diff --git a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json index 3a096f10043..e04919b7fac 100644 --- a/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json +++ b/advisories/unreviewed/2024/01/GHSA-qmff-49xc-7rf6/GHSA-qmff-49xc-7rf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmff-49xc-7rf6", - "modified": "2024-10-16T15:32:05Z", + "modified": "2024-11-25T12:33:22Z", "published": "2024-01-17T18:31:36Z", "aliases": [ "CVE-2024-0646" diff --git a/advisories/unreviewed/2024/11/GHSA-mx37-2933-qxxq/GHSA-mx37-2933-qxxq.json b/advisories/unreviewed/2024/11/GHSA-mx37-2933-qxxq/GHSA-mx37-2933-qxxq.json new file mode 100644 index 00000000000..bea24db6e45 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mx37-2933-qxxq/GHSA-mx37-2933-qxxq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx37-2933-qxxq", + "modified": "2024-11-25T12:33:23Z", + "published": "2024-11-25T12:33:23Z", + "aliases": [ + "CVE-2020-12492" + ], + "details": "Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12492" + }, + { + "type": "WEB", + "url": "https://www.vivo.com/en/support/security-advisory-detail?id=12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T10:21:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qg98-f7q6-8623/GHSA-qg98-f7q6-8623.json b/advisories/unreviewed/2024/11/GHSA-qg98-f7q6-8623/GHSA-qg98-f7q6-8623.json new file mode 100644 index 00000000000..ff4d39bdc64 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qg98-f7q6-8623/GHSA-qg98-f7q6-8623.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg98-f7q6-8623", + "modified": "2024-11-25T12:33:23Z", + "published": "2024-11-25T12:33:23Z", + "aliases": [ + "CVE-2020-12491" + ], + "details": "Improper control of framework service permissions with possibility of some sensitive device information leakage.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-12491" + }, + { + "type": "WEB", + "url": "https://www.vivo.com/en/support/security-advisory-detail?id=11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T10:15:04Z" + } +} \ No newline at end of file