Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-06-12 18:31:57 +00:00
parent ac206a1c90
commit 720c22cd19
52 changed files with 1205 additions and 70 deletions
@@ -55,7 +55,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-327"
"CWE-327",
"CWE-347"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23pr-fhrm-f58r",
"modified": "2024-06-10T09:31:05Z",
"modified": "2024-06-12T18:30:38Z",
"published": "2024-06-10T09:31:05Z",
"aliases": [
"CVE-2024-35721"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26v6-wwwv-j4cc",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-5909"
],
"details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5909"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2024-5909"
}
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:53Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2ch9-gmhf-h625",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-37039"
],
"details": "CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the\ndevice when an attacker sends a specially crafted HTTP request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37039"
},
{
"type": "WEB",
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:51Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pvh-rqjq-h9px",
"modified": "2024-06-12T18:30:40Z",
"published": "2024-06-12T18:30:40Z",
"aliases": [
"CVE-2024-36761"
],
"details": "naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36761"
},
{
"type": "WEB",
"url": "https://github.com/gfx-rs/naga/issues/2591"
},
{
"type": "WEB",
"url": "https://github.com/MageWeiG/VulnerabilityCollection/blob/main/CVE-2024-36761/info.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T16:15:11Z"
}
}
@@ -0,0 +1,31 @@
{
"schema_version": "1.4.0",
"id": "GHSA-349w-vchp-x42g",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-2230"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2230"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c87-xvq4-93w3",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-37878"
],
"details": "Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php\" PHP directly echoes parameters input from external sources",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37878"
},
{
"type": "WEB",
"url": "https://gist.github.com/sylvieverykawaii/243f1756151bee027725c6961d8c1ba9"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:51Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qp4-cvq4-28r4",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-0865"
],
"details": "CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege\nescalation when logged in as a non-administrative user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0865"
},
{
"type": "WEB",
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-03.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T18:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rf3-8wmx-cm8q",
"modified": "2024-06-12T12:30:40Z",
"modified": "2024-06-12T18:30:39Z",
"published": "2024-06-10T09:31:06Z",
"aliases": [
"CVE-2024-36971"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix __dst_negative_advice() race\n\n__dst_negative_advice() does not enforce proper RCU rules when\nsk->dst_cache must be cleared, leading to possible UAF.\n\nRCU rules are that we must first clear sk->sk_dst_cache,\nthen call dst_release(old_dst).\n\nNote that sk_dst_reset(sk) is implementing this protocol correctly,\nwhile __dst_negative_advice() uses the wrong order.\n\nGiven that ip6_negative_advice() has special logic\nagainst RTF_CACHE, this means each of the three ->negative_advice()\nexisting methods must perform the sk_dst_reset() themselves.\n\nNote the check against NULL dst is centralized in\n__dst_negative_advice(), there is no need to duplicate\nit in various callbacks.\n\nMany thanks to Clement Lecigne for tracking this issue.\n\nThis old bug became visible after the blamed commit, using UDP sockets.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-10T09:15:09Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46fj-mg88-7m5g",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-5559"
],
"details": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could\ncause denial of service, device reboot, or an attacker gaining full control of the relay when a\nspecially crafted reset token is entered into the front panel of the device.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5559"
},
{
"type": "WEB",
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-02.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T18:15:12Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rrj-v9hp-2x5j",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-37040"
],
"details": "CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability\nexists that could allow a user with access to the devices web interface to cause a fault on the\ndevice when sending a malformed HTTP request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37040"
},
{
"type": "WEB",
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:51Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58rr-w6gv-4p4h",
"modified": "2024-06-10T03:30:47Z",
"modified": "2024-06-12T18:30:38Z",
"published": "2024-06-10T03:30:46Z",
"aliases": [
"CVE-2024-37880"
],
"details": "The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-10T02:15:47Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-829",
"CWE-98"
],
"severity": "MODERATE",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-683h-wmfw-2p2m",
"modified": "2024-06-09T21:30:33Z",
"modified": "2024-06-12T18:30:38Z",
"published": "2024-06-09T21:30:33Z",
"aliases": [
"CVE-2024-37570"
],
"details": "On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-09T20:15:09Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q37-cp6x-mhfw",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-5908"
],
"details": "A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5908"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2024-5908"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T17:15:53Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75r7-wf67-87f9",
"modified": "2024-06-10T18:31:09Z",
"modified": "2024-06-12T18:30:40Z",
"published": "2024-06-10T18:31:09Z",
"aliases": [
"CVE-2024-5102"
],
"details": "A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\\SYSTEM. The vulnerability exists within the \"Repair\" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the system files and make Windows callback to a specially-crafted file which could be used to launch a privileged shell instance.\n\nThis issue affects Avast Antivirus prior to 24.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1284"
"CWE-1284",
"CWE-59"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-10T17:16:34Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-794c-cp85-xv63",
"modified": "2024-06-10T09:31:05Z",
"modified": "2024-06-12T18:30:38Z",
"published": "2024-06-10T09:31:05Z",
"aliases": [
"CVE-2024-35722"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pqc-r2rx-5hhc",
"modified": "2024-06-10T21:30:38Z",
"modified": "2024-06-12T18:30:40Z",
"published": "2024-06-10T21:30:38Z",
"aliases": [
"CVE-2024-27792"
],
"details": "This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-10T20:15:13Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc55-mvqc-g9mg",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-37629"
],
"details": "SummerNote 0.8.18 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37629"
},
{
"type": "WEB",
"url": "https://github.com/summernote/summernote/issues/4642"
},
{
"type": "WEB",
"url": "https://grumpz.net/cve-2024-37629-simple-xss-payload-exploits-0day-vulnerability-in-10000-web-apps"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T18:15:12Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chfm-r46v-69qh",
"modified": "2024-06-12T18:30:41Z",
"published": "2024-06-12T18:30:41Z",
"aliases": [
"CVE-2024-28762"
],
"details": "IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 285246.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28762"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/285246"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7156847"
}
],
"database_specific": {
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T18:15:11Z"
}
}

Some files were not shown because too many files have changed in this diff Show More