mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7qf7-6m7f-hv3w",
|
||||
"modified": "2022-02-19T00:01:50Z",
|
||||
"modified": "2025-02-06T18:30:58Z",
|
||||
"published": "2022-02-12T00:00:44Z",
|
||||
"aliases": [
|
||||
"CVE-2021-34235"
|
||||
],
|
||||
"details": "Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
|
||||
@@ -31,7 +31,8 @@
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-119",
|
||||
"CWE-122"
|
||||
"CWE-122",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j8w2-wx5p-fvx4",
|
||||
"modified": "2022-05-13T01:14:58Z",
|
||||
"modified": "2025-02-06T18:30:58Z",
|
||||
"published": "2022-05-13T01:14:58Z",
|
||||
"aliases": [
|
||||
"CVE-2019-1653"
|
||||
@@ -82,7 +82,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-200"
|
||||
"CWE-200",
|
||||
"CWE-284"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v2fr-wv49-j53x",
|
||||
"modified": "2022-05-24T17:36:06Z",
|
||||
"modified": "2025-02-06T18:30:58Z",
|
||||
"published": "2022-05-24T17:36:06Z",
|
||||
"aliases": [
|
||||
"CVE-2020-29574"
|
||||
],
|
||||
"details": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x7vj-wqq4-cq4v",
|
||||
"modified": "2022-05-24T17:22:02Z",
|
||||
"modified": "2025-02-06T18:30:58Z",
|
||||
"published": "2022-05-24T17:22:02Z",
|
||||
"aliases": [
|
||||
"CVE-2020-15069"
|
||||
],
|
||||
"details": "Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -20,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rc8f-8m86-p4vm",
|
||||
"modified": "2022-11-22T21:30:18Z",
|
||||
"modified": "2025-02-06T18:30:58Z",
|
||||
"published": "2022-11-18T00:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-23748"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://cpr-zero.checkpoint.com/vulns/cprid-2193"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://cpr-zero.checkpoint.com/vulns/cprid-2193/%2C"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://cpr-zero.checkpoint.com/vulns/cprid-2193/,"
|
||||
@@ -34,6 +38,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-114",
|
||||
"CWE-426"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -29,7 +29,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-287"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -29,7 +29,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-639"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -33,7 +33,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-36g9-fjvv-qmj3",
|
||||
"modified": "2024-04-04T05:36:39Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:15Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27909"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7xr3-6fgq-rv6h",
|
||||
"modified": "2024-04-04T05:36:44Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24501"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-ffrf-xcmj-f59q",
|
||||
"modified": "2024-04-04T05:36:41Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:15Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27911"
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-122",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fqm3-34q3-vw23",
|
||||
"modified": "2024-04-04T05:36:45Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24502"
|
||||
@@ -26,7 +26,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-326"
|
||||
"CWE-326",
|
||||
"CWE-521"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fww7-pq4g-vxx7",
|
||||
"modified": "2024-04-04T05:36:43Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24500"
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-494"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gjg3-8mx2-7f8f",
|
||||
"modified": "2024-04-04T05:36:22Z",
|
||||
"modified": "2025-02-06T18:30:59Z",
|
||||
"published": "2023-07-06T19:24:15Z",
|
||||
"aliases": [
|
||||
"CVE-2022-38840"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m3qp-4rm3-pr3q",
|
||||
"modified": "2024-04-04T05:36:47Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-24503"
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-494"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pgrf-qrwj-3vf5",
|
||||
"modified": "2024-04-04T05:36:40Z",
|
||||
"modified": "2025-02-06T18:31:00Z",
|
||||
"published": "2023-07-06T19:24:15Z",
|
||||
"aliases": [
|
||||
"CVE-2023-27910"
|
||||
@@ -26,6 +26,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-121",
|
||||
"CWE-787"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,16 +1,20 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-24g5-r7q6-hhmg",
|
||||
"modified": "2024-05-16T21:31:56Z",
|
||||
"modified": "2025-02-06T18:31:01Z",
|
||||
"published": "2024-04-12T15:37:21Z",
|
||||
"aliases": [
|
||||
"CVE-2024-21605"
|
||||
],
|
||||
"details": "An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\n\n\nSpecific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the device. This leads to excessive resource consumption and in turn severe impact on all control and management protocols of the device.\n\n\n\nThis issue affects Juniper Networks Junos OS:\n * 21.2 version 21.2R3-S3 and later versions earlier than 21.2R3-S6;\n * 22.1 version 22.1R3 and later versions earlier than 22.1R3-S4;\n * 22.2 version \n\n22.2R2\n\nand later versions earlier than 22.2R3-S2;\n * 22.3 version \n\n22.3R2 \n\nand later versions earlier than 22.3R3-S1;\n\n * 22.4 versions earlier than 22.4R2-S2, 22.4R3;\n * 23.2 versions earlier than 23.2R1-S1, 23.2R2.\n\n\n\n\nThis issue does not affect Juniper Networks Junos OS 21.4R1 and later versions of 21.4.\n\n",
|
||||
"details": "An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\n\n\nSpecific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the device. This leads to excessive resource consumption and in turn severe impact on all control and management protocols of the device.\n\n\n\nThis issue affects Juniper Networks Junos OS:\n * 21.2 version 21.2R3-S3 and later versions earlier than 21.2R3-S6;\n * 22.1 version 22.1R3 and later versions earlier than 22.1R3-S4;\n * 22.2 version \n\n22.2R2\n\nand later versions earlier than 22.2R3-S2;\n * 22.3 version \n\n22.3R2 \n\nand later versions earlier than 22.3R3-S1;\n\n * 22.4 versions earlier than 22.4R2-S2, 22.4R3;\n * 23.2 versions earlier than 23.2R1-S1, 23.2R2.\n\n\n\n\nThis issue does not affect Juniper Networks Junos OS 21.4R1 and later versions of 21.4.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-26w9-32mp-48g9",
|
||||
"modified": "2024-04-25T06:30:35Z",
|
||||
"modified": "2025-02-06T18:31:01Z",
|
||||
"published": "2024-04-25T06:30:35Z",
|
||||
"aliases": [
|
||||
"CVE-2024-4159"
|
||||
],
|
||||
"details": "\nBrocade SANnav before Brocade SANnav v2.3.1 lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated, remote attacker to reach Kafka APIs and send malicious data.\n\n",
|
||||
"details": "Brocade SANnav before Brocade SANnav v2.3.1 lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated, remote attacker to reach Kafka APIs and send malicious data.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3xr5-7rvh-x3v2",
|
||||
"modified": "2025-01-30T18:32:04Z",
|
||||
"modified": "2025-02-06T18:31:01Z",
|
||||
"published": "2024-04-04T18:30:33Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25705"
|
||||
@@ -22,6 +22,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/the-portal-for-arcgis-security-2024-update-2-is-available-install-these-patches-at-your-earliest-opportunity-to-address-these-vulnerabilities"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user