diff --git a/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json b/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json index ac233663a1f..11931b6778d 100644 --- a/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json +++ b/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jpxc-vmjf-9fcj", - "modified": "2024-09-16T22:55:00Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-09-16T14:37:26Z", "aliases": [ "CVE-2024-8775" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8775" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8969" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8775" diff --git a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json index ed96f058fe7..91edb85665b 100644 --- a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json +++ b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-586p-749j-fhwp", - "modified": "2024-11-06T12:31:32Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-9675" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8686" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8690" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8703" diff --git a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json index 7887a994e1a..830622e9f0b 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json +++ b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mc76-5925-c5p6", - "modified": "2024-11-05T09:30:36Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9341" @@ -72,6 +72,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8428" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8690" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8846" diff --git a/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json b/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json index 75ac48ca760..6de660b771b 100644 --- a/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json +++ b/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32p4-gm2c-wmch", - "modified": "2024-11-06T15:37:19Z", + "modified": "2024-11-06T21:30:55Z", "published": "2024-11-06T12:31:32Z", "aliases": [ "CVE-2024-9902" @@ -140,6 +140,10 @@ "type": "WEB", "url": "https://github.com/ansible/ansible/commit/f7be90626da3035c697623dcf9c90b7a0bc91c92" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8969" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9902" diff --git a/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json b/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json index a0f50528217..4678ebf947f 100644 --- a/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json +++ b/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-3jvj-rg8c-7p8m/GHSA-3jvj-rg8c-7p8m.json b/advisories/unreviewed/2023/07/GHSA-3jvj-rg8c-7p8m/GHSA-3jvj-rg8c-7p8m.json index 0ccb86a01e0..da27061172f 100644 --- a/advisories/unreviewed/2023/07/GHSA-3jvj-rg8c-7p8m/GHSA-3jvj-rg8c-7p8m.json +++ b/advisories/unreviewed/2023/07/GHSA-3jvj-rg8c-7p8m/GHSA-3jvj-rg8c-7p8m.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-jmwv-xww6-6hcv/GHSA-jmwv-xww6-6hcv.json b/advisories/unreviewed/2023/07/GHSA-jmwv-xww6-6hcv/GHSA-jmwv-xww6-6hcv.json index 3a307dd5286..ef0d78243dd 100644 --- a/advisories/unreviewed/2023/07/GHSA-jmwv-xww6-6hcv/GHSA-jmwv-xww6-6hcv.json +++ b/advisories/unreviewed/2023/07/GHSA-jmwv-xww6-6hcv/GHSA-jmwv-xww6-6hcv.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-273", "CWE-754" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/01/GHSA-jggv-jphq-xvw7/GHSA-jggv-jphq-xvw7.json b/advisories/unreviewed/2024/01/GHSA-jggv-jphq-xvw7/GHSA-jggv-jphq-xvw7.json index 710a53e062d..b791748e7ed 100644 --- a/advisories/unreviewed/2024/01/GHSA-jggv-jphq-xvw7/GHSA-jggv-jphq-xvw7.json +++ b/advisories/unreviewed/2024/01/GHSA-jggv-jphq-xvw7/GHSA-jggv-jphq-xvw7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json b/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json index 89bea21f2b8..28387a92fc3 100644 --- a/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json +++ b/advisories/unreviewed/2024/01/GHSA-q6j4-xjv3-96rj/GHSA-q6j4-xjv3-96rj.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-2c83-rhjj-cjg4/GHSA-2c83-rhjj-cjg4.json b/advisories/unreviewed/2024/02/GHSA-2c83-rhjj-cjg4/GHSA-2c83-rhjj-cjg4.json index 3e2c1ebc416..00b25163bf2 100644 --- a/advisories/unreviewed/2024/02/GHSA-2c83-rhjj-cjg4/GHSA-2c83-rhjj-cjg4.json +++ b/advisories/unreviewed/2024/02/GHSA-2c83-rhjj-cjg4/GHSA-2c83-rhjj-cjg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2c83-rhjj-cjg4", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2024-23674" ], "details": "The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the \"sPACE (Spoofing Password Authenticated Connection Establishment)\" issue. This occurs because of a combination of factors, such as insecure PIN entry (for basic readers) and eid:// deeplinking. The victim must be using a modified eID kernel, which may occur if the victim is tricked into installing a fake version of an official app. NOTE: the BSI position is \"ensuring a secure operational environment at the client side is an obligation of the ID card owner.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-v35r-73cx-8h67/GHSA-v35r-73cx-8h67.json b/advisories/unreviewed/2024/02/GHSA-v35r-73cx-8h67/GHSA-v35r-73cx-8h67.json index 16dc739c53a..2aaa15f9540 100644 --- a/advisories/unreviewed/2024/02/GHSA-v35r-73cx-8h67/GHSA-v35r-73cx-8h67.json +++ b/advisories/unreviewed/2024/02/GHSA-v35r-73cx-8h67/GHSA-v35r-73cx-8h67.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-vr4j-34fw-6v8v/GHSA-vr4j-34fw-6v8v.json b/advisories/unreviewed/2024/02/GHSA-vr4j-34fw-6v8v/GHSA-vr4j-34fw-6v8v.json index 31af891b5e9..afa0512a0b1 100644 --- a/advisories/unreviewed/2024/02/GHSA-vr4j-34fw-6v8v/GHSA-vr4j-34fw-6v8v.json +++ b/advisories/unreviewed/2024/02/GHSA-vr4j-34fw-6v8v/GHSA-vr4j-34fw-6v8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vr4j-34fw-6v8v", - "modified": "2024-02-16T03:30:51Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-02-16T03:30:51Z", "aliases": [ "CVE-2024-0030" ], "details": "In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6hr8-534p-8986/GHSA-6hr8-534p-8986.json b/advisories/unreviewed/2024/03/GHSA-6hr8-534p-8986/GHSA-6hr8-534p-8986.json index 76453ee9485..73a725f1b93 100644 --- a/advisories/unreviewed/2024/03/GHSA-6hr8-534p-8986/GHSA-6hr8-534p-8986.json +++ b/advisories/unreviewed/2024/03/GHSA-6hr8-534p-8986/GHSA-6hr8-534p-8986.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hr8-534p-8986", - "modified": "2024-06-26T00:31:35Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2023-52492" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fix NULL pointer in channel unregistration function\n\n__dma_async_device_channel_register() can fail. In case of failure,\nchan->local is freed (with free_percpu()), and chan->local is nullified.\nWhen dma_async_device_unregister() is called (because of managed API or\nintentionally by DMA controller driver), channels are unconditionally\nunregistered, leading to this NULL pointer:\n[ 1.318693] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000d0\n[...]\n[ 1.484499] Call trace:\n[ 1.486930] device_del+0x40/0x394\n[ 1.490314] device_unregister+0x20/0x7c\n[ 1.494220] __dma_async_device_channel_unregister+0x68/0xc0\n\nLook at dma_async_device_register() function error path, channel device\nunregistration is done only if chan->local is not NULL.\n\nThen add the same condition at the beginning of\n__dma_async_device_channel_unregister() function, to avoid NULL pointer\nissue whatever the API used to reach this function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json b/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json index 2e18ef60941..55d9fa119e6 100644 --- a/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json +++ b/advisories/unreviewed/2024/03/GHSA-76jf-phxv-6m5c/GHSA-76jf-phxv-6m5c.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9mq8-5h36-frr5/GHSA-9mq8-5h36-frr5.json b/advisories/unreviewed/2024/03/GHSA-9mq8-5h36-frr5/GHSA-9mq8-5h36-frr5.json index 2b2a074544a..4ed43549634 100644 --- a/advisories/unreviewed/2024/03/GHSA-9mq8-5h36-frr5/GHSA-9mq8-5h36-frr5.json +++ b/advisories/unreviewed/2024/03/GHSA-9mq8-5h36-frr5/GHSA-9mq8-5h36-frr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mq8-5h36-frr5", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-03-21T12:31:56Z", "aliases": [ "CVE-2023-52620" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: disallow timeout for anonymous sets\n\nNever used from userspace, disallow these parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T11:15:28Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9prw-2r97-97f6/GHSA-9prw-2r97-97f6.json b/advisories/unreviewed/2024/03/GHSA-9prw-2r97-97f6/GHSA-9prw-2r97-97f6.json index e543a89cca6..e10319d316f 100644 --- a/advisories/unreviewed/2024/03/GHSA-9prw-2r97-97f6/GHSA-9prw-2r97-97f6.json +++ b/advisories/unreviewed/2024/03/GHSA-9prw-2r97-97f6/GHSA-9prw-2r97-97f6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9prw-2r97-97f6", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-03-03T00:30:31Z", "aliases": [ "CVE-2023-52511" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sun6i: reduce DMA RX transfer width to single byte\n\nThrough empirical testing it has been determined that sometimes RX SPI\ntransfers with DMA enabled return corrupted data. This is down to single\nor even multiple bytes lost during DMA transfer from SPI peripheral to\nmemory. It seems the RX FIFO within the SPI peripheral can become\nconfused when performing bus read accesses wider than a single byte to it\nduring an active SPI transfer.\n\nThis patch reduces the width of individual DMA read accesses to the\nRX FIFO to a single byte to mitigate that issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json b/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json index b6faaf0eca6..d7a0e12735b 100644 --- a/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json +++ b/advisories/unreviewed/2024/03/GHSA-cpxg-8g4c-4mhp/GHSA-cpxg-8g4c-4mhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpxg-8g4c-4mhp", - "modified": "2024-03-11T21:31:24Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-03-11T21:31:24Z", "aliases": [ "CVE-2024-22006" ], "details": "Android kernel allows Information disclosure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f4j7-jf79-wp46/GHSA-f4j7-jf79-wp46.json b/advisories/unreviewed/2024/03/GHSA-f4j7-jf79-wp46/GHSA-f4j7-jf79-wp46.json index 8e430570c12..0d367c0c603 100644 --- a/advisories/unreviewed/2024/03/GHSA-f4j7-jf79-wp46/GHSA-f4j7-jf79-wp46.json +++ b/advisories/unreviewed/2024/03/GHSA-f4j7-jf79-wp46/GHSA-f4j7-jf79-wp46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f4j7-jf79-wp46", - "modified": "2024-03-16T00:30:32Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-03-16T00:30:32Z", "aliases": [ "CVE-2024-23298" ], "details": "A logic issue was addressed with improved state management.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f8jx-pmvg-jgfh/GHSA-f8jx-pmvg-jgfh.json b/advisories/unreviewed/2024/03/GHSA-f8jx-pmvg-jgfh/GHSA-f8jx-pmvg-jgfh.json index 3bff6ed7df2..5c3ffc8e42e 100644 --- a/advisories/unreviewed/2024/03/GHSA-f8jx-pmvg-jgfh/GHSA-f8jx-pmvg-jgfh.json +++ b/advisories/unreviewed/2024/03/GHSA-f8jx-pmvg-jgfh/GHSA-f8jx-pmvg-jgfh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8jx-pmvg-jgfh", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52522" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix possible store tearing in neigh_periodic_work()\n\nWhile looking at a related syzbot report involving neigh_periodic_work(),\nI found that I forgot to add an annotation when deleting an\nRCU protected item from a list.\n\nReaders use rcu_deference(*np), we need to use either\nrcu_assign_pointer() or WRITE_ONCE() on writer side\nto prevent store tearing.\n\nI use rcu_assign_pointer() to have lockdep support,\nthis was the choice made in neigh_flush_dev().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wf6g-6473-wm39/GHSA-wf6g-6473-wm39.json b/advisories/unreviewed/2024/03/GHSA-wf6g-6473-wm39/GHSA-wf6g-6473-wm39.json index 36dc3365668..5b92dbaa88d 100644 --- a/advisories/unreviewed/2024/03/GHSA-wf6g-6473-wm39/GHSA-wf6g-6473-wm39.json +++ b/advisories/unreviewed/2024/03/GHSA-wf6g-6473-wm39/GHSA-wf6g-6473-wm39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wf6g-6473-wm39", - "modified": "2024-03-02T00:31:31Z", + "modified": "2024-11-06T21:30:53Z", "published": "2024-03-02T00:31:31Z", "aliases": [ "CVE-2023-49539" ], "details": "Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4743-mhg5-8p4q/GHSA-4743-mhg5-8p4q.json b/advisories/unreviewed/2024/04/GHSA-4743-mhg5-8p4q/GHSA-4743-mhg5-8p4q.json index fbdf078a869..154959f272f 100644 --- a/advisories/unreviewed/2024/04/GHSA-4743-mhg5-8p4q/GHSA-4743-mhg5-8p4q.json +++ b/advisories/unreviewed/2024/04/GHSA-4743-mhg5-8p4q/GHSA-4743-mhg5-8p4q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json b/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json index fb29f1e45c2..e9e67c8f97d 100644 --- a/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json +++ b/advisories/unreviewed/2024/04/GHSA-c27x-344g-xx8m/GHSA-c27x-344g-xx8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c27x-344g-xx8m", - "modified": "2024-04-05T21:32:43Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-04-05T21:32:43Z", "aliases": [ "CVE-2024-29742" ], "details": "In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json b/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json index 1b4316ca67e..88640810649 100644 --- a/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json +++ b/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpf4-cfch-367m", - "modified": "2024-06-25T21:31:12Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-04-05T09:30:38Z", "aliases": [ "CVE-2024-26810" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Lock external INTx masking ops\n\nMask operations through config space changes to DisINTx may race INTx\nconfiguration changes via ioctl. Create wrappers that add locking for\npaths outside of the core interrupt code.\n\nIn particular, irq_type is updated holding igate, therefore testing\nis_intx() requires holding igate. For example clearing DisINTx from\nconfig space can otherwise race changes of the interrupt configuration.\n\nThis aligns interfaces which may trigger the INTx eventfd into two\ncamps, one side serialized by igate and the other only enabled while\nINTx is configured. A subsequent patch introduces synchronization for\nthe latter flows.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T09:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json b/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json index de284111684..3c31fbb5fa5 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json +++ b/advisories/unreviewed/2024/04/GHSA-qp87-7fwc-x65r/GHSA-qp87-7fwc-x65r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp87-7fwc-x65r", - "modified": "2024-06-26T00:31:37Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-04-17T12:32:03Z", "aliases": [ "CVE-2024-26843" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: runtime: Fix potential overflow of soft-reserved region size\n\nmd_size will have been narrowed if we have >= 4GB worth of pages in a\nsoft-reserved region.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5p99-hcg9-j3m3/GHSA-5p99-hcg9-j3m3.json b/advisories/unreviewed/2024/05/GHSA-5p99-hcg9-j3m3/GHSA-5p99-hcg9-j3m3.json index 01eb6b0d282..223ea677276 100644 --- a/advisories/unreviewed/2024/05/GHSA-5p99-hcg9-j3m3/GHSA-5p99-hcg9-j3m3.json +++ b/advisories/unreviewed/2024/05/GHSA-5p99-hcg9-j3m3/GHSA-5p99-hcg9-j3m3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5p99-hcg9-j3m3", - "modified": "2024-05-21T18:31:21Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52800" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix htt pktlog locking\n\nThe ath11k active pdevs are protected by RCU but the htt pktlog handling\ncode calling ath11k_mac_get_ar_by_pdev_id() was not marked as a\nread-side critical section.\n\nMark the code in question as an RCU read-side critical section to avoid\nany potential use-after-free issues.\n\nCompile tested only.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-62x6-4gmp-fg78/GHSA-62x6-4gmp-fg78.json b/advisories/unreviewed/2024/05/GHSA-62x6-4gmp-fg78/GHSA-62x6-4gmp-fg78.json index 4f160133f70..ca8d5b5b058 100644 --- a/advisories/unreviewed/2024/05/GHSA-62x6-4gmp-fg78/GHSA-62x6-4gmp-fg78.json +++ b/advisories/unreviewed/2024/05/GHSA-62x6-4gmp-fg78/GHSA-62x6-4gmp-fg78.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62x6-4gmp-fg78", - "modified": "2024-05-21T15:31:42Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-21T15:31:42Z", "aliases": [ "CVE-2021-47297" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix uninit-value in caif_seqpkt_sendmsg\n\nWhen nr_segs equal to zero in iovec_from_user, the object\nmsg->msg_iter.iov is uninit stack memory in caif_seqpkt_sendmsg\nwhich is defined in ___sys_sendmsg. So we cann't just judge\nmsg->msg_iter.iov->base directlly. We can use nr_segs to judge\nmsg in caif_seqpkt_sendmsg whether has data buffers.\n\n=====================================================\nBUG: KMSAN: uninit-value in caif_seqpkt_sendmsg+0x693/0xf60 net/caif/caif_socket.c:542\nCall Trace:\n __dump_stack lib/dump_stack.c:77 [inline]\n dump_stack+0x1c9/0x220 lib/dump_stack.c:118\n kmsan_report+0xf7/0x1e0 mm/kmsan/kmsan_report.c:118\n __msan_warning+0x58/0xa0 mm/kmsan/kmsan_instr.c:215\n caif_seqpkt_sendmsg+0x693/0xf60 net/caif/caif_socket.c:542\n sock_sendmsg_nosec net/socket.c:652 [inline]\n sock_sendmsg net/socket.c:672 [inline]\n ____sys_sendmsg+0x12b6/0x1350 net/socket.c:2343\n ___sys_sendmsg net/socket.c:2397 [inline]\n __sys_sendmmsg+0x808/0xc90 net/socket.c:2480\n __compat_sys_sendmmsg net/compat.c:656 [inline]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json b/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json index 660d985b69e..7b5d1460ee1 100644 --- a/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json +++ b/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6vq2-rrj2-6jjh", - "modified": "2024-05-22T09:31:46Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-22T09:31:46Z", "aliases": [ "CVE-2021-47477" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: dt9812: fix DMA buffers on stack\n\nUSB transfer buffers are typically mapped for DMA and must not be\nallocated on the stack or transfers will fail.\n\nAllocate proper transfer buffers in the various command helpers and\nreturn an error on short transfers instead of acting on random stack\ndata.\n\nNote that this also fixes a stack info leak on systems where DMA is not\nused as 32 bytes are always sent to the device regardless of how short\nthe command is.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T09:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8gv2-gcw7-7jwv/GHSA-8gv2-gcw7-7jwv.json b/advisories/unreviewed/2024/05/GHSA-8gv2-gcw7-7jwv/GHSA-8gv2-gcw7-7jwv.json index ecd5835d4a4..21176d60e86 100644 --- a/advisories/unreviewed/2024/05/GHSA-8gv2-gcw7-7jwv/GHSA-8gv2-gcw7-7jwv.json +++ b/advisories/unreviewed/2024/05/GHSA-8gv2-gcw7-7jwv/GHSA-8gv2-gcw7-7jwv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gv2-gcw7-7jwv", - "modified": "2024-06-10T18:30:58Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27816" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker may be able to access user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -71,7 +74,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:04Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json b/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json index 06195c07e72..701294c7877 100644 --- a/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json +++ b/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fx68-rvxh-32hf", - "modified": "2024-05-01T15:30:35Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-01T15:30:35Z", "aliases": [ "CVE-2024-27032" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid potential panic during recovery\n\nDuring recovery, if FAULT_BLOCK is on, it is possible that\nf2fs_reserve_new_block() will return -ENOSPC during recovery,\nthen it may trigger panic.\n\nAlso, if fault injection rate is 1 and only FAULT_BLOCK fault\ntype is on, it may encounter deadloop in loop of block reservation.\n\nLet's change as below to fix these issues:\n- remove bug_on() to avoid panic.\n- limit the loop count of block reservation to avoid potential\ndeadloop.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h6gr-4677-26p9/GHSA-h6gr-4677-26p9.json b/advisories/unreviewed/2024/05/GHSA-h6gr-4677-26p9/GHSA-h6gr-4677-26p9.json index b06b84d9e95..e832dd94ff4 100644 --- a/advisories/unreviewed/2024/05/GHSA-h6gr-4677-26p9/GHSA-h6gr-4677-26p9.json +++ b/advisories/unreviewed/2024/05/GHSA-h6gr-4677-26p9/GHSA-h6gr-4677-26p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6gr-4677-26p9", - "modified": "2024-05-21T15:31:44Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-21T15:31:44Z", "aliases": [ "CVE-2021-47384" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field\n\nIf driver read tmp value sufficient for\n(tmp & 0x08) && (!(tmp & 0x80)) && ((tmp & 0x7) == ((tmp >> 4) & 0x7))\nfrom device then Null pointer dereference occurs.\n(It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers)\nAlso lm75[] does not serve a purpose anymore after switching to\ndevm_i2c_new_dummy_device() in w83791d_detect_subclients().\n\nThe patch fixes possible NULL pointer dereference by removing lm75[].\n\nFound by Linux Driver Verification project (linuxtesting.org).\n\n[groeck: Dropped unnecessary continuation lines, fixed multi-line alignments]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:23Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hm79-2xvr-6jv4/GHSA-hm79-2xvr-6jv4.json b/advisories/unreviewed/2024/05/GHSA-hm79-2xvr-6jv4/GHSA-hm79-2xvr-6jv4.json index 95084f89850..ede0f209c79 100644 --- a/advisories/unreviewed/2024/05/GHSA-hm79-2xvr-6jv4/GHSA-hm79-2xvr-6jv4.json +++ b/advisories/unreviewed/2024/05/GHSA-hm79-2xvr-6jv4/GHSA-hm79-2xvr-6jv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hm79-2xvr-6jv4", - "modified": "2024-05-01T15:30:36Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27054" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: fix double module refcount decrement\n\nOnce the discipline is associated with the device, deleting the device\ntakes care of decrementing the module's refcount. Doing it manually on\nthis error path causes refcount to artificially decrease on each error\nwhile it should just stay the same.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json b/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json index 8f0aae52dce..d64d67a0ff7 100644 --- a/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json +++ b/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9g6-83mp-8mvr", - "modified": "2024-06-26T00:31:41Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ttpci: fix two memleaks in budget_av_attach\n\nWhen saa7146_register_device and saa7146_vv_init fails, budget_av_attach\nshould free the resources it allocates, like the error-handling of\nttpci_budget_init does. Besides, there are two fixme comment refers to\nsuch deallocations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:51Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json b/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json index 84e04e5fde5..f829997a75c 100644 --- a/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json +++ b/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p47x-q59q-2mpw", - "modified": "2024-05-21T15:31:40Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-21T15:31:40Z", "aliases": [ "CVE-2021-47231" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcba_usb: fix memory leak in mcba_usb\n\nSyzbot reported memory leak in SocketCAN driver for Microchip CAN BUS\nAnalyzer Tool. The problem was in unfreed usb_coherent.\n\nIn mcba_usb_start() 20 coherent buffers are allocated and there is\nnothing, that frees them:\n\n1) In callback function the urb is resubmitted and that's all\n2) In disconnect function urbs are simply killed, but URB_FREE_BUFFER\n is not set (see mcba_usb_start) and this flag cannot be used with\n coherent buffers.\n\nFail log:\n| [ 1354.053291][ T8413] mcba_usb 1-1:0.0 can0: device disconnected\n| [ 1367.059384][ T8420] kmemleak: 20 new suspected memory leaks (see /sys/kernel/debug/kmem)\n\nSo, all allocated buffers should be freed with usb_free_coherent()\nexplicitly\n\nNOTE:\nThe same pattern for allocating and freeing coherent buffers\nis used in drivers/net/can/usb/kvaser_usb/kvaser_usb_core.c", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x4xc-qqhc-xfmq/GHSA-x4xc-qqhc-xfmq.json b/advisories/unreviewed/2024/05/GHSA-x4xc-qqhc-xfmq/GHSA-x4xc-qqhc-xfmq.json index 9655fe6a0f4..32f06cd9daf 100644 --- a/advisories/unreviewed/2024/05/GHSA-x4xc-qqhc-xfmq/GHSA-x4xc-qqhc-xfmq.json +++ b/advisories/unreviewed/2024/05/GHSA-x4xc-qqhc-xfmq/GHSA-x4xc-qqhc-xfmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4xc-qqhc-xfmq", - "modified": "2024-05-21T18:31:23Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52870" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt6765: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:23Z" diff --git a/advisories/unreviewed/2024/06/GHSA-89r8-fpgw-f2hq/GHSA-89r8-fpgw-f2hq.json b/advisories/unreviewed/2024/06/GHSA-89r8-fpgw-f2hq/GHSA-89r8-fpgw-f2hq.json index d88091801b6..ef2a943a69e 100644 --- a/advisories/unreviewed/2024/06/GHSA-89r8-fpgw-f2hq/GHSA-89r8-fpgw-f2hq.json +++ b/advisories/unreviewed/2024/06/GHSA-89r8-fpgw-f2hq/GHSA-89r8-fpgw-f2hq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89r8-fpgw-f2hq", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47586" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: dwmac-rk: fix oob read in rk_gmac_setup\n\nKASAN reports an out-of-bounds read in rk_gmac_setup on the line:\n\n\twhile (ops->regs[i]) {\n\nThis happens for most platforms since the regs flexible array member is\nempty, so the memory after the ops structure is being read here. It\nseems that mostly this happens to contain zero anyway, so we get lucky\nand everything still works.\n\nTo avoid adding redundant data to nearly all the ops structures, add a\nnew flag to indicate whether the regs field is valid and avoid this loop\nwhen it is not.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hmmc-gg67-83cw/GHSA-hmmc-gg67-83cw.json b/advisories/unreviewed/2024/06/GHSA-hmmc-gg67-83cw/GHSA-hmmc-gg67-83cw.json index 7667b5a7ddf..059dc9886ba 100644 --- a/advisories/unreviewed/2024/06/GHSA-hmmc-gg67-83cw/GHSA-hmmc-gg67-83cw.json +++ b/advisories/unreviewed/2024/06/GHSA-hmmc-gg67-83cw/GHSA-hmmc-gg67-83cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmmc-gg67-83cw", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38593" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: micrel: Fix receiving the timestamp in the frame for lan8841\n\nThe blamed commit started to use the ptp workqueue to get the second\npart of the timestamp. And when the port was set down, then this\nworkqueue is stopped. But if the config option NETWORK_PHY_TIMESTAMPING\nis not enabled, then the ptp_clock is not initialized so then it would\ncrash when it would try to access the delayed work.\nSo then basically by setting up and then down the port, it would crash.\nThe fix consists in checking if the ptp_clock is initialized and only\nthen cancel the delayed work.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json b/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json index 2efd34868a3..ee1cb075264 100644 --- a/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json +++ b/advisories/unreviewed/2024/08/GHSA-hm5h-rw9m-g27p/GHSA-hm5h-rw9m-g27p.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json b/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json index 1f7c7f03767..f1ed38d7966 100644 --- a/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json +++ b/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73w6-p42r-w4jh", - "modified": "2024-09-30T21:31:06Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-09-30T21:31:06Z", "aliases": [ "CVE-2024-28808" ], "details": "An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T21:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json b/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json index 75761779342..8cae358220a 100644 --- a/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json +++ b/advisories/unreviewed/2024/09/GHSA-ff7x-57mx-2mfq/GHSA-ff7x-57mx-2mfq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ff7x-57mx-2mfq", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-39339" ], "details": "A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and personally identifiable information (PII). The exposure of such information may have serious implications for user privacy and system integrity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T20:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json b/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json index 04515f50633..eae8a4d7293 100644 --- a/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json +++ b/advisories/unreviewed/2024/10/GHSA-2239-h2rh-5fp9/GHSA-2239-h2rh-5fp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2239-h2rh-5fp9", - "modified": "2024-10-17T18:31:36Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-10-17T18:31:36Z", "aliases": [ "CVE-2024-49220" diff --git a/advisories/unreviewed/2024/10/GHSA-mh6q-7483-rvj7/GHSA-mh6q-7483-rvj7.json b/advisories/unreviewed/2024/10/GHSA-mh6q-7483-rvj7/GHSA-mh6q-7483-rvj7.json index 19562b17f02..d43a4cfd1fb 100644 --- a/advisories/unreviewed/2024/10/GHSA-mh6q-7483-rvj7/GHSA-mh6q-7483-rvj7.json +++ b/advisories/unreviewed/2024/10/GHSA-mh6q-7483-rvj7/GHSA-mh6q-7483-rvj7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh6q-7483-rvj7", - "modified": "2024-10-11T18:32:50Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-42018" ], "details": "An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to the security of the HPC configuration. Because these parameters are needed for initialization, there is no available mechanism to ensure access control on the management node, and a mitigation measure is normally put in place to prevent access to unprivileged users. It was discovered that this mitigation measure does not survive a reboot of diskful nodes. (Diskless nodes are not at risk.) The mistake lies in the cloudinit configuration: the iptables configuration should have been in the bootcmd instead of the runcmd section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T17:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json index 97f09f1a4e9..97bc10f62a5 100644 --- a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json +++ b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq2p-5pc6-wpgf", - "modified": "2024-11-06T12:31:32Z", + "modified": "2024-11-06T21:30:54Z", "published": "2024-10-15T18:30:50Z", "aliases": [ "CVE-2024-9676" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8686" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8690" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9676" diff --git a/advisories/unreviewed/2024/11/GHSA-2jc3-r6g9-7j93/GHSA-2jc3-r6g9-7j93.json b/advisories/unreviewed/2024/11/GHSA-2jc3-r6g9-7j93/GHSA-2jc3-r6g9-7j93.json index 3e8066b09f0..2a0da074d83 100644 --- a/advisories/unreviewed/2024/11/GHSA-2jc3-r6g9-7j93/GHSA-2jc3-r6g9-7j93.json +++ b/advisories/unreviewed/2024/11/GHSA-2jc3-r6g9-7j93/GHSA-2jc3-r6g9-7j93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jc3-r6g9-7j93", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-06T21:30:55Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-45185" ], "details": "An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS protocol.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T20:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3gf9-wv65-gwh9/GHSA-3gf9-wv65-gwh9.json b/advisories/unreviewed/2024/11/GHSA-3gf9-wv65-gwh9/GHSA-3gf9-wv65-gwh9.json index 55aa234838f..38c88185c3c 100644 --- a/advisories/unreviewed/2024/11/GHSA-3gf9-wv65-gwh9/GHSA-3gf9-wv65-gwh9.json +++ b/advisories/unreviewed/2024/11/GHSA-3gf9-wv65-gwh9/GHSA-3gf9-wv65-gwh9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3gf9-wv65-gwh9", - "modified": "2024-11-05T00:31:28Z", + "modified": "2024-11-06T21:30:55Z", "published": "2024-11-05T00:31:28Z", "aliases": [ "CVE-2024-48052" ], "details": "In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json b/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json new file mode 100644 index 00000000000..aca74807ff1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w77-hpx9-8fm3", + "modified": "2024-11-06T21:30:56Z", + "published": "2024-11-06T21:30:56Z", + "aliases": [ + "CVE-2024-10941" + ], + "details": "A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10941" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1880879" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1887614" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-21" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9394-rw2q-x5m7/GHSA-9394-rw2q-x5m7.json b/advisories/unreviewed/2024/11/GHSA-9394-rw2q-x5m7/GHSA-9394-rw2q-x5m7.json index 38dc4c64469..2b60dd6a4ef 100644 --- a/advisories/unreviewed/2024/11/GHSA-9394-rw2q-x5m7/GHSA-9394-rw2q-x5m7.json +++ b/advisories/unreviewed/2024/11/GHSA-9394-rw2q-x5m7/GHSA-9394-rw2q-x5m7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9394-rw2q-x5m7", - "modified": "2024-11-04T21:30:33Z", + "modified": "2024-11-06T21:30:55Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-48463" ], "details": "Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T21:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9jcp-9vh9-r3w5/GHSA-9jcp-9vh9-r3w5.json b/advisories/unreviewed/2024/11/GHSA-9jcp-9vh9-r3w5/GHSA-9jcp-9vh9-r3w5.json index 9312445c632..f3e6d737772 100644 --- a/advisories/unreviewed/2024/11/GHSA-9jcp-9vh9-r3w5/GHSA-9jcp-9vh9-r3w5.json +++ b/advisories/unreviewed/2024/11/GHSA-9jcp-9vh9-r3w5/GHSA-9jcp-9vh9-r3w5.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-611", "CWE-91" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json b/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json index 57d850e04bb..308b4617c2c 100644 --- a/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json +++ b/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm2r-w7cj-r54r", - "modified": "2024-11-05T18:32:11Z", + "modified": "2024-11-06T21:30:55Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-51362" ], "details": "The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security. No credentials or special permissions are required, and access can be gained remotely over the network.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T17:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json b/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json index 12e28092757..3f0c6d5df3d 100644 --- a/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json +++ b/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-r265-6x28-5pfq/GHSA-r265-6x28-5pfq.json b/advisories/unreviewed/2024/11/GHSA-r265-6x28-5pfq/GHSA-r265-6x28-5pfq.json new file mode 100644 index 00000000000..6a5bdc04fce --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r265-6x28-5pfq/GHSA-r265-6x28-5pfq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r265-6x28-5pfq", + "modified": "2024-11-06T21:30:56Z", + "published": "2024-11-06T21:30:56Z", + "aliases": [ + "CVE-2024-10926" + ], + "details": "A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /toggle_fold_panel.php of the component Tabelas Section. The manipulation of the argument p leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10926" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1h9LlTV1FVvOSDBWc7qwU_5qcboCKd6H99Oqg3rZdBRQ/edit?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283325" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283325" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.429635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-06T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json b/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json index 89d4d7afbbb..df53b25e260 100644 --- a/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json +++ b/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv9r-mhj6-33xr", - "modified": "2024-11-05T21:30:43Z", + "modified": "2024-11-06T21:30:55Z", "published": "2024-11-05T21:30:43Z", "aliases": [ "CVE-2024-51240" ], "details": "An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T19:15:07Z"