From 720c22cd197e3d6bd2986ac895e97f031065301b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Jun 2024 18:31:57 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5357-c2jx-v7qh.json | 3 +- .../GHSA-23pr-fhrm-f58r.json | 2 +- .../GHSA-26v6-wwwv-j4cc.json | 35 +++++++++++++ .../GHSA-2ch9-gmhf-h625.json | 38 ++++++++++++++ .../GHSA-2pvh-rqjq-h9px.json | 39 +++++++++++++++ .../GHSA-349w-vchp-x42g.json | 31 ++++++++++++ .../GHSA-3c87-xvq4-93w3.json | 35 +++++++++++++ .../GHSA-3qp4-cvq4-28r4.json | 38 ++++++++++++++ .../GHSA-3rf3-8wmx-cm8q.json | 11 ++-- .../GHSA-46fj-mg88-7m5g.json | 38 ++++++++++++++ .../GHSA-4rrj-v9hp-2x5j.json | 38 ++++++++++++++ .../GHSA-58rr-w6gv-4p4h.json | 11 ++-- .../GHSA-64f4-8h54-qf3g.json | 1 + .../GHSA-683h-wmfw-2p2m.json | 11 ++-- .../GHSA-6q37-cp6x-mhfw.json | 35 +++++++++++++ .../GHSA-75r7-wf67-87f9.json | 12 +++-- .../GHSA-794c-cp85-xv63.json | 2 +- .../GHSA-8pqc-r2rx-5hhc.json | 9 ++-- .../GHSA-cc55-mvqc-g9mg.json | 39 +++++++++++++++ .../GHSA-chfm-r46v-69qh.json | 42 ++++++++++++++++ .../GHSA-cjpf-prr4-vrfm.json | 35 +++++++++++++ .../GHSA-f3h5-qqxj-cvgg.json | 38 ++++++++++++++ .../GHSA-g5jv-2gj9-v424.json | 50 +++++++++++++++++++ .../GHSA-gmx3-vpcp-74h9.json | 9 ++-- .../GHSA-gq77-25f4-cr3x.json | 9 ++-- .../GHSA-h339-65jr-4wwh.json | 50 +++++++++++++++++++ .../GHSA-h9rg-mrq2-9rc6.json | 9 ++-- .../GHSA-hh55-gjrq-j457.json | 38 ++++++++++++++ .../GHSA-j253-hr3w-xhj7.json | 38 ++++++++++++++ .../GHSA-j36h-6hh5-9jw6.json | 38 ++++++++++++++ .../GHSA-j37r-fj8f-2g89.json | 9 ++-- .../GHSA-jp38-8m55-7qcq.json | 11 ++-- .../GHSA-m2cr-jxg8-pr4v.json | 11 ++-- .../GHSA-mp92-8wvj-jphh.json | 11 ++-- .../GHSA-mv75-qm55-5jjf.json | 2 +- .../GHSA-p8p4-424q-cf58.json | 35 +++++++++++++ .../GHSA-prhw-q7f9-j4w8.json | 50 +++++++++++++++++++ .../GHSA-q5cc-c5xp-qh6h.json | 38 ++++++++++++++ .../GHSA-qhx6-9fwx-wcfm.json | 38 ++++++++++++++ .../GHSA-qjwc-rqjc-76pj.json | 35 +++++++++++++ .../GHSA-r3pr-q6h2-2wph.json | 38 ++++++++++++++ .../GHSA-r62h-v64h-w564.json | 9 ++-- .../GHSA-r796-crfr-hhr5.json | 38 ++++++++++++++ .../GHSA-v437-m266-vxr7.json | 11 ++-- .../GHSA-v5m7-r9rr-hxp7.json | 9 ++-- .../GHSA-vh98-48jw-fxwj.json | 35 +++++++++++++ .../GHSA-vmfr-35cq-g5ch.json | 9 ++-- .../GHSA-w7px-49pq-qfpj.json | 9 ++-- .../GHSA-whj9-g8q3-623p.json | 35 +++++++++++++ .../GHSA-x36j-wqpg-pv3x.json | 38 ++++++++++++++ .../GHSA-xwj5-5q25-vqmg.json | 9 ++-- .../GHSA-xxpf-fvph-64v2.json | 11 ++-- 52 files changed, 1205 insertions(+), 70 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-2ch9-gmhf-h625/GHSA-2ch9-gmhf-h625.json create mode 100644 advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json create mode 100644 advisories/unreviewed/2024/06/GHSA-349w-vchp-x42g/GHSA-349w-vchp-x42g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3c87-xvq4-93w3/GHSA-3c87-xvq4-93w3.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-46fj-mg88-7m5g/GHSA-46fj-mg88-7m5g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-4rrj-v9hp-2x5j/GHSA-4rrj-v9hp-2x5j.json create mode 100644 advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cc55-mvqc-g9mg/GHSA-cc55-mvqc-g9mg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-chfm-r46v-69qh/GHSA-chfm-r46v-69qh.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-f3h5-qqxj-cvgg/GHSA-f3h5-qqxj-cvgg.json create mode 100644 advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json create mode 100644 advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json create mode 100644 advisories/unreviewed/2024/06/GHSA-hh55-gjrq-j457/GHSA-hh55-gjrq-j457.json create mode 100644 advisories/unreviewed/2024/06/GHSA-j253-hr3w-xhj7/GHSA-j253-hr3w-xhj7.json create mode 100644 advisories/unreviewed/2024/06/GHSA-j36h-6hh5-9jw6/GHSA-j36h-6hh5-9jw6.json create mode 100644 advisories/unreviewed/2024/06/GHSA-p8p4-424q-cf58/GHSA-p8p4-424q-cf58.json create mode 100644 advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json create mode 100644 advisories/unreviewed/2024/06/GHSA-q5cc-c5xp-qh6h/GHSA-q5cc-c5xp-qh6h.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json create mode 100644 advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-r3pr-q6h2-2wph/GHSA-r3pr-q6h2-2wph.json create mode 100644 advisories/unreviewed/2024/06/GHSA-r796-crfr-hhr5/GHSA-r796-crfr-hhr5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json create mode 100644 advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json create mode 100644 advisories/unreviewed/2024/06/GHSA-x36j-wqpg-pv3x/GHSA-x36j-wqpg-pv3x.json diff --git a/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json b/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json index d81e6278cfe..0cdc13c0473 100644 --- a/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json +++ b/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json @@ -55,7 +55,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-327" + "CWE-327", + "CWE-347" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/unreviewed/2024/06/GHSA-23pr-fhrm-f58r/GHSA-23pr-fhrm-f58r.json b/advisories/unreviewed/2024/06/GHSA-23pr-fhrm-f58r/GHSA-23pr-fhrm-f58r.json index 2f35fe7d3a6..379f85e95a6 100644 --- a/advisories/unreviewed/2024/06/GHSA-23pr-fhrm-f58r/GHSA-23pr-fhrm-f58r.json +++ b/advisories/unreviewed/2024/06/GHSA-23pr-fhrm-f58r/GHSA-23pr-fhrm-f58r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23pr-fhrm-f58r", - "modified": "2024-06-10T09:31:05Z", + "modified": "2024-06-12T18:30:38Z", "published": "2024-06-10T09:31:05Z", "aliases": [ "CVE-2024-35721" diff --git a/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json b/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json new file mode 100644 index 00000000000..742de397809 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-26v6-wwwv-j4cc/GHSA-26v6-wwwv-j4cc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26v6-wwwv-j4cc", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5909" + ], + "details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5909" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5909" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-2ch9-gmhf-h625/GHSA-2ch9-gmhf-h625.json b/advisories/unreviewed/2024/06/GHSA-2ch9-gmhf-h625/GHSA-2ch9-gmhf-h625.json new file mode 100644 index 00000000000..1a690e30149 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2ch9-gmhf-h625/GHSA-2ch9-gmhf-h625.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ch9-gmhf-h625", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-37039" + ], + "details": "CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the\ndevice when an attacker sends a specially crafted HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37039" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-252" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json b/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json new file mode 100644 index 00000000000..b4b03e0394f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2pvh-rqjq-h9px/GHSA-2pvh-rqjq-h9px.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pvh-rqjq-h9px", + "modified": "2024-06-12T18:30:40Z", + "published": "2024-06-12T18:30:40Z", + "aliases": [ + "CVE-2024-36761" + ], + "details": "naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36761" + }, + { + "type": "WEB", + "url": "https://github.com/gfx-rs/naga/issues/2591" + }, + { + "type": "WEB", + "url": "https://github.com/MageWeiG/VulnerabilityCollection/blob/main/CVE-2024-36761/info.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-349w-vchp-x42g/GHSA-349w-vchp-x42g.json b/advisories/unreviewed/2024/06/GHSA-349w-vchp-x42g/GHSA-349w-vchp-x42g.json new file mode 100644 index 00000000000..0607b262735 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-349w-vchp-x42g/GHSA-349w-vchp-x42g.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-349w-vchp-x42g", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-2230" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2230" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3c87-xvq4-93w3/GHSA-3c87-xvq4-93w3.json b/advisories/unreviewed/2024/06/GHSA-3c87-xvq4-93w3/GHSA-3c87-xvq4-93w3.json new file mode 100644 index 00000000000..1a9b09c4fb6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3c87-xvq4-93w3/GHSA-3c87-xvq4-93w3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c87-xvq4-93w3", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-37878" + ], + "details": "Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php\" PHP directly echoes parameters input from external sources", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37878" + }, + { + "type": "WEB", + "url": "https://gist.github.com/sylvieverykawaii/243f1756151bee027725c6961d8c1ba9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json b/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json new file mode 100644 index 00000000000..bf91b0471d6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3qp4-cvq4-28r4/GHSA-3qp4-cvq4-28r4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qp4-cvq4-28r4", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-0865" + ], + "details": "CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege\nescalation when logged in as a non-administrative user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0865" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json b/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json index 21edc783abe..f1774dc7a1e 100644 --- a/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json +++ b/advisories/unreviewed/2024/06/GHSA-3rf3-8wmx-cm8q/GHSA-3rf3-8wmx-cm8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rf3-8wmx-cm8q", - "modified": "2024-06-12T12:30:40Z", + "modified": "2024-06-12T18:30:39Z", "published": "2024-06-10T09:31:06Z", "aliases": [ "CVE-2024-36971" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix __dst_negative_advice() race\n\n__dst_negative_advice() does not enforce proper RCU rules when\nsk->dst_cache must be cleared, leading to possible UAF.\n\nRCU rules are that we must first clear sk->sk_dst_cache,\nthen call dst_release(old_dst).\n\nNote that sk_dst_reset(sk) is implementing this protocol correctly,\nwhile __dst_negative_advice() uses the wrong order.\n\nGiven that ip6_negative_advice() has special logic\nagainst RTF_CACHE, this means each of the three ->negative_advice()\nexisting methods must perform the sk_dst_reset() themselves.\n\nNote the check against NULL dst is centralized in\n__dst_negative_advice(), there is no need to duplicate\nit in various callbacks.\n\nMany thanks to Clement Lecigne for tracking this issue.\n\nThis old bug became visible after the blamed commit, using UDP sockets.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T09:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-46fj-mg88-7m5g/GHSA-46fj-mg88-7m5g.json b/advisories/unreviewed/2024/06/GHSA-46fj-mg88-7m5g/GHSA-46fj-mg88-7m5g.json new file mode 100644 index 00000000000..8a18fa9182d --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-46fj-mg88-7m5g/GHSA-46fj-mg88-7m5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46fj-mg88-7m5g", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5559" + ], + "details": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could\ncause denial of service, device reboot, or an attacker gaining full control of the relay when a\nspecially crafted reset token is entered into the front panel of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5559" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4rrj-v9hp-2x5j/GHSA-4rrj-v9hp-2x5j.json b/advisories/unreviewed/2024/06/GHSA-4rrj-v9hp-2x5j/GHSA-4rrj-v9hp-2x5j.json new file mode 100644 index 00000000000..9457a382404 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4rrj-v9hp-2x5j/GHSA-4rrj-v9hp-2x5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rrj-v9hp-2x5j", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-37040" + ], + "details": "CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability\nexists that could allow a user with access to the device’s web interface to cause a fault on the\ndevice when sending a malformed HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37040" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-58rr-w6gv-4p4h/GHSA-58rr-w6gv-4p4h.json b/advisories/unreviewed/2024/06/GHSA-58rr-w6gv-4p4h/GHSA-58rr-w6gv-4p4h.json index b2cf53f4d4c..1060e8da82f 100644 --- a/advisories/unreviewed/2024/06/GHSA-58rr-w6gv-4p4h/GHSA-58rr-w6gv-4p4h.json +++ b/advisories/unreviewed/2024/06/GHSA-58rr-w6gv-4p4h/GHSA-58rr-w6gv-4p4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58rr-w6gv-4p4h", - "modified": "2024-06-10T03:30:47Z", + "modified": "2024-06-12T18:30:38Z", "published": "2024-06-10T03:30:46Z", "aliases": [ "CVE-2024-37880" ], "details": "The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T02:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json b/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json index 38bec273814..d12fba64508 100644 --- a/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json +++ b/advisories/unreviewed/2024/06/GHSA-64f4-8h54-qf3g/GHSA-64f4-8h54-qf3g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-98" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-683h-wmfw-2p2m/GHSA-683h-wmfw-2p2m.json b/advisories/unreviewed/2024/06/GHSA-683h-wmfw-2p2m/GHSA-683h-wmfw-2p2m.json index b2566d2af0e..01e2059928e 100644 --- a/advisories/unreviewed/2024/06/GHSA-683h-wmfw-2p2m/GHSA-683h-wmfw-2p2m.json +++ b/advisories/unreviewed/2024/06/GHSA-683h-wmfw-2p2m/GHSA-683h-wmfw-2p2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-683h-wmfw-2p2m", - "modified": "2024-06-09T21:30:33Z", + "modified": "2024-06-12T18:30:38Z", "published": "2024-06-09T21:30:33Z", "aliases": [ "CVE-2024-37570" ], "details": "On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-09T20:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json b/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json new file mode 100644 index 00000000000..1cc80232903 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6q37-cp6x-mhfw/GHSA-6q37-cp6x-mhfw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q37-cp6x-mhfw", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5908" + ], + "details": "A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5908" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5908" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-75r7-wf67-87f9/GHSA-75r7-wf67-87f9.json b/advisories/unreviewed/2024/06/GHSA-75r7-wf67-87f9/GHSA-75r7-wf67-87f9.json index 5306a8341c1..2a68129e218 100644 --- a/advisories/unreviewed/2024/06/GHSA-75r7-wf67-87f9/GHSA-75r7-wf67-87f9.json +++ b/advisories/unreviewed/2024/06/GHSA-75r7-wf67-87f9/GHSA-75r7-wf67-87f9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75r7-wf67-87f9", - "modified": "2024-06-10T18:31:09Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T18:31:09Z", "aliases": [ "CVE-2024-5102" ], "details": "A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\\SYSTEM. The vulnerability exists within the \"Repair\" (settings -> troubleshooting -> repair) feature, which attempts to delete a file in the current user's AppData directory as NT AUTHORITY\\SYSTEM. A low-privileged user can make a pseudo-symlink and a junction folder and point to a file on the system. This can provide a low-privileged user an Elevation of Privilege to win a race-condition which will re-create the system files and make Windows callback to a specially-crafted file which could be used to launch a privileged shell instance.\n\nThis issue affects Avast Antivirus prior to 24.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1284" + "CWE-1284", + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T17:16:34Z" diff --git a/advisories/unreviewed/2024/06/GHSA-794c-cp85-xv63/GHSA-794c-cp85-xv63.json b/advisories/unreviewed/2024/06/GHSA-794c-cp85-xv63/GHSA-794c-cp85-xv63.json index 11be4ddd50d..38098a6ea39 100644 --- a/advisories/unreviewed/2024/06/GHSA-794c-cp85-xv63/GHSA-794c-cp85-xv63.json +++ b/advisories/unreviewed/2024/06/GHSA-794c-cp85-xv63/GHSA-794c-cp85-xv63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-794c-cp85-xv63", - "modified": "2024-06-10T09:31:05Z", + "modified": "2024-06-12T18:30:38Z", "published": "2024-06-10T09:31:05Z", "aliases": [ "CVE-2024-35722" diff --git a/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json b/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json index fd159773c7e..8ff3696a6ad 100644 --- a/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json +++ b/advisories/unreviewed/2024/06/GHSA-8pqc-r2rx-5hhc/GHSA-8pqc-r2rx-5hhc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pqc-r2rx-5hhc", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2024-27792" ], "details": "This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cc55-mvqc-g9mg/GHSA-cc55-mvqc-g9mg.json b/advisories/unreviewed/2024/06/GHSA-cc55-mvqc-g9mg/GHSA-cc55-mvqc-g9mg.json new file mode 100644 index 00000000000..75be45032c6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cc55-mvqc-g9mg/GHSA-cc55-mvqc-g9mg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc55-mvqc-g9mg", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-37629" + ], + "details": "SummerNote 0.8.18 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37629" + }, + { + "type": "WEB", + "url": "https://github.com/summernote/summernote/issues/4642" + }, + { + "type": "WEB", + "url": "https://grumpz.net/cve-2024-37629-simple-xss-payload-exploits-0day-vulnerability-in-10000-web-apps" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-chfm-r46v-69qh/GHSA-chfm-r46v-69qh.json b/advisories/unreviewed/2024/06/GHSA-chfm-r46v-69qh/GHSA-chfm-r46v-69qh.json new file mode 100644 index 00000000000..90ebd5d13a6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-chfm-r46v-69qh/GHSA-chfm-r46v-69qh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chfm-r46v-69qh", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-28762" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 285246.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28762" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/285246" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7156847" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json b/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json new file mode 100644 index 00000000000..884d0b9ed92 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cjpf-prr4-vrfm/GHSA-cjpf-prr4-vrfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjpf-prr4-vrfm", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-24051" + ], + "details": "Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24051" + }, + { + "type": "WEB", + "url": "https://github.com/tkruppert/Reported_Vulnerabilities/blob/main/CVE-2024-24051.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f3h5-qqxj-cvgg/GHSA-f3h5-qqxj-cvgg.json b/advisories/unreviewed/2024/06/GHSA-f3h5-qqxj-cvgg/GHSA-f3h5-qqxj-cvgg.json new file mode 100644 index 00000000000..7d44e5de554 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f3h5-qqxj-cvgg/GHSA-f3h5-qqxj-cvgg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3h5-qqxj-cvgg", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-37038" + ], + "details": "CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated\nuser with access to the device’s web interface to perform unauthorized file and firmware\nuploads when crafting custom web requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37038" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json b/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json new file mode 100644 index 00000000000..0dae7eb6663 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-g5jv-2gj9-v424/GHSA-g5jv-2gj9-v424.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5jv-2gj9-v424", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5898" + ], + "details": "A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file print_payroll.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268142 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5898" + }, + { + "type": "WEB", + "url": "https://github.com/guiyxli/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.268142" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.268142" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.354926" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json b/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json index 89e72e7ceed..24220b7a36d 100644 --- a/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json +++ b/advisories/unreviewed/2024/06/GHSA-gmx3-vpcp-74h9/GHSA-gmx3-vpcp-74h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmx3-vpcp-74h9", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2022-48683" ], "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gq77-25f4-cr3x/GHSA-gq77-25f4-cr3x.json b/advisories/unreviewed/2024/06/GHSA-gq77-25f4-cr3x/GHSA-gq77-25f4-cr3x.json index 1745ac4ec9d..ffc7e78732d 100644 --- a/advisories/unreviewed/2024/06/GHSA-gq77-25f4-cr3x/GHSA-gq77-25f4-cr3x.json +++ b/advisories/unreviewed/2024/06/GHSA-gq77-25f4-cr3x/GHSA-gq77-25f4-cr3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq77-25f4-cr3x", - "modified": "2024-06-10T18:31:09Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T18:31:09Z", "aliases": [ "CVE-2024-31611" ], "details": "SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T17:16:26Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json b/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json new file mode 100644 index 00000000000..400d50299dc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-h339-65jr-4wwh/GHSA-h339-65jr-4wwh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h339-65jr-4wwh", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5896" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268140.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5896" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql12.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.268140" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.268140" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.354925" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json b/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json index 12803cea416..d6bcef51b91 100644 --- a/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json +++ b/advisories/unreviewed/2024/06/GHSA-h9rg-mrq2-9rc6/GHSA-h9rg-mrq2-9rc6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9rg-mrq2-9rc6", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2022-32933" ], "details": "An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hh55-gjrq-j457/GHSA-hh55-gjrq-j457.json b/advisories/unreviewed/2024/06/GHSA-hh55-gjrq-j457/GHSA-hh55-gjrq-j457.json new file mode 100644 index 00000000000..c1aba70d6b6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hh55-gjrq-j457/GHSA-hh55-gjrq-j457.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh55-gjrq-j457", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-37037" + ], + "details": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path\nTraversal’) vulnerability exists that could allow an authenticated user with access to the device’s\nweb interface to corrupt files and impact device functionality when sending a crafted HTTP\nrequest.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37037" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j253-hr3w-xhj7/GHSA-j253-hr3w-xhj7.json b/advisories/unreviewed/2024/06/GHSA-j253-hr3w-xhj7/GHSA-j253-hr3w-xhj7.json new file mode 100644 index 00000000000..5b1c3460795 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j253-hr3w-xhj7/GHSA-j253-hr3w-xhj7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j253-hr3w-xhj7", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5558" + ], + "details": "CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could\ncause escalation of privileges when an attacker abuses a limited admin account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5558" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-04.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j36h-6hh5-9jw6/GHSA-j36h-6hh5-9jw6.json b/advisories/unreviewed/2024/06/GHSA-j36h-6hh5-9jw6/GHSA-j36h-6hh5-9jw6.json new file mode 100644 index 00000000000..47279bf65cc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-j36h-6hh5-9jw6/GHSA-j36h-6hh5-9jw6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j36h-6hh5-9jw6", + "modified": "2024-06-12T18:30:40Z", + "published": "2024-06-12T18:30:40Z", + "aliases": [ + "CVE-2024-5759" + ], + "details": "An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5759" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2024-10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j37r-fj8f-2g89/GHSA-j37r-fj8f-2g89.json b/advisories/unreviewed/2024/06/GHSA-j37r-fj8f-2g89/GHSA-j37r-fj8f-2g89.json index d6f0f421287..9e39509ba20 100644 --- a/advisories/unreviewed/2024/06/GHSA-j37r-fj8f-2g89/GHSA-j37r-fj8f-2g89.json +++ b/advisories/unreviewed/2024/06/GHSA-j37r-fj8f-2g89/GHSA-j37r-fj8f-2g89.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j37r-fj8f-2g89", - "modified": "2024-06-10T12:30:42Z", + "modified": "2024-06-12T18:30:39Z", "published": "2024-06-10T12:30:42Z", "aliases": [ "CVE-2024-3699" ], "details": "Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T12:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json b/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json index 74c5eb35a9b..457ac26877a 100644 --- a/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json +++ b/advisories/unreviewed/2024/06/GHSA-jp38-8m55-7qcq/GHSA-jp38-8m55-7qcq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jp38-8m55-7qcq", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2022-32897" ], "details": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json b/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json index c146210336c..cc22f57dacf 100644 --- a/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json +++ b/advisories/unreviewed/2024/06/GHSA-m2cr-jxg8-pr4v/GHSA-m2cr-jxg8-pr4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2cr-jxg8-pr4v", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2024-37393" ], "details": "Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mp92-8wvj-jphh/GHSA-mp92-8wvj-jphh.json b/advisories/unreviewed/2024/06/GHSA-mp92-8wvj-jphh/GHSA-mp92-8wvj-jphh.json index e0d7c9a1268..591899d1d05 100644 --- a/advisories/unreviewed/2024/06/GHSA-mp92-8wvj-jphh/GHSA-mp92-8wvj-jphh.json +++ b/advisories/unreviewed/2024/06/GHSA-mp92-8wvj-jphh/GHSA-mp92-8wvj-jphh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mp92-8wvj-jphh", - "modified": "2024-06-09T21:30:33Z", + "modified": "2024-06-12T18:30:38Z", "published": "2024-06-09T21:30:33Z", "aliases": [ "CVE-2024-37569" ], "details": "An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-09T20:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mv75-qm55-5jjf/GHSA-mv75-qm55-5jjf.json b/advisories/unreviewed/2024/06/GHSA-mv75-qm55-5jjf/GHSA-mv75-qm55-5jjf.json index 1ee7810a6f9..e665b00c4c2 100644 --- a/advisories/unreviewed/2024/06/GHSA-mv75-qm55-5jjf/GHSA-mv75-qm55-5jjf.json +++ b/advisories/unreviewed/2024/06/GHSA-mv75-qm55-5jjf/GHSA-mv75-qm55-5jjf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mv75-qm55-5jjf", - "modified": "2024-06-10T18:31:09Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T18:31:09Z", "aliases": [ "CVE-2024-5597" diff --git a/advisories/unreviewed/2024/06/GHSA-p8p4-424q-cf58/GHSA-p8p4-424q-cf58.json b/advisories/unreviewed/2024/06/GHSA-p8p4-424q-cf58/GHSA-p8p4-424q-cf58.json new file mode 100644 index 00000000000..4e1b2b045dc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-p8p4-424q-cf58/GHSA-p8p4-424q-cf58.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8p4-424q-cf58", + "modified": "2024-06-12T18:30:40Z", + "published": "2024-06-12T18:30:40Z", + "aliases": [ + "CVE-2024-22855" + ], + "details": "A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22855" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52025" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json b/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json new file mode 100644 index 00000000000..d42a15555da --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-prhw-q7f9-j4w8/GHSA-prhw-q7f9-j4w8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prhw-q7f9-j4w8", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5897" + ], + "details": "A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268141 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5897" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.268141" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.268141" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.354923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-q5cc-c5xp-qh6h/GHSA-q5cc-c5xp-qh6h.json b/advisories/unreviewed/2024/06/GHSA-q5cc-c5xp-qh6h/GHSA-q5cc-c5xp-qh6h.json new file mode 100644 index 00000000000..441bdfe325c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-q5cc-c5xp-qh6h/GHSA-q5cc-c5xp-qh6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5cc-c5xp-qh6h", + "modified": "2024-06-12T18:30:40Z", + "published": "2024-06-12T18:30:40Z", + "aliases": [ + "CVE-2024-37036" + ], + "details": "CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass\nwhen sending a malformed POST request and particular configuration parameters are set.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37036" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json b/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json new file mode 100644 index 00000000000..e285374ee06 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qhx6-9fwx-wcfm/GHSA-qhx6-9fwx-wcfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhx6-9fwx-wcfm", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-2747" + ], + "details": "CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could\ncause privilege escalation when a valid user replaces a trusted file name on the system and\nreboots the machine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2747" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-100-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-100-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json b/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json new file mode 100644 index 00000000000..27b15ddaddf --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-qjwc-rqjc-76pj/GHSA-qjwc-rqjc-76pj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjwc-rqjc-76pj", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5905" + ], + "details": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5905" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5905" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r3pr-q6h2-2wph/GHSA-r3pr-q6h2-2wph.json b/advisories/unreviewed/2024/06/GHSA-r3pr-q6h2-2wph/GHSA-r3pr-q6h2-2wph.json new file mode 100644 index 00000000000..7a30666b87f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r3pr-q6h2-2wph/GHSA-r3pr-q6h2-2wph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3pr-q6h2-2wph", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5557" + ], + "details": "CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause\nexposure of SNMP credentials when an attacker has access to the controller logs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5557" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-04.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r62h-v64h-w564/GHSA-r62h-v64h-w564.json b/advisories/unreviewed/2024/06/GHSA-r62h-v64h-w564/GHSA-r62h-v64h-w564.json index 1b3041f8db8..771e072c372 100644 --- a/advisories/unreviewed/2024/06/GHSA-r62h-v64h-w564/GHSA-r62h-v64h-w564.json +++ b/advisories/unreviewed/2024/06/GHSA-r62h-v64h-w564/GHSA-r62h-v64h-w564.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r62h-v64h-w564", - "modified": "2024-06-10T12:30:42Z", + "modified": "2024-06-12T18:30:39Z", "published": "2024-06-10T12:30:42Z", "aliases": [ "CVE-2024-3700" ], "details": "Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations.\n\nThis issue affects Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T12:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r796-crfr-hhr5/GHSA-r796-crfr-hhr5.json b/advisories/unreviewed/2024/06/GHSA-r796-crfr-hhr5/GHSA-r796-crfr-hhr5.json new file mode 100644 index 00000000000..895925743be --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r796-crfr-hhr5/GHSA-r796-crfr-hhr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r796-crfr-hhr5", + "modified": "2024-06-12T18:30:40Z", + "published": "2024-06-12T18:30:40Z", + "aliases": [ + "CVE-2024-1891" + ], + "details": "A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1891" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2024-10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-v437-m266-vxr7/GHSA-v437-m266-vxr7.json b/advisories/unreviewed/2024/06/GHSA-v437-m266-vxr7/GHSA-v437-m266-vxr7.json index 32312f4ffa9..e79328d1cec 100644 --- a/advisories/unreviewed/2024/06/GHSA-v437-m266-vxr7/GHSA-v437-m266-vxr7.json +++ b/advisories/unreviewed/2024/06/GHSA-v437-m266-vxr7/GHSA-v437-m266-vxr7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v437-m266-vxr7", - "modified": "2024-06-10T18:31:09Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T18:31:09Z", "aliases": [ "CVE-2024-31612" ], "details": "Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T18:15:31Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v5m7-r9rr-hxp7/GHSA-v5m7-r9rr-hxp7.json b/advisories/unreviewed/2024/06/GHSA-v5m7-r9rr-hxp7/GHSA-v5m7-r9rr-hxp7.json index 956b537568f..ccf57d73222 100644 --- a/advisories/unreviewed/2024/06/GHSA-v5m7-r9rr-hxp7/GHSA-v5m7-r9rr-hxp7.json +++ b/advisories/unreviewed/2024/06/GHSA-v5m7-r9rr-hxp7/GHSA-v5m7-r9rr-hxp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5m7-r9rr-hxp7", - "modified": "2024-06-10T12:30:42Z", + "modified": "2024-06-12T18:30:39Z", "published": "2024-06-10T12:30:42Z", "aliases": [ "CVE-2024-1228" ], "details": "Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations.\n\nThis issue affects Eurosoft Przychodnia software before version 20240417.001 (from that version vulnerability is fixed).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T12:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json b/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json new file mode 100644 index 00000000000..e16af64303c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vh98-48jw-fxwj/GHSA-vh98-48jw-fxwj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh98-48jw-fxwj", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5907" + ], + "details": "A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5907" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5907" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json b/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json index 90c76779ba8..0e87054f1a9 100644 --- a/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json +++ b/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmfr-35cq-g5ch", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2024-23299" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json b/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json index bbff88e5a2c..8068627b852 100644 --- a/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json +++ b/advisories/unreviewed/2024/06/GHSA-w7px-49pq-qfpj/GHSA-w7px-49pq-qfpj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7px-49pq-qfpj", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2023-40389" ], "details": "The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json b/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json new file mode 100644 index 00000000000..14867e2c243 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-whj9-g8q3-623p/GHSA-whj9-g8q3-623p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whj9-g8q3-623p", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5906" + ], + "details": "A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5906" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5906" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x36j-wqpg-pv3x/GHSA-x36j-wqpg-pv3x.json b/advisories/unreviewed/2024/06/GHSA-x36j-wqpg-pv3x/GHSA-x36j-wqpg-pv3x.json new file mode 100644 index 00000000000..627733ed512 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-x36j-wqpg-pv3x/GHSA-x36j-wqpg-pv3x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x36j-wqpg-pv3x", + "modified": "2024-06-12T18:30:41Z", + "published": "2024-06-12T18:30:41Z", + "aliases": [ + "CVE-2024-5560" + ], + "details": "CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the\ndevice’s web interface when an attacker sends a specially crafted HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5560" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-12T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json b/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json index 616cffa0d2a..a28c9a169b2 100644 --- a/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json +++ b/advisories/unreviewed/2024/06/GHSA-xwj5-5q25-vqmg/GHSA-xwj5-5q25-vqmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwj5-5q25-vqmg", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2024-32167" ], "details": "Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json b/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json index c793b78b7b2..839a68c16b0 100644 --- a/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json +++ b/advisories/unreviewed/2024/06/GHSA-xxpf-fvph-64v2/GHSA-xxpf-fvph-64v2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xxpf-fvph-64v2", - "modified": "2024-06-10T21:30:38Z", + "modified": "2024-06-12T18:30:40Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2022-48578" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5. Processing an AppleScript may result in unexpected termination or disclosure of process memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-10T20:15:12Z"