From 87fc9aa873bc23a8a340abc684204cf761a58a94 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 21 Jun 2023 21:31:36 +0000 Subject: [PATCH] Publish Advisories GHSA-25x7-989g-366h GHSA-2873-9vw6-x36q GHSA-39h7-cq3m-g3fv GHSA-4gff-fjgq-76g6 GHSA-5rc2-qffv-3c8p GHSA-75cg-g4f4-h9c2 GHSA-7693-rm3h-988x GHSA-8c88-9jmc-phqr GHSA-9qvp-qqr3-gfx3 GHSA-fqhp-rhm6-8rrj GHSA-gmvw-h9hf-3rxv GHSA-h3v4-g87v-9f8x GHSA-h9x5-2vrm-ww3f GHSA-pq98-r2rc-hr54 GHSA-qwvc-xxgc-r8jq GHSA-r33p-xcv8-c582 GHSA-r4jh-xqh3-r437 GHSA-r6x9-4x42-c57h GHSA-rrr5-v5h9-fpwp GHSA-v668-ccv8-m5gx GHSA-wp54-pwvg-rqq5 GHSA-xc2q-prrj-8cp6 --- .../GHSA-25x7-989g-366h.json | 38 ++++++++++++++++ .../GHSA-2873-9vw6-x36q.json | 7 ++- .../GHSA-39h7-cq3m-g3fv.json | 35 +++++++++++++++ .../GHSA-4gff-fjgq-76g6.json | 39 +++++++++++++++++ .../GHSA-5rc2-qffv-3c8p.json | 7 ++- .../GHSA-75cg-g4f4-h9c2.json | 3 +- .../GHSA-7693-rm3h-988x.json | 35 +++++++++++++++ .../GHSA-8c88-9jmc-phqr.json | 38 ++++++++++++++++ .../GHSA-9qvp-qqr3-gfx3.json | 35 +++++++++++++++ .../GHSA-fqhp-rhm6-8rrj.json | 43 +++++++++++++++++++ .../GHSA-gmvw-h9hf-3rxv.json | 38 ++++++++++++++++ .../GHSA-h3v4-g87v-9f8x.json | 9 ++-- .../GHSA-h9x5-2vrm-ww3f.json | 38 ++++++++++++++++ .../GHSA-pq98-r2rc-hr54.json | 38 ++++++++++++++++ .../GHSA-qwvc-xxgc-r8jq.json | 2 +- .../GHSA-r33p-xcv8-c582.json | 9 ++-- .../GHSA-r4jh-xqh3-r437.json | 2 +- .../GHSA-r6x9-4x42-c57h.json | 4 ++ .../GHSA-rrr5-v5h9-fpwp.json | 4 ++ .../GHSA-v668-ccv8-m5gx.json | 4 ++ .../GHSA-wp54-pwvg-rqq5.json | 7 ++- .../GHSA-xc2q-prrj-8cp6.json | 2 +- 22 files changed, 421 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json create mode 100644 advisories/unreviewed/2023/06/GHSA-39h7-cq3m-g3fv/GHSA-39h7-cq3m-g3fv.json create mode 100644 advisories/unreviewed/2023/06/GHSA-4gff-fjgq-76g6/GHSA-4gff-fjgq-76g6.json create mode 100644 advisories/unreviewed/2023/06/GHSA-7693-rm3h-988x/GHSA-7693-rm3h-988x.json create mode 100644 advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json create mode 100644 advisories/unreviewed/2023/06/GHSA-9qvp-qqr3-gfx3/GHSA-9qvp-qqr3-gfx3.json create mode 100644 advisories/unreviewed/2023/06/GHSA-fqhp-rhm6-8rrj/GHSA-fqhp-rhm6-8rrj.json create mode 100644 advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json create mode 100644 advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json create mode 100644 advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json diff --git a/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json b/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json new file mode 100644 index 00000000000..95fc6d746c2 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-25x7-989g-366h/GHSA-25x7-989g-366h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25x7-989g-366h", + "modified": "2023-06-21T21:30:24Z", + "published": "2023-06-21T21:30:24Z", + "aliases": [ + "CVE-2023-0971" + ], + "details": "A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0971" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json b/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json index faa5bb70502..592adc88366 100644 --- a/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json +++ b/advisories/unreviewed/2023/06/GHSA-2873-9vw6-x36q/GHSA-2873-9vw6-x36q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2873-9vw6-x36q", - "modified": "2023-06-14T09:30:42Z", + "modified": "2023-06-21T21:30:24Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-33933" ], "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-39h7-cq3m-g3fv/GHSA-39h7-cq3m-g3fv.json b/advisories/unreviewed/2023/06/GHSA-39h7-cq3m-g3fv/GHSA-39h7-cq3m-g3fv.json new file mode 100644 index 00000000000..078c386c285 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-39h7-cq3m-g3fv/GHSA-39h7-cq3m-g3fv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39h7-cq3m-g3fv", + "modified": "2023-06-21T21:30:25Z", + "published": "2023-06-21T21:30:25Z", + "aliases": [ + "CVE-2023-24261" + ], + "details": "A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24261" + }, + { + "type": "WEB", + "url": "https://justinapplegate.me/2023/glinet-CVE-2023-24261/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-4gff-fjgq-76g6/GHSA-4gff-fjgq-76g6.json b/advisories/unreviewed/2023/06/GHSA-4gff-fjgq-76g6/GHSA-4gff-fjgq-76g6.json new file mode 100644 index 00000000000..cf3cd8e526f --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-4gff-fjgq-76g6/GHSA-4gff-fjgq-76g6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gff-fjgq-76g6", + "modified": "2023-06-21T21:30:25Z", + "published": "2023-06-21T21:30:25Z", + "aliases": [ + "CVE-2023-33591" + ], + "details": "User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33591" + }, + { + "type": "WEB", + "url": "https://github.com/DARSHANAGUPTA10/CVE/blob/main/CVE%202023-33591" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com/user-registration-login-and-user-management-system-with-admin-panel/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json b/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json index 3b8d1e6e5ac..8625f4347be 100644 --- a/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json +++ b/advisories/unreviewed/2023/06/GHSA-5rc2-qffv-3c8p/GHSA-5rc2-qffv-3c8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rc2-qffv-3c8p", - "modified": "2023-06-14T09:30:42Z", + "modified": "2023-06-21T21:30:24Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-30631" ], "details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.\n\n8.x users should upgrade to 8.1.7 or later versions\n9.x users should upgrade to 9.2.1 or later versions\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-75cg-g4f4-h9c2/GHSA-75cg-g4f4-h9c2.json b/advisories/unreviewed/2023/06/GHSA-75cg-g4f4-h9c2/GHSA-75cg-g4f4-h9c2.json index 55147a4a45d..b40627ba39b 100644 --- a/advisories/unreviewed/2023/06/GHSA-75cg-g4f4-h9c2/GHSA-75cg-g4f4-h9c2.json +++ b/advisories/unreviewed/2023/06/GHSA-75cg-g4f4-h9c2/GHSA-75cg-g4f4-h9c2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-7693-rm3h-988x/GHSA-7693-rm3h-988x.json b/advisories/unreviewed/2023/06/GHSA-7693-rm3h-988x/GHSA-7693-rm3h-988x.json new file mode 100644 index 00000000000..469f7bf5bea --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-7693-rm3h-988x/GHSA-7693-rm3h-988x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7693-rm3h-988x", + "modified": "2023-06-21T21:30:25Z", + "published": "2023-06-21T21:30:24Z", + "aliases": [ + "CVE-2023-25435" + ], + "details": "libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25435" + }, + { + "type": "WEB", + "url": "https://gitlab.com/libtiff/libtiff/-/issues/518" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json b/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json new file mode 100644 index 00000000000..753071f7f1b --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c88-9jmc-phqr", + "modified": "2023-06-21T21:30:24Z", + "published": "2023-06-21T21:30:24Z", + "aliases": [ + "CVE-2023-0970" + ], + "details": "Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0970" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-9qvp-qqr3-gfx3/GHSA-9qvp-qqr3-gfx3.json b/advisories/unreviewed/2023/06/GHSA-9qvp-qqr3-gfx3/GHSA-9qvp-qqr3-gfx3.json new file mode 100644 index 00000000000..39ea5a75913 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-9qvp-qqr3-gfx3/GHSA-9qvp-qqr3-gfx3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qvp-qqr3-gfx3", + "modified": "2023-06-21T21:30:25Z", + "published": "2023-06-21T21:30:25Z", + "aliases": [ + "CVE-2023-33405" + ], + "details": "Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33405" + }, + { + "type": "WEB", + "url": "https://github.com/hacip/CVE-2023-33405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-fqhp-rhm6-8rrj/GHSA-fqhp-rhm6-8rrj.json b/advisories/unreviewed/2023/06/GHSA-fqhp-rhm6-8rrj/GHSA-fqhp-rhm6-8rrj.json new file mode 100644 index 00000000000..d2907186a83 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-fqhp-rhm6-8rrj/GHSA-fqhp-rhm6-8rrj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqhp-rhm6-8rrj", + "modified": "2023-06-21T21:30:25Z", + "published": "2023-06-21T21:30:25Z", + "aliases": [ + "CVE-2023-33289" + ], + "details": "The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33289" + }, + { + "type": "WEB", + "url": "https://gist.github.com/6en6ar/b118888dc739e8979038f24c8ac33611" + }, + { + "type": "WEB", + "url": "https://github.com/progscrape/urlnorm" + }, + { + "type": "WEB", + "url": "https://lib.rs/crates/urlnorm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json b/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json new file mode 100644 index 00000000000..8ed87b74697 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmvw-h9hf-3rxv", + "modified": "2023-06-21T21:30:24Z", + "published": "2023-06-21T21:30:24Z", + "aliases": [ + "CVE-2023-0969" + ], + "details": "A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0969" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-h3v4-g87v-9f8x/GHSA-h3v4-g87v-9f8x.json b/advisories/unreviewed/2023/06/GHSA-h3v4-g87v-9f8x/GHSA-h3v4-g87v-9f8x.json index 9008d8206dc..19090119ced 100644 --- a/advisories/unreviewed/2023/06/GHSA-h3v4-g87v-9f8x/GHSA-h3v4-g87v-9f8x.json +++ b/advisories/unreviewed/2023/06/GHSA-h3v4-g87v-9f8x/GHSA-h3v4-g87v-9f8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3v4-g87v-9f8x", - "modified": "2023-06-13T21:30:18Z", + "modified": "2023-06-21T21:30:22Z", "published": "2023-06-13T21:30:18Z", "aliases": [ "CVE-2023-27836" ], "details": "TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json b/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json new file mode 100644 index 00000000000..383203dad3a --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9x5-2vrm-ww3f", + "modified": "2023-06-21T21:30:24Z", + "published": "2023-06-21T21:30:24Z", + "aliases": [ + "CVE-2023-0972" + ], + "details": "Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0972" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json b/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json new file mode 100644 index 00000000000..f46d54d0331 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq98-r2rc-hr54", + "modified": "2023-06-21T21:30:25Z", + "published": "2023-06-21T21:30:25Z", + "aliases": [ + "CVE-2023-3110" + ], + "details": "Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3110" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000V6HZzQAN?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json b/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json index bc56bb73780..9b1b7472b9d 100644 --- a/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json +++ b/advisories/unreviewed/2023/06/GHSA-qwvc-xxgc-r8jq/GHSA-qwvc-xxgc-r8jq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-r33p-xcv8-c582/GHSA-r33p-xcv8-c582.json b/advisories/unreviewed/2023/06/GHSA-r33p-xcv8-c582/GHSA-r33p-xcv8-c582.json index 0539c707b7a..b2508540d8e 100644 --- a/advisories/unreviewed/2023/06/GHSA-r33p-xcv8-c582/GHSA-r33p-xcv8-c582.json +++ b/advisories/unreviewed/2023/06/GHSA-r33p-xcv8-c582/GHSA-r33p-xcv8-c582.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r33p-xcv8-c582", - "modified": "2023-06-13T12:30:16Z", + "modified": "2023-06-21T21:30:22Z", "published": "2023-06-13T12:30:16Z", "aliases": [ "CVE-2023-29160" ], "details": "Stack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json b/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json index d5ea421fd03..11b2a495898 100644 --- a/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json +++ b/advisories/unreviewed/2023/06/GHSA-r4jh-xqh3-r437/GHSA-r4jh-xqh3-r437.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-r6x9-4x42-c57h/GHSA-r6x9-4x42-c57h.json b/advisories/unreviewed/2023/06/GHSA-r6x9-4x42-c57h/GHSA-r6x9-4x42-c57h.json index 96ca24890be..0aa72109dc1 100644 --- a/advisories/unreviewed/2023/06/GHSA-r6x9-4x42-c57h/GHSA-r6x9-4x42-c57h.json +++ b/advisories/unreviewed/2023/06/GHSA-r6x9-4x42-c57h/GHSA-r6x9-4x42-c57h.json @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30082" }, + { + "type": "WEB", + "url": "https://blog.manavparekh.com/2023/06/cve-2023-30082.html" + }, { "type": "WEB", "url": "https://github.com/manavparekh/CVEs/blob/main/CVE-2023-30082/Steps%20to%20reproduce.txt" diff --git a/advisories/unreviewed/2023/06/GHSA-rrr5-v5h9-fpwp/GHSA-rrr5-v5h9-fpwp.json b/advisories/unreviewed/2023/06/GHSA-rrr5-v5h9-fpwp/GHSA-rrr5-v5h9-fpwp.json index 24b4034c48d..d45af444db3 100644 --- a/advisories/unreviewed/2023/06/GHSA-rrr5-v5h9-fpwp/GHSA-rrr5-v5h9-fpwp.json +++ b/advisories/unreviewed/2023/06/GHSA-rrr5-v5h9-fpwp/GHSA-rrr5-v5h9-fpwp.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-2911" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/06/21/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-v668-ccv8-m5gx/GHSA-v668-ccv8-m5gx.json b/advisories/unreviewed/2023/06/GHSA-v668-ccv8-m5gx/GHSA-v668-ccv8-m5gx.json index 2f16e0dacec..3b1767edd45 100644 --- a/advisories/unreviewed/2023/06/GHSA-v668-ccv8-m5gx/GHSA-v668-ccv8-m5gx.json +++ b/advisories/unreviewed/2023/06/GHSA-v668-ccv8-m5gx/GHSA-v668-ccv8-m5gx.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-2828" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/06/21/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-wp54-pwvg-rqq5/GHSA-wp54-pwvg-rqq5.json b/advisories/unreviewed/2023/06/GHSA-wp54-pwvg-rqq5/GHSA-wp54-pwvg-rqq5.json index 942f8c2018c..5b89edd415b 100644 --- a/advisories/unreviewed/2023/06/GHSA-wp54-pwvg-rqq5/GHSA-wp54-pwvg-rqq5.json +++ b/advisories/unreviewed/2023/06/GHSA-wp54-pwvg-rqq5/GHSA-wp54-pwvg-rqq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp54-pwvg-rqq5", - "modified": "2023-06-06T21:30:18Z", + "modified": "2023-06-21T21:30:22Z", "published": "2023-06-06T21:30:18Z", "aliases": [ "CVE-2023-2603" ], "details": "A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json b/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json index c9f626b2700..5c316d7b3f4 100644 --- a/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json +++ b/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], "severity": null, "github_reviewed": false,