diff --git a/advisories/unreviewed/2023/01/GHSA-35p7-263x-jc9h/GHSA-35p7-263x-jc9h.json b/advisories/unreviewed/2023/01/GHSA-35p7-263x-jc9h/GHSA-35p7-263x-jc9h.json index 5f49dd8ec01..91a8643376f 100644 --- a/advisories/unreviewed/2023/01/GHSA-35p7-263x-jc9h/GHSA-35p7-263x-jc9h.json +++ b/advisories/unreviewed/2023/01/GHSA-35p7-263x-jc9h/GHSA-35p7-263x-jc9h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35p7-263x-jc9h", - "modified": "2023-01-30T18:30:25Z", + "modified": "2024-08-06T21:30:47Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22659" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22659" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-4vw8-623p-rpv2/GHSA-4vw8-623p-rpv2.json b/advisories/unreviewed/2023/01/GHSA-4vw8-623p-rpv2/GHSA-4vw8-623p-rpv2.json index 3b5f9191820..1ea48d819ed 100644 --- a/advisories/unreviewed/2023/01/GHSA-4vw8-623p-rpv2/GHSA-4vw8-623p-rpv2.json +++ b/advisories/unreviewed/2023/01/GHSA-4vw8-623p-rpv2/GHSA-4vw8-623p-rpv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vw8-623p-rpv2", - "modified": "2023-02-02T00:30:16Z", + "modified": "2024-08-06T21:30:47Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22662" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22662" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-f846-r37x-3h9w/GHSA-f846-r37x-3h9w.json b/advisories/unreviewed/2023/01/GHSA-f846-r37x-3h9w/GHSA-f846-r37x-3h9w.json index fecb1d5831d..a4cf36f585e 100644 --- a/advisories/unreviewed/2023/01/GHSA-f846-r37x-3h9w/GHSA-f846-r37x-3h9w.json +++ b/advisories/unreviewed/2023/01/GHSA-f846-r37x-3h9w/GHSA-f846-r37x-3h9w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f846-r37x-3h9w", - "modified": "2023-01-30T18:30:20Z", + "modified": "2024-08-06T21:30:46Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22654" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22654" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-g43h-746q-4j8p/GHSA-g43h-746q-4j8p.json b/advisories/unreviewed/2023/01/GHSA-g43h-746q-4j8p/GHSA-g43h-746q-4j8p.json index 1ef8c451324..29b0faecd69 100644 --- a/advisories/unreviewed/2023/01/GHSA-g43h-746q-4j8p/GHSA-g43h-746q-4j8p.json +++ b/advisories/unreviewed/2023/01/GHSA-g43h-746q-4j8p/GHSA-g43h-746q-4j8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g43h-746q-4j8p", - "modified": "2023-01-30T18:30:22Z", + "modified": "2024-08-06T21:30:47Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22657" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22657" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-gp9q-v6ph-4fp7/GHSA-gp9q-v6ph-4fp7.json b/advisories/unreviewed/2023/01/GHSA-gp9q-v6ph-4fp7/GHSA-gp9q-v6ph-4fp7.json index 867a8eb487d..46e8a5f4501 100644 --- a/advisories/unreviewed/2023/01/GHSA-gp9q-v6ph-4fp7/GHSA-gp9q-v6ph-4fp7.json +++ b/advisories/unreviewed/2023/01/GHSA-gp9q-v6ph-4fp7/GHSA-gp9q-v6ph-4fp7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gp9q-v6ph-4fp7", - "modified": "2023-01-30T18:30:21Z", + "modified": "2024-08-06T21:30:46Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22656" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22656" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-p37c-3rwx-j4gw/GHSA-p37c-3rwx-j4gw.json b/advisories/unreviewed/2023/01/GHSA-p37c-3rwx-j4gw/GHSA-p37c-3rwx-j4gw.json index c6f2029300d..08eb4b9e5f6 100644 --- a/advisories/unreviewed/2023/01/GHSA-p37c-3rwx-j4gw/GHSA-p37c-3rwx-j4gw.json +++ b/advisories/unreviewed/2023/01/GHSA-p37c-3rwx-j4gw/GHSA-p37c-3rwx-j4gw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p37c-3rwx-j4gw", - "modified": "2023-01-30T18:30:21Z", + "modified": "2024-08-06T21:30:46Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22655" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22655" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-qwhg-pvmj-c2g2/GHSA-qwhg-pvmj-c2g2.json b/advisories/unreviewed/2023/01/GHSA-qwhg-pvmj-c2g2/GHSA-qwhg-pvmj-c2g2.json index 45993405b60..5f6be7c9323 100644 --- a/advisories/unreviewed/2023/01/GHSA-qwhg-pvmj-c2g2/GHSA-qwhg-pvmj-c2g2.json +++ b/advisories/unreviewed/2023/01/GHSA-qwhg-pvmj-c2g2/GHSA-qwhg-pvmj-c2g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwhg-pvmj-c2g2", - "modified": "2023-02-02T00:30:16Z", + "modified": "2024-08-06T21:30:47Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22660" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22660" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-rf9w-rpj6-vm45/GHSA-rf9w-rpj6-vm45.json b/advisories/unreviewed/2023/01/GHSA-rf9w-rpj6-vm45/GHSA-rf9w-rpj6-vm45.json index 5621e077217..563f7d8eb43 100644 --- a/advisories/unreviewed/2023/01/GHSA-rf9w-rpj6-vm45/GHSA-rf9w-rpj6-vm45.json +++ b/advisories/unreviewed/2023/01/GHSA-rf9w-rpj6-vm45/GHSA-rf9w-rpj6-vm45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf9w-rpj6-vm45", - "modified": "2023-02-02T00:30:16Z", + "modified": "2024-08-06T21:30:47Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22661" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22661" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json b/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json index b7e9fab9254..7feed758de8 100644 --- a/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json +++ b/advisories/unreviewed/2023/01/GHSA-v9hj-4wpj-hcq2/GHSA-v9hj-4wpj-hcq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9hj-4wpj-hcq2", - "modified": "2023-01-30T18:30:23Z", + "modified": "2024-08-06T21:30:46Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22658" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22658" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2023/01/GHSA-xr9x-fhcv-6qm7/GHSA-xr9x-fhcv-6qm7.json b/advisories/unreviewed/2023/01/GHSA-xr9x-fhcv-6qm7/GHSA-xr9x-fhcv-6qm7.json index 80aca8cab73..40bc6f7a4fd 100644 --- a/advisories/unreviewed/2023/01/GHSA-xr9x-fhcv-6qm7/GHSA-xr9x-fhcv-6qm7.json +++ b/advisories/unreviewed/2023/01/GHSA-xr9x-fhcv-6qm7/GHSA-xr9x-fhcv-6qm7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xr9x-fhcv-6qm7", - "modified": "2023-01-30T21:30:44Z", + "modified": "2024-08-06T21:30:46Z", "published": "2023-01-20T21:30:32Z", "aliases": [ "CVE-2020-22653" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22653" }, + { + "type": "WEB", + "url": "https://hdhrmi.blogspot.com/2020/03/multiple-vulnerabilities-in-ruckus.html?m=1" + }, { "type": "WEB", "url": "https://support.ruckuswireless.com/security_bulletins/302" diff --git a/advisories/unreviewed/2024/03/GHSA-4qvc-25ff-jcmq/GHSA-4qvc-25ff-jcmq.json b/advisories/unreviewed/2024/03/GHSA-4qvc-25ff-jcmq/GHSA-4qvc-25ff-jcmq.json index 6576b0a81f3..d79bda35ba6 100644 --- a/advisories/unreviewed/2024/03/GHSA-4qvc-25ff-jcmq/GHSA-4qvc-25ff-jcmq.json +++ b/advisories/unreviewed/2024/03/GHSA-4qvc-25ff-jcmq/GHSA-4qvc-25ff-jcmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qvc-25ff-jcmq", - "modified": "2024-03-27T00:30:57Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-03-27T00:30:57Z", "aliases": [ "CVE-2024-2209" ], "details": "A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T00:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json b/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json index 3ee3e165bf2..73289a65a4e 100644 --- a/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json +++ b/advisories/unreviewed/2024/03/GHSA-w853-6hc5-89h2/GHSA-w853-6hc5-89h2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w853-6hc5-89h2", - "modified": "2024-03-20T15:32:21Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-03-20T15:32:21Z", "aliases": [ "CVE-2024-24336" ], "details": "A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users visiting the affected page, via the 'Circulation note' and ‘Patrons Restriction’ components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json b/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json index 4ea3f0a958d..8d6fdb2ae6d 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json +++ b/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json @@ -56,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-f685-p7gp-hwrf/GHSA-f685-p7gp-hwrf.json b/advisories/unreviewed/2024/04/GHSA-f685-p7gp-hwrf/GHSA-f685-p7gp-hwrf.json index 972c03d4c4c..bc840ce951b 100644 --- a/advisories/unreviewed/2024/04/GHSA-f685-p7gp-hwrf/GHSA-f685-p7gp-hwrf.json +++ b/advisories/unreviewed/2024/04/GHSA-f685-p7gp-hwrf/GHSA-f685-p7gp-hwrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f685-p7gp-hwrf", - "modified": "2024-04-30T21:30:32Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-04-30T21:30:32Z", "aliases": [ "CVE-2024-26331" ], "details": "ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T19:15:23Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json b/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json index 39797a33c01..b53cf3bcca4 100644 --- a/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json +++ b/advisories/unreviewed/2024/04/GHSA-fff2-pwcg-x73m/GHSA-fff2-pwcg-x73m.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-r2fj-j5gm-xjr5/GHSA-r2fj-j5gm-xjr5.json b/advisories/unreviewed/2024/04/GHSA-r2fj-j5gm-xjr5/GHSA-r2fj-j5gm-xjr5.json index 55a3a9db36e..6d85c9aee4f 100644 --- a/advisories/unreviewed/2024/04/GHSA-r2fj-j5gm-xjr5/GHSA-r2fj-j5gm-xjr5.json +++ b/advisories/unreviewed/2024/04/GHSA-r2fj-j5gm-xjr5/GHSA-r2fj-j5gm-xjr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2fj-j5gm-xjr5", - "modified": "2024-05-05T18:30:33Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-04-30T15:30:37Z", "aliases": [ "CVE-2024-33309" ], "details": "An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information via an insecure API endpoint", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T15:15:53Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7gj8-545r-5295/GHSA-7gj8-545r-5295.json b/advisories/unreviewed/2024/07/GHSA-7gj8-545r-5295/GHSA-7gj8-545r-5295.json index 17ec6d88e72..ae7471d5434 100644 --- a/advisories/unreviewed/2024/07/GHSA-7gj8-545r-5295/GHSA-7gj8-545r-5295.json +++ b/advisories/unreviewed/2024/07/GHSA-7gj8-545r-5295/GHSA-7gj8-545r-5295.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-cc8c-62x7-qwjr/GHSA-cc8c-62x7-qwjr.json b/advisories/unreviewed/2024/07/GHSA-cc8c-62x7-qwjr/GHSA-cc8c-62x7-qwjr.json index ec973616469..7e8cef5d86d 100644 --- a/advisories/unreviewed/2024/07/GHSA-cc8c-62x7-qwjr/GHSA-cc8c-62x7-qwjr.json +++ b/advisories/unreviewed/2024/07/GHSA-cc8c-62x7-qwjr/GHSA-cc8c-62x7-qwjr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-cm9f-fpj4-64q9/GHSA-cm9f-fpj4-64q9.json b/advisories/unreviewed/2024/07/GHSA-cm9f-fpj4-64q9/GHSA-cm9f-fpj4-64q9.json index 2b89b523d5c..be0c6f1c323 100644 --- a/advisories/unreviewed/2024/07/GHSA-cm9f-fpj4-64q9/GHSA-cm9f-fpj4-64q9.json +++ b/advisories/unreviewed/2024/07/GHSA-cm9f-fpj4-64q9/GHSA-cm9f-fpj4-64q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cm9f-fpj4-64q9", - "modified": "2024-08-01T15:32:13Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-07-26T21:31:16Z", "aliases": [ "CVE-2024-41628" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://docs.severalnines.com/docs/clustercontrol/changelogs/changes-in-v2-1-0" }, + { + "type": "WEB", + "url": "https://github.com/Redshift-CyberSecurity/CVE-2024-41628" + }, { "type": "WEB", "url": "http://clustercontrol.com" diff --git a/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json b/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json index 06aa7d038b5..a1cca7cdf68 100644 --- a/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json +++ b/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json b/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json new file mode 100644 index 00000000000..f11442d10af --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-373g-hg3v-qf78", + "modified": "2024-08-06T21:30:48Z", + "published": "2024-08-06T21:30:48Z", + "aliases": [ + "CVE-2024-7534" + ], + "details": "Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7534" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/352467338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3rxw-3rwx-9c67/GHSA-3rxw-3rwx-9c67.json b/advisories/unreviewed/2024/08/GHSA-3rxw-3rwx-9c67/GHSA-3rxw-3rwx-9c67.json new file mode 100644 index 00000000000..009efa4c3a4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3rxw-3rwx-9c67/GHSA-3rxw-3rwx-9c67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rxw-3rwx-9c67", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42400" + ], + "details": "Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42400" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json b/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json new file mode 100644 index 00000000000..12ded5c347f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4c65-phqf-cq3w/GHSA-4c65-phqf-cq3w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c65-phqf-cq3w", + "modified": "2024-08-06T21:30:48Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-7532" + ], + "details": "Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7532" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/350528343" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4r7q-rwrj-9wg2/GHSA-4r7q-rwrj-9wg2.json b/advisories/unreviewed/2024/08/GHSA-4r7q-rwrj-9wg2/GHSA-4r7q-rwrj-9wg2.json new file mode 100644 index 00000000000..b901223eced --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4r7q-rwrj-9wg2/GHSA-4r7q-rwrj-9wg2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r7q-rwrj-9wg2", + "modified": "2024-08-06T21:30:48Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-7533" + ], + "details": "Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7533" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/353552540" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json b/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json new file mode 100644 index 00000000000..bb5083c04e1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r3g-hmqv-cpgr", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42398" + ], + "details": "Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42398" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9h4x-2mmw-9488/GHSA-9h4x-2mmw-9488.json b/advisories/unreviewed/2024/08/GHSA-9h4x-2mmw-9488/GHSA-9h4x-2mmw-9488.json new file mode 100644 index 00000000000..936c9bcea24 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9h4x-2mmw-9488/GHSA-9h4x-2mmw-9488.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h4x-2mmw-9488", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42399" + ], + "details": "Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42399" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json b/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json index e33e7a41ed2..69f5978866a 100644 --- a/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json +++ b/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v35-4xcr-w9ph", - "modified": "2024-08-01T18:32:50Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-08-01T18:32:50Z", "aliases": [ "CVE-2024-41260" ], "details": "A static initialization vector (IV) in the encrypt function of netbird v0.28.4 allows attackers to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-321" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-01T16:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json b/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json index e15196e7c9e..7cb3ce5a303 100644 --- a/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json +++ b/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6ch-gp25-6cpv", - "modified": "2024-08-06T18:30:57Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-08-06T18:30:57Z", "aliases": [ "CVE-2024-6998" ], "details": "Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:50Z" diff --git a/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json b/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json new file mode 100644 index 00000000000..39acc4077e8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frq3-h54x-6725", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42218" + ], + "details": "1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42218" + }, + { + "type": "WEB", + "url": "https://app-updates.agilebits.com" + }, + { + "type": "WEB", + "url": "https://support.1password.com/kb/202408" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json b/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json new file mode 100644 index 00000000000..068be1d06bd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gqq7-89cw-236x/GHSA-gqq7-89cw-236x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqq7-89cw-236x", + "modified": "2024-08-06T21:30:48Z", + "published": "2024-08-06T21:30:48Z", + "aliases": [ + "CVE-2024-7536" + ], + "details": "Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7536" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/354847246" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json b/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json new file mode 100644 index 00000000000..8b7d304e0a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gvhm-xpqg-38jw/GHSA-gvhm-xpqg-38jw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvhm-xpqg-38jw", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-28739" + ], + "details": "An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28739" + }, + { + "type": "WEB", + "url": "https://febin0x4e4a.wordpress.com/2024/03/07/xss-to-one-click-rce-in-koha-ils" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json b/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json new file mode 100644 index 00000000000..743210afeb2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj89-h95x-jw36", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42397" + ], + "details": "Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42397" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json b/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json new file mode 100644 index 00000000000..46adc277e2e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m578-pv52-h53w/GHSA-m578-pv52-h53w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m578-pv52-h53w", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42395" + ], + "details": "There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42395" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mccf-vjw6-rwhg/GHSA-mccf-vjw6-rwhg.json b/advisories/unreviewed/2024/08/GHSA-mccf-vjw6-rwhg/GHSA-mccf-vjw6-rwhg.json new file mode 100644 index 00000000000..570e8b629b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mccf-vjw6-rwhg/GHSA-mccf-vjw6-rwhg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mccf-vjw6-rwhg", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42396" + ], + "details": "Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42396" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mm8x-5pvc-7mmq/GHSA-mm8x-5pvc-7mmq.json b/advisories/unreviewed/2024/08/GHSA-mm8x-5pvc-7mmq/GHSA-mm8x-5pvc-7mmq.json new file mode 100644 index 00000000000..f231b9b5dcf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mm8x-5pvc-7mmq/GHSA-mm8x-5pvc-7mmq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm8x-5pvc-7mmq", + "modified": "2024-08-06T21:30:48Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-7535" + ], + "details": "Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7535" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/352690885" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p3pf-mff8-3h47/GHSA-p3pf-mff8-3h47.json b/advisories/unreviewed/2024/08/GHSA-p3pf-mff8-3h47/GHSA-p3pf-mff8-3h47.json new file mode 100644 index 00000000000..512e18b8d3c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p3pf-mff8-3h47/GHSA-p3pf-mff8-3h47.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3pf-mff8-3h47", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-41270" + ], + "details": "An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41270" + }, + { + "type": "WEB", + "url": "https://gist.github.com/nyxfqq/cfae38fada582a0f576d154be1aeb1fc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q3fp-vrq4-532q/GHSA-q3fp-vrq4-532q.json b/advisories/unreviewed/2024/08/GHSA-q3fp-vrq4-532q/GHSA-q3fp-vrq4-532q.json new file mode 100644 index 00000000000..c1445d16191 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q3fp-vrq4-532q/GHSA-q3fp-vrq4-532q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3fp-vrq4-532q", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42219" + ], + "details": "1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42219" + }, + { + "type": "WEB", + "url": "https://app-updates.agilebits.com" + }, + { + "type": "WEB", + "url": "https://support.1password.com/kb/202408a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q6mf-h7m3-wffm/GHSA-q6mf-h7m3-wffm.json b/advisories/unreviewed/2024/08/GHSA-q6mf-h7m3-wffm/GHSA-q6mf-h7m3-wffm.json new file mode 100644 index 00000000000..416e6aab695 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q6mf-h7m3-wffm/GHSA-q6mf-h7m3-wffm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6mf-h7m3-wffm", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42393" + ], + "details": "There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42393" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r54r-2wq9-h4ww/GHSA-r54r-2wq9-h4ww.json b/advisories/unreviewed/2024/08/GHSA-r54r-2wq9-h4ww/GHSA-r54r-2wq9-h4ww.json new file mode 100644 index 00000000000..d6326fe089e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r54r-2wq9-h4ww/GHSA-r54r-2wq9-h4ww.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r54r-2wq9-h4ww", + "modified": "2024-08-06T21:30:48Z", + "published": "2024-08-06T21:30:48Z", + "aliases": [ + "CVE-2024-7550" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7550" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/355256380" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T21:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v82q-947r-frwp/GHSA-v82q-947r-frwp.json b/advisories/unreviewed/2024/08/GHSA-v82q-947r-frwp/GHSA-v82q-947r-frwp.json new file mode 100644 index 00000000000..5b063baf520 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v82q-947r-frwp/GHSA-v82q-947r-frwp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v82q-947r-frwp", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-28740" + ], + "details": "Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28740" + }, + { + "type": "WEB", + "url": "https://febin0x4e4a.wordpress.com/2023/01/11/xss-vulnerability-in-koha-integrated-library-system" + }, + { + "type": "WEB", + "url": "https://febin0x4e4a.wordpress.com/2024/03/07/xss-to-one-click-rce-in-koha-ils" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json b/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json new file mode 100644 index 00000000000..b42cc7c90be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v9rg-h6h9-q754/GHSA-v9rg-h6h9-q754.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9rg-h6h9-q754", + "modified": "2024-08-06T21:30:47Z", + "published": "2024-08-06T21:30:47Z", + "aliases": [ + "CVE-2024-42394" + ], + "details": "There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42394" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json b/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json index 1a754aa8849..e7d9deb1da4 100644 --- a/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json +++ b/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpvc-jgp6-vg6f", - "modified": "2024-08-06T18:30:57Z", + "modified": "2024-08-06T21:30:47Z", "published": "2024-08-06T18:30:57Z", "aliases": [ "CVE-2024-6988" ], "details": "Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T16:15:49Z"