diff --git a/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json b/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json new file mode 100644 index 00000000000..6b8b5751e6f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8mwf-wgf7-7qpx/GHSA-8mwf-wgf7-7qpx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mwf-wgf7-7qpx", + "modified": "2024-05-31T00:30:44Z", + "published": "2024-05-31T00:30:43Z", + "aliases": [ + "CVE-2024-5497" + ], + "details": "Out of bounds memory access in Keyboard Inputs in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5497" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339061099" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json b/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json new file mode 100644 index 00000000000..9db6e206355 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8xgv-q88p-ghq4/GHSA-8xgv-q88p-ghq4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xgv-q88p-ghq4", + "modified": "2024-05-31T00:30:43Z", + "published": "2024-05-31T00:30:43Z", + "aliases": [ + "CVE-2024-5496" + ], + "details": "Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5496" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/338929744" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json b/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json new file mode 100644 index 00000000000..30a4a399ef4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f6rr-qfxh-hcf9/GHSA-f6rr-qfxh-hcf9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6rr-qfxh-hcf9", + "modified": "2024-05-31T00:30:43Z", + "published": "2024-05-31T00:30:43Z", + "aliases": [ + "CVE-2024-5493" + ], + "details": "Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5493" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339877165" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json b/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json new file mode 100644 index 00000000000..003999a2c02 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqjc-cfjx-7rv8", + "modified": "2024-05-31T00:30:44Z", + "published": "2024-05-31T00:30:44Z", + "aliases": [ + "CVE-2024-5498" + ], + "details": "Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5498" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339588211" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json b/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json new file mode 100644 index 00000000000..c4d6fd61223 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fv2x-w8xf-gxpq/GHSA-fv2x-w8xf-gxpq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2x-w8xf-gxpq", + "modified": "2024-05-31T00:30:43Z", + "published": "2024-05-31T00:30:43Z", + "aliases": [ + "CVE-2024-5494" + ], + "details": "Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5494" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/338071106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json b/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json new file mode 100644 index 00000000000..464758403e3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gcpc-53j8-75v3/GHSA-gcpc-53j8-75v3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcpc-53j8-75v3", + "modified": "2024-05-31T00:30:44Z", + "published": "2024-05-31T00:30:44Z", + "aliases": [ + "CVE-2024-37017" + ], + "details": "asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37017" + }, + { + "type": "WEB", + "url": "https://github.com/cinecert/asdcplib/issues/138" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json b/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json new file mode 100644 index 00000000000..2fab8a227bc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hqfv-mf6j-g3j6/GHSA-hqfv-mf6j-g3j6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqfv-mf6j-g3j6", + "modified": "2024-05-31T00:30:44Z", + "published": "2024-05-31T00:30:44Z", + "aliases": [ + "CVE-2024-5499" + ], + "details": "Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5499" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339877167" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wrxh-8wc3-33rm/GHSA-wrxh-8wc3-33rm.json b/advisories/unreviewed/2024/05/GHSA-wrxh-8wc3-33rm/GHSA-wrxh-8wc3-33rm.json new file mode 100644 index 00000000000..d5cab02b492 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wrxh-8wc3-33rm/GHSA-wrxh-8wc3-33rm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrxh-8wc3-33rm", + "modified": "2024-05-31T00:30:43Z", + "published": "2024-05-31T00:30:43Z", + "aliases": [ + "CVE-2024-5495" + ], + "details": "Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5495" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/338103465" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-30T23:15:48Z" + } +} \ No newline at end of file