diff --git a/advisories/unreviewed/2024/02/GHSA-gh95-m6w6-g25c/GHSA-gh95-m6w6-g25c.json b/advisories/unreviewed/2024/02/GHSA-gh95-m6w6-g25c/GHSA-gh95-m6w6-g25c.json index a43dc015d48..8109e5cae5d 100644 --- a/advisories/unreviewed/2024/02/GHSA-gh95-m6w6-g25c/GHSA-gh95-m6w6-g25c.json +++ b/advisories/unreviewed/2024/02/GHSA-gh95-m6w6-g25c/GHSA-gh95-m6w6-g25c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gh95-m6w6-g25c", - "modified": "2024-02-29T00:30:23Z", + "modified": "2024-11-26T09:30:47Z", "published": "2024-02-29T00:30:23Z", "aliases": [ "CVE-2024-21798" ], "details": "ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Affected products and versions are as follows: WRC-1167GS2-B v1.67 and earlier, WRC-1167GS2H-B v1.67 and earlier, WRC-2533GS2-B v1.62 and earlier, WRC-2533GS2-W v1.62 and earlier, and WRC-2533GS2V-B v1.62 and earlier.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T23:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x775-35gr-xw72/GHSA-x775-35gr-xw72.json b/advisories/unreviewed/2024/02/GHSA-x775-35gr-xw72/GHSA-x775-35gr-xw72.json index f8889189cad..92464a3c034 100644 --- a/advisories/unreviewed/2024/02/GHSA-x775-35gr-xw72/GHSA-x775-35gr-xw72.json +++ b/advisories/unreviewed/2024/02/GHSA-x775-35gr-xw72/GHSA-x775-35gr-xw72.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json index 17175722e55..c24443e3a4e 100644 --- a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json +++ b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq2p-5pc6-wpgf", - "modified": "2024-11-24T21:30:46Z", + "modified": "2024-11-26T09:30:48Z", "published": "2024-10-15T18:30:50Z", "aliases": [ "CVE-2024-9676" @@ -22,52 +22,12 @@ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9676" }, { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8418" + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-wq2p-5pc6-wpgf" }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8428" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8437" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8686" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8690" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8694" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8700" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:8984" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9051" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9454" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9459" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:9926" + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317467" }, { "type": "WEB", @@ -75,11 +35,55 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317467" + "url": "https://access.redhat.com/errata/RHSA-2024:9926" }, { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-wq2p-5pc6-wpgf" + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9459" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9454" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9051" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8984" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8700" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8694" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8690" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8686" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8437" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8428" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8418" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10289" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json b/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json new file mode 100644 index 00000000000..a11f391acf5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-27gg-q2pj-f574/GHSA-27gg-q2pj-f574.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27gg-q2pj-f574", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-32151" + ], + "details": "User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32151" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-257" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json b/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json new file mode 100644 index 00000000000..2d144104bcd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2php-gcq2-fxqp/GHSA-2php-gcq2-fxqp.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2php-gcq2-fxqp", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-33605" + ], + "details": "Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33605" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json b/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json new file mode 100644 index 00000000000..91a5db227f0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3chv-hrqx-p726", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2017-11076" + ], + "details": "On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-11076" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3gg9-g25v-rjf5/GHSA-3gg9-g25v-rjf5.json b/advisories/unreviewed/2024/11/GHSA-3gg9-g25v-rjf5/GHSA-3gg9-g25v-rjf5.json new file mode 100644 index 00000000000..6aa129acb73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3gg9-g25v-rjf5/GHSA-3gg9-g25v-rjf5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gg9-g25v-rjf5", + "modified": "2024-11-26T09:30:48Z", + "published": "2024-11-26T09:30:48Z", + "aliases": [ + "CVE-2024-10857" + ], + "details": "The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10857" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3195423/product-input-fields-for-woocommerce/trunk?contextall=1&old=3173573&old_path=%2Fproduct-input-fields-for-woocommerce%2Ftrunk" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e45207af-3886-4d95-9cd8-5ecdc683dc58?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3v44-23hf-q5wp/GHSA-3v44-23hf-q5wp.json b/advisories/unreviewed/2024/11/GHSA-3v44-23hf-q5wp/GHSA-3v44-23hf-q5wp.json new file mode 100644 index 00000000000..3a93a4c561e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3v44-23hf-q5wp/GHSA-3v44-23hf-q5wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v44-23hf-q5wp", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-8772" + ], + "details": "51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8772" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/permalink/231072/cve-2024-8772pdf-en-US_InternalID-231072.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-45wv-ch7h-93hx/GHSA-45wv-ch7h-93hx.json b/advisories/unreviewed/2024/11/GHSA-45wv-ch7h-93hx/GHSA-45wv-ch7h-93hx.json new file mode 100644 index 00000000000..4009a9a6e36 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-45wv-ch7h-93hx/GHSA-45wv-ch7h-93hx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45wv-ch7h-93hx", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2017-18153" + ], + "details": "A race condition exists in a driver potentially leading to a use-after-free condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-18153" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4f95-7725-5826/GHSA-4f95-7725-5826.json b/advisories/unreviewed/2024/11/GHSA-4f95-7725-5826/GHSA-4f95-7725-5826.json new file mode 100644 index 00000000000..e251ade7152 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4f95-7725-5826/GHSA-4f95-7725-5826.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f95-7725-5826", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-36254" + ], + "details": "Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36254" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5c2r-f52f-mq7p/GHSA-5c2r-f52f-mq7p.json b/advisories/unreviewed/2024/11/GHSA-5c2r-f52f-mq7p/GHSA-5c2r-f52f-mq7p.json new file mode 100644 index 00000000000..a3137981396 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5c2r-f52f-mq7p/GHSA-5c2r-f52f-mq7p.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c2r-f52f-mq7p", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-29146" + ], + "details": "User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29146" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5cqj-32fq-vgj6/GHSA-5cqj-32fq-vgj6.json b/advisories/unreviewed/2024/11/GHSA-5cqj-32fq-vgj6/GHSA-5cqj-32fq-vgj6.json new file mode 100644 index 00000000000..7af956eed3f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5cqj-32fq-vgj6/GHSA-5cqj-32fq-vgj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cqj-32fq-vgj6", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2018-11952" + ], + "details": "An image with a version lower than the fuse version may potentially be booted lead to improper authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-11952" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-62g5-fcg3-v3cp/GHSA-62g5-fcg3-v3cp.json b/advisories/unreviewed/2024/11/GHSA-62g5-fcg3-v3cp/GHSA-62g5-fcg3-v3cp.json new file mode 100644 index 00000000000..3ae8f024b86 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-62g5-fcg3-v3cp/GHSA-62g5-fcg3-v3cp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62g5-fcg3-v3cp", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-9504" + ], + "details": "The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9504" + }, + { + "type": "WEB", + "url": "https://hacked.be/posts/CVE-2024-9504" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3195800/booking-calendar" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1fb05281-205f-4d9c-aac9-2b37e069a6fb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6p9j-wxqr-cxf6/GHSA-6p9j-wxqr-cxf6.json b/advisories/unreviewed/2024/11/GHSA-6p9j-wxqr-cxf6/GHSA-6p9j-wxqr-cxf6.json new file mode 100644 index 00000000000..68277920fd8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6p9j-wxqr-cxf6/GHSA-6p9j-wxqr-cxf6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p9j-wxqr-cxf6", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-34162" + ], + "details": "The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to \"SIMPLE\", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34162" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-767" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6rr7-f623-4g74/GHSA-6rr7-f623-4g74.json b/advisories/unreviewed/2024/11/GHSA-6rr7-f623-4g74/GHSA-6rr7-f623-4g74.json new file mode 100644 index 00000000000..99ef275e321 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6rr7-f623-4g74/GHSA-6rr7-f623-4g74.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rr7-f623-4g74", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2024-11119" + ], + "details": "The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11119" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bne-gallery-extended/trunk/bne-gallery-extended.php#L178" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3191705" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/bne-gallery-extended/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1f9277d8-ac81-4950-a1e5-4e6c6b042f84?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7p2j-6vvg-vfq9/GHSA-7p2j-6vvg-vfq9.json b/advisories/unreviewed/2024/11/GHSA-7p2j-6vvg-vfq9/GHSA-7p2j-6vvg-vfq9.json new file mode 100644 index 00000000000..6b7ec4e378e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7p2j-6vvg-vfq9/GHSA-7p2j-6vvg-vfq9.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p2j-6vvg-vfq9", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-29978" + ], + "details": "User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29978" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92v2-fpqg-mwfv/GHSA-92v2-fpqg-mwfv.json b/advisories/unreviewed/2024/11/GHSA-92v2-fpqg-mwfv/GHSA-92v2-fpqg-mwfv.json new file mode 100644 index 00000000000..3838d9e6089 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92v2-fpqg-mwfv/GHSA-92v2-fpqg-mwfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92v2-fpqg-mwfv", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2018-11922" + ], + "details": "Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-11922" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-97w9-7qcx-qc77/GHSA-97w9-7qcx-qc77.json b/advisories/unreviewed/2024/11/GHSA-97w9-7qcx-qc77/GHSA-97w9-7qcx-qc77.json new file mode 100644 index 00000000000..e916df6a483 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-97w9-7qcx-qc77/GHSA-97w9-7qcx-qc77.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97w9-7qcx-qc77", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-36249" + ], + "details": "Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36249" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cjjx-vgmp-vf5g/GHSA-cjjx-vgmp-vf5g.json b/advisories/unreviewed/2024/11/GHSA-cjjx-vgmp-vf5g/GHSA-cjjx-vgmp-vf5g.json new file mode 100644 index 00000000000..a447e35a4c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cjjx-vgmp-vf5g/GHSA-cjjx-vgmp-vf5g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjjx-vgmp-vf5g", + "modified": "2024-11-26T09:30:48Z", + "published": "2024-11-26T09:30:48Z", + "aliases": [ + "CVE-2024-11002" + ], + "details": "The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11002" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/inpost-gallery/trunk/index.php#L323" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192113" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/inpost-gallery/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5fbb2dcf-38b8-4ef1-bfea-bf5872cc7e37?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cmfc-j23h-6h8c/GHSA-cmfc-j23h-6h8c.json b/advisories/unreviewed/2024/11/GHSA-cmfc-j23h-6h8c/GHSA-cmfc-j23h-6h8c.json new file mode 100644 index 00000000000..628354e786b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cmfc-j23h-6h8c/GHSA-cmfc-j23h-6h8c.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmfc-j23h-6h8c", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:48Z", + "aliases": [ + "CVE-2024-28038" + ], + "details": "The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28038" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cp6c-c5pc-v63g/GHSA-cp6c-c5pc-v63g.json b/advisories/unreviewed/2024/11/GHSA-cp6c-c5pc-v63g/GHSA-cp6c-c5pc-v63g.json new file mode 100644 index 00000000000..098cbe97973 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cp6c-c5pc-v63g/GHSA-cp6c-c5pc-v63g.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp6c-c5pc-v63g", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-36248" + ], + "details": "API keys for some cloud services are hardcoded in the \"main\" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36248" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f3p8-f68m-q84w/GHSA-f3p8-f68m-q84w.json b/advisories/unreviewed/2024/11/GHSA-f3p8-f68m-q84w/GHSA-f3p8-f68m-q84w.json new file mode 100644 index 00000000000..41756bf0c56 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f3p8-f68m-q84w/GHSA-f3p8-f68m-q84w.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3p8-f68m-q84w", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-36251" + ], + "details": "The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36251" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f3wf-2g4f-5hv8/GHSA-f3wf-2g4f-5hv8.json b/advisories/unreviewed/2024/11/GHSA-f3wf-2g4f-5hv8/GHSA-f3wf-2g4f-5hv8.json new file mode 100644 index 00000000000..fd586bba5be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f3wf-2g4f-5hv8/GHSA-f3wf-2g4f-5hv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3wf-2g4f-5hv8", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-6831" + ], + "details": "Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. \nAxis has released patched versions for the highlighted flaw. Please \nrefer to the Axis security advisory for more information and solution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6831" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/a2/9a/41/cve-2024-6831-en-US-455107.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fcgq-rhw7-f4x4/GHSA-fcgq-rhw7-f4x4.json b/advisories/unreviewed/2024/11/GHSA-fcgq-rhw7-f4x4/GHSA-fcgq-rhw7-f4x4.json new file mode 100644 index 00000000000..4d316505798 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fcgq-rhw7-f4x4/GHSA-fcgq-rhw7-f4x4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcgq-rhw7-f4x4", + "modified": "2024-11-26T09:30:48Z", + "published": "2024-11-26T09:30:48Z", + "aliases": [ + "CVE-2024-6476" + ], + "details": "Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. \n Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6476" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/e5/24/82/cve-2024-6476pdf-en-US-455104.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gq4f-rq24-q85j/GHSA-gq4f-rq24-q85j.json b/advisories/unreviewed/2024/11/GHSA-gq4f-rq24-q85j/GHSA-gq4f-rq24-q85j.json new file mode 100644 index 00000000000..92435401ebd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gq4f-rq24-q85j/GHSA-gq4f-rq24-q85j.json @@ -0,0 +1,98 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq4f-rq24-q85j", + "modified": "2024-11-26T09:30:48Z", + "published": "2024-11-26T09:30:48Z", + "aliases": [ + "CVE-2024-11202" + ], + "details": "Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11202" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/package/cminds-free.php#L1465" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cm-email-blacklist/trunk/package/cminds-free.php#L1465" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cm-header-footer-script-loader/trunk/package/cminds-free.php#L1465" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cm-on-demand-search-and-replace/trunk/package/cminds-free.php#L1469" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cm-pop-up-banners/trunk/package/cminds-free.php#L1471" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cm-video-lesson-manager/trunk/package/cminds-free.php#L1465" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/enhanced-tooltipglossary/trunk/package/cminds-free.php#L1465" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3191536" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192354" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192381" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192416" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3192808" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3193808" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3194393" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/cm-pop-up-banners/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/db759c60-9ce9-407d-8d1f-cbbfd09759d5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json b/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json new file mode 100644 index 00000000000..fd249a229be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gq9c-8cr6-3qh3/GHSA-gq9c-8cr6-3qh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq9c-8cr6-3qh3", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-47257" + ], + "details": "Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. \nAxis has released patched AXIS OS versions for the highlighted flaw for products that are still under AXIS OS software support. Please refer to the Axis security advisory for more information and solution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47257" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/permalink/231088/cve-2024-47257pdf-en-US_InternalID-231088.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gqv4-5xq3-67ff/GHSA-gqv4-5xq3-67ff.json b/advisories/unreviewed/2024/11/GHSA-gqv4-5xq3-67ff/GHSA-gqv4-5xq3-67ff.json new file mode 100644 index 00000000000..702af5f604e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gqv4-5xq3-67ff/GHSA-gqv4-5xq3-67ff.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqv4-5xq3-67ff", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-28955" + ], + "details": "Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28955" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h8rh-4fh4-4x2h/GHSA-h8rh-4fh4-4x2h.json b/advisories/unreviewed/2024/11/GHSA-h8rh-4fh4-4x2h/GHSA-h8rh-4fh4-4x2h.json new file mode 100644 index 00000000000..9f1e11be2a8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h8rh-4fh4-4x2h/GHSA-h8rh-4fh4-4x2h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8rh-4fh4-4x2h", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2024-11091" + ], + "details": "The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11091" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3195829" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/support-svg/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d9207baf-348c-4d3b-a6f0-cbfcd2624f78?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qj8p-c5h3-g242/GHSA-qj8p-c5h3-g242.json b/advisories/unreviewed/2024/11/GHSA-qj8p-c5h3-g242/GHSA-qj8p-c5h3-g242.json new file mode 100644 index 00000000000..0677ead62e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qj8p-c5h3-g242/GHSA-qj8p-c5h3-g242.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj8p-c5h3-g242", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-8160" + ], + "details": "Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating with an administrator-privileged service account. \nAxis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8160" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/permalink/231071/cve-2024-8160pdf-en-US_InternalID-231071.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r2p2-9v38-jgqg/GHSA-r2p2-9v38-jgqg.json b/advisories/unreviewed/2024/11/GHSA-r2p2-9v38-jgqg/GHSA-r2p2-9v38-jgqg.json new file mode 100644 index 00000000000..da04642bba7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r2p2-9v38-jgqg/GHSA-r2p2-9v38-jgqg.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2p2-9v38-jgqg", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-33610" + ], + "details": "\"sessionlist.html\" and \"sys_trayentryreboot.html\" are accessible with no authentication. \"sessionlist.html\" provides logged-in users' session information including session cookies, and \"sys_trayentryreboot.html\" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33610" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json b/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json new file mode 100644 index 00000000000..3eb857a864c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6g4-pj3m-jq5m", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2017-17772" + ], + "details": "In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-17772" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r96p-gqpg-mpgw/GHSA-r96p-gqpg-mpgw.json b/advisories/unreviewed/2024/11/GHSA-r96p-gqpg-mpgw/GHSA-r96p-gqpg-mpgw.json new file mode 100644 index 00000000000..55369d92dea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r96p-gqpg-mpgw/GHSA-r96p-gqpg-mpgw.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r96p-gqpg-mpgw", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2024-9170" + ], + "details": "The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with ShopManager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9170" + }, + { + "type": "WEB", + "url": "https://booster.io/changelog" + }, + { + "type": "WEB", + "url": "https://booster.io/shortcodes/wcj_product_meta" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woocommerce-jetpack/trunk/includes/shortcodes/class-wcj-products-shortcodes.php#L963" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3187178" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/woocommerce-jetpack/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0abf9705-2716-403f-9348-e43a8d8fb1d2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rfh8-64f6-3gcc/GHSA-rfh8-64f6-3gcc.json b/advisories/unreviewed/2024/11/GHSA-rfh8-64f6-3gcc/GHSA-rfh8-64f6-3gcc.json new file mode 100644 index 00000000000..78485544eea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rfh8-64f6-3gcc/GHSA-rfh8-64f6-3gcc.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfh8-64f6-3gcc", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-35244" + ], + "details": "There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35244" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rgcf-5mhj-jm48/GHSA-rgcf-5mhj-jm48.json b/advisories/unreviewed/2024/11/GHSA-rgcf-5mhj-jm48/GHSA-rgcf-5mhj-jm48.json new file mode 100644 index 00000000000..e31e2a2ea3f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rgcf-5mhj-jm48/GHSA-rgcf-5mhj-jm48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgcf-5mhj-jm48", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2016-10394" + ], + "details": "Initial xbl_sec revision does not have all the debug policy features and critical checks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-10394" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json b/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json new file mode 100644 index 00000000000..66ffc1289c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh49-w6rx-xcxg", + "modified": "2024-11-26T09:30:49Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2024-33616" + ], + "details": "Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the feature. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33616" + }, + { + "type": "WEB", + "url": "https://global.sharp/products/copier/info/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jp.sharp/business/print/information/info_security_2024-05.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93051062" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.co.jp/information/20240531_02.html" + }, + { + "type": "WEB", + "url": "https://www.toshibatec.com/information/20240531_02.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w495-f8hj-9gqr/GHSA-w495-f8hj-9gqr.json b/advisories/unreviewed/2024/11/GHSA-w495-f8hj-9gqr/GHSA-w495-f8hj-9gqr.json new file mode 100644 index 00000000000..08807bba23b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w495-f8hj-9gqr/GHSA-w495-f8hj-9gqr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w495-f8hj-9gqr", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:50Z", + "aliases": [ + "CVE-2024-11192" + ], + "details": "The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11192" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/spotify-play-button-for-wordpress/tags/2.11/sptify-play-button-for-wordpress.php#L137" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/spotify-play-button-for-wordpress/tags/2.11/sptify-play-button-for-wordpress.php#L147" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fspotify-play-button-for-wordpress&old=3189556&new_path=%2Fspotify-play-button-for-wordpress&new=3191339&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/spotify-play-button-for-wordpress/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a52e43dd-46b4-445b-b350-a2fd76315869?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w87w-8cvj-w7xf/GHSA-w87w-8cvj-w7xf.json b/advisories/unreviewed/2024/11/GHSA-w87w-8cvj-w7xf/GHSA-w87w-8cvj-w7xf.json new file mode 100644 index 00000000000..daa53b08f1d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w87w-8cvj-w7xf/GHSA-w87w-8cvj-w7xf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w87w-8cvj-w7xf", + "modified": "2024-11-26T09:30:48Z", + "published": "2024-11-26T09:30:48Z", + "aliases": [ + "CVE-2024-6749" + ], + "details": "Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply. \n\n Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6749" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/e6/e8/1e/cve-2024-6749-en-US-455106.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json b/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json new file mode 100644 index 00000000000..042916eec81 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9fw-pjxp-5fgx", + "modified": "2024-11-26T09:30:50Z", + "published": "2024-11-26T09:30:49Z", + "aliases": [ + "CVE-2017-15832" + ], + "details": "Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-15832" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2018-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T09:15:04Z" + } +} \ No newline at end of file