diff --git a/advisories/unreviewed/2022/05/GHSA-625v-hxfr-pr86/GHSA-625v-hxfr-pr86.json b/advisories/unreviewed/2022/05/GHSA-625v-hxfr-pr86/GHSA-625v-hxfr-pr86.json index 7cc1e561d89..57790e431d4 100644 --- a/advisories/unreviewed/2022/05/GHSA-625v-hxfr-pr86/GHSA-625v-hxfr-pr86.json +++ b/advisories/unreviewed/2022/05/GHSA-625v-hxfr-pr86/GHSA-625v-hxfr-pr86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-625v-hxfr-pr86", - "modified": "2022-05-24T17:39:54Z", + "modified": "2024-04-19T18:31:09Z", "published": "2022-05-24T17:39:54Z", "aliases": [ "CVE-2021-2103" ], "details": "Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h6wv-f88c-2rj2/GHSA-h6wv-f88c-2rj2.json b/advisories/unreviewed/2022/05/GHSA-h6wv-f88c-2rj2/GHSA-h6wv-f88c-2rj2.json index f7f47eb2062..de48d3c7567 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6wv-f88c-2rj2/GHSA-h6wv-f88c-2rj2.json +++ b/advisories/unreviewed/2022/05/GHSA-h6wv-f88c-2rj2/GHSA-h6wv-f88c-2rj2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6wv-f88c-2rj2", - "modified": "2022-05-24T17:39:55Z", + "modified": "2024-04-19T18:31:09Z", "published": "2022-05-24T17:39:55Z", "aliases": [ "CVE-2021-2104" ], "details": "Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v9c2-mfx9-w528/GHSA-v9c2-mfx9-w528.json b/advisories/unreviewed/2022/05/GHSA-v9c2-mfx9-w528/GHSA-v9c2-mfx9-w528.json index 04f8e6a2546..a44e23ec422 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9c2-mfx9-w528/GHSA-v9c2-mfx9-w528.json +++ b/advisories/unreviewed/2022/05/GHSA-v9c2-mfx9-w528/GHSA-v9c2-mfx9-w528.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9c2-mfx9-w528", - "modified": "2022-05-24T17:39:54Z", + "modified": "2024-04-19T18:31:09Z", "published": "2022-05-24T17:39:54Z", "aliases": [ "CVE-2021-2102" ], "details": "Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json b/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json index 3079e08b2f7..62cf0e860ee 100644 --- a/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json +++ b/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74mg-f7w3-pcrr", - "modified": "2024-02-20T21:30:26Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-02-20T21:30:26Z", "aliases": [ "CVE-2023-52436" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: explicitly null-terminate the xattr list\n\nWhen setting an xattr, explicitly null-terminate the xattr list. This\neliminates the fragile assumption that the unused xattr space is always\nzeroed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T21:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json b/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json index 1fd6a39677d..664e1d4f484 100644 --- a/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json +++ b/advisories/unreviewed/2024/02/GHSA-7pp5-c4g8-xxc4/GHSA-7pp5-c4g8-xxc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pp5-c4g8-xxc4", - "modified": "2024-02-28T03:30:30Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-02-23T12:30:31Z", "aliases": [ "CVE-2024-26593" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: i801: Fix block process call transactions\n\nAccording to the Intel datasheets, software must reset the block\nbuffer index twice for block process call transactions: once before\nwriting the outgoing data to the buffer, and once again before\nreading the incoming data from the buffer.\n\nThe driver is currently missing the second reset, causing the wrong\nportion of the block buffer to be read.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-23T10:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json index 3709ce3b436..be3fbeb391e 100644 --- a/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json +++ b/advisories/unreviewed/2024/02/GHSA-92f7-c7hw-58cr/GHSA-92f7-c7hw-58cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92f7-c7hw-58cr", - "modified": "2024-02-23T09:30:38Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-26581" ], "details": "netfilter: nft_set_rbtree: skip end interval element from gc\n\nrbtree lazy gc on insert might collect an end interval element that has\nbeen just added in this transactions, skip end interval elements that\nare not yet active.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -67,7 +70,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T13:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json index 826bd18de75..6ee084ee9c3 100644 --- a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json +++ b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xr62-xhf5-qw2c", - "modified": "2024-04-19T12:31:16Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2609" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json b/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json new file mode 100644 index 00000000000..fd219e3b89e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26cp-j6f9-2w7c", + "modified": "2024-04-19T18:31:12Z", + "published": "2024-04-19T18:31:12Z", + "aliases": [ + "CVE-2024-32206" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the component \\affiche\\admin\\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32206" + }, + { + "type": "WEB", + "url": "https://github.com/majic-banana/vulnerability/blob/main/POC/WUZHICMS4.1.0%20Stored%20Xss%20In%20Affiche%20Model.md" + }, + { + "type": "WEB", + "url": "https://github.com/wuzhicms/wuzhicms" + }, + { + "type": "WEB", + "url": "http://wuzhicms.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2qcm-jqxv-pxmj/GHSA-2qcm-jqxv-pxmj.json b/advisories/unreviewed/2024/04/GHSA-2qcm-jqxv-pxmj/GHSA-2qcm-jqxv-pxmj.json new file mode 100644 index 00000000000..e15f1d039e1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2qcm-jqxv-pxmj/GHSA-2qcm-jqxv-pxmj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qcm-jqxv-pxmj", + "modified": "2024-04-19T18:31:11Z", + "published": "2024-04-19T18:31:11Z", + "aliases": [ + "CVE-2024-31587" + ], + "details": "SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31587" + }, + { + "type": "WEB", + "url": "https://github.com/kklzzcun/kklzzcun.github.io/blob/main/Camera.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2wrh-3gmh-mgcw/GHSA-2wrh-3gmh-mgcw.json b/advisories/unreviewed/2024/04/GHSA-2wrh-3gmh-mgcw/GHSA-2wrh-3gmh-mgcw.json new file mode 100644 index 00000000000..e8ad004f9b2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2wrh-3gmh-mgcw/GHSA-2wrh-3gmh-mgcw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wrh-3gmh-mgcw", + "modified": "2024-04-19T18:31:13Z", + "published": "2024-04-19T18:31:13Z", + "aliases": [ + "CVE-2022-40745" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40745" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/236452" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3m9x-qjwr-9h5x/GHSA-3m9x-qjwr-9h5x.json b/advisories/unreviewed/2024/04/GHSA-3m9x-qjwr-9h5x/GHSA-3m9x-qjwr-9h5x.json new file mode 100644 index 00000000000..8fa66085f43 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3m9x-qjwr-9h5x/GHSA-3m9x-qjwr-9h5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m9x-qjwr-9h5x", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2024-29991" + ], + "details": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29991" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29991" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json b/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json new file mode 100644 index 00000000000..0e9bfab68c8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mxv-473p-h624", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51797" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51797" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10756" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json index bc598079d5d..4ef1f4cfb90 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json +++ b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vhm-v3w9-8mr8", - "modified": "2024-04-16T18:31:36Z", + "modified": "2024-04-19T18:31:10Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-3863" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json b/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json new file mode 100644 index 00000000000..f4992ae3de3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rw9-59ch-c9mh", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51791" + ], + "details": "Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51791" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10738" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4w8x-p5gf-gh2h/GHSA-4w8x-p5gf-gh2h.json b/advisories/unreviewed/2024/04/GHSA-4w8x-p5gf-gh2h/GHSA-4w8x-p5gf-gh2h.json new file mode 100644 index 00000000000..d04e4dd9b0c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4w8x-p5gf-gh2h/GHSA-4w8x-p5gf-gh2h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w8x-p5gf-gh2h", + "modified": "2024-04-19T18:31:14Z", + "published": "2024-04-19T18:31:14Z", + "aliases": [ + "CVE-2023-27279" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27279" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248533" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-58j4-c8m7-xcgv/GHSA-58j4-c8m7-xcgv.json b/advisories/unreviewed/2024/04/GHSA-58j4-c8m7-xcgv/GHSA-58j4-c8m7-xcgv.json new file mode 100644 index 00000000000..9377c346496 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-58j4-c8m7-xcgv/GHSA-58j4-c8m7-xcgv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58j4-c8m7-xcgv", + "modified": "2024-04-19T18:31:14Z", + "published": "2024-04-19T18:31:14Z", + "aliases": [ + "CVE-2023-49963" + ], + "details": "DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49963" + }, + { + "type": "WEB", + "url": "https://gitlab.com/loudmouth-security/vulnerability-disclosures/cve-2023-49963" + }, + { + "type": "WEB", + "url": "https://loudmouth.io" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5mvp-3rph-rfxg/GHSA-5mvp-3rph-rfxg.json b/advisories/unreviewed/2024/04/GHSA-5mvp-3rph-rfxg/GHSA-5mvp-3rph-rfxg.json index aef42e36566..fbef94b74be 100644 --- a/advisories/unreviewed/2024/04/GHSA-5mvp-3rph-rfxg/GHSA-5mvp-3rph-rfxg.json +++ b/advisories/unreviewed/2024/04/GHSA-5mvp-3rph-rfxg/GHSA-5mvp-3rph-rfxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mvp-3rph-rfxg", - "modified": "2024-04-17T09:30:32Z", + "modified": "2024-04-19T18:31:10Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3839" ], "details": "Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5r57-jcc8-jhh3/GHSA-5r57-jcc8-jhh3.json b/advisories/unreviewed/2024/04/GHSA-5r57-jcc8-jhh3/GHSA-5r57-jcc8-jhh3.json index f8582adfaf0..e36ada55428 100644 --- a/advisories/unreviewed/2024/04/GHSA-5r57-jcc8-jhh3/GHSA-5r57-jcc8-jhh3.json +++ b/advisories/unreviewed/2024/04/GHSA-5r57-jcc8-jhh3/GHSA-5r57-jcc8-jhh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5r57-jcc8-jhh3", - "modified": "2024-04-17T09:30:32Z", + "modified": "2024-04-19T18:31:10Z", "published": "2024-04-17T09:30:31Z", "aliases": [ "CVE-2024-3834" ], "details": "Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json b/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json new file mode 100644 index 00000000000..12b10a7ab56 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cjw-2w3q-pv7g", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-50008" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the av_malloc function in libavutil/mem.c:105:9 component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50008" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/commit/5f87a68cf70dafeab2fb89b42e41a4c29053b89b" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10701" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json index c8bf61f3b6e..7e6bdd4fdfc 100644 --- a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json +++ b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6f82-r7wj-8fxf", - "modified": "2024-04-19T12:31:17Z", + "modified": "2024-04-19T18:31:10Z", "published": "2024-04-16T18:31:35Z", "aliases": [ "CVE-2024-3859" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-7m35-9cg4-vcm2/GHSA-7m35-9cg4-vcm2.json b/advisories/unreviewed/2024/04/GHSA-7m35-9cg4-vcm2/GHSA-7m35-9cg4-vcm2.json new file mode 100644 index 00000000000..4ad34526f48 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7m35-9cg4-vcm2/GHSA-7m35-9cg4-vcm2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m35-9cg4-vcm2", + "modified": "2024-04-19T18:31:10Z", + "published": "2024-04-19T18:31:10Z", + "aliases": [ + "CVE-2023-22869" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22869" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/244119" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json index 1f6d383f98a..385cc6d1834 100644 --- a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json +++ b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8564-m639-jh8r", - "modified": "2024-04-19T12:31:17Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3857" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json b/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json new file mode 100644 index 00000000000..4ecb161c09b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q63-w3px-vg38", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51798" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51798" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10758" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json b/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json new file mode 100644 index 00000000000..132c1cc1ede --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9726-xp73-4p4q", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-50009" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50009" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10699" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json b/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json new file mode 100644 index 00000000000..05a55d40f81 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmrp-gx54-8xq7", + "modified": "2024-04-19T18:31:12Z", + "published": "2024-04-19T18:31:12Z", + "aliases": [ + "CVE-2024-32409" + ], + "details": "An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32409" + }, + { + "type": "WEB", + "url": "https://gitee.com/whats-the-bad-idea/cve" + }, + { + "type": "WEB", + "url": "http://semcms.com" + }, + { + "type": "WEB", + "url": "http://www.sem-cms.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json b/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json new file mode 100644 index 00000000000..a47c30d12e8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f72f-6w6j-jj9v", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51796" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51796" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10753" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json b/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json new file mode 100644 index 00000000000..8e25bae24f7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f99r-65w5-r273", + "modified": "2024-04-19T18:31:11Z", + "published": "2024-04-19T18:31:11Z", + "aliases": [ + "CVE-2024-27752" + ], + "details": "Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27752" + }, + { + "type": "WEB", + "url": "https://github.com/flyhha/cms/blob/main/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json b/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json index b1b717989a1..8636fc11de2 100644 --- a/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json +++ b/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fff2-pwcg-x73m", - "modified": "2024-04-17T09:30:32Z", + "modified": "2024-04-19T18:31:10Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3838" ], "details": "Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fr3m-v7j2-vv6p/GHSA-fr3m-v7j2-vv6p.json b/advisories/unreviewed/2024/04/GHSA-fr3m-v7j2-vv6p/GHSA-fr3m-v7j2-vv6p.json new file mode 100644 index 00000000000..e2b344161e8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fr3m-v7j2-vv6p/GHSA-fr3m-v7j2-vv6p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr3m-v7j2-vv6p", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2024-31546" + ], + "details": "Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the \"id\" parameter of /admin/damage/view_damage.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31546" + }, + { + "type": "WEB", + "url": "https://github.com/emirhanmtl/vuln-research/blob/main/SQLi-2-Computer-Laboratory-Management-System-PoC.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json b/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json new file mode 100644 index 00000000000..ea5e293e791 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3wp-whmx-cpqj", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-50010" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the set_encoder_id function in /fftools/ffmpeg_enc.c component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50010" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10702" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h5wc-jv87-367w/GHSA-h5wc-jv87-367w.json b/advisories/unreviewed/2024/04/GHSA-h5wc-jv87-367w/GHSA-h5wc-jv87-367w.json index 6158fe30ae8..0e290097965 100644 --- a/advisories/unreviewed/2024/04/GHSA-h5wc-jv87-367w/GHSA-h5wc-jv87-367w.json +++ b/advisories/unreviewed/2024/04/GHSA-h5wc-jv87-367w/GHSA-h5wc-jv87-367w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5wc-jv87-367w", - "modified": "2024-04-17T09:30:32Z", + "modified": "2024-04-19T18:31:10Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3837" ], "details": "Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hhfx-wj9x-f5m6/GHSA-hhfx-wj9x-f5m6.json b/advisories/unreviewed/2024/04/GHSA-hhfx-wj9x-f5m6/GHSA-hhfx-wj9x-f5m6.json new file mode 100644 index 00000000000..1be50e86781 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hhfx-wj9x-f5m6/GHSA-hhfx-wj9x-f5m6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhfx-wj9x-f5m6", + "modified": "2024-04-19T18:31:14Z", + "published": "2024-04-19T18:31:14Z", + "aliases": [ + "CVE-2023-37397" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37397" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/259672" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hjqg-7wq4-xvwx/GHSA-hjqg-7wq4-xvwx.json b/advisories/unreviewed/2024/04/GHSA-hjqg-7wq4-xvwx/GHSA-hjqg-7wq4-xvwx.json new file mode 100644 index 00000000000..1a98e182b9c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hjqg-7wq4-xvwx/GHSA-hjqg-7wq4-xvwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjqg-7wq4-xvwx", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-47435" + ], + "details": "An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47435" + }, + { + "type": "WEB", + "url": "https://github.com/blinkfox/hexo-theme-matery/issues/897" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json b/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json new file mode 100644 index 00000000000..936a9f4f3ea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwp9-p6mr-p438", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51793" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51793" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10743" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json b/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json new file mode 100644 index 00000000000..679ead2b52e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfff-gxr9-9j6r", + "modified": "2024-04-19T18:31:14Z", + "published": "2024-04-19T18:31:14Z", + "aliases": [ + "CVE-2023-49501" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49501" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10686" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10686#no1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json index a891b2cd72c..72c172c7bdd 100644 --- a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json +++ b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvc5-vcrh-v937", - "modified": "2024-04-19T12:31:17Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-3861" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-mx3p-fhpw-x6rv/GHSA-mx3p-fhpw-x6rv.json b/advisories/unreviewed/2024/04/GHSA-mx3p-fhpw-x6rv/GHSA-mx3p-fhpw-x6rv.json new file mode 100644 index 00000000000..fcbf1240f47 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mx3p-fhpw-x6rv/GHSA-mx3p-fhpw-x6rv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx3p-fhpw-x6rv", + "modified": "2024-04-19T18:31:11Z", + "published": "2024-04-19T18:31:11Z", + "aliases": [ + "CVE-2024-22640" + ], + "details": "TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22640" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF" + }, + { + "type": "WEB", + "url": "https://github.com/zunak/CVE-2024-22640" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json index 524fdc3d5c0..981196fe091 100644 --- a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json +++ b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7c-2483-8558", - "modified": "2024-04-19T12:31:17Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3852" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json b/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json new file mode 100644 index 00000000000..8b0121abca5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppm8-gjfw-8977", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51795" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51795" + }, + { + "type": "WEB", + "url": "https://ffmpeg.org" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10749" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json b/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json new file mode 100644 index 00000000000..e751040f7c1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2j3-5vpq-qxp4", + "modified": "2024-04-19T18:31:14Z", + "published": "2024-04-19T18:31:14Z", + "aliases": [ + "CVE-2023-49502" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49502" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10688" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json b/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json new file mode 100644 index 00000000000..db5dc96fa53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3pf-hpw8-6327", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2024-31552" + ], + "details": "CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31552" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/sickle-ffnce/awixr8/gsu7nyi0gu9q1nl8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r76q-x459-hm6w/GHSA-r76q-x459-hm6w.json b/advisories/unreviewed/2024/04/GHSA-r76q-x459-hm6w/GHSA-r76q-x459-hm6w.json new file mode 100644 index 00000000000..008d0ed544a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r76q-x459-hm6w/GHSA-r76q-x459-hm6w.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r76q-x459-hm6w", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2024-2440" + ], + "details": "A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.9.13, 3.10.10, 3.11.8 and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2440" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.10/admin/release-notes#3.10.10" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.11/admin/release-notes#3.11.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.12/admin/release-notes#3.12.2" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json b/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json new file mode 100644 index 00000000000..ce015a53d6a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8wj-r2jc-587q", + "modified": "2024-04-19T18:31:14Z", + "published": "2024-04-19T18:31:14Z", + "aliases": [ + "CVE-2023-50007" + ], + "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via theav_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50007" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/commit/b1942734c7cbcdc9034034373abcc9ecb9644c47" + }, + { + "type": "WEB", + "url": "https://trac.ffmpeg.org/ticket/10700" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json b/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json new file mode 100644 index 00000000000..1c666a33653 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v26v-9938-hw55", + "modified": "2024-04-19T18:31:11Z", + "published": "2024-04-19T18:31:11Z", + "aliases": [ + "CVE-2024-31846" + ], + "details": "An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31846" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json b/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json new file mode 100644 index 00000000000..1f7364fd559 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4c8-xmpc-f835", + "modified": "2024-04-19T18:31:11Z", + "published": "2024-04-19T18:31:11Z", + "aliases": [ + "CVE-2024-31841" + ], + "details": "An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31841" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vpvj-x83r-f4rf/GHSA-vpvj-x83r-f4rf.json b/advisories/unreviewed/2024/04/GHSA-vpvj-x83r-f4rf/GHSA-vpvj-x83r-f4rf.json new file mode 100644 index 00000000000..8947c55bf6f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vpvj-x83r-f4rf/GHSA-vpvj-x83r-f4rf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpvj-x83r-f4rf", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2024-31547" + ], + "details": "Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the \"id\" parameter of /admin/item/view_item.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31547" + }, + { + "type": "WEB", + "url": "https://github.com/emirhanmtl/vuln-research/blob/main/SQLi-3-Computer-Laboratory-Management-System-PoC.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w5vg-49mg-6cxx/GHSA-w5vg-49mg-6cxx.json b/advisories/unreviewed/2024/04/GHSA-w5vg-49mg-6cxx/GHSA-w5vg-49mg-6cxx.json new file mode 100644 index 00000000000..ea8248d8918 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w5vg-49mg-6cxx/GHSA-w5vg-49mg-6cxx.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5vg-49mg-6cxx", + "modified": "2024-04-19T18:31:16Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2024-3979" + ], + "details": "A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The manipulation leads to race condition. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261596.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3979" + }, + { + "type": "WEB", + "url": "https://github.com/COVESA/vsomeip/issues/663" + }, + { + "type": "WEB", + "url": "https://github.com/COVESA/vsomeip/files/14904610/details.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.261596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.261596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312410" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json index b60c6c0ce03..609ddfc443f 100644 --- a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json +++ b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xc66-q4x2-cwqx", - "modified": "2024-04-19T12:31:17Z", + "modified": "2024-04-19T18:31:09Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3854" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-20" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json b/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json new file mode 100644 index 00000000000..2b163c861ae --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj57-m8w7-83wf", + "modified": "2024-04-19T18:31:15Z", + "published": "2024-04-19T18:31:15Z", + "aliases": [ + "CVE-2023-51792" + ], + "details": "Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51792" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libde265/issues/427" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libde265" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json b/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json new file mode 100644 index 00000000000..e3cc114c035 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xr37-jcv5-cqxv/GHSA-xr37-jcv5-cqxv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr37-jcv5-cqxv", + "modified": "2024-04-19T18:31:10Z", + "published": "2024-04-19T18:31:10Z", + "aliases": [ + "CVE-2023-37396" + ], + "details": "IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37396" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/259671" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7148632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T16:15:09Z" + } +} \ No newline at end of file