From 77351e68fc20986c76405def75fd1f68abeac76f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Dec 2024 18:32:23 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-65fr-gpw6-j777.json | 1 + .../GHSA-8hjj-wf8c-mhwq.json | 3 +- .../GHSA-pvcj-xvm2-wgmw.json | 3 +- .../GHSA-rcv8-v727-xg26.json | 3 +- .../GHSA-25vc-3hfp-rp87.json | 15 ++++++-- .../GHSA-3ch6-f277-559q.json | 15 ++++++-- .../GHSA-43jg-wxfj-4rf7.json | 15 ++++++-- .../GHSA-48j9-xh9v-wh6m.json | 3 +- .../GHSA-65x6-qq63-m88g.json | 15 ++++++-- .../GHSA-66ww-hh28-59jg.json | 15 ++++++-- .../GHSA-6m5f-gf5f-wvx9.json | 15 ++++++-- .../GHSA-88w2-c8v7-h7p6.json | 15 ++++++-- .../GHSA-9pjj-2jvj-24rm.json | 15 ++++++-- .../GHSA-fq4x-x6f2-9q95.json | 15 ++++++-- .../GHSA-gpp8-r7jq-fh8v.json | 14 +++++-- .../GHSA-jxp6-f9wg-m536.json | 4 +- .../GHSA-prp3-rrcq-rrx9.json | 11 ++++-- .../GHSA-rgfh-pm48-24wc.json | 11 ++++-- .../GHSA-w8p8-q938-ccr8.json | 3 +- .../GHSA-wqm6-ppvq-v664.json | 15 ++++++-- .../GHSA-xc3w-pcvf-rm7m.json | 15 ++++++-- .../GHSA-x7v5-rxwv-mpjw.json | 4 +- .../GHSA-222x-r452-4688.json | 11 ++++-- .../GHSA-2gc3-gxvv-r87c.json | 11 ++++-- .../GHSA-8vgx-r4c9-cvmm.json | 15 ++++++-- .../GHSA-jqcw-7ccj-65rw.json | 11 ++++-- .../GHSA-rgmh-52xq-8wg7.json | 11 ++++-- .../GHSA-63pv-p59f-jpr4.json | 15 ++++++-- .../GHSA-m8g6-3qqh-77pv.json | 11 ++++-- .../GHSA-7q82-fxvh-gf2x.json | 6 ++- .../GHSA-2v3j-xqf9-rv5m.json | 11 ++++-- .../GHSA-4wg6-j4jc-xh8j.json | 29 +++++++++++++++ .../GHSA-52q6-f4x4-49j2.json | 11 ++++-- .../GHSA-5gjq-58c4-9ff5.json | 15 ++++++-- .../GHSA-5wwr-qqmw-x5rf.json | 29 +++++++++++++++ .../GHSA-6qhw-w3qj-8cf9.json | 29 +++++++++++++++ .../GHSA-7928-q347-xx6q.json | 36 ++++++++++++++++++ .../GHSA-9696-g44j-7f38.json | 29 +++++++++++++++ .../GHSA-c2gq-fxg8-22f9.json | 36 ++++++++++++++++++ .../GHSA-c4vf-pw69-v3w3.json | 36 ++++++++++++++++++ .../GHSA-c8qh-4m7p-p922.json | 33 +++++++++++++++++ .../GHSA-hmv6-ggqr-j3vm.json | 29 +++++++++++++++ .../GHSA-jm78-cpqh-vmm5.json | 15 ++++++-- .../GHSA-m48f-94xr-79qr.json | 37 +++++++++++++++++++ .../GHSA-m9wg-w5mf-5pw9.json | 37 +++++++++++++++++++ .../GHSA-px3q-m266-8w5r.json | 29 +++++++++++++++ .../GHSA-vfjm-xw35-h45p.json | 36 ++++++++++++++++++ .../GHSA-vh4h-v74p-9778.json | 29 +++++++++++++++ .../GHSA-vq37-g99r-q77r.json | 29 +++++++++++++++ .../GHSA-wcr5-5qw2-r34w.json | 36 ++++++++++++++++++ 50 files changed, 788 insertions(+), 99 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7928-q347-xx6q/GHSA-7928-q347-xx6q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c4vf-pw69-v3w3/GHSA-c4vf-pw69-v3w3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vfjm-xw35-h45p/GHSA-vfjm-xw35-h45p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wcr5-5qw2-r34w/GHSA-wcr5-5qw2-r34w.json diff --git a/advisories/unreviewed/2023/05/GHSA-65fr-gpw6-j777/GHSA-65fr-gpw6-j777.json b/advisories/unreviewed/2023/05/GHSA-65fr-gpw6-j777/GHSA-65fr-gpw6-j777.json index 3bfb0c64ec2..690a589a30b 100644 --- a/advisories/unreviewed/2023/05/GHSA-65fr-gpw6-j777/GHSA-65fr-gpw6-j777.json +++ b/advisories/unreviewed/2023/05/GHSA-65fr-gpw6-j777/GHSA-65fr-gpw6-j777.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1391", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/05/GHSA-8hjj-wf8c-mhwq/GHSA-8hjj-wf8c-mhwq.json b/advisories/unreviewed/2023/05/GHSA-8hjj-wf8c-mhwq/GHSA-8hjj-wf8c-mhwq.json index 1e13bf9458e..4ae24997da3 100644 --- a/advisories/unreviewed/2023/05/GHSA-8hjj-wf8c-mhwq/GHSA-8hjj-wf8c-mhwq.json +++ b/advisories/unreviewed/2023/05/GHSA-8hjj-wf8c-mhwq/GHSA-8hjj-wf8c-mhwq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-420" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-pvcj-xvm2-wgmw/GHSA-pvcj-xvm2-wgmw.json b/advisories/unreviewed/2023/05/GHSA-pvcj-xvm2-wgmw/GHSA-pvcj-xvm2-wgmw.json index 000f294a933..687dfdf1104 100644 --- a/advisories/unreviewed/2023/05/GHSA-pvcj-xvm2-wgmw/GHSA-pvcj-xvm2-wgmw.json +++ b/advisories/unreviewed/2023/05/GHSA-pvcj-xvm2-wgmw/GHSA-pvcj-xvm2-wgmw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-345" + "CWE-345", + "CWE-354" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-rcv8-v727-xg26/GHSA-rcv8-v727-xg26.json b/advisories/unreviewed/2023/05/GHSA-rcv8-v727-xg26/GHSA-rcv8-v727-xg26.json index fc01dfde338..431debc3e93 100644 --- a/advisories/unreviewed/2023/05/GHSA-rcv8-v727-xg26/GHSA-rcv8-v727-xg26.json +++ b/advisories/unreviewed/2023/05/GHSA-rcv8-v727-xg26/GHSA-rcv8-v727-xg26.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-413" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json b/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json index 7897c1522c5..315012bcc91 100644 --- a/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json +++ b/advisories/unreviewed/2024/02/GHSA-25vc-3hfp-rp87/GHSA-25vc-3hfp-rp87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-25vc-3hfp-rp87", - "modified": "2024-02-18T06:30:31Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-18T06:30:31Z", "aliases": [ "CVE-2023-52369" ], "details": "Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T04:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json b/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json index e43ad4245e6..98942011f77 100644 --- a/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json +++ b/advisories/unreviewed/2024/02/GHSA-3ch6-f277-559q/GHSA-3ch6-f277-559q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3ch6-f277-559q", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47013" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send\n\nIn emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..).\nIf some error happens in emac_tx_fill_tpd(), the skb will be freed via\ndev_kfree_skb(skb) in error branch of emac_tx_fill_tpd().\nBut the freed skb is still used via skb->len by netdev_sent_queue(,skb->len).\n\nAs i observed that emac_tx_fill_tpd() haven't modified the value of skb->len,\nthus my patch assigns skb->len to 'len' before the possible free and\nuse 'len' instead of skb->len later.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-43jg-wxfj-4rf7/GHSA-43jg-wxfj-4rf7.json b/advisories/unreviewed/2024/02/GHSA-43jg-wxfj-4rf7/GHSA-43jg-wxfj-4rf7.json index 77c01190a16..e597064eb6e 100644 --- a/advisories/unreviewed/2024/02/GHSA-43jg-wxfj-4rf7/GHSA-43jg-wxfj-4rf7.json +++ b/advisories/unreviewed/2024/02/GHSA-43jg-wxfj-4rf7/GHSA-43jg-wxfj-4rf7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-43jg-wxfj-4rf7", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47005" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: Fix NULL pointer dereference for ->get_features()\n\nget_features ops of pci_epc_ops may return NULL, causing NULL pointer\ndereference in pci_epf_test_alloc_space function. Let us add a check for\npci_epc_feature pointer in pci_epf_test_bind before we access it to avoid\nany such NULL pointer dereference and return -ENOTSUPP in case\npci_epc_feature is not found.\n\nWhen the patch is not applied and EPC features is not implemented in the\nplatform driver, we see the following dump due to kernel NULL pointer\ndereference.\n\nCall trace:\n pci_epf_test_bind+0xf4/0x388\n pci_epf_bind+0x3c/0x80\n pci_epc_epf_link+0xa8/0xcc\n configfs_symlink+0x1a4/0x48c\n vfs_symlink+0x104/0x184\n do_symlinkat+0x80/0xd4\n __arm64_sys_symlinkat+0x1c/0x24\n el0_svc_common.constprop.3+0xb8/0x170\n el0_svc_handler+0x70/0x88\n el0_svc+0x8/0x640\nCode: d2800581 b9403ab9 f9404ebb 8b394f60 (f9400400)\n---[ end trace a438e3c5a24f9df0 ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json b/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json index 31424d20485..5ade1641660 100644 --- a/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json +++ b/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json b/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json index 2bf2397776d..c619fb4a32c 100644 --- a/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json +++ b/advisories/unreviewed/2024/02/GHSA-65x6-qq63-m88g/GHSA-65x6-qq63-m88g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65x6-qq63-m88g", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47012" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix a use after free in siw_alloc_mr\n\nOur code analyzer reported a UAF.\n\nIn siw_alloc_mr(), it calls siw_mr_add_mem(mr,..). In the implementation of\nsiw_mr_add_mem(), mem is assigned to mr->mem and then mem is freed via\nkfree(mem) if xa_alloc_cyclic() failed. Here, mr->mem still point to a\nfreed object. After, the execution continue up to the err_out branch of\nsiw_alloc_mr, and the freed mr->mem is used in siw_mr_drop_mem(mr).\n\nMy patch moves \"mr->mem = mem\" behind the if (xa_alloc_cyclic(..)<0) {}\nsection, to avoid the uaf.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json b/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json index e8c01b1985c..e5ba11f34bd 100644 --- a/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json +++ b/advisories/unreviewed/2024/02/GHSA-66ww-hh28-59jg/GHSA-66ww-hh28-59jg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-66ww-hh28-59jg", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47017" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nath10k: Fix a use after free in ath10k_htc_send_bundle\n\nIn ath10k_htc_send_bundle, the bundle_skb could be freed by\ndev_kfree_skb_any(bundle_skb). But the bundle_skb is used later\nby bundle_skb->len.\n\nAs skb_len = bundle_skb->len, my patch replaces bundle_skb->len to\nskb_len after the bundle_skb was freed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json b/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json index d8b33897a05..88f59cc8255 100644 --- a/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json +++ b/advisories/unreviewed/2024/02/GHSA-6m5f-gf5f-wvx9/GHSA-6m5f-gf5f-wvx9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6m5f-gf5f-wvx9", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47022" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7615: fix memleak when mt7615_unregister_device()\n\nmt7615_tx_token_put() should get call before mt76_free_pending_txwi().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json b/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json index 2d1aa9e40bf..a23d5709e78 100644 --- a/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json +++ b/advisories/unreviewed/2024/02/GHSA-88w2-c8v7-h7p6/GHSA-88w2-c8v7-h7p6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88w2-c8v7-h7p6", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47021" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7915: fix memleak when mt7915_unregister_device()\n\nmt7915_tx_token_put() should get call before mt76_free_pending_txwi().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json b/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json index f2a641c10f2..67c49f79824 100644 --- a/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json +++ b/advisories/unreviewed/2024/02/GHSA-9pjj-2jvj-24rm/GHSA-9pjj-2jvj-24rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pjj-2jvj-24rm", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47008" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Make sure GHCB is mapped before updating\n\nAccess to the GHCB is mainly in the VMGEXIT path and it is known that the\nGHCB will be mapped. But there are two paths where it is possible the GHCB\nmight not be mapped.\n\nThe sev_vcpu_deliver_sipi_vector() routine will update the GHCB to inform\nthe caller of the AP Reset Hold NAE event that a SIPI has been delivered.\nHowever, if a SIPI is performed without a corresponding AP Reset Hold,\nthen the GHCB might not be mapped (depending on the previous VMEXIT),\nwhich will result in a NULL pointer dereference.\n\nThe svm_complete_emulated_msr() routine will update the GHCB to inform\nthe caller of a RDMSR/WRMSR operation about any errors. While it is likely\nthat the GHCB will be mapped in this situation, add a safe guard\nin this path to be certain a NULL pointer dereference is not encountered.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json b/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json index 04b5f09b6f6..3150f578ff2 100644 --- a/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json +++ b/advisories/unreviewed/2024/02/GHSA-fq4x-x6f2-9q95/GHSA-fq4x-x6f2-9q95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fq4x-x6f2-9q95", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47009" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix memory leak on object td\n\nTwo error return paths are neglecting to free allocated object td,\ncausing a memory leak. Fix this by returning via the error return\npath that securely kfree's td.\n\nFixes clang scan-build warning:\nsecurity/keys/trusted-keys/trusted_tpm1.c:496:10: warning: Potential\nmemory leak [unix.Malloc]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json b/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json index 63ef9c7c8f2..1a379c6bce8 100644 --- a/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json +++ b/advisories/unreviewed/2024/02/GHSA-gpp8-r7jq-fh8v/GHSA-gpp8-r7jq-fh8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gpp8-r7jq-fh8v", - "modified": "2024-02-18T03:30:24Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-18T03:30:24Z", "aliases": [ "CVE-2023-52365" ], "details": "Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -25,9 +30,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T03:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json b/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json index 56da811688f..cc812602a77 100644 --- a/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json +++ b/advisories/unreviewed/2024/02/GHSA-jxp6-f9wg-m536/GHSA-jxp6-f9wg-m536.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json b/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json index a8f839f7e57..b4f422f7304 100644 --- a/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json +++ b/advisories/unreviewed/2024/02/GHSA-prp3-rrcq-rrx9/GHSA-prp3-rrcq-rrx9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prp3-rrcq-rrx9", - "modified": "2024-02-18T03:30:24Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-18T03:30:24Z", "aliases": [ "CVE-2023-52387" ], "details": "Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T03:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json b/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json index e046d53f3c7..13baf1fb9ed 100644 --- a/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json +++ b/advisories/unreviewed/2024/02/GHSA-rgfh-pm48-24wc/GHSA-rgfh-pm48-24wc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgfh-pm48-24wc", - "modified": "2024-02-18T03:30:24Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-18T03:30:24Z", "aliases": [ "CVE-2023-52363" ], "details": "Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T03:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-w8p8-q938-ccr8/GHSA-w8p8-q938-ccr8.json b/advisories/unreviewed/2024/02/GHSA-w8p8-q938-ccr8/GHSA-w8p8-q938-ccr8.json index ca496d1af71..3a5f4a49124 100644 --- a/advisories/unreviewed/2024/02/GHSA-w8p8-q938-ccr8/GHSA-w8p8-q938-ccr8.json +++ b/advisories/unreviewed/2024/02/GHSA-w8p8-q938-ccr8/GHSA-w8p8-q938-ccr8.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-wqm6-ppvq-v664/GHSA-wqm6-ppvq-v664.json b/advisories/unreviewed/2024/02/GHSA-wqm6-ppvq-v664/GHSA-wqm6-ppvq-v664.json index 2c1d9a60834..8ed401783c3 100644 --- a/advisories/unreviewed/2024/02/GHSA-wqm6-ppvq-v664/GHSA-wqm6-ppvq-v664.json +++ b/advisories/unreviewed/2024/02/GHSA-wqm6-ppvq-v664/GHSA-wqm6-ppvq-v664.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wqm6-ppvq-v664", - "modified": "2024-07-05T09:33:42Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47002" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix null pointer dereference in svc_rqst_free()\n\nWhen alloc_pages_node() returns null in svc_rqst_alloc(), the\nnull rq_scratch_page pointer will be dereferenced when calling\nput_page() in svc_rqst_free(). Fix it by adding a null check.\n\nAddresses-Coverity: (\"Dereference after null check\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json b/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json index 3616a32fff5..c2ba3601052 100644 --- a/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json +++ b/advisories/unreviewed/2024/02/GHSA-xc3w-pcvf-rm7m/GHSA-xc3w-pcvf-rm7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xc3w-pcvf-rm7m", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47003" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Fix potential null dereference on pointer status\n\nThere are calls to idxd_cmd_exec that pass a null status pointer however\na recent commit has added an assignment to *status that can end up\nwith a null pointer dereference. The function expects a null status\npointer sometimes as there is a later assignment to *status where\nstatus is first null checked. Fix the issue by null checking status\nbefore making the assignment.\n\nAddresses-Coverity: (\"Explicit null dereferenced\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json b/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json index 623fc425787..7ffdddac344 100644 --- a/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json +++ b/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json index f0f4e0cbb0b..d229ed8ef3e 100644 --- a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json +++ b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-222x-r452-4688", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52359" ], "details": "Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module.\nImpact: Successful exploitation of this vulnerability will affect availability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json b/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json index e8fcff4658c..9abb2b3c8e7 100644 --- a/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json +++ b/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gc3-gxvv-r87c", - "modified": "2024-04-08T12:30:32Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-04-08T12:30:32Z", "aliases": [ "CVE-2024-27895" ], "details": "Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json b/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json index ed19f756208..c80051ea9dc 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json +++ b/advisories/unreviewed/2024/04/GHSA-8vgx-r4c9-cvmm/GHSA-8vgx-r4c9-cvmm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vgx-r4c9-cvmm", - "modified": "2024-04-08T12:30:32Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-04-08T12:30:32Z", "aliases": [ "CVE-2023-52386" ], "details": "Out-of-bounds write vulnerability in the RSMC module.\nImpact: Successful exploitation of this vulnerability will affect availability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json b/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json index deddedfa56e..4d9643ce5ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json +++ b/advisories/unreviewed/2024/04/GHSA-jqcw-7ccj-65rw/GHSA-jqcw-7ccj-65rw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqcw-7ccj-65rw", - "modified": "2024-04-07T09:30:29Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-04-07T09:30:29Z", "aliases": [ "CVE-2024-30417" ], "details": "Path traversal vulnerability in the Bluetooth-based sharing module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json index 45b1891fac5..8d550aaa86b 100644 --- a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json +++ b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgmh-52xq-8wg7", - "modified": "2024-04-07T09:30:29Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-04-07T09:30:29Z", "aliases": [ "CVE-2023-52715" ], "details": "The SystemUI module has a vulnerability in permission management.\nImpact: Successful exploitation of this vulnerability may affect availability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T09:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-63pv-p59f-jpr4/GHSA-63pv-p59f-jpr4.json b/advisories/unreviewed/2024/05/GHSA-63pv-p59f-jpr4/GHSA-63pv-p59f-jpr4.json index a4a9d201bd4..c9eea261c0f 100644 --- a/advisories/unreviewed/2024/05/GHSA-63pv-p59f-jpr4/GHSA-63pv-p59f-jpr4.json +++ b/advisories/unreviewed/2024/05/GHSA-63pv-p59f-jpr4/GHSA-63pv-p59f-jpr4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-63pv-p59f-jpr4", - "modified": "2024-05-07T15:30:40Z", + "modified": "2024-12-09T18:31:18Z", "published": "2024-05-07T15:30:40Z", "aliases": [ "CVE-2024-33122" ], "details": "Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T15:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m8g6-3qqh-77pv/GHSA-m8g6-3qqh-77pv.json b/advisories/unreviewed/2024/06/GHSA-m8g6-3qqh-77pv/GHSA-m8g6-3qqh-77pv.json index caad0dd7623..c84ebf5bf04 100644 --- a/advisories/unreviewed/2024/06/GHSA-m8g6-3qqh-77pv/GHSA-m8g6-3qqh-77pv.json +++ b/advisories/unreviewed/2024/06/GHSA-m8g6-3qqh-77pv/GHSA-m8g6-3qqh-77pv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8g6-3qqh-77pv", - "modified": "2024-06-13T06:30:53Z", + "modified": "2024-12-09T18:31:19Z", "published": "2024-06-13T06:30:53Z", "aliases": [ "CVE-2023-52890" ], "details": "NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T04:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json b/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json index 0bbbae3dcc1..5fd891b603c 100644 --- a/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json +++ b/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q82-fxvh-gf2x", - "modified": "2024-12-03T18:31:02Z", + "modified": "2024-12-09T18:31:19Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-51164" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51164" }, + { + "type": "WEB", + "url": "https://abcc111.github.io/posts/CVE-2024-51164" + }, { "type": "WEB", "url": "https://gitee.com/ketr/jepaas-release" diff --git a/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json b/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json index c0346cc69dc..eb90241b9df 100644 --- a/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json +++ b/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2v3j-xqf9-rv5m", - "modified": "2024-12-09T06:30:56Z", + "modified": "2024-12-09T18:31:19Z", "published": "2024-12-09T06:30:56Z", "aliases": [ "CVE-2024-9651" ], "details": "The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T06:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json b/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json new file mode 100644 index 00000000000..a6d266cdd37 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4wg6-j4jc-xh8j/GHSA-4wg6-j4jc-xh8j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wg6-j4jc-xh8j", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-54933" + ], + "details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54933" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/SQL%20Injection%20-%20delete%20content.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-52q6-f4x4-49j2/GHSA-52q6-f4x4-49j2.json b/advisories/unreviewed/2024/12/GHSA-52q6-f4x4-49j2/GHSA-52q6-f4x4-49j2.json index 2b43a2fc8c0..0f6554aa2b1 100644 --- a/advisories/unreviewed/2024/12/GHSA-52q6-f4x4-49j2/GHSA-52q6-f4x4-49j2.json +++ b/advisories/unreviewed/2024/12/GHSA-52q6-f4x4-49j2/GHSA-52q6-f4x4-49j2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-52q6-f4x4-49j2", - "modified": "2024-12-09T00:31:40Z", + "modified": "2024-12-09T18:31:19Z", "published": "2024-12-09T00:31:40Z", "aliases": [ "CVE-2024-55560" ], "details": "MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-08T23:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json b/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json index b1994d683e7..fff7d587a8b 100644 --- a/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json +++ b/advisories/unreviewed/2024/12/GHSA-5gjq-58c4-9ff5/GHSA-5gjq-58c4-9ff5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gjq-58c4-9ff5", - "modified": "2024-12-09T03:30:59Z", + "modified": "2024-12-09T18:31:19Z", "published": "2024-12-09T03:30:59Z", "aliases": [ "CVE-2024-55564" ], "details": "The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T02:15:19Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json b/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json new file mode 100644 index 00000000000..882ae456223 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5wwr-qqmw-x5rf/GHSA-5wwr-qqmw-x5rf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wwr-qqmw-x5rf", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2022-38946" + ], + "details": "Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38946" + }, + { + "type": "WEB", + "url": "https://github.com/Cosemz/CVE/blob/main/Doctor-Appointment.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json b/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json new file mode 100644 index 00000000000..f84289f1818 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6qhw-w3qj-8cf9/GHSA-6qhw-w3qj-8cf9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qhw-w3qj-8cf9", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-54930" + ], + "details": "Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54930" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/SQL%20Injection%20-%20delete%20student.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7928-q347-xx6q/GHSA-7928-q347-xx6q.json b/advisories/unreviewed/2024/12/GHSA-7928-q347-xx6q/GHSA-7928-q347-xx6q.json new file mode 100644 index 00000000000..756e9e3af7a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7928-q347-xx6q/GHSA-7928-q347-xx6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7928-q347-xx6q", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-45761" + ], + "details": "Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45761" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000258320/dsa-2024-481-security-update-for-dell-openmanage-server-administrator-omsa-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json b/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json new file mode 100644 index 00000000000..d2b11b198bb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9696-g44j-7f38", + "modified": "2024-12-09T18:31:20Z", + "published": "2024-12-09T18:31:20Z", + "aliases": [ + "CVE-2024-54935" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54935" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/Stored%20XSS%20-%20student%20message.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json b/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json new file mode 100644 index 00000000000..c600facad16 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c2gq-fxg8-22f9/GHSA-c2gq-fxg8-22f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2gq-fxg8-22f9", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-11608" + ], + "details": "A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11608" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c4vf-pw69-v3w3/GHSA-c4vf-pw69-v3w3.json b/advisories/unreviewed/2024/12/GHSA-c4vf-pw69-v3w3/GHSA-c4vf-pw69-v3w3.json new file mode 100644 index 00000000000..887f72f4f31 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c4vf-pw69-v3w3/GHSA-c4vf-pw69-v3w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4vf-pw69-v3w3", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-11268" + ], + "details": "A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11268" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json b/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json new file mode 100644 index 00000000000..b31df41f0a3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c8qh-4m7p-p922/GHSA-c8qh-4m7p-p922.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8qh-4m7p-p922", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-53450" + ], + "details": "RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53450" + }, + { + "type": "WEB", + "url": "https://github.com/infiniflow/ragflow/blob/cec208051f6f5996fefc8f36b6b71231b1807533/web/src/hooks/document-hooks.ts#L23" + }, + { + "type": "WEB", + "url": "https://github.com/thanhtung4102/Unauthentication-in-Ragflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json b/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json new file mode 100644 index 00000000000..3d128682fbf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hmv6-ggqr-j3vm/GHSA-hmv6-ggqr-j3vm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmv6-ggqr-j3vm", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2022-38947" + ], + "details": "SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38947" + }, + { + "type": "WEB", + "url": "https://github.com/Cosemz/CVE/blob/main/Flipkart-Clone-PHP/Flipkart-Clone-PHP.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jm78-cpqh-vmm5/GHSA-jm78-cpqh-vmm5.json b/advisories/unreviewed/2024/12/GHSA-jm78-cpqh-vmm5/GHSA-jm78-cpqh-vmm5.json index 30f72f7df0d..9d912a9090c 100644 --- a/advisories/unreviewed/2024/12/GHSA-jm78-cpqh-vmm5/GHSA-jm78-cpqh-vmm5.json +++ b/advisories/unreviewed/2024/12/GHSA-jm78-cpqh-vmm5/GHSA-jm78-cpqh-vmm5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jm78-cpqh-vmm5", - "modified": "2024-12-07T06:30:46Z", + "modified": "2024-12-09T18:31:19Z", "published": "2024-12-07T06:30:45Z", "aliases": [ "CVE-2024-11183" ], "details": "The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-07T06:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json b/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json new file mode 100644 index 00000000000..ca5db3aa799 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m48f-94xr-79qr/GHSA-m48f-94xr-79qr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m48f-94xr-79qr", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-40583" + ], + "details": "Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40583" + }, + { + "type": "WEB", + "url": "https://medium.com/@vishnuchttrj/exploiting-vms-vulnerabilities-to-access-confidential-data-cve-2024-40582-cve-2024-40583-60d957933b78" + }, + { + "type": "WEB", + "url": "http://curovms.com" + }, + { + "type": "WEB", + "url": "http://pentaminds.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json b/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json new file mode 100644 index 00000000000..d779fdcb003 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m9wg-w5mf-5pw9/GHSA-m9wg-w5mf-5pw9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9wg-w5mf-5pw9", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-40582" + ], + "details": "Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40582" + }, + { + "type": "WEB", + "url": "https://medium.com/@vishnuchttrj/exploiting-vms-vulnerabilities-to-access-confidential-data-cve-2024-40582-cve-2024-40583-60d957933b78" + }, + { + "type": "WEB", + "url": "http://curovms.com" + }, + { + "type": "WEB", + "url": "http://pentaminds.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json b/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json new file mode 100644 index 00000000000..5f920ca58f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-px3q-m266-8w5r/GHSA-px3q-m266-8w5r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px3q-m266-8w5r", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2023-43962" + ], + "details": "Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary code via the project name function in the project settings tab.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43962" + }, + { + "type": "WEB", + "url": "https://github.com/Cosemz/CVE/blob/main/xunruicms/XunRuiCms%20Stored%20XSS%20%28Authenticated%29.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vfjm-xw35-h45p/GHSA-vfjm-xw35-h45p.json b/advisories/unreviewed/2024/12/GHSA-vfjm-xw35-h45p/GHSA-vfjm-xw35-h45p.json new file mode 100644 index 00000000000..b815a25e487 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vfjm-xw35-h45p/GHSA-vfjm-xw35-h45p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfjm-xw35-h45p", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-11454" + ], + "details": "A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11454" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json b/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json new file mode 100644 index 00000000000..8c7d0c4e968 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vh4h-v74p-9778/GHSA-vh4h-v74p-9778.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh4h-v74p-9778", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-54926" + ], + "details": "A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54926" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/SQL%20Injection%20-%20search_class.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json b/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json new file mode 100644 index 00000000000..48d0bcdb08c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vq37-g99r-q77r/GHSA-vq37-g99r-q77r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq37-g99r-q77r", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-54922" + ], + "details": "A SQL Injection was found in /lms/admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54922" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/Kashipara/E-learning%20Management%20System%20project/SQL%20Injection%20-%20edit_user.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wcr5-5qw2-r34w/GHSA-wcr5-5qw2-r34w.json b/advisories/unreviewed/2024/12/GHSA-wcr5-5qw2-r34w/GHSA-wcr5-5qw2-r34w.json new file mode 100644 index 00000000000..30a971731c9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wcr5-5qw2-r34w/GHSA-wcr5-5qw2-r34w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcr5-5qw2-r34w", + "modified": "2024-12-09T18:31:19Z", + "published": "2024-12-09T18:31:19Z", + "aliases": [ + "CVE-2024-45760" + ], + "details": "Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45760" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000258320/dsa-2024-481-security-update-for-dell-openmanage-server-administrator-omsa-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T17:15:08Z" + } +} \ No newline at end of file