From 880c358666d3c0bdd807d5f963155a3b3aebd9b2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Dec 2024 12:32:03 +0000 Subject: [PATCH] Publish Advisories GHSA-4cqj-vg46-4946 GHSA-ffw9-qr6v-4c9c GHSA-gm94-vr86-wgqv GHSA-h7hf-xhjp-fvww GHSA-hc6q-5pvq-h8ff GHSA-jm85-vm3h-hj2v GHSA-jpj4-cc78-mvh2 GHSA-mcxh-4gjr-cmr4 GHSA-p4pq-33vh-rcmg GHSA-pvh6-5fjm-pm8r GHSA-q674-gg53-r46c GHSA-v55h-fmcq-hv7v GHSA-w867-8ghv-295x GHSA-xx24-r484-7p82 --- .../GHSA-4cqj-vg46-4946.json | 36 +++++++++++++++++++ .../GHSA-ffw9-qr6v-4c9c.json | 36 +++++++++++++++++++ .../GHSA-gm94-vr86-wgqv.json | 36 +++++++++++++++++++ .../GHSA-h7hf-xhjp-fvww.json | 36 +++++++++++++++++++ .../GHSA-hc6q-5pvq-h8ff.json | 36 +++++++++++++++++++ .../GHSA-jm85-vm3h-hj2v.json | 36 +++++++++++++++++++ .../GHSA-jpj4-cc78-mvh2.json | 36 +++++++++++++++++++ .../GHSA-mcxh-4gjr-cmr4.json | 36 +++++++++++++++++++ .../GHSA-p4pq-33vh-rcmg.json | 36 +++++++++++++++++++ .../GHSA-pvh6-5fjm-pm8r.json | 36 +++++++++++++++++++ .../GHSA-q674-gg53-r46c.json | 36 +++++++++++++++++++ .../GHSA-v55h-fmcq-hv7v.json | 36 +++++++++++++++++++ .../GHSA-w867-8ghv-295x.json | 36 +++++++++++++++++++ .../GHSA-xx24-r484-7p82.json | 36 +++++++++++++++++++ 14 files changed, 504 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-4cqj-vg46-4946/GHSA-4cqj-vg46-4946.json create mode 100644 advisories/unreviewed/2024/12/GHSA-ffw9-qr6v-4c9c/GHSA-ffw9-qr6v-4c9c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h7hf-xhjp-fvww/GHSA-h7hf-xhjp-fvww.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hc6q-5pvq-h8ff/GHSA-hc6q-5pvq-h8ff.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jm85-vm3h-hj2v/GHSA-jm85-vm3h-hj2v.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jpj4-cc78-mvh2/GHSA-jpj4-cc78-mvh2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mcxh-4gjr-cmr4/GHSA-mcxh-4gjr-cmr4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p4pq-33vh-rcmg/GHSA-p4pq-33vh-rcmg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pvh6-5fjm-pm8r/GHSA-pvh6-5fjm-pm8r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q674-gg53-r46c/GHSA-q674-gg53-r46c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v55h-fmcq-hv7v/GHSA-v55h-fmcq-hv7v.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w867-8ghv-295x/GHSA-w867-8ghv-295x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xx24-r484-7p82/GHSA-xx24-r484-7p82.json diff --git a/advisories/unreviewed/2024/12/GHSA-4cqj-vg46-4946/GHSA-4cqj-vg46-4946.json b/advisories/unreviewed/2024/12/GHSA-4cqj-vg46-4946/GHSA-4cqj-vg46-4946.json new file mode 100644 index 00000000000..4aecebb4bb4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4cqj-vg46-4946/GHSA-4cqj-vg46-4946.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cqj-vg46-4946", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9210" + ], + "details": "There is an insufficient integrity vulnerability in Huawei products. A module does not perform sufficient integrity check in a specific scenario. Attackers can exploit the vulnerability by physically install malware. This could compromise normal service of the affected device. (Vulnerability ID: HWPSIRT-2020-00145)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9210.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9210" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2021/huawei-sa-20210106-01-myna-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-354" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ffw9-qr6v-4c9c/GHSA-ffw9-qr6v-4c9c.json b/advisories/unreviewed/2024/12/GHSA-ffw9-qr6v-4c9c/GHSA-ffw9-qr6v-4c9c.json new file mode 100644 index 00000000000..032243b0a09 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ffw9-qr6v-4c9c/GHSA-ffw9-qr6v-4c9c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffw9-qr6v-4c9c", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9086" + ], + "details": "There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service abnormal. (Vulnerability ID: HWPSIRT-2017-08234)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9086.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9086" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200826-01-buffer_en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-124" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json b/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json new file mode 100644 index 00000000000..a1b7e3aeee4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gm94-vr86-wgqv/GHSA-gm94-vr86-wgqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm94-vr86-wgqv", + "modified": "2024-12-27T12:30:36Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2024-3393" + ], + "details": "A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3393" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-3393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h7hf-xhjp-fvww/GHSA-h7hf-xhjp-fvww.json b/advisories/unreviewed/2024/12/GHSA-h7hf-xhjp-fvww/GHSA-h7hf-xhjp-fvww.json new file mode 100644 index 00000000000..3ab20c16ef0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h7hf-xhjp-fvww/GHSA-h7hf-xhjp-fvww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7hf-xhjp-fvww", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-1819" + ], + "details": "There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)\n\nThe seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-1819" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20191218-01-cops-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hc6q-5pvq-h8ff/GHSA-hc6q-5pvq-h8ff.json b/advisories/unreviewed/2024/12/GHSA-hc6q-5pvq-h8ff/GHSA-hc6q-5pvq-h8ff.json new file mode 100644 index 00000000000..9d56bd93241 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hc6q-5pvq-h8ff/GHSA-hc6q-5pvq-h8ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc6q-5pvq-h8ff", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9081" + ], + "details": "There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)\n\n\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9081" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200826-15-smartphone-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jm85-vm3h-hj2v/GHSA-jm85-vm3h-hj2v.json b/advisories/unreviewed/2024/12/GHSA-jm85-vm3h-hj2v/GHSA-jm85-vm3h-hj2v.json new file mode 100644 index 00000000000..678b9de1497 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jm85-vm3h-hj2v/GHSA-jm85-vm3h-hj2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm85-vm3h-hj2v", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9082" + ], + "details": "There is an information disclosure vulnerability in several smartphones. The system has a logic judging error under certain scenario, the attacker should gain the permit to execute commands in ADB mode and then do a series of operation on the phone. Successful exploit could allow the attacker to gain certain information from certain apps locked by Applock. (Vulnerability ID: HWPSIRT-2019-07112)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9082.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9082" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200826-16-smartphone-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jpj4-cc78-mvh2/GHSA-jpj4-cc78-mvh2.json b/advisories/unreviewed/2024/12/GHSA-jpj4-cc78-mvh2/GHSA-jpj4-cc78-mvh2.json new file mode 100644 index 00000000000..987efafa5d8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jpj4-cc78-mvh2/GHSA-jpj4-cc78-mvh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpj4-cc78-mvh2", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9222" + ], + "details": "There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9222" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200826-01-fc-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mcxh-4gjr-cmr4/GHSA-mcxh-4gjr-cmr4.json b/advisories/unreviewed/2024/12/GHSA-mcxh-4gjr-cmr4/GHSA-mcxh-4gjr-cmr4.json new file mode 100644 index 00000000000..e0687f7ce47 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mcxh-4gjr-cmr4/GHSA-mcxh-4gjr-cmr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcxh-4gjr-cmr4", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-1818" + ], + "details": "There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)\n\nThe seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-1818" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20191218-01-cops-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p4pq-33vh-rcmg/GHSA-p4pq-33vh-rcmg.json b/advisories/unreviewed/2024/12/GHSA-p4pq-33vh-rcmg/GHSA-p4pq-33vh-rcmg.json new file mode 100644 index 00000000000..c748a6ad9ca --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p4pq-33vh-rcmg/GHSA-p4pq-33vh-rcmg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4pq-33vh-rcmg", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9089" + ], + "details": "There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. Attackers with user access can exploit this vulnerability to obtain some information. This can lead to information leak. (Vulnerability ID: HWPSIRT-2019-12141)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9089.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9089" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200826-09-smartphone-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pvh6-5fjm-pm8r/GHSA-pvh6-5fjm-pm8r.json b/advisories/unreviewed/2024/12/GHSA-pvh6-5fjm-pm8r/GHSA-pvh6-5fjm-pm8r.json new file mode 100644 index 00000000000..cc159a4d469 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pvh6-5fjm-pm8r/GHSA-pvh6-5fjm-pm8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvh6-5fjm-pm8r", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9236" + ], + "details": "There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to compromise module service. (Vulnerability ID: HWPSIRT-2020-05010)\n\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9236.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9236" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200812-01-fc-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q674-gg53-r46c/GHSA-q674-gg53-r46c.json b/advisories/unreviewed/2024/12/GHSA-q674-gg53-r46c/GHSA-q674-gg53-r46c.json new file mode 100644 index 00000000000..1e427dba5f1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q674-gg53-r46c/GHSA-q674-gg53-r46c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q674-gg53-r46c", + "modified": "2024-12-27T12:30:36Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9253" + ], + "details": "There is a stack overflow vulnerability in some Huawei smart phone. An attacker can craft specific packet to exploit this vulnerability. Due to insufficient verification, this could be exploited to tamper with the information to affect the availability. (Vulnerability ID: HWPSIRT-2019-11030)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9253.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9253" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200715-08-smartphone-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v55h-fmcq-hv7v/GHSA-v55h-fmcq-hv7v.json b/advisories/unreviewed/2024/12/GHSA-v55h-fmcq-hv7v/GHSA-v55h-fmcq-hv7v.json new file mode 100644 index 00000000000..8a8263d8345 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v55h-fmcq-hv7v/GHSA-v55h-fmcq-hv7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v55h-fmcq-hv7v", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9085" + ], + "details": "There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to insufficient validation of some parameter in the message, successful exploit may cause some process abnormal. (Vulnerability ID: HWPSIRT-2017-10105)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9085.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9085" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200826-01-pointer_en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w867-8ghv-295x/GHSA-w867-8ghv-295x.json b/advisories/unreviewed/2024/12/GHSA-w867-8ghv-295x/GHSA-w867-8ghv-295x.json new file mode 100644 index 00000000000..7b1faf4e76f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w867-8ghv-295x/GHSA-w867-8ghv-295x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w867-8ghv-295x", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9080" + ], + "details": "There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID: HWPSIRT-2020-05272)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9080.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9080" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200819-01-smartphone-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xx24-r484-7p82/GHSA-xx24-r484-7p82.json b/advisories/unreviewed/2024/12/GHSA-xx24-r484-7p82/GHSA-xx24-r484-7p82.json new file mode 100644 index 00000000000..c65cc124685 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xx24-r484-7p82/GHSA-xx24-r484-7p82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx24-r484-7p82", + "modified": "2024-12-27T12:30:35Z", + "published": "2024-12-27T12:30:35Z", + "aliases": [ + "CVE-2020-9211" + ], + "details": "There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103)\n\nThis vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9211" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2021/huawei-sa-20210106-01-smartphone-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T10:15:14Z" + } +} \ No newline at end of file