Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-04-19 18:32:25 +00:00
parent c2dabcca91
commit 86e72dcb1a
50 changed files with 1411 additions and 38 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-625v-hxfr-pr86",
"modified": "2022-05-24T17:39:54Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2022-05-24T17:39:54Z",
"aliases": [
"CVE-2021-2103"
],
"details": "Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6wv-f88c-2rj2",
"modified": "2022-05-24T17:39:55Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2022-05-24T17:39:55Z",
"aliases": [
"CVE-2021-2104"
],
"details": "Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9c2-mfx9-w528",
"modified": "2022-05-24T17:39:54Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2022-05-24T17:39:54Z",
"aliases": [
"CVE-2021-2102"
],
"details": "Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74mg-f7w3-pcrr",
"modified": "2024-02-20T21:30:26Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2024-02-20T21:30:26Z",
"aliases": [
"CVE-2023-52436"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: explicitly null-terminate the xattr list\n\nWhen setting an xattr, explicitly null-terminate the xattr list. This\neliminates the fragile assumption that the unused xattr space is always\nzeroed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-20T21:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pp5-c4g8-xxc4",
"modified": "2024-02-28T03:30:30Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2024-02-23T12:30:31Z",
"aliases": [
"CVE-2024-26593"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: i801: Fix block process call transactions\n\nAccording to the Intel datasheets, software must reset the block\nbuffer index twice for block process call transactions: once before\nwriting the outgoing data to the buffer, and once again before\nreading the incoming data from the buffer.\n\nThe driver is currently missing the second reset, causing the wrong\nportion of the block buffer to be read.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T10:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92f7-c7hw-58cr",
"modified": "2024-02-23T09:30:38Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2024-02-20T15:31:04Z",
"aliases": [
"CVE-2024-26581"
],
"details": "netfilter: nft_set_rbtree: skip end interval element from gc\n\nrbtree lazy gc on insert might collect an end interval element that has\nbeen just added in this transactions, skip end interval elements that\nare not yet active.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -67,7 +70,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-20T13:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xr62-xhf5-qw2c",
"modified": "2024-04-19T12:31:16Z",
"modified": "2024-04-19T18:31:09Z",
"published": "2024-03-19T12:30:41Z",
"aliases": [
"CVE-2024-2609"
@@ -33,6 +33,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-20"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26cp-j6f9-2w7c",
"modified": "2024-04-19T18:31:12Z",
"published": "2024-04-19T18:31:12Z",
"aliases": [
"CVE-2024-32206"
],
"details": "A stored cross-site scripting (XSS) vulnerability in the component \\affiche\\admin\\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32206"
},
{
"type": "WEB",
"url": "https://github.com/majic-banana/vulnerability/blob/main/POC/WUZHICMS4.1.0%20Stored%20Xss%20In%20Affiche%20Model.md"
},
{
"type": "WEB",
"url": "https://github.com/wuzhicms/wuzhicms"
},
{
"type": "WEB",
"url": "http://wuzhicms.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T16:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qcm-jqxv-pxmj",
"modified": "2024-04-19T18:31:11Z",
"published": "2024-04-19T18:31:11Z",
"aliases": [
"CVE-2024-31587"
],
"details": "SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31587"
},
{
"type": "WEB",
"url": "https://github.com/kklzzcun/kklzzcun.github.io/blob/main/Camera.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T16:15:10Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wrh-3gmh-mgcw",
"modified": "2024-04-19T18:31:13Z",
"published": "2024-04-19T18:31:13Z",
"aliases": [
"CVE-2022-40745"
],
"details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40745"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/236452"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7148632"
}
],
"database_specific": {
"cwe_ids": [
"CWE-326"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:51Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m9x-qjwr-9h5x",
"modified": "2024-04-19T18:31:15Z",
"published": "2024-04-19T18:31:15Z",
"aliases": [
"CVE-2024-29991"
],
"details": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29991"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29991"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:54Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mxv-473p-h624",
"modified": "2024-04-19T18:31:15Z",
"published": "2024-04-19T18:31:15Z",
"aliases": [
"CVE-2023-51797"
],
"details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51797"
},
{
"type": "WEB",
"url": "https://ffmpeg.org"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg"
},
{
"type": "WEB",
"url": "https://trac.ffmpeg.org/ticket/10756"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:52Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vhm-v3w9-8mr8",
"modified": "2024-04-16T18:31:36Z",
"modified": "2024-04-19T18:31:10Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3863"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-20"
}
],
"database_specific": {
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rw9-59ch-c9mh",
"modified": "2024-04-19T18:31:15Z",
"published": "2024-04-19T18:31:15Z",
"aliases": [
"CVE-2023-51791"
],
"details": "Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51791"
},
{
"type": "WEB",
"url": "https://ffmpeg.org"
},
{
"type": "WEB",
"url": "https://trac.ffmpeg.org/ticket/10738"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:52Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4w8x-p5gf-gh2h",
"modified": "2024-04-19T18:31:14Z",
"published": "2024-04-19T18:31:14Z",
"aliases": [
"CVE-2023-27279"
],
"details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27279"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248533"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7148632"
}
],
"database_specific": {
"cwe_ids": [
"CWE-799"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:51Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58j4-c8m7-xcgv",
"modified": "2024-04-19T18:31:14Z",
"published": "2024-04-19T18:31:14Z",
"aliases": [
"CVE-2023-49963"
],
"details": "DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49963"
},
{
"type": "WEB",
"url": "https://gitlab.com/loudmouth-security/vulnerability-disclosures/cve-2023-49963"
},
{
"type": "WEB",
"url": "https://loudmouth.io"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:51Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mvp-3rph-rfxg",
"modified": "2024-04-17T09:30:32Z",
"modified": "2024-04-19T18:31:10Z",
"published": "2024-04-17T09:30:32Z",
"aliases": [
"CVE-2024-3839"
],
"details": "Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T08:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5r57-jcc8-jhh3",
"modified": "2024-04-17T09:30:32Z",
"modified": "2024-04-19T18:31:10Z",
"published": "2024-04-17T09:30:31Z",
"aliases": [
"CVE-2024-3834"
],
"details": "Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T08:15:10Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cjw-2w3q-pv7g",
"modified": "2024-04-19T18:31:15Z",
"published": "2024-04-19T18:31:15Z",
"aliases": [
"CVE-2023-50008"
],
"details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the av_malloc function in libavutil/mem.c:105:9 component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50008"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg/commit/5f87a68cf70dafeab2fb89b42e41a4c29053b89b"
},
{
"type": "WEB",
"url": "https://trac.ffmpeg.org/ticket/10701"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-19T17:15:52Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6f82-r7wj-8fxf",
"modified": "2024-04-19T12:31:17Z",
"modified": "2024-04-19T18:31:10Z",
"published": "2024-04-16T18:31:35Z",
"aliases": [
"CVE-2024-3859"
@@ -33,6 +33,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-20"
}
],
"database_specific": {

Some files were not shown because too many files have changed in this diff Show More