From 713d56f031aaa1751bd299d44b150e5221c7f2d4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 10 Jun 2024 21:31:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-wq96-w9cg-v635.json | 19 +++++- .../GHSA-4vg6-rmxw-vq23.json | 6 +- .../GHSA-2w5m-pqcc-26xx.json | 11 +-- .../GHSA-9cr4-w78w-p2qr.json | 6 +- .../GHSA-9gxf-r468-r4c5.json | 6 +- .../GHSA-fxqv-fm95-w2rw.json | 9 ++- .../GHSA-26hp-vwv6-p4qg.json | 47 +++++++++++++ .../GHSA-39m6-6wm4-cm5w.json | 63 +++++++++++++++++ .../GHSA-3cff-hppc-4g4r.json | 38 +++++++++++ .../GHSA-49gg-c8j8-3j2c.json | 35 ++++++++++ .../GHSA-596p-4hx4-frm9.json | 55 +++++++++++++++ .../GHSA-6jq2-3f4f-qgw5.json | 59 ++++++++++++++++ .../GHSA-7x84-wx2f-425f.json | 55 +++++++++++++++ .../GHSA-8pqc-r2rx-5hhc.json | 35 ++++++++++ .../GHSA-8vmh-j4m8-xhc4.json | 3 +- .../GHSA-984g-34ww-rvq9.json | 51 ++++++++++++++ .../GHSA-9p2j-9mm4-8r6m.json | 63 +++++++++++++++++ .../GHSA-c5vq-9hf6-g7cw.json | 55 +++++++++++++++ .../GHSA-cvp2-j7mv-gx79.json | 35 ++++++++++ .../GHSA-fvqw-wg8v-hmcw.json | 39 +++++++++++ .../GHSA-g3vc-vgcj-26vj.json | 47 +++++++++++++ .../GHSA-gc92-5p58-4rf7.json | 63 +++++++++++++++++ .../GHSA-gmx3-vpcp-74h9.json | 35 ++++++++++ .../GHSA-h98r-frj5-jj3c.json | 47 +++++++++++++ .../GHSA-h9rg-mrq2-9rc6.json | 35 ++++++++++ .../GHSA-hv3w-wgcx-8ggg.json | 47 +++++++++++++ .../GHSA-j24x-6m7r-h4gp.json | 59 ++++++++++++++++ .../GHSA-j776-p2rm-mmrr.json | 43 ++++++++++++ .../GHSA-jp38-8m55-7qcq.json | 35 ++++++++++ .../GHSA-jpjh-5cvh-hrp7.json | 51 ++++++++++++++ .../GHSA-m2cr-jxg8-pr4v.json | 43 ++++++++++++ .../GHSA-mv5f-f7c2-2pg5.json | 35 ++++++++++ .../GHSA-mxj9-494w-v3gp.json | 63 +++++++++++++++++ .../GHSA-p457-rwhw-j6q4.json | 59 ++++++++++++++++ .../GHSA-p82c-6c84-fq36.json | 39 +++++++++++ .../GHSA-pwf2-5r2p-9c9w.json | 55 +++++++++++++++ .../GHSA-qg33-x2c5-6p44.json | 35 ++++++++++ .../GHSA-qvvc-v3mj-qch5.json | 59 ++++++++++++++++ .../GHSA-r6h9-62mm-q9wm.json | 55 +++++++++++++++ .../GHSA-rfp9-6j63-rc88.json | 47 +++++++++++++ .../GHSA-rp5x-rj69-r36x.json | 39 +++++++++++ .../GHSA-rw6q-xw3r-fxvm.json | 55 +++++++++++++++ .../GHSA-rx6g-pr26-7gxj.json | 47 +++++++++++++ .../GHSA-v8pv-8xhp-96rh.json | 67 +++++++++++++++++++ .../GHSA-vmfr-35cq-g5ch.json | 43 ++++++++++++ .../GHSA-vxqj-33jf-35x5.json | 51 ++++++++++++++ .../GHSA-w7px-49pq-qfpj.json | 39 +++++++++++ .../GHSA-wfrc-c4v4-fvxm.json | 35 ++++++++++ .../GHSA-wwpw-6x6h-qhvr.json | 55 +++++++++++++++ .../GHSA-xf4m-339r-jvfr.json | 47 +++++++++++++ .../GHSA-xwj5-5q25-vqmg.json | 35 ++++++++++ .../GHSA-xxpf-fvph-64v2.json | 35 ++++++++++ 52 files changed, 2177 insertions(+), 13 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3cff-hppc-4g4r/GHSA-3cff-hppc-4g4r.json create mode 100644 advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-596p-4hx4-frm9/GHSA-596p-4hx4-frm9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-6jq2-3f4f-qgw5/GHSA-6jq2-3f4f-qgw5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-7x84-wx2f-425f/GHSA-7x84-wx2f-425f.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-984g-34ww-rvq9/GHSA-984g-34ww-rvq9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9p2j-9mm4-8r6m/GHSA-9p2j-9mm4-8r6m.json create mode 100644 advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json create mode 100644 advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json create mode 100644 advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json create mode 100644 advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json create mode 100644 advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json create mode 100644 advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json create mode 100644 advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-mxj9-494w-v3gp/GHSA-mxj9-494w-v3gp.json create mode 100644 advisories/unreviewed/2024/06/GHSA-p457-rwhw-j6q4/GHSA-p457-rwhw-j6q4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-p82c-6c84-fq36/GHSA-p82c-6c84-fq36.json create mode 100644 advisories/unreviewed/2024/06/GHSA-pwf2-5r2p-9c9w/GHSA-pwf2-5r2p-9c9w.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-r6h9-62mm-q9wm/GHSA-r6h9-62mm-q9wm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rfp9-6j63-rc88/GHSA-rfp9-6j63-rc88.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rw6q-xw3r-fxvm/GHSA-rw6q-xw3r-fxvm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-wwpw-6x6h-qhvr/GHSA-wwpw-6x6h-qhvr.json create mode 100644 advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json create mode 100644 advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json diff --git a/advisories/unreviewed/2022/05/GHSA-wq96-w9cg-v635/GHSA-wq96-w9cg-v635.json b/advisories/unreviewed/2022/05/GHSA-wq96-w9cg-v635/GHSA-wq96-w9cg-v635.json index 39947909026..1b14420dca2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wq96-w9cg-v635/GHSA-wq96-w9cg-v635.json +++ b/advisories/unreviewed/2022/05/GHSA-wq96-w9cg-v635/GHSA-wq96-w9cg-v635.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq96-w9cg-v635", - "modified": "2022-05-24T19:18:13Z", + "modified": "2024-06-10T21:30:34Z", "published": "2022-05-24T19:18:13Z", "aliases": [ "CVE-2021-35591" ], "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -18,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-35591" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MLAXYFLUDC636S46X34USCLDZAOFBM2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PRCU3RTIPVKPC3GMC76YW7DJEXUEY6FG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XF3ZFPL3JJ26YRUGXLXQZYJBLZV3WC2C" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5MLAXYFLUDC636S46X34USCLDZAOFBM2" diff --git a/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json b/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json index 0e672db6873..7d01d6c151f 100644 --- a/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json +++ b/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vg6-rmxw-vq23", - "modified": "2024-02-15T06:31:36Z", + "modified": "2024-06-10T21:30:34Z", "published": "2024-02-15T06:31:36Z", "aliases": [ "CVE-2024-25941" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240510-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-2w5m-pqcc-26xx/GHSA-2w5m-pqcc-26xx.json b/advisories/unreviewed/2024/05/GHSA-2w5m-pqcc-26xx/GHSA-2w5m-pqcc-26xx.json index fc6647a051f..b7e25036c00 100644 --- a/advisories/unreviewed/2024/05/GHSA-2w5m-pqcc-26xx/GHSA-2w5m-pqcc-26xx.json +++ b/advisories/unreviewed/2024/05/GHSA-2w5m-pqcc-26xx/GHSA-2w5m-pqcc-26xx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2w5m-pqcc-26xx", - "modified": "2024-05-01T03:30:31Z", + "modified": "2024-06-10T21:30:34Z", "published": "2024-05-01T03:30:31Z", "aliases": [ "CVE-2024-33764" ], "details": "lunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T03:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json b/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json index adc7d388f8f..778c8cff2e3 100644 --- a/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json +++ b/advisories/unreviewed/2024/05/GHSA-9cr4-w78w-p2qr/GHSA-9cr4-w78w-p2qr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cr4-w78w-p2qr", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-06-10T21:30:35Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-23229" @@ -38,6 +38,10 @@ "type": "WEB", "url": "https://support.apple.com/kb/HT214085" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214105" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/May/14" diff --git a/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json b/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json index 2d57306f796..449d325c708 100644 --- a/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json +++ b/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9gxf-r468-r4c5", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-06-10T21:30:35Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27789" @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://support.apple.com/kb/HT214100" }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214105" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT214107" diff --git a/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json b/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json index 91ed78a9ab7..cb16c690eaf 100644 --- a/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json +++ b/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxqv-fm95-w2rw", - "modified": "2024-05-03T21:30:29Z", + "modified": "2024-06-10T21:30:34Z", "published": "2024-05-03T15:30:55Z", "aliases": [ "CVE-2024-33844" ], "details": "The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong MAV_MISSION_TYPE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T15:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json b/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json new file mode 100644 index 00000000000..28929374da2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-26hp-vwv6-p4qg/GHSA-26hp-vwv6-p4qg.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26hp-vwv6-p4qg", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27855" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27855" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json b/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json new file mode 100644 index 00000000000..ef45c606fa6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-39m6-6wm4-cm5w/GHSA-39m6-6wm4-cm5w.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39m6-6wm4-cm5w", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27840" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27840" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3cff-hppc-4g4r/GHSA-3cff-hppc-4g4r.json b/advisories/unreviewed/2024/06/GHSA-3cff-hppc-4g4r/GHSA-3cff-hppc-4g4r.json new file mode 100644 index 00000000000..14af9cb8d9f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3cff-hppc-4g4r/GHSA-3cff-hppc-4g4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cff-hppc-4g4r", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-22279" + ], + "details": "Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade\n the service availability of the Cloud Foundry deployment if performed at scale.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22279" + }, + { + "type": "WEB", + "url": "https://www.cloudfoundry.org/blog/cve-2024-22279-gorouter-denial-of-service-attack" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json b/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json new file mode 100644 index 00000000000..98d8b95774c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-49gg-c8j8-3j2c/GHSA-49gg-c8j8-3j2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49gg-c8j8-3j2c", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-33850" + ], + "details": "Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33850" + }, + { + "type": "WEB", + "url": "https://docs.pexip.com/admin/security_bulletins.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-596p-4hx4-frm9/GHSA-596p-4hx4-frm9.json b/advisories/unreviewed/2024/06/GHSA-596p-4hx4-frm9/GHSA-596p-4hx4-frm9.json new file mode 100644 index 00000000000..6e925b5e194 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-596p-4hx4-frm9/GHSA-596p-4hx4-frm9.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-596p-4hx4-frm9", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27811" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to elevate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27811" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6jq2-3f4f-qgw5/GHSA-6jq2-3f4f-qgw5.json b/advisories/unreviewed/2024/06/GHSA-6jq2-3f4f-qgw5/GHSA-6jq2-3f4f-qgw5.json new file mode 100644 index 00000000000..4b435088eba --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6jq2-3f4f-qgw5/GHSA-6jq2-3f4f-qgw5.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jq2-3f4f-qgw5", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27805" + ], + "details": "An issue was addressed with improved validation of environment variables. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to access sensitive user data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27805" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7x84-wx2f-425f/GHSA-7x84-wx2f-425f.json b/advisories/unreviewed/2024/06/GHSA-7x84-wx2f-425f/GHSA-7x84-wx2f-425f.json new file mode 100644 index 00000000000..22558524ce6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7x84-wx2f-425f/GHSA-7x84-wx2f-425f.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x84-wx2f-425f", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27851" + ], + "details": "The issue was addressed with improved bounds checks. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27851" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json b/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json new file mode 100644 index 00000000000..fd159773c7e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pqc-r2rx-5hhc", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-27792" + ], + "details": "This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27792" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214084" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8vmh-j4m8-xhc4/GHSA-8vmh-j4m8-xhc4.json b/advisories/unreviewed/2024/06/GHSA-8vmh-j4m8-xhc4/GHSA-8vmh-j4m8-xhc4.json index 7246431936f..1ef8375ad95 100644 --- a/advisories/unreviewed/2024/06/GHSA-8vmh-j4m8-xhc4/GHSA-8vmh-j4m8-xhc4.json +++ b/advisories/unreviewed/2024/06/GHSA-8vmh-j4m8-xhc4/GHSA-8vmh-j4m8-xhc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vmh-j4m8-xhc4", - "modified": "2024-06-04T15:30:58Z", + "modified": "2024-06-10T21:30:37Z", "published": "2024-06-04T15:30:58Z", "aliases": [ "CVE-2024-35629" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-98" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/06/GHSA-984g-34ww-rvq9/GHSA-984g-34ww-rvq9.json b/advisories/unreviewed/2024/06/GHSA-984g-34ww-rvq9/GHSA-984g-34ww-rvq9.json new file mode 100644 index 00000000000..b7a37ea6e6e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-984g-34ww-rvq9/GHSA-984g-34ww-rvq9.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-984g-34ww-rvq9", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27833" + ], + "details": "An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5. Processing maliciously crafted web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27833" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9p2j-9mm4-8r6m/GHSA-9p2j-9mm4-8r6m.json b/advisories/unreviewed/2024/06/GHSA-9p2j-9mm4-8r6m/GHSA-9p2j-9mm4-8r6m.json new file mode 100644 index 00000000000..3fca82e05e3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9p2j-9mm4-8r6m/GHSA-9p2j-9mm4-8r6m.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p2j-9mm4-8r6m", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27831" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27831" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json b/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json new file mode 100644 index 00000000000..e6180041b5e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c5vq-9hf6-g7cw/GHSA-c5vq-9hf6-g7cw.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5vq-9hf6-g7cw", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27832" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to elevate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27832" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json b/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json new file mode 100644 index 00000000000..2b9a72ec7c4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cvp2-j7mv-gx79/GHSA-cvp2-j7mv-gx79.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvp2-j7mv-gx79", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27845" + ], + "details": "A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json b/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json new file mode 100644 index 00000000000..83774e31f9a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-fvqw-wg8v-hmcw/GHSA-fvqw-wg8v-hmcw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvqw-wg8v-hmcw", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27848" + ], + "details": "This issue was addressed with improved permissions checking. This issue is fixed in macOS Sonoma 14.5, iOS 17.5 and iPadOS 17.5. A malicious app may be able to gain root privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27848" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json b/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json new file mode 100644 index 00000000000..f7fabd93df9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g3vc-vgcj-26vj/GHSA-g3vc-vgcj-26vj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3vc-vgcj-26vj", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-23251" + ], + "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.5, watchOS 10.5, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. An attacker with physical access may be able to leak Mail account credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23251" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json b/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json new file mode 100644 index 00000000000..6257956c6bc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gc92-5p58-4rf7/GHSA-gc92-5p58-4rf7.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc92-5p58-4rf7", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27817" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27817" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json b/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json new file mode 100644 index 00000000000..89e72e7ceed --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmx3-vpcp-74h9", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2022-48683" + ], + "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its sandbox.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48683" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213488" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json b/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json new file mode 100644 index 00000000000..55a355041f1 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h98r-frj5-jj3c/GHSA-h98r-frj5-jj3c.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h98r-frj5-jj3c", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27844" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5. A website's permission dialog may persist after navigation away from the site.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json b/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json new file mode 100644 index 00000000000..12803cea416 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9rg-mrq2-9rc6", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2022-32933" + ], + "details": "An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32933" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json b/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json new file mode 100644 index 00000000000..a16bfae1497 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hv3w-wgcx-8ggg/GHSA-hv3w-wgcx-8ggg.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv3w-wgcx-8ggg", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27836" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, iOS 17.5 and iPadOS 17.5. Processing a maliciously crafted image may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27836" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json b/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json new file mode 100644 index 00000000000..75445ea1904 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j24x-6m7r-h4gp", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27838" + ], + "details": "The issue was addressed by adding additional logic. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27838" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json b/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json new file mode 100644 index 00000000000..784233dd7b3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j776-p2rm-mmrr/GHSA-j776-p2rm-mmrr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j776-p2rm-mmrr", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27885" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, macOS Monterey 12.7.5. An app may be able to modify protected parts of the file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27885" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json b/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json new file mode 100644 index 00000000000..74c5eb35a9b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp38-8m55-7qcq", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2022-32897" + ], + "details": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32897" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json b/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json new file mode 100644 index 00000000000..05591ec0b8c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jpjh-5cvh-hrp7/GHSA-jpjh-5cvh-hrp7.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpjh-5cvh-hrp7", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27828" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 1.2, watchOS 10.5, tvOS 17.5, iOS 17.5 and iPadOS 17.5. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27828" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json b/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json new file mode 100644 index 00000000000..c146210336c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2cr-jxg8-pr4v", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-37393" + ], + "details": "Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37393" + }, + { + "type": "WEB", + "url": "https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-ada2/ad2ce8fa-42a0-4371-ad18-5d1d1c488b22" + }, + { + "type": "WEB", + "url": "https://securenvoy.com/support" + }, + { + "type": "WEB", + "url": "https://www.optistream.io/blogs/tech/securenvoy-cve-2024-37393" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json b/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json new file mode 100644 index 00000000000..ae5407b8635 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv5f-f7c2-2pg5", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27814" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27814" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mxj9-494w-v3gp/GHSA-mxj9-494w-v3gp.json b/advisories/unreviewed/2024/06/GHSA-mxj9-494w-v3gp/GHSA-mxj9-494w-v3gp.json new file mode 100644 index 00000000000..e2f3150e8f0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mxj9-494w-v3gp/GHSA-mxj9-494w-v3gp.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxj9-494w-v3gp", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27802" + ], + "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27802" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p457-rwhw-j6q4/GHSA-p457-rwhw-j6q4.json b/advisories/unreviewed/2024/06/GHSA-p457-rwhw-j6q4/GHSA-p457-rwhw-j6q4.json new file mode 100644 index 00000000000..893170a5417 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p457-rwhw-j6q4/GHSA-p457-rwhw-j6q4.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p457-rwhw-j6q4", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27806" + ], + "details": "This issue was addressed with improved environment sanitization. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to access sensitive user data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27806" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-p82c-6c84-fq36/GHSA-p82c-6c84-fq36.json b/advisories/unreviewed/2024/06/GHSA-p82c-6c84-fq36/GHSA-p82c-6c84-fq36.json new file mode 100644 index 00000000000..b656f59f4ab --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p82c-6c84-fq36/GHSA-p82c-6c84-fq36.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p82c-6c84-fq36", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27807" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. An app may be able to circumvent App Privacy Report logging.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27807" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-pwf2-5r2p-9c9w/GHSA-pwf2-5r2p-9c9w.json b/advisories/unreviewed/2024/06/GHSA-pwf2-5r2p-9c9w/GHSA-pwf2-5r2p-9c9w.json new file mode 100644 index 00000000000..e54077e5963 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-pwf2-5r2p-9c9w/GHSA-pwf2-5r2p-9c9w.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwf2-5r2p-9c9w", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27808" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27808" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json b/advisories/unreviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json new file mode 100644 index 00000000000..79138273c12 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg33-x2c5-6p44", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-37014" + ], + "details": "Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the \"POST /api/v1/custom_component\" endpoint and provide a Python script.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37014" + }, + { + "type": "WEB", + "url": "https://github.com/langflow-ai/langflow/issues/1973" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json b/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json new file mode 100644 index 00000000000..2a9dbb743ae --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qvvc-v3mj-qch5/GHSA-qvvc-v3mj-qch5.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvvc-v3mj-qch5", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27820" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27820" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r6h9-62mm-q9wm/GHSA-r6h9-62mm-q9wm.json b/advisories/unreviewed/2024/06/GHSA-r6h9-62mm-q9wm/GHSA-r6h9-62mm-q9wm.json new file mode 100644 index 00000000000..f774f0cade4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r6h9-62mm-q9wm/GHSA-r6h9-62mm-q9wm.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6h9-62mm-q9wm", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27815" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27815" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rfp9-6j63-rc88/GHSA-rfp9-6j63-rc88.json b/advisories/unreviewed/2024/06/GHSA-rfp9-6j63-rc88/GHSA-rfp9-6j63-rc88.json new file mode 100644 index 00000000000..5a1467e5569 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rfp9-6j63-rc88/GHSA-rfp9-6j63-rc88.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfp9-6j63-rc88", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-27799" + ], + "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27799" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json b/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json new file mode 100644 index 00000000000..2bcfe1bdc45 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rp5x-rj69-r36x/GHSA-rp5x-rj69-r36x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp5x-rj69-r36x", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27812" + ], + "details": "The issue was addressed with improvements to the file handling protocol. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27812" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rw6q-xw3r-fxvm/GHSA-rw6q-xw3r-fxvm.json b/advisories/unreviewed/2024/06/GHSA-rw6q-xw3r-fxvm/GHSA-rw6q-xw3r-fxvm.json new file mode 100644 index 00000000000..b052bc75e34 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rw6q-xw3r-fxvm/GHSA-rw6q-xw3r-fxvm.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw6q-xw3r-fxvm", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27830" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27830" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json b/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json new file mode 100644 index 00000000000..50434f32c63 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rx6g-pr26-7gxj/GHSA-rx6g-pr26-7gxj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx6g-pr26-7gxj", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-23282" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, watchOS 10.5, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A maliciously crafted email may be able to initiate FaceTime calls without user authorization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23282" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json b/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json new file mode 100644 index 00000000000..7e9446762a2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-v8pv-8xhp-96rh/GHSA-v8pv-8xhp-96rh.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8pv-8xhp-96rh", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27800" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8, tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing a maliciously crafted message may lead to a denial-of-service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27800" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214100" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214105" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214107" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json b/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json new file mode 100644 index 00000000000..90c76779ba8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmfr-35cq-g5ch", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-23299" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to break out of its sandbox.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23299" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214083" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214084" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214085" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json b/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json new file mode 100644 index 00000000000..91b9d9992d2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vxqj-33jf-35x5/GHSA-vxqj-33jf-35x5.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxqj-33jf-35x5", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27857" + ], + "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, tvOS 17.5, iOS 17.5 and iPadOS 17.5. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27857" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json b/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json new file mode 100644 index 00000000000..bbff88e5a2c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7px-49pq-qfpj", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2023-40389" + ], + "details": "The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to access sensitive user data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40389" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214083" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214085" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json b/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json new file mode 100644 index 00000000000..cc3f57243c3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfrc-c4v4-fvxm", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27819" + ], + "details": "The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27819" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wwpw-6x6h-qhvr/GHSA-wwpw-6x6h-qhvr.json b/advisories/unreviewed/2024/06/GHSA-wwpw-6x6h-qhvr/GHSA-wwpw-6x6h-qhvr.json new file mode 100644 index 00000000000..7c5de8cbe86 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-wwpw-6x6h-qhvr/GHSA-wwpw-6x6h-qhvr.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwpw-6x6h-qhvr", + "modified": "2024-06-10T21:30:39Z", + "published": "2024-06-10T21:30:39Z", + "aliases": [ + "CVE-2024-27801" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to elevate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27801" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214102" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214104" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json b/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json new file mode 100644 index 00000000000..760eb4eaf9e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf4m-339r-jvfr", + "modified": "2024-06-10T21:30:40Z", + "published": "2024-06-10T21:30:40Z", + "aliases": [ + "CVE-2024-27850" + ], + "details": "This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5, iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to fingerprint the user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27850" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214101" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214103" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214106" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT214108" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json b/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json new file mode 100644 index 00000000000..616cffa0d2a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwj5-5q25-vqmg", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2024-32167" + ], + "details": "Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32167" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/cms/blob/main/omos.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json b/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json new file mode 100644 index 00000000000..c793b78b7b2 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxpf-fvph-64v2", + "modified": "2024-06-10T21:30:38Z", + "published": "2024-06-10T21:30:38Z", + "aliases": [ + "CVE-2022-48578" + ], + "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5. Processing an AppleScript may result in unexpected termination or disclosure of process memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48578" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T20:15:12Z" + } +} \ No newline at end of file