From 89f654e14413565fe8806988431548365569b7f5 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Thu, 7 Nov 2024 18:31:59 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-qrqv-26gf-xgwh.json | 126 ++++++++++++++++++
.../GHSA-rp8c-4xv6-27j8.json | 2 +-
.../GHSA-2977-w3fj-rc33.json | 11 +-
.../GHSA-8g3f-2wpw-9j4h.json | 9 +-
.../GHSA-9rf2-394m-48f4.json | 9 +-
.../GHSA-9rfw-9cwj-2c6f.json | 9 +-
.../GHSA-38mw-3mfv-34fc.json | 2 +-
.../GHSA-6x38-gwgp-2pcm.json | 9 +-
.../GHSA-9cgg-5x5j-5c33.json | 9 +-
.../GHSA-g2m6-m2m8-q4qh.json | 11 +-
.../GHSA-mfw5-pp35-j4h8.json | 9 +-
.../GHSA-qgvx-mvf3-xw8r.json | 11 +-
.../GHSA-rfqm-jp7w-mhx8.json | 11 +-
.../GHSA-v5w3-8cw8-83hq.json | 11 +-
.../GHSA-v7f6-wfg6-2hv6.json | 9 +-
.../GHSA-vr5f-v75p-g4qw.json | 9 +-
.../GHSA-wq2c-938c-jg3c.json | 9 +-
.../GHSA-x338-2m9x-gw9v.json | 11 +-
.../GHSA-xhm5-2j4f-4x4p.json | 11 +-
.../GHSA-f722-mp6c-4849.json | 11 +-
.../GHSA-fwhc-9g43-hmcm.json | 11 +-
.../GHSA-jfm9-vph2-8wfq.json | 11 +-
.../GHSA-mpqv-9884-5x3c.json | 2 +-
.../GHSA-qfqh-2r56-v98p.json | 2 +-
.../GHSA-v7mg-j3ph-w749.json | 11 +-
.../GHSA-x8rv-vr65-phwh.json | 9 +-
.../GHSA-xq4m-hfgr-r2x5.json | 9 +-
.../GHSA-265f-v3vf-6m77.json | 9 +-
.../GHSA-33w7-r9c3-9qwq.json | 11 +-
.../GHSA-5g7f-2wxq-wj73.json | 11 +-
.../GHSA-86hr-63r2-f3c9.json | 11 +-
.../GHSA-973h-x7w2-jgpx.json | 9 +-
.../GHSA-h347-4rgx-68rr.json | 9 +-
.../GHSA-hcvq-7hmv-2q86.json | 9 +-
.../GHSA-hh52-hj46-fhvm.json | 11 +-
.../GHSA-jg34-cmw8-gw85.json | 9 +-
.../GHSA-mpm3-wjp6-8g7x.json | 9 +-
.../GHSA-pfcp-m93f-hrvg.json | 9 +-
.../GHSA-qgpq-9pcq-24fj.json | 11 +-
.../GHSA-r7pj-34j8-6jgg.json | 9 +-
.../GHSA-rh2v-79c5-2v68.json | 11 +-
.../GHSA-vpwx-x2qh-rw8j.json | 11 +-
.../GHSA-vvgm-85j8-2648.json | 9 +-
.../GHSA-xrrj-cr4g-f623.json | 11 +-
.../GHSA-4xjp-m233-hj66.json | 9 +-
.../GHSA-7g8p-3g9q-44r8.json | 9 +-
.../GHSA-hfwg-2mm4-h8c4.json | 11 +-
.../GHSA-w69w-gv35-vqjh.json | 9 +-
.../GHSA-p36x-j8pc-9vcr.json | 11 +-
.../GHSA-p9pr-gh8g-j3cx.json | 9 +-
.../GHSA-xfp3-mm6f-4fw4.json | 11 +-
.../GHSA-25m4-rhwx-m523.json | 2 +-
.../GHSA-365x-gvhj-29hg.json | 3 +-
.../GHSA-8qrg-fxff-9fcm.json | 11 +-
.../GHSA-9x5x-jw3v-frfw.json | 9 +-
.../GHSA-jx8h-cfqr-f26f.json | 11 +-
.../GHSA-qpr4-w3rc-m373.json | 2 +-
.../GHSA-vch3-xc23-jrf2.json | 9 +-
.../GHSA-2mvw-cmvf-9wp4.json | 9 +-
.../GHSA-3fgp-h8mw-wrh5.json | 11 +-
.../GHSA-3qgh-6635-p7pp.json | 39 ++++++
.../GHSA-3v5g-chfr-w797.json | 35 +++++
.../GHSA-44f7-vf3h-r86f.json | 39 ++++++
.../GHSA-6mm9-jjjf-pcj3.json | 39 ++++++
.../GHSA-6rcc-2x92-3rpg.json | 35 +++++
.../GHSA-74f8-hfjw-wvrf.json | 11 +-
.../GHSA-c4pf-hc84-698h.json | 43 ++++++
.../GHSA-cp74-46v8-qrjr.json | 43 ++++++
.../GHSA-fjv6-j3p5-xvwr.json | 35 +++++
.../GHSA-g93m-8x6h-g5gv.json | 9 +-
.../GHSA-h4jm-pc24-hx88.json | 43 ++++++
.../GHSA-hcpx-v556-ch6p.json | 38 ++++++
.../GHSA-j7hj-68jp-pg28.json | 35 +++++
.../GHSA-j9g6-vvr6-x5wm.json | 38 ++++++
.../GHSA-jgqg-jqq9-5x4c.json | 43 ++++++
.../GHSA-mhq2-gxcg-4hc8.json | 3 +-
.../GHSA-mpfv-w8fh-9hfv.json | 62 +++++++++
.../GHSA-mw3p-xpcv-h9gq.json | 62 +++++++++
.../GHSA-pcrp-7g2p-q7pj.json | 43 ++++++
.../GHSA-q37q-6c8j-qf6q.json | 35 +++++
.../GHSA-q7m5-chmw-937j.json | 35 +++++
.../GHSA-qrqv-26gf-xgwh.json | 42 ------
.../GHSA-qw6p-p38p-ggp9.json | 62 +++++++++
.../GHSA-rw99-6hrh-fmjr.json | 42 ++++++
.../GHSA-rwhw-2ccq-46p7.json | 58 ++++++++
.../GHSA-w7p4-hj4q-wh7p.json | 35 +++++
.../GHSA-wxg7-96h5-9qcc.json | 43 ++++++
.../GHSA-xq95-8x62-4j38.json | 39 ++++++
88 files changed, 1507 insertions(+), 238 deletions(-)
create mode 100644 advisories/github-reviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-3v5g-chfr-w797/GHSA-3v5g-chfr-w797.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-44f7-vf3h-r86f/GHSA-44f7-vf3h-r86f.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-6mm9-jjjf-pcj3/GHSA-6mm9-jjjf-pcj3.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-cp74-46v8-qrjr/GHSA-cp74-46v8-qrjr.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-q7m5-chmw-937j/GHSA-q7m5-chmw-937j.json
delete mode 100644 advisories/unreviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-qw6p-p38p-ggp9/GHSA-qw6p-p38p-ggp9.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-rw99-6hrh-fmjr/GHSA-rw99-6hrh-fmjr.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json
create mode 100644 advisories/unreviewed/2024/11/GHSA-xq95-8x62-4j38/GHSA-xq95-8x62-4j38.json
diff --git a/advisories/github-reviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json b/advisories/github-reviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json
new file mode 100644
index 00000000000..24fdcfea2e4
--- /dev/null
+++ b/advisories/github-reviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json
@@ -0,0 +1,126 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qrqv-26gf-xgwh",
+ "modified": "2024-11-07T18:30:36Z",
+ "published": "2024-11-07T15:31:52Z",
+ "aliases": [
+ "CVE-2024-43440"
+ ],
+ "summary": "Moodle LFI vulnerability when restoring malformed block backups",
+ "details": "A flaw was found in moodle. A local file may include risks when restoring block backups.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "moodle/moodle"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "4.1.12"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "moodle/moodle"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "4.2.0-beta"
+ },
+ {
+ "fixed": "4.2.9"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "moodle/moodle"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "4.3.0-beta"
+ },
+ {
+ "fixed": "4.3.6"
+ }
+ ]
+ }
+ ]
+ },
+ {
+ "package": {
+ "ecosystem": "Packagist",
+ "name": "moodle/moodle"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "4.4.0-beta"
+ },
+ {
+ "fixed": "4.4.2"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43440"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2304269"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/moodle/moodle"
+ },
+ {
+ "type": "WEB",
+ "url": "https://moodle.org/mod/forum/discuss.php?d=461210"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-11-07T18:30:36Z",
+ "nvd_published_at": "2024-11-07T14:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2023/07/GHSA-rp8c-4xv6-27j8/GHSA-rp8c-4xv6-27j8.json b/advisories/unreviewed/2023/07/GHSA-rp8c-4xv6-27j8/GHSA-rp8c-4xv6-27j8.json
index cfe30d1f7c0..0a77055bea6 100644
--- a/advisories/unreviewed/2023/07/GHSA-rp8c-4xv6-27j8/GHSA-rp8c-4xv6-27j8.json
+++ b/advisories/unreviewed/2023/07/GHSA-rp8c-4xv6-27j8/GHSA-rp8c-4xv6-27j8.json
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/02/GHSA-2977-w3fj-rc33/GHSA-2977-w3fj-rc33.json b/advisories/unreviewed/2024/02/GHSA-2977-w3fj-rc33/GHSA-2977-w3fj-rc33.json
index d6bb9eff1a4..2fffc6eccce 100644
--- a/advisories/unreviewed/2024/02/GHSA-2977-w3fj-rc33/GHSA-2977-w3fj-rc33.json
+++ b/advisories/unreviewed/2024/02/GHSA-2977-w3fj-rc33/GHSA-2977-w3fj-rc33.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2977-w3fj-rc33",
- "modified": "2024-02-29T00:30:22Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-02-29T00:30:22Z",
"aliases": [
"CVE-2023-49338"
],
"details": "Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-276"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T22:15:26Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-8g3f-2wpw-9j4h/GHSA-8g3f-2wpw-9j4h.json b/advisories/unreviewed/2024/02/GHSA-8g3f-2wpw-9j4h/GHSA-8g3f-2wpw-9j4h.json
index 78dd152a389..0ae3f29588a 100644
--- a/advisories/unreviewed/2024/02/GHSA-8g3f-2wpw-9j4h/GHSA-8g3f-2wpw-9j4h.json
+++ b/advisories/unreviewed/2024/02/GHSA-8g3f-2wpw-9j4h/GHSA-8g3f-2wpw-9j4h.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g3f-2wpw-9j4h",
- "modified": "2024-02-21T09:31:01Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-02-21T09:31:01Z",
"aliases": [
"CVE-2023-42946"
],
"details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to leak sensitive user information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T07:15:51Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-9rf2-394m-48f4/GHSA-9rf2-394m-48f4.json b/advisories/unreviewed/2024/02/GHSA-9rf2-394m-48f4/GHSA-9rf2-394m-48f4.json
index 23698b2c738..bbb8b2d9d87 100644
--- a/advisories/unreviewed/2024/02/GHSA-9rf2-394m-48f4/GHSA-9rf2-394m-48f4.json
+++ b/advisories/unreviewed/2024/02/GHSA-9rf2-394m-48f4/GHSA-9rf2-394m-48f4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9rf2-394m-48f4",
- "modified": "2024-02-28T09:30:37Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-02-28T09:30:37Z",
"aliases": [
"CVE-2021-47006"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9064/1: hw_breakpoint: Do not directly check the event's overflow_handler hook\n\nThe commit 1879445dfa7b (\"perf/core: Set event's default\n::overflow_handler()\") set a default event->overflow_handler in\nperf_event_alloc(), and replace the check event->overflow_handler with\nis_default_overflow_handler(), but one is missing.\n\nCurrently, the bp->overflow_handler can not be NULL. As a result,\nenable_single_step() is always not invoked.\n\nComments from Zhen Lei:\n\n https://patchwork.kernel.org/project/linux-arm-kernel/patch/20210207105934.2001-1-thunder.leizhen@huawei.com/",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T09:15:38Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-9rfw-9cwj-2c6f/GHSA-9rfw-9cwj-2c6f.json b/advisories/unreviewed/2024/02/GHSA-9rfw-9cwj-2c6f/GHSA-9rfw-9cwj-2c6f.json
index bd699a40271..abebc497505 100644
--- a/advisories/unreviewed/2024/02/GHSA-9rfw-9cwj-2c6f/GHSA-9rfw-9cwj-2c6f.json
+++ b/advisories/unreviewed/2024/02/GHSA-9rfw-9cwj-2c6f/GHSA-9rfw-9cwj-2c6f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9rfw-9cwj-2c6f",
- "modified": "2024-02-21T09:31:01Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-02-21T09:31:01Z",
"aliases": [
"CVE-2023-42953"
],
"details": "A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T07:15:51Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json b/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json
index 6a52df3fc32..61be235e53a 100644
--- a/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json
+++ b/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/03/GHSA-6x38-gwgp-2pcm/GHSA-6x38-gwgp-2pcm.json b/advisories/unreviewed/2024/03/GHSA-6x38-gwgp-2pcm/GHSA-6x38-gwgp-2pcm.json
index ee49bd7f272..4d741ff6cf7 100644
--- a/advisories/unreviewed/2024/03/GHSA-6x38-gwgp-2pcm/GHSA-6x38-gwgp-2pcm.json
+++ b/advisories/unreviewed/2024/03/GHSA-6x38-gwgp-2pcm/GHSA-6x38-gwgp-2pcm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6x38-gwgp-2pcm",
- "modified": "2024-03-01T00:30:28Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-03-01T00:30:28Z",
"aliases": [
"CVE-2021-47060"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Stop looking for coalesced MMIO zones if the bus is destroyed\n\nAbort the walk of coalesced MMIO zones if kvm_io_bus_unregister_dev()\nfails to allocate memory for the new instance of the bus. If it can't\ninstantiate a new bus, unregister_dev() destroys all devices _except_ the\ntarget device. But, it doesn't tell the caller that it obliterated the\nbus and invoked the destructor for all devices that were on the bus. In\nthe coalesced MMIO case, this can result in a deleted list entry\ndereference due to attempting to continue iterating on coalesced_zones\nafter future entries (in the walk) have been deleted.\n\nOpportunistically add curly braces to the for-loop, which encompasses\nmany lines but sneaks by without braces due to the guts being a single\nif statement.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T23:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-9cgg-5x5j-5c33/GHSA-9cgg-5x5j-5c33.json b/advisories/unreviewed/2024/03/GHSA-9cgg-5x5j-5c33/GHSA-9cgg-5x5j-5c33.json
index 14c6bf48655..803fb7d79ac 100644
--- a/advisories/unreviewed/2024/03/GHSA-9cgg-5x5j-5c33/GHSA-9cgg-5x5j-5c33.json
+++ b/advisories/unreviewed/2024/03/GHSA-9cgg-5x5j-5c33/GHSA-9cgg-5x5j-5c33.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9cgg-5x5j-5c33",
- "modified": "2024-03-14T00:31:05Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-08T03:31:24Z",
"aliases": [
"CVE-2024-23227"
],
"details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to read sensitive location information.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -47,7 +50,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:47Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json b/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json
index 99fab854efc..2856b04ca5a 100644
--- a/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json
+++ b/advisories/unreviewed/2024/03/GHSA-g2m6-m2m8-q4qh/GHSA-g2m6-m2m8-q4qh.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g2m6-m2m8-q4qh",
- "modified": "2024-03-25T09:32:34Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-25T09:32:34Z",
"aliases": [
"CVE-2024-29216"
],
"details": "Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-522"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T07:15:50Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json b/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json
index c4995d2fd0e..b5ac4c39bce 100644
--- a/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json
+++ b/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfw5-pp35-j4h8",
- "modified": "2024-06-16T15:30:43Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52581"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix memleak when more than 255 elements expired\n\nWhen more than 255 elements expired we're supposed to switch to a new gc\ncontainer structure.\n\nThis never happens: u8 type will wrap before reaching the boundary\nand nft_trans_gc_space() always returns true.\n\nThis means we recycle the initial gc container structure and\nlose track of the elements that came before.\n\nWhile at it, don't deref 'gc' after we've passed it to call_rcu.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json b/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json
index aa52817d526..9adfd0520c3 100644
--- a/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json
+++ b/advisories/unreviewed/2024/03/GHSA-qgvx-mvf3-xw8r/GHSA-qgvx-mvf3-xw8r.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgvx-mvf3-xw8r",
- "modified": "2024-03-18T03:30:32Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-18T03:30:32Z",
"aliases": [
"CVE-2023-39933"
],
"details": "Insufficient verification vulnerability exists in Broadcast Mail CGI (pmc.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a user who can upload files through the product may execute an arbitrary executable file with the web server's execution privilege.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-18T01:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-rfqm-jp7w-mhx8/GHSA-rfqm-jp7w-mhx8.json b/advisories/unreviewed/2024/03/GHSA-rfqm-jp7w-mhx8/GHSA-rfqm-jp7w-mhx8.json
index d794a1c7a84..8c37f056916 100644
--- a/advisories/unreviewed/2024/03/GHSA-rfqm-jp7w-mhx8/GHSA-rfqm-jp7w-mhx8.json
+++ b/advisories/unreviewed/2024/03/GHSA-rfqm-jp7w-mhx8/GHSA-rfqm-jp7w-mhx8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfqm-jp7w-mhx8",
- "modified": "2024-03-12T21:31:00Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-12T21:31:00Z",
"aliases": [
"CVE-2024-24097"
],
"details": "Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-12T21:15:58Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json b/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json
index 56235bb128d..ce29d43d961 100644
--- a/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json
+++ b/advisories/unreviewed/2024/03/GHSA-v5w3-8cw8-83hq/GHSA-v5w3-8cw8-83hq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5w3-8cw8-83hq",
- "modified": "2024-03-26T18:32:05Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-26T18:32:05Z",
"aliases": [
"CVE-2024-2921"
],
"details": "Improper access control in PAM vault permissions in Devolutions Server 2024.1.6 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.\n\n",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-306"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T16:15:14Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-v7f6-wfg6-2hv6/GHSA-v7f6-wfg6-2hv6.json b/advisories/unreviewed/2024/03/GHSA-v7f6-wfg6-2hv6/GHSA-v7f6-wfg6-2hv6.json
index dfee759a608..e7c672670e4 100644
--- a/advisories/unreviewed/2024/03/GHSA-v7f6-wfg6-2hv6/GHSA-v7f6-wfg6-2hv6.json
+++ b/advisories/unreviewed/2024/03/GHSA-v7f6-wfg6-2hv6/GHSA-v7f6-wfg6-2hv6.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7f6-wfg6-2hv6",
- "modified": "2024-03-12T09:30:41Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-12T09:30:41Z",
"aliases": [
"CVE-2024-24964"
],
"details": "Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-12T08:15:45Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json b/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json
index 1605bf37c6d..528abdddde4 100644
--- a/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json
+++ b/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vr5f-v75p-g4qw",
- "modified": "2024-03-25T09:32:35Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-25T09:32:35Z",
"aliases": [
"CVE-2021-47140"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Clear DMA ops when switching domain\n\nSince commit 08a27c1c3ecf (\"iommu: Add support to change default domain\nof an iommu group\") a user can switch a device between IOMMU and direct\nDMA through sysfs. This doesn't work for AMD IOMMU at the moment because\ndev->dma_ops is not cleared when switching from a DMA to an identity\nIOMMU domain. The DMA layer thus attempts to use the dma-iommu ops on an\nidentity domain, causing an oops:\n\n # echo 0000:00:05.0 > /sys/sys/bus/pci/drivers/e1000e/unbind\n # echo identity > /sys/bus/pci/devices/0000:00:05.0/iommu_group/type\n # echo 0000:00:05.0 > /sys/sys/bus/pci/drivers/e1000e/bind\n ...\n BUG: kernel NULL pointer dereference, address: 0000000000000028\n ...\n Call Trace:\n iommu_dma_alloc\n e1000e_setup_tx_resources\n e1000e_open\n\nSince iommu_change_dev_def_domain() calls probe_finalize() again, clear\nthe dma_ops there like Vt-d does.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T09:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-wq2c-938c-jg3c/GHSA-wq2c-938c-jg3c.json b/advisories/unreviewed/2024/03/GHSA-wq2c-938c-jg3c/GHSA-wq2c-938c-jg3c.json
index 7a99085cece..55353114765 100644
--- a/advisories/unreviewed/2024/03/GHSA-wq2c-938c-jg3c/GHSA-wq2c-938c-jg3c.json
+++ b/advisories/unreviewed/2024/03/GHSA-wq2c-938c-jg3c/GHSA-wq2c-938c-jg3c.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wq2c-938c-jg3c",
- "modified": "2024-03-05T09:31:19Z",
+ "modified": "2024-11-07T18:31:19Z",
"published": "2024-03-05T09:31:19Z",
"aliases": [
"CVE-2024-26339"
],
"details": "swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T09:15:45Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-x338-2m9x-gw9v/GHSA-x338-2m9x-gw9v.json b/advisories/unreviewed/2024/03/GHSA-x338-2m9x-gw9v/GHSA-x338-2m9x-gw9v.json
index 199c9bb46e4..5c956ab162a 100644
--- a/advisories/unreviewed/2024/03/GHSA-x338-2m9x-gw9v/GHSA-x338-2m9x-gw9v.json
+++ b/advisories/unreviewed/2024/03/GHSA-x338-2m9x-gw9v/GHSA-x338-2m9x-gw9v.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x338-2m9x-gw9v",
- "modified": "2024-03-11T21:31:27Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-11T21:31:26Z",
"aliases": [
"CVE-2024-27225"
],
"details": "In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T19:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json b/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json
index b017c1b1525..9c7ade04196 100644
--- a/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json
+++ b/advisories/unreviewed/2024/03/GHSA-xhm5-2j4f-4x4p/GHSA-xhm5-2j4f-4x4p.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xhm5-2j4f-4x4p",
- "modified": "2024-03-18T09:30:30Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-03-18T09:30:30Z",
"aliases": [
"CVE-2024-21824"
],
"details": "Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-306"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-18T08:15:06Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-f722-mp6c-4849/GHSA-f722-mp6c-4849.json b/advisories/unreviewed/2024/04/GHSA-f722-mp6c-4849/GHSA-f722-mp6c-4849.json
index cf97927f64e..9cfeb04c235 100644
--- a/advisories/unreviewed/2024/04/GHSA-f722-mp6c-4849/GHSA-f722-mp6c-4849.json
+++ b/advisories/unreviewed/2024/04/GHSA-f722-mp6c-4849/GHSA-f722-mp6c-4849.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f722-mp6c-4849",
- "modified": "2024-04-11T21:30:52Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-04-11T21:30:52Z",
"aliases": [
"CVE-2024-22719"
],
"details": "SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-11T20:15:33Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-fwhc-9g43-hmcm/GHSA-fwhc-9g43-hmcm.json b/advisories/unreviewed/2024/04/GHSA-fwhc-9g43-hmcm/GHSA-fwhc-9g43-hmcm.json
index 8ac43872ac3..6e08c275f7a 100644
--- a/advisories/unreviewed/2024/04/GHSA-fwhc-9g43-hmcm/GHSA-fwhc-9g43-hmcm.json
+++ b/advisories/unreviewed/2024/04/GHSA-fwhc-9g43-hmcm/GHSA-fwhc-9g43-hmcm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fwhc-9g43-hmcm",
- "modified": "2024-04-17T00:30:57Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-04-17T00:30:57Z",
"aliases": [
"CVE-2024-29402"
],
"details": "cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-613"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T23:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json b/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json
index 09b086d4082..d6197d8fa9e 100644
--- a/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json
+++ b/advisories/unreviewed/2024/04/GHSA-jfm9-vph2-8wfq/GHSA-jfm9-vph2-8wfq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jfm9-vph2-8wfq",
- "modified": "2024-04-08T06:31:30Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-04-08T06:31:30Z",
"aliases": [
"CVE-2024-1589"
],
"details": "The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-08T05:15:07Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-mpqv-9884-5x3c/GHSA-mpqv-9884-5x3c.json b/advisories/unreviewed/2024/04/GHSA-mpqv-9884-5x3c/GHSA-mpqv-9884-5x3c.json
index f14e01504f7..c7de7d75b48 100644
--- a/advisories/unreviewed/2024/04/GHSA-mpqv-9884-5x3c/GHSA-mpqv-9884-5x3c.json
+++ b/advisories/unreviewed/2024/04/GHSA-mpqv-9884-5x3c/GHSA-mpqv-9884-5x3c.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-319"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/04/GHSA-qfqh-2r56-v98p/GHSA-qfqh-2r56-v98p.json b/advisories/unreviewed/2024/04/GHSA-qfqh-2r56-v98p/GHSA-qfqh-2r56-v98p.json
index 247598905e8..cae8dbef6f8 100644
--- a/advisories/unreviewed/2024/04/GHSA-qfqh-2r56-v98p/GHSA-qfqh-2r56-v98p.json
+++ b/advisories/unreviewed/2024/04/GHSA-qfqh-2r56-v98p/GHSA-qfqh-2r56-v98p.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/04/GHSA-v7mg-j3ph-w749/GHSA-v7mg-j3ph-w749.json b/advisories/unreviewed/2024/04/GHSA-v7mg-j3ph-w749/GHSA-v7mg-j3ph-w749.json
index a73c7949d11..f9b08e6afed 100644
--- a/advisories/unreviewed/2024/04/GHSA-v7mg-j3ph-w749/GHSA-v7mg-j3ph-w749.json
+++ b/advisories/unreviewed/2024/04/GHSA-v7mg-j3ph-w749/GHSA-v7mg-j3ph-w749.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7mg-j3ph-w749",
- "modified": "2024-04-01T03:30:40Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-04-01T03:30:40Z",
"aliases": [
"CVE-2024-20047"
],
"details": "In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587865; Issue ID: ALPS08486807.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-190"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-01T03:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json b/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json
index 2d5bce0c967..aa62f9f54ea 100644
--- a/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json
+++ b/advisories/unreviewed/2024/04/GHSA-x8rv-vr65-phwh/GHSA-x8rv-vr65-phwh.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8rv-vr65-phwh",
- "modified": "2024-04-08T09:31:13Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-04-08T09:31:13Z",
"aliases": [
"CVE-2023-52543"
],
"details": "Permission verification vulnerability in the system module.\nImpact: Successful exploitation of this vulnerability will affect availability.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-269"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-08T09:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json b/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json
index d319670220b..cc4fda9cdcf 100644
--- a/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json
+++ b/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xq4m-hfgr-r2x5",
- "modified": "2024-06-27T12:30:44Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2024-26685"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential bug in end_buffer_async_write\n\nAccording to a syzbot report, end_buffer_async_write(), which handles the\ncompletion of block device writes, may detect abnormal condition of the\nbuffer async_write flag and cause a BUG_ON failure when using nilfs2.\n\nNilfs2 itself does not use end_buffer_async_write(). But, the async_write\nflag is now used as a marker by commit 7f42ec394156 (\"nilfs2: fix issue\nwith race condition of competition between segments for dirty blocks\") as\na means of resolving double list insertion of dirty blocks in\nnilfs_lookup_dirty_data_buffers() and nilfs_lookup_node_buffers() and the\nresulting crash.\n\nThis modification is safe as long as it is used for file data and b-tree\nnode blocks where the page caches are independent. However, it was\nirrelevant and redundant to also introduce async_write for segment summary\nand super root blocks that share buffers with the backing device. This\nled to the possibility that the BUG_ON check in end_buffer_async_write\nwould fail as described above, if independent writebacks of the backing\ndevice occurred in parallel.\n\nThe use of async_write for segment summary buffers has already been\nremoved in a previous change.\n\nFix this issue by removing the manipulation of the async_write flag for\nthe remaining super root block buffer.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -63,7 +66,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:52Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json b/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json
index bc40c4d90bf..519ef14101a 100644
--- a/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json
+++ b/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-265f-v3vf-6m77",
- "modified": "2024-06-26T00:31:38Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-01T06:31:41Z",
"aliases": [
"CVE-2024-26950"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwireguard: netlink: access device through ctx instead of peer\n\nThe previous commit fixed a bug that led to a NULL peer->device being\ndereferenced. It's actually easier and faster performance-wise to\ninstead get the device from ctx->wg. This semantically makes more sense\ntoo, since ctx->wg->peer_allowedips.seq is compared with\nctx->allowedips_seq, basing them both in ctx. This also acts as a\ndefence in depth provision against freed peers.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-01T06:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json b/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json
index 3b44b4dcddc..1fa7a000e3e 100644
--- a/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json
+++ b/advisories/unreviewed/2024/05/GHSA-33w7-r9c3-9qwq/GHSA-33w7-r9c3-9qwq.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-33w7-r9c3-9qwq",
- "modified": "2024-05-21T15:31:41Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-21T15:31:41Z",
"aliases": [
"CVE-2021-47257"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ieee802154: fix null deref in parse dev addr\n\nFix a logic error that could result in a null deref if the user sets\nthe mode incorrectly for the given addr type.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:14Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json b/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json
index bdf1159ed60..71e6981fbe6 100644
--- a/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json
+++ b/advisories/unreviewed/2024/05/GHSA-5g7f-2wxq-wj73/GHSA-5g7f-2wxq-wj73.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g7f-2wxq-wj73",
- "modified": "2024-05-23T18:30:55Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-21T15:31:45Z",
"aliases": [
"CVE-2024-33527"
],
"details": "A Stored Cross-site Scripting (XSS) vulnerability in the \"Import of Users and login name of user\" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or HTML via XML file upload.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:29Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json b/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json
index e9c910bf241..78683ed3885 100644
--- a/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json
+++ b/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86hr-63r2-f3c9",
- "modified": "2024-05-22T09:31:46Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-22T09:31:46Z",
"aliases": [
"CVE-2021-47484"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Fix possible null pointer dereference.\n\nThis patch fixes possible null pointer dereference in files\n\"rvu_debugfs.c\" and \"rvu_nix.c\"",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T09:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json b/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json
index e6e3d2e7924..59bb2d2f481 100644
--- a/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json
+++ b/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-973h-x7w2-jgpx",
- "modified": "2024-05-01T15:30:35Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-01T15:30:35Z",
"aliases": [
"CVE-2024-27040"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add 'replay' NULL check in 'edp_set_replay_allow_active()'\n\nIn the first if statement, we're checking if 'replay' is NULL. But in\nthe second if statement, we're not checking if 'replay' is NULL again\nbefore calling replay->funcs->replay_set_power_opt().\n\nif (replay == NULL && force_static)\n return false;\n\n...\n\nif (link->replay_settings.replay_feature_enabled &&\n replay->funcs->replay_set_power_opt) {\n\treplay->funcs->replay_set_power_opt(replay, *power_opts, panel_inst);\n\tlink->replay_settings.replay_power_opt_active = *power_opts;\n}\n\nIf 'replay' is NULL, this will cause a null pointer dereference.\n\nFixes the below found by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/link/protocols/link_edp_panel_control.c:895 edp_set_replay_allow_active() error: we previously assumed 'replay' could be null (see line 887)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-01T13:15:49Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json b/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json
index dba76f20693..310e8d89ecf 100644
--- a/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json
+++ b/advisories/unreviewed/2024/05/GHSA-h347-4rgx-68rr/GHSA-h347-4rgx-68rr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h347-4rgx-68rr",
- "modified": "2024-05-17T15:31:09Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2023-52673"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix a debugfs null pointer error\n\n[WHY & HOW]\nCheck whether get_subvp_en() callback exists before calling it.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:10Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hcvq-7hmv-2q86/GHSA-hcvq-7hmv-2q86.json b/advisories/unreviewed/2024/05/GHSA-hcvq-7hmv-2q86/GHSA-hcvq-7hmv-2q86.json
index 68be0029a0e..780cd99b550 100644
--- a/advisories/unreviewed/2024/05/GHSA-hcvq-7hmv-2q86/GHSA-hcvq-7hmv-2q86.json
+++ b/advisories/unreviewed/2024/05/GHSA-hcvq-7hmv-2q86/GHSA-hcvq-7hmv-2q86.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcvq-7hmv-2q86",
- "modified": "2024-05-21T18:31:18Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-21T18:31:18Z",
"aliases": [
"CVE-2023-52703"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/usb: kalmia: Don't pass act_len in usb_bulk_msg error path\n\nsyzbot reported that act_len in kalmia_send_init_packet() is\nuninitialized when passing it to the first usb_bulk_msg error path. Jiri\nPirko noted that it's pointless to pass it in the error path, and that\nthe value that would be printed in the second error path would be the\nvalue of act_len from the first call to usb_bulk_msg.[1]\n\nWith this in mind, let's just not pass act_len to the usb_bulk_msg error\npaths.\n\n1: https://lore.kernel.org/lkml/Y9pY61y1nwTuzMOa@nanopsycho/",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json b/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json
index 5404110c27a..b4c1ce48906 100644
--- a/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json
+++ b/advisories/unreviewed/2024/05/GHSA-hh52-hj46-fhvm/GHSA-hh52-hj46-fhvm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh52-hj46-fhvm",
- "modified": "2024-05-14T18:30:45Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-14T18:30:45Z",
"aliases": [
"CVE-2022-32510"
],
"details": "An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-319"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T10:43:42Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-jg34-cmw8-gw85/GHSA-jg34-cmw8-gw85.json b/advisories/unreviewed/2024/05/GHSA-jg34-cmw8-gw85/GHSA-jg34-cmw8-gw85.json
index b6cff591376..b3f067178fe 100644
--- a/advisories/unreviewed/2024/05/GHSA-jg34-cmw8-gw85/GHSA-jg34-cmw8-gw85.json
+++ b/advisories/unreviewed/2024/05/GHSA-jg34-cmw8-gw85/GHSA-jg34-cmw8-gw85.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg34-cmw8-gw85",
- "modified": "2024-05-21T18:31:19Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-21T18:31:19Z",
"aliases": [
"CVE-2023-52746"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm/compat: prevent potential spectre v1 gadget in xfrm_xlate32_attr()\n\n int type = nla_type(nla);\n\n if (type > XFRMA_MAX) {\n return -EOPNOTSUPP;\n }\n\n@type is then used as an array index and can be used\nas a Spectre v1 gadget.\n\n if (nla_len(nla) < compat_policy[type].len) {\n\narray_index_nospec() can be used to prevent leaking\ncontent of kernel memory to malicious users.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:14Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json b/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json
index 421f174e383..79e1940c44c 100644
--- a/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json
+++ b/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpm3-wjp6-8g7x",
- "modified": "2024-05-21T15:31:39Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-21T15:31:39Z",
"aliases": [
"CVE-2021-47225"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: fix deadlock in AP/VLAN handling\n\nSyzbot reports that when you have AP_VLAN interfaces that are up\nand close the AP interface they belong to, we get a deadlock. No\nsurprise - since we dev_close() them with the wiphy mutex held,\nwhich goes back into the netdev notifier in cfg80211 and tries to\nacquire the wiphy mutex there.\n\nTo fix this, we need to do two things:\n 1) prevent changing iftype while AP_VLANs are up, we can't\n easily fix this case since cfg80211 already calls us with\n the wiphy mutex held, but change_interface() is relatively\n rare in drivers anyway, so changing iftype isn't used much\n (and userspace has to fall back to down/change/up anyway)\n 2) pull the dev_close() loop over VLANs out of the wiphy mutex\n section in the normal stop case",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-pfcp-m93f-hrvg/GHSA-pfcp-m93f-hrvg.json b/advisories/unreviewed/2024/05/GHSA-pfcp-m93f-hrvg/GHSA-pfcp-m93f-hrvg.json
index 4bb43e005f7..461e6d4acc3 100644
--- a/advisories/unreviewed/2024/05/GHSA-pfcp-m93f-hrvg/GHSA-pfcp-m93f-hrvg.json
+++ b/advisories/unreviewed/2024/05/GHSA-pfcp-m93f-hrvg/GHSA-pfcp-m93f-hrvg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfcp-m93f-hrvg",
- "modified": "2024-05-17T12:31:00Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-17T12:31:00Z",
"aliases": [
"CVE-2024-27402"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: fix racy skb_queue_empty() use\n\nThe receive queues are protected by their respective spin-lock, not\nthe socket lock. This could lead to skb_peek() unexpectedly\nreturning NULL or a pointer to an already dequeued socket buffer.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T12:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qgpq-9pcq-24fj/GHSA-qgpq-9pcq-24fj.json b/advisories/unreviewed/2024/05/GHSA-qgpq-9pcq-24fj/GHSA-qgpq-9pcq-24fj.json
index f1a6ea94fa0..38d4f7a48a0 100644
--- a/advisories/unreviewed/2024/05/GHSA-qgpq-9pcq-24fj/GHSA-qgpq-9pcq-24fj.json
+++ b/advisories/unreviewed/2024/05/GHSA-qgpq-9pcq-24fj/GHSA-qgpq-9pcq-24fj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgpq-9pcq-24fj",
- "modified": "2024-05-14T18:31:02Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-14T18:31:02Z",
"aliases": [
"CVE-2023-24203"
],
"details": "Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T17:15:13Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json b/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json
index 96f2d596d22..7fd292837e0 100644
--- a/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json
+++ b/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r7pj-34j8-6jgg",
- "modified": "2024-05-22T09:31:45Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-05-22T09:31:45Z",
"aliases": [
"CVE-2021-47465"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: Fix stack handling in idle_kvm_start_guest()\n\nIn commit 10d91611f426 (\"powerpc/64s: Reimplement book3s idle code in\nC\") kvm_start_guest() became idle_kvm_start_guest(). The old code\nallocated a stack frame on the emergency stack, but didn't use the\nframe to store anything, and also didn't store anything in its caller's\nframe.\n\nidle_kvm_start_guest() on the other hand is written more like a normal C\nfunction, it creates a frame on entry, and also stores CR/LR into its\ncallers frame (per the ABI). The problem is that there is no caller\nframe on the emergency stack.\n\nThe emergency stack for a given CPU is allocated with:\n\n paca_ptrs[i]->emergency_sp = alloc_stack(limit, i) + THREAD_SIZE;\n\nSo emergency_sp actually points to the first address above the emergency\nstack allocation for a given CPU, we must not store above it without\nfirst decrementing it to create a frame. This is different to the\nregular kernel stack, paca->kstack, which is initialised to point at an\ninitial frame that is ready to use.\n\nidle_kvm_start_guest() stores the backchain, CR and LR all of which\nwrite outside the allocation for the emergency stack. It then creates a\nstack frame and saves the non-volatile registers. Unfortunately the\nframe it creates is not large enough to fit the non-volatiles, and so\nthe saving of the non-volatile registers also writes outside the\nemergency stack allocation.\n\nThe end result is that we corrupt whatever is at 0-24 bytes, and 112-248\nbytes above the emergency stack allocation.\n\nIn practice this has gone unnoticed because the memory immediately above\nthe emergency stack happens to be used for other stack allocations,\neither another CPUs mc_emergency_sp or an IRQ stack. See the order of\ncalls to irqstack_early_init() and emergency_stack_init().\n\nThe low addresses of another stack are the top of that stack, and so are\nonly used if that stack is under extreme pressue, which essentially\nnever happens in practice - and if it did there's a high likelyhood we'd\ncrash due to that stack overflowing.\n\nStill, we shouldn't be corrupting someone else's stack, and it is purely\nluck that we aren't corrupting something else.\n\nTo fix it we save CR/LR into the caller's frame using the existing r1 on\nentry, we then create a SWITCH_FRAME_SIZE frame (which has space for\npt_regs) on the emergency stack with the backchain pointing to the\nexisting stack, and then finally we switch to the new frame on the\nemergency stack.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
+ }
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T07:15:11Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json b/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json
index e98c9c1e744..bfa04b2e651 100644
--- a/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json
+++ b/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rh2v-79c5-2v68",
- "modified": "2024-05-22T09:31:46Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-22T09:31:46Z",
"aliases": [
"CVE-2021-47478"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: Fix out of bound access for corrupted isofs image\n\nWhen isofs image is suitably corrupted isofs_read_inode() can read data\nbeyond the end of buffer. Sanity-check the directory entry length before\nusing it.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-125"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-22T09:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vpwx-x2qh-rw8j/GHSA-vpwx-x2qh-rw8j.json b/advisories/unreviewed/2024/05/GHSA-vpwx-x2qh-rw8j/GHSA-vpwx-x2qh-rw8j.json
index 75cf2ac3bb0..1ef314f5b3e 100644
--- a/advisories/unreviewed/2024/05/GHSA-vpwx-x2qh-rw8j/GHSA-vpwx-x2qh-rw8j.json
+++ b/advisories/unreviewed/2024/05/GHSA-vpwx-x2qh-rw8j/GHSA-vpwx-x2qh-rw8j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpwx-x2qh-rw8j",
- "modified": "2024-05-17T06:31:17Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-17T06:31:17Z",
"aliases": [
"CVE-2024-3580"
],
"details": "The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T06:15:53Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json b/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json
index 6bcc4fa44bd..ad9a7df4942 100644
--- a/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json
+++ b/advisories/unreviewed/2024/05/GHSA-vvgm-85j8-2648/GHSA-vvgm-85j8-2648.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvgm-85j8-2648",
- "modified": "2024-05-15T06:30:44Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-15T06:30:44Z",
"aliases": [
"CVE-2024-3630"
],
"details": "The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-15T06:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-xrrj-cr4g-f623/GHSA-xrrj-cr4g-f623.json b/advisories/unreviewed/2024/05/GHSA-xrrj-cr4g-f623/GHSA-xrrj-cr4g-f623.json
index 6e4785bd7d4..86e30bd6dc1 100644
--- a/advisories/unreviewed/2024/05/GHSA-xrrj-cr4g-f623/GHSA-xrrj-cr4g-f623.json
+++ b/advisories/unreviewed/2024/05/GHSA-xrrj-cr4g-f623/GHSA-xrrj-cr4g-f623.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xrrj-cr4g-f623",
- "modified": "2024-05-14T18:31:02Z",
+ "modified": "2024-11-07T18:31:20Z",
"published": "2024-05-14T18:31:02Z",
"aliases": [
"CVE-2024-3241"
],
"details": "The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T16:17:31Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json b/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json
index c6b770ca79f..345406dacdd 100644
--- a/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json
+++ b/advisories/unreviewed/2024/06/GHSA-4xjp-m233-hj66/GHSA-4xjp-m233-hj66.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xjp-m233-hj66",
- "modified": "2024-06-25T21:31:16Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-06-25T21:31:16Z",
"aliases": [
"CVE-2024-21739"
],
"details": "Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-25T21:15:57Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json b/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json
index dd02a91ae13..3bade120b26 100644
--- a/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json
+++ b/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7g8p-3g9q-44r8",
- "modified": "2024-06-19T15:30:52Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-06-19T15:30:52Z",
"aliases": [
"CVE-2024-38542"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mana_ib: boundary check before installing cq callbacks\n\nAdd a boundary check inside mana_ib_install_cq_cb to prevent index overflow.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-19T14:15:14Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json b/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json
index c08dd15101e..81a6320d69d 100644
--- a/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json
+++ b/advisories/unreviewed/2024/06/GHSA-hfwg-2mm4-h8c4/GHSA-hfwg-2mm4-h8c4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hfwg-2mm4-h8c4",
- "modified": "2024-06-19T15:30:55Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-06-19T15:30:55Z",
"aliases": [
"CVE-2021-47583"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mxl111sf: change mutex_init() location\n\nSyzbot reported, that mxl111sf_ctrl_msg() uses uninitialized\nmutex. The problem was in wrong mutex_init() location.\n\nPrevious mutex_init(&state->msg_lock) call was in ->init() function, but\ndvb_usbv2_init() has this order of calls:\n\n\tdvb_usbv2_init()\n\t dvb_usbv2_adapter_init()\n\t dvb_usbv2_adapter_frontend_init()\n\t props->frontend_attach()\n\n\t props->init()\n\nSince mxl111sf_* devices call mxl111sf_ctrl_msg() in ->frontend_attach()\ninternally we need to initialize state->msg_lock before\nfrontend_attach(). To achieve it, ->probe() call added to all mxl111sf_*\ndevices, which will simply initiaize mutex.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-908"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-19T15:15:52Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json b/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json
index d9f528b82cd..f0ec80f6710 100644
--- a/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json
+++ b/advisories/unreviewed/2024/06/GHSA-w69w-gv35-vqjh/GHSA-w69w-gv35-vqjh.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w69w-gv35-vqjh",
- "modified": "2024-06-19T15:30:53Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-06-19T15:30:53Z",
"aliases": [
"CVE-2024-38548"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: bridge: cdns-mhdp8546: Fix possible null pointer dereference\n\nIn cdns_mhdp_atomic_enable(), the return value of drm_mode_duplicate() is\nassigned to mhdp_state->current_mode, and there is a dereference of it in\ndrm_mode_set_name(), which will lead to a NULL pointer dereference on\nfailure of drm_mode_duplicate().\n\nFix this bug add a check of mhdp_state->current_mode.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
"CWE-476"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-19T14:15:15Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json b/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json
index 12b1d68d1d0..e63fa7fe47f 100644
--- a/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json
+++ b/advisories/unreviewed/2024/07/GHSA-p36x-j8pc-9vcr/GHSA-p36x-j8pc-9vcr.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p36x-j8pc-9vcr",
- "modified": "2024-07-05T18:34:18Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-07-05T18:34:18Z",
"aliases": [
"CVE-2024-37767"
],
"details": "Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-306"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-05T17:15:11Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json b/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json
index 40d89ff49e1..46834c4e22c 100644
--- a/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json
+++ b/advisories/unreviewed/2024/07/GHSA-p9pr-gh8g-j3cx/GHSA-p9pr-gh8g-j3cx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9pr-gh8g-j3cx",
- "modified": "2024-07-31T21:32:37Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-07-31T21:32:37Z",
"aliases": [
"CVE-2023-28149"
],
"details": "An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T19:15:10Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json b/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json
index eab0cb14ef9..06f5e51818b 100644
--- a/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json
+++ b/advisories/unreviewed/2024/07/GHSA-xfp3-mm6f-4fw4/GHSA-xfp3-mm6f-4fw4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfp3-mm6f-4fw4",
- "modified": "2024-07-17T18:31:01Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-07-17T18:31:01Z",
"aliases": [
"CVE-2024-38446"
],
"details": "NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in a POST request.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-639"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-17T17:15:15Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json b/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json
index 377c647d3e3..2ef45153c94 100644
--- a/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json
+++ b/advisories/unreviewed/2024/10/GHSA-25m4-rhwx-m523/GHSA-25m4-rhwx-m523.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25m4-rhwx-m523",
- "modified": "2024-10-29T18:30:37Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-10-29T18:30:37Z",
"aliases": [
"CVE-2024-8924"
diff --git a/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json b/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json
index 142d5f9bf6f..08de7171687 100644
--- a/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json
+++ b/advisories/unreviewed/2024/10/GHSA-365x-gvhj-29hg/GHSA-365x-gvhj-29hg.json
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-122"
+ "CWE-122",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json b/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json
index 9f5e139a2dd..360394486cb 100644
--- a/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json
+++ b/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qrg-fxff-9fcm",
- "modified": "2024-10-21T18:30:58Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-10-21T18:30:58Z",
"aliases": [
"CVE-2024-49953"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix crash caused by calling __xfrm_state_delete() twice\n\nThe km.state is not checked in driver's delayed work. When\nxfrm_state_check_expire() is called, the state can be reset to\nXFRM_STATE_EXPIRED, even if it is XFRM_STATE_DEAD already. This\nhappens when xfrm state is deleted, but not freed yet. As\n__xfrm_state_delete() is called again in xfrm timer, the following\ncrash occurs.\n\nTo fix this issue, skip xfrm_state_check_expire() if km.state is not\nXFRM_STATE_VALID.\n\n Oops: general protection fault, probably for non-canonical address 0xdead000000000108: 0000 [#1] SMP\n CPU: 5 UID: 0 PID: 7448 Comm: kworker/u102:2 Not tainted 6.11.0-rc2+ #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5e_ipsec: eth%d mlx5e_ipsec_handle_sw_limits [mlx5_core]\n RIP: 0010:__xfrm_state_delete+0x3d/0x1b0\n Code: 0f 84 8b 01 00 00 48 89 fd c6 87 c8 00 00 00 05 48 8d bb 40 10 00 00 e8 11 04 1a 00 48 8b 95 b8 00 00 00 48 8b 85 c0 00 00 00 <48> 89 42 08 48 89 10 48 8b 55 10 48 b8 00 01 00 00 00 00 ad de 48\n RSP: 0018:ffff88885f945ec8 EFLAGS: 00010246\n RAX: dead000000000122 RBX: ffffffff82afa940 RCX: 0000000000000036\n RDX: dead000000000100 RSI: 0000000000000000 RDI: ffffffff82afb980\n RBP: ffff888109a20340 R08: ffff88885f945ea0 R09: 0000000000000000\n R10: 0000000000000000 R11: ffff88885f945ff8 R12: 0000000000000246\n R13: ffff888109a20340 R14: ffff88885f95f420 R15: ffff88885f95f400\n FS: 0000000000000000(0000) GS:ffff88885f940000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f2163102430 CR3: 00000001128d6001 CR4: 0000000000370eb0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ? die_addr+0x33/0x90\n ? exc_general_protection+0x1a2/0x390\n ? asm_exc_general_protection+0x22/0x30\n ? __xfrm_state_delete+0x3d/0x1b0\n ? __xfrm_state_delete+0x2f/0x1b0\n xfrm_timer_handler+0x174/0x350\n ? __xfrm_state_delete+0x1b0/0x1b0\n __hrtimer_run_queues+0x121/0x270\n hrtimer_run_softirq+0x88/0xd0\n handle_softirqs+0xcc/0x270\n do_softirq+0x3c/0x50\n \n \n __local_bh_enable_ip+0x47/0x50\n mlx5e_ipsec_handle_sw_limits+0x7d/0x90 [mlx5_core]\n process_one_work+0x137/0x2d0\n worker_thread+0x28d/0x3a0\n ? rescuer_thread+0x480/0x480\n kthread+0xb8/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n ",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-672"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T18:15:16Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json b/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json
index a852fb13936..a9fba914399 100644
--- a/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json
+++ b/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x5x-jw3v-frfw",
- "modified": "2024-10-21T18:30:58Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-10-21T18:30:58Z",
"aliases": [
"CVE-2024-49958"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reserve space for inline xattr before attaching reflink tree\n\nOne of our customers reported a crash and a corrupted ocfs2 filesystem. \nThe crash was due to the detection of corruption. Upon troubleshooting,\nthe fsck -fn output showed the below corruption\n\n[EXTENT_LIST_FREE] Extent list in owner 33080590 claims 230 as the next free chain record,\nbut fsck believes the largest valid value is 227. Clamp the next record value? n\n\nThe stat output from the debugfs.ocfs2 showed the following corruption\nwhere the \"Next Free Rec:\" had overshot the \"Count:\" in the root metadata\nblock.\n\n Inode: 33080590 Mode: 0640 Generation: 2619713622 (0x9c25a856)\n FS Generation: 904309833 (0x35e6ac49)\n CRC32: 00000000 ECC: 0000\n Type: Regular Attr: 0x0 Flags: Valid\n Dynamic Features: (0x16) HasXattr InlineXattr Refcounted\n Extended Attributes Block: 0 Extended Attributes Inline Size: 256\n User: 0 (root) Group: 0 (root) Size: 281320357888\n Links: 1 Clusters: 141738\n ctime: 0x66911b56 0x316edcb8 -- Fri Jul 12 06:02:30.829349048 2024\n atime: 0x66911d6b 0x7f7a28d -- Fri Jul 12 06:11:23.133669517 2024\n mtime: 0x66911b56 0x12ed75d7 -- Fri Jul 12 06:02:30.317552087 2024\n dtime: 0x0 -- Wed Dec 31 17:00:00 1969\n Refcount Block: 2777346\n Last Extblk: 2886943 Orphan Slot: 0\n Sub Alloc Slot: 0 Sub Alloc Bit: 14\n Tree Depth: 1 Count: 227 Next Free Rec: 230\n ## Offset Clusters Block#\n 0 0 2310 2776351\n 1 2310 2139 2777375\n 2 4449 1221 2778399\n 3 5670 731 2779423\n 4 6401 566 2780447\n ....... .... .......\n ....... .... .......\n\nThe issue was in the reflink workfow while reserving space for inline\nxattr. The problematic function is ocfs2_reflink_xattr_inline(). By the\ntime this function is called the reflink tree is already recreated at the\ndestination inode from the source inode. At this point, this function\nreserves space for inline xattrs at the destination inode without even\nchecking if there is space at the root metadata block. It simply reduces\nthe l_count from 243 to 227 thereby making space of 256 bytes for inline\nxattr whereas the inode already has extents beyond this index (in this\ncase up to 230), thereby causing corruption.\n\nThe fix for this is to reserve space for inline metadata at the destination\ninode before the reflink tree gets recreated. The customer has verified the\nfix.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T18:15:17Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json b/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json
index a376548a917..dd1925ef08a 100644
--- a/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json
+++ b/advisories/unreviewed/2024/10/GHSA-jx8h-cfqr-f26f/GHSA-jx8h-cfqr-f26f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx8h-cfqr-f26f",
- "modified": "2024-10-21T21:30:52Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-10-21T21:30:52Z",
"aliases": [
"CVE-2022-48998"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/bpf/32: Fix Oops on tail call tests\n\ntest_bpf tail call tests end up as:\n\n test_bpf: #0 Tail call leaf jited:1 85 PASS\n test_bpf: #1 Tail call 2 jited:1 111 PASS\n test_bpf: #2 Tail call 3 jited:1 145 PASS\n test_bpf: #3 Tail call 4 jited:1 170 PASS\n test_bpf: #4 Tail call load/store leaf jited:1 190 PASS\n test_bpf: #5 Tail call load/store jited:1\n BUG: Unable to handle kernel data access on write at 0xf1b4e000\n Faulting instruction address: 0xbe86b710\n Oops: Kernel access of bad area, sig: 11 [#1]\n BE PAGE_SIZE=4K MMU=Hash PowerMac\n Modules linked in: test_bpf(+)\n CPU: 0 PID: 97 Comm: insmod Not tainted 6.1.0-rc4+ #195\n Hardware name: PowerMac3,1 750CL 0x87210 PowerMac\n NIP: be86b710 LR: be857e88 CTR: be86b704\n REGS: f1b4df20 TRAP: 0300 Not tainted (6.1.0-rc4+)\n MSR: 00009032 CR: 28008242 XER: 00000000\n DAR: f1b4e000 DSISR: 42000000\n GPR00: 00000001 f1b4dfe0 c11d2280 00000000 00000000 00000000 00000002 00000000\n GPR08: f1b4e000 be86b704 f1b4e000 00000000 00000000 100d816a f2440000 fe73baa8\n GPR16: f2458000 00000000 c1941ae4 f1fe2248 00000045 c0de0000 f2458030 00000000\n GPR24: 000003e8 0000000f f2458000 f1b4dc90 3e584b46 00000000 f24466a0 c1941a00\n NIP [be86b710] 0xbe86b710\n LR [be857e88] __run_one+0xec/0x264 [test_bpf]\n Call Trace:\n [f1b4dfe0] [00000002] 0x2 (unreliable)\n Instruction dump:\n XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX\n XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX\n ---[ end trace 0000000000000000 ]---\n\nThis is a tentative to write above the stack. The problem is encoutered\nwith tests added by commit 38608ee7b690 (\"bpf, tests: Add load store\ntest case for tail call\")\n\nThis happens because tail call is done to a BPF prog with a different\nstack_depth. At the time being, the stack is kept as is when the caller\ntail calls its callee. But at exit, the callee restores the stack based\non its own properties. Therefore here, at each run, r1 is erroneously\nincreased by 32 - 16 = 16 bytes.\n\nThis was done that way in order to pass the tail call count from caller\nto callee through the stack. As powerpc32 doesn't have a red zone in\nthe stack, it was necessary the maintain the stack as is for the tail\ncall. But it was not anticipated that the BPF frame size could be\ndifferent.\n\nLet's take a new approach. Use register r4 to carry the tail call count\nduring the tail call, and save it into the stack at function entry if\nrequired. This means the input parameter must be in r3, which is more\ncorrect as it is a 32 bits parameter, then tail call better match with\nnormal BPF function entry, the down side being that we move that input\nparameter back and forth between r3 and r4. That can be optimised later.\n\nDoing that also has the advantage of maximising the common parts between\ntail calls and a normal function exit.\n\nWith the fix, tail call tests are now successfull:\n\n test_bpf: #0 Tail call leaf jited:1 53 PASS\n test_bpf: #1 Tail call 2 jited:1 115 PASS\n test_bpf: #2 Tail call 3 jited:1 154 PASS\n test_bpf: #3 Tail call 4 jited:1 165 PASS\n test_bpf: #4 Tail call load/store leaf jited:1 101 PASS\n test_bpf: #5 Tail call load/store jited:1 141 PASS\n test_bpf: #6 Tail call error path, max count reached jited:1 994 PASS\n test_bpf: #7 Tail call count preserved across function calls jited:1 140975 PASS\n test_bpf: #8 Tail call error path, NULL target jited:1 110 PASS\n test_bpf: #9 Tail call error path, index out of range jited:1 69 PASS\n test_bpf: test_tail_calls: Summary: 10 PASSED, 0 FAILED, [10/10 JIT'ed]",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T20:15:11Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json b/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json
index f8d1dad981e..c6d4d7256aa 100644
--- a/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json
+++ b/advisories/unreviewed/2024/10/GHSA-qpr4-w3rc-m373/GHSA-qpr4-w3rc-m373.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpr4-w3rc-m373",
- "modified": "2024-10-29T18:30:36Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-10-29T18:30:36Z",
"aliases": [
"CVE-2024-8923"
diff --git a/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json b/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json
index e58ac1d2d6f..c127abbab68 100644
--- a/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json
+++ b/advisories/unreviewed/2024/10/GHSA-vch3-xc23-jrf2/GHSA-vch3-xc23-jrf2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vch3-xc23-jrf2",
- "modified": "2024-10-21T21:30:52Z",
+ "modified": "2024-11-07T18:31:21Z",
"published": "2024-10-21T21:30:52Z",
"aliases": [
"CVE-2022-48997"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: tpm: Protect tpm_pm_suspend with locks\n\nCurrently tpm transactions are executed unconditionally in\ntpm_pm_suspend() function, which may lead to races with other tpm\naccessors in the system.\n\nSpecifically, the hw_random tpm driver makes use of tpm_get_random(),\nand this function is called in a loop from a kthread, which means it's\nnot frozen alongside userspace, and so can race with the work done\nduring system suspend:\n\n tpm tpm0: tpm_transmit: tpm_recv: error -52\n tpm tpm0: invalid TPM_STS.x 0xff, dumping stack for forensics\n CPU: 0 PID: 1 Comm: init Not tainted 6.1.0-rc5+ #135\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-20220807_005459-localhost 04/01/2014\n Call Trace:\n tpm_tis_status.cold+0x19/0x20\n tpm_transmit+0x13b/0x390\n tpm_transmit_cmd+0x20/0x80\n tpm1_pm_suspend+0xa6/0x110\n tpm_pm_suspend+0x53/0x80\n __pnp_bus_suspend+0x35/0xe0\n __device_suspend+0x10f/0x350\n\nFix this by calling tpm_try_get_ops(), which itself is a wrapper around\ntpm_chip_start(), but takes the appropriate mutex.\n\n[Jason: reworked commit message, added metadata]",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T20:15:11Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json b/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json
index b5dff0101b4..5fd3abb4745 100644
--- a/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json
+++ b/advisories/unreviewed/2024/11/GHSA-2mvw-cmvf-9wp4/GHSA-2mvw-cmvf-9wp4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mvw-cmvf-9wp4",
- "modified": "2024-11-07T06:30:34Z",
+ "modified": "2024-11-07T18:31:23Z",
"published": "2024-11-07T06:30:34Z",
"aliases": [
"CVE-2024-10027"
],
"details": "The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-07T06:15:13Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json b/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json
index 1cf0a034d0e..ee62b1d7ede 100644
--- a/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json
+++ b/advisories/unreviewed/2024/11/GHSA-3fgp-h8mw-wrh5/GHSA-3fgp-h8mw-wrh5.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3fgp-h8mw-wrh5",
- "modified": "2024-11-07T00:30:36Z",
+ "modified": "2024-11-07T18:31:22Z",
"published": "2024-11-07T00:30:36Z",
"aliases": [
"CVE-2024-48325"
],
"details": "Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the \"getDocuments\" function of the \"InstituicaoDocumentacaoController\" class. The \"instituicao_id\" parameter in \"/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id\" is not properly sanitized, allowing an unauthenticated remote attacker to inject malicious SQL commands.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-06T23:15:04Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json b/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json
new file mode 100644
index 00000000000..cc61d73188f
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-3qgh-6635-p7pp/GHSA-3qgh-6635-p7pp.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3qgh-6635-p7pp",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2024-48290"
+ ],
+ "details": "An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48290"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitee.com/guozhi123456/vulnerability-Report/blob/master/Realtek/Realtek.md"
+ },
+ {
+ "type": "WEB",
+ "url": "http://realtek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-3v5g-chfr-w797/GHSA-3v5g-chfr-w797.json b/advisories/unreviewed/2024/11/GHSA-3v5g-chfr-w797/GHSA-3v5g-chfr-w797.json
new file mode 100644
index 00000000000..9b6309a31b0
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-3v5g-chfr-w797/GHSA-3v5g-chfr-w797.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3v5g-chfr-w797",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2020-11926"
+ ],
+ "details": "An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript file. Also, the disclosed information includes the SSID and WPA2 key for the Wi-Fi network the device is connected to.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11926"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-44f7-vf3h-r86f/GHSA-44f7-vf3h-r86f.json b/advisories/unreviewed/2024/11/GHSA-44f7-vf3h-r86f/GHSA-44f7-vf3h-r86f.json
new file mode 100644
index 00000000000..4c38a711ec5
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-44f7-vf3h-r86f/GHSA-44f7-vf3h-r86f.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-44f7-vf3h-r86f",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2019-20459"
+ ],
+ "details": "An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling the network card or changing the DNS servers.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20459"
+ },
+ {
+ "type": "WEB",
+ "url": "https://epson.com/Support/wa00826"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-6mm9-jjjf-pcj3/GHSA-6mm9-jjjf-pcj3.json b/advisories/unreviewed/2024/11/GHSA-6mm9-jjjf-pcj3/GHSA-6mm9-jjjf-pcj3.json
new file mode 100644
index 00000000000..fd28db90266
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-6mm9-jjjf-pcj3/GHSA-6mm9-jjjf-pcj3.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6mm9-jjjf-pcj3",
+ "modified": "2024-11-07T18:31:25Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2024-51428"
+ ],
+ "details": "An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51428"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitee.com/guozhi123456/vulnerability-Report/blob/master/Esp/Accept_Invaild_Address.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/espressif/esp-idf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json b/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json
new file mode 100644
index 00000000000..ef7544f922b
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-6rcc-2x92-3rpg/GHSA-6rcc-2x92-3rpg.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6rcc-2x92-3rpg",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2020-11919"
+ ],
+ "details": "An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11919"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json b/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json
index 0e53a1e9e15..7f899695723 100644
--- a/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json
+++ b/advisories/unreviewed/2024/11/GHSA-74f8-hfjw-wvrf/GHSA-74f8-hfjw-wvrf.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74f8-hfjw-wvrf",
- "modified": "2024-11-07T00:30:36Z",
+ "modified": "2024-11-07T18:31:22Z",
"published": "2024-11-07T00:30:36Z",
"aliases": [
"CVE-2024-51409"
],
"details": "Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format to a router running the corresponding version of the firmware.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-120"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-06T23:15:04Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json b/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json
new file mode 100644
index 00000000000..57596bc5e66
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-c4pf-hc84-698h/GHSA-c4pf-hc84-698h.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c4pf-hc84-698h",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2024-48953"
+ ],
+ "details": "An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48953"
+ },
+ {
+ "type": "WEB",
+ "url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968899128221-Authentication-Bypass-using-URL-endpoints-in-the-Authentication-Modules"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-cp74-46v8-qrjr/GHSA-cp74-46v8-qrjr.json b/advisories/unreviewed/2024/11/GHSA-cp74-46v8-qrjr/GHSA-cp74-46v8-qrjr.json
new file mode 100644
index 00000000000..b400e7b58bf
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-cp74-46v8-qrjr/GHSA-cp74-46v8-qrjr.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cp74-46v8-qrjr",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2019-20457"
+ ],
+ "details": "An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorization cookie. The value of the authorization cookie is the MD5 hash of the password in hexadecimal. An attacker can easily derive the true MD5 hash from this, and use offline cracking attacks to obtain administrative access to the device.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20457"
+ },
+ {
+ "type": "WEB",
+ "url": "https://global.brother"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.brother.com/g/s/security/en/index.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json b/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json
new file mode 100644
index 00000000000..b8159157dfb
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-fjv6-j3p5-xvwr/GHSA-fjv6-j3p5-xvwr.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fjv6-j3p5-xvwr",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2020-11917"
+ ],
+ "details": "An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye devices, violating the privacy of users who do not wish to disclose their ownership of this type of device. (Various resources such as wigle.net can be use for mapping of SSIDs to physical locations.)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11917"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json b/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json
index 550c59a6a60..f12e1068eca 100644
--- a/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json
+++ b/advisories/unreviewed/2024/11/GHSA-g93m-8x6h-g5gv/GHSA-g93m-8x6h-g5gv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g93m-8x6h-g5gv",
- "modified": "2024-11-07T12:30:35Z",
+ "modified": "2024-11-07T18:31:23Z",
"published": "2024-11-07T12:30:35Z",
"aliases": [
"CVE-2024-51504"
],
"details": "When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of client's IP address detection in IPAuthenticationProvider, which uses HTTP request headers, is weak and allows an attacker to bypass authentication via spoofing client's IP address in request headers. Default configuration honors X-Forwarded-For HTTP header to read client's IP address. X-Forwarded-For request header is mainly used by proxy servers to identify the client and can be easily spoofed by an attacker pretending that the request comes from a different IP address. Admin Server commands, such as snapshot and restore arbitrarily can be executed on successful exploitation which could potentially lead to information leakage or service availability issues. Users are recommended to upgrade to version 3.9.3, which fixes this issue.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-290"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-07T10:15:08Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json b/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json
new file mode 100644
index 00000000000..081b16b513a
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-h4jm-pc24-hx88/GHSA-h4jm-pc24-hx88.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h4jm-pc24-hx88",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-48952"
+ ],
+ "details": "An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48952"
+ },
+ {
+ "type": "WEB",
+ "url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968950913693-Static-JWT-Key-enables-unauthorized-API-access"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json b/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json
new file mode 100644
index 00000000000..c4156e2f02d
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-hcpx-v556-ch6p/GHSA-hcpx-v556-ch6p.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hcpx-v556-ch6p",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-40715"
+ ],
+ "details": "A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40715"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.veeam.com/kb4682"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json b/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json
new file mode 100644
index 00000000000..2b3a218a23c
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-j7hj-68jp-pg28/GHSA-j7hj-68jp-pg28.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j7hj-68jp-pg28",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-8378"
+ ],
+ "details": "The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8378"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wpscan.com/vulnerability/17be4bf2-486d-43ab-b87a-2117c8d77ca8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T16:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json b/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json
new file mode 100644
index 00000000000..45cf1abbe53
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-j9g6-vvr6-x5wm/GHSA-j9g6-vvr6-x5wm.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j9g6-vvr6-x5wm",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-10668"
+ ],
+ "details": "There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is contained in this frame is written to disk in the Downloads folder. Quickshare normally deletes unkown files, however an attacker can send two Payload transfer frames of type FILE and the same payload ID. The deletion logic will only delete the first file and not the second. We recommend upgrading past commit 5d8b9156e0c339d82d3dab0849187e8819ad92c0 or Quick Share Windows v1.0.2002.2",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:A/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Green"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10668"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/google/nearby/pull/2892"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-434"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T16:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json b/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json
new file mode 100644
index 00000000000..43a4651790a
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-jgqg-jqq9-5x4c/GHSA-jgqg-jqq9-5x4c.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jgqg-jqq9-5x4c",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2024-48954"
+ ],
+ "details": "An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48954"
+ },
+ {
+ "type": "WEB",
+ "url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968851138461-Remote-Code-Execution-RCE-in-EventHub-Collector"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json b/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json
index 0848703e1c4..7325bcc3ea6 100644
--- a/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json
+++ b/advisories/unreviewed/2024/11/GHSA-mhq2-gxcg-4hc8/GHSA-mhq2-gxcg-4hc8.json
@@ -48,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-707"
+ "CWE-707",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json b/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json
new file mode 100644
index 00000000000..5de72ff0bf3
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json
@@ -0,0 +1,62 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mpfv-w8fh-9hfv",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-10964"
+ ],
+ "details": "A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10964"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/emqx/neuron/issues/2280"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/emqx/neuron/pull/2286"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/emqx/neuron/pull/2286/commits/3e3a583d72548af1740b3e61a5eab3b628cc439e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.283410"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.283410"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.435372"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-119"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json b/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json
new file mode 100644
index 00000000000..cea4d00bef9
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-mw3p-xpcv-h9gq/GHSA-mw3p-xpcv-h9gq.json
@@ -0,0 +1,62 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mw3p-xpcv-h9gq",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2024-10966"
+ ],
+ "details": "A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10966"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Dreamy-elfland/240914"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.283412"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.283412"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.437310"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.totolink.net"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.youtube.com/watch?v=zRNv1OvT55c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-77"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json b/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json
new file mode 100644
index 00000000000..10d2fbf5bde
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-pcrp-7g2p-q7pj/GHSA-pcrp-7g2p-q7pj.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pcrp-7g2p-q7pj",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-48951"
+ ],
+ "details": "An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48951"
+ },
+ {
+ "type": "WEB",
+ "url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968916591261-Server-Side-Request-Forgery-SSRF-on-SOAR-results-in-authentication-bypass"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json b/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json
new file mode 100644
index 00000000000..18334dda3e8
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-q37q-6c8j-qf6q/GHSA-q37q-6c8j-qf6q.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q37q-6c8j-qf6q",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2020-11916"
+ ],
+ "details": "An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11916"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-q7m5-chmw-937j/GHSA-q7m5-chmw-937j.json b/advisories/unreviewed/2024/11/GHSA-q7m5-chmw-937j/GHSA-q7m5-chmw-937j.json
new file mode 100644
index 00000000000..18050fb1815
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-q7m5-chmw-937j/GHSA-q7m5-chmw-937j.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q7m5-chmw-937j",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2020-11921"
+ ],
+ "details": "An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth connection between the Lush 2 and a mobile phone. This allows an attacker to gain full control over the device.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11921"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json b/advisories/unreviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json
deleted file mode 100644
index e143499f310..00000000000
--- a/advisories/unreviewed/2024/11/GHSA-qrqv-26gf-xgwh/GHSA-qrqv-26gf-xgwh.json
+++ /dev/null
@@ -1,42 +0,0 @@
-{
- "schema_version": "1.4.0",
- "id": "GHSA-qrqv-26gf-xgwh",
- "modified": "2024-11-07T15:31:52Z",
- "published": "2024-11-07T15:31:52Z",
- "aliases": [
- "CVE-2024-43440"
- ],
- "details": "A flaw was found in moodle. A local file may include risks when restoring block backups.",
- "severity": [
- {
- "type": "CVSS_V3",
- "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
- }
- ],
- "affected": [
-
- ],
- "references": [
- {
- "type": "ADVISORY",
- "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43440"
- },
- {
- "type": "WEB",
- "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2304269"
- },
- {
- "type": "WEB",
- "url": "https://moodle.org/mod/forum/discuss.php?d=461210"
- }
- ],
- "database_specific": {
- "cwe_ids": [
-
- ],
- "severity": "HIGH",
- "github_reviewed": false,
- "github_reviewed_at": null,
- "nvd_published_at": "2024-11-07T14:15:16Z"
- }
-}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-qw6p-p38p-ggp9/GHSA-qw6p-p38p-ggp9.json b/advisories/unreviewed/2024/11/GHSA-qw6p-p38p-ggp9/GHSA-qw6p-p38p-ggp9.json
new file mode 100644
index 00000000000..01f05f88be7
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-qw6p-p38p-ggp9/GHSA-qw6p-p38p-ggp9.json
@@ -0,0 +1,62 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qw6p-p38p-ggp9",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-10965"
+ ],
+ "details": "A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch is named c9ce39747e0372aaa2157b2b56174914a12c06d8. It is recommended to apply a patch to fix this issue.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10965"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/emqx/neuron/issues/2281"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/emqx/neuron/pull/2282"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fengzeroz/neuron/commit/c9ce39747e0372aaa2157b2b56174914a12c06d8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.283411"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.283411"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.435375"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-rw99-6hrh-fmjr/GHSA-rw99-6hrh-fmjr.json b/advisories/unreviewed/2024/11/GHSA-rw99-6hrh-fmjr/GHSA-rw99-6hrh-fmjr.json
new file mode 100644
index 00000000000..98de0b3d0c6
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-rw99-6hrh-fmjr/GHSA-rw99-6hrh-fmjr.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rw99-6hrh-fmjr",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-10963"
+ ],
+ "details": "A vulnerability was found in pam_access due to the improper handling of tokens in access.conf, interpreted as hostnames. This flaw allows attackers to bypass access restrictions by spoofing hostnames, undermining configurations designed to limit access to specific TTYs or services. The flaw poses a risk in environments relying on these configurations for local access control.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10963"
+ },
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/security/cve/CVE-2024-10963"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2324291"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-287"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T16:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json b/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json
new file mode 100644
index 00000000000..473513f1123
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json
@@ -0,0 +1,58 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rwhw-2ccq-46p7",
+ "modified": "2024-11-07T18:31:25Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2024-10967"
+ ],
+ "details": "A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10967"
+ },
+ {
+ "type": "WEB",
+ "url": "https://code-projects.org"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/1104533685/cve/blob/main/sql.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.283416"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.283416"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.437312"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:16Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json b/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json
new file mode 100644
index 00000000000..1ba2ede92a4
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-w7p4-hj4q-wh7p/GHSA-w7p4-hj4q-wh7p.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w7p4-hj4q-wh7p",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2020-11918"
+ ],
+ "details": "An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11918"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json b/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json
new file mode 100644
index 00000000000..408496be034
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-wxg7-96h5-9qcc/GHSA-wxg7-96h5-9qcc.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wxg7-96h5-9qcc",
+ "modified": "2024-11-07T18:31:23Z",
+ "published": "2024-11-07T18:31:23Z",
+ "aliases": [
+ "CVE-2024-48950"
+ ],
+ "details": "An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48950"
+ },
+ {
+ "type": "WEB",
+ "url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968264954525-Authentication-and-CSRF-bypass-leading-to-unauthorized-access"
+ },
+ {
+ "type": "WEB",
+ "url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T17:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/11/GHSA-xq95-8x62-4j38/GHSA-xq95-8x62-4j38.json b/advisories/unreviewed/2024/11/GHSA-xq95-8x62-4j38/GHSA-xq95-8x62-4j38.json
new file mode 100644
index 00000000000..0d80202d97f
--- /dev/null
+++ b/advisories/unreviewed/2024/11/GHSA-xq95-8x62-4j38/GHSA-xq95-8x62-4j38.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xq95-8x62-4j38",
+ "modified": "2024-11-07T18:31:24Z",
+ "published": "2024-11-07T18:31:24Z",
+ "aliases": [
+ "CVE-2019-20458"
+ ],
+ "details": "An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20458"
+ },
+ {
+ "type": "WEB",
+ "url": "https://epson.com/Support/wa00826"
+ },
+ {
+ "type": "WEB",
+ "url": "https://seclists.org/fulldisclosure/2024/Jul/14"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-11-07T18:15:15Z"
+ }
+}
\ No newline at end of file