diff --git a/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json b/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json index 3b2747e8ece..04501324a93 100644 --- a/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json +++ b/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-485v-466m-9mjv", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2017-13320" ], "details": "In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T22:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json b/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json index 07adfe0fba5..052a9768e9b 100644 --- a/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json +++ b/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5p2r-c897-jgj5", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9349" ], "details": "In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T22:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json b/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json index d35d3149863..111c9f5d83e 100644 --- a/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json +++ b/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v84-c4c3-p44c", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9352" ], "details": "In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json b/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json index 75a1a459c2f..67083c7b40a 100644 --- a/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json +++ b/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7485-8f3w-4mrf", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9374" ], "details": "In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T00:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7676-xq8c-838g/GHSA-7676-xq8c-838g.json b/advisories/unreviewed/2024/11/GHSA-7676-xq8c-838g/GHSA-7676-xq8c-838g.json index 30578230fa0..a622de136e3 100644 --- a/advisories/unreviewed/2024/11/GHSA-7676-xq8c-838g/GHSA-7676-xq8c-838g.json +++ b/advisories/unreviewed/2024/11/GHSA-7676-xq8c-838g/GHSA-7676-xq8c-838g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7676-xq8c-838g", - "modified": "2024-11-28T06:32:41Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T06:32:41Z", "aliases": [ "CVE-2018-9377" ], "details": "In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T01:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-94hw-5cx8-g994/GHSA-94hw-5cx8-g994.json b/advisories/unreviewed/2024/11/GHSA-94hw-5cx8-g994/GHSA-94hw-5cx8-g994.json index fa43ef5e502..b5a4d565f0f 100644 --- a/advisories/unreviewed/2024/11/GHSA-94hw-5cx8-g994/GHSA-94hw-5cx8-g994.json +++ b/advisories/unreviewed/2024/11/GHSA-94hw-5cx8-g994/GHSA-94hw-5cx8-g994.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-94hw-5cx8-g994", - "modified": "2024-11-15T15:30:58Z", + "modified": "2024-11-30T00:32:13Z", "published": "2024-11-15T15:30:58Z", "aliases": [ "CVE-2024-50986" ], "details": "An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -33,9 +34,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-426" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T15:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json b/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json index 1ac0b4cc977..f9d19dd993e 100644 --- a/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json +++ b/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvc5-85r6-6h2v", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9353" ], "details": "In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g425-4w2w-qh83/GHSA-g425-4w2w-qh83.json b/advisories/unreviewed/2024/11/GHSA-g425-4w2w-qh83/GHSA-g425-4w2w-qh83.json index 1447c083032..420e917f987 100644 --- a/advisories/unreviewed/2024/11/GHSA-g425-4w2w-qh83/GHSA-g425-4w2w-qh83.json +++ b/advisories/unreviewed/2024/11/GHSA-g425-4w2w-qh83/GHSA-g425-4w2w-qh83.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g425-4w2w-qh83", - "modified": "2024-11-27T21:32:45Z", + "modified": "2024-11-30T00:32:13Z", "published": "2024-11-27T21:32:45Z", "aliases": [ "CVE-2017-13316" ], "details": "In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T20:15:22Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json b/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json index 36d2e7d2132..264300be03d 100644 --- a/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json +++ b/advisories/unreviewed/2024/11/GHSA-h4c9-8j9c-xf43/GHSA-h4c9-8j9c-xf43.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-h4c9-8j9c-xf43", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-30T00:32:13Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2024-52769" ], "details": "An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T17:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json b/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json index ea8fe530a73..15bdf71cf89 100644 --- a/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json +++ b/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jpfm-vcpf-r226", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9351" ], "details": "In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m39h-w67h-425w/GHSA-m39h-w67h-425w.json b/advisories/unreviewed/2024/11/GHSA-m39h-w67h-425w/GHSA-m39h-w67h-425w.json index 3049f4664d6..72c8ce6bce4 100644 --- a/advisories/unreviewed/2024/11/GHSA-m39h-w67h-425w/GHSA-m39h-w67h-425w.json +++ b/advisories/unreviewed/2024/11/GHSA-m39h-w67h-425w/GHSA-m39h-w67h-425w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m39h-w67h-425w", - "modified": "2024-11-27T21:32:45Z", + "modified": "2024-11-30T00:32:13Z", "published": "2024-11-27T21:32:45Z", "aliases": [ "CVE-2017-13319" ], "details": "In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T20:15:22Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json b/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json index 66be02e7613..161218954ac 100644 --- a/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json +++ b/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qv87-xf2v-gghw", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9354" ], "details": "In VideoFrameScheduler.cpp of VideoFrameScheduler::PLL::fit, there is a possible remote denial of service due to divide by 0. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json b/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json index 8b526d8d144..f7657ef3676 100644 --- a/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json +++ b/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r756-r5qv-286x", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2018-9350" ], "details": "In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T22:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json b/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json index 65f3fc748a9..11f8174527e 100644 --- a/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json +++ b/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wv5r-6ww5-7f4f", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2017-13321" ], "details": "In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T22:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json b/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json index 406e59ae428..0611dc56fdd 100644 --- a/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json +++ b/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxj2-cjm8-36fx", - "modified": "2024-11-28T00:39:26Z", + "modified": "2024-11-30T00:32:14Z", "published": "2024-11-28T00:39:26Z", "aliases": [ "CVE-2017-13323" ], "details": "In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T22:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x839-278f-vq33/GHSA-x839-278f-vq33.json b/advisories/unreviewed/2024/11/GHSA-x839-278f-vq33/GHSA-x839-278f-vq33.json new file mode 100644 index 00000000000..f6b2932cd81 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x839-278f-vq33/GHSA-x839-278f-vq33.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x839-278f-vq33", + "modified": "2024-11-30T00:32:14Z", + "published": "2024-11-30T00:32:14Z", + "aliases": [ + "CVE-2024-54159" + ], + "details": "stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54159" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/61.html" + }, + { + "type": "WEB", + "url": "https://security.opensuse.org/2024/11/29/stalld-fixed-tmp-file.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/11/29/3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xwr9-qp3g-c7vh/GHSA-xwr9-qp3g-c7vh.json b/advisories/unreviewed/2024/11/GHSA-xwr9-qp3g-c7vh/GHSA-xwr9-qp3g-c7vh.json new file mode 100644 index 00000000000..f6e717d9512 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xwr9-qp3g-c7vh/GHSA-xwr9-qp3g-c7vh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwr9-qp3g-c7vh", + "modified": "2024-11-30T00:32:14Z", + "published": "2024-11-30T00:32:14Z", + "aliases": [ + "CVE-2024-53623" + ], + "details": "Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53623" + }, + { + "type": "WEB", + "url": "https://github.com/Crane-c/CVE_Request/blob/main/TP-Link/C7v5/TPLink_ARCHERC7v5_unauthorized_access_vulnerability_first.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T23:15:04Z" + } +} \ No newline at end of file