +++ b/advisories/unreviewed/2023/12/GHSA-w9xw-437c-59ch/GHSA-w9xw-437c-59ch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9xw-437c-59ch", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:18Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-51396" diff --git a/advisories/unreviewed/2023/12/GHSA-wf3c-fh77-x5hq/GHSA-wf3c-fh77-x5hq.json b/advisories/unreviewed/2023/12/GHSA-wf3c-fh77-x5hq/GHSA-wf3c-fh77-x5hq.json index ba6e3b99c13..1289780bb7a 100644 --- a/advisories/unreviewed/2023/12/GHSA-wf3c-fh77-x5hq/GHSA-wf3c-fh77-x5hq.json +++ b/advisories/unreviewed/2023/12/GHSA-wf3c-fh77-x5hq/GHSA-wf3c-fh77-x5hq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wf3c-fh77-x5hq", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T06:30:19Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-50837" diff --git a/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json b/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json new file mode 100644 index 00000000000..e813f26dbd4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-895h-3m6x-8h8x", + "modified": "2024-01-05T06:30:19Z", + "published": "2024-01-05T06:30:19Z", + "aliases": [ + "CVE-2024-22086" + ], + "details": "handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22086" + }, + { + "type": "WEB", + "url": "https://github.com/hayyp/cherry/issues/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h8cg-wwvx-fmhj/GHSA-h8cg-wwvx-fmhj.json b/advisories/unreviewed/2024/01/GHSA-h8cg-wwvx-fmhj/GHSA-h8cg-wwvx-fmhj.json new file mode 100644 index 00000000000..5ee2ded4c5d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h8cg-wwvx-fmhj/GHSA-h8cg-wwvx-fmhj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8cg-wwvx-fmhj", + "modified": "2024-01-05T06:30:19Z", + "published": "2024-01-05T06:30:19Z", + "aliases": [ + "CVE-2024-22088" + ], + "details": "Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22088" + }, + { + "type": "WEB", + "url": "https://github.com/chendotjs/lotos/issues/7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json b/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json new file mode 100644 index 00000000000..8349d1e4413 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h93h-6948-g84m", + "modified": "2024-01-05T06:30:19Z", + "published": "2024-01-05T06:30:19Z", + "aliases": [ + "CVE-2023-51277" + ], + "details": "nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51277" + }, + { + "type": "WEB", + "url": "https://github.com/tuxu/nbviewer-app/commit/dc1e4ddf64c78e13175a39b076fa0646fc62e581" + }, + { + "type": "WEB", + "url": "https://developer.apple.com/documentation/security/notarizing_macos_software_before_distribution/resolving_common_notarization_issues#3087731" + }, + { + "type": "WEB", + "url": "https://github.com/tuxu/nbviewer-app/compare/0.1.5...0.1.6" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=c0nawqA_bdI" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json b/advisories/unreviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json new file mode 100644 index 00000000000..d8202361c0a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j225-cvw7-qrx7", + "modified": "2024-01-05T06:30:19Z", + "published": "2024-01-05T06:30:19Z", + "aliases": [ + "CVE-2023-52323" + ], + "details": "PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52323" + }, + { + "type": "WEB", + "url": "https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/pycryptodomex/#history" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json b/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json new file mode 100644 index 00000000000..ca7479c159e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m892-r7q3-ww6c", + "modified": "2024-01-05T06:30:19Z", + "published": "2024-01-05T06:30:19Z", + "aliases": [ + "CVE-2024-22087" + ], + "details": "route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22087" + }, + { + "type": "WEB", + "url": "https://github.com/foxweb/pico/issues/31" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T04:15:07Z" + } +} \ No newline at end of file