diff --git a/advisories/github-reviewed/2022/12/GHSA-q6cq-m9gm-6q2f/GHSA-q6cq-m9gm-6q2f.json b/advisories/github-reviewed/2022/12/GHSA-q6cq-m9gm-6q2f/GHSA-q6cq-m9gm-6q2f.json index c1ec280fb2d..e0594850de2 100644 --- a/advisories/github-reviewed/2022/12/GHSA-q6cq-m9gm-6q2f/GHSA-q6cq-m9gm-6q2f.json +++ b/advisories/github-reviewed/2022/12/GHSA-q6cq-m9gm-6q2f/GHSA-q6cq-m9gm-6q2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q6cq-m9gm-6q2f", - "modified": "2023-01-09T08:22:04Z", + "modified": "2024-10-23T18:34:22Z", "published": "2022-12-25T06:30:20Z", "aliases": [ "CVE-2022-45197" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/poezio/slixmpp/tags" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/slixmpp/PYSEC-2022-43013.yaml" + }, { "type": "WEB", "url": "https://lab.louiz.org/poezio/slixmpp/-/commit/b60b1b985db928532f97c4f61d6fbc801f0aa7fa" diff --git a/advisories/unreviewed/2024/02/GHSA-8ghq-wfr9-j428/GHSA-8ghq-wfr9-j428.json b/advisories/unreviewed/2024/02/GHSA-8ghq-wfr9-j428/GHSA-8ghq-wfr9-j428.json index 5c04a39336b..e7a6f849440 100644 --- a/advisories/unreviewed/2024/02/GHSA-8ghq-wfr9-j428/GHSA-8ghq-wfr9-j428.json +++ b/advisories/unreviewed/2024/02/GHSA-8ghq-wfr9-j428/GHSA-8ghq-wfr9-j428.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8ghq-wfr9-j428", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-25225" ], "details": "A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pw88-xv3r-x8m2/GHSA-pw88-xv3r-x8m2.json b/advisories/unreviewed/2024/02/GHSA-pw88-xv3r-x8m2/GHSA-pw88-xv3r-x8m2.json index 62dc6f4369c..6c132973918 100644 --- a/advisories/unreviewed/2024/02/GHSA-pw88-xv3r-x8m2/GHSA-pw88-xv3r-x8m2.json +++ b/advisories/unreviewed/2024/02/GHSA-pw88-xv3r-x8m2/GHSA-pw88-xv3r-x8m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pw88-xv3r-x8m2", - "modified": "2024-02-14T18:30:25Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-25226" ], "details": "A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T15:15:09Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xrp5-mffj-h7gr/GHSA-xrp5-mffj-h7gr.json b/advisories/unreviewed/2024/09/GHSA-xrp5-mffj-h7gr/GHSA-xrp5-mffj-h7gr.json index 04ff09d4e71..cda1dba6e4d 100644 --- a/advisories/unreviewed/2024/09/GHSA-xrp5-mffj-h7gr/GHSA-xrp5-mffj-h7gr.json +++ b/advisories/unreviewed/2024/09/GHSA-xrp5-mffj-h7gr/GHSA-xrp5-mffj-h7gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrp5-mffj-h7gr", - "modified": "2024-09-07T12:30:43Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-09-07T12:30:43Z", "aliases": [ "CVE-2024-6010" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6010" }, + { + "type": "WEB", + "url": "https://docs.stylemixthemes.com/cost-calculator-builder/changelog-1/changelog-pro-version" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/trunk/frontend/dist/order.js" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3172590" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fc04e676-e394-488e-a239-95af5f865613?source=cve" diff --git a/advisories/unreviewed/2024/10/GHSA-253g-rphr-6h5j/GHSA-253g-rphr-6h5j.json b/advisories/unreviewed/2024/10/GHSA-253g-rphr-6h5j/GHSA-253g-rphr-6h5j.json new file mode 100644 index 00000000000..2e9d4c67dbc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-253g-rphr-6h5j/GHSA-253g-rphr-6h5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-253g-rphr-6h5j", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20472" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.\n\nThis vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20472" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sql-inj-LOYAFcfq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-25c8-p9xf-2v4m/GHSA-25c8-p9xf-2v4m.json b/advisories/unreviewed/2024/10/GHSA-25c8-p9xf-2v4m/GHSA-25c8-p9xf-2v4m.json index 2acc675617a..4cfc04960aa 100644 --- a/advisories/unreviewed/2024/10/GHSA-25c8-p9xf-2v4m/GHSA-25c8-p9xf-2v4m.json +++ b/advisories/unreviewed/2024/10/GHSA-25c8-p9xf-2v4m/GHSA-25c8-p9xf-2v4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25c8-p9xf-2v4m", - "modified": "2024-10-23T00:31:43Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-23T00:31:43Z", "aliases": [ "CVE-2024-31029" ], "details": "An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote attackers to cause a Denial of Service through specially crafted packets.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-27g3-cp2g-22pw/GHSA-27g3-cp2g-22pw.json b/advisories/unreviewed/2024/10/GHSA-27g3-cp2g-22pw/GHSA-27g3-cp2g-22pw.json new file mode 100644 index 00000000000..43d830ae1f4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-27g3-cp2g-22pw/GHSA-27g3-cp2g-22pw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27g3-cp2g-22pw", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20260" + ], + "details": "A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eventually cease all together.\n\nThis vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections on the virtual platforms. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted virtual platform. A successful exploit could allow the attacker to deplete system memory, resulting in a denial of service (DoS) condition. The memory could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20260" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftdvirtual-dos-MuenGnYR" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2jcv-f397-c9m8/GHSA-2jcv-f397-c9m8.json b/advisories/unreviewed/2024/10/GHSA-2jcv-f397-c9m8/GHSA-2jcv-f397-c9m8.json new file mode 100644 index 00000000000..7561482df08 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2jcv-f397-c9m8/GHSA-2jcv-f397-c9m8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jcv-f397-c9m8", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20402" + ], + "details": "A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.\n\n This vulnerability is due to a logic error in memory management when the device is handling SSL VPN connections. An attacker could exploit this vulnerability by sending crafted SSL/TLS packets to the SSL VPN server of the affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20402" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-dos-hOnB9pH4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-788" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2pcf-5mqc-gcgr/GHSA-2pcf-5mqc-gcgr.json b/advisories/unreviewed/2024/10/GHSA-2pcf-5mqc-gcgr/GHSA-2pcf-5mqc-gcgr.json index 84899eaac74..b6123e21fcf 100644 --- a/advisories/unreviewed/2024/10/GHSA-2pcf-5mqc-gcgr/GHSA-2pcf-5mqc-gcgr.json +++ b/advisories/unreviewed/2024/10/GHSA-2pcf-5mqc-gcgr/GHSA-2pcf-5mqc-gcgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pcf-5mqc-gcgr", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49858" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefistub/tpm: Use ACPI reclaim memory for event log to avoid corruption\n\nThe TPM event log table is a Linux specific construct, where the data\nproduced by the GetEventLog() boot service is cached in memory, and\npassed on to the OS using an EFI configuration table.\n\nThe use of EFI_LOADER_DATA here results in the region being left\nunreserved in the E820 memory map constructed by the EFI stub, and this\nis the memory description that is passed on to the incoming kernel by\nkexec, which is therefore unaware that the region should be reserved.\n\nEven though the utility of the TPM2 event log after a kexec is\nquestionable, any corruption might send the parsing code off into the\nweeds and crash the kernel. So let's use EFI_ACPI_RECLAIM_MEMORY\ninstead, which is always treated as reserved by the E820 conversion\nlogic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-32j9-8mq4-72ff/GHSA-32j9-8mq4-72ff.json b/advisories/unreviewed/2024/10/GHSA-32j9-8mq4-72ff/GHSA-32j9-8mq4-72ff.json index 564a5d08a03..60f68d820a5 100644 --- a/advisories/unreviewed/2024/10/GHSA-32j9-8mq4-72ff/GHSA-32j9-8mq4-72ff.json +++ b/advisories/unreviewed/2024/10/GHSA-32j9-8mq4-72ff/GHSA-32j9-8mq4-72ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-32j9-8mq4-72ff", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47733" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Delete subtree of 'fs/netfs' when netfs module exits\n\nIn netfs_init() or fscache_proc_init(), we create dentry under 'fs/netfs',\nbut in netfs_exit(), we only delete the proc entry of 'fs/netfs' without\ndeleting its subtree. This triggers the following WARNING:\n\n==================================================================\nremove_proc_entry: removing non-empty directory 'fs/netfs', leaking at least 'requests'\nWARNING: CPU: 4 PID: 566 at fs/proc/generic.c:717 remove_proc_entry+0x160/0x1c0\nModules linked in: netfs(-)\nCPU: 4 UID: 0 PID: 566 Comm: rmmod Not tainted 6.11.0-rc3 #860\nRIP: 0010:remove_proc_entry+0x160/0x1c0\nCall Trace:\n \n netfs_exit+0x12/0x620 [netfs]\n __do_sys_delete_module.isra.0+0x14c/0x2e0\n do_syscall_64+0x4b/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n==================================================================\n\nTherefore use remove_proc_subtree() instead of remove_proc_entry() to\nfix the above problem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-772" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-333m-q4jm-qjq4/GHSA-333m-q4jm-qjq4.json b/advisories/unreviewed/2024/10/GHSA-333m-q4jm-qjq4/GHSA-333m-q4jm-qjq4.json index b1176ddad2d..f252573657f 100644 --- a/advisories/unreviewed/2024/10/GHSA-333m-q4jm-qjq4/GHSA-333m-q4jm-qjq4.json +++ b/advisories/unreviewed/2024/10/GHSA-333m-q4jm-qjq4/GHSA-333m-q4jm-qjq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-333m-q4jm-qjq4", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49856" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/sgx: Fix deadlock in SGX NUMA node search\n\nWhen the current node doesn't have an EPC section configured by firmware\nand all other EPC sections are used up, CPU can get stuck inside the\nwhile loop that looks for an available EPC page from remote nodes\nindefinitely, leading to a soft lockup. Note how nid_of_current will\nnever be equal to nid in that while loop because nid_of_current is not\nset in sgx_numa_mask.\n\nAlso worth mentioning is that it's perfectly fine for the firmware not\nto setup an EPC section on a node. While setting up an EPC section on\neach node can enhance performance, it is not a requirement for\nfunctionality.\n\nRework the loop to start and end on *a* node that has SGX memory. This\navoids the deadlock looking for the current SGX-lacking node to show up\nin the loop when it never will.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3cwp-ww6r-f893/GHSA-3cwp-ww6r-f893.json b/advisories/unreviewed/2024/10/GHSA-3cwp-ww6r-f893/GHSA-3cwp-ww6r-f893.json new file mode 100644 index 00000000000..f4d624de37b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3cwp-ww6r-f893/GHSA-3cwp-ww6r-f893.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cwp-ww6r-f893", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49657" + ], + "details": "Missing Authorization vulnerability in ReneeCussack 3D Work In Progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49657" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/renee-work-in-progress/wordpress-3d-work-in-progress-plugin-1-0-3-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3j6m-cq99-v646/GHSA-3j6m-cq99-v646.json b/advisories/unreviewed/2024/10/GHSA-3j6m-cq99-v646/GHSA-3j6m-cq99-v646.json new file mode 100644 index 00000000000..938f5850cc6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3j6m-cq99-v646/GHSA-3j6m-cq99-v646.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j6m-cq99-v646", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20372" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20372" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3mhv-6x8q-5v9p/GHSA-3mhv-6x8q-5v9p.json b/advisories/unreviewed/2024/10/GHSA-3mhv-6x8q-5v9p/GHSA-3mhv-6x8q-5v9p.json new file mode 100644 index 00000000000..a4c0c934fa8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3mhv-6x8q-5v9p/GHSA-3mhv-6x8q-5v9p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mhv-6x8q-5v9p", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49676" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through 0.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49676" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-icons-for-elementor/wordpress-custom-icons-for-elementor-plugin-0-3-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3r4j-q266-j9h3/GHSA-3r4j-q266-j9h3.json b/advisories/unreviewed/2024/10/GHSA-3r4j-q266-j9h3/GHSA-3r4j-q266-j9h3.json new file mode 100644 index 00000000000..f1ce372bd6f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3r4j-q266-j9h3/GHSA-3r4j-q266-j9h3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r4j-q266-j9h3", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20471" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.\n\n This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20471" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sql-inj-LOYAFcfq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3wfx-mj93-vf8v/GHSA-3wfx-mj93-vf8v.json b/advisories/unreviewed/2024/10/GHSA-3wfx-mj93-vf8v/GHSA-3wfx-mj93-vf8v.json index d49e8282db4..0140ce9d82c 100644 --- a/advisories/unreviewed/2024/10/GHSA-3wfx-mj93-vf8v/GHSA-3wfx-mj93-vf8v.json +++ b/advisories/unreviewed/2024/10/GHSA-3wfx-mj93-vf8v/GHSA-3wfx-mj93-vf8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wfx-mj93-vf8v", - "modified": "2024-10-23T00:31:43Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-23T00:31:43Z", "aliases": [ "CVE-2024-10231" ], "details": "Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4378-qv4j-pgj4/GHSA-4378-qv4j-pgj4.json b/advisories/unreviewed/2024/10/GHSA-4378-qv4j-pgj4/GHSA-4378-qv4j-pgj4.json new file mode 100644 index 00000000000..c7df083dd18 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4378-qv4j-pgj4/GHSA-4378-qv4j-pgj4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4378-qv4j-pgj4", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20298" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20298" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-46qv-gx85-99hh/GHSA-46qv-gx85-99hh.json b/advisories/unreviewed/2024/10/GHSA-46qv-gx85-99hh/GHSA-46qv-gx85-99hh.json index 86ce83fde63..698051ceba7 100644 --- a/advisories/unreviewed/2024/10/GHSA-46qv-gx85-99hh/GHSA-46qv-gx85-99hh.json +++ b/advisories/unreviewed/2024/10/GHSA-46qv-gx85-99hh/GHSA-46qv-gx85-99hh.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-4947-vm3r-mmm2/GHSA-4947-vm3r-mmm2.json b/advisories/unreviewed/2024/10/GHSA-4947-vm3r-mmm2/GHSA-4947-vm3r-mmm2.json index c03d611a27d..27e982d15ff 100644 --- a/advisories/unreviewed/2024/10/GHSA-4947-vm3r-mmm2/GHSA-4947-vm3r-mmm2.json +++ b/advisories/unreviewed/2024/10/GHSA-4947-vm3r-mmm2/GHSA-4947-vm3r-mmm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4947-vm3r-mmm2", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49851" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Clean up TPM space after command failure\n\ntpm_dev_transmit prepares the TPM space before attempting command\ntransmission. However if the command fails no rollback of this\npreparation is done. This can result in transient handles being leaked\nif the device is subsequently closed with no further commands performed.\n\nFix this by flushing the space in the event of command transmission\nfailure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-459" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4jwf-2c3g-hqmj/GHSA-4jwf-2c3g-hqmj.json b/advisories/unreviewed/2024/10/GHSA-4jwf-2c3g-hqmj/GHSA-4jwf-2c3g-hqmj.json new file mode 100644 index 00000000000..9595bd061f9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4jwf-2c3g-hqmj/GHSA-4jwf-2c3g-hqmj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jwf-2c3g-hqmj", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20274" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document.\n\nThis vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitting malicious content to an affected device and using the device to generate a document that contains sensitive information. A successful exploit could allow the attacker to alter the standard layout of the device-generated documents, access arbitrary files from the underlying operating system, and conduct server-side request forgery (SSRF) attacks. To successfully exploit this vulnerability, an attacker would need valid credentials for a user account with policy-editing permissions, such as Network Admin, Intrusion Admin, or any custom user role with the same capabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20274" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-html-inj-nfJeYHxz" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4q8m-h8wc-99q6/GHSA-4q8m-h8wc-99q6.json b/advisories/unreviewed/2024/10/GHSA-4q8m-h8wc-99q6/GHSA-4q8m-h8wc-99q6.json new file mode 100644 index 00000000000..9726bef21d4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4q8m-h8wc-99q6/GHSA-4q8m-h8wc-99q6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q8m-h8wc-99q6", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20408" + ], + "details": "A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need valid remote access VPN user credentials on the affected device.\n\n This vulnerability is due to improper validation of data in HTTPS POST requests. An attacker could exploit this vulnerability by sending a crafted HTTPS POST request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20408" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dap-dos-bhEkP7n" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4qjx-wpr6-v7fg/GHSA-4qjx-wpr6-v7fg.json b/advisories/unreviewed/2024/10/GHSA-4qjx-wpr6-v7fg/GHSA-4qjx-wpr6-v7fg.json new file mode 100644 index 00000000000..62bc488b335 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4qjx-wpr6-v7fg/GHSA-4qjx-wpr6-v7fg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qjx-wpr6-v7fg", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49671" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix allows Upload a Web Shell to a Web Server.This issue affects AI Image Generator for Your Content & Featured Images – AI Postpix: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ai-postpix/wordpress-ai-postpix-plugin-1-1-8-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4qrp-r28g-j2vf/GHSA-4qrp-r28g-j2vf.json b/advisories/unreviewed/2024/10/GHSA-4qrp-r28g-j2vf/GHSA-4qrp-r28g-j2vf.json new file mode 100644 index 00000000000..541444696ba --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4qrp-r28g-j2vf/GHSA-4qrp-r28g-j2vf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qrp-r28g-j2vf", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20351" + ], + "details": "A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be dropped, resulting in a denial of service (DoS) condition.\n\nThis vulnerability is due to the improper handling of TCP/IP network traffic. An attacker could exploit this vulnerability by sending a large amount of TCP/IP network traffic through the affected device. A successful exploit could allow the attacker to cause the Cisco FTD device to drop network traffic, resulting in a DoS condition. The affected device must be rebooted to resolve the DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20351" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-xss-yjj7ZjVq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sa-ftd-snort-fw-BCJTZPMu" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-522v-vw33-wcv7/GHSA-522v-vw33-wcv7.json b/advisories/unreviewed/2024/10/GHSA-522v-vw33-wcv7/GHSA-522v-vw33-wcv7.json index 52508341845..5da97974a4b 100644 --- a/advisories/unreviewed/2024/10/GHSA-522v-vw33-wcv7/GHSA-522v-vw33-wcv7.json +++ b/advisories/unreviewed/2024/10/GHSA-522v-vw33-wcv7/GHSA-522v-vw33-wcv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-522v-vw33-wcv7", - "modified": "2024-10-21T12:30:54Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T12:30:54Z", "aliases": [ "CVE-2024-47678" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nicmp: change the order of rate limits\n\nICMP messages are ratelimited :\n\nAfter the blamed commits, the two rate limiters are applied in this order:\n\n1) host wide ratelimit (icmp_global_allow())\n\n2) Per destination ratelimit (inetpeer based)\n\nIn order to avoid side-channels attacks, we need to apply\nthe per destination check first.\n\nThis patch makes the following change :\n\n1) icmp_global_allow() checks if the host wide limit is reached.\n But credits are not yet consumed. This is deferred to 3)\n\n2) The per destination limit is checked/updated.\n This might add a new node in inetpeer tree.\n\n3) icmp_global_consume() consumes tokens if prior operations succeeded.\n\nThis means that host wide ratelimit is still effective\nin keeping inetpeer tree small even under DDOS.\n\nAs a bonus, I removed icmp_global.lock as the fast path\ncan use a lock-free operation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T12:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5j5v-66r8-4gm4/GHSA-5j5v-66r8-4gm4.json b/advisories/unreviewed/2024/10/GHSA-5j5v-66r8-4gm4/GHSA-5j5v-66r8-4gm4.json index 64a3937c9ce..34d4dfb1b61 100644 --- a/advisories/unreviewed/2024/10/GHSA-5j5v-66r8-4gm4/GHSA-5j5v-66r8-4gm4.json +++ b/advisories/unreviewed/2024/10/GHSA-5j5v-66r8-4gm4/GHSA-5j5v-66r8-4gm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5j5v-66r8-4gm4", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49862" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowercap: intel_rapl: Fix off by one in get_rpi()\n\nThe rp->priv->rpi array is either rpi_msr or rpi_tpmi which have\nNR_RAPL_PRIMITIVES number of elements. Thus the > needs to be >=\nto prevent an off by one access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-193" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5q5x-hwcj-q6c2/GHSA-5q5x-hwcj-q6c2.json b/advisories/unreviewed/2024/10/GHSA-5q5x-hwcj-q6c2/GHSA-5q5x-hwcj-q6c2.json new file mode 100644 index 00000000000..d9c47fd5a09 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5q5x-hwcj-q6c2/GHSA-5q5x-hwcj-q6c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q5x-hwcj-q6c2", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20495" + ], + "details": "A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to improper validation of client key data after the TLS session is established. An attacker could exploit this vulnerability by sending a crafted key value to an affected system over the secure TLS session. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20495" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-vpn-cZf8gT" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5w8m-6wwq-mm8m/GHSA-5w8m-6wwq-mm8m.json b/advisories/unreviewed/2024/10/GHSA-5w8m-6wwq-mm8m/GHSA-5w8m-6wwq-mm8m.json index 9d1c81c260e..d1c50dfb920 100644 --- a/advisories/unreviewed/2024/10/GHSA-5w8m-6wwq-mm8m/GHSA-5w8m-6wwq-mm8m.json +++ b/advisories/unreviewed/2024/10/GHSA-5w8m-6wwq-mm8m/GHSA-5w8m-6wwq-mm8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5w8m-6wwq-mm8m", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49852" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: elx: libefc: Fix potential use after free in efc_nport_vport_del()\n\nThe kref_put() function will call nport->release if the refcount drops to\nzero. The nport->release release function is _efc_nport_free() which frees\n\"nport\". But then we dereference \"nport\" on the next line which is a use\nafter free. Re-order these lines to avoid the use after free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5xm6-h565-q6mc/GHSA-5xm6-h565-q6mc.json b/advisories/unreviewed/2024/10/GHSA-5xm6-h565-q6mc/GHSA-5xm6-h565-q6mc.json new file mode 100644 index 00000000000..b0c69d0c48b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5xm6-h565-q6mc/GHSA-5xm6-h565-q6mc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xm6-h565-q6mc", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20329" + ], + "details": "A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root.\n\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI commands over SSH. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20329" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssh-rce-gRAuPEUF" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-146" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-67cp-gwr2-6w65/GHSA-67cp-gwr2-6w65.json b/advisories/unreviewed/2024/10/GHSA-67cp-gwr2-6w65/GHSA-67cp-gwr2-6w65.json new file mode 100644 index 00000000000..bc7fbffa7ff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-67cp-gwr2-6w65/GHSA-67cp-gwr2-6w65.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67cp-gwr2-6w65", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-10292" + ], + "details": "A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10292" + }, + { + "type": "WEB", + "url": "https://github.com/LvZCh/zzcms2023/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.427136" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6grm-m6x5-4cvx/GHSA-6grm-m6x5-4cvx.json b/advisories/unreviewed/2024/10/GHSA-6grm-m6x5-4cvx/GHSA-6grm-m6x5-4cvx.json new file mode 100644 index 00000000000..e8b339798b8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6grm-m6x5-4cvx/GHSA-6grm-m6x5-4cvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6grm-m6x5-4cvx", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20415" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20415" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6h6m-782c-4x8h/GHSA-6h6m-782c-4x8h.json b/advisories/unreviewed/2024/10/GHSA-6h6m-782c-4x8h/GHSA-6h6m-782c-4x8h.json index 792d3306792..73cddca741c 100644 --- a/advisories/unreviewed/2024/10/GHSA-6h6m-782c-4x8h/GHSA-6h6m-782c-4x8h.json +++ b/advisories/unreviewed/2024/10/GHSA-6h6m-782c-4x8h/GHSA-6h6m-782c-4x8h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6h6m-782c-4x8h", - "modified": "2024-10-23T00:31:45Z", + "modified": "2024-10-23T18:33:08Z", "published": "2024-10-23T00:31:45Z", "aliases": [ "CVE-2024-48415" ], "details": "itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6hr8-8x9g-vvm6/GHSA-6hr8-8x9g-vvm6.json b/advisories/unreviewed/2024/10/GHSA-6hr8-8x9g-vvm6/GHSA-6hr8-8x9g-vvm6.json index 35d26ee18db..09688abab28 100644 --- a/advisories/unreviewed/2024/10/GHSA-6hr8-8x9g-vvm6/GHSA-6hr8-8x9g-vvm6.json +++ b/advisories/unreviewed/2024/10/GHSA-6hr8-8x9g-vvm6/GHSA-6hr8-8x9g-vvm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hr8-8x9g-vvm6", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47737" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: call cache_put if xdr_reserve_space returns NULL\n\nIf not enough buffer space available, but idmap_lookup has triggered\nlookup_fn which calls cache_get and returns successfully. Then we\nmissed to call cache_put here which pairs with cache_get.\n\nReviwed-by: Jeff Layton ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6vh9-9qf6-mvjj/GHSA-6vh9-9qf6-mvjj.json b/advisories/unreviewed/2024/10/GHSA-6vh9-9qf6-mvjj/GHSA-6vh9-9qf6-mvjj.json new file mode 100644 index 00000000000..a131776034c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6vh9-9qf6-mvjj/GHSA-6vh9-9qf6-mvjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vh9-9qf6-mvjj", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20407" + ], + "details": "A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. Devices that are configured with Snort 2 are not affected by this vulnerability. \n\n This vulnerability is due to a logic error when handling embryonic (half-open) TCP connections. An attacker could exploit this vulnerability by sending a crafted traffic pattern through an affected device. A successful exploit could allow unintended traffic to enter the network protected by the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20407" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-bypass-PTry37fX" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-753j-68h2-88xf/GHSA-753j-68h2-88xf.json b/advisories/unreviewed/2024/10/GHSA-753j-68h2-88xf/GHSA-753j-68h2-88xf.json index 1203c84940d..4b5f86bee96 100644 --- a/advisories/unreviewed/2024/10/GHSA-753j-68h2-88xf/GHSA-753j-68h2-88xf.json +++ b/advisories/unreviewed/2024/10/GHSA-753j-68h2-88xf/GHSA-753j-68h2-88xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-753j-68h2-88xf", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47659" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: tcp: ipv4, fix incorrect labeling\n\nCurrently, Smack mirrors the label of incoming tcp/ipv4 connections:\nwhen a label 'foo' connects to a label 'bar' with tcp/ipv4,\n'foo' always gets 'foo' in returned ipv4 packets. So,\n1) returned packets are incorrectly labeled ('foo' instead of 'bar')\n2) 'bar' can write to 'foo' without being authorized to write.\n\nHere is a scenario how to see this:\n\n* Take two machines, let's call them C and S,\n with active Smack in the default state\n (no settings, no rules, no labeled hosts, only builtin labels)\n\n* At S, add Smack rule 'foo bar w'\n (labels 'foo' and 'bar' are instantiated at S at this moment)\n\n* At S, at label 'bar', launch a program\n that listens for incoming tcp/ipv4 connections\n\n* From C, at label 'foo', connect to the listener at S.\n (label 'foo' is instantiated at C at this moment)\n Connection succeedes and works.\n\n* Send some data in both directions.\n* Collect network traffic of this connection.\n\nAll packets in both directions are labeled with the CIPSO\nof the label 'foo'. Hence, label 'bar' writes to 'foo' without\nbeing authorized, and even without ever being known at C.\n\nIf anybody cares: exactly the same happens with DCCP.\n\nThis behavior 1st manifested in release 2.6.29.4 (see Fixes below)\nand it looks unintentional. At least, no explanation was provided.\n\nI changed returned packes label into the 'bar',\nto bring it into line with the Smack documentation claims.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T14:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7874-r67m-25qh/GHSA-7874-r67m-25qh.json b/advisories/unreviewed/2024/10/GHSA-7874-r67m-25qh/GHSA-7874-r67m-25qh.json new file mode 100644 index 00000000000..745684197d9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7874-r67m-25qh/GHSA-7874-r67m-25qh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7874-r67m-25qh", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20339" + ], + "details": "A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThis vulnerability is due to an issue that occurs when TLS traffic is processed. An attacker could exploit this vulnerability by sending certain TLS traffic over IPv4 through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition and impacting traffic to and through the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20339" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls-dos-QXYE5Ufy" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7hrq-m3jx-vxhp/GHSA-7hrq-m3jx-vxhp.json b/advisories/unreviewed/2024/10/GHSA-7hrq-m3jx-vxhp/GHSA-7hrq-m3jx-vxhp.json new file mode 100644 index 00000000000..c1b6572e0b9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7hrq-m3jx-vxhp/GHSA-7hrq-m3jx-vxhp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hrq-m3jx-vxhp", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-10297" + ], + "details": "A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/changeimage.php of the component Managecard Edit Image Page. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10297" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281564" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281564" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7hw4-fm5w-rcv6/GHSA-7hw4-fm5w-rcv6.json b/advisories/unreviewed/2024/10/GHSA-7hw4-fm5w-rcv6/GHSA-7hw4-fm5w-rcv6.json index 6a5bb4b7954..ef0dd44a5ae 100644 --- a/advisories/unreviewed/2024/10/GHSA-7hw4-fm5w-rcv6/GHSA-7hw4-fm5w-rcv6.json +++ b/advisories/unreviewed/2024/10/GHSA-7hw4-fm5w-rcv6/GHSA-7hw4-fm5w-rcv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hw4-fm5w-rcv6", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-47748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost_vdpa: assign irq bypass producer token correctly\n\nWe used to call irq_bypass_unregister_producer() in\nvhost_vdpa_setup_vq_irq() which is problematic as we don't know if the\ntoken pointer is still valid or not.\n\nActually, we use the eventfd_ctx as the token so the life cycle of the\ntoken should be bound to the VHOST_SET_VRING_CALL instead of\nvhost_vdpa_setup_vq_irq() which could be called by set_status().\n\nFixing this by setting up irq bypass producer's token when handling\nVHOST_SET_VRING_CALL and un-registering the producer before calling\nvhost_vring_ioctl() to prevent a possible use after free as eventfd\ncould have been released in vhost_vring_ioctl(). And such registering\nand unregistering will only be done if DRIVER_OK is set.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-83hg-vhh4-2hfh/GHSA-83hg-vhh4-2hfh.json b/advisories/unreviewed/2024/10/GHSA-83hg-vhh4-2hfh/GHSA-83hg-vhh4-2hfh.json new file mode 100644 index 00000000000..3b311d4b4cb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-83hg-vhh4-2hfh/GHSA-83hg-vhh4-2hfh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83hg-vhh4-2hfh", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20431" + ], + "details": "A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy.\n\n This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending traffic through an affected device. A successful exploit could allow the attacker to bypass a geolocation-based access control policy and successfully send traffic to a protected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20431" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-geoip-bypass-MB4zRDu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-229" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8478-wgh8-m8mf/GHSA-8478-wgh8-m8mf.json b/advisories/unreviewed/2024/10/GHSA-8478-wgh8-m8mf/GHSA-8478-wgh8-m8mf.json index 0294d78f4a6..11fa84de384 100644 --- a/advisories/unreviewed/2024/10/GHSA-8478-wgh8-m8mf/GHSA-8478-wgh8-m8mf.json +++ b/advisories/unreviewed/2024/10/GHSA-8478-wgh8-m8mf/GHSA-8478-wgh8-m8mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8478-wgh8-m8mf", - "modified": "2024-10-21T12:30:55Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T12:30:55Z", "aliases": [ "CVE-2024-47688" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: Fix a potential null-ptr-deref in module_add_driver()\n\nInject fault while probing of-fpga-region, if kasprintf() fails in\nmodule_add_driver(), the second sysfs_remove_link() in exit path will cause\nnull-ptr-deref as below because kernfs_name_hash() will call strlen() with\nNULL driver_name.\n\nFix it by releasing resources based on the exit path sequence.\n\n\t KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n\t Mem abort info:\n\t ESR = 0x0000000096000005\n\t EC = 0x25: DABT (current EL), IL = 32 bits\n\t SET = 0, FnV = 0\n\t EA = 0, S1PTW = 0\n\t FSC = 0x05: level 1 translation fault\n\t Data abort info:\n\t ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000\n\t CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n\t GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n\t [dfffffc000000000] address between user and kernel address ranges\n\t Internal error: Oops: 0000000096000005 [#1] PREEMPT SMP\n\t Dumping ftrace buffer:\n\t (ftrace buffer empty)\n\t Modules linked in: of_fpga_region(+) fpga_region fpga_bridge cfg80211 rfkill 8021q garp mrp stp llc ipv6 [last unloaded: of_fpga_region]\n\t CPU: 2 UID: 0 PID: 2036 Comm: modprobe Not tainted 6.11.0-rc2-g6a0e38264012 #295\n\t Hardware name: linux,dummy-virt (DT)\n\t pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n\t pc : strlen+0x24/0xb0\n\t lr : kernfs_name_hash+0x1c/0xc4\n\t sp : ffffffc081f97380\n\t x29: ffffffc081f97380 x28: ffffffc081f97b90 x27: ffffff80c821c2a0\n\t x26: ffffffedac0be418 x25: 0000000000000000 x24: ffffff80c09d2000\n\t x23: 0000000000000000 x22: 0000000000000000 x21: 0000000000000000\n\t x20: 0000000000000000 x19: 0000000000000000 x18: 0000000000001840\n\t x17: 0000000000000000 x16: 0000000000000000 x15: 1ffffff8103f2e42\n\t x14: 00000000f1f1f1f1 x13: 0000000000000004 x12: ffffffb01812d61d\n\t x11: 1ffffff01812d61c x10: ffffffb01812d61c x9 : dfffffc000000000\n\t x8 : 0000004fe7ed29e4 x7 : ffffff80c096b0e7 x6 : 0000000000000001\n\t x5 : ffffff80c096b0e0 x4 : 1ffffffdb990efa2 x3 : 0000000000000000\n\t x2 : 0000000000000000 x1 : dfffffc000000000 x0 : 0000000000000000\n\t Call trace:\n\t strlen+0x24/0xb0\n\t kernfs_name_hash+0x1c/0xc4\n\t kernfs_find_ns+0x118/0x2e8\n\t kernfs_remove_by_name_ns+0x80/0x100\n\t sysfs_remove_link+0x74/0xa8\n\t module_add_driver+0x278/0x394\n\t bus_add_driver+0x1f0/0x43c\n\t driver_register+0xf4/0x3c0\n\t __platform_driver_register+0x60/0x88\n\t of_fpga_region_init+0x20/0x1000 [of_fpga_region]\n\t do_one_initcall+0x110/0x788\n\t do_init_module+0x1dc/0x5c8\n\t load_module+0x3c38/0x4cac\n\t init_module_from_file+0xd4/0x128\n\t idempotent_init_module+0x2cc/0x528\n\t __arm64_sys_finit_module+0xac/0x100\n\t invoke_syscall+0x6c/0x258\n\t el0_svc_common.constprop.0+0x160/0x22c\n\t do_el0_svc+0x44/0x5c\n\t el0_svc+0x48/0xb8\n\t el0t_64_sync_handler+0x13c/0x158\n\t el0t_64_sync+0x190/0x194\n\t Code: f2fbffe1 a90157f4 12000802 aa0003f5 (38e16861)\n\t ---[ end trace 0000000000000000 ]---\n\t Kernel panic - not syncing: Oops: Fatal exception", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T12:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-89mf-4cg3-w93v/GHSA-89mf-4cg3-w93v.json b/advisories/unreviewed/2024/10/GHSA-89mf-4cg3-w93v/GHSA-89mf-4cg3-w93v.json index 5540fa4f898..9758243c928 100644 --- a/advisories/unreviewed/2024/10/GHSA-89mf-4cg3-w93v/GHSA-89mf-4cg3-w93v.json +++ b/advisories/unreviewed/2024/10/GHSA-89mf-4cg3-w93v/GHSA-89mf-4cg3-w93v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89mf-4cg3-w93v", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47666" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm80xx: Set phy->enable_completion only when we wait for it\n\npm8001_phy_control() populates the enable_completion pointer with a stack\naddress, sends a PHY_LINK_RESET / PHY_HARD_RESET, waits 300 ms, and\nreturns. The problem arises when a phy control response comes late. After\n300 ms the pm8001_phy_control() function returns and the passed\nenable_completion stack address is no longer valid. Late phy control\nresponse invokes complete() on a dangling enable_completion pointer which\nleads to a kernel crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8c5w-3324-r69p/GHSA-8c5w-3324-r69p.json b/advisories/unreviewed/2024/10/GHSA-8c5w-3324-r69p/GHSA-8c5w-3324-r69p.json index cd6e86ce13e..0b484e09cb2 100644 --- a/advisories/unreviewed/2024/10/GHSA-8c5w-3324-r69p/GHSA-8c5w-3324-r69p.json +++ b/advisories/unreviewed/2024/10/GHSA-8c5w-3324-r69p/GHSA-8c5w-3324-r69p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c5w-3324-r69p", - "modified": "2024-10-23T00:31:44Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-23T00:31:44Z", "aliases": [ "CVE-2024-44812" ], "details": "SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8j6j-jm5x-gjfx/GHSA-8j6j-jm5x-gjfx.json b/advisories/unreviewed/2024/10/GHSA-8j6j-jm5x-gjfx/GHSA-8j6j-jm5x-gjfx.json new file mode 100644 index 00000000000..0233cf92d39 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8j6j-jm5x-gjfx/GHSA-8j6j-jm5x-gjfx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j6j-jm5x-gjfx", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20273" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20273" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8pv3-xhwv-wgg4/GHSA-8pv3-xhwv-wgg4.json b/advisories/unreviewed/2024/10/GHSA-8pv3-xhwv-wgg4/GHSA-8pv3-xhwv-wgg4.json new file mode 100644 index 00000000000..c16d8f73a2c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8pv3-xhwv-wgg4/GHSA-8pv3-xhwv-wgg4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pv3-xhwv-wgg4", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20269" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20269" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8qj8-qf9j-579x/GHSA-8qj8-qf9j-579x.json b/advisories/unreviewed/2024/10/GHSA-8qj8-qf9j-579x/GHSA-8qj8-qf9j-579x.json index 8027007abf1..3d337121cd3 100644 --- a/advisories/unreviewed/2024/10/GHSA-8qj8-qf9j-579x/GHSA-8qj8-qf9j-579x.json +++ b/advisories/unreviewed/2024/10/GHSA-8qj8-qf9j-579x/GHSA-8qj8-qf9j-579x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qj8-qf9j-579x", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49854" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix uaf for accessing waker_bfqq after splitting\n\nAfter commit 42c306ed7233 (\"block, bfq: don't break merge chain in\nbfq_split_bfqq()\"), if the current procress is the last holder of bfqq,\nthe bfqq can be freed after bfq_split_bfqq(). Hence recored the bfqq and\nthen access bfqq->waker_bfqq may trigger UAF. What's more, the waker_bfqq\nmay in the merge chain of bfqq, hence just recored waker_bfqq is still\nnot safe.\n\nFix the problem by adding a helper bfq_waker_bfqq() to check if\nbfqq->waker_bfqq is in the merge chain, and current procress is the only\nholder.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8vhw-wjxq-h782/GHSA-8vhw-wjxq-h782.json b/advisories/unreviewed/2024/10/GHSA-8vhw-wjxq-h782/GHSA-8vhw-wjxq-h782.json new file mode 100644 index 00000000000..fc3dfe26ccc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8vhw-wjxq-h782/GHSA-8vhw-wjxq-h782.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vhw-wjxq-h782", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20377" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\n\n This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker could exploit this vulnerability by by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20377" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-infodisc-RL4mJFer" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9298-29xj-7998/GHSA-9298-29xj-7998.json b/advisories/unreviewed/2024/10/GHSA-9298-29xj-7998/GHSA-9298-29xj-7998.json index e92537c1b96..ee62619607b 100644 --- a/advisories/unreviewed/2024/10/GHSA-9298-29xj-7998/GHSA-9298-29xj-7998.json +++ b/advisories/unreviewed/2024/10/GHSA-9298-29xj-7998/GHSA-9298-29xj-7998.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9298-29xj-7998", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47731" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/perf: Fix ali_drw_pmu driver interrupt status clearing\n\nThe alibaba_uncore_pmu driver forgot to clear all interrupt status\nin the interrupt processing function. After the PMU counter overflow\ninterrupt occurred, an interrupt storm occurred, causing the system\nto hang.\n\nTherefore, clear the correct interrupt status in the interrupt handling\nfunction to fix it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-459" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9688-r3h2-vvjq/GHSA-9688-r3h2-vvjq.json b/advisories/unreviewed/2024/10/GHSA-9688-r3h2-vvjq/GHSA-9688-r3h2-vvjq.json new file mode 100644 index 00000000000..4bb23df78ef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9688-r3h2-vvjq/GHSA-9688-r3h2-vvjq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9688-r3h2-vvjq", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20424" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root.\n\n This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20424" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9jfw-gm57-mv43/GHSA-9jfw-gm57-mv43.json b/advisories/unreviewed/2024/10/GHSA-9jfw-gm57-mv43/GHSA-9jfw-gm57-mv43.json index e3514d369e0..f83e5159216 100644 --- a/advisories/unreviewed/2024/10/GHSA-9jfw-gm57-mv43/GHSA-9jfw-gm57-mv43.json +++ b/advisories/unreviewed/2024/10/GHSA-9jfw-gm57-mv43/GHSA-9jfw-gm57-mv43.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jfw-gm57-mv43", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47667" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)\n\nErrata #i2037 in AM65x/DRA80xM Processors Silicon Revision 1.0\n(SPRZ452D_July 2018_Revised December 2019 [1]) mentions when an\ninbound PCIe TLP spans more than two internal AXI 128-byte bursts,\nthe bus may corrupt the packet payload and the corrupt data may\ncause associated applications or the processor to hang.\n\nThe workaround for Errata #i2037 is to limit the maximum read\nrequest size and maximum payload size to 128 bytes. Add workaround\nfor Errata #i2037 here.\n\nThe errata and workaround is applicable only to AM65x SR 1.0 and\nlater versions of the silicon will have this fixed.\n\n[1] -> https://www.ti.com/lit/er/sprz452i/sprz452i.pdf", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9pg5-823w-rm94/GHSA-9pg5-823w-rm94.json b/advisories/unreviewed/2024/10/GHSA-9pg5-823w-rm94/GHSA-9pg5-823w-rm94.json index b1e34645f70..6641ee6743f 100644 --- a/advisories/unreviewed/2024/10/GHSA-9pg5-823w-rm94/GHSA-9pg5-823w-rm94.json +++ b/advisories/unreviewed/2024/10/GHSA-9pg5-823w-rm94/GHSA-9pg5-823w-rm94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9pg5-823w-rm94", - "modified": "2024-10-23T00:31:46Z", + "modified": "2024-10-23T18:33:08Z", "published": "2024-10-23T00:31:46Z", "aliases": [ "CVE-2024-48657" ], "details": "SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9pj9-8qr7-5x38/GHSA-9pj9-8qr7-5x38.json b/advisories/unreviewed/2024/10/GHSA-9pj9-8qr7-5x38/GHSA-9pj9-8qr7-5x38.json new file mode 100644 index 00000000000..6b70e3ff610 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9pj9-8qr7-5x38/GHSA-9pj9-8qr7-5x38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pj9-8qr7-5x38", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20426" + ], + "details": "A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted IKEv2 traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20426" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2-dos-9FgEyHsF" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9w63-8337-3g35/GHSA-9w63-8337-3g35.json b/advisories/unreviewed/2024/10/GHSA-9w63-8337-3g35/GHSA-9w63-8337-3g35.json index d055277e0d3..11204a762d3 100644 --- a/advisories/unreviewed/2024/10/GHSA-9w63-8337-3g35/GHSA-9w63-8337-3g35.json +++ b/advisories/unreviewed/2024/10/GHSA-9w63-8337-3g35/GHSA-9w63-8337-3g35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w63-8337-3g35", - "modified": "2024-10-23T00:31:45Z", + "modified": "2024-10-23T18:33:08Z", "published": "2024-10-23T00:31:45Z", "aliases": [ "CVE-2024-48656" ], "details": "Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c5qg-9fv2-7vcj/GHSA-c5qg-9fv2-7vcj.json b/advisories/unreviewed/2024/10/GHSA-c5qg-9fv2-7vcj/GHSA-c5qg-9fv2-7vcj.json new file mode 100644 index 00000000000..c876888b10f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c5qg-9fv2-7vcj/GHSA-c5qg-9fv2-7vcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5qg-9fv2-7vcj", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49684" + ], + "details": "Deserialization of Untrusted Data vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49684" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-time-capsule/wordpress-backup-and-staging-by-wp-time-capsule-plugin-1-22-21-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c5xm-9r44-7w3j/GHSA-c5xm-9r44-7w3j.json b/advisories/unreviewed/2024/10/GHSA-c5xm-9r44-7w3j/GHSA-c5xm-9r44-7w3j.json index 4e1cd803a19..e8a68c57bd7 100644 --- a/advisories/unreviewed/2024/10/GHSA-c5xm-9r44-7w3j/GHSA-c5xm-9r44-7w3j.json +++ b/advisories/unreviewed/2024/10/GHSA-c5xm-9r44-7w3j/GHSA-c5xm-9r44-7w3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5xm-9r44-7w3j", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47739" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npadata: use integer wrap around to prevent deadlock on seq_nr overflow\n\nWhen submitting more than 2^32 padata objects to padata_do_serial, the\ncurrent sorting implementation incorrectly sorts padata objects with\noverflowed seq_nr, causing them to be placed before existing objects in\nthe reorder list. This leads to a deadlock in the serialization process\nas padata_find_next cannot match padata->seq_nr and pd->processed\nbecause the padata instance with overflowed seq_nr will be selected\nnext.\n\nTo fix this, we use an unsigned integer wrap around to correctly sort\npadata objects in scenarios with integer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-ccgr-xwcc-r26p/GHSA-ccgr-xwcc-r26p.json b/advisories/unreviewed/2024/10/GHSA-ccgr-xwcc-r26p/GHSA-ccgr-xwcc-r26p.json index 8c4a426d6a1..ecdad1379cc 100644 --- a/advisories/unreviewed/2024/10/GHSA-ccgr-xwcc-r26p/GHSA-ccgr-xwcc-r26p.json +++ b/advisories/unreviewed/2024/10/GHSA-ccgr-xwcc-r26p/GHSA-ccgr-xwcc-r26p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccgr-xwcc-r26p", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47660" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: clear PARENT_WATCHED flags lazily\n\nIn some setups directories can have many (usually negative) dentries.\nHence __fsnotify_update_child_dentry_flags() function can take a\nsignificant amount of time. Since the bulk of this function happens\nunder inode->i_lock this causes a significant contention on the lock\nwhen we remove the watch from the directory as the\n__fsnotify_update_child_dentry_flags() call from fsnotify_recalc_mask()\nraces with __fsnotify_update_child_dentry_flags() calls from\n__fsnotify_parent() happening on children. This can lead upto softlockup\nreports reported by users.\n\nFix the problem by calling fsnotify_update_children_dentry_flags() to\nset PARENT_WATCHED flags only when parent starts watching children.\n\nWhen parent stops watching children, clear false positive PARENT_WATCHED\nflags lazily in __fsnotify_parent() for each accessed child.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T14:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cp3f-3wc5-j85w/GHSA-cp3f-3wc5-j85w.json b/advisories/unreviewed/2024/10/GHSA-cp3f-3wc5-j85w/GHSA-cp3f-3wc5-j85w.json new file mode 100644 index 00000000000..7f158c8ba6d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cp3f-3wc5-j85w/GHSA-cp3f-3wc5-j85w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp3f-3wc5-j85w", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20481" + ], + "details": "A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service.\n\n This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected.\n\n Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20481" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-772" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cqv2-qp3h-xq97/GHSA-cqv2-qp3h-xq97.json b/advisories/unreviewed/2024/10/GHSA-cqv2-qp3h-xq97/GHSA-cqv2-qp3h-xq97.json new file mode 100644 index 00000000000..5c074065c8b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cqv2-qp3h-xq97/GHSA-cqv2-qp3h-xq97.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqv2-qp3h-xq97", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20370" + ], + "details": "A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate their administrative privileges to root. The attacker would need valid administrative credentials on the device to exploit this vulnerability. This vulnerability exists because certain system configurations and executable files have insecure storage and permissions. An attacker could exploit this vulnerability by authenticating on the device and then performing a series of steps that includes downloading malicious system files and accessing the Cisco FXOS CLI to configure the attack. A successful exploit could allow the attacker to obtain root access on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20370" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-priv-esc-hBS9gnwq" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cr59-3vcq-rrw6/GHSA-cr59-3vcq-rrw6.json b/advisories/unreviewed/2024/10/GHSA-cr59-3vcq-rrw6/GHSA-cr59-3vcq-rrw6.json index 3bdcb5df22c..8e3d4e0ca58 100644 --- a/advisories/unreviewed/2024/10/GHSA-cr59-3vcq-rrw6/GHSA-cr59-3vcq-rrw6.json +++ b/advisories/unreviewed/2024/10/GHSA-cr59-3vcq-rrw6/GHSA-cr59-3vcq-rrw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cr59-3vcq-rrw6", - "modified": "2024-10-23T00:31:43Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-23T00:31:43Z", "aliases": [ "CVE-2024-40493" ], "details": "Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes `coap_msg_get_payload(resp)` to return a null pointer, which is then dereferenced in a call to `memcpy`.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f2r7-4vx7-p4cw/GHSA-f2r7-4vx7-p4cw.json b/advisories/unreviewed/2024/10/GHSA-f2r7-4vx7-p4cw/GHSA-f2r7-4vx7-p4cw.json index d65dee7737f..121bc995eca 100644 --- a/advisories/unreviewed/2024/10/GHSA-f2r7-4vx7-p4cw/GHSA-f2r7-4vx7-p4cw.json +++ b/advisories/unreviewed/2024/10/GHSA-f2r7-4vx7-p4cw/GHSA-f2r7-4vx7-p4cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2r7-4vx7-p4cw", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47663" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: iio: frequency: ad9834: Validate frequency parameter value\n\nIn ad9834_write_frequency() clk_get_rate() can return 0. In such case\nad9834_calc_freqreg() call will lead to division by zero. Checking\n'if (fout > (clk_freq / 2))' doesn't protect in case of 'fout' is 0.\nad9834_write_frequency() is called from ad9834_write(), where fout is\ntaken from text buffer, which can contain any value.\n\nModify parameters checking.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f5h4-685p-r266/GHSA-f5h4-685p-r266.json b/advisories/unreviewed/2024/10/GHSA-f5h4-685p-r266/GHSA-f5h4-685p-r266.json index b69fe69a426..d93fc8da0f7 100644 --- a/advisories/unreviewed/2024/10/GHSA-f5h4-685p-r266/GHSA-f5h4-685p-r266.json +++ b/advisories/unreviewed/2024/10/GHSA-f5h4-685p-r266/GHSA-f5h4-685p-r266.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5h4-685p-r266", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47730" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - inject error before stopping queue\n\nThe master ooo cannot be completely closed when the\naccelerator core reports memory error. Therefore, the driver\nneeds to inject the qm error to close the master ooo. Currently,\nthe qm error is injected after stopping queue, memory may be\nreleased immediately after stopping queue, causing the device to\naccess the released memory. Therefore, error is injected to close master\nooo before stopping queue to ensure that the device does not access\nthe released memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f5rp-4vg3-xcrx/GHSA-f5rp-4vg3-xcrx.json b/advisories/unreviewed/2024/10/GHSA-f5rp-4vg3-xcrx/GHSA-f5rp-4vg3-xcrx.json new file mode 100644 index 00000000000..bb06bc54215 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f5rp-4vg3-xcrx/GHSA-f5rp-4vg3-xcrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5rp-4vg3-xcrx", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20474" + ], + "details": "A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client.\n\n This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software.\n\n Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20474" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csc-dos-XvPhM3bj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f7qm-mcg6-fhvg/GHSA-f7qm-mcg6-fhvg.json b/advisories/unreviewed/2024/10/GHSA-f7qm-mcg6-fhvg/GHSA-f7qm-mcg6-fhvg.json new file mode 100644 index 00000000000..03c6a471a6e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f7qm-mcg6-fhvg/GHSA-f7qm-mcg6-fhvg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7qm-mcg6-fhvg", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20299" + ], + "details": "A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due to a logic error in populating group ACLs when an AnyConnect client establishes a new session toward an affected device. An attacker could exploit this vulnerability by establishing an AnyConnect connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20299" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-acl-bypass-VvnLNKqf" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json b/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json new file mode 100644 index 00000000000..d60e170cac4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f928-7mj9-m8wx", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20341" + ], + "details": "A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper validation of user-supplied input to application endpoints. An attacker could exploit this vulnerability by persuading a user to follow a link designed to submit malicious input to the affected application. A successful exploit could allow the attacker to execute arbitrary HTML or script code in the browser in the context of the web services page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20341" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-xss-yjj7ZjVq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-yjj7ZjVq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fqcq-8xcg-f9hh/GHSA-fqcq-8xcg-f9hh.json b/advisories/unreviewed/2024/10/GHSA-fqcq-8xcg-f9hh/GHSA-fqcq-8xcg-f9hh.json new file mode 100644 index 00000000000..b5f2c27b7fb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fqcq-8xcg-f9hh/GHSA-fqcq-8xcg-f9hh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqcq-8xcg-f9hh", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20410" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20410" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g83r-p76f-vcgv/GHSA-g83r-p76f-vcgv.json b/advisories/unreviewed/2024/10/GHSA-g83r-p76f-vcgv/GHSA-g83r-p76f-vcgv.json new file mode 100644 index 00000000000..530e9e37df4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g83r-p76f-vcgv/GHSA-g83r-p76f-vcgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g83r-p76f-vcgv", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49653" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in James Eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49653" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/portfolleo/wordpress-portfolleo-plugin-1-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gmcr-26hv-76c3/GHSA-gmcr-26hv-76c3.json b/advisories/unreviewed/2024/10/GHSA-gmcr-26hv-76c3/GHSA-gmcr-26hv-76c3.json index 28eee646209..41f95f28002 100644 --- a/advisories/unreviewed/2024/10/GHSA-gmcr-26hv-76c3/GHSA-gmcr-26hv-76c3.json +++ b/advisories/unreviewed/2024/10/GHSA-gmcr-26hv-76c3/GHSA-gmcr-26hv-76c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmcr-26hv-76c3", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47732" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: iaa - Fix potential use after free bug\n\nThe free_device_compression_mode(iaa_device, device_mode) function frees\n\"device_mode\" but it iss passed to iaa_compression_modes[i]->free() a few\nlines later resulting in a use after free.\n\nThe good news is that, so far as I can tell, nothing implements the\n->free() function and the use after free happens in dead code. But, with\nthis fix, when something does implement it, we'll be ready. :)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-grr9-pcqm-fmr6/GHSA-grr9-pcqm-fmr6.json b/advisories/unreviewed/2024/10/GHSA-grr9-pcqm-fmr6/GHSA-grr9-pcqm-fmr6.json index 1cf5f78d5ad..360bbbdda1d 100644 --- a/advisories/unreviewed/2024/10/GHSA-grr9-pcqm-fmr6/GHSA-grr9-pcqm-fmr6.json +++ b/advisories/unreviewed/2024/10/GHSA-grr9-pcqm-fmr6/GHSA-grr9-pcqm-fmr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grr9-pcqm-fmr6", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-47751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: kirin: Fix buffer overflow in kirin_pcie_parse_port()\n\nWithin kirin_pcie_parse_port(), the pcie->num_slots is compared to\npcie->gpio_id_reset size (MAX_PCI_SLOTS) which is correct and would lead\nto an overflow.\n\nThus, fix condition to pcie->num_slots + 1 >= MAX_PCI_SLOTS and move\npcie->num_slots increment below the if-statement to avoid out-of-bounds\narray access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[kwilczynski: commit log]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gvjq-f8m6-m457/GHSA-gvjq-f8m6-m457.json b/advisories/unreviewed/2024/10/GHSA-gvjq-f8m6-m457/GHSA-gvjq-f8m6-m457.json new file mode 100644 index 00000000000..2ccfcd80bfe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gvjq-f8m6-m457/GHSA-gvjq-f8m6-m457.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvjq-f8m6-m457", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20268" + ], + "details": "A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device.\n\nThis vulnerability is due to insufficient input validation of SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device using IPv4 or IPv6. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability affects all versions of SNMP (versions 1, 2c, and 3) and requires a valid SNMP community string or valid SNMPv3 user credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20268" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-snmp-dos-7TcnzxTU" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-231" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gxcq-9p33-rq8f/GHSA-gxcq-9p33-rq8f.json b/advisories/unreviewed/2024/10/GHSA-gxcq-9p33-rq8f/GHSA-gxcq-9p33-rq8f.json new file mode 100644 index 00000000000..78528201faa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gxcq-9p33-rq8f/GHSA-gxcq-9p33-rq8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxcq-9p33-rq8f", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20403" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20403" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h53j-2x3f-48pf/GHSA-h53j-2x3f-48pf.json b/advisories/unreviewed/2024/10/GHSA-h53j-2x3f-48pf/GHSA-h53j-2x3f-48pf.json new file mode 100644 index 00000000000..c8683b426cf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h53j-2x3f-48pf/GHSA-h53j-2x3f-48pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h53j-2x3f-48pf", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49701" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse Mags.This issue affects Mags: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49701" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mags/wordpress-mags-theme-1-1-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h68c-jggg-j49q/GHSA-h68c-jggg-j49q.json b/advisories/unreviewed/2024/10/GHSA-h68c-jggg-j49q/GHSA-h68c-jggg-j49q.json new file mode 100644 index 00000000000..205c9ad44fa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h68c-jggg-j49q/GHSA-h68c-jggg-j49q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h68c-jggg-j49q", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49658" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Ecomerciar Woocommerce Custom Profile Picture allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Custom Profile Picture: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-custom-profile-picture/wordpress-woocommerce-custom-profile-picture-plugin-1-0-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h72q-rx75-mpgf/GHSA-h72q-rx75-mpgf.json b/advisories/unreviewed/2024/10/GHSA-h72q-rx75-mpgf/GHSA-h72q-rx75-mpgf.json index 68c435922de..697e36114f2 100644 --- a/advisories/unreviewed/2024/10/GHSA-h72q-rx75-mpgf/GHSA-h72q-rx75-mpgf.json +++ b/advisories/unreviewed/2024/10/GHSA-h72q-rx75-mpgf/GHSA-h72q-rx75-mpgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h72q-rx75-mpgf", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47665" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup\n\nDefinitely condition dma_get_cache_alignment * defined value > 256\nduring driver initialization is not reason to BUG_ON(). Turn that to\ngraceful error out with -EINVAL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h9p7-c5rq-hwjj/GHSA-h9p7-c5rq-hwjj.json b/advisories/unreviewed/2024/10/GHSA-h9p7-c5rq-hwjj/GHSA-h9p7-c5rq-hwjj.json index 283497c2526..d8bce096622 100644 --- a/advisories/unreviewed/2024/10/GHSA-h9p7-c5rq-hwjj/GHSA-h9p7-c5rq-hwjj.json +++ b/advisories/unreviewed/2024/10/GHSA-h9p7-c5rq-hwjj/GHSA-h9p7-c5rq-hwjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9p7-c5rq-hwjj", - "modified": "2024-10-23T00:31:44Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-23T00:31:44Z", "aliases": [ "CVE-2024-40494" ], "details": "Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hf42-4qwp-gc9r/GHSA-hf42-4qwp-gc9r.json b/advisories/unreviewed/2024/10/GHSA-hf42-4qwp-gc9r/GHSA-hf42-4qwp-gc9r.json new file mode 100644 index 00000000000..6b454a8b236 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hf42-4qwp-gc9r/GHSA-hf42-4qwp-gc9r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf42-4qwp-gc9r", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20342" + ], + "details": "Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured rate limiting filter.\n\nThis vulnerability is due to an incorrect connection count comparison. An attacker could exploit this vulnerability by sending traffic through an affected device at a rate that exceeds a configured rate filter. A successful exploit could allow the attacker to successfully bypass the rate filter. This could allow unintended traffic to enter the network protected by the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20342" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-xss-yjj7ZjVq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-rf-bypass-OY8f3pnM" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1025" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hr33-3275-hjcv/GHSA-hr33-3275-hjcv.json b/advisories/unreviewed/2024/10/GHSA-hr33-3275-hjcv/GHSA-hr33-3275-hjcv.json new file mode 100644 index 00000000000..ac6ce827713 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hr33-3275-hjcv/GHSA-hr33-3275-hjcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr33-3275-hjcv", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20387" + ], + "details": "A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20387" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-infodisc-RL4mJFer" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hvrr-v8q8-3r9q/GHSA-hvrr-v8q8-3r9q.json b/advisories/unreviewed/2024/10/GHSA-hvrr-v8q8-3r9q/GHSA-hvrr-v8q8-3r9q.json new file mode 100644 index 00000000000..2ca641f12c3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hvrr-v8q8-3r9q/GHSA-hvrr-v8q8-3r9q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvrr-v8q8-3r9q", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20473" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.\n\nThis vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20473" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sql-inj-LOYAFcfq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hwhr-j2m2-9887/GHSA-hwhr-j2m2-9887.json b/advisories/unreviewed/2024/10/GHSA-hwhr-j2m2-9887/GHSA-hwhr-j2m2-9887.json new file mode 100644 index 00000000000..0440ae346b8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hwhr-j2m2-9887/GHSA-hwhr-j2m2-9887.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhr-j2m2-9887", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20409" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20409" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j8v5-9q85-rgvv/GHSA-j8v5-9q85-rgvv.json b/advisories/unreviewed/2024/10/GHSA-j8v5-9q85-rgvv/GHSA-j8v5-9q85-rgvv.json new file mode 100644 index 00000000000..8593003f181 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j8v5-9q85-rgvv/GHSA-j8v5-9q85-rgvv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8v5-9q85-rgvv", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-10296" + ], + "details": "A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/card-bwdates-reports-details.php of the component Report of Medical Card Page. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10296" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281563" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281563" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.427400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jfpv-3cc9-x9c2/GHSA-jfpv-3cc9-x9c2.json b/advisories/unreviewed/2024/10/GHSA-jfpv-3cc9-x9c2/GHSA-jfpv-3cc9-x9c2.json new file mode 100644 index 00000000000..78b2afb77a4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jfpv-3cc9-x9c2/GHSA-jfpv-3cc9-x9c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfpv-3cc9-x9c2", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49690" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Interactive Qi Blocks.This issue affects Qi Blocks: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49690" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/qi-blocks/wordpress-qi-blocks-plugin-1-3-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jgmv-vp3c-xpj5/GHSA-jgmv-vp3c-xpj5.json b/advisories/unreviewed/2024/10/GHSA-jgmv-vp3c-xpj5/GHSA-jgmv-vp3c-xpj5.json index de25ce0c11c..7aab35c7cbf 100644 --- a/advisories/unreviewed/2024/10/GHSA-jgmv-vp3c-xpj5/GHSA-jgmv-vp3c-xpj5.json +++ b/advisories/unreviewed/2024/10/GHSA-jgmv-vp3c-xpj5/GHSA-jgmv-vp3c-xpj5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jgqf-4rxm-w86h/GHSA-jgqf-4rxm-w86h.json b/advisories/unreviewed/2024/10/GHSA-jgqf-4rxm-w86h/GHSA-jgqf-4rxm-w86h.json new file mode 100644 index 00000000000..8477cd634bf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jgqf-4rxm-w86h/GHSA-jgqf-4rxm-w86h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgqf-4rxm-w86h", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20275" + ], + "details": "A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.\n\nThis vulnerability is due to insufficient validation of user data that is supplied through the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute arbitrary operating system commands on the affected device. To exploit this vulnerability, an attacker would need valid credentials for a user account with at least the role of Network Administrator. In addition, the attacker would need to persuade a legitimate user to initiate a cluster backup on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20275" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-g8AOKnDP" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jr5q-32rg-gcqq/GHSA-jr5q-32rg-gcqq.json b/advisories/unreviewed/2024/10/GHSA-jr5q-32rg-gcqq/GHSA-jr5q-32rg-gcqq.json new file mode 100644 index 00000000000..dafda0cb51d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jr5q-32rg-gcqq/GHSA-jr5q-32rg-gcqq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr5q-32rg-gcqq", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20340" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, an attacker must have a valid account on the device with the role of Security Approver, Intrusion Admin, Access Admin, or Network Admin.\n\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to read the contents of databases on the affected device and also obtain limited read access to the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20340" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sql-inject-2EnmTC8v" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json b/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json new file mode 100644 index 00000000000..dd9bb1d941f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrcg-6c8x-ff3h", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20331" + ], + "details": "A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from authenticating.\n\nThis vulnerability is due to insufficient entropy in the authentication process. An attacker could exploit this vulnerability by determining the handle of an authenticating user and using it to terminate their authentication session. A successful exploit could allow the attacker to force a user to restart the authentication process, preventing a legitimate user from establishing remote access VPN sessions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20331" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-vpn-nyH3fhp" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-330" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jwpj-m256-82wg/GHSA-jwpj-m256-82wg.json b/advisories/unreviewed/2024/10/GHSA-jwpj-m256-82wg/GHSA-jwpj-m256-82wg.json new file mode 100644 index 00000000000..a78b27ee0dc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jwpj-m256-82wg/GHSA-jwpj-m256-82wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwpj-m256-82wg", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20388" + ], + "details": "A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device.\n\n This vulnerability is due to improper authentication of password update responses. An attacker could exploit this vulnerability by forcing a password reset on an affected device. A successful exploit could allow the attacker to determine valid user names in the unauthenticated response to a forced password reset.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20388" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-infodisc-RL4mJFer" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-202" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m4qh-qp46-jwg7/GHSA-m4qh-qp46-jwg7.json b/advisories/unreviewed/2024/10/GHSA-m4qh-qp46-jwg7/GHSA-m4qh-qp46-jwg7.json new file mode 100644 index 00000000000..dddae4059f6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m4qh-qp46-jwg7/GHSA-m4qh-qp46-jwg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4qh-qp46-jwg7", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20482" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker must have a valid account on the device that is configured with a custom read-only role.\n\n This vulnerability is due to insufficient validation of role permissions in part of the web-based management interface. An attacker could exploit this vulnerability by performing a write operation on the affected part of the web-based management interface. A successful exploit could allow the attacker to modify certain parts of the configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20482" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-priv-esc-CMQ4S6m7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json b/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json new file mode 100644 index 00000000000..1891e769663 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m6p4-vhgw-8c9c/GHSA-m6p4-vhgw-8c9c.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6p4-vhgw-8c9c", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-50383" + ], + "details": "Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be affected.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50383" + }, + { + "type": "WEB", + "url": "https://github.com/randombit/botan/commit/53b0cfde580e86b03d0d27a488b6c134f662e957" + }, + { + "type": "WEB", + "url": "https://arxiv.org/pdf/2410.13489" + }, + { + "type": "WEB", + "url": "https://github.com/randombit/botan/compare/3.5.0...3.6.0" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=41887153" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m83r-8rcp-wv5v/GHSA-m83r-8rcp-wv5v.json b/advisories/unreviewed/2024/10/GHSA-m83r-8rcp-wv5v/GHSA-m83r-8rcp-wv5v.json new file mode 100644 index 00000000000..cd6ca23c994 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m83r-8rcp-wv5v/GHSA-m83r-8rcp-wv5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m83r-8rcp-wv5v", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20485" + ], + "details": "A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.\n\n This vulnerability is due to improper validation of a specific file when it is read from system flash memory. An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20485" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-lce-vU3ekMJ3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m8w7-x24f-68q9/GHSA-m8w7-x24f-68q9.json b/advisories/unreviewed/2024/10/GHSA-m8w7-x24f-68q9/GHSA-m8w7-x24f-68q9.json new file mode 100644 index 00000000000..17b959ffa60 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m8w7-x24f-68q9/GHSA-m8w7-x24f-68q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8w7-x24f-68q9", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20364" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20364" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mjg4-c9jw-rmgw/GHSA-mjg4-c9jw-rmgw.json b/advisories/unreviewed/2024/10/GHSA-mjg4-c9jw-rmgw/GHSA-mjg4-c9jw-rmgw.json index b7f4e54da29..7690aae729f 100644 --- a/advisories/unreviewed/2024/10/GHSA-mjg4-c9jw-rmgw/GHSA-mjg4-c9jw-rmgw.json +++ b/advisories/unreviewed/2024/10/GHSA-mjg4-c9jw-rmgw/GHSA-mjg4-c9jw-rmgw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjg4-c9jw-rmgw", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47662" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Remove register from DCN35 DMCUB diagnostic collection\n\n[Why]\nThese registers should not be read from driver and triggering the\nsecurity violation when DMCUB work times out and diagnostics are\ncollected blocks Z8 entry.\n\n[How]\nRemove the register read from DCN35.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mpm3-wqpq-7qv7/GHSA-mpm3-wqpq-7qv7.json b/advisories/unreviewed/2024/10/GHSA-mpm3-wqpq-7qv7/GHSA-mpm3-wqpq-7qv7.json new file mode 100644 index 00000000000..61f78450cec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mpm3-wqpq-7qv7/GHSA-mpm3-wqpq-7qv7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpm3-wqpq-7qv7", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49669" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official allows Upload a Web Shell to a Web Server.This issue affects INK Official: from n/a through 4.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49669" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ink-official/wordpress-ink-official-plugin-4-1-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json b/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json new file mode 100644 index 00000000000..78f2376226d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p27h-83pf-6hh9/GHSA-p27h-83pf-6hh9.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p27h-83pf-6hh9", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-50382" + ], + "details": "Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50382" + }, + { + "type": "WEB", + "url": "https://github.com/randombit/botan/commit/53b0cfde580e86b03d0d27a488b6c134f662e957" + }, + { + "type": "WEB", + "url": "https://arxiv.org/pdf/2410.13489" + }, + { + "type": "WEB", + "url": "https://github.com/randombit/botan/compare/3.5.0...3.6.0" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=41887153" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p38m-32qc-f4cg/GHSA-p38m-32qc-f4cg.json b/advisories/unreviewed/2024/10/GHSA-p38m-32qc-f4cg/GHSA-p38m-32qc-f4cg.json new file mode 100644 index 00000000000..96ad3e557c8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p38m-32qc-f4cg/GHSA-p38m-32qc-f4cg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p38m-32qc-f4cg", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20412" + ], + "details": "A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials.\n\n This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20412" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-statcred-dFC8tXT5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p6rg-m225-p79c/GHSA-p6rg-m225-p79c.json b/advisories/unreviewed/2024/10/GHSA-p6rg-m225-p79c/GHSA-p6rg-m225-p79c.json new file mode 100644 index 00000000000..c6152ba3c15 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p6rg-m225-p79c/GHSA-p6rg-m225-p79c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rg-m225-p79c", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20300" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20300" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json b/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json new file mode 100644 index 00000000000..90e1c311c29 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj9f-9jr9-4wm7", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20379" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system.\n\n This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. The attacker would need valid user credentials to exploit this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20379" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-file-read-5q4mQRn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-prx7-jm7p-362c/GHSA-prx7-jm7p-362c.json b/advisories/unreviewed/2024/10/GHSA-prx7-jm7p-362c/GHSA-prx7-jm7p-362c.json new file mode 100644 index 00000000000..c087172ec4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-prx7-jm7p-362c/GHSA-prx7-jm7p-362c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prx7-jm7p-362c", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20330" + ], + "details": "A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause the Snort detection engine to restart unexpectedly.\n\nThis vulnerability is due to improper memory management when the Snort detection engine processes specific TCP or UDP packets. An attacker could exploit this vulnerability by sending crafted TCP or UDP packets through a device that is inspecting traffic using the Snort detection engine. A successful exploit could allow the attacker to restart the Snort detection engine repeatedly, which could cause a denial of service (DoS) condition. The DoS condition impacts only the traffic through the device that is examined by the Snort detection engine. The device can still be managed over the network.\nNote: Once a memory block is corrupted, it cannot be cleared until the Cisco Firepower 2100 Series Appliance is manually reloaded. This means that the Snort detection engine could crash repeatedly, causing traffic that is processed by the Snort detection engine to be dropped until the device is manually reloaded.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20330" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd2100-snort-dos-M9HuMt75" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-788" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q69h-fcgw-hqmq/GHSA-q69h-fcgw-hqmq.json b/advisories/unreviewed/2024/10/GHSA-q69h-fcgw-hqmq/GHSA-q69h-fcgw-hqmq.json new file mode 100644 index 00000000000..a42e5a40f98 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q69h-fcgw-hqmq/GHSA-q69h-fcgw-hqmq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q69h-fcgw-hqmq", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49668" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Admin Verbalize WP Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/verbalize-wp/wordpress-verbalize-wp-plugin-1-0-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q97h-2fjm-733c/GHSA-q97h-2fjm-733c.json b/advisories/unreviewed/2024/10/GHSA-q97h-2fjm-733c/GHSA-q97h-2fjm-733c.json index c72dadd26c0..5297a18e5a5 100644 --- a/advisories/unreviewed/2024/10/GHSA-q97h-2fjm-733c/GHSA-q97h-2fjm-733c.json +++ b/advisories/unreviewed/2024/10/GHSA-q97h-2fjm-733c/GHSA-q97h-2fjm-733c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q97h-2fjm-733c", - "modified": "2024-10-09T15:32:19Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:19Z", "aliases": [ "CVE-2024-47658" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: stm32/cryp - call finalize with bh disabled\n\nThe finalize operation in interrupt mode produce a produces a spinlock\nrecursion warning. The reason is the fact that BH must be disabled\nduring this process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T14:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qc5r-vqgv-fc5p/GHSA-qc5r-vqgv-fc5p.json b/advisories/unreviewed/2024/10/GHSA-qc5r-vqgv-fc5p/GHSA-qc5r-vqgv-fc5p.json new file mode 100644 index 00000000000..70cff95992e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qc5r-vqgv-fc5p/GHSA-qc5r-vqgv-fc5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc5r-vqgv-fc5p", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-9949" + ], + "details": "Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9949" + }, + { + "type": "WEB", + "url": "https://forescout.my.site.com/support/s/article/High-Severity-Vulnerability-in-Secure-Connector-HPS-Inspection-Engine-v11-3-5-and-lower" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qf32-pvhj-vvx7/GHSA-qf32-pvhj-vvx7.json b/advisories/unreviewed/2024/10/GHSA-qf32-pvhj-vvx7/GHSA-qf32-pvhj-vvx7.json index 5ba51adae7e..557d5d37ad1 100644 --- a/advisories/unreviewed/2024/10/GHSA-qf32-pvhj-vvx7/GHSA-qf32-pvhj-vvx7.json +++ b/advisories/unreviewed/2024/10/GHSA-qf32-pvhj-vvx7/GHSA-qf32-pvhj-vvx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qf32-pvhj-vvx7", - "modified": "2024-10-09T15:32:19Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:19Z", "aliases": [ "CVE-2024-46871" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX\n\n[Why & How]\nIt actually exposes '6' types in enum dmub_notification_type. Not 5. Using smaller\nnumber to create array dmub_callback & dmub_thread_offload has potential to access\nitem out of array bound. Fix it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T14:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qfh3-92rr-375x/GHSA-qfh3-92rr-375x.json b/advisories/unreviewed/2024/10/GHSA-qfh3-92rr-375x/GHSA-qfh3-92rr-375x.json new file mode 100644 index 00000000000..4fcdabf40dc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qfh3-92rr-375x/GHSA-qfh3-92rr-375x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfh3-92rr-375x", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20382" + ], + "details": "A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper validation of user-supplied input to application endpoints. An attacker could exploit this vulnerability by persuading a user to follow a link designed to submit malicious input to the affected application. A successful exploit could allow the attacker to execute arbitrary HTML or script code in the browser in the context of the web services page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20382" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-yjj7ZjVq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qhxx-xgp6-7rvh/GHSA-qhxx-xgp6-7rvh.json b/advisories/unreviewed/2024/10/GHSA-qhxx-xgp6-7rvh/GHSA-qhxx-xgp6-7rvh.json index 5d9068edff1..90c025962f7 100644 --- a/advisories/unreviewed/2024/10/GHSA-qhxx-xgp6-7rvh/GHSA-qhxx-xgp6-7rvh.json +++ b/advisories/unreviewed/2024/10/GHSA-qhxx-xgp6-7rvh/GHSA-qhxx-xgp6-7rvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qhxx-xgp6-7rvh", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-47750" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix Use-After-Free of rsv_qp on HIP08\n\nCurrently rsv_qp is freed before ib_unregister_device() is called\non HIP08. During the time interval, users can still dereg MR and\nrsv_qp will be used in this process, leading to a UAF. Move the\nrelease of rsv_qp after calling ib_unregister_device() to fix it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qpxg-4f92-ww23/GHSA-qpxg-4f92-ww23.json b/advisories/unreviewed/2024/10/GHSA-qpxg-4f92-ww23/GHSA-qpxg-4f92-ww23.json index 9ff6dba6773..c6d556f3fbd 100644 --- a/advisories/unreviewed/2024/10/GHSA-qpxg-4f92-ww23/GHSA-qpxg-4f92-ww23.json +++ b/advisories/unreviewed/2024/10/GHSA-qpxg-4f92-ww23/GHSA-qpxg-4f92-ww23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpxg-4f92-ww23", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47745" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: call the security_mmap_file() LSM hook in remap_file_pages()\n\nThe remap_file_pages syscall handler calls do_mmap() directly, which\ndoesn't contain the LSM security check. And if the process has called\npersonality(READ_IMPLIES_EXEC) before and remap_file_pages() is called for\nRW pages, this will actually result in remapping the pages to RWX,\nbypassing a W^X policy enforced by SELinux.\n\nSo we should check prot by security_mmap_file LSM hook in the\nremap_file_pages syscall handler before do_mmap() is called. Otherwise, it\npotentially permits an attacker to bypass a W^X policy enforced by\nSELinux.\n\nThe bypass is similar to CVE-2016-10044, which bypass the same thing via\nAIO and can be found in [1].\n\nThe PoC:\n\n$ cat > test.c\n\nint main(void) {\n\tsize_t pagesz = sysconf(_SC_PAGE_SIZE);\n\tint mfd = syscall(SYS_memfd_create, \"test\", 0);\n\tconst char *buf = mmap(NULL, 4 * pagesz, PROT_READ | PROT_WRITE,\n\t\tMAP_SHARED, mfd, 0);\n\tunsigned int old = syscall(SYS_personality, 0xffffffff);\n\tsyscall(SYS_personality, READ_IMPLIES_EXEC | old);\n\tsyscall(SYS_remap_file_pages, buf, pagesz, 0, 2, 0);\n\tsyscall(SYS_personality, old);\n\t// show the RWX page exists even if W^X policy is enforced\n\tint fd = open(\"/proc/self/maps\", O_RDONLY);\n\tunsigned char buf2[1024];\n\twhile (1) {\n\t\tint ret = read(fd, buf2, 1024);\n\t\tif (ret <= 0) break;\n\t\twrite(1, buf2, ret);\n\t}\n\tclose(fd);\n}\n\n$ gcc test.c -o test\n$ ./test | grep rwx\n7f1836c34000-7f1836c35000 rwxs 00002000 00:01 2050 /memfd:test (deleted)\n\n[PM: subject line tweaks]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-670" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qvwj-r2mj-jh93/GHSA-qvwj-r2mj-jh93.json b/advisories/unreviewed/2024/10/GHSA-qvwj-r2mj-jh93/GHSA-qvwj-r2mj-jh93.json index b5ac3bbf7b9..74f2100c9ca 100644 --- a/advisories/unreviewed/2024/10/GHSA-qvwj-r2mj-jh93/GHSA-qvwj-r2mj-jh93.json +++ b/advisories/unreviewed/2024/10/GHSA-qvwj-r2mj-jh93/GHSA-qvwj-r2mj-jh93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvwj-r2mj-jh93", - "modified": "2024-10-21T12:30:55Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T12:30:55Z", "aliases": [ "CVE-2024-47689" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to don't set SB_RDONLY in f2fs_handle_critical_error()\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 58 at kernel/rcu/sync.c:177 rcu_sync_dtor+0xcd/0x180 kernel/rcu/sync.c:177\nCPU: 1 UID: 0 PID: 58 Comm: kworker/1:2 Not tainted 6.10.0-syzkaller-12562-g1722389b0d86 #0\nWorkqueue: events destroy_super_work\nRIP: 0010:rcu_sync_dtor+0xcd/0x180 kernel/rcu/sync.c:177\nCall Trace:\n percpu_free_rwsem+0x41/0x80 kernel/locking/percpu-rwsem.c:42\n destroy_super_work+0xec/0x130 fs/super.c:282\n process_one_work kernel/workqueue.c:3231 [inline]\n process_scheduled_works+0xa2c/0x1830 kernel/workqueue.c:3312\n worker_thread+0x86d/0xd40 kernel/workqueue.c:3390\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nAs Christian Brauner pointed out [1]: the root cause is f2fs sets\nSB_RDONLY flag in internal function, rather than setting the flag\ncovered w/ sb->s_umount semaphore via remount procedure, then below\nrace condition causes this bug:\n\n- freeze_super()\n - sb_wait_write(sb, SB_FREEZE_WRITE)\n - sb_wait_write(sb, SB_FREEZE_PAGEFAULT)\n - sb_wait_write(sb, SB_FREEZE_FS)\n\t\t\t\t\t- f2fs_handle_critical_error\n\t\t\t\t\t - sb->s_flags |= SB_RDONLY\n- thaw_super\n - thaw_super_locked\n - sb_rdonly() is true, so it skips\n sb_freeze_unlock(sb, SB_FREEZE_FS)\n - deactivate_locked_super\n\nSince f2fs has almost the same logic as ext4 [2] when handling critical\nerror in filesystem if it mounts w/ errors=remount-ro option:\n- set CP_ERROR_FLAG flag which indicates filesystem is stopped\n- record errors to superblock\n- set SB_RDONLY falg\nOnce we set CP_ERROR_FLAG flag, all writable interfaces can detect the\nflag and stop any further updates on filesystem. So, it is safe to not\nset SB_RDONLY flag, let's remove the logic and keep in line w/ ext4 [3].\n\n[1] https://lore.kernel.org/all/20240729-himbeeren-funknetz-96e62f9c7aee@brauner\n[2] https://lore.kernel.org/all/20240729132721.hxih6ehigadqf7wx@quack3\n[3] https://lore.kernel.org/linux-ext4/20240805201241.27286-1-jack@suse.cz", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T12:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qwfh-68gj-m9p3/GHSA-qwfh-68gj-m9p3.json b/advisories/unreviewed/2024/10/GHSA-qwfh-68gj-m9p3/GHSA-qwfh-68gj-m9p3.json new file mode 100644 index 00000000000..97341652a23 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qwfh-68gj-m9p3/GHSA-qwfh-68gj-m9p3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwfh-68gj-m9p3", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-49652" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in ReneeCussack 3D Work In Progress allows Upload a Web Shell to a Web Server.This issue affects 3D Work In Progress: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/renee-work-in-progress/wordpress-3d-work-in-progress-plugin-1-0-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qwpx-5prv-xmxx/GHSA-qwpx-5prv-xmxx.json b/advisories/unreviewed/2024/10/GHSA-qwpx-5prv-xmxx/GHSA-qwpx-5prv-xmxx.json index e2bc738d612..ab0ea58dc0d 100644 --- a/advisories/unreviewed/2024/10/GHSA-qwpx-5prv-xmxx/GHSA-qwpx-5prv-xmxx.json +++ b/advisories/unreviewed/2024/10/GHSA-qwpx-5prv-xmxx/GHSA-qwpx-5prv-xmxx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-r5hp-h863-8vpx/GHSA-r5hp-h863-8vpx.json b/advisories/unreviewed/2024/10/GHSA-r5hp-h863-8vpx/GHSA-r5hp-h863-8vpx.json new file mode 100644 index 00000000000..367282d8764 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r5hp-h863-8vpx/GHSA-r5hp-h863-8vpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5hp-h863-8vpx", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20384" + ], + "details": "A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device.\n\n This vulnerability is due to a logic error that occurs when NSG ACLs are populated on an affected device. An attacker could exploit this vulnerability by establishing a connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20384" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-nsgacl-bypass-77XnEAsL" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rmpg-3w9x-w6pr/GHSA-rmpg-3w9x-w6pr.json b/advisories/unreviewed/2024/10/GHSA-rmpg-3w9x-w6pr/GHSA-rmpg-3w9x-w6pr.json new file mode 100644 index 00000000000..bc4f9bacb2b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rmpg-3w9x-w6pr/GHSA-rmpg-3w9x-w6pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmpg-3w9x-w6pr", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20494" + ], + "details": "A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.\n\n This vulnerability is due to improper data validation during the TLS 1.3 handshake. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.\n\n Note: This vulnerability can also impact the integrity of a device by causing VPN HostScan communication failures or file transfer failures when Cisco ASA Software is upgraded using Cisco Adaptive Security Device Manager (ASDM).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20494" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-tls-CWY6zXB" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rw27-7fmj-vgcv/GHSA-rw27-7fmj-vgcv.json b/advisories/unreviewed/2024/10/GHSA-rw27-7fmj-vgcv/GHSA-rw27-7fmj-vgcv.json new file mode 100644 index 00000000000..d4090463fc7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rw27-7fmj-vgcv/GHSA-rw27-7fmj-vgcv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw27-7fmj-vgcv", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-10293" + ], + "details": "A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10293" + }, + { + "type": "WEB", + "url": "https://github.com/LvZCh/zzcms2023/issues/6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.427146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v3gf-g9fc-578x/GHSA-v3gf-g9fc-578x.json b/advisories/unreviewed/2024/10/GHSA-v3gf-g9fc-578x/GHSA-v3gf-g9fc-578x.json new file mode 100644 index 00000000000..14cac694554 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v3gf-g9fc-578x/GHSA-v3gf-g9fc-578x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3gf-g9fc-578x", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20493" + ], + "details": "A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (DoS) condition.\n\n This vulnerability is due to ineffective handling of memory resources during the authentication process. An attacker could exploit this vulnerability by sending crafted packets, which could cause resource exhaustion of the authentication process. A successful exploit could allow the attacker to deny authentication for Remote Access SSL VPN users for several minutes, resulting in a temporary DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20493" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-vpn-4gYEWMKg" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-772" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v4mc-99px-fq68/GHSA-v4mc-99px-fq68.json b/advisories/unreviewed/2024/10/GHSA-v4mc-99px-fq68/GHSA-v4mc-99px-fq68.json new file mode 100644 index 00000000000..9a5da7b8eec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v4mc-99px-fq68/GHSA-v4mc-99px-fq68.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4mc-99px-fq68", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20297" + ], + "details": "A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due to a logic error in populating group ACLs when an AnyConnect client establishes a new session toward an affected device. An attacker could exploit this vulnerability by establishing an AnyConnect connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20297" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-acl-bypass-VvnLNKqf" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vf64-qg5h-qxhf/GHSA-vf64-qg5h-qxhf.json b/advisories/unreviewed/2024/10/GHSA-vf64-qg5h-qxhf/GHSA-vf64-qg5h-qxhf.json index 12e6b4ffa8e..829a6bba995 100644 --- a/advisories/unreviewed/2024/10/GHSA-vf64-qg5h-qxhf/GHSA-vf64-qg5h-qxhf.json +++ b/advisories/unreviewed/2024/10/GHSA-vf64-qg5h-qxhf/GHSA-vf64-qg5h-qxhf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf64-qg5h-qxhf", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49861" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix helper writes to read-only maps\n\nLonial found an issue that despite user- and BPF-side frozen BPF map\n(like in case of .rodata), it was still possible to write into it from\na BPF program side through specific helpers having ARG_PTR_TO_{LONG,INT}\nas arguments.\n\nIn check_func_arg() when the argument is as mentioned, the meta->raw_mode\nis never set. Later, check_helper_mem_access(), under the case of\nPTR_TO_MAP_VALUE as register base type, it assumes BPF_READ for the\nsubsequent call to check_map_access_type() and given the BPF map is\nread-only it succeeds.\n\nThe helpers really need to be annotated as ARG_PTR_TO_{LONG,INT} | MEM_UNINIT\nwhen results are written into them as opposed to read out of them. The\nlatter indicates that it's okay to pass a pointer to uninitialized memory\nas the memory is written to anyway.\n\nHowever, ARG_PTR_TO_{LONG,INT} is a special case of ARG_PTR_TO_FIXED_SIZE_MEM\njust with additional alignment requirement. So it is better to just get\nrid of the ARG_PTR_TO_{LONG,INT} special cases altogether and reuse the\nfixed size memory types. For this, add MEM_ALIGNED to additionally ensure\nalignment given these helpers write directly into the args via * = val.\nThe .arg*_size has been initialized reflecting the actual sizeof(*).\n\nMEM_ALIGNED can only be used in combination with MEM_FIXED_SIZE annotated\nargument types, since in !MEM_FIXED_SIZE cases the verifier does not know\nthe buffer size a priori and therefore cannot blindly write * = val.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vpj6-g6hc-j3cp/GHSA-vpj6-g6hc-j3cp.json b/advisories/unreviewed/2024/10/GHSA-vpj6-g6hc-j3cp/GHSA-vpj6-g6hc-j3cp.json index 3ba82afc907..67ff93554cd 100644 --- a/advisories/unreviewed/2024/10/GHSA-vpj6-g6hc-j3cp/GHSA-vpj6-g6hc-j3cp.json +++ b/advisories/unreviewed/2024/10/GHSA-vpj6-g6hc-j3cp/GHSA-vpj6-g6hc-j3cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpj6-g6hc-j3cp", - "modified": "2024-10-21T15:32:26Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47734" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: Fix unnecessary warnings and logs from bond_xdp_get_xmit_slave()\n\nsyzbot reported a WARNING in bond_xdp_get_xmit_slave. To reproduce\nthis[1], one bond device (bond1) has xdpdrv, which increases\nbpf_master_redirect_enabled_key. Another bond device (bond0) which is\nunsupported by XDP but its slave (veth3) has xdpgeneric that returns\nXDP_TX. This triggers WARN_ON_ONCE() from the xdp_master_redirect().\nTo reduce unnecessary warnings and improve log management, we need to\ndelete the WARN_ON_ONCE() and add ratelimit to the netdev_err().\n\n[1] Steps to reproduce:\n # Needs tx_xdp with return XDP_TX;\n ip l add veth0 type veth peer veth1\n ip l add veth3 type veth peer veth4\n ip l add bond0 type bond mode 6 # BOND_MODE_ALB, unsupported by XDP\n ip l add bond1 type bond # BOND_MODE_ROUNDROBIN by default\n ip l set veth0 master bond1\n ip l set bond1 up\n # Increases bpf_master_redirect_enabled_key\n ip l set dev bond1 xdpdrv object tx_xdp.o section xdp_tx\n ip l set veth3 master bond0\n ip l set bond0 up\n ip l set veth4 up\n # Triggers WARN_ON_ONCE() from the xdp_master_redirect()\n ip l set veth3 xdpgeneric object tx_xdp.o section xdp_tx", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vq87-vqwh-6mj9/GHSA-vq87-vqwh-6mj9.json b/advisories/unreviewed/2024/10/GHSA-vq87-vqwh-6mj9/GHSA-vq87-vqwh-6mj9.json new file mode 100644 index 00000000000..26702dde8cc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vq87-vqwh-6mj9/GHSA-vq87-vqwh-6mj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq87-vqwh-6mj9", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20526" + ], + "details": "A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device.\n\n This vulnerability is due to a logic error when an SSH session is established. An attacker could exploit this vulnerability by sending crafted SSH messages to an affected device. A successful exploit could allow the attacker to exhaust available SSH resources on the affected device so that new SSH connections to the device are denied, resulting in a DoS condition. Existing SSH connections to the device would continue to function normally. The device must be rebooted manually to recover. However, user traffic would not be impacted and could be managed using a remote application such as Cisco Adaptive Security Device Manager (ASDM).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20526" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssh-dos-eEDWu5RM" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vv26-9jw2-p445/GHSA-vv26-9jw2-p445.json b/advisories/unreviewed/2024/10/GHSA-vv26-9jw2-p445/GHSA-vv26-9jw2-p445.json new file mode 100644 index 00000000000..202d4063833 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vv26-9jw2-p445/GHSA-vv26-9jw2-p445.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv26-9jw2-p445", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20374" + ], + "details": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system.\n\n This vulnerability is due to insufficient input validation of certain HTTP request parameters that are sent to the web-based management interface. An attacker could exploit this vulnerability by authenticating to the Cisco FMC web-based management interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute commands as the root user on the affected device. To exploit this vulnerability, an attacker would need Administrator-level credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20374" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-2HBkA97G" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vvmc-4gqr-h5j4/GHSA-vvmc-4gqr-h5j4.json b/advisories/unreviewed/2024/10/GHSA-vvmc-4gqr-h5j4/GHSA-vvmc-4gqr-h5j4.json index 70769b61c9c..1620c8697c7 100644 --- a/advisories/unreviewed/2024/10/GHSA-vvmc-4gqr-h5j4/GHSA-vvmc-4gqr-h5j4.json +++ b/advisories/unreviewed/2024/10/GHSA-vvmc-4gqr-h5j4/GHSA-vvmc-4gqr-h5j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvmc-4gqr-h5j4", - "modified": "2024-10-21T12:30:55Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T12:30:54Z", "aliases": [ "CVE-2024-47686" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nep93xx: clock: Fix off by one in ep93xx_div_recalc_rate()\n\nThe psc->div[] array has psc->num_div elements. These values come from\nwhen we call clk_hw_register_div(). It's adc_divisors and\nARRAY_SIZE(adc_divisors)) and so on. So this condition needs to be >=\ninstead of > to prevent an out of bounds read.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-193" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T12:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w38w-gj7f-5836/GHSA-w38w-gj7f-5836.json b/advisories/unreviewed/2024/10/GHSA-w38w-gj7f-5836/GHSA-w38w-gj7f-5836.json new file mode 100644 index 00000000000..210dab086b0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w38w-gj7f-5836/GHSA-w38w-gj7f-5836.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w38w-gj7f-5836", + "modified": "2024-10-23T18:33:09Z", + "published": "2024-10-23T18:33:09Z", + "aliases": [ + "CVE-2024-20386" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20386" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w6gx-j65f-mmx4/GHSA-w6gx-j65f-mmx4.json b/advisories/unreviewed/2024/10/GHSA-w6gx-j65f-mmx4/GHSA-w6gx-j65f-mmx4.json new file mode 100644 index 00000000000..33d92e81e96 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w6gx-j65f-mmx4/GHSA-w6gx-j65f-mmx4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6gx-j65f-mmx4", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-20264" + ], + "details": "A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20264" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-M446vbEO" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-dhJxQYZs" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8rc-768j-hfvx/GHSA-w8rc-768j-hfvx.json b/advisories/unreviewed/2024/10/GHSA-w8rc-768j-hfvx/GHSA-w8rc-768j-hfvx.json new file mode 100644 index 00000000000..b686753a47e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w8rc-768j-hfvx/GHSA-w8rc-768j-hfvx.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8rc-768j-hfvx", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-10291" + ], + "details": "A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10291" + }, + { + "type": "WEB", + "url": "https://github.com/LvZCh/zzcms2023/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.427101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wccr-cp5j-5ggc/GHSA-wccr-cp5j-5ggc.json b/advisories/unreviewed/2024/10/GHSA-wccr-cp5j-5ggc/GHSA-wccr-cp5j-5ggc.json index 3dd8c1d821c..8e89e1c8df6 100644 --- a/advisories/unreviewed/2024/10/GHSA-wccr-cp5j-5ggc/GHSA-wccr-cp5j-5ggc.json +++ b/advisories/unreviewed/2024/10/GHSA-wccr-cp5j-5ggc/GHSA-wccr-cp5j-5ggc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wccr-cp5j-5ggc", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-23T18:33:06Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47664" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware\n\nIf the value of max_speed_hz is 0, it may cause a division by zero\nerror in hisi_calc_effective_speed().\nThe value of max_speed_hz is provided by firmware.\nFirmware is generally considered as a trusted domain. However, as\ndivision by zero errors can cause system failure, for defense measure,\nthe value of max_speed is validated here. So 0 is regarded as invalid\nand an error code is returned.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json b/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json new file mode 100644 index 00000000000..f8d78eb3d94 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wfjj-9rr8-m3rh/GHSA-wfjj-9rr8-m3rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfjj-9rr8-m3rh", + "modified": "2024-10-23T18:33:08Z", + "published": "2024-10-23T18:33:08Z", + "aliases": [ + "CVE-2024-30124" + ], + "details": "HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30124" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0115627" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-23T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wrc3-47r8-p9qm/GHSA-wrc3-47r8-p9qm.json b/advisories/unreviewed/2024/10/GHSA-wrc3-47r8-p9qm/GHSA-wrc3-47r8-p9qm.json index 82fed1e6554..5546f1ba377 100644 --- a/advisories/unreviewed/2024/10/GHSA-wrc3-47r8-p9qm/GHSA-wrc3-47r8-p9qm.json +++ b/advisories/unreviewed/2024/10/GHSA-wrc3-47r8-p9qm/GHSA-wrc3-47r8-p9qm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrc3-47r8-p9qm", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49860" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: sysfs: validate return type of _STR method\n\nOnly buffer objects are valid return values of _STR.\n\nIf something else is returned description_show() will access invalid\nmemory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wxrr-6r77-mpjf/GHSA-wxrr-6r77-mpjf.json b/advisories/unreviewed/2024/10/GHSA-wxrr-6r77-mpjf/GHSA-wxrr-6r77-mpjf.json index dcff9d5e191..05ab862fca1 100644 --- a/advisories/unreviewed/2024/10/GHSA-wxrr-6r77-mpjf/GHSA-wxrr-6r77-mpjf.json +++ b/advisories/unreviewed/2024/10/GHSA-wxrr-6r77-mpjf/GHSA-wxrr-6r77-mpjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxrr-6r77-mpjf", - "modified": "2024-10-21T15:32:27Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-49853" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix double free in OPTEE transport\n\nChannels can be shared between protocols, avoid freeing the same channel\ndescriptors twice when unloading the stack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T13:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xc58-g4fh-rfxp/GHSA-xc58-g4fh-rfxp.json b/advisories/unreviewed/2024/10/GHSA-xc58-g4fh-rfxp/GHSA-xc58-g4fh-rfxp.json index c6c9ca078db..ae0cc158a3b 100644 --- a/advisories/unreviewed/2024/10/GHSA-xc58-g4fh-rfxp/GHSA-xc58-g4fh-rfxp.json +++ b/advisories/unreviewed/2024/10/GHSA-xc58-g4fh-rfxp/GHSA-xc58-g4fh-rfxp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc58-g4fh-rfxp", - "modified": "2024-10-23T00:31:43Z", + "modified": "2024-10-23T18:33:07Z", "published": "2024-10-23T00:31:43Z", "aliases": [ "CVE-2024-26519" ], "details": "An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-22T22:15:04Z"