From 7a2e86c91099b0c1359be0bfed9175542a7b4092 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 15 Aug 2024 21:33:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5c29-m8gg-59qv.json | 11 ++-- .../GHSA-8w7v-3vv4-c289.json | 11 ++-- .../GHSA-jmv9-2j4f-m6fq.json | 11 ++-- .../GHSA-mwr4-m2r6-rmh7.json | 11 ++-- .../GHSA-qrf5-gh6v-gv6g.json | 11 ++-- .../GHSA-2m33-2vvh-2jjh.json | 11 ++-- .../GHSA-3qw5-v9cc-v262.json | 11 ++-- .../GHSA-52mm-25mr-346r.json | 11 ++-- .../GHSA-576j-rcf9-73mm.json | 11 ++-- .../GHSA-62qx-2wp9-mxh3.json | 9 ++-- .../GHSA-987g-v7r7-rp9w.json | 11 ++-- .../GHSA-h97h-gh5w-hqv2.json | 11 ++-- .../GHSA-v8vw-8cg3-cx4p.json | 11 ++-- .../GHSA-vr4q-vx84-9g5x.json | 2 +- .../GHSA-597x-4hfr-67c4.json | 11 ++-- .../GHSA-j9hf-h25p-vw62.json | 11 ++-- .../GHSA-m98g-cw9w-r9qw.json | 9 ++-- .../GHSA-ww3h-6rx6-947h.json | 11 ++-- .../GHSA-387f-ggqp-ccr9.json | 11 ++-- .../GHSA-455v-w5mm-7hf6.json | 4 +- .../GHSA-78m2-r6wc-m75w.json | 9 ++-- .../GHSA-hmw2-fx34-2q97.json | 9 ++-- .../GHSA-rqww-cppp-wq8m.json | 11 ++-- .../GHSA-v43c-gjm6-v4wg.json | 11 ++-- .../GHSA-fc83-86ww-f7qw.json | 3 +- .../GHSA-qjqw-554m-3g9j.json | 2 +- .../GHSA-xpj4-jm23-59w7.json | 3 +- .../GHSA-22qx-rv28-v9m8.json | 11 ++-- .../GHSA-3j4q-cm56-9492.json | 11 ++-- .../GHSA-3p9r-c4f8-vv7m.json | 11 ++-- .../GHSA-4f38-rjhv-hc58.json | 12 +++-- .../GHSA-5m24-c4vx-fjj8.json | 11 ++-- .../GHSA-6g7p-7w92-r3v3.json | 11 ++-- .../GHSA-765j-3jm5-8cf6.json | 11 ++-- .../GHSA-7q2m-phm4-h2g3.json | 39 ++++++++++++++ .../GHSA-84mw-hccv-m82r.json | 11 ++-- .../GHSA-8547-j8j2-79v8.json | 11 ++-- .../GHSA-8jv6-9x2j-w49p.json | 43 +++++++++++++++ .../GHSA-8x5q-gq29-2h75.json | 4 +- .../GHSA-96vh-rc6m-vw24.json | 35 ++++++++++++ .../GHSA-9q7g-3c57-wvv7.json | 11 ++-- .../GHSA-c62c-fvgv-j4v4.json | 11 ++-- .../GHSA-cr4v-6m54-7vh3.json | 38 +++++++++++++ .../GHSA-fq2g-8q79-phh9.json | 54 +++++++++++++++++++ .../GHSA-gv29-jxwh-r2gm.json | 39 ++++++++++++++ .../GHSA-h755-c54r-2xq5.json | 38 +++++++++++++ .../GHSA-j828-57c8-xr27.json | 11 ++-- .../GHSA-jc6p-q9f6-3qq3.json | 38 +++++++++++++ .../GHSA-m6q3-mcjx-5646.json | 11 ++-- .../GHSA-mcrq-g49g-vf4v.json | 11 ++-- .../GHSA-mr7q-fp6v-4rc6.json | 39 ++++++++++++++ .../GHSA-mx5j-m2q8-9rc2.json | 11 ++-- .../GHSA-q4q3-6vr4-qq23.json | 11 ++-- .../GHSA-r449-444r-3mjw.json | 54 +++++++++++++++++++ .../GHSA-v4x2-xrc6-7q7j.json | 11 ++-- .../GHSA-v574-8m96-8mp9.json | 39 ++++++++++++++ .../GHSA-v68h-j2w8-x6w3.json | 3 +- .../GHSA-vr5q-96fr-9g77.json | 11 ++-- .../GHSA-vv44-rh9q-4cc8.json | 11 ++-- .../GHSA-wp6j-mqr7-v2hf.json | 11 ++-- .../GHSA-wq55-fhp8-6jh8.json | 11 ++-- .../GHSA-x6qm-4c7w-8wm7.json | 38 +++++++++++++ .../GHSA-xg38-j8ww-g8hg.json | 11 ++-- .../GHSA-xh57-2h8m-3798.json | 11 ++-- 64 files changed, 818 insertions(+), 185 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cr4v-6m54-7vh3/GHSA-cr4v-6m54-7vh3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fq2g-8q79-phh9/GHSA-fq2g-8q79-phh9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h755-c54r-2xq5/GHSA-h755-c54r-2xq5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jc6p-q9f6-3qq3/GHSA-jc6p-q9f6-3qq3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mr7q-fp6v-4rc6/GHSA-mr7q-fp6v-4rc6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r449-444r-3mjw/GHSA-r449-444r-3mjw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json diff --git a/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json b/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json index 9a2506f6709..45b01cea374 100644 --- a/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json +++ b/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5c29-m8gg-59qv", - "modified": "2024-02-21T18:31:02Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-02-21T18:31:02Z", "aliases": [ "CVE-2024-25895" ], "details": "A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T18:15:51Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8w7v-3vv4-c289/GHSA-8w7v-3vv4-c289.json b/advisories/unreviewed/2024/02/GHSA-8w7v-3vv4-c289/GHSA-8w7v-3vv4-c289.json index aebd2e1b4c5..345bba49532 100644 --- a/advisories/unreviewed/2024/02/GHSA-8w7v-3vv4-c289/GHSA-8w7v-3vv4-c289.json +++ b/advisories/unreviewed/2024/02/GHSA-8w7v-3vv4-c289/GHSA-8w7v-3vv4-c289.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w7v-3vv4-c289", - "modified": "2024-02-21T21:30:25Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2023-37177" ], "details": "SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T21:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jmv9-2j4f-m6fq/GHSA-jmv9-2j4f-m6fq.json b/advisories/unreviewed/2024/02/GHSA-jmv9-2j4f-m6fq/GHSA-jmv9-2j4f-m6fq.json index 4bc430f7eaa..3cd98252ba4 100644 --- a/advisories/unreviewed/2024/02/GHSA-jmv9-2j4f-m6fq/GHSA-jmv9-2j4f-m6fq.json +++ b/advisories/unreviewed/2024/02/GHSA-jmv9-2j4f-m6fq/GHSA-jmv9-2j4f-m6fq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmv9-2j4f-m6fq", - "modified": "2024-02-21T21:30:25Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2024-25461" ], "details": "Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T20:15:46Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mwr4-m2r6-rmh7/GHSA-mwr4-m2r6-rmh7.json b/advisories/unreviewed/2024/02/GHSA-mwr4-m2r6-rmh7/GHSA-mwr4-m2r6-rmh7.json index 33388be4855..b21d3820728 100644 --- a/advisories/unreviewed/2024/02/GHSA-mwr4-m2r6-rmh7/GHSA-mwr4-m2r6-rmh7.json +++ b/advisories/unreviewed/2024/02/GHSA-mwr4-m2r6-rmh7/GHSA-mwr4-m2r6-rmh7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwr4-m2r6-rmh7", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-0018" ], "details": "In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T20:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qrf5-gh6v-gv6g/GHSA-qrf5-gh6v-gv6g.json b/advisories/unreviewed/2024/02/GHSA-qrf5-gh6v-gv6g/GHSA-qrf5-gh6v-gv6g.json index 03dc84fcef8..b69c91aded2 100644 --- a/advisories/unreviewed/2024/02/GHSA-qrf5-gh6v-gv6g/GHSA-qrf5-gh6v-gv6g.json +++ b/advisories/unreviewed/2024/02/GHSA-qrf5-gh6v-gv6g/GHSA-qrf5-gh6v-gv6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrf5-gh6v-gv6g", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-08-15T21:31:17Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40114" ], "details": "In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json b/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json index 64062d9f0ec..1f384eee6e4 100644 --- a/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json +++ b/advisories/unreviewed/2024/03/GHSA-2m33-2vvh-2jjh/GHSA-2m33-2vvh-2jjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2m33-2vvh-2jjh", - "modified": "2024-03-29T15:30:32Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-29T15:30:32Z", "aliases": [ "CVE-2024-30639" ], "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T14:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3qw5-v9cc-v262/GHSA-3qw5-v9cc-v262.json b/advisories/unreviewed/2024/03/GHSA-3qw5-v9cc-v262/GHSA-3qw5-v9cc-v262.json index 24ebbfe81e8..c6e7eb28715 100644 --- a/advisories/unreviewed/2024/03/GHSA-3qw5-v9cc-v262/GHSA-3qw5-v9cc-v262.json +++ b/advisories/unreviewed/2024/03/GHSA-3qw5-v9cc-v262/GHSA-3qw5-v9cc-v262.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qw5-v9cc-v262", - "modified": "2024-03-21T21:31:15Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-21T21:31:15Z", "aliases": [ "CVE-2024-29374" ], "details": "A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the \"GET /?lang=\" URL parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T19:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json b/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json index 9c3703eba29..aa6678e77d7 100644 --- a/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json +++ b/advisories/unreviewed/2024/03/GHSA-52mm-25mr-346r/GHSA-52mm-25mr-346r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52mm-25mr-346r", - "modified": "2024-03-29T15:30:31Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-29T15:30:31Z", "aliases": [ "CVE-2024-30632" ], "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-576j-rcf9-73mm/GHSA-576j-rcf9-73mm.json b/advisories/unreviewed/2024/03/GHSA-576j-rcf9-73mm/GHSA-576j-rcf9-73mm.json index e53f60274fc..39fdc0ae17a 100644 --- a/advisories/unreviewed/2024/03/GHSA-576j-rcf9-73mm/GHSA-576j-rcf9-73mm.json +++ b/advisories/unreviewed/2024/03/GHSA-576j-rcf9-73mm/GHSA-576j-rcf9-73mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-576j-rcf9-73mm", - "modified": "2024-03-13T18:31:34Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-28670" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T16:15:30Z" diff --git a/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json b/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json index 60e386d5243..4eefdefbed4 100644 --- a/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json +++ b/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62qx-2wp9-mxh3", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27219" ], "details": "In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-987g-v7r7-rp9w/GHSA-987g-v7r7-rp9w.json b/advisories/unreviewed/2024/03/GHSA-987g-v7r7-rp9w/GHSA-987g-v7r7-rp9w.json index c467ce667ae..36acf33ab8f 100644 --- a/advisories/unreviewed/2024/03/GHSA-987g-v7r7-rp9w/GHSA-987g-v7r7-rp9w.json +++ b/advisories/unreviewed/2024/03/GHSA-987g-v7r7-rp9w/GHSA-987g-v7r7-rp9w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-987g-v7r7-rp9w", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-25993" ], "details": "In tmu_reset_tmu_trip_counter of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h97h-gh5w-hqv2/GHSA-h97h-gh5w-hqv2.json b/advisories/unreviewed/2024/03/GHSA-h97h-gh5w-hqv2/GHSA-h97h-gh5w-hqv2.json index 1b0623f0c0d..b70c5d606e1 100644 --- a/advisories/unreviewed/2024/03/GHSA-h97h-gh5w-hqv2/GHSA-h97h-gh5w-hqv2.json +++ b/advisories/unreviewed/2024/03/GHSA-h97h-gh5w-hqv2/GHSA-h97h-gh5w-hqv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h97h-gh5w-hqv2", - "modified": "2024-03-13T18:31:34Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-28680" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T16:15:30Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v8vw-8cg3-cx4p/GHSA-v8vw-8cg3-cx4p.json b/advisories/unreviewed/2024/03/GHSA-v8vw-8cg3-cx4p/GHSA-v8vw-8cg3-cx4p.json index 8819c7d182b..2435e18aa30 100644 --- a/advisories/unreviewed/2024/03/GHSA-v8vw-8cg3-cx4p/GHSA-v8vw-8cg3-cx4p.json +++ b/advisories/unreviewed/2024/03/GHSA-v8vw-8cg3-cx4p/GHSA-v8vw-8cg3-cx4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8vw-8cg3-cx4p", - "modified": "2024-03-13T18:31:34Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-28683" ], "details": "DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T16:15:30Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vr4q-vx84-9g5x/GHSA-vr4q-vx84-9g5x.json b/advisories/unreviewed/2024/03/GHSA-vr4q-vx84-9g5x/GHSA-vr4q-vx84-9g5x.json index 911461c5d47..e230c293077 100644 --- a/advisories/unreviewed/2024/03/GHSA-vr4q-vx84-9g5x/GHSA-vr4q-vx84-9g5x.json +++ b/advisories/unreviewed/2024/03/GHSA-vr4q-vx84-9g5x/GHSA-vr4q-vx84-9g5x.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-250" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json b/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json index 625de665740..17d8ccc1738 100644 --- a/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json +++ b/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-597x-4hfr-67c4", - "modified": "2024-04-03T09:30:32Z", + "modified": "2024-08-15T21:31:18Z", "published": "2024-04-03T09:30:32Z", "aliases": [ "CVE-2024-24506" ], "details": "Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T07:15:42Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j9hf-h25p-vw62/GHSA-j9hf-h25p-vw62.json b/advisories/unreviewed/2024/04/GHSA-j9hf-h25p-vw62/GHSA-j9hf-h25p-vw62.json index 6f9ffef8125..65eed9dd310 100644 --- a/advisories/unreviewed/2024/04/GHSA-j9hf-h25p-vw62/GHSA-j9hf-h25p-vw62.json +++ b/advisories/unreviewed/2024/04/GHSA-j9hf-h25p-vw62/GHSA-j9hf-h25p-vw62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9hf-h25p-vw62", - "modified": "2024-04-15T21:30:46Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-04-15T21:30:46Z", "aliases": [ "CVE-2024-30840" ], "details": "A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T20:15:11Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json b/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json index 10089c8fc4d..fb544d8d2b0 100644 --- a/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json +++ b/advisories/unreviewed/2024/04/GHSA-m98g-cw9w-r9qw/GHSA-m98g-cw9w-r9qw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m98g-cw9w-r9qw", - "modified": "2024-04-25T18:30:39Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-32358" ], "details": "An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-25T17:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json b/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json index e3d512e6b85..9a56464aece 100644 --- a/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json +++ b/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww3h-6rx6-947h", - "modified": "2024-04-30T18:30:33Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-04-30T18:30:33Z", "aliases": [ "CVE-2019-19755" ], "details": "ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-300" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T18:15:19Z" diff --git a/advisories/unreviewed/2024/05/GHSA-387f-ggqp-ccr9/GHSA-387f-ggqp-ccr9.json b/advisories/unreviewed/2024/05/GHSA-387f-ggqp-ccr9/GHSA-387f-ggqp-ccr9.json index 55fc600cf10..ee28ff48261 100644 --- a/advisories/unreviewed/2024/05/GHSA-387f-ggqp-ccr9/GHSA-387f-ggqp-ccr9.json +++ b/advisories/unreviewed/2024/05/GHSA-387f-ggqp-ccr9/GHSA-387f-ggqp-ccr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-387f-ggqp-ccr9", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34211" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:34Z" diff --git a/advisories/unreviewed/2024/05/GHSA-455v-w5mm-7hf6/GHSA-455v-w5mm-7hf6.json b/advisories/unreviewed/2024/05/GHSA-455v-w5mm-7hf6/GHSA-455v-w5mm-7hf6.json index 4d81513ec0e..7f6deaaa4b6 100644 --- a/advisories/unreviewed/2024/05/GHSA-455v-w5mm-7hf6/GHSA-455v-w5mm-7hf6.json +++ b/advisories/unreviewed/2024/05/GHSA-455v-w5mm-7hf6/GHSA-455v-w5mm-7hf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-455v-w5mm-7hf6", - "modified": "2024-05-14T18:30:59Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-05-14T18:30:59Z", "aliases": [ "CVE-2024-22270" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-78m2-r6wc-m75w/GHSA-78m2-r6wc-m75w.json b/advisories/unreviewed/2024/05/GHSA-78m2-r6wc-m75w/GHSA-78m2-r6wc-m75w.json index 0e401259492..81facc9a7bb 100644 --- a/advisories/unreviewed/2024/05/GHSA-78m2-r6wc-m75w/GHSA-78m2-r6wc-m75w.json +++ b/advisories/unreviewed/2024/05/GHSA-78m2-r6wc-m75w/GHSA-78m2-r6wc-m75w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78m2-r6wc-m75w", - "modified": "2024-05-03T18:30:37Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-28519" ], "details": "A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privilege escalation for low-privileged users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json b/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json index 1deff946881..f011aa4029d 100644 --- a/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json +++ b/advisories/unreviewed/2024/05/GHSA-hmw2-fx34-2q97/GHSA-hmw2-fx34-2q97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmw2-fx34-2q97", - "modified": "2024-05-06T21:30:38Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-1695" ], "details": "A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC products, which might allow escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T21:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rqww-cppp-wq8m/GHSA-rqww-cppp-wq8m.json b/advisories/unreviewed/2024/05/GHSA-rqww-cppp-wq8m/GHSA-rqww-cppp-wq8m.json index de36a0ee990..990fc1fb15d 100644 --- a/advisories/unreviewed/2024/05/GHSA-rqww-cppp-wq8m/GHSA-rqww-cppp-wq8m.json +++ b/advisories/unreviewed/2024/05/GHSA-rqww-cppp-wq8m/GHSA-rqww-cppp-wq8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqww-cppp-wq8m", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34944" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:38Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v43c-gjm6-v4wg/GHSA-v43c-gjm6-v4wg.json b/advisories/unreviewed/2024/05/GHSA-v43c-gjm6-v4wg/GHSA-v43c-gjm6-v4wg.json index 2196c9cf635..38d5a06aa90 100644 --- a/advisories/unreviewed/2024/05/GHSA-v43c-gjm6-v4wg/GHSA-v43c-gjm6-v4wg.json +++ b/advisories/unreviewed/2024/05/GHSA-v43c-gjm6-v4wg/GHSA-v43c-gjm6-v4wg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v43c-gjm6-v4wg", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34207" ], "details": "TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:34Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json b/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json index c7dc4afd5ae..25ce1e8a276 100644 --- a/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json +++ b/advisories/unreviewed/2024/06/GHSA-fc83-86ww-f7qw/GHSA-fc83-86ww-f7qw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json b/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json index f97e211bbf7..631b0f06f0c 100644 --- a/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json +++ b/advisories/unreviewed/2024/06/GHSA-qjqw-554m-3g9j/GHSA-qjqw-554m-3g9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjqw-554m-3g9j", - "modified": "2024-06-12T15:31:44Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-28021" diff --git a/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json b/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json index 7204c0db825..61f3bd31b50 100644 --- a/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json +++ b/advisories/unreviewed/2024/06/GHSA-xpj4-jm23-59w7/GHSA-xpj4-jm23-59w7.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json b/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json index 4e1430fc229..779a60b786f 100644 --- a/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json +++ b/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22qx-rv28-v9m8", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42943" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json b/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json index 848906551b5..8223c456619 100644 --- a/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json +++ b/advisories/unreviewed/2024/08/GHSA-3j4q-cm56-9492/GHSA-3j4q-cm56-9492.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j4q-cm56-9492", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42948" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json b/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json index 6e21398c4d9..77305dd51a8 100644 --- a/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json +++ b/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p9r-c4f8-vv7m", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42946" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json b/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json index 03f586ed1d9..20825a94ec8 100644 --- a/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json +++ b/advisories/unreviewed/2024/08/GHSA-4f38-rjhv-hc58/GHSA-4f38-rjhv-hc58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f38-rjhv-hc58", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42944" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json b/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json index c358baca1cf..23e6f3cbe86 100644 --- a/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json +++ b/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5m24-c4vx-fjj8", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42984" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json b/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json index 976485b3bec..1931f660c80 100644 --- a/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json +++ b/advisories/unreviewed/2024/08/GHSA-6g7p-7w92-r3v3/GHSA-6g7p-7w92-r3v3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6g7p-7w92-r3v3", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-31798" ], "details": "Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json b/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json index 7f7dd72b1b6..26d6c61dd31 100644 --- a/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json +++ b/advisories/unreviewed/2024/08/GHSA-765j-3jm5-8cf6/GHSA-765j-3jm5-8cf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-765j-3jm5-8cf6", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42941" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json b/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json new file mode 100644 index 00000000000..3a8aef43e42 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q2m-phm4-h2g3", + "modified": "2024-08-15T21:31:19Z", + "published": "2024-08-15T21:31:19Z", + "aliases": [ + "CVE-2024-27728" + ], + "details": "Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27728" + }, + { + "type": "WEB", + "url": "https://github.com/friendica/friendica/pull/13927" + }, + { + "type": "WEB", + "url": "https://leo.oliver.nz/posts/2024/05/friendica-cve-disclosures" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json b/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json index 814f8dea97c..043f1ab7310 100644 --- a/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json +++ b/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84mw-hccv-m82r", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42949" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json b/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json index 3f6f3380e7a..c26706081a2 100644 --- a/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json +++ b/advisories/unreviewed/2024/08/GHSA-8547-j8j2-79v8/GHSA-8547-j8j2-79v8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8547-j8j2-79v8", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42940" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json b/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json new file mode 100644 index 00000000000..64ef06e4c5b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jv6-9x2j-w49p", + "modified": "2024-08-15T21:31:19Z", + "published": "2024-08-15T21:31:19Z", + "aliases": [ + "CVE-2024-23168" + ], + "details": "Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23168" + }, + { + "type": "WEB", + "url": "https://github.com/Xiexe/XSOverlay-Issue-Tracker" + }, + { + "type": "WEB", + "url": "https://store.steampowered.com/news/app/1173510?emclan=103582791465938574&emgid=7792991106417394332" + }, + { + "type": "WEB", + "url": "https://vuln.ryotak.net/advisories/70" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json b/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json index d68b3429f6c..986e1681e6d 100644 --- a/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json +++ b/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x5q-gq29-2h75", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-21981" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json b/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json new file mode 100644 index 00000000000..5c2eaaae54e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96vh-rc6m-vw24", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:19Z", + "aliases": [ + "CVE-2024-42757" + ], + "details": "Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42757" + }, + { + "type": "WEB", + "url": "https://github.com/Nop3z/CVE/blob/main/Asus/FW_RT_N15U_30043763754/FW_RT_N15U_30043763754%20RCE.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json b/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json index bcd2bf23355..44efb1a9bec 100644 --- a/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json +++ b/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9q7g-3c57-wvv7", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42954" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json b/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json index 2d00233101d..185be8800ad 100644 --- a/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json +++ b/advisories/unreviewed/2024/08/GHSA-c62c-fvgv-j4v4/GHSA-c62c-fvgv-j4v4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c62c-fvgv-j4v4", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42950" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cr4v-6m54-7vh3/GHSA-cr4v-6m54-7vh3.json b/advisories/unreviewed/2024/08/GHSA-cr4v-6m54-7vh3/GHSA-cr4v-6m54-7vh3.json new file mode 100644 index 00000000000..e7bf664fb2e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cr4v-6m54-7vh3/GHSA-cr4v-6m54-7vh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr4v-6m54-7vh3", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:20Z", + "aliases": [ + "CVE-2024-7866" + ], + "details": "In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7866" + }, + { + "type": "WEB", + "url": "https://www.xpdfreader.com/security-bug/object-loops.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fq2g-8q79-phh9/GHSA-fq2g-8q79-phh9.json b/advisories/unreviewed/2024/08/GHSA-fq2g-8q79-phh9/GHSA-fq2g-8q79-phh9.json new file mode 100644 index 00000000000..8baf8623454 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fq2g-8q79-phh9/GHSA-fq2g-8q79-phh9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq2g-8q79-phh9", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:20Z", + "aliases": [ + "CVE-2024-7838" + ], + "details": "A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcategory.php. The manipulation of the argument cname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7838" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/a/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274742" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274742" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391525" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json b/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json new file mode 100644 index 00000000000..a0cd1043a73 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv29-jxwh-r2gm", + "modified": "2024-08-15T21:31:19Z", + "published": "2024-08-15T21:31:19Z", + "aliases": [ + "CVE-2024-27731" + ], + "details": "Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27731" + }, + { + "type": "WEB", + "url": "https://github.com/friendica/friendica/pull/13927" + }, + { + "type": "WEB", + "url": "https://leo.oliver.nz/posts/2024/05/friendica-cve-disclosures" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h755-c54r-2xq5/GHSA-h755-c54r-2xq5.json b/advisories/unreviewed/2024/08/GHSA-h755-c54r-2xq5/GHSA-h755-c54r-2xq5.json new file mode 100644 index 00000000000..10ffe73d7d7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h755-c54r-2xq5/GHSA-h755-c54r-2xq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h755-c54r-2xq5", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:20Z", + "aliases": [ + "CVE-2024-6456" + ], + "details": "AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface user who had been socially engineered by a miscreant into opening a specially crafted URL.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6456" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-228-10" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json b/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json index 240fac8d790..108af9f8f6c 100644 --- a/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json +++ b/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j828-57c8-xr27", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42968" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jc6p-q9f6-3qq3/GHSA-jc6p-q9f6-3qq3.json b/advisories/unreviewed/2024/08/GHSA-jc6p-q9f6-3qq3/GHSA-jc6p-q9f6-3qq3.json new file mode 100644 index 00000000000..775cea8ded3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jc6p-q9f6-3qq3/GHSA-jc6p-q9f6-3qq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc6p-q9f6-3qq3", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:20Z", + "aliases": [ + "CVE-2024-7867" + ], + "details": "In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7867" + }, + { + "type": "WEB", + "url": "https://www.xpdfreader.com/security-bug/CVE-2024-7867.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json b/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json index f3a63ae7b09..5f34f5d28f7 100644 --- a/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json +++ b/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m6q3-mcjx-5646", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42955" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json b/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json index e3c82518ff1..7182c717b7f 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json +++ b/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcrq-g49g-vf4v", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42942" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mr7q-fp6v-4rc6/GHSA-mr7q-fp6v-4rc6.json b/advisories/unreviewed/2024/08/GHSA-mr7q-fp6v-4rc6/GHSA-mr7q-fp6v-4rc6.json new file mode 100644 index 00000000000..041837daf13 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mr7q-fp6v-4rc6/GHSA-mr7q-fp6v-4rc6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr7q-fp6v-4rc6", + "modified": "2024-08-15T21:31:19Z", + "published": "2024-08-15T21:31:19Z", + "aliases": [ + "CVE-2024-27729" + ], + "details": "Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27729" + }, + { + "type": "WEB", + "url": "https://github.com/friendica/friendica/pull/13927" + }, + { + "type": "WEB", + "url": "https://leo.oliver.nz/posts/2024/05/friendica-cve-disclosures" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json b/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json index 0e5da7ac958..41990e8fdbb 100644 --- a/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json +++ b/advisories/unreviewed/2024/08/GHSA-mx5j-m2q8-9rc2/GHSA-mx5j-m2q8-9rc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mx5j-m2q8-9rc2", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42952" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json b/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json index ceb14877c96..02fbc22d999 100644 --- a/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json +++ b/advisories/unreviewed/2024/08/GHSA-q4q3-6vr4-qq23/GHSA-q4q3-6vr4-qq23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q4q3-6vr4-qq23", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-22218" ], "details": "XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T18:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r449-444r-3mjw/GHSA-r449-444r-3mjw.json b/advisories/unreviewed/2024/08/GHSA-r449-444r-3mjw/GHSA-r449-444r-3mjw.json new file mode 100644 index 00000000000..a4d8f1150ee --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r449-444r-3mjw/GHSA-r449-444r-3mjw.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r449-444r-3mjw", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:20Z", + "aliases": [ + "CVE-2024-7839" + ], + "details": "A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7839" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/a/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274743" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274743" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391531" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json b/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json index 7c9b41a2e94..b19fbea4b39 100644 --- a/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json +++ b/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4x2-xrc6-7q7j", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42953" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPW parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json b/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json new file mode 100644 index 00000000000..79d543c935d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v574-8m96-8mp9", + "modified": "2024-08-15T21:31:19Z", + "published": "2024-08-15T21:31:19Z", + "aliases": [ + "CVE-2024-27730" + ], + "details": "Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27730" + }, + { + "type": "WEB", + "url": "https://github.com/friendica/friendica/pull/13927" + }, + { + "type": "WEB", + "url": "https://leo.oliver.nz/posts/2024/05/friendica-cve-disclosures" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json b/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json index f73b1ce9476..90154978473 100644 --- a/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json +++ b/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-601" + "CWE-601", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json b/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json index 533eaf3739d..75866d2d2f7 100644 --- a/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json +++ b/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vr5q-96fr-9g77", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42951" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json b/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json index b536118a473..8b8d7d9a9b7 100644 --- a/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json +++ b/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vv44-rh9q-4cc8", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42974" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json b/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json index 31579554dcb..ee8aded8cd2 100644 --- a/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json +++ b/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp6j-mqr7-v2hf", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42983" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json b/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json index 84cdc936088..f9569a94ed2 100644 --- a/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json +++ b/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq55-fhp8-6jh8", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42945" ], "details": "Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json b/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json new file mode 100644 index 00000000000..f9ecca01393 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6qm-4c7w-8wm7/GHSA-x6qm-4c7w-8wm7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6qm-4c7w-8wm7", + "modified": "2024-08-15T21:31:20Z", + "published": "2024-08-15T21:31:20Z", + "aliases": [ + "CVE-2024-7868" + ], + "details": "In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7868" + }, + { + "type": "WEB", + "url": "https://www.xpdfreader.com/security-bug/CVE-2024-7868.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json b/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json index d64e0d66b45..7b80f4c6a19 100644 --- a/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json +++ b/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xg38-j8ww-g8hg", - "modified": "2024-08-15T18:31:52Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:52Z", "aliases": [ "CVE-2024-42979" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json b/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json index 5de689d8c8c..dd1192cb69b 100644 --- a/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json +++ b/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xh57-2h8m-3798", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-08-15T21:31:19Z", "published": "2024-08-15T18:31:51Z", "aliases": [ "CVE-2024-42973" ], "details": "Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T17:15:20Z"