From 7f45dad746ed4d6cddf1a13b37827a96023c74bb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 6 Aug 2024 09:33:38 +0000 Subject: [PATCH] Publish Advisories GHSA-f537-rhm6-gc65 GHSA-qxhm-3vp2-fcq3 --- .../GHSA-f537-rhm6-gc65.json | 6 ++- .../GHSA-qxhm-3vp2-fcq3.json | 43 +++++++++++++++++++ 2 files changed, 48 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json diff --git a/advisories/unreviewed/2024/06/GHSA-f537-rhm6-gc65/GHSA-f537-rhm6-gc65.json b/advisories/unreviewed/2024/06/GHSA-f537-rhm6-gc65/GHSA-f537-rhm6-gc65.json index 4b9367f8773..0320a0f0a58 100644 --- a/advisories/unreviewed/2024/06/GHSA-f537-rhm6-gc65/GHSA-f537-rhm6-gc65.json +++ b/advisories/unreviewed/2024/06/GHSA-f537-rhm6-gc65/GHSA-f537-rhm6-gc65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f537-rhm6-gc65", - "modified": "2024-06-18T00:31:25Z", + "modified": "2024-08-06T09:31:38Z", "published": "2024-06-18T00:31:25Z", "aliases": [ "CVE-2024-6080" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json b/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json new file mode 100644 index 00000000000..cce13c1ebb9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qxhm-3vp2-fcq3/GHSA-qxhm-3vp2-fcq3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxhm-3vp2-fcq3", + "modified": "2024-08-06T09:31:38Z", + "published": "2024-08-06T09:31:38Z", + "aliases": [ + "CVE-2024-41995" + ], + "details": "Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of MFPs and printers that contain JavaTM Platform, see the information provided by the vendor.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41995" + }, + { + "type": "WEB", + "url": "https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2024-000010" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN78728294" + }, + { + "type": "WEB", + "url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000010" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T07:15:46Z" + } +} \ No newline at end of file