From 79f3c64516fa37e0f79fa80668efb930bc506e2d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 24 Sep 2024 15:33:01 +0000 Subject: [PATCH] Publish Advisories GHSA-f3wc-3vxv-xmvr GHSA-3h5p-pg4g-m6gv GHSA-qf8r-gmh3-q7x2 GHSA-6879-gf6q-3qmj GHSA-74qm-4v7r-jw2f GHSA-93r2-j783-g4wf GHSA-mcw8-xx8x-344q GHSA-rcw8-56q4-fh4w --- .../05/GHSA-f3wc-3vxv-xmvr/GHSA-f3wc-3vxv-xmvr.json | 6 +++++- .../06/GHSA-3h5p-pg4g-m6gv/GHSA-3h5p-pg4g-m6gv.json | 1 + .../06/GHSA-qf8r-gmh3-q7x2/GHSA-qf8r-gmh3-q7x2.json | 6 +++++- .../09/GHSA-6879-gf6q-3qmj/GHSA-6879-gf6q-3qmj.json | 11 +++++++---- .../09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json | 3 ++- .../09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json | 9 ++++++--- .../09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json | 11 +++++++---- .../09/GHSA-rcw8-56q4-fh4w/GHSA-rcw8-56q4-fh4w.json | 9 ++++++--- 8 files changed, 39 insertions(+), 17 deletions(-) diff --git a/advisories/github-reviewed/2023/05/GHSA-f3wc-3vxv-xmvr/GHSA-f3wc-3vxv-xmvr.json b/advisories/github-reviewed/2023/05/GHSA-f3wc-3vxv-xmvr/GHSA-f3wc-3vxv-xmvr.json index c85218ff480..3aa0d66a8ba 100644 --- a/advisories/github-reviewed/2023/05/GHSA-f3wc-3vxv-xmvr/GHSA-f3wc-3vxv-xmvr.json +++ b/advisories/github-reviewed/2023/05/GHSA-f3wc-3vxv-xmvr/GHSA-f3wc-3vxv-xmvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3wc-3vxv-xmvr", - "modified": "2023-05-24T17:28:26Z", + "modified": "2024-09-24T15:31:50Z", "published": "2023-05-24T17:28:26Z", "aliases": [ "CVE-2023-32323" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-3h5p-pg4g-m6gv/GHSA-3h5p-pg4g-m6gv.json b/advisories/unreviewed/2024/06/GHSA-3h5p-pg4g-m6gv/GHSA-3h5p-pg4g-m6gv.json index f4f034c94f2..24956ed73dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-3h5p-pg4g-m6gv/GHSA-3h5p-pg4g-m6gv.json +++ b/advisories/unreviewed/2024/06/GHSA-3h5p-pg4g-m6gv/GHSA-3h5p-pg4g-m6gv.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-qf8r-gmh3-q7x2/GHSA-qf8r-gmh3-q7x2.json b/advisories/unreviewed/2024/06/GHSA-qf8r-gmh3-q7x2/GHSA-qf8r-gmh3-q7x2.json index 1f0db1c48ae..68d81b12a22 100644 --- a/advisories/unreviewed/2024/06/GHSA-qf8r-gmh3-q7x2/GHSA-qf8r-gmh3-q7x2.json +++ b/advisories/unreviewed/2024/06/GHSA-qf8r-gmh3-q7x2/GHSA-qf8r-gmh3-q7x2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qf8r-gmh3-q7x2", - "modified": "2024-07-30T00:34:24Z", + "modified": "2024-09-24T15:31:32Z", "published": "2024-06-26T18:30:28Z", "aliases": [ "CVE-2024-38272" ], "details": "There exists a vulnerability in Quickshare/Nearby where an attacker can bypass the accept file dialog on QuickShare Windows. Normally in QuickShare Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quickshare or above", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-6879-gf6q-3qmj/GHSA-6879-gf6q-3qmj.json b/advisories/unreviewed/2024/09/GHSA-6879-gf6q-3qmj/GHSA-6879-gf6q-3qmj.json index 1cbb29fbb0d..5ef0a29e323 100644 --- a/advisories/unreviewed/2024/09/GHSA-6879-gf6q-3qmj/GHSA-6879-gf6q-3qmj.json +++ b/advisories/unreviewed/2024/09/GHSA-6879-gf6q-3qmj/GHSA-6879-gf6q-3qmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6879-gf6q-3qmj", - "modified": "2024-09-17T00:31:03Z", + "modified": "2024-09-24T15:31:31Z", "published": "2024-09-17T00:31:03Z", "aliases": [ "CVE-2024-40770" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted network settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json b/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json index 1146f594802..c62aaae839b 100644 --- a/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json +++ b/advisories/unreviewed/2024/09/GHSA-74qm-4v7r-jw2f/GHSA-74qm-4v7r-jw2f.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json b/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json index 9af8ec73b67..5de1b9d6feb 100644 --- a/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json +++ b/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93r2-j783-g4wf", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T15:31:32Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40843" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json b/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json index abde2e8a79f..82c190028e6 100644 --- a/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json +++ b/advisories/unreviewed/2024/09/GHSA-mcw8-xx8x-344q/GHSA-mcw8-xx8x-344q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcw8-xx8x-344q", - "modified": "2024-09-18T15:30:53Z", + "modified": "2024-09-24T15:31:32Z", "published": "2024-09-18T15:30:53Z", "aliases": [ "CVE-2024-46590" ], "details": "Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T15:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rcw8-56q4-fh4w/GHSA-rcw8-56q4-fh4w.json b/advisories/unreviewed/2024/09/GHSA-rcw8-56q4-fh4w/GHSA-rcw8-56q4-fh4w.json index 9d88bdbbe3c..a4dfbb806af 100644 --- a/advisories/unreviewed/2024/09/GHSA-rcw8-56q4-fh4w/GHSA-rcw8-56q4-fh4w.json +++ b/advisories/unreviewed/2024/09/GHSA-rcw8-56q4-fh4w/GHSA-rcw8-56q4-fh4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcw8-56q4-fh4w", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-24T15:31:32Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40842" ], "details": "An issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:49Z"