From 7cf37bfa0b7e821821c2a81b3e7ba3e019d1052b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 14 Apr 2023 18:31:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../04/GHSA-29vj-5h9f-8qr5/GHSA-29vj-5h9f-8qr5.json | 11 +++++++---- .../04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json | 11 +++++++---- .../04/GHSA-34mm-8vxq-7m2j/GHSA-34mm-8vxq-7m2j.json | 11 +++++++---- .../04/GHSA-367q-63cf-925j/GHSA-367q-63cf-925j.json | 11 +++++++---- .../04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json | 11 +++++++---- .../04/GHSA-44xc-f95p-5vmh/GHSA-44xc-f95p-5vmh.json | 11 +++++++---- .../04/GHSA-459j-jhfx-fmj6/GHSA-459j-jhfx-fmj6.json | 11 +++++++---- .../04/GHSA-45pp-w4rj-fj8v/GHSA-45pp-w4rj-fj8v.json | 11 +++++++---- .../04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json | 11 +++++++---- .../04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json | 9 ++++++--- .../04/GHSA-5rpj-29cm-cpqf/GHSA-5rpj-29cm-cpqf.json | 11 +++++++---- .../04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json | 9 ++++++--- .../04/GHSA-8j63-7567-qrrm/GHSA-8j63-7567-qrrm.json | 4 ++++ .../04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json | 11 +++++++---- .../04/GHSA-c2xc-7cgf-x32h/GHSA-c2xc-7cgf-x32h.json | 11 +++++++---- .../04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json | 9 ++++++--- .../04/GHSA-cprr-rh4x-6x3j/GHSA-cprr-rh4x-6x3j.json | 11 +++++++---- .../04/GHSA-fffg-x79m-65gr/GHSA-fffg-x79m-65gr.json | 11 +++++++---- .../04/GHSA-gj52-rqw6-xxqh/GHSA-gj52-rqw6-xxqh.json | 11 +++++++---- .../04/GHSA-gr5r-rfrm-7m5x/GHSA-gr5r-rfrm-7m5x.json | 11 +++++++---- .../04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json | 9 ++++++--- .../04/GHSA-jv73-596c-j7p7/GHSA-jv73-596c-j7p7.json | 11 +++++++---- .../04/GHSA-mhrj-hwc3-pwvq/GHSA-mhrj-hwc3-pwvq.json | 11 +++++++---- .../04/GHSA-mwg7-wp3h-xm4h/GHSA-mwg7-wp3h-xm4h.json | 11 +++++++---- .../04/GHSA-q3wj-5w9x-rhw4/GHSA-q3wj-5w9x-rhw4.json | 11 +++++++---- .../04/GHSA-qmvc-wj32-3pg9/GHSA-qmvc-wj32-3pg9.json | 11 +++++++---- .../04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json | 11 +++++++---- .../04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json | 9 ++++++--- .../04/GHSA-xj47-998q-qjgw/GHSA-xj47-998q-qjgw.json | 11 +++++++---- 29 files changed, 195 insertions(+), 107 deletions(-) diff --git a/advisories/unreviewed/2023/04/GHSA-29vj-5h9f-8qr5/GHSA-29vj-5h9f-8qr5.json b/advisories/unreviewed/2023/04/GHSA-29vj-5h9f-8qr5/GHSA-29vj-5h9f-8qr5.json index 2f71d106f19..27371785ed2 100644 --- a/advisories/unreviewed/2023/04/GHSA-29vj-5h9f-8qr5/GHSA-29vj-5h9f-8qr5.json +++ b/advisories/unreviewed/2023/04/GHSA-29vj-5h9f-8qr5/GHSA-29vj-5h9f-8qr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29vj-5h9f-8qr5", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:20Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47338" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json b/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json index d248f7b4f2b..71d08729923 100644 --- a/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json +++ b/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2p4x-63mg-m275", - "modified": "2023-04-10T21:30:20Z", + "modified": "2023-04-14T18:30:18Z", "published": "2023-04-10T21:30:20Z", "aliases": [ "CVE-2023-27178" ], "details": "An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T21:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-34mm-8vxq-7m2j/GHSA-34mm-8vxq-7m2j.json b/advisories/unreviewed/2023/04/GHSA-34mm-8vxq-7m2j/GHSA-34mm-8vxq-7m2j.json index 6f2e0a8e6d9..c8bf3c470d3 100644 --- a/advisories/unreviewed/2023/04/GHSA-34mm-8vxq-7m2j/GHSA-34mm-8vxq-7m2j.json +++ b/advisories/unreviewed/2023/04/GHSA-34mm-8vxq-7m2j/GHSA-34mm-8vxq-7m2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34mm-8vxq-7m2j", - "modified": "2023-04-11T03:31:19Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T03:31:19Z", "aliases": [ "CVE-2023-28341" ], "details": "Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T01:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-367q-63cf-925j/GHSA-367q-63cf-925j.json b/advisories/unreviewed/2023/04/GHSA-367q-63cf-925j/GHSA-367q-63cf-925j.json index 3264589027e..d8ffbe35606 100644 --- a/advisories/unreviewed/2023/04/GHSA-367q-63cf-925j/GHSA-367q-63cf-925j.json +++ b/advisories/unreviewed/2023/04/GHSA-367q-63cf-925j/GHSA-367q-63cf-925j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-367q-63cf-925j", - "modified": "2023-04-10T15:30:24Z", + "modified": "2023-04-14T18:30:18Z", "published": "2023-04-10T15:30:24Z", "aliases": [ "CVE-2023-29375" ], "details": "An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json b/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json index 19054b49901..791002a39c6 100644 --- a/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json +++ b/advisories/unreviewed/2023/04/GHSA-3gqh-xgpm-cfvx/GHSA-3gqh-xgpm-cfvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3gqh-xgpm-cfvx", - "modified": "2023-04-05T18:30:18Z", + "modified": "2023-04-14T18:30:20Z", "published": "2023-04-05T18:30:18Z", "aliases": [ "CVE-2023-29389" ], "details": "Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged \"Key is validated\" messages via CAN Injection, as exploited in the wild in (for example) July 2022.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-05T16:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-44xc-f95p-5vmh/GHSA-44xc-f95p-5vmh.json b/advisories/unreviewed/2023/04/GHSA-44xc-f95p-5vmh/GHSA-44xc-f95p-5vmh.json index ffa68e6210a..c3a923c97cd 100644 --- a/advisories/unreviewed/2023/04/GHSA-44xc-f95p-5vmh/GHSA-44xc-f95p-5vmh.json +++ b/advisories/unreviewed/2023/04/GHSA-44xc-f95p-5vmh/GHSA-44xc-f95p-5vmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44xc-f95p-5vmh", - "modified": "2023-04-07T21:30:15Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-07T21:30:15Z", "aliases": [ "CVE-2023-1801" ], "details": "The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-07T21:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-459j-jhfx-fmj6/GHSA-459j-jhfx-fmj6.json b/advisories/unreviewed/2023/04/GHSA-459j-jhfx-fmj6/GHSA-459j-jhfx-fmj6.json index c7993852e99..b583ef5800a 100644 --- a/advisories/unreviewed/2023/04/GHSA-459j-jhfx-fmj6/GHSA-459j-jhfx-fmj6.json +++ b/advisories/unreviewed/2023/04/GHSA-459j-jhfx-fmj6/GHSA-459j-jhfx-fmj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-459j-jhfx-fmj6", - "modified": "2023-04-11T03:31:20Z", + "modified": "2023-04-14T18:30:18Z", "published": "2023-04-11T03:31:20Z", "aliases": [ "CVE-2022-38604" ], "details": "Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T01:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-45pp-w4rj-fj8v/GHSA-45pp-w4rj-fj8v.json b/advisories/unreviewed/2023/04/GHSA-45pp-w4rj-fj8v/GHSA-45pp-w4rj-fj8v.json index 1e767f86517..e0bc242abdf 100644 --- a/advisories/unreviewed/2023/04/GHSA-45pp-w4rj-fj8v/GHSA-45pp-w4rj-fj8v.json +++ b/advisories/unreviewed/2023/04/GHSA-45pp-w4rj-fj8v/GHSA-45pp-w4rj-fj8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45pp-w4rj-fj8v", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47336" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json b/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json index 2a3eedf70f6..dc6030b4ffb 100644 --- a/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json +++ b/advisories/unreviewed/2023/04/GHSA-4j2h-6232-f9wf/GHSA-4j2h-6232-f9wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j2h-6232-f9wf", - "modified": "2023-04-11T03:31:19Z", + "modified": "2023-04-14T18:30:18Z", "published": "2023-04-11T03:31:19Z", "aliases": [ "CVE-2023-27191" ], "details": "An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T01:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json b/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json index 71e8c8e64b0..79d3b8a863a 100644 --- a/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json +++ b/advisories/unreviewed/2023/04/GHSA-587p-pvvj-3ghc/GHSA-587p-pvvj-3ghc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-587p-pvvj-3ghc", - "modified": "2023-04-10T18:30:21Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-10T18:30:21Z", "aliases": [ "CVE-2015-10100" ], "details": "A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10. This issue affects some unknown processing of the file classes/dynwid_class.php. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.11 is able to address this issue. The name of the patch is d0a19c6efcdc86d7093b369bc9e29a0629e57795. It is recommended to upgrade the affected component. The identifier VDB-225353 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T18:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-5rpj-29cm-cpqf/GHSA-5rpj-29cm-cpqf.json b/advisories/unreviewed/2023/04/GHSA-5rpj-29cm-cpqf/GHSA-5rpj-29cm-cpqf.json index 3cda87c3617..0ae71ad1967 100644 --- a/advisories/unreviewed/2023/04/GHSA-5rpj-29cm-cpqf/GHSA-5rpj-29cm-cpqf.json +++ b/advisories/unreviewed/2023/04/GHSA-5rpj-29cm-cpqf/GHSA-5rpj-29cm-cpqf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rpj-29cm-cpqf", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47466" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json b/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json index 9bab841202d..ea420bc3a48 100644 --- a/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json +++ b/advisories/unreviewed/2023/04/GHSA-64jx-9wjf-vr92/GHSA-64jx-9wjf-vr92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64jx-9wjf-vr92", - "modified": "2023-04-10T18:30:22Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-10T18:30:22Z", "aliases": [ "CVE-2023-26986" ], "details": "An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T16:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8j63-7567-qrrm/GHSA-8j63-7567-qrrm.json b/advisories/unreviewed/2023/04/GHSA-8j63-7567-qrrm/GHSA-8j63-7567-qrrm.json index 222a98bfd9c..1c2a54ef49f 100644 --- a/advisories/unreviewed/2023/04/GHSA-8j63-7567-qrrm/GHSA-8j63-7567-qrrm.json +++ b/advisories/unreviewed/2023/04/GHSA-8j63-7567-qrrm/GHSA-8j63-7567-qrrm.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28311" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171882/Microsoft-Word-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json b/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json index c8491d7d503..fa7dd8bed16 100644 --- a/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json +++ b/advisories/unreviewed/2023/04/GHSA-9cpg-q9f9-cq47/GHSA-9cpg-q9f9-cq47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9cpg-q9f9-cq47", - "modified": "2023-04-06T21:30:18Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-06T21:30:18Z", "aliases": [ "CVE-2023-28500" ], "details": "** UNSUPPORTED WHEN ASSIGNED ** A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL. Adobe LiveCycle ES4 version 11.0.1 and later may be vulnerable if the application is installed with Java environment 7u21 and earlier. Exploitation of the vulnerability depends on two factors: insecure deserialization methods used in the Adobe LiveCycle application, and the use of Java environments 7u21 and earlier. The code execution is performed in the context of the account that is running the Adobe LiveCycle application. If the account is privileged, exploitation provides privileged access to the operating system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-06T21:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-c2xc-7cgf-x32h/GHSA-c2xc-7cgf-x32h.json b/advisories/unreviewed/2023/04/GHSA-c2xc-7cgf-x32h/GHSA-c2xc-7cgf-x32h.json index 466fc1b48db..04498b1fa01 100644 --- a/advisories/unreviewed/2023/04/GHSA-c2xc-7cgf-x32h/GHSA-c2xc-7cgf-x32h.json +++ b/advisories/unreviewed/2023/04/GHSA-c2xc-7cgf-x32h/GHSA-c2xc-7cgf-x32h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2xc-7cgf-x32h", - "modified": "2023-04-06T18:30:19Z", + "modified": "2023-04-14T18:30:20Z", "published": "2023-04-06T18:30:19Z", "aliases": [ "CVE-2023-0580" ], "details": "Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application, the following ones are affected by this vulnerability: User Interface System Monitoring1 Asset Inventory This issue affects My Control System (on-premise): from 5.0;0 through 5.13.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-06T17:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json b/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json index 21f87fb7d6c..a88636be90c 100644 --- a/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json +++ b/advisories/unreviewed/2023/04/GHSA-cgw5-jvm7-6f73/GHSA-cgw5-jvm7-6f73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgw5-jvm7-6f73", - "modified": "2023-04-10T18:30:22Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-10T18:30:22Z", "aliases": [ "CVE-2023-1969" ], "details": "A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file /admin/inventory/manage_stock.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-225406 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T16:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-cprr-rh4x-6x3j/GHSA-cprr-rh4x-6x3j.json b/advisories/unreviewed/2023/04/GHSA-cprr-rh4x-6x3j/GHSA-cprr-rh4x-6x3j.json index 0b6b4a5fcda..d415efd3bbb 100644 --- a/advisories/unreviewed/2023/04/GHSA-cprr-rh4x-6x3j/GHSA-cprr-rh4x-6x3j.json +++ b/advisories/unreviewed/2023/04/GHSA-cprr-rh4x-6x3j/GHSA-cprr-rh4x-6x3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cprr-rh4x-6x3j", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47463" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-fffg-x79m-65gr/GHSA-fffg-x79m-65gr.json b/advisories/unreviewed/2023/04/GHSA-fffg-x79m-65gr/GHSA-fffg-x79m-65gr.json index bf95888f77e..0f166438af9 100644 --- a/advisories/unreviewed/2023/04/GHSA-fffg-x79m-65gr/GHSA-fffg-x79m-65gr.json +++ b/advisories/unreviewed/2023/04/GHSA-fffg-x79m-65gr/GHSA-fffg-x79m-65gr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fffg-x79m-65gr", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47467" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-gj52-rqw6-xxqh/GHSA-gj52-rqw6-xxqh.json b/advisories/unreviewed/2023/04/GHSA-gj52-rqw6-xxqh/GHSA-gj52-rqw6-xxqh.json index ba671516085..f60c34213c0 100644 --- a/advisories/unreviewed/2023/04/GHSA-gj52-rqw6-xxqh/GHSA-gj52-rqw6-xxqh.json +++ b/advisories/unreviewed/2023/04/GHSA-gj52-rqw6-xxqh/GHSA-gj52-rqw6-xxqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gj52-rqw6-xxqh", - "modified": "2023-04-11T03:31:20Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T03:31:20Z", "aliases": [ "CVE-2022-43293" ], "details": "Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \\Wacom\\Wacom_Tablet.exe.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T01:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-gr5r-rfrm-7m5x/GHSA-gr5r-rfrm-7m5x.json b/advisories/unreviewed/2023/04/GHSA-gr5r-rfrm-7m5x/GHSA-gr5r-rfrm-7m5x.json index 27b91ad32bb..1ab5c2ecb0a 100644 --- a/advisories/unreviewed/2023/04/GHSA-gr5r-rfrm-7m5x/GHSA-gr5r-rfrm-7m5x.json +++ b/advisories/unreviewed/2023/04/GHSA-gr5r-rfrm-7m5x/GHSA-gr5r-rfrm-7m5x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr5r-rfrm-7m5x", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47464" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json b/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json index 70c506323d7..13f4d47c0a2 100644 --- a/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json +++ b/advisories/unreviewed/2023/04/GHSA-h266-6cqj-cxmw/GHSA-h266-6cqj-cxmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h266-6cqj-cxmw", - "modified": "2023-04-10T18:30:22Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-10T18:30:21Z", "aliases": [ "CVE-2023-27650" ], "details": "An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T17:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-jv73-596c-j7p7/GHSA-jv73-596c-j7p7.json b/advisories/unreviewed/2023/04/GHSA-jv73-596c-j7p7/GHSA-jv73-596c-j7p7.json index 59000ec13db..22e738cfa87 100644 --- a/advisories/unreviewed/2023/04/GHSA-jv73-596c-j7p7/GHSA-jv73-596c-j7p7.json +++ b/advisories/unreviewed/2023/04/GHSA-jv73-596c-j7p7/GHSA-jv73-596c-j7p7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jv73-596c-j7p7", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47337" ], "details": "In media service, there is a missing permission check. This could lead to local denial of service in media service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-mhrj-hwc3-pwvq/GHSA-mhrj-hwc3-pwvq.json b/advisories/unreviewed/2023/04/GHSA-mhrj-hwc3-pwvq/GHSA-mhrj-hwc3-pwvq.json index 5d7f36a2ce9..68c2430ad4b 100644 --- a/advisories/unreviewed/2023/04/GHSA-mhrj-hwc3-pwvq/GHSA-mhrj-hwc3-pwvq.json +++ b/advisories/unreviewed/2023/04/GHSA-mhrj-hwc3-pwvq/GHSA-mhrj-hwc3-pwvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhrj-hwc3-pwvq", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47335" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-mwg7-wp3h-xm4h/GHSA-mwg7-wp3h-xm4h.json b/advisories/unreviewed/2023/04/GHSA-mwg7-wp3h-xm4h/GHSA-mwg7-wp3h-xm4h.json index 4fb5301e037..11e78464c87 100644 --- a/advisories/unreviewed/2023/04/GHSA-mwg7-wp3h-xm4h/GHSA-mwg7-wp3h-xm4h.json +++ b/advisories/unreviewed/2023/04/GHSA-mwg7-wp3h-xm4h/GHSA-mwg7-wp3h-xm4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwg7-wp3h-xm4h", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47362" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-q3wj-5w9x-rhw4/GHSA-q3wj-5w9x-rhw4.json b/advisories/unreviewed/2023/04/GHSA-q3wj-5w9x-rhw4/GHSA-q3wj-5w9x-rhw4.json index 059a62324a9..cab96ef1769 100644 --- a/advisories/unreviewed/2023/04/GHSA-q3wj-5w9x-rhw4/GHSA-q3wj-5w9x-rhw4.json +++ b/advisories/unreviewed/2023/04/GHSA-q3wj-5w9x-rhw4/GHSA-q3wj-5w9x-rhw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3wj-5w9x-rhw4", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47468" ], "details": "In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-qmvc-wj32-3pg9/GHSA-qmvc-wj32-3pg9.json b/advisories/unreviewed/2023/04/GHSA-qmvc-wj32-3pg9/GHSA-qmvc-wj32-3pg9.json index 6cc7c240a17..564d20ef806 100644 --- a/advisories/unreviewed/2023/04/GHSA-qmvc-wj32-3pg9/GHSA-qmvc-wj32-3pg9.json +++ b/advisories/unreviewed/2023/04/GHSA-qmvc-wj32-3pg9/GHSA-qmvc-wj32-3pg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmvc-wj32-3pg9", - "modified": "2023-04-10T15:30:24Z", + "modified": "2023-04-14T18:30:18Z", "published": "2023-04-10T15:30:24Z", "aliases": [ "CVE-2023-29376" ], "details": "An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potential XSS by privileged users in Sitefinity to media libraries.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json b/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json index ec5a4b901b4..b5f2bfb7c28 100644 --- a/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json +++ b/advisories/unreviewed/2023/04/GHSA-wfwf-xhx7-3whj/GHSA-wfwf-xhx7-3whj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wfwf-xhx7-3whj", - "modified": "2023-04-10T18:30:22Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-10T18:30:22Z", "aliases": [ "CVE-2023-26919" ], "details": "delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T16:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json b/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json index 4c7a838b52a..aedf30b1de8 100644 --- a/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json +++ b/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr4w-95gx-6cfr", - "modified": "2023-04-08T06:30:24Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-08T06:30:24Z", "aliases": [ "CVE-2023-24626" ], "details": "socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-08T05:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-xj47-998q-qjgw/GHSA-xj47-998q-qjgw.json b/advisories/unreviewed/2023/04/GHSA-xj47-998q-qjgw/GHSA-xj47-998q-qjgw.json index 00956d327c7..2b604ef295b 100644 --- a/advisories/unreviewed/2023/04/GHSA-xj47-998q-qjgw/GHSA-xj47-998q-qjgw.json +++ b/advisories/unreviewed/2023/04/GHSA-xj47-998q-qjgw/GHSA-xj47-998q-qjgw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj47-998q-qjgw", - "modified": "2023-04-11T12:30:25Z", + "modified": "2023-04-14T18:30:19Z", "published": "2023-04-11T12:30:25Z", "aliases": [ "CVE-2022-47465" ], "details": "In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T12:15:00Z"