diff --git a/advisories/unreviewed/2022/04/GHSA-4x77-wr7f-56wv/GHSA-4x77-wr7f-56wv.json b/advisories/unreviewed/2022/04/GHSA-4x77-wr7f-56wv/GHSA-4x77-wr7f-56wv.json index d849c78ff0e..c72ceaff6a8 100644 --- a/advisories/unreviewed/2022/04/GHSA-4x77-wr7f-56wv/GHSA-4x77-wr7f-56wv.json +++ b/advisories/unreviewed/2022/04/GHSA-4x77-wr7f-56wv/GHSA-4x77-wr7f-56wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x77-wr7f-56wv", - "modified": "2022-04-29T02:57:21Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-04-29T02:57:21Z", "aliases": [ "CVE-2004-0217" ], "details": "The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json b/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json index 084f7ebe1a5..8be22c5dc62 100644 --- a/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json +++ b/advisories/unreviewed/2022/04/GHSA-8cvx-3rg5-x9j3/GHSA-8cvx-3rg5-x9j3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cvx-3rg5-x9j3", - "modified": "2022-04-29T02:59:53Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-04-29T02:59:53Z", "aliases": [ "CVE-2004-1603" ], "details": "cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -49,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-8gpj-8888-5722/GHSA-8gpj-8888-5722.json b/advisories/unreviewed/2022/04/GHSA-8gpj-8888-5722/GHSA-8gpj-8888-5722.json index 75795912365..0bd62a46f74 100644 --- a/advisories/unreviewed/2022/04/GHSA-8gpj-8888-5722/GHSA-8gpj-8888-5722.json +++ b/advisories/unreviewed/2022/04/GHSA-8gpj-8888-5722/GHSA-8gpj-8888-5722.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gpj-8888-5722", - "modified": "2022-04-30T18:18:08Z", + "modified": "2024-01-26T18:30:29Z", "published": "2022-04-30T18:18:08Z", "aliases": [ "CVE-2001-1494" ], "details": "script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -57,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-9cg4-m358-cc47/GHSA-9cg4-m358-cc47.json b/advisories/unreviewed/2022/04/GHSA-9cg4-m358-cc47/GHSA-9cg4-m358-cc47.json index 857f4a3fbe0..e1df608ca14 100644 --- a/advisories/unreviewed/2022/04/GHSA-9cg4-m358-cc47/GHSA-9cg4-m358-cc47.json +++ b/advisories/unreviewed/2022/04/GHSA-9cg4-m358-cc47/GHSA-9cg4-m358-cc47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9cg4-m358-cc47", - "modified": "2022-04-30T18:13:45Z", + "modified": "2024-01-26T18:30:28Z", "published": "2022-04-30T18:13:45Z", "aliases": [ "CVE-2000-0498" ], "details": "Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-178" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-9fxf-pgc8-6fjq/GHSA-9fxf-pgc8-6fjq.json b/advisories/unreviewed/2022/04/GHSA-9fxf-pgc8-6fjq/GHSA-9fxf-pgc8-6fjq.json index 4c41d40f160..30b1cb67259 100644 --- a/advisories/unreviewed/2022/04/GHSA-9fxf-pgc8-6fjq/GHSA-9fxf-pgc8-6fjq.json +++ b/advisories/unreviewed/2022/04/GHSA-9fxf-pgc8-6fjq/GHSA-9fxf-pgc8-6fjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fxf-pgc8-6fjq", - "modified": "2022-04-30T18:13:45Z", + "modified": "2024-01-26T18:30:28Z", "published": "2022-04-30T18:13:45Z", "aliases": [ "CVE-2000-0497" ], "details": "IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-178" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-cgm8-c3pr-78fr/GHSA-cgm8-c3pr-78fr.json b/advisories/unreviewed/2022/04/GHSA-cgm8-c3pr-78fr/GHSA-cgm8-c3pr-78fr.json index da1e8f3e02a..66dafd3f378 100644 --- a/advisories/unreviewed/2022/04/GHSA-cgm8-c3pr-78fr/GHSA-cgm8-c3pr-78fr.json +++ b/advisories/unreviewed/2022/04/GHSA-cgm8-c3pr-78fr/GHSA-cgm8-c3pr-78fr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgm8-c3pr-78fr", - "modified": "2022-04-30T18:15:12Z", + "modified": "2024-01-26T18:30:29Z", "published": "2022-04-30T18:15:12Z", "aliases": [ "CVE-2001-0006" ], "details": "The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to \"No Access\" and disable Winsock network connectivity to cause a denial of service, aka the \"Winsock Mutex\" vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-j97v-38wx-6pjj/GHSA-j97v-38wx-6pjj.json b/advisories/unreviewed/2022/04/GHSA-j97v-38wx-6pjj/GHSA-j97v-38wx-6pjj.json index d7f090ffd4b..25a591574f2 100644 --- a/advisories/unreviewed/2022/04/GHSA-j97v-38wx-6pjj/GHSA-j97v-38wx-6pjj.json +++ b/advisories/unreviewed/2022/04/GHSA-j97v-38wx-6pjj/GHSA-j97v-38wx-6pjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j97v-38wx-6pjj", - "modified": "2022-04-30T18:19:56Z", + "modified": "2024-01-26T18:30:29Z", "published": "2022-04-30T18:19:56Z", "aliases": [ "CVE-2002-0793" ], "details": "Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -57,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-jx8m-xm6x-225q/GHSA-jx8m-xm6x-225q.json b/advisories/unreviewed/2022/04/GHSA-jx8m-xm6x-225q/GHSA-jx8m-xm6x-225q.json index 11a80345c96..9336c8c400d 100644 --- a/advisories/unreviewed/2022/04/GHSA-jx8m-xm6x-225q/GHSA-jx8m-xm6x-225q.json +++ b/advisories/unreviewed/2022/04/GHSA-jx8m-xm6x-225q/GHSA-jx8m-xm6x-225q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx8m-xm6x-225q", - "modified": "2022-04-29T01:26:40Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-04-29T01:26:40Z", "aliases": [ "CVE-2003-0578" ], "details": "cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json b/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json index 5343413b83e..7d0d95e3d30 100644 --- a/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json +++ b/advisories/unreviewed/2022/04/GHSA-m82x-j38m-84qv/GHSA-m82x-j38m-84qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m82x-j38m-84qv", - "modified": "2022-04-29T03:00:25Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-04-29T03:00:25Z", "aliases": [ "CVE-2004-1901" ], "details": "Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-mw4j-8wf7-4rfp/GHSA-mw4j-8wf7-4rfp.json b/advisories/unreviewed/2022/04/GHSA-mw4j-8wf7-4rfp/GHSA-mw4j-8wf7-4rfp.json index 5b2b3af9097..16040a10cac 100644 --- a/advisories/unreviewed/2022/04/GHSA-mw4j-8wf7-4rfp/GHSA-mw4j-8wf7-4rfp.json +++ b/advisories/unreviewed/2022/04/GHSA-mw4j-8wf7-4rfp/GHSA-mw4j-8wf7-4rfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mw4j-8wf7-4rfp", - "modified": "2022-04-30T18:11:12Z", + "modified": "2024-01-26T18:30:27Z", "published": "2022-04-30T18:11:12Z", "aliases": [ "CVE-1999-0783" ], "details": "FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-p742-xf6g-v4h3/GHSA-p742-xf6g-v4h3.json b/advisories/unreviewed/2022/04/GHSA-p742-xf6g-v4h3/GHSA-p742-xf6g-v4h3.json index 4d39bd1c9ac..5cf964c415e 100644 --- a/advisories/unreviewed/2022/04/GHSA-p742-xf6g-v4h3/GHSA-p742-xf6g-v4h3.json +++ b/advisories/unreviewed/2022/04/GHSA-p742-xf6g-v4h3/GHSA-p742-xf6g-v4h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p742-xf6g-v4h3", - "modified": "2022-04-30T18:20:17Z", + "modified": "2024-01-26T18:30:29Z", "published": "2022-04-30T18:20:17Z", "aliases": [ "CVE-2002-0969" ], "details": "Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long \"datadir\" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-pqvf-h958-3qmw/GHSA-pqvf-h958-3qmw.json b/advisories/unreviewed/2022/04/GHSA-pqvf-h958-3qmw/GHSA-pqvf-h958-3qmw.json index 6eec2e48df6..742fc2ded81 100644 --- a/advisories/unreviewed/2022/04/GHSA-pqvf-h958-3qmw/GHSA-pqvf-h958-3qmw.json +++ b/advisories/unreviewed/2022/04/GHSA-pqvf-h958-3qmw/GHSA-pqvf-h958-3qmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqvf-h958-3qmw", - "modified": "2022-04-29T02:58:10Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-04-29T02:58:10Z", "aliases": [ "CVE-2004-0689" ], "details": "KDE before 3.3.0 does not properly handle when certain symbolic links point to \"stale\" locations, which could allow local users to create or truncate arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -53,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-qc48-8mcw-gxqv/GHSA-qc48-8mcw-gxqv.json b/advisories/unreviewed/2022/04/GHSA-qc48-8mcw-gxqv/GHSA-qc48-8mcw-gxqv.json index ec4577c6c93..bed138df6ba 100644 --- a/advisories/unreviewed/2022/04/GHSA-qc48-8mcw-gxqv/GHSA-qc48-8mcw-gxqv.json +++ b/advisories/unreviewed/2022/04/GHSA-qc48-8mcw-gxqv/GHSA-qc48-8mcw-gxqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc48-8mcw-gxqv", - "modified": "2022-04-30T18:13:44Z", + "modified": "2024-01-26T18:30:28Z", "published": "2022-04-30T18:13:44Z", "aliases": [ "CVE-2000-0499" ], "details": "The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-178" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-r44p-pj93-6hhq/GHSA-r44p-pj93-6hhq.json b/advisories/unreviewed/2022/04/GHSA-r44p-pj93-6hhq/GHSA-r44p-pj93-6hhq.json index 63f1f3b7995..97fefb4ebba 100644 --- a/advisories/unreviewed/2022/04/GHSA-r44p-pj93-6hhq/GHSA-r44p-pj93-6hhq.json +++ b/advisories/unreviewed/2022/04/GHSA-r44p-pj93-6hhq/GHSA-r44p-pj93-6hhq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r44p-pj93-6hhq", - "modified": "2022-04-30T18:15:03Z", + "modified": "2024-01-26T18:30:28Z", "published": "2022-04-30T18:15:03Z", "aliases": [ "CVE-2000-1178" ], "details": "Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -53,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-rwp9-w3rx-vf92/GHSA-rwp9-w3rx-vf92.json b/advisories/unreviewed/2022/04/GHSA-rwp9-w3rx-vf92/GHSA-rwp9-w3rx-vf92.json index 482f2f43a1f..43f0311251d 100644 --- a/advisories/unreviewed/2022/04/GHSA-rwp9-w3rx-vf92/GHSA-rwp9-w3rx-vf92.json +++ b/advisories/unreviewed/2022/04/GHSA-rwp9-w3rx-vf92/GHSA-rwp9-w3rx-vf92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwp9-w3rx-vf92", - "modified": "2022-04-30T18:12:22Z", + "modified": "2024-01-26T18:30:27Z", "published": "2022-04-30T18:12:22Z", "aliases": [ "CVE-1999-1386" ], "details": "Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json b/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json index d1651ad90c8..591bbce6bd6 100644 --- a/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json +++ b/advisories/unreviewed/2022/04/GHSA-wjpj-j5w8-2m2p/GHSA-wjpj-j5w8-2m2p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjpj-j5w8-2m2p", - "modified": "2022-04-29T03:00:04Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-04-29T03:00:04Z", "aliases": [ "CVE-2004-1714" ], "details": "BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-x2cg-9rfp-53mf/GHSA-x2cg-9rfp-53mf.json b/advisories/unreviewed/2022/04/GHSA-x2cg-9rfp-53mf/GHSA-x2cg-9rfp-53mf.json index df6d8506d1e..632f54c35a1 100644 --- a/advisories/unreviewed/2022/04/GHSA-x2cg-9rfp-53mf/GHSA-x2cg-9rfp-53mf.json +++ b/advisories/unreviewed/2022/04/GHSA-x2cg-9rfp-53mf/GHSA-x2cg-9rfp-53mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x2cg-9rfp-53mf", - "modified": "2022-04-30T18:14:40Z", + "modified": "2024-01-26T18:30:28Z", "published": "2022-04-30T18:14:40Z", "aliases": [ "CVE-2000-0972" ], "details": "HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-3m96-w3xc-w9j4/GHSA-3m96-w3xc-w9j4.json b/advisories/unreviewed/2022/05/GHSA-3m96-w3xc-w9j4/GHSA-3m96-w3xc-w9j4.json index 4cdb8ff20e7..d16175c4808 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m96-w3xc-w9j4/GHSA-3m96-w3xc-w9j4.json +++ b/advisories/unreviewed/2022/05/GHSA-3m96-w3xc-w9j4/GHSA-3m96-w3xc-w9j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3m96-w3xc-w9j4", - "modified": "2022-05-01T01:52:18Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-01T01:52:18Z", "aliases": [ "CVE-2005-0824" ], "details": "The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json b/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json index 543afdf1a4c..1b0f81e42c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json +++ b/advisories/unreviewed/2022/05/GHSA-492m-hh57-3gv9/GHSA-492m-hh57-3gv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-492m-hh57-3gv9", - "modified": "2022-05-02T03:29:59Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-02T03:29:59Z", "aliases": [ "CVE-2009-1936" ], "details": "_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json b/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json index 97a91d0c0b1..409b1cc202e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json +++ b/advisories/unreviewed/2022/05/GHSA-6gmh-pw6w-cww4/GHSA-6gmh-pw6w-cww4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6gmh-pw6w-cww4", - "modified": "2022-05-02T03:13:48Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-02T03:13:48Z", "aliases": [ "CVE-2009-0244" ], "details": "Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6hvx-3mcf-v9xf/GHSA-6hvx-3mcf-v9xf.json b/advisories/unreviewed/2022/05/GHSA-6hvx-3mcf-v9xf/GHSA-6hvx-3mcf-v9xf.json index aefeab7f614..aa971994e7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hvx-3mcf-v9xf/GHSA-6hvx-3mcf-v9xf.json +++ b/advisories/unreviewed/2022/05/GHSA-6hvx-3mcf-v9xf/GHSA-6hvx-3mcf-v9xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hvx-3mcf-v9xf", - "modified": "2022-05-01T02:03:14Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-01T02:03:14Z", "aliases": [ "CVE-2005-1916" ], "details": "linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-84hh-rjph-rr29/GHSA-84hh-rjph-rr29.json b/advisories/unreviewed/2022/05/GHSA-84hh-rjph-rr29/GHSA-84hh-rjph-rr29.json index 69bcb0338f5..b1a6647ce25 100644 --- a/advisories/unreviewed/2022/05/GHSA-84hh-rjph-rr29/GHSA-84hh-rjph-rr29.json +++ b/advisories/unreviewed/2022/05/GHSA-84hh-rjph-rr29/GHSA-84hh-rjph-rr29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84hh-rjph-rr29", - "modified": "2022-05-02T03:54:51Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T03:54:51Z", "aliases": [ "CVE-2009-4449" ], "details": "Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8fqg-637q-r2qf/GHSA-8fqg-637q-r2qf.json b/advisories/unreviewed/2022/05/GHSA-8fqg-637q-r2qf/GHSA-8fqg-637q-r2qf.json index 9f0883f6884..582bee13900 100644 --- a/advisories/unreviewed/2022/05/GHSA-8fqg-637q-r2qf/GHSA-8fqg-637q-r2qf.json +++ b/advisories/unreviewed/2022/05/GHSA-8fqg-637q-r2qf/GHSA-8fqg-637q-r2qf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8fqg-637q-r2qf", - "modified": "2022-05-02T03:50:42Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T03:50:42Z", "aliases": [ "CVE-2009-4013" ], "details": "Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4013" }, + { + "type": "WEB", + "url": "http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=c8d01f062b3e5137cf65196760b079a855c75e00" + }, + { + "type": "WEB", + "url": "http://git.debian.org/?p=lintian/lintian.git%3Ba=commit%3Bh=fbe0c92b2ef7e360d13414bf40d6af5507d0c86d" + }, { "type": "WEB", "url": "http://git.debian.org/?p=lintian/lintian.git;a=commit;h=c8d01f062b3e5137cf65196760b079a855c75e00" diff --git a/advisories/unreviewed/2022/05/GHSA-9354-6mjp-r2vv/GHSA-9354-6mjp-r2vv.json b/advisories/unreviewed/2022/05/GHSA-9354-6mjp-r2vv/GHSA-9354-6mjp-r2vv.json index 161577b1cdb..07fcb4ed189 100644 --- a/advisories/unreviewed/2022/05/GHSA-9354-6mjp-r2vv/GHSA-9354-6mjp-r2vv.json +++ b/advisories/unreviewed/2022/05/GHSA-9354-6mjp-r2vv/GHSA-9354-6mjp-r2vv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-98hv-c54f-3q9x/GHSA-98hv-c54f-3q9x.json b/advisories/unreviewed/2022/05/GHSA-98hv-c54f-3q9x/GHSA-98hv-c54f-3q9x.json index 2167dd55f17..acee9fe34cf 100644 --- a/advisories/unreviewed/2022/05/GHSA-98hv-c54f-3q9x/GHSA-98hv-c54f-3q9x.json +++ b/advisories/unreviewed/2022/05/GHSA-98hv-c54f-3q9x/GHSA-98hv-c54f-3q9x.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-gchh-gcff-w82w/GHSA-gchh-gcff-w82w.json b/advisories/unreviewed/2022/05/GHSA-gchh-gcff-w82w/GHSA-gchh-gcff-w82w.json index 04b53ad44e5..81646030599 100644 --- a/advisories/unreviewed/2022/05/GHSA-gchh-gcff-w82w/GHSA-gchh-gcff-w82w.json +++ b/advisories/unreviewed/2022/05/GHSA-gchh-gcff-w82w/GHSA-gchh-gcff-w82w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gchh-gcff-w82w", - "modified": "2022-05-02T03:51:07Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T03:51:07Z", "aliases": [ "CVE-2009-4053" ], "details": "Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4053" }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54303" + }, { "type": "WEB", "url": "http://secunia.com/advisories/37381" diff --git a/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json b/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json index b7b9fc4a437..acdb1929534 100644 --- a/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json +++ b/advisories/unreviewed/2022/05/GHSA-jccq-8hwf-xp6j/GHSA-jccq-8hwf-xp6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jccq-8hwf-xp6j", - "modified": "2022-05-02T03:52:40Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T03:52:40Z", "aliases": [ "CVE-2009-4194" ], "details": "Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-p97q-m42v-rwxw/GHSA-p97q-m42v-rwxw.json b/advisories/unreviewed/2022/05/GHSA-p97q-m42v-rwxw/GHSA-p97q-m42v-rwxw.json index 71a3d581e2b..7337d66210b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p97q-m42v-rwxw/GHSA-p97q-m42v-rwxw.json +++ b/advisories/unreviewed/2022/05/GHSA-p97q-m42v-rwxw/GHSA-p97q-m42v-rwxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p97q-m42v-rwxw", - "modified": "2022-05-01T07:44:30Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-01T07:44:30Z", "aliases": [ "CVE-2006-7079" ], "details": "Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json b/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json index b24bb8d16a9..c16f727e664 100644 --- a/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json +++ b/advisories/unreviewed/2022/05/GHSA-pgp4-m4pc-4jr6/GHSA-pgp4-m4pc-4jr6.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-q5c9-crv8-jc57/GHSA-q5c9-crv8-jc57.json b/advisories/unreviewed/2022/05/GHSA-q5c9-crv8-jc57/GHSA-q5c9-crv8-jc57.json index 7145269aaf9..87ae8462284 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5c9-crv8-jc57/GHSA-q5c9-crv8-jc57.json +++ b/advisories/unreviewed/2022/05/GHSA-q5c9-crv8-jc57/GHSA-q5c9-crv8-jc57.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json b/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json index 69a3d368b36..583f0d09cd6 100644 --- a/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json +++ b/advisories/unreviewed/2022/05/GHSA-q72h-v4jg-pwvv/GHSA-q72h-v4jg-pwvv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q72h-v4jg-pwvv", - "modified": "2022-05-17T00:43:18Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-17T00:43:18Z", "aliases": [ "CVE-2008-5748" ], "details": "Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qhmp-pxvc-gh7c/GHSA-qhmp-pxvc-gh7c.json b/advisories/unreviewed/2022/05/GHSA-qhmp-pxvc-gh7c/GHSA-qhmp-pxvc-gh7c.json index cfbb4e6c846..45da120cfe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qhmp-pxvc-gh7c/GHSA-qhmp-pxvc-gh7c.json +++ b/advisories/unreviewed/2022/05/GHSA-qhmp-pxvc-gh7c/GHSA-qhmp-pxvc-gh7c.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json b/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json index 462fc468d4a..23a32e1b1e3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json +++ b/advisories/unreviewed/2022/05/GHSA-qrhw-r9hg-cwcm/GHSA-qrhw-r9hg-cwcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrhw-r9hg-cwcm", - "modified": "2022-05-02T03:56:06Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T03:56:06Z", "aliases": [ "CVE-2009-4581" ], "details": "Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v4r8-qwq6-39xh/GHSA-v4r8-qwq6-39xh.json b/advisories/unreviewed/2022/05/GHSA-v4r8-qwq6-39xh/GHSA-v4r8-qwq6-39xh.json index 73246963caf..fd650520a1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4r8-qwq6-39xh/GHSA-v4r8-qwq6-39xh.json +++ b/advisories/unreviewed/2022/05/GHSA-v4r8-qwq6-39xh/GHSA-v4r8-qwq6-39xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4r8-qwq6-39xh", - "modified": "2022-05-01T02:02:49Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-01T02:02:49Z", "aliases": [ "CVE-2005-1880" ], "details": "everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -41,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json b/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json index 357f118ebcd..c5d2fd37ea7 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json +++ b/advisories/unreviewed/2022/05/GHSA-v6ph-x2c7-6g37/GHSA-v6ph-x2c7-6g37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6ph-x2c7-6g37", - "modified": "2022-05-02T06:09:43Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T06:09:43Z", "aliases": [ "CVE-2010-0013" ], "details": "Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v6wx-rx33-54f5/GHSA-v6wx-rx33-54f5.json b/advisories/unreviewed/2022/05/GHSA-v6wx-rx33-54f5/GHSA-v6wx-rx33-54f5.json index d13b1c0594a..67154461d66 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6wx-rx33-54f5/GHSA-v6wx-rx33-54f5.json +++ b/advisories/unreviewed/2022/05/GHSA-v6wx-rx33-54f5/GHSA-v6wx-rx33-54f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6wx-rx33-54f5", - "modified": "2022-05-02T06:09:43Z", + "modified": "2024-01-26T18:30:31Z", "published": "2022-05-02T06:09:43Z", "aliases": [ "CVE-2010-0012" ], "details": "Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -54,6 +57,10 @@ "type": "WEB", "url": "http://www.debian.org/security/2010/dsa-1967" }, + { + "type": "WEB", + "url": "http://www.mail-archive.com/debian-devel-changes%40lists.debian.org/msg264483.html" + }, { "type": "WEB", "url": "http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg264483.html" diff --git a/advisories/unreviewed/2022/05/GHSA-w5f5-qh6w-mqx9/GHSA-w5f5-qh6w-mqx9.json b/advisories/unreviewed/2022/05/GHSA-w5f5-qh6w-mqx9/GHSA-w5f5-qh6w-mqx9.json index 2e0b91503fb..bba589da6e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5f5-qh6w-mqx9/GHSA-w5f5-qh6w-mqx9.json +++ b/advisories/unreviewed/2022/05/GHSA-w5f5-qh6w-mqx9/GHSA-w5f5-qh6w-mqx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5f5-qh6w-mqx9", - "modified": "2022-05-01T02:02:49Z", + "modified": "2024-01-26T18:30:30Z", "published": "2022-05-01T02:02:49Z", "aliases": [ "CVE-2005-1879" ], "details": "LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -53,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-3v9w-qp9v-wq29/GHSA-3v9w-qp9v-wq29.json b/advisories/unreviewed/2022/08/GHSA-3v9w-qp9v-wq29/GHSA-3v9w-qp9v-wq29.json index 53cb5b04121..67057dcb15b 100644 --- a/advisories/unreviewed/2022/08/GHSA-3v9w-qp9v-wq29/GHSA-3v9w-qp9v-wq29.json +++ b/advisories/unreviewed/2022/08/GHSA-3v9w-qp9v-wq29/GHSA-3v9w-qp9v-wq29.json @@ -24,6 +24,14 @@ { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-959/" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176794/Vinchin-Backup-And-Recovery-7.2-Default-MySQL-Credentials.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/30" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-v3v3-pwm3-3xx8/GHSA-v3v3-pwm3-3xx8.json b/advisories/unreviewed/2022/10/GHSA-v3v3-pwm3-3xx8/GHSA-v3v3-pwm3-3xx8.json index 324df3cdec9..65ae3779362 100644 --- a/advisories/unreviewed/2022/10/GHSA-v3v3-pwm3-3xx8/GHSA-v3v3-pwm3-3xx8.json +++ b/advisories/unreviewed/2022/10/GHSA-v3v3-pwm3-3xx8/GHSA-v3v3-pwm3-3xx8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-707", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/07/GHSA-c36p-x44h-8wcq/GHSA-c36p-x44h-8wcq.json b/advisories/unreviewed/2023/07/GHSA-c36p-x44h-8wcq/GHSA-c36p-x44h-8wcq.json index eb43588c8db..17bf9bb9210 100644 --- a/advisories/unreviewed/2023/07/GHSA-c36p-x44h-8wcq/GHSA-c36p-x44h-8wcq.json +++ b/advisories/unreviewed/2023/07/GHSA-c36p-x44h-8wcq/GHSA-c36p-x44h-8wcq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c36p-x44h-8wcq", - "modified": "2023-07-18T21:30:37Z", + "modified": "2024-01-26T18:30:31Z", "published": "2023-07-18T21:30:37Z", "aliases": [ "CVE-2023-22006" @@ -46,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-18T21:15:12Z" diff --git a/advisories/unreviewed/2023/07/GHSA-mw33-48wm-m4r2/GHSA-mw33-48wm-m4r2.json b/advisories/unreviewed/2023/07/GHSA-mw33-48wm-m4r2/GHSA-mw33-48wm-m4r2.json index 013c848b3b7..8acb175cdd6 100644 --- a/advisories/unreviewed/2023/07/GHSA-mw33-48wm-m4r2/GHSA-mw33-48wm-m4r2.json +++ b/advisories/unreviewed/2023/07/GHSA-mw33-48wm-m4r2/GHSA-mw33-48wm-m4r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw33-48wm-m4r2", - "modified": "2023-07-18T21:30:38Z", + "modified": "2024-01-26T18:30:31Z", "published": "2023-07-18T21:30:38Z", "aliases": [ "CVE-2023-22036" @@ -46,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-18T21:15:13Z" diff --git a/advisories/unreviewed/2023/07/GHSA-p276-58r4-6c33/GHSA-p276-58r4-6c33.json b/advisories/unreviewed/2023/07/GHSA-p276-58r4-6c33/GHSA-p276-58r4-6c33.json index fb790dfa42f..869b552f8bd 100644 --- a/advisories/unreviewed/2023/07/GHSA-p276-58r4-6c33/GHSA-p276-58r4-6c33.json +++ b/advisories/unreviewed/2023/07/GHSA-p276-58r4-6c33/GHSA-p276-58r4-6c33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p276-58r4-6c33", - "modified": "2023-07-18T21:30:38Z", + "modified": "2024-01-26T18:30:31Z", "published": "2023-07-18T21:30:38Z", "aliases": [ "CVE-2023-22045" @@ -46,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-18T21:15:14Z" diff --git a/advisories/unreviewed/2023/07/GHSA-rgxf-494f-377c/GHSA-rgxf-494f-377c.json b/advisories/unreviewed/2023/07/GHSA-rgxf-494f-377c/GHSA-rgxf-494f-377c.json index 501b03efeea..8c7205a1e97 100644 --- a/advisories/unreviewed/2023/07/GHSA-rgxf-494f-377c/GHSA-rgxf-494f-377c.json +++ b/advisories/unreviewed/2023/07/GHSA-rgxf-494f-377c/GHSA-rgxf-494f-377c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgxf-494f-377c", - "modified": "2023-07-18T21:30:38Z", + "modified": "2024-01-26T18:30:31Z", "published": "2023-07-18T21:30:38Z", "aliases": [ "CVE-2023-22041" @@ -46,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-18T21:15:13Z" diff --git a/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json b/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json index 2e36c9af450..e5e84a4513a 100644 --- a/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json +++ b/advisories/unreviewed/2023/09/GHSA-99j9-jf36-9747/GHSA-99j9-jf36-9747.json @@ -68,6 +68,18 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/17" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json b/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json index 268d5a07c5d..211059ca7b2 100644 --- a/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json +++ b/advisories/unreviewed/2023/10/GHSA-7xw9-w465-6x42/GHSA-7xw9-w465-6x42.json @@ -52,6 +52,18 @@ { "type": "WEB", "url": "https://www.secpod.com/blog/high-severity-heap-buffer-overflow-vulnerability/" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-x3qx-m3c2-qfhx/GHSA-x3qx-m3c2-qfhx.json b/advisories/unreviewed/2023/10/GHSA-x3qx-m3c2-qfhx/GHSA-x3qx-m3c2-qfhx.json index f16bf8de4a1..ee5181f8dca 100644 --- a/advisories/unreviewed/2023/10/GHSA-x3qx-m3c2-qfhx/GHSA-x3qx-m3c2-qfhx.json +++ b/advisories/unreviewed/2023/10/GHSA-x3qx-m3c2-qfhx/GHSA-x3qx-m3c2-qfhx.json @@ -44,6 +44,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json b/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json index 3951e49a384..fe199331dac 100644 --- a/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json +++ b/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json @@ -52,6 +52,10 @@ { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5556" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176721/Chrome-content-NavigationURLLoaderImpl-FallbackToNonInterceptedRequest-Heap-Use-After-Free.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json b/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json index 00b4298271d..3d5cd9cb919 100644 --- a/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json +++ b/advisories/unreviewed/2023/12/GHSA-95hw-v8fq-666q/GHSA-95hw-v8fq-666q.json @@ -73,6 +73,10 @@ "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Dec/8" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/35" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/12/05/1" diff --git a/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json b/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json index 3956ecf6ebb..1f4604c3461 100644 --- a/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json +++ b/advisories/unreviewed/2023/12/GHSA-phhr-cqm7-gjv6/GHSA-phhr-cqm7-gjv6.json @@ -73,6 +73,10 @@ "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Dec/8" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/35" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/12/05/1" diff --git a/advisories/unreviewed/2024/01/GHSA-223p-3v7f-rwxh/GHSA-223p-3v7f-rwxh.json b/advisories/unreviewed/2024/01/GHSA-223p-3v7f-rwxh/GHSA-223p-3v7f-rwxh.json index c1202401b01..237f947ad03 100644 --- a/advisories/unreviewed/2024/01/GHSA-223p-3v7f-rwxh/GHSA-223p-3v7f-rwxh.json +++ b/advisories/unreviewed/2024/01/GHSA-223p-3v7f-rwxh/GHSA-223p-3v7f-rwxh.json @@ -37,6 +37,26 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-2vfj-ww29-h4x2/GHSA-2vfj-ww29-h4x2.json b/advisories/unreviewed/2024/01/GHSA-2vfj-ww29-h4x2/GHSA-2vfj-ww29-h4x2.json index 089f45baf2b..889e27308b1 100644 --- a/advisories/unreviewed/2024/01/GHSA-2vfj-ww29-h4x2/GHSA-2vfj-ww29-h4x2.json +++ b/advisories/unreviewed/2024/01/GHSA-2vfj-ww29-h4x2/GHSA-2vfj-ww29-h4x2.json @@ -53,6 +53,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT214041" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-36mq-j57w-rh2g/GHSA-36mq-j57w-rh2g.json b/advisories/unreviewed/2024/01/GHSA-36mq-j57w-rh2g/GHSA-36mq-j57w-rh2g.json index 1775f8ce9a7..6f8d8eccbe6 100644 --- a/advisories/unreviewed/2024/01/GHSA-36mq-j57w-rh2g/GHSA-36mq-j57w-rh2g.json +++ b/advisories/unreviewed/2024/01/GHSA-36mq-j57w-rh2g/GHSA-36mq-j57w-rh2g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36mq-j57w-rh2g", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51928" ], "details": "An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T01:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3fg7-rwvx-xrf8/GHSA-3fg7-rwvx-xrf8.json b/advisories/unreviewed/2024/01/GHSA-3fg7-rwvx-xrf8/GHSA-3fg7-rwvx-xrf8.json new file mode 100644 index 00000000000..ea5504b4133 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3fg7-rwvx-xrf8/GHSA-3fg7-rwvx-xrf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fg7-rwvx-xrf8", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-21985" + ], + "details": "ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 \nand 9.13.1P4 are susceptible to a vulnerability which could allow an \nauthenticated user with multiple remote accounts with differing roles to\n perform actions via REST API beyond their intended privilege. Possible \nactions include viewing limited configuration details and metrics or \nmodifying limited settings, some of which could result in a Denial of \nService (DoS).\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21985" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240126-0001/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json index 8c73ec0b307..4143639a1d7 100644 --- a/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json +++ b/advisories/unreviewed/2024/01/GHSA-3h6x-952r-xr8p/GHSA-3h6x-952r-xr8p.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/27" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-3jcf-xpxj-7444/GHSA-3jcf-xpxj-7444.json b/advisories/unreviewed/2024/01/GHSA-3jcf-xpxj-7444/GHSA-3jcf-xpxj-7444.json new file mode 100644 index 00000000000..ef473bdb687 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3jcf-xpxj-7444/GHSA-3jcf-xpxj-7444.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jcf-xpxj-7444", + "modified": "2024-01-26T18:30:35Z", + "published": "2024-01-26T18:30:35Z", + "aliases": [ + "CVE-2024-20305" + ], + "details": "A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20305" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuc-xss-9TFuu5MS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json b/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json index 4ce03b5af44..90239d2bce3 100644 --- a/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json +++ b/advisories/unreviewed/2024/01/GHSA-4287-v2hm-q9f2/GHSA-4287-v2hm-q9f2.json @@ -29,6 +29,18 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-45x8-rqf3-8w66/GHSA-45x8-rqf3-8w66.json b/advisories/unreviewed/2024/01/GHSA-45x8-rqf3-8w66/GHSA-45x8-rqf3-8w66.json index 1e4dd83f905..1e57513b2bb 100644 --- a/advisories/unreviewed/2024/01/GHSA-45x8-rqf3-8w66/GHSA-45x8-rqf3-8w66.json +++ b/advisories/unreviewed/2024/01/GHSA-45x8-rqf3-8w66/GHSA-45x8-rqf3-8w66.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45x8-rqf3-8w66", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2021-31314" ], "details": "File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T01:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json b/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json index d7827bafd23..5654b28cf56 100644 --- a/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json +++ b/advisories/unreviewed/2024/01/GHSA-46g9-6366-qgqc/GHSA-46g9-6366-qgqc.json @@ -37,6 +37,26 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/27" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-4957-7vhp-7v59/GHSA-4957-7vhp-7v59.json b/advisories/unreviewed/2024/01/GHSA-4957-7vhp-7v59/GHSA-4957-7vhp-7v59.json new file mode 100644 index 00000000000..7dc5362e010 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4957-7vhp-7v59/GHSA-4957-7vhp-7v59.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4957-7vhp-7v59", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0937" + ], + "details": "A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252182 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early and confirmed immediately the existence of the issue. A patch is planned to be released in February 2024.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0937" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-6" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-6/blob/main/poc.py" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252182" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4g25-v4mv-2xm5/GHSA-4g25-v4mv-2xm5.json b/advisories/unreviewed/2024/01/GHSA-4g25-v4mv-2xm5/GHSA-4g25-v4mv-2xm5.json index 650ea9f9283..86fdd40dfb7 100644 --- a/advisories/unreviewed/2024/01/GHSA-4g25-v4mv-2xm5/GHSA-4g25-v4mv-2xm5.json +++ b/advisories/unreviewed/2024/01/GHSA-4g25-v4mv-2xm5/GHSA-4g25-v4mv-2xm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g25-v4mv-2xm5", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51925" ], "details": "An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T02:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4q4m-92jh-42rv/GHSA-4q4m-92jh-42rv.json b/advisories/unreviewed/2024/01/GHSA-4q4m-92jh-42rv/GHSA-4q4m-92jh-42rv.json index ee628e7b4ff..7fd3c647df5 100644 --- a/advisories/unreviewed/2024/01/GHSA-4q4m-92jh-42rv/GHSA-4q4m-92jh-42rv.json +++ b/advisories/unreviewed/2024/01/GHSA-4q4m-92jh-42rv/GHSA-4q4m-92jh-42rv.json @@ -53,6 +53,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213940" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-59xg-4f7f-395p/GHSA-59xg-4f7f-395p.json b/advisories/unreviewed/2024/01/GHSA-59xg-4f7f-395p/GHSA-59xg-4f7f-395p.json new file mode 100644 index 00000000000..1f0b633ee33 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-59xg-4f7f-395p/GHSA-59xg-4f7f-395p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59xg-4f7f-395p", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0933" + ], + "details": "A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \\app\\model\\Upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0933" + }, + { + "type": "WEB", + "url": "https://docs.qq.com/doc/DYnNWeHdTVXZqZURH" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252140" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252140" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6g2q-qmv9-573f/GHSA-6g2q-qmv9-573f.json b/advisories/unreviewed/2024/01/GHSA-6g2q-qmv9-573f/GHSA-6g2q-qmv9-573f.json index 1ad6641af8f..988360ae4f3 100644 --- a/advisories/unreviewed/2024/01/GHSA-6g2q-qmv9-573f/GHSA-6g2q-qmv9-573f.json +++ b/advisories/unreviewed/2024/01/GHSA-6g2q-qmv9-573f/GHSA-6g2q-qmv9-573f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6g2q-qmv9-573f", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-47024" ], "details": "Cross Site Request Forgery vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to obtain sensitive information and escalate privileges via a crafted script to the UserSelfService component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T02:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-6qf7-fwc5-gpgg/GHSA-6qf7-fwc5-gpgg.json b/advisories/unreviewed/2024/01/GHSA-6qf7-fwc5-gpgg/GHSA-6qf7-fwc5-gpgg.json new file mode 100644 index 00000000000..ac2c94cb382 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6qf7-fwc5-gpgg/GHSA-6qf7-fwc5-gpgg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qf7-fwc5-gpgg", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0931" + ], + "details": "A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0931" + }, + { + "type": "WEB", + "url": "https://github.com/yaoyue123/iot/blob/main/Tenda/AC10U/saveParentControlInfo_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252136" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252136" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json b/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json index f222265cbc8..faad40537e8 100644 --- a/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json +++ b/advisories/unreviewed/2024/01/GHSA-7258-xmq8-x5x7/GHSA-7258-xmq8-x5x7.json @@ -37,6 +37,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT214036" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json index 0a234b8f08c..f092067c817 100644 --- a/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json +++ b/advisories/unreviewed/2024/01/GHSA-73m5-j333-fcwc/GHSA-73m5-j333-fcwc.json @@ -41,6 +41,30 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/27" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-7h8c-fcpr-6vff/GHSA-7h8c-fcpr-6vff.json b/advisories/unreviewed/2024/01/GHSA-7h8c-fcpr-6vff/GHSA-7h8c-fcpr-6vff.json new file mode 100644 index 00000000000..487d67fe401 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7h8c-fcpr-6vff/GHSA-7h8c-fcpr-6vff.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h8c-fcpr-6vff", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0928" + ], + "details": "A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. Affected by this vulnerability is the function fromDhcpListClient. The manipulation of the argument page/listN leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0928" + }, + { + "type": "WEB", + "url": "https://github.com/yaoyue123/iot/blob/main/Tenda/AC10U/fromDhcpListClient_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252133" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json b/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json index d245005bc10..0526ccb65a4 100644 --- a/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json +++ b/advisories/unreviewed/2024/01/GHSA-8g27-wpjg-5vv9/GHSA-8g27-wpjg-5vv9.json @@ -29,6 +29,18 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-8j2c-wgm2-c4h8/GHSA-8j2c-wgm2-c4h8.json b/advisories/unreviewed/2024/01/GHSA-8j2c-wgm2-c4h8/GHSA-8j2c-wgm2-c4h8.json new file mode 100644 index 00000000000..b4336b438e8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8j2c-wgm2-c4h8/GHSA-8j2c-wgm2-c4h8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j2c-wgm2-c4h8", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0929" + ], + "details": "A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252134 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0929" + }, + { + "type": "WEB", + "url": "https://github.com/yaoyue123/iot/blob/main/Tenda/AC10U/fromNatStaticSetting.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252134" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252134" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json index 8eeec67bd3f..5988636f9dd 100644 --- a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json +++ b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json @@ -45,6 +45,34 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/27" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json b/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json index 4ecc50e10a9..e58851fcd5d 100644 --- a/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json +++ b/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214059" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-cwg6-4j47-7vj4/GHSA-cwg6-4j47-7vj4.json b/advisories/unreviewed/2024/01/GHSA-cwg6-4j47-7vj4/GHSA-cwg6-4j47-7vj4.json new file mode 100644 index 00000000000..e6f524453b3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cwg6-4j47-7vj4/GHSA-cwg6-4j47-7vj4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwg6-4j47-7vj4", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0930" + ], + "details": "A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252135. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0930" + }, + { + "type": "WEB", + "url": "https://github.com/yaoyue123/iot/blob/main/Tenda/AC10U/fromSetWirelessRepeat.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252135" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f3jq-6wmx-vhvw/GHSA-f3jq-6wmx-vhvw.json b/advisories/unreviewed/2024/01/GHSA-f3jq-6wmx-vhvw/GHSA-f3jq-6wmx-vhvw.json index 3169cb6cc1c..1e767373ef2 100644 --- a/advisories/unreviewed/2024/01/GHSA-f3jq-6wmx-vhvw/GHSA-f3jq-6wmx-vhvw.json +++ b/advisories/unreviewed/2024/01/GHSA-f3jq-6wmx-vhvw/GHSA-f3jq-6wmx-vhvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3jq-6wmx-vhvw", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51892" ], "details": "An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T01:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json b/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json index a8d48d2becd..a05bb1c2d90 100644 --- a/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json +++ b/advisories/unreviewed/2024/01/GHSA-f8vm-23j7-pf2r/GHSA-f8vm-23j7-pf2r.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fj9j-r9xc-pv7f/GHSA-fj9j-r9xc-pv7f.json b/advisories/unreviewed/2024/01/GHSA-fj9j-r9xc-pv7f/GHSA-fj9j-r9xc-pv7f.json index 3c41edb01ff..668a484e905 100644 --- a/advisories/unreviewed/2024/01/GHSA-fj9j-r9xc-pv7f/GHSA-fj9j-r9xc-pv7f.json +++ b/advisories/unreviewed/2024/01/GHSA-fj9j-r9xc-pv7f/GHSA-fj9j-r9xc-pv7f.json @@ -25,6 +25,14 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fw68-2r4f-9r26/GHSA-fw68-2r4f-9r26.json b/advisories/unreviewed/2024/01/GHSA-fw68-2r4f-9r26/GHSA-fw68-2r4f-9r26.json index 556d623c9ba..f015ee416f5 100644 --- a/advisories/unreviewed/2024/01/GHSA-fw68-2r4f-9r26/GHSA-fw68-2r4f-9r26.json +++ b/advisories/unreviewed/2024/01/GHSA-fw68-2r4f-9r26/GHSA-fw68-2r4f-9r26.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fwm9-7w87-mfmp/GHSA-fwm9-7w87-mfmp.json b/advisories/unreviewed/2024/01/GHSA-fwm9-7w87-mfmp/GHSA-fwm9-7w87-mfmp.json new file mode 100644 index 00000000000..863e3a2ad2e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fwm9-7w87-mfmp/GHSA-fwm9-7w87-mfmp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwm9-7w87-mfmp", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0936" + ], + "details": "A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252181 was assigned to this vulnerability. NOTE: The vendor was contacted early and confirmed immediately the existence of the issue. A patch is planned to be released in February 2024.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0936" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-5" + }, + { + "type": "WEB", + "url": "https://github.com/bayuncao/vul-cve-5/blob/main/poc.py" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252181" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252181" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json b/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json index 982968a3ab7..a1ea006f760 100644 --- a/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json +++ b/advisories/unreviewed/2024/01/GHSA-gqqw-gq22-ww82/GHSA-gqqw-gq22-ww82.json @@ -53,6 +53,18 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT214041" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-gxh9-cf3g-3v7f/GHSA-gxh9-cf3g-3v7f.json b/advisories/unreviewed/2024/01/GHSA-gxh9-cf3g-3v7f/GHSA-gxh9-cf3g-3v7f.json new file mode 100644 index 00000000000..beee5394642 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gxh9-cf3g-3v7f/GHSA-gxh9-cf3g-3v7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxh9-cf3g-3v7f", + "modified": "2024-01-26T18:30:35Z", + "published": "2024-01-26T18:30:35Z", + "aliases": [ + "CVE-2024-20253" + ], + "details": "A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20253" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-rce-bWNzQcUm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json b/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json index 5c670b15ed8..2d29bb2a72d 100644 --- a/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json +++ b/advisories/unreviewed/2024/01/GHSA-h3x8-jx27-7vw4/GHSA-h3x8-jx27-7vw4.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-h49c-jgw7-9grp/GHSA-h49c-jgw7-9grp.json b/advisories/unreviewed/2024/01/GHSA-h49c-jgw7-9grp/GHSA-h49c-jgw7-9grp.json new file mode 100644 index 00000000000..35680151662 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h49c-jgw7-9grp/GHSA-h49c-jgw7-9grp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h49c-jgw7-9grp", + "modified": "2024-01-26T18:30:35Z", + "published": "2024-01-26T18:30:35Z", + "aliases": [ + "CVE-2024-20263" + ], + "details": "A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. This vulnerability is due to incorrect processing of ACLs on a stacked configuration when either the primary or backup switches experience a full stack reload or power cycle. An attacker could exploit this vulnerability by sending crafted traffic through an affected device. A successful exploit could allow the attacker to bypass configured ACLs, causing traffic to be dropped or forwarded in an unexpected manner. The attacker does not have control over the conditions that result in the device being in the vulnerable state. Note: In the vulnerable state, the ACL would be correctly applied on the primary devices but could be incorrectly applied to the backup devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20263" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-bus-acl-bypass-5zn9hNJk" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hq74-5cxf-phqw/GHSA-hq74-5cxf-phqw.json b/advisories/unreviewed/2024/01/GHSA-hq74-5cxf-phqw/GHSA-hq74-5cxf-phqw.json index a9f16074610..d09c882afc0 100644 --- a/advisories/unreviewed/2024/01/GHSA-hq74-5cxf-phqw/GHSA-hq74-5cxf-phqw.json +++ b/advisories/unreviewed/2024/01/GHSA-hq74-5cxf-phqw/GHSA-hq74-5cxf-phqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq74-5cxf-phqw", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51927" ], "details": "YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T01:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-hrvq-3565-fq43/GHSA-hrvq-3565-fq43.json b/advisories/unreviewed/2024/01/GHSA-hrvq-3565-fq43/GHSA-hrvq-3565-fq43.json index 83bbdab715f..abcd511ab87 100644 --- a/advisories/unreviewed/2024/01/GHSA-hrvq-3565-fq43/GHSA-hrvq-3565-fq43.json +++ b/advisories/unreviewed/2024/01/GHSA-hrvq-3565-fq43/GHSA-hrvq-3565-fq43.json @@ -29,6 +29,18 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json b/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json new file mode 100644 index 00000000000..e5c9fcb61b6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j4wq-qx9v-xvqj/GHSA-j4wq-qx9v-xvqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4wq-qx9v-xvqj", + "modified": "2024-01-26T18:30:35Z", + "published": "2024-01-26T18:30:35Z", + "aliases": [ + "CVE-2024-21336" + ], + "details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21336" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21336" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jc3c-72g2-mm2j/GHSA-jc3c-72g2-mm2j.json b/advisories/unreviewed/2024/01/GHSA-jc3c-72g2-mm2j/GHSA-jc3c-72g2-mm2j.json index a12567b4642..b3740dfceff 100644 --- a/advisories/unreviewed/2024/01/GHSA-jc3c-72g2-mm2j/GHSA-jc3c-72g2-mm2j.json +++ b/advisories/unreviewed/2024/01/GHSA-jc3c-72g2-mm2j/GHSA-jc3c-72g2-mm2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc3c-72g2-mm2j", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51906" ], "details": "An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T02:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-m9p3-73xg-xgfx/GHSA-m9p3-73xg-xgfx.json b/advisories/unreviewed/2024/01/GHSA-m9p3-73xg-xgfx/GHSA-m9p3-73xg-xgfx.json index aad4d35f4da..2bfd6212542 100644 --- a/advisories/unreviewed/2024/01/GHSA-m9p3-73xg-xgfx/GHSA-m9p3-73xg-xgfx.json +++ b/advisories/unreviewed/2024/01/GHSA-m9p3-73xg-xgfx/GHSA-m9p3-73xg-xgfx.json @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT214036" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-p7hc-wp5x-pvx7/GHSA-p7hc-wp5x-pvx7.json b/advisories/unreviewed/2024/01/GHSA-p7hc-wp5x-pvx7/GHSA-p7hc-wp5x-pvx7.json new file mode 100644 index 00000000000..4161bf8ac8b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p7hc-wp5x-pvx7/GHSA-p7hc-wp5x-pvx7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hc-wp5x-pvx7", + "modified": "2024-01-26T18:30:34Z", + "published": "2024-01-26T18:30:34Z", + "aliases": [ + "CVE-2024-0932" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This issue affects the function setSmartPowerManagement. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252137 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0932" + }, + { + "type": "WEB", + "url": "https://github.com/yaoyue123/iot/blob/main/Tenda/AC10U/setSmartPowerManagement.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252137" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json b/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json index 1f3c89ad795..74ee3f6142e 100644 --- a/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json +++ b/advisories/unreviewed/2024/01/GHSA-qh5h-jvwg-m9xw/GHSA-qh5h-jvwg-m9xw.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json b/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json index 9d08e413116..ae51595727f 100644 --- a/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json +++ b/advisories/unreviewed/2024/01/GHSA-qwm3-5pgj-28qh/GHSA-qwm3-5pgj-28qh.json @@ -45,6 +45,34 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214063" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/34" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/38" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json b/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json index a425885cc27..0b4a5af508a 100644 --- a/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json +++ b/advisories/unreviewed/2024/01/GHSA-r2mg-qw96-w89q/GHSA-r2mg-qw96-w89q.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json b/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json index 654e4c6e346..21bdb3456fa 100644 --- a/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json +++ b/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://blog.cloudlinux.com/cagefs-lve-wrappers-and-bsock-have-been-rolled-out-to-100" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176790/CloudLinux-CageFS-7.1.1-1-Token-Disclosure.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/24" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-vf8q-f3vp-ccgf/GHSA-vf8q-f3vp-ccgf.json b/advisories/unreviewed/2024/01/GHSA-vf8q-f3vp-ccgf/GHSA-vf8q-f3vp-ccgf.json index d2d57d102e7..dd9c7712a47 100644 --- a/advisories/unreviewed/2024/01/GHSA-vf8q-f3vp-ccgf/GHSA-vf8q-f3vp-ccgf.json +++ b/advisories/unreviewed/2024/01/GHSA-vf8q-f3vp-ccgf/GHSA-vf8q-f3vp-ccgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf8q-f3vp-ccgf", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51924" ], "details": "An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T02:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json b/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json index 862e868a753..52090ad4a5a 100644 --- a/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json +++ b/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w64x-j9r3-q79q", - "modified": "2024-01-24T15:30:29Z", + "modified": "2024-01-26T18:30:32Z", "published": "2024-01-16T06:30:31Z", "aliases": [ "CVE-2023-22527" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://jira.atlassian.com/browse/CONFSERVER-93833" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176789/Atlassian-Confluence-SSTI-Injection.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-w84c-xcg5-6p7x/GHSA-w84c-xcg5-6p7x.json b/advisories/unreviewed/2024/01/GHSA-w84c-xcg5-6p7x/GHSA-w84c-xcg5-6p7x.json new file mode 100644 index 00000000000..30eac951b18 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w84c-xcg5-6p7x/GHSA-w84c-xcg5-6p7x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w84c-xcg5-6p7x", + "modified": "2024-01-26T18:30:35Z", + "published": "2024-01-26T18:30:35Z", + "aliases": [ + "CVE-2024-0938" + ], + "details": "A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file /general/email/inbox/delete_webmail.php. The manipulation of the argument WEBBODY_ID_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252183. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0938" + }, + { + "type": "WEB", + "url": "https://github.com/Yu1e/vuls/blob/main/SQL%20injection%20vulnerability%20exists%20in%20Tongda%20OA.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252183" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-26T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wp4m-7hpj-8qp8/GHSA-wp4m-7hpj-8qp8.json b/advisories/unreviewed/2024/01/GHSA-wp4m-7hpj-8qp8/GHSA-wp4m-7hpj-8qp8.json index 1fbfc32ae47..4170173510e 100644 --- a/advisories/unreviewed/2024/01/GHSA-wp4m-7hpj-8qp8/GHSA-wp4m-7hpj-8qp8.json +++ b/advisories/unreviewed/2024/01/GHSA-wp4m-7hpj-8qp8/GHSA-wp4m-7hpj-8qp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp4m-7hpj-8qp8", - "modified": "2024-01-20T00:30:27Z", + "modified": "2024-01-26T18:30:32Z", "published": "2024-01-20T00:30:27Z", "aliases": [ "CVE-2024-23688" ], "details": "Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-323" + "CWE-323", + "CWE-330" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-19T22:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-wq93-576j-8q58/GHSA-wq93-576j-8q58.json b/advisories/unreviewed/2024/01/GHSA-wq93-576j-8q58/GHSA-wq93-576j-8q58.json index 85425d299d6..2ab24774807 100644 --- a/advisories/unreviewed/2024/01/GHSA-wq93-576j-8q58/GHSA-wq93-576j-8q58.json +++ b/advisories/unreviewed/2024/01/GHSA-wq93-576j-8q58/GHSA-wq93-576j-8q58.json @@ -33,6 +33,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/33" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/39" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/40" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json b/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json index 5a944c4336f..ce10beb68d9 100644 --- a/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json +++ b/advisories/unreviewed/2024/01/GHSA-x8jc-9x8v-27f5/GHSA-x8jc-9x8v-27f5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8jc-9x8v-27f5", - "modified": "2024-01-23T03:31:07Z", + "modified": "2024-01-26T18:30:34Z", "published": "2024-01-23T03:31:07Z", "aliases": [ "CVE-2023-42935" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/kb/HT213984" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json b/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json index 88901307081..33df53220b0 100644 --- a/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json +++ b/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://blog.cloudlinux.com/lve-manager-lve-stats-lve-utils-and-alt-python27-cllib-have-been-rolled-out-to-100" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176791/CloudLinux-CageFS-7.0.8-2-Insufficiently-Restricted-Proxy-Command.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/25" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-xhgx-qvgm-xg3q/GHSA-xhgx-qvgm-xg3q.json b/advisories/unreviewed/2024/01/GHSA-xhgx-qvgm-xg3q/GHSA-xhgx-qvgm-xg3q.json index 12e1757b8b6..af0099abf5e 100644 --- a/advisories/unreviewed/2024/01/GHSA-xhgx-qvgm-xg3q/GHSA-xhgx-qvgm-xg3q.json +++ b/advisories/unreviewed/2024/01/GHSA-xhgx-qvgm-xg3q/GHSA-xhgx-qvgm-xg3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhgx-qvgm-xg3q", - "modified": "2024-01-20T03:30:29Z", + "modified": "2024-01-26T18:30:33Z", "published": "2024-01-20T03:30:29Z", "aliases": [ "CVE-2023-51926" ], "details": "YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-20T01:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xw66-fwrq-35x6/GHSA-xw66-fwrq-35x6.json b/advisories/unreviewed/2024/01/GHSA-xw66-fwrq-35x6/GHSA-xw66-fwrq-35x6.json index 7c4ac9ba871..550f3abdb03 100644 --- a/advisories/unreviewed/2024/01/GHSA-xw66-fwrq-35x6/GHSA-xw66-fwrq-35x6.json +++ b/advisories/unreviewed/2024/01/GHSA-xw66-fwrq-35x6/GHSA-xw66-fwrq-35x6.json @@ -25,6 +25,14 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/HT214061" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/36" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Jan/37" } ], "database_specific": {