From 84ee08844f69960e9dc025700f539d9264eaebe7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 5 Nov 2024 21:32:07 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mgcr-5hwm-m58m.json | 2 +- .../GHSA-327h-468p-mffv.json | 11 ++++-- .../GHSA-528v-fv7h-v892.json | 4 +- .../GHSA-9m3j-vpcw-4f37.json | 9 +++-- .../GHSA-gp6j-7c6x-xpmx.json | 11 ++++-- .../GHSA-h3cg-9jm8-7468.json | 9 +++-- .../GHSA-p9j3-jrc9-jv9h.json | 11 ++++-- .../GHSA-35c8-rp3m-p5v6.json | 9 +++-- .../GHSA-52jg-m3rm-ch68.json | 1 + .../GHSA-5gr3-55rj-mm4c.json | 9 +++-- .../GHSA-9475-r4q8-rfwm.json | 9 +++-- .../GHSA-mxh6-2xpg-m77w.json | 9 +++-- .../GHSA-pp36-2qc2-w4hw.json | 9 +++-- .../GHSA-9fvf-9v35-97qv.json | 11 ++++-- .../GHSA-c8hq-5hxw-3w26.json | 9 +++-- .../GHSA-h63r-7v46-7432.json | 11 ++++-- .../GHSA-hjw5-rhfw-qhhq.json | 11 ++++-- .../GHSA-qp44-g28j-qgqp.json | 9 +++-- .../GHSA-x246-w3fc-9p6h.json | 11 ++++-- .../GHSA-x8m6-m5rq-285x.json | 11 ++++-- .../GHSA-22hg-74mg-cj6f.json | 11 ++++-- .../GHSA-5h68-7cjq-vgrx.json | 11 ++++-- .../GHSA-h37j-8pp8-r22g.json | 11 ++++-- .../GHSA-h765-5xqm-7h48.json | 9 +++-- .../GHSA-w9j3-89mr-p378.json | 9 +++-- .../GHSA-6g69-qf5f-hcwq.json | 2 +- .../GHSA-gg9v-4hff-mc2m.json | 2 +- .../GHSA-w2jv-599h-mr48.json | 2 +- .../GHSA-c2vh-2vcm-gqjq.json | 9 +++-- .../GHSA-58m7-hfr6-rrx2.json | 11 ++++-- .../GHSA-hfvw-6r46-qm8f.json | 1 + .../GHSA-pwf9-7hmp-q2xf.json | 11 ++++-- .../GHSA-q7v6-v4wg-h8m2.json | 11 ++++-- .../GHSA-qc52-868v-6vh4.json | 11 ++++-- .../GHSA-vwp4-85g8-fgjg.json | 3 +- .../GHSA-22h9-mj69-54jf.json | 11 ++++-- .../GHSA-23gq-5hj3-m433.json | 9 +++-- .../GHSA-2hfc-prjx-wjcx.json | 11 ++++-- .../GHSA-2m6f-fj9h-6vmp.json | 11 ++++-- .../GHSA-4qm8-phhf-q2q2.json | 2 +- .../GHSA-5grf-38mv-vxvv.json | 35 +++++++++++++++++ .../GHSA-7hpj-6m83-46cj.json | 11 ++++-- .../GHSA-7jm9-xpwx-v999.json | 38 +++++++++++++++++++ .../GHSA-9hqw-38w2-29xc.json | 38 +++++++++++++++++++ .../GHSA-f63j-xmq2-hrpg.json | 11 ++++-- .../GHSA-g7rx-xjjw-j9xq.json | 2 +- .../GHSA-gcgg-hvp7-xgf7.json | 9 +++-- .../GHSA-hm22-mpqr-wp46.json | 11 ++++-- .../GHSA-hm9x-5qmp-g6fq.json | 35 +++++++++++++++++ .../GHSA-hv6q-xm2j-9hqv.json | 11 ++++-- .../GHSA-qvc8-jp6r-8639.json | 35 +++++++++++++++++ .../GHSA-rcx3-jx8c-54gq.json | 11 ++++-- .../GHSA-rrg7-hv9c-7q66.json | 11 ++++-- .../GHSA-vvmx-2vhq-c359.json | 11 ++++-- .../GHSA-w9pr-cvj2-cxfc.json | 35 +++++++++++++++++ .../GHSA-x4vq-mwg4-r55q.json | 11 ++++-- .../GHSA-xv9r-mhj6-33xr.json | 35 +++++++++++++++++ 57 files changed, 529 insertions(+), 155 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7jm9-xpwx-v999/GHSA-7jm9-xpwx-v999.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9hqw-38w2-29xc/GHSA-9hqw-38w2-29xc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json diff --git a/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json b/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json index 213d852253c..4d4cd84e1f1 100644 --- a/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json +++ b/advisories/unreviewed/2023/07/GHSA-mgcr-5hwm-m58m/GHSA-mgcr-5hwm-m58m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json b/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json index 35c669d9272..1f44cf10750 100644 --- a/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json +++ b/advisories/unreviewed/2024/02/GHSA-327h-468p-mffv/GHSA-327h-468p-mffv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-327h-468p-mffv", - "modified": "2024-02-27T03:31:02Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-02-27T03:31:02Z", "aliases": [ "CVE-2024-24096" ], "details": "Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T02:15:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json b/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json index 328a97ebef4..b1aabec6b01 100644 --- a/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json +++ b/advisories/unreviewed/2024/02/GHSA-528v-fv7h-v892/GHSA-528v-fv7h-v892.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-528v-fv7h-v892", - "modified": "2024-02-29T03:33:12Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-02-29T03:33:12Z", "aliases": [ "CVE-2023-37495" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json index 790ddd9536c..a1916122944 100644 --- a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json +++ b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m3j-vpcw-4f37", - "modified": "2024-03-04T09:30:29Z", + "modified": "2024-11-05T21:30:30Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1548" ], "details": "A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json b/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json index 5b67d0d8f59..40d78806d29 100644 --- a/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json +++ b/advisories/unreviewed/2024/02/GHSA-gp6j-7c6x-xpmx/GHSA-gp6j-7c6x-xpmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp6j-7c6x-xpmx", - "modified": "2024-02-27T03:31:02Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-02-27T03:31:02Z", "aliases": [ "CVE-2024-24095" ], "details": "Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T02:15:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json b/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json index 9bc9d9622fb..a146efc8595 100644 --- a/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json +++ b/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3cg-9jm8-7468", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42858" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:49Z" diff --git a/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json b/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json index ffb03f1afb7..86f857bd9bb 100644 --- a/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json +++ b/advisories/unreviewed/2024/02/GHSA-p9j3-jrc9-jv9h/GHSA-p9j3-jrc9-jv9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9j3-jrc9-jv9h", - "modified": "2024-02-29T03:33:14Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-02-29T03:33:14Z", "aliases": [ "CVE-2023-49932" ], "details": "An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-281" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:41:40Z" diff --git a/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json b/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json index 7253719e88f..635297d99ff 100644 --- a/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json +++ b/advisories/unreviewed/2024/03/GHSA-35c8-rp3m-p5v6/GHSA-35c8-rp3m-p5v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35c8-rp3m-p5v6", - "modified": "2024-03-21T06:33:04Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-03-21T06:33:04Z", "aliases": [ "CVE-2024-29862" ], "details": "The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json b/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json index 62a24e4ac10..6e304a75a93 100644 --- a/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json +++ b/advisories/unreviewed/2024/03/GHSA-52jg-m3rm-ch68/GHSA-52jg-m3rm-ch68.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-26" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json b/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json index 7d34d543b2f..07cffe68c7a 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json +++ b/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gr3-55rj-mm4c", - "modified": "2024-03-04T18:30:38Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-03-04T18:30:38Z", "aliases": [ "CVE-2021-47096" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: rawmidi - fix the uninitalized user_pversion\n\nThe user_pversion was uninitialized for the user space file structure\nin the open function, because the file private structure use\nkmalloc for the allocation.\n\nThe kernel ALSA sequencer code clears the file structure, so no additional\nfixes are required.\n\nBugLink: https://github.com/alsa-project/alsa-lib/issues/178", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T18:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json b/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json index 145a00db1b2..32ad25ae387 100644 --- a/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json +++ b/advisories/unreviewed/2024/03/GHSA-9475-r4q8-rfwm/GHSA-9475-r4q8-rfwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9475-r4q8-rfwm", - "modified": "2024-03-13T21:31:01Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-03-05T21:30:25Z", "aliases": [ "CVE-2024-23256" ], "details": "A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T20:16:01Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json b/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json index 46a627f02b7..0084725e12d 100644 --- a/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json +++ b/advisories/unreviewed/2024/03/GHSA-mxh6-2xpg-m77w/GHSA-mxh6-2xpg-m77w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxh6-2xpg-m77w", - "modified": "2024-03-23T03:30:25Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-03-20T15:32:57Z", "aliases": [ "CVE-2023-46841" ], "details": "Recent x86 CPUs offer functionality named Control-flow Enforcement\nTechnology (CET). A sub-feature of this are Shadow Stacks (CET-SS).\nCET-SS is a hardware feature designed to protect against Return Oriented\nProgramming attacks. When enabled, traditional stacks holding both data\nand return addresses are accompanied by so called \"shadow stacks\",\nholding little more than return addresses. Shadow stacks aren't\nwritable by normal instructions, and upon function returns their\ncontents are used to check for possible manipulation of a return address\ncoming from the traditional stack.\n\nIn particular certain memory accesses need intercepting by Xen. In\nvarious cases the necessary emulation involves kind of replaying of\nthe instruction. Such replaying typically involves filling and then\ninvoking of a stub. Such a replayed instruction may raise an\nexceptions, which is expected and dealt with accordingly.\n\nUnfortunately the interaction of both of the above wasn't right:\nRecovery involves removal of a call frame from the (traditional) stack.\nThe counterpart of this operation for the shadow stack was missing.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T11:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json b/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json index a72bb2560bb..e55cfd95ec3 100644 --- a/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json +++ b/advisories/unreviewed/2024/03/GHSA-pp36-2qc2-w4hw/GHSA-pp36-2qc2-w4hw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp36-2qc2-w4hw", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-03-18T12:30:35Z", "aliases": [ "CVE-2024-26633" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()\n\nsyzbot pointed out [1] that NEXTHDR_FRAGMENT handling is broken.\n\nReading frag_off can only be done if we pulled enough bytes\nto skb->head. Currently we might access garbage.\n\n[1]\nBUG: KMSAN: uninit-value in ip6_tnl_parse_tlv_enc_lim+0x94f/0xbb0\nip6_tnl_parse_tlv_enc_lim+0x94f/0xbb0\nipxip6_tnl_xmit net/ipv6/ip6_tunnel.c:1326 [inline]\nip6_tnl_start_xmit+0xab2/0x1a70 net/ipv6/ip6_tunnel.c:1432\n__netdev_start_xmit include/linux/netdevice.h:4940 [inline]\nnetdev_start_xmit include/linux/netdevice.h:4954 [inline]\nxmit_one net/core/dev.c:3548 [inline]\ndev_hard_start_xmit+0x247/0xa10 net/core/dev.c:3564\n__dev_queue_xmit+0x33b8/0x5130 net/core/dev.c:4349\ndev_queue_xmit include/linux/netdevice.h:3134 [inline]\nneigh_connected_output+0x569/0x660 net/core/neighbour.c:1592\nneigh_output include/net/neighbour.h:542 [inline]\nip6_finish_output2+0x23a9/0x2b30 net/ipv6/ip6_output.c:137\nip6_finish_output+0x855/0x12b0 net/ipv6/ip6_output.c:222\nNF_HOOK_COND include/linux/netfilter.h:303 [inline]\nip6_output+0x323/0x610 net/ipv6/ip6_output.c:243\ndst_output include/net/dst.h:451 [inline]\nip6_local_out+0xe9/0x140 net/ipv6/output_core.c:155\nip6_send_skb net/ipv6/ip6_output.c:1952 [inline]\nip6_push_pending_frames+0x1f9/0x560 net/ipv6/ip6_output.c:1972\nrawv6_push_pending_frames+0xbe8/0xdf0 net/ipv6/raw.c:582\nrawv6_sendmsg+0x2b66/0x2e70 net/ipv6/raw.c:920\ninet_sendmsg+0x105/0x190 net/ipv4/af_inet.c:847\nsock_sendmsg_nosec net/socket.c:730 [inline]\n__sock_sendmsg net/socket.c:745 [inline]\n____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n__sys_sendmsg net/socket.c:2667 [inline]\n__do_sys_sendmsg net/socket.c:2676 [inline]\n__se_sys_sendmsg net/socket.c:2674 [inline]\n__x64_sys_sendmsg+0x307/0x490 net/socket.c:2674\ndo_syscall_x64 arch/x86/entry/common.c:52 [inline]\ndo_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\nentry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\nslab_post_alloc_hook+0x129/0xa70 mm/slab.h:768\nslab_alloc_node mm/slub.c:3478 [inline]\n__kmem_cache_alloc_node+0x5c9/0x970 mm/slub.c:3517\n__do_kmalloc_node mm/slab_common.c:1006 [inline]\n__kmalloc_node_track_caller+0x118/0x3c0 mm/slab_common.c:1027\nkmalloc_reserve+0x249/0x4a0 net/core/skbuff.c:582\npskb_expand_head+0x226/0x1a00 net/core/skbuff.c:2098\n__pskb_pull_tail+0x13b/0x2310 net/core/skbuff.c:2655\npskb_may_pull_reason include/linux/skbuff.h:2673 [inline]\npskb_may_pull include/linux/skbuff.h:2681 [inline]\nip6_tnl_parse_tlv_enc_lim+0x901/0xbb0 net/ipv6/ip6_tunnel.c:408\nipxip6_tnl_xmit net/ipv6/ip6_tunnel.c:1326 [inline]\nip6_tnl_start_xmit+0xab2/0x1a70 net/ipv6/ip6_tunnel.c:1432\n__netdev_start_xmit include/linux/netdevice.h:4940 [inline]\nnetdev_start_xmit include/linux/netdevice.h:4954 [inline]\nxmit_one net/core/dev.c:3548 [inline]\ndev_hard_start_xmit+0x247/0xa10 net/core/dev.c:3564\n__dev_queue_xmit+0x33b8/0x5130 net/core/dev.c:4349\ndev_queue_xmit include/linux/netdevice.h:3134 [inline]\nneigh_connected_output+0x569/0x660 net/core/neighbour.c:1592\nneigh_output include/net/neighbour.h:542 [inline]\nip6_finish_output2+0x23a9/0x2b30 net/ipv6/ip6_output.c:137\nip6_finish_output+0x855/0x12b0 net/ipv6/ip6_output.c:222\nNF_HOOK_COND include/linux/netfilter.h:303 [inline]\nip6_output+0x323/0x610 net/ipv6/ip6_output.c:243\ndst_output include/net/dst.h:451 [inline]\nip6_local_out+0xe9/0x140 net/ipv6/output_core.c:155\nip6_send_skb net/ipv6/ip6_output.c:1952 [inline]\nip6_push_pending_frames+0x1f9/0x560 net/ipv6/ip6_output.c:1972\nrawv6_push_pending_frames+0xbe8/0xdf0 net/ipv6/raw.c:582\nrawv6_sendmsg+0x2b66/0x2e70 net/ipv6/raw.c:920\ninet_sendmsg+0x105/0x190 net/ipv4/af_inet.c:847\nsock_sendmsg_nosec net/socket.c:730 [inline]\n__sock_sendmsg net/socket.c:745 [inline]\n____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n__sys_sendmsg net/socket.c:2667 [inline]\n__do_sys_sendms\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T11:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json b/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json index 437450701a8..41b9a05ee90 100644 --- a/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json +++ b/advisories/unreviewed/2024/04/GHSA-9fvf-9v35-97qv/GHSA-9fvf-9v35-97qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fvf-9v35-97qv", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-04T21:30:30Z", "aliases": [ "CVE-2023-38709" ], "details": "Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.\n\nThis issue affects Apache HTTP Server: through 2.4.58.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json b/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json index 31819501530..765b303a277 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json +++ b/advisories/unreviewed/2024/04/GHSA-c8hq-5hxw-3w26/GHSA-c8hq-5hxw-3w26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8hq-5hxw-3w26", - "modified": "2024-04-02T09:30:41Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26676" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Call kfree_skb() for dead unix_(sk)->oob_skb in GC.\n\nsyzbot reported a warning [0] in __unix_gc() with a repro, which\ncreates a socketpair and sends one socket's fd to itself using the\npeer.\n\n socketpair(AF_UNIX, SOCK_STREAM, 0, [3, 4]) = 0\n sendmsg(4, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base=\"\\360\", iov_len=1}],\n msg_iovlen=1, msg_control=[{cmsg_len=20, cmsg_level=SOL_SOCKET,\n cmsg_type=SCM_RIGHTS, cmsg_data=[3]}],\n msg_controllen=24, msg_flags=0}, MSG_OOB|MSG_PROBE|MSG_DONTWAIT|MSG_ZEROCOPY) = 1\n\nThis forms a self-cyclic reference that GC should finally untangle\nbut does not due to lack of MSG_OOB handling, resulting in memory\nleak.\n\nRecently, commit 11498715f266 (\"af_unix: Remove io_uring code for\nGC.\") removed io_uring's dead code in GC and revealed the problem.\n\nThe code was executed at the final stage of GC and unconditionally\nmoved all GC candidates from gc_candidates to gc_inflight_list.\nThat papered over the reported problem by always making the following\nWARN_ON_ONCE(!list_empty(&gc_candidates)) false.\n\nThe problem has been there since commit 2aab4b969002 (\"af_unix: fix\nstruct pid leaks in OOB support\") added full scm support for MSG_OOB\nwhile fixing another bug.\n\nTo fix this problem, we must call kfree_skb() for unix_sk(sk)->oob_skb\nif the socket still exists in gc_candidates after purging collected skb.\n\nThen, we need to set NULL to oob_skb before calling kfree_skb() because\nit calls last fput() and triggers unix_release_sock(), where we call\nduplicate kfree_skb(u->oob_skb) if not NULL.\n\nNote that the leaked socket remained being linked to a global list, so\nkmemleak also could not detect it. We need to check /proc/net/protocol\nto notice the unfreed socket.\n\n[0]:\nWARNING: CPU: 0 PID: 2863 at net/unix/garbage.c:345 __unix_gc+0xc74/0xe80 net/unix/garbage.c:345\nModules linked in:\nCPU: 0 PID: 2863 Comm: kworker/u4:11 Not tainted 6.8.0-rc1-syzkaller-00583-g1701940b1a02 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nWorkqueue: events_unbound __unix_gc\nRIP: 0010:__unix_gc+0xc74/0xe80 net/unix/garbage.c:345\nCode: 8b 5c 24 50 e9 86 f8 ff ff e8 f8 e4 22 f8 31 d2 48 c7 c6 30 6a 69 89 4c 89 ef e8 97 ef ff ff e9 80 f9 ff ff e8 dd e4 22 f8 90 <0f> 0b 90 e9 7b fd ff ff 48 89 df e8 5c e7 7c f8 e9 d3 f8 ff ff e8\nRSP: 0018:ffffc9000b03fba0 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffffc9000b03fc10 RCX: ffffffff816c493e\nRDX: ffff88802c02d940 RSI: ffffffff896982f3 RDI: ffffc9000b03fb30\nRBP: ffffc9000b03fce0 R08: 0000000000000001 R09: fffff52001607f66\nR10: 0000000000000003 R11: 0000000000000002 R12: dffffc0000000000\nR13: ffffc9000b03fc10 R14: ffffc9000b03fc10 R15: 0000000000000001\nFS: 0000000000000000(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005559c8677a60 CR3: 000000000d57a000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n process_one_work+0x889/0x15e0 kernel/workqueue.c:2633\n process_scheduled_works kernel/workqueue.c:2706 [inline]\n worker_thread+0x8b9/0x12a0 kernel/workqueue.c:2787\n kthread+0x2c6/0x3b0 kernel/kthread.c:388\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:242\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json b/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json index 0ac9805543d..b1089d2fec3 100644 --- a/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json +++ b/advisories/unreviewed/2024/04/GHSA-h63r-7v46-7432/GHSA-h63r-7v46-7432.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h63r-7v46-7432", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52554" ], "details": "Permission control vulnerability in the Bluetooth module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hjw5-rhfw-qhhq/GHSA-hjw5-rhfw-qhhq.json b/advisories/unreviewed/2024/04/GHSA-hjw5-rhfw-qhhq/GHSA-hjw5-rhfw-qhhq.json index c8412a3717f..9f3bfe2179b 100644 --- a/advisories/unreviewed/2024/04/GHSA-hjw5-rhfw-qhhq/GHSA-hjw5-rhfw-qhhq.json +++ b/advisories/unreviewed/2024/04/GHSA-hjw5-rhfw-qhhq/GHSA-hjw5-rhfw-qhhq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjw5-rhfw-qhhq", - "modified": "2024-04-22T18:30:47Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-22T18:30:47Z", "aliases": [ "CVE-2024-28436" ], "details": "Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-22T17:15:39Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json b/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json index d6db3b642ab..ea26201057f 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json +++ b/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp44-g28j-qgqp", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32299" ], "details": "Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json b/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json index fbde5877e7b..e60e7f946cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json +++ b/advisories/unreviewed/2024/04/GHSA-x246-w3fc-9p6h/GHSA-x246-w3fc-9p6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x246-w3fc-9p6h", - "modified": "2024-04-07T09:30:28Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-07T09:30:28Z", "aliases": [ "CVE-2024-30415" ], "details": "Vulnerability of improper permission control in the window management module.\nImpact: Successful exploitation of this vulnerability will affect availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T08:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json b/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json index 05f224a0940..7ca8c562480 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json +++ b/advisories/unreviewed/2024/04/GHSA-x8m6-m5rq-285x/GHSA-x8m6-m5rq-285x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8m6-m5rq-285x", - "modified": "2024-04-08T03:30:52Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-04-08T03:30:52Z", "aliases": [ "CVE-2023-52534" ], "details": "In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T03:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-22hg-74mg-cj6f/GHSA-22hg-74mg-cj6f.json b/advisories/unreviewed/2024/05/GHSA-22hg-74mg-cj6f/GHSA-22hg-74mg-cj6f.json index 4621cd5d60b..882d3183a60 100644 --- a/advisories/unreviewed/2024/05/GHSA-22hg-74mg-cj6f/GHSA-22hg-74mg-cj6f.json +++ b/advisories/unreviewed/2024/05/GHSA-22hg-74mg-cj6f/GHSA-22hg-74mg-cj6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22hg-74mg-cj6f", - "modified": "2024-06-27T12:30:46Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-05-20T12:30:28Z", "aliases": [ "CVE-2024-35969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr\n\nAlthough ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it\nstill means hlist_for_each_entry_rcu can return an item that got removed\nfrom the list. The memory itself of such item is not freed thanks to RCU\nbut nothing guarantees the actual content of the memory is sane.\n\nIn particular, the reference count can be zero. This can happen if\nipv6_del_addr is called in parallel. ipv6_del_addr removes the entry\nfrom inet6_addr_lst (hlist_del_init_rcu(&ifp->addr_lst)) and drops all\nreferences (__in6_ifa_put(ifp) + in6_ifa_put(ifp)). With bad enough\ntiming, this can happen:\n\n1. In ipv6_get_ifaddr, hlist_for_each_entry_rcu returns an entry.\n\n2. Then, the whole ipv6_del_addr is executed for the given entry. The\n reference count drops to zero and kfree_rcu is scheduled.\n\n3. ipv6_get_ifaddr continues and tries to increments the reference count\n (in6_ifa_hold).\n\n4. The rcu is unlocked and the entry is freed.\n\n5. The freed entry is returned.\n\nPrevent increasing of the reference count in such case. The name\nin6_ifa_hold_safe is chosen to mimic the existing fib6_info_hold_safe.\n\n[ 41.506330] refcount_t: addition on 0; use-after-free.\n[ 41.506760] WARNING: CPU: 0 PID: 595 at lib/refcount.c:25 refcount_warn_saturate+0xa5/0x130\n[ 41.507413] Modules linked in: veth bridge stp llc\n[ 41.507821] CPU: 0 PID: 595 Comm: python3 Not tainted 6.9.0-rc2.main-00208-g49563be82afa #14\n[ 41.508479] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)\n[ 41.509163] RIP: 0010:refcount_warn_saturate+0xa5/0x130\n[ 41.509586] Code: ad ff 90 0f 0b 90 90 c3 cc cc cc cc 80 3d c0 30 ad 01 00 75 a0 c6 05 b7 30 ad 01 01 90 48 c7 c7 38 cc 7a 8c e8 cc 18 ad ff 90 <0f> 0b 90 90 c3 cc cc cc cc 80 3d 98 30 ad 01 00 0f 85 75 ff ff ff\n[ 41.510956] RSP: 0018:ffffbda3c026baf0 EFLAGS: 00010282\n[ 41.511368] RAX: 0000000000000000 RBX: ffff9e9c46914800 RCX: 0000000000000000\n[ 41.511910] RDX: ffff9e9c7ec29c00 RSI: ffff9e9c7ec1c900 RDI: ffff9e9c7ec1c900\n[ 41.512445] RBP: ffff9e9c43660c9c R08: 0000000000009ffb R09: 00000000ffffdfff\n[ 41.512998] R10: 00000000ffffdfff R11: ffffffff8ca58a40 R12: ffff9e9c4339a000\n[ 41.513534] R13: 0000000000000001 R14: ffff9e9c438a0000 R15: ffffbda3c026bb48\n[ 41.514086] FS: 00007fbc4cda1740(0000) GS:ffff9e9c7ec00000(0000) knlGS:0000000000000000\n[ 41.514726] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 41.515176] CR2: 000056233b337d88 CR3: 000000000376e006 CR4: 0000000000370ef0\n[ 41.515713] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 41.516252] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 41.516799] Call Trace:\n[ 41.517037] \n[ 41.517249] ? __warn+0x7b/0x120\n[ 41.517535] ? refcount_warn_saturate+0xa5/0x130\n[ 41.517923] ? report_bug+0x164/0x190\n[ 41.518240] ? handle_bug+0x3d/0x70\n[ 41.518541] ? exc_invalid_op+0x17/0x70\n[ 41.520972] ? asm_exc_invalid_op+0x1a/0x20\n[ 41.521325] ? refcount_warn_saturate+0xa5/0x130\n[ 41.521708] ipv6_get_ifaddr+0xda/0xe0\n[ 41.522035] inet6_rtm_getaddr+0x342/0x3f0\n[ 41.522376] ? __pfx_inet6_rtm_getaddr+0x10/0x10\n[ 41.522758] rtnetlink_rcv_msg+0x334/0x3d0\n[ 41.523102] ? netlink_unicast+0x30f/0x390\n[ 41.523445] ? __pfx_rtnetlink_rcv_msg+0x10/0x10\n[ 41.523832] netlink_rcv_skb+0x53/0x100\n[ 41.524157] netlink_unicast+0x23b/0x390\n[ 41.524484] netlink_sendmsg+0x1f2/0x440\n[ 41.524826] __sys_sendto+0x1d8/0x1f0\n[ 41.525145] __x64_sys_sendto+0x1f/0x30\n[ 41.525467] do_syscall_64+0xa5/0x1b0\n[ 41.525794] entry_SYSCALL_64_after_hwframe+0x72/0x7a\n[ 41.526213] RIP: 0033:0x7fbc4cfcea9a\n[ 41.526528] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89\n[ 41.527942] RSP: 002b:00007f\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json b/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json index 28028e84d77..535131f9b9d 100644 --- a/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json +++ b/advisories/unreviewed/2024/05/GHSA-5h68-7cjq-vgrx/GHSA-5h68-7cjq-vgrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h68-7cjq-vgrx", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32607" ], "details": "HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json b/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json index 10ea2173739..2d6cddea696 100644 --- a/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json +++ b/advisories/unreviewed/2024/05/GHSA-h37j-8pp8-r22g/GHSA-h37j-8pp8-r22g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h37j-8pp8-r22g", - "modified": "2024-05-14T15:32:52Z", + "modified": "2024-11-05T21:30:31Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-26517" ], "details": "SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:09:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h765-5xqm-7h48/GHSA-h765-5xqm-7h48.json b/advisories/unreviewed/2024/05/GHSA-h765-5xqm-7h48/GHSA-h765-5xqm-7h48.json index f6b93f1dff0..8b800447074 100644 --- a/advisories/unreviewed/2024/05/GHSA-h765-5xqm-7h48/GHSA-h765-5xqm-7h48.json +++ b/advisories/unreviewed/2024/05/GHSA-h765-5xqm-7h48/GHSA-h765-5xqm-7h48.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h765-5xqm-7h48", - "modified": "2024-05-21T18:31:20Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52768" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: use vmm_table as array in wilc struct\n\nEnabling KASAN and running some iperf tests raises some memory issues with\nvmm_table:\n\nBUG: KASAN: slab-out-of-bounds in wilc_wlan_handle_txq+0x6ac/0xdb4\nWrite of size 4 at addr c3a61540 by task wlan0-tx/95\n\nKASAN detects that we are writing data beyond range allocated to vmm_table.\nThere is indeed a mismatch between the size passed to allocator in\nwilc_wlan_init, and the range of possible indexes used later: allocation\nsize is missing a multiplication by sizeof(u32)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w9j3-89mr-p378/GHSA-w9j3-89mr-p378.json b/advisories/unreviewed/2024/05/GHSA-w9j3-89mr-p378/GHSA-w9j3-89mr-p378.json index b71d009da3c..f5b8c6d1741 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9j3-89mr-p378/GHSA-w9j3-89mr-p378.json +++ b/advisories/unreviewed/2024/05/GHSA-w9j3-89mr-p378/GHSA-w9j3-89mr-p378.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9j3-89mr-p378", - "modified": "2024-05-21T18:31:21Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52819" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga\n\nFor pptable structs that use flexible array sizes, use flexible arrays.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:19Z" diff --git a/advisories/unreviewed/2024/06/GHSA-6g69-qf5f-hcwq/GHSA-6g69-qf5f-hcwq.json b/advisories/unreviewed/2024/06/GHSA-6g69-qf5f-hcwq/GHSA-6g69-qf5f-hcwq.json index 619bc3019e1..adec217cfbc 100644 --- a/advisories/unreviewed/2024/06/GHSA-6g69-qf5f-hcwq/GHSA-6g69-qf5f-hcwq.json +++ b/advisories/unreviewed/2024/06/GHSA-6g69-qf5f-hcwq/GHSA-6g69-qf5f-hcwq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-gg9v-4hff-mc2m/GHSA-gg9v-4hff-mc2m.json b/advisories/unreviewed/2024/07/GHSA-gg9v-4hff-mc2m/GHSA-gg9v-4hff-mc2m.json index aeab199a821..a41687a37d4 100644 --- a/advisories/unreviewed/2024/07/GHSA-gg9v-4hff-mc2m/GHSA-gg9v-4hff-mc2m.json +++ b/advisories/unreviewed/2024/07/GHSA-gg9v-4hff-mc2m/GHSA-gg9v-4hff-mc2m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-w2jv-599h-mr48/GHSA-w2jv-599h-mr48.json b/advisories/unreviewed/2024/07/GHSA-w2jv-599h-mr48/GHSA-w2jv-599h-mr48.json index 17bbb15fdcb..0b155f1e394 100644 --- a/advisories/unreviewed/2024/07/GHSA-w2jv-599h-mr48/GHSA-w2jv-599h-mr48.json +++ b/advisories/unreviewed/2024/07/GHSA-w2jv-599h-mr48/GHSA-w2jv-599h-mr48.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-c2vh-2vcm-gqjq/GHSA-c2vh-2vcm-gqjq.json b/advisories/unreviewed/2024/09/GHSA-c2vh-2vcm-gqjq/GHSA-c2vh-2vcm-gqjq.json index 3810cba9f1d..7613cccfd05 100644 --- a/advisories/unreviewed/2024/09/GHSA-c2vh-2vcm-gqjq/GHSA-c2vh-2vcm-gqjq.json +++ b/advisories/unreviewed/2024/09/GHSA-c2vh-2vcm-gqjq/GHSA-c2vh-2vcm-gqjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2vh-2vcm-gqjq", - "modified": "2024-09-27T03:30:29Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-09-27T03:30:29Z", "aliases": [ "CVE-2024-7011" ], "details": "Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, NP-CA4200W, NP-CA4202W, NP-CA4260X, NP-CA4300X, NP-CA4355X, NP-CD2100U, NP-CD2120X, NP-CD2300X, NP-CR2100X, NP-CR2170W, NP-CR2170X, NP-CR2200U, NP-CR2200W, NP-CR2280X, NP-CR2310X, NP-CR2350X, NP-MC302XG, NP-MC332WG, NP-MC332WJL, NP-MC342XG, NP-MC372X, NP-MC372XG, NP-MC382W, NP-MC382WG, NP-MC422XG, NP-ME342UG, NP-ME372W, NP-ME372WG, NP-ME372WJL, NP-ME382U, NP-ME382UG, NP-ME382UJL, NP-ME402X, NP-ME402XG, NP-ME402XJL, NP-CB4500XL, NP-CG6400UL, NP-CG6400WL, NP-CG6500XL, NP-PE455UL, NP-PE455ULG, NP-PE455WL, NP-PE455WLG, NP-PE505XLG, NP-CB4600U, NP-CF6600U, NP-P474U, NP-P554U, NP-P554U+, NP-P554UG, NP-P554UJL, NP-CG6600UL, NP-P547UL, NP-P547ULG, NP-P547ULJL, NP-P607UL+, NP-P627UL, NP-P627UL+, NP-P627ULG, NP-P627ULJL, NP-PV710UL-B, NP-PV710UL-B1, NP-PV710UL-W, NP-PV710UL-W+, NP-PV710UL-W1, NP-PV730UL-BJL, NP-PV730UL-WJL, NP-PV800UL-B, NP-PV800UL-B+, NP-PV800UL-B1, NP-PV800UL-BJL, NP-PV800UL-W, NP-PV800UL-W+, NP-PV800UL-W1, NP-PV800UL-WJL, NP-CA4200X, NP-CA4265X, NP-CA4300U, NP-CA4300W, NP-CA4305X, NP-CA4400X, NP-CD2125X, NP-CD2200W, NP-CD2300U, NP-CD2310X, NP-CR2105X, NP-CR2200X, NP-CR2205W, NP-CR2300U, NP-CR2300W, NP-CR2315X, NP-CR2400X, NP-MC333XG, NP-MC363XG, NP-MC393WJL, NP-MC423W, NP-MC423WG, NP-MC453X, NP-MC453X, NP-MC453XG, NP-MC453XJL, NP-ME383WG, NP-ME403U, NP-ME403UG, NP-ME403UJL, NP-ME423W, NP-ME423WG, NP-ME423WJL, NP-ME453X, NP-ME453XG, NP-CB4400USL, NP-CB4400WSL, NP-CB4510UL, NP-CB4510WL, NP-CB4510XL, NP-CB4550USL, NP-CB6700UL, NP-CG6510UL, NP-PE456USL, NP-PE456USLG, NP-PE456USLJL, NP-PE456WSLG, NP-PE506UL, NP-PE506ULG, NP-PE506ULJL, NP-PE506WL, NP-PE506WLG, NP-PE506WLJL) allows an attacker to cause a denial-of-service (DoS) condition via SNMP service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1242" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T03:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json b/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json index 406f3a62064..16565034bd5 100644 --- a/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json +++ b/advisories/unreviewed/2024/10/GHSA-58m7-hfr6-rrx2/GHSA-58m7-hfr6-rrx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58m7-hfr6-rrx2", - "modified": "2024-10-23T06:31:19Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-10-23T06:31:19Z", "aliases": [ "CVE-2024-50066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mremap: fix move_normal_pmd/retract_page_tables race\n\nIn mremap(), move_page_tables() looks at the type of the PMD entry and the\nspecified address range to figure out by which method the next chunk of\npage table entries should be moved.\n\nAt that point, the mmap_lock is held in write mode, but no rmap locks are\nheld yet. For PMD entries that point to page tables and are fully covered\nby the source address range, move_pgt_entry(NORMAL_PMD, ...) is called,\nwhich first takes rmap locks, then does move_normal_pmd(). \nmove_normal_pmd() takes the necessary page table locks at source and\ndestination, then moves an entire page table from the source to the\ndestination.\n\nThe problem is: The rmap locks, which protect against concurrent page\ntable removal by retract_page_tables() in the THP code, are only taken\nafter the PMD entry has been read and it has been decided how to move it. \nSo we can race as follows (with two processes that have mappings of the\nsame tmpfs file that is stored on a tmpfs mount with huge=advise); note\nthat process A accesses page tables through the MM while process B does it\nthrough the file rmap:\n\nprocess A process B\n========= =========\nmremap\n mremap_to\n move_vma\n move_page_tables\n get_old_pmd\n alloc_new_pmd\n *** PREEMPT ***\n madvise(MADV_COLLAPSE)\n do_madvise\n madvise_walk_vmas\n madvise_vma_behavior\n madvise_collapse\n hpage_collapse_scan_file\n collapse_file\n retract_page_tables\n i_mmap_lock_read(mapping)\n pmdp_collapse_flush\n i_mmap_unlock_read(mapping)\n move_pgt_entry(NORMAL_PMD, ...)\n take_rmap_locks\n move_normal_pmd\n drop_rmap_locks\n\nWhen this happens, move_normal_pmd() can end up creating bogus PMD entries\nin the line `pmd_populate(mm, new_pmd, pmd_pgtable(pmd))`. The effect\ndepends on arch-specific and machine-specific details; on x86, you can end\nup with physical page 0 mapped as a page table, which is likely\nexploitable for user->kernel privilege escalation.\n\nFix the race by letting process B recheck that the PMD still points to a\npage table after the rmap locks have been taken. Otherwise, we bail and\nlet the caller fall back to the PTE-level copying path, which will then\nbail immediately at the pmd_none() check.\n\nBug reachability: Reaching this bug requires that you can create\nshmem/file THP mappings - anonymous THP uses different code that doesn't\nzap stuff under rmap locks. File THP is gated on an experimental config\nflag (CONFIG_READ_ONLY_THP_FOR_FS), so on normal distro kernels you need\nshmem THP to hit this bug. As far as I know, getting shmem THP normally\nrequires that you can mount your own tmpfs with the right mount flags,\nwhich would require creating your own user+mount namespace; though I don't\nknow if some distros maybe enable shmem THP by default or something like\nthat.\n\nBug impact: This issue can likely be used for user->kernel privilege\nescalation when it is reachable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-23T06:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hfvw-6r46-qm8f/GHSA-hfvw-6r46-qm8f.json b/advisories/unreviewed/2024/10/GHSA-hfvw-6r46-qm8f/GHSA-hfvw-6r46-qm8f.json index 983ebaf5b11..9ef42e42ceb 100644 --- a/advisories/unreviewed/2024/10/GHSA-hfvw-6r46-qm8f/GHSA-hfvw-6r46-qm8f.json +++ b/advisories/unreviewed/2024/10/GHSA-hfvw-6r46-qm8f/GHSA-hfvw-6r46-qm8f.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-644" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-pwf9-7hmp-q2xf/GHSA-pwf9-7hmp-q2xf.json b/advisories/unreviewed/2024/10/GHSA-pwf9-7hmp-q2xf/GHSA-pwf9-7hmp-q2xf.json index 2c1223de6a7..a79fef0af35 100644 --- a/advisories/unreviewed/2024/10/GHSA-pwf9-7hmp-q2xf/GHSA-pwf9-7hmp-q2xf.json +++ b/advisories/unreviewed/2024/10/GHSA-pwf9-7hmp-q2xf/GHSA-pwf9-7hmp-q2xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwf9-7hmp-q2xf", - "modified": "2024-10-08T18:33:13Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-10-08T18:33:13Z", "aliases": [ "CVE-2024-45918" ], "details": "Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-08T17:15:54Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json b/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json index 776c85e4177..a8ccd7649a9 100644 --- a/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json +++ b/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7v6-v4wg-h8m2", - "modified": "2024-10-17T15:31:08Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-10-17T15:31:08Z", "aliases": [ "CVE-2023-6728" ], "details": "Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-17T13:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qc52-868v-6vh4/GHSA-qc52-868v-6vh4.json b/advisories/unreviewed/2024/10/GHSA-qc52-868v-6vh4/GHSA-qc52-868v-6vh4.json index 726e4e5ff32..2bf83f38fd9 100644 --- a/advisories/unreviewed/2024/10/GHSA-qc52-868v-6vh4/GHSA-qc52-868v-6vh4.json +++ b/advisories/unreviewed/2024/10/GHSA-qc52-868v-6vh4/GHSA-qc52-868v-6vh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc52-868v-6vh4", - "modified": "2024-10-09T06:30:23Z", + "modified": "2024-11-05T21:30:32Z", "published": "2024-10-09T06:30:23Z", "aliases": [ "CVE-2024-5968" ], "details": "The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T06:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vwp4-85g8-fgjg/GHSA-vwp4-85g8-fgjg.json b/advisories/unreviewed/2024/10/GHSA-vwp4-85g8-fgjg/GHSA-vwp4-85g8-fgjg.json index d7fac60c8bf..20579bcd3bd 100644 --- a/advisories/unreviewed/2024/10/GHSA-vwp4-85g8-fgjg/GHSA-vwp4-85g8-fgjg.json +++ b/advisories/unreviewed/2024/10/GHSA-vwp4-85g8-fgjg/GHSA-vwp4-85g8-fgjg.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-22h9-mj69-54jf/GHSA-22h9-mj69-54jf.json b/advisories/unreviewed/2024/11/GHSA-22h9-mj69-54jf/GHSA-22h9-mj69-54jf.json index 4aea448bb39..5b5c50bb690 100644 --- a/advisories/unreviewed/2024/11/GHSA-22h9-mj69-54jf/GHSA-22h9-mj69-54jf.json +++ b/advisories/unreviewed/2024/11/GHSA-22h9-mj69-54jf/GHSA-22h9-mj69-54jf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22h9-mj69-54jf", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-30617" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 \"/main/social/home.php,\" allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-23gq-5hj3-m433/GHSA-23gq-5hj3-m433.json b/advisories/unreviewed/2024/11/GHSA-23gq-5hj3-m433/GHSA-23gq-5hj3-m433.json index 8623776eb87..300d56ebff9 100644 --- a/advisories/unreviewed/2024/11/GHSA-23gq-5hj3-m433/GHSA-23gq-5hj3-m433.json +++ b/advisories/unreviewed/2024/11/GHSA-23gq-5hj3-m433/GHSA-23gq-5hj3-m433.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23gq-5hj3-m433", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-30619" ], "details": "Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via \"/main/inc/ajax/message.ajax.php?a=get_count_message\" AND \"/main/inc/ajax/online.ajax.php?a=get_users_online.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json b/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json index 289372a7f15..b475d217dea 100644 --- a/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json +++ b/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hfc-prjx-wjcx", - "modified": "2024-11-05T18:32:11Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-48312" ], "details": "WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T17:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2m6f-fj9h-6vmp/GHSA-2m6f-fj9h-6vmp.json b/advisories/unreviewed/2024/11/GHSA-2m6f-fj9h-6vmp/GHSA-2m6f-fj9h-6vmp.json index cc9cea12a50..a31f640c2de 100644 --- a/advisories/unreviewed/2024/11/GHSA-2m6f-fj9h-6vmp/GHSA-2m6f-fj9h-6vmp.json +++ b/advisories/unreviewed/2024/11/GHSA-2m6f-fj9h-6vmp/GHSA-2m6f-fj9h-6vmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2m6f-fj9h-6vmp", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-30618" ], "details": "A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json b/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json index 153d73fb903..f59acfc19f9 100644 --- a/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json +++ b/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qm8-phhf-q2q2", - "modified": "2024-11-04T12:32:57Z", + "modified": "2024-11-05T21:30:42Z", "published": "2024-11-04T12:32:57Z", "aliases": [ "CVE-2024-48878" diff --git a/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json b/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json new file mode 100644 index 00000000000..db386a73c5b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5grf-38mv-vxvv/GHSA-5grf-38mv-vxvv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5grf-38mv-vxvv", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-51382" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compromise the integrity and security of the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51382" + }, + { + "type": "WEB", + "url": "https://hacking-notes.medium.com/cve-2024-51382-jatos-v3-9-3-csrf-admin-password-reset-1adeff0386ed" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7hpj-6m83-46cj/GHSA-7hpj-6m83-46cj.json b/advisories/unreviewed/2024/11/GHSA-7hpj-6m83-46cj/GHSA-7hpj-6m83-46cj.json index 46693e7e08c..0c9d4dbb467 100644 --- a/advisories/unreviewed/2024/11/GHSA-7hpj-6m83-46cj/GHSA-7hpj-6m83-46cj.json +++ b/advisories/unreviewed/2024/11/GHSA-7hpj-6m83-46cj/GHSA-7hpj-6m83-46cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hpj-6m83-46cj", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-30616" ], "details": "Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7jm9-xpwx-v999/GHSA-7jm9-xpwx-v999.json b/advisories/unreviewed/2024/11/GHSA-7jm9-xpwx-v999/GHSA-7jm9-xpwx-v999.json new file mode 100644 index 00000000000..de8e870eeb1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7jm9-xpwx-v999/GHSA-7jm9-xpwx-v999.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jm9-xpwx-v999", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-0134" + ], + "details": "NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0134" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5585" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-61" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9hqw-38w2-29xc/GHSA-9hqw-38w2-29xc.json b/advisories/unreviewed/2024/11/GHSA-9hqw-38w2-29xc/GHSA-9hqw-38w2-29xc.json new file mode 100644 index 00000000000..19a6fa5deb1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9hqw-38w2-29xc/GHSA-9hqw-38w2-29xc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hqw-38w2-29xc", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-7995" + ], + "details": "A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7995" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f63j-xmq2-hrpg/GHSA-f63j-xmq2-hrpg.json b/advisories/unreviewed/2024/11/GHSA-f63j-xmq2-hrpg/GHSA-f63j-xmq2-hrpg.json index 9b7d66e92a2..a83055fec83 100644 --- a/advisories/unreviewed/2024/11/GHSA-f63j-xmq2-hrpg/GHSA-f63j-xmq2-hrpg.json +++ b/advisories/unreviewed/2024/11/GHSA-f63j-xmq2-hrpg/GHSA-f63j-xmq2-hrpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f63j-xmq2-hrpg", - "modified": "2024-11-04T18:31:23Z", + "modified": "2024-11-05T21:30:42Z", "published": "2024-11-04T18:31:23Z", "aliases": [ "CVE-2024-51326" ], "details": "SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T18:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json b/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json index 213abb6e90b..7c71fe29dcb 100644 --- a/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json +++ b/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7rx-xjjw-j9xq", - "modified": "2024-11-04T12:32:57Z", + "modified": "2024-11-05T21:30:42Z", "published": "2024-11-04T12:32:57Z", "aliases": [ "CVE-2024-36485" diff --git a/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json b/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json index af854ca1827..b53678263a2 100644 --- a/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json +++ b/advisories/unreviewed/2024/11/GHSA-gcgg-hvp7-xgf7/GHSA-gcgg-hvp7-xgf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gcgg-hvp7-xgf7", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-05T21:30:42Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20114" ], "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09037038; Issue ID: MSV-1714.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hm22-mpqr-wp46/GHSA-hm22-mpqr-wp46.json b/advisories/unreviewed/2024/11/GHSA-hm22-mpqr-wp46/GHSA-hm22-mpqr-wp46.json index c3198f0c6bb..4b6934d9778 100644 --- a/advisories/unreviewed/2024/11/GHSA-hm22-mpqr-wp46/GHSA-hm22-mpqr-wp46.json +++ b/advisories/unreviewed/2024/11/GHSA-hm22-mpqr-wp46/GHSA-hm22-mpqr-wp46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hm22-mpqr-wp46", - "modified": "2024-11-04T18:31:23Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-04T18:31:23Z", "aliases": [ "CVE-2024-51327" ], "details": "SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T18:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json b/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json new file mode 100644 index 00000000000..b7570a48975 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hm9x-5qmp-g6fq/GHSA-hm9x-5qmp-g6fq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm9x-5qmp-g6fq", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-51381" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51381" + }, + { + "type": "WEB", + "url": "https://hacking-notes.medium.com/cve-2024-51381-jatos-v3-9-3-csrf-admin-account-creation-94035f24d0be" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hv6q-xm2j-9hqv/GHSA-hv6q-xm2j-9hqv.json b/advisories/unreviewed/2024/11/GHSA-hv6q-xm2j-9hqv/GHSA-hv6q-xm2j-9hqv.json index 0372562f641..2da7b1786ab 100644 --- a/advisories/unreviewed/2024/11/GHSA-hv6q-xm2j-9hqv/GHSA-hv6q-xm2j-9hqv.json +++ b/advisories/unreviewed/2024/11/GHSA-hv6q-xm2j-9hqv/GHSA-hv6q-xm2j-9hqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hv6q-xm2j-9hqv", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T21:30:43Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-51024" ], "details": "D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json b/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json new file mode 100644 index 00000000000..24309bd472d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qvc8-jp6r-8639/GHSA-qvc8-jp6r-8639.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvc8-jp6r-8639", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-51380" + ], + "details": "Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51380" + }, + { + "type": "WEB", + "url": "https://hacking-notes.medium.com/cve-2024-51380-jatos-v3-9-3-stored-xss-properties-component-44aea338ee9c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json b/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json index fc1b1d77262..1f7713b6abe 100644 --- a/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json +++ b/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcx3-jx8c-54gq", - "modified": "2024-11-01T18:31:32Z", + "modified": "2024-11-05T21:30:40Z", "published": "2024-11-01T18:31:32Z", "aliases": [ "CVE-2024-51398" ], "details": "Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-521" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T16:15:09Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json b/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json index 8450c501607..f9c4f003a67 100644 --- a/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json +++ b/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rrg7-hv9c-7q66", - "modified": "2024-11-01T18:31:33Z", + "modified": "2024-11-05T21:30:40Z", "published": "2024-11-01T18:31:33Z", "aliases": [ "CVE-2024-51399" ], "details": "Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can lead to data breaches and identity theft.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T16:15:09Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json b/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json index 78a16c226fa..6d56d7e3bf9 100644 --- a/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json +++ b/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvmx-2vhq-c359", - "modified": "2024-11-01T18:31:33Z", + "modified": "2024-11-05T21:30:40Z", "published": "2024-11-01T18:31:33Z", "aliases": [ "CVE-2024-48352" ], "details": "Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T17:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json b/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json new file mode 100644 index 00000000000..2272acbc350 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w9pr-cvj2-cxfc/GHSA-w9pr-cvj2-cxfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9pr-cvj2-cxfc", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-51379" + ], + "details": "Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51379" + }, + { + "type": "WEB", + "url": "https://hacking-notes.medium.com/cve-2024-51379-jatos-v3-9-3-stored-xss-description-component-de49d0077a96" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json b/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json index 77f07881c00..daa3712f341 100644 --- a/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json +++ b/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4vq-mwg4-r55q", - "modified": "2024-11-01T18:31:33Z", + "modified": "2024-11-05T21:30:41Z", "published": "2024-11-01T18:31:33Z", "aliases": [ "CVE-2024-48353" ], "details": "Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T18:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json b/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json new file mode 100644 index 00000000000..89d4d7afbbb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xv9r-mhj6-33xr/GHSA-xv9r-mhj6-33xr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv9r-mhj6-33xr", + "modified": "2024-11-05T21:30:43Z", + "published": "2024-11-05T21:30:43Z", + "aliases": [ + "CVE-2024-51240" + ], + "details": "An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51240" + }, + { + "type": "WEB", + "url": "https://github.com/VitoCrl/vulnerability_research/tree/main/CVE-2024-51240" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T19:15:07Z" + } +} \ No newline at end of file