From 8cc200892c3365dfaeb169c06f37fba66ea7b91e Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 30 Oct 2024 15:31:52 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-5hw4-hqhq-pf4g.json | 1 +
.../GHSA-gp72-c58g-57q3.json | 11 ++++--
.../GHSA-3898-wjpq-fj5f.json | 9 +++--
.../GHSA-55jv-x7fj-7mg4.json | 11 ++++--
.../GHSA-fvvm-pp96-j72m.json | 11 ++++--
.../GHSA-4285-7mp2-g3hv.json | 11 ++++--
.../GHSA-5w6v-768m-rvhm.json | 9 +++--
.../GHSA-ccrr-hx7g-hmm4.json | 2 +-
.../GHSA-276c-c7gr-r4j6.json | 38 +++++++++++++++++++
.../GHSA-3gr7-wwrx-664v.json | 2 +-
.../GHSA-3hjx-m6qm-hh35.json | 9 +++--
.../GHSA-43gj-mj95-qp4h.json | 35 +++++++++++++++++
.../GHSA-4fj6-9r38-4v86.json | 38 +++++++++++++++++++
.../GHSA-4hjf-5mq4-f6c7.json | 35 +++++++++++++++++
.../GHSA-4vhv-rmg8-wc9v.json | 6 ++-
.../GHSA-59xm-4xxw-45c5.json | 38 +++++++++++++++++++
.../GHSA-5q8j-rx3p-q6jm.json | 2 +-
.../GHSA-64xw-25gj-x6w6.json | 35 +++++++++++++++++
.../GHSA-6qvq-5969-5wrp.json | 38 +++++++++++++++++++
.../GHSA-6w7x-r67f-jr7g.json | 38 +++++++++++++++++++
.../GHSA-777g-cfq7-cgv7.json | 11 ++++--
.../GHSA-8c5r-55p8-8p8m.json | 11 ++++--
.../GHSA-8m9g-c3mm-hr68.json | 7 +++-
.../GHSA-c2hr-6qhm-xv9r.json | 2 +-
.../GHSA-cm54-mprw-5279.json | 6 ++-
.../GHSA-cxc4-ppv4-gfgj.json | 11 ++++--
.../GHSA-fh9m-mpjc-38hg.json | 35 +++++++++++++++++
.../GHSA-fv52-m5w8-2242.json | 35 +++++++++++++++++
.../GHSA-g5vx-c2fq-6jm8.json | 7 +++-
.../GHSA-h72p-7xmw-gpp8.json | 9 +++--
.../GHSA-hjxq-5796-f748.json | 38 +++++++++++++++++++
.../GHSA-jc6j-jf92-jq35.json | 2 +-
.../GHSA-jxm2-6gmh-4m8x.json | 38 +++++++++++++++++++
.../GHSA-p2c8-3p7x-5wc8.json | 38 +++++++++++++++++++
.../GHSA-p346-px87-vf2h.json | 11 ++++--
.../GHSA-p3wf-f274-7gx2.json | 9 +++--
.../GHSA-pr83-52rx-w5f5.json | 38 +++++++++++++++++++
.../GHSA-q2hv-8prh-hr3r.json | 2 +-
.../GHSA-q2q4-jrr5-68rj.json | 38 +++++++++++++++++++
.../GHSA-q63q-pqgx-268p.json | 38 +++++++++++++++++++
.../GHSA-qjqh-fr2p-8mpm.json | 38 +++++++++++++++++++
.../GHSA-r5jh-qcvm-667j.json | 11 ++++--
.../GHSA-r5mw-c5jc-r788.json | 6 ++-
.../GHSA-r9vf-qqqr-747x.json | 38 +++++++++++++++++++
.../GHSA-rr46-96rc-r6xm.json | 2 +-
.../GHSA-v76h-6p79-mvh2.json | 35 +++++++++++++++++
.../GHSA-v7pq-vg76-qwqx.json | 9 +++--
.../GHSA-vmg4-jx97-rmvv.json | 7 +++-
.../GHSA-vpwg-6766-6xgp.json | 35 +++++++++++++++++
.../GHSA-w6g2-qqv5-83qj.json | 2 +-
.../GHSA-x29p-mgvr-2q2p.json | 2 +-
.../GHSA-xvc9-v5hw-8v8j.json | 9 +++--
52 files changed, 884 insertions(+), 75 deletions(-)
create mode 100644 advisories/unreviewed/2024/10/GHSA-276c-c7gr-r4j6/GHSA-276c-c7gr-r4j6.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-4fj6-9r38-4v86/GHSA-4fj6-9r38-4v86.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-59xm-4xxw-45c5/GHSA-59xm-4xxw-45c5.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-6qvq-5969-5wrp/GHSA-6qvq-5969-5wrp.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-6w7x-r67f-jr7g/GHSA-6w7x-r67f-jr7g.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-hjxq-5796-f748/GHSA-hjxq-5796-f748.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-jxm2-6gmh-4m8x/GHSA-jxm2-6gmh-4m8x.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-p2c8-3p7x-5wc8/GHSA-p2c8-3p7x-5wc8.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-pr83-52rx-w5f5/GHSA-pr83-52rx-w5f5.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-q2q4-jrr5-68rj/GHSA-q2q4-jrr5-68rj.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-q63q-pqgx-268p/GHSA-q63q-pqgx-268p.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-qjqh-fr2p-8mpm/GHSA-qjqh-fr2p-8mpm.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-r9vf-qqqr-747x/GHSA-r9vf-qqqr-747x.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json
create mode 100644 advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json
diff --git a/advisories/unreviewed/2022/03/GHSA-5hw4-hqhq-pf4g/GHSA-5hw4-hqhq-pf4g.json b/advisories/unreviewed/2022/03/GHSA-5hw4-hqhq-pf4g/GHSA-5hw4-hqhq-pf4g.json
index 4f8e9cf7431..073bd01825e 100644
--- a/advisories/unreviewed/2022/03/GHSA-5hw4-hqhq-pf4g/GHSA-5hw4-hqhq-pf4g.json
+++ b/advisories/unreviewed/2022/03/GHSA-5hw4-hqhq-pf4g/GHSA-5hw4-hqhq-pf4g.json
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-120",
"CWE-787"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/02/GHSA-gp72-c58g-57q3/GHSA-gp72-c58g-57q3.json b/advisories/unreviewed/2024/02/GHSA-gp72-c58g-57q3/GHSA-gp72-c58g-57q3.json
index 8daaf22db13..f998e01260e 100644
--- a/advisories/unreviewed/2024/02/GHSA-gp72-c58g-57q3/GHSA-gp72-c58g-57q3.json
+++ b/advisories/unreviewed/2024/02/GHSA-gp72-c58g-57q3/GHSA-gp72-c58g-57q3.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gp72-c58g-57q3",
- "modified": "2024-02-22T18:30:30Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-02-22T18:30:30Z",
"aliases": [
"CVE-2024-25802"
],
"details": "SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-434"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-22T18:15:48Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json b/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json
index 0735488ab27..195fc43e0aa 100644
--- a/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json
+++ b/advisories/unreviewed/2024/04/GHSA-3898-wjpq-fj5f/GHSA-3898-wjpq-fj5f.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3898-wjpq-fj5f",
- "modified": "2024-04-10T15:30:39Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-04-10T15:30:39Z",
"aliases": [
"CVE-2024-2428"
],
"details": "The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T05:15:49Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-55jv-x7fj-7mg4/GHSA-55jv-x7fj-7mg4.json b/advisories/unreviewed/2024/04/GHSA-55jv-x7fj-7mg4/GHSA-55jv-x7fj-7mg4.json
index d7342735790..fbce7a5e887 100644
--- a/advisories/unreviewed/2024/04/GHSA-55jv-x7fj-7mg4/GHSA-55jv-x7fj-7mg4.json
+++ b/advisories/unreviewed/2024/04/GHSA-55jv-x7fj-7mg4/GHSA-55jv-x7fj-7mg4.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55jv-x7fj-7mg4",
- "modified": "2024-04-26T06:30:34Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-04-26T06:30:34Z",
"aliases": [
"CVE-2024-2159"
],
"details": "The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-26T05:15:50Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json b/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json
index 20f993ac088..085fbca5dda 100644
--- a/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json
+++ b/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvvm-pp96-j72m",
- "modified": "2024-04-16T18:31:36Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3862"
],
"details": "The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
+ }
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-908"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-4285-7mp2-g3hv/GHSA-4285-7mp2-g3hv.json b/advisories/unreviewed/2024/07/GHSA-4285-7mp2-g3hv/GHSA-4285-7mp2-g3hv.json
index d0ec4b6080e..6a100107f57 100644
--- a/advisories/unreviewed/2024/07/GHSA-4285-7mp2-g3hv/GHSA-4285-7mp2-g3hv.json
+++ b/advisories/unreviewed/2024/07/GHSA-4285-7mp2-g3hv/GHSA-4285-7mp2-g3hv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4285-7mp2-g3hv",
- "modified": "2024-07-01T06:31:18Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-07-01T06:31:18Z",
"aliases": [
"CVE-2024-6130"
],
"details": "The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-79"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T06:15:23Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-5w6v-768m-rvhm/GHSA-5w6v-768m-rvhm.json b/advisories/unreviewed/2024/07/GHSA-5w6v-768m-rvhm/GHSA-5w6v-768m-rvhm.json
index 5109e4826ed..8c7be04d369 100644
--- a/advisories/unreviewed/2024/07/GHSA-5w6v-768m-rvhm/GHSA-5w6v-768m-rvhm.json
+++ b/advisories/unreviewed/2024/07/GHSA-5w6v-768m-rvhm/GHSA-5w6v-768m-rvhm.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5w6v-768m-rvhm",
- "modified": "2024-08-21T06:32:18Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-07-16T03:31:00Z",
"aliases": [
"CVE-2024-6780"
],
"details": "Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security risks.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
+ }
],
"affected": [
@@ -35,7 +38,7 @@
"cwe_ids": [
"CWE-732"
],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-16T02:15:12Z"
diff --git a/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json b/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json
index 76e4dfd7738..31be6ca19d3 100644
--- a/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json
+++ b/advisories/unreviewed/2024/09/GHSA-ccrr-hx7g-hmm4/GHSA-ccrr-hx7g-hmm4.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-276c-c7gr-r4j6/GHSA-276c-c7gr-r4j6.json b/advisories/unreviewed/2024/10/GHSA-276c-c7gr-r4j6/GHSA-276c-c7gr-r4j6.json
new file mode 100644
index 00000000000..59122c10a91
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-276c-c7gr-r4j6/GHSA-276c-c7gr-r4j6.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-276c-c7gr-r4j6",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-33623"
+ ],
+ "details": "A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33623"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2001"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-835"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-3gr7-wwrx-664v/GHSA-3gr7-wwrx-664v.json b/advisories/unreviewed/2024/10/GHSA-3gr7-wwrx-664v/GHSA-3gr7-wwrx-664v.json
index 9522ad3ae95..84d087f76ef 100644
--- a/advisories/unreviewed/2024/10/GHSA-3gr7-wwrx-664v/GHSA-3gr7-wwrx-664v.json
+++ b/advisories/unreviewed/2024/10/GHSA-3gr7-wwrx-664v/GHSA-3gr7-wwrx-664v.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-3hjx-m6qm-hh35/GHSA-3hjx-m6qm-hh35.json b/advisories/unreviewed/2024/10/GHSA-3hjx-m6qm-hh35/GHSA-3hjx-m6qm-hh35.json
index 10a4cd79ab3..e8c641e2975 100644
--- a/advisories/unreviewed/2024/10/GHSA-3hjx-m6qm-hh35/GHSA-3hjx-m6qm-hh35.json
+++ b/advisories/unreviewed/2024/10/GHSA-3hjx-m6qm-hh35/GHSA-3hjx-m6qm-hh35.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hjx-m6qm-hh35",
- "modified": "2024-10-30T09:30:47Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-30T09:30:47Z",
"aliases": [
"CVE-2024-8444"
],
"details": "The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-30T07:15:16Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json b/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json
new file mode 100644
index 00000000000..696367a0d3a
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-43gj-mj95-qp4h/GHSA-43gj-mj95-qp4h.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-43gj-mj95-qp4h",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-51299"
+ ],
+ "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51299"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-4fj6-9r38-4v86/GHSA-4fj6-9r38-4v86.json b/advisories/unreviewed/2024/10/GHSA-4fj6-9r38-4v86/GHSA-4fj6-9r38-4v86.json
new file mode 100644
index 00000000000..9b13234f865
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-4fj6-9r38-4v86/GHSA-4fj6-9r38-4v86.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4fj6-9r38-4v86",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-28875"
+ ],
+ "details": "A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be found at address 0x80100910\n\n 80100910 40 6d 21 74 ds \"@m!t2K1\"\n 32 4b 31 00\n \nIt is referenced by the function located at 0x800b78b0 and is used as shown in the pseudocode below:\n\n if ((SECOND_FROM_BOOT_TIME < 300) &&\n (is_equal = strcmp(password,\"@m!t2K1\")) {\n return 1;}\n \nWhere 1 is the return value to admin-level access (0 being fail and 3 being user).",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28875"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1979"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-798"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json b/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json
new file mode 100644
index 00000000000..2e6b58b261b
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-4hjf-5mq4-f6c7/GHSA-4hjf-5mq4-f6c7.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4hjf-5mq4-f6c7",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-51296"
+ ],
+ "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51296"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json b/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json
index 3961c5b02ad..fb99bf3cba6 100644
--- a/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json
+++ b/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vhv-rmg8-wc9v",
- "modified": "2024-10-11T15:30:33Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-10-11T15:30:33Z",
"aliases": [
"CVE-2024-6657"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6657"
},
+ {
+ "type": "WEB",
+ "url": "https://community.silabs.com/068Vm00000FPVg0"
+ },
{
"type": "WEB",
"url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm00000E9IIbIAN?operationContext=S1"
diff --git a/advisories/unreviewed/2024/10/GHSA-59xm-4xxw-45c5/GHSA-59xm-4xxw-45c5.json b/advisories/unreviewed/2024/10/GHSA-59xm-4xxw-45c5/GHSA-59xm-4xxw-45c5.json
new file mode 100644
index 00000000000..c1b31059c9b
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-59xm-4xxw-45c5/GHSA-59xm-4xxw-45c5.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-59xm-4xxw-45c5",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-32946"
+ ],
+ "details": "A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it to network sniffing attacks.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32946"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1983"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-319"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-5q8j-rx3p-q6jm/GHSA-5q8j-rx3p-q6jm.json b/advisories/unreviewed/2024/10/GHSA-5q8j-rx3p-q6jm/GHSA-5q8j-rx3p-q6jm.json
index 202f5ec488c..a59b7840884 100644
--- a/advisories/unreviewed/2024/10/GHSA-5q8j-rx3p-q6jm/GHSA-5q8j-rx3p-q6jm.json
+++ b/advisories/unreviewed/2024/10/GHSA-5q8j-rx3p-q6jm/GHSA-5q8j-rx3p-q6jm.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json b/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json
new file mode 100644
index 00000000000..107801154a3
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-64xw-25gj-x6w6",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-51257"
+ ],
+ "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51257"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-6qvq-5969-5wrp/GHSA-6qvq-5969-5wrp.json b/advisories/unreviewed/2024/10/GHSA-6qvq-5969-5wrp/GHSA-6qvq-5969-5wrp.json
new file mode 100644
index 00000000000..ee23a8a807a
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-6qvq-5969-5wrp/GHSA-6qvq-5969-5wrp.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6qvq-5969-5wrp",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-33700"
+ ],
+ "details": "The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to cause a denial of service through a series of malformed FTP commands. This can lead to device reboots and service disruption.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1998"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-20"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-6w7x-r67f-jr7g/GHSA-6w7x-r67f-jr7g.json b/advisories/unreviewed/2024/10/GHSA-6w7x-r67f-jr7g/GHSA-6w7x-r67f-jr7g.json
new file mode 100644
index 00000000000..51d42ed02cc
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-6w7x-r67f-jr7g/GHSA-6w7x-r67f-jr7g.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6w7x-r67f-jr7g",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-33699"
+ ],
+ "details": "The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33699"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1984"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-620"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-777g-cfq7-cgv7/GHSA-777g-cfq7-cgv7.json b/advisories/unreviewed/2024/10/GHSA-777g-cfq7-cgv7/GHSA-777g-cfq7-cgv7.json
index ee498b856e2..1c1c78702ee 100644
--- a/advisories/unreviewed/2024/10/GHSA-777g-cfq7-cgv7/GHSA-777g-cfq7-cgv7.json
+++ b/advisories/unreviewed/2024/10/GHSA-777g-cfq7-cgv7/GHSA-777g-cfq7-cgv7.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-777g-cfq7-cgv7",
- "modified": "2024-10-29T03:31:06Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-29T03:31:06Z",
"aliases": [
"CVE-2024-50085"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow\n\nSyzkaller reported this splat:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in mptcp_pm_nl_rm_addr_or_subflow+0xb44/0xcc0 net/mptcp/pm_netlink.c:881\n Read of size 4 at addr ffff8880569ac858 by task syz.1.2799/14662\n\n CPU: 0 UID: 0 PID: 14662 Comm: syz.1.2799 Not tainted 6.12.0-rc2-syzkaller-00307-g36c254515dc6 #0\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n Call Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n mptcp_pm_nl_rm_addr_or_subflow+0xb44/0xcc0 net/mptcp/pm_netlink.c:881\n mptcp_pm_nl_rm_subflow_received net/mptcp/pm_netlink.c:914 [inline]\n mptcp_nl_remove_id_zero_address+0x305/0x4a0 net/mptcp/pm_netlink.c:1572\n mptcp_pm_nl_del_addr_doit+0x5c9/0x770 net/mptcp/pm_netlink.c:1603\n genl_family_rcv_msg_doit+0x202/0x2f0 net/netlink/genetlink.c:1115\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x565/0x800 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x165/0x410 net/netlink/af_netlink.c:2551\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]\n netlink_unicast+0x53c/0x7f0 net/netlink/af_netlink.c:1357\n netlink_sendmsg+0x8b8/0xd70 net/netlink/af_netlink.c:1901\n sock_sendmsg_nosec net/socket.c:729 [inline]\n __sock_sendmsg net/socket.c:744 [inline]\n ____sys_sendmsg+0x9ae/0xb40 net/socket.c:2607\n ___sys_sendmsg+0x135/0x1e0 net/socket.c:2661\n __sys_sendmsg+0x117/0x1f0 net/socket.c:2690\n do_syscall_32_irqs_on arch/x86/entry/common.c:165 [inline]\n __do_fast_syscall_32+0x73/0x120 arch/x86/entry/common.c:386\n do_fast_syscall_32+0x32/0x80 arch/x86/entry/common.c:411\n entry_SYSENTER_compat_after_hwframe+0x84/0x8e\n RIP: 0023:0xf7fe4579\n Code: b8 01 10 06 03 74 b4 01 10 07 03 74 b0 01 10 08 03 74 d8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 51 52 55 89 e5 0f 34 cd 80 <5d> 5a 59 c3 90 90 90 90 8d b4 26 00 00 00 00 8d b4 26 00 00 00 00\n RSP: 002b:00000000f574556c EFLAGS: 00000296 ORIG_RAX: 0000000000000172\n RAX: ffffffffffffffda RBX: 000000000000000b RCX: 0000000020000140\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000296 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n \n\n Allocated by task 5387:\n kasan_save_stack+0x33/0x60 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394\n kmalloc_noprof include/linux/slab.h:878 [inline]\n kzalloc_noprof include/linux/slab.h:1014 [inline]\n subflow_create_ctx+0x87/0x2a0 net/mptcp/subflow.c:1803\n subflow_ulp_init+0xc3/0x4d0 net/mptcp/subflow.c:1956\n __tcp_set_ulp net/ipv4/tcp_ulp.c:146 [inline]\n tcp_set_ulp+0x326/0x7f0 net/ipv4/tcp_ulp.c:167\n mptcp_subflow_create_socket+0x4ae/0x10a0 net/mptcp/subflow.c:1764\n __mptcp_subflow_connect+0x3cc/0x1490 net/mptcp/subflow.c:1592\n mptcp_pm_create_subflow_or_signal_addr+0xbda/0x23a0 net/mptcp/pm_netlink.c:642\n mptcp_pm_nl_fully_established net/mptcp/pm_netlink.c:650 [inline]\n mptcp_pm_nl_work+0x3a1/0x4f0 net/mptcp/pm_netlink.c:943\n mptcp_worker+0x15a/0x1240 net/mptcp/protocol.c:2777\n process_one_work+0x958/0x1b30 kernel/workqueue.c:3229\n process_scheduled_works kernel/workqueue.c:3310 [inline]\n worker_thread+0x6c8/0xf00 kernel/workqueue.c:3391\n kthread+0x2c1/0x3a0 kernel/kthread.c:389\n ret_from_fork+0x45/0x80 arch/x86/ke\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T01:15:05Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-8c5r-55p8-8p8m/GHSA-8c5r-55p8-8p8m.json b/advisories/unreviewed/2024/10/GHSA-8c5r-55p8-8p8m/GHSA-8c5r-55p8-8p8m.json
index 5bf0a6a5fbc..a546105da36 100644
--- a/advisories/unreviewed/2024/10/GHSA-8c5r-55p8-8p8m/GHSA-8c5r-55p8-8p8m.json
+++ b/advisories/unreviewed/2024/10/GHSA-8c5r-55p8-8p8m/GHSA-8c5r-55p8-8p8m.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c5r-55p8-8p8m",
- "modified": "2024-10-28T21:30:36Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-28T21:30:35Z",
"aliases": [
"CVE-2024-44285"
],
"details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1, visionOS 2.1, tvOS 18.1. An app may be able to cause unexpected system termination or corrupt kernel memory.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-28T21:15:08Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json b/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json
index 0aa4a549da5..18e24e76ff9 100644
--- a/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json
+++ b/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8m9g-c3mm-hr68",
- "modified": "2024-10-03T18:30:36Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-10-03T18:30:36Z",
"aliases": [
"CVE-2024-7825"
],
"details": "Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
diff --git a/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json b/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json
index 61ae82853b7..0e7618a4106 100644
--- a/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json
+++ b/advisories/unreviewed/2024/10/GHSA-c2hr-6qhm-xv9r/GHSA-c2hr-6qhm-xv9r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2hr-6qhm-xv9r",
- "modified": "2024-10-24T21:31:04Z",
+ "modified": "2024-10-30T15:30:45Z",
"published": "2024-10-24T21:31:04Z",
"aliases": [
"CVE-2024-7763"
diff --git a/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json b/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json
index 1a229d8d19c..8ca35cd89bb 100644
--- a/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json
+++ b/advisories/unreviewed/2024/10/GHSA-cm54-mprw-5279/GHSA-cm54-mprw-5279.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cm54-mprw-5279",
- "modified": "2024-10-30T12:31:24Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-30T12:31:24Z",
"aliases": [
"CVE-2024-10525"
],
"details": "In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
diff --git a/advisories/unreviewed/2024/10/GHSA-cxc4-ppv4-gfgj/GHSA-cxc4-ppv4-gfgj.json b/advisories/unreviewed/2024/10/GHSA-cxc4-ppv4-gfgj/GHSA-cxc4-ppv4-gfgj.json
index 854952e48a2..9ca92c7c925 100644
--- a/advisories/unreviewed/2024/10/GHSA-cxc4-ppv4-gfgj/GHSA-cxc4-ppv4-gfgj.json
+++ b/advisories/unreviewed/2024/10/GHSA-cxc4-ppv4-gfgj/GHSA-cxc4-ppv4-gfgj.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxc4-ppv4-gfgj",
- "modified": "2024-10-29T03:31:06Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-29T03:31:06Z",
"aliases": [
"CVE-2024-50087"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix uninitialized pointer free on read_alloc_one_name() error\n\nThe function read_alloc_one_name() does not initialize the name field of\nthe passed fscrypt_str struct if kmalloc fails to allocate the\ncorresponding buffer. Thus, it is not guaranteed that\nfscrypt_str.name is initialized when freeing it.\n\nThis is a follow-up to the linked patch that fixes the remaining\ninstances of the bug introduced by commit e43eec81c516 (\"btrfs: use\nstruct qstr instead of name and namelen pairs\").",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-824"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T01:15:05Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json b/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json
new file mode 100644
index 00000000000..6cd2c0da2be
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fh9m-mpjc-38hg",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-51298"
+ ],
+ "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51298"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json b/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json
new file mode 100644
index 00000000000..22c30114238
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-fv52-m5w8-2242/GHSA-fv52-m5w8-2242.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fv52-m5w8-2242",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-51304"
+ ],
+ "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51304"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T13:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json b/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json
index 658d36847bc..086698c789f 100644
--- a/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json
+++ b/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5vx-c2fq-6jm8",
- "modified": "2024-10-03T18:30:36Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-10-03T18:30:36Z",
"aliases": [
"CVE-2024-7826"
],
"details": "Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
diff --git a/advisories/unreviewed/2024/10/GHSA-h72p-7xmw-gpp8/GHSA-h72p-7xmw-gpp8.json b/advisories/unreviewed/2024/10/GHSA-h72p-7xmw-gpp8/GHSA-h72p-7xmw-gpp8.json
index 198fff220e8..82a88cb6a99 100644
--- a/advisories/unreviewed/2024/10/GHSA-h72p-7xmw-gpp8/GHSA-h72p-7xmw-gpp8.json
+++ b/advisories/unreviewed/2024/10/GHSA-h72p-7xmw-gpp8/GHSA-h72p-7xmw-gpp8.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h72p-7xmw-gpp8",
- "modified": "2024-10-30T00:31:04Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-30T00:31:04Z",
"aliases": [
"CVE-2024-10487"
],
"details": "Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T22:15:03Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-hjxq-5796-f748/GHSA-hjxq-5796-f748.json b/advisories/unreviewed/2024/10/GHSA-hjxq-5796-f748/GHSA-hjxq-5796-f748.json
new file mode 100644
index 00000000000..c9c8b44f688
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-hjxq-5796-f748/GHSA-hjxq-5796-f748.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hjxq-5796-f748",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-50419"
+ ],
+ "details": "Incorrect Authorization vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift – animation and page builder blocks: from n/a through 9.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50419"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/vulnerability/greenshift-animation-and-page-builder-blocks/wordpress-greenshift-animation-and-page-builder-blocks-plugin-9-7-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-863"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-jc6j-jf92-jq35/GHSA-jc6j-jf92-jq35.json b/advisories/unreviewed/2024/10/GHSA-jc6j-jf92-jq35/GHSA-jc6j-jf92-jq35.json
index 7c7b6dbe91a..09a3f041b7d 100644
--- a/advisories/unreviewed/2024/10/GHSA-jc6j-jf92-jq35/GHSA-jc6j-jf92-jq35.json
+++ b/advisories/unreviewed/2024/10/GHSA-jc6j-jf92-jq35/GHSA-jc6j-jf92-jq35.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-jxm2-6gmh-4m8x/GHSA-jxm2-6gmh-4m8x.json b/advisories/unreviewed/2024/10/GHSA-jxm2-6gmh-4m8x/GHSA-jxm2-6gmh-4m8x.json
new file mode 100644
index 00000000000..43add39b29d
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-jxm2-6gmh-4m8x/GHSA-jxm2-6gmh-4m8x.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jxm2-6gmh-4m8x",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-24777"
+ ],
+ "details": "A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious web page to trigger this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24777"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1981"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-p2c8-3p7x-5wc8/GHSA-p2c8-3p7x-5wc8.json b/advisories/unreviewed/2024/10/GHSA-p2c8-3p7x-5wc8/GHSA-p2c8-3p7x-5wc8.json
new file mode 100644
index 00000000000..3d771fbe0ee
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-p2c8-3p7x-5wc8/GHSA-p2c8-3p7x-5wc8.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p2c8-3p7x-5wc8",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-33626"
+ ],
+ "details": "The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the device's WiFi network.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33626"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1986"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json b/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json
index 3bcb0a37fbb..21f3eadbeac 100644
--- a/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json
+++ b/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p346-px87-vf2h",
- "modified": "2024-10-29T03:31:06Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-29T03:31:06Z",
"aliases": [
"CVE-2024-50084"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()\n\nCommit a3c1e45156ad (\"net: microchip: vcap: Fix use-after-free error in\nkunit test\") fixed the use-after-free error, but introduced below\nmemory leaks by removing necessary vcap_free_rule(), add it to fix it.\n\n\tunreferenced object 0xffffff80ca58b700 (size 192):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898264\n\t hex dump (first 32 bytes):\n\t 00 12 7a 00 05 00 00 00 0a 00 00 00 64 00 00 00 ..z.........d...\n\t 00 00 00 00 00 00 00 00 00 04 0b cc 80 ff ff ff ................\n\t backtrace (crc 9c09c3fe):\n\t [<0000000052a0be73>] kmemleak_alloc+0x34/0x40\n\t [<0000000043605459>] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [<0000000040a01b8d>] vcap_alloc_rule+0x3cc/0x9c4\n\t [<000000003fe86110>] vcap_api_encode_rule_test+0x1ac/0x16b0\n\t [<00000000b3595fc4>] kunit_try_run_case+0x13c/0x3ac\n\t [<0000000010f5d2bf>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000c5d82c9a>] kthread+0x2e8/0x374\n\t [<00000000f4287308>] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0400 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898265\n\t hex dump (first 32 bytes):\n\t 80 04 0b cc 80 ff ff ff 18 b7 58 ca 80 ff ff ff ..........X.....\n\t 39 00 00 00 02 00 00 00 06 05 04 03 02 01 ff ff 9...............\n\t backtrace (crc daf014e9):\n\t [<0000000052a0be73>] kmemleak_alloc+0x34/0x40\n\t [<0000000043605459>] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [<000000000ff63fd4>] vcap_rule_add_key+0x2cc/0x528\n\t [<00000000dfdb1e81>] vcap_api_encode_rule_test+0x224/0x16b0\n\t [<00000000b3595fc4>] kunit_try_run_case+0x13c/0x3ac\n\t [<0000000010f5d2bf>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000c5d82c9a>] kthread+0x2e8/0x374\n\t [<00000000f4287308>] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0700 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898265\n\t hex dump (first 32 bytes):\n\t 80 07 0b cc 80 ff ff ff 28 b7 58 ca 80 ff ff ff ........(.X.....\n\t 3c 00 00 00 00 00 00 00 01 2f 03 b3 ec ff ff ff <......../......\n\t backtrace (crc 8d877792):\n\t [<0000000052a0be73>] kmemleak_alloc+0x34/0x40\n\t [<0000000043605459>] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [<000000006eadfab7>] vcap_rule_add_action+0x2d0/0x52c\n\t [<00000000323475d1>] vcap_api_encode_rule_test+0x4d4/0x16b0\n\t [<00000000b3595fc4>] kunit_try_run_case+0x13c/0x3ac\n\t [<0000000010f5d2bf>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000c5d82c9a>] kthread+0x2e8/0x374\n\t [<00000000f4287308>] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0900 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898266\n\t hex dump (first 32 bytes):\n\t 80 09 0b cc 80 ff ff ff 80 06 0b cc 80 ff ff ff ................\n\t 7d 00 00 00 01 00 00 00 00 00 00 00 ff 00 00 00 }...............\n\t backtrace (crc 34181e56):\n\t [<0000000052a0be73>] kmemleak_alloc+0x34/0x40\n\t [<0000000043605459>] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [<000000000ff63fd4>] vcap_rule_add_key+0x2cc/0x528\n\t [<00000000991e3564>] vcap_val_rule+0xcf0/0x13e8\n\t [<00000000fc9868e5>] vcap_api_encode_rule_test+0x678/0x16b0\n\t [<00000000b3595fc4>] kunit_try_run_case+0x13c/0x3ac\n\t [<0000000010f5d2bf>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000c5d82c9a>] kthread+0x2e8/0x374\n\t [<00000000f4287308>] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0980 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898266\n\t hex dump (first 32 bytes):\n\t 18 b7 58 ca 80 ff ff ff 00 09 0b cc 80 ff ff ff ..X.............\n\t 67 00 00 00 00 00 00 00 01 01 74 88 c0 ff ff ff g.........t.....\n\t backtrace (crc 275fd9be):\n\t [<0000000052a0be73>] kmemleak_alloc+0x34/0x40\n\t [<0000000043605459>] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [<000000000ff63fd4>] vcap_rule_add_key+0x2cc/0x528\n\t [<000000001396a1a2>] test_add_de\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-401"
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T01:15:05Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-p3wf-f274-7gx2/GHSA-p3wf-f274-7gx2.json b/advisories/unreviewed/2024/10/GHSA-p3wf-f274-7gx2/GHSA-p3wf-f274-7gx2.json
index 7a79486398a..31fab1e5b2d 100644
--- a/advisories/unreviewed/2024/10/GHSA-p3wf-f274-7gx2/GHSA-p3wf-f274-7gx2.json
+++ b/advisories/unreviewed/2024/10/GHSA-p3wf-f274-7gx2/GHSA-p3wf-f274-7gx2.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3wf-f274-7gx2",
- "modified": "2024-10-30T00:31:04Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-30T00:31:04Z",
"aliases": [
"CVE-2024-10488"
],
"details": "Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
- "severity": null,
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T22:15:03Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-pr83-52rx-w5f5/GHSA-pr83-52rx-w5f5.json b/advisories/unreviewed/2024/10/GHSA-pr83-52rx-w5f5/GHSA-pr83-52rx-w5f5.json
new file mode 100644
index 00000000000..cad313b9a28
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-pr83-52rx-w5f5/GHSA-pr83-52rx-w5f5.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pr83-52rx-w5f5",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-28052"
+ ],
+ "details": "The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and small offices while aiming to be easy to configure and operate. In addition to providing a WiFi access point, the device serves as a 4-port wired router and implements a variety of common SOHO router capabilities such as port forwarding, quality-of-service, web-based administration, a DHCP server, a basic DMZ, and UPnP capabilities.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28052"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1997"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-131"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-q2hv-8prh-hr3r/GHSA-q2hv-8prh-hr3r.json b/advisories/unreviewed/2024/10/GHSA-q2hv-8prh-hr3r/GHSA-q2hv-8prh-hr3r.json
index e80cff92114..8b2d2ca26a4 100644
--- a/advisories/unreviewed/2024/10/GHSA-q2hv-8prh-hr3r/GHSA-q2hv-8prh-hr3r.json
+++ b/advisories/unreviewed/2024/10/GHSA-q2hv-8prh-hr3r/GHSA-q2hv-8prh-hr3r.json
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-q2q4-jrr5-68rj/GHSA-q2q4-jrr5-68rj.json b/advisories/unreviewed/2024/10/GHSA-q2q4-jrr5-68rj/GHSA-q2q4-jrr5-68rj.json
new file mode 100644
index 00000000000..51ced17940d
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-q2q4-jrr5-68rj/GHSA-q2q4-jrr5-68rj.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q2q4-jrr5-68rj",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-23309"
+ ],
+ "details": "The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23309"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1996"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-291"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-q63q-pqgx-268p/GHSA-q63q-pqgx-268p.json b/advisories/unreviewed/2024/10/GHSA-q63q-pqgx-268p/GHSA-q63q-pqgx-268p.json
new file mode 100644
index 00000000000..c7be9e1566f
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-q63q-pqgx-268p/GHSA-q63q-pqgx-268p.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q63q-pqgx-268p",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-31151"
+ ],
+ "details": "A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The password string can be found at addresses 0x 803cdd0f and 0x803da3e6:\n\n 803cdd0f 41 72 69 65 ds \"AriesSerenaCairryNativitaMegan\"\n 73 53 65 72 \n 65 6e 61 43\n ...\n\nIt is referenced by the function at 0x800b78b0 and simplified in the pseudocode below:\n\n if (is_equal = strcmp(password,\"AriesSerenaCairryNativitaMegan\"){\n ret = 3;}\n\nWhere 3 is the return value to user-level access (0 being fail and 1 being admin/backdoor).\n\nWhile there's no legitimate functionality to change this password, once authenticated it is possible manually make a change by taking advantage of TALOS-2024-XXXXX using HTTP POST paramater \"Pu\" (new user password) in place of \"Pa\" (new admin password).",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31151"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1979"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-798"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-qjqh-fr2p-8mpm/GHSA-qjqh-fr2p-8mpm.json b/advisories/unreviewed/2024/10/GHSA-qjqh-fr2p-8mpm/GHSA-qjqh-fr2p-8mpm.json
new file mode 100644
index 00000000000..8b8ea688252
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-qjqh-fr2p-8mpm/GHSA-qjqh-fr2p-8mpm.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qjqh-fr2p-8mpm",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-33603"
+ ],
+ "details": "The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33603"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1985"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:06Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-r5jh-qcvm-667j/GHSA-r5jh-qcvm-667j.json b/advisories/unreviewed/2024/10/GHSA-r5jh-qcvm-667j/GHSA-r5jh-qcvm-667j.json
index d22bd87e897..8320c8545e2 100644
--- a/advisories/unreviewed/2024/10/GHSA-r5jh-qcvm-667j/GHSA-r5jh-qcvm-667j.json
+++ b/advisories/unreviewed/2024/10/GHSA-r5jh-qcvm-667j/GHSA-r5jh-qcvm-667j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5jh-qcvm-667j",
- "modified": "2024-10-29T03:31:06Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-29T03:31:06Z",
"aliases": [
"CVE-2024-50086"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix user-after-free from session log off\n\nThere is racy issue between smb2 session log off and smb2 session setup.\nIt will cause user-after-free from session log off.\nThis add session_lock when setting SMB2_SESSION_EXPIRED and referece\ncount to session struct not to free session while it is being used.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-416"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T01:15:05Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json b/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json
index 83db85687c1..d34372773ae 100644
--- a/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json
+++ b/advisories/unreviewed/2024/10/GHSA-r5mw-c5jc-r788/GHSA-r5mw-c5jc-r788.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5mw-c5jc-r788",
- "modified": "2024-10-30T12:31:24Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-30T12:31:24Z",
"aliases": [
"CVE-2024-3935"
],
"details": "In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
diff --git a/advisories/unreviewed/2024/10/GHSA-r9vf-qqqr-747x/GHSA-r9vf-qqqr-747x.json b/advisories/unreviewed/2024/10/GHSA-r9vf-qqqr-747x/GHSA-r9vf-qqqr-747x.json
new file mode 100644
index 00000000000..6b7760624f8
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-r9vf-qqqr-747x/GHSA-r9vf-qqqr-747x.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r9vf-qqqr-747x",
+ "modified": "2024-10-30T15:30:46Z",
+ "published": "2024-10-30T15:30:46Z",
+ "aliases": [
+ "CVE-2024-31152"
+ ],
+ "details": "The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot. This could lead to network service interruptions.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31152"
+ },
+ {
+ "type": "WEB",
+ "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1982"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-400"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-rr46-96rc-r6xm/GHSA-rr46-96rc-r6xm.json b/advisories/unreviewed/2024/10/GHSA-rr46-96rc-r6xm/GHSA-rr46-96rc-r6xm.json
index 5d383b33c48..1cba8572d48 100644
--- a/advisories/unreviewed/2024/10/GHSA-rr46-96rc-r6xm/GHSA-rr46-96rc-r6xm.json
+++ b/advisories/unreviewed/2024/10/GHSA-rr46-96rc-r6xm/GHSA-rr46-96rc-r6xm.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json b/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json
new file mode 100644
index 00000000000..a93d0bc9a7a
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-v76h-6p79-mvh2/GHSA-v76h-6p79-mvh2.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v76h-6p79-mvh2",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-51301"
+ ],
+ "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51301"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json b/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json
index 8a505f09ff9..4dfb037f7e7 100644
--- a/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json
+++ b/advisories/unreviewed/2024/10/GHSA-v7pq-vg76-qwqx/GHSA-v7pq-vg76-qwqx.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7pq-vg76-qwqx",
- "modified": "2024-10-29T03:31:06Z",
+ "modified": "2024-10-30T15:30:46Z",
"published": "2024-10-29T03:31:06Z",
"aliases": [
"CVE-2024-50083"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix mptcp DSS corruption due to large pmtu xmit\n\nSyzkaller was able to trigger a DSS corruption:\n\n TCP: request_sock_subflow_v4: Possible SYN flooding on port [::]:20002. Sending cookies.\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 5227 at net/mptcp/protocol.c:695 __mptcp_move_skbs_from_subflow+0x20a9/0x21f0 net/mptcp/protocol.c:695\n Modules linked in:\n CPU: 0 UID: 0 PID: 5227 Comm: syz-executor350 Not tainted 6.11.0-syzkaller-08829-gaf9c191ac2a0 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\n RIP: 0010:__mptcp_move_skbs_from_subflow+0x20a9/0x21f0 net/mptcp/protocol.c:695\n Code: 0f b6 dc 31 ff 89 de e8 b5 dd ea f5 89 d8 48 81 c4 50 01 00 00 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 98 da ea f5 90 <0f> 0b 90 e9 47 ff ff ff e8 8a da ea f5 90 0f 0b 90 e9 99 e0 ff ff\n RSP: 0018:ffffc90000006db8 EFLAGS: 00010246\n RAX: ffffffff8ba9df18 RBX: 00000000000055f0 RCX: ffff888030023c00\n RDX: 0000000000000100 RSI: 00000000000081e5 RDI: 00000000000055f0\n RBP: 1ffff110062bf1ae R08: ffffffff8ba9cf12 R09: 1ffff110062bf1b8\n R10: dffffc0000000000 R11: ffffed10062bf1b9 R12: 0000000000000000\n R13: dffffc0000000000 R14: 00000000700cec61 R15: 00000000000081e5\n FS: 000055556679c380(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000020287000 CR3: 0000000077892000 CR4: 00000000003506f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n move_skbs_to_msk net/mptcp/protocol.c:811 [inline]\n mptcp_data_ready+0x29c/0xa90 net/mptcp/protocol.c:854\n subflow_data_ready+0x34a/0x920 net/mptcp/subflow.c:1490\n tcp_data_queue+0x20fd/0x76c0 net/ipv4/tcp_input.c:5283\n tcp_rcv_established+0xfba/0x2020 net/ipv4/tcp_input.c:6237\n tcp_v4_do_rcv+0x96d/0xc70 net/ipv4/tcp_ipv4.c:1915\n tcp_v4_rcv+0x2dc0/0x37f0 net/ipv4/tcp_ipv4.c:2350\n ip_protocol_deliver_rcu+0x22e/0x440 net/ipv4/ip_input.c:205\n ip_local_deliver_finish+0x341/0x5f0 net/ipv4/ip_input.c:233\n NF_HOOK+0x3a4/0x450 include/linux/netfilter.h:314\n NF_HOOK+0x3a4/0x450 include/linux/netfilter.h:314\n __netif_receive_skb_one_core net/core/dev.c:5662 [inline]\n __netif_receive_skb+0x2bf/0x650 net/core/dev.c:5775\n process_backlog+0x662/0x15b0 net/core/dev.c:6107\n __napi_poll+0xcb/0x490 net/core/dev.c:6771\n napi_poll net/core/dev.c:6840 [inline]\n net_rx_action+0x89b/0x1240 net/core/dev.c:6962\n handle_softirqs+0x2c5/0x980 kernel/softirq.c:554\n do_softirq+0x11b/0x1e0 kernel/softirq.c:455\n \n \n __local_bh_enable_ip+0x1bb/0x200 kernel/softirq.c:382\n local_bh_enable include/linux/bottom_half.h:33 [inline]\n rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline]\n __dev_queue_xmit+0x1764/0x3e80 net/core/dev.c:4451\n dev_queue_xmit include/linux/netdevice.h:3094 [inline]\n neigh_hh_output include/net/neighbour.h:526 [inline]\n neigh_output include/net/neighbour.h:540 [inline]\n ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236\n ip_local_out net/ipv4/ip_output.c:130 [inline]\n __ip_queue_xmit+0x118c/0x1b80 net/ipv4/ip_output.c:536\n __tcp_transmit_skb+0x2544/0x3b30 net/ipv4/tcp_output.c:1466\n tcp_transmit_skb net/ipv4/tcp_output.c:1484 [inline]\n tcp_mtu_probe net/ipv4/tcp_output.c:2547 [inline]\n tcp_write_xmit+0x641d/0x6bf0 net/ipv4/tcp_output.c:2752\n __tcp_push_pending_frames+0x9b/0x360 net/ipv4/tcp_output.c:3015\n tcp_push_pending_frames include/net/tcp.h:2107 [inline]\n tcp_data_snd_check net/ipv4/tcp_input.c:5714 [inline]\n tcp_rcv_established+0x1026/0x2020 net/ipv4/tcp_input.c:6239\n tcp_v4_do_rcv+0x96d/0xc70 net/ipv4/tcp_ipv4.c:1915\n sk_backlog_rcv include/net/sock.h:1113 [inline]\n __release_sock+0x214/0x350 net/core/sock.c:3072\n release_sock+0x61/0x1f0 net/core/sock.c:3626\n mptcp_push_\n---truncated---",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
],
"affected": [
@@ -47,7 +50,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-29T01:15:05Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json b/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json
index 51f2fb5bc24..6901f41a6d2 100644
--- a/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json
+++ b/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmg4-jx97-rmvv",
- "modified": "2024-10-03T18:30:36Z",
+ "modified": "2024-10-30T15:30:44Z",
"published": "2024-10-03T18:30:36Z",
"aliases": [
"CVE-2024-7824"
],
"details": "Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
],
"affected": [
diff --git a/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json b/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json
new file mode 100644
index 00000000000..c795a3fdd6e
--- /dev/null
+++ b/advisories/unreviewed/2024/10/GHSA-vpwg-6766-6xgp/GHSA-vpwg-6766-6xgp.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vpwg-6766-6xgp",
+ "modified": "2024-10-30T15:30:47Z",
+ "published": "2024-10-30T15:30:47Z",
+ "aliases": [
+ "CVE-2024-51300"
+ ],
+ "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51300"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-10-30T14:15:08Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/10/GHSA-w6g2-qqv5-83qj/GHSA-w6g2-qqv5-83qj.json b/advisories/unreviewed/2024/10/GHSA-w6g2-qqv5-83qj/GHSA-w6g2-qqv5-83qj.json
index 77adeb4d47c..98a4da14065 100644
--- a/advisories/unreviewed/2024/10/GHSA-w6g2-qqv5-83qj/GHSA-w6g2-qqv5-83qj.json
+++ b/advisories/unreviewed/2024/10/GHSA-w6g2-qqv5-83qj/GHSA-w6g2-qqv5-83qj.json
@@ -52,7 +52,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-276"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-x29p-mgvr-2q2p/GHSA-x29p-mgvr-2q2p.json b/advisories/unreviewed/2024/10/GHSA-x29p-mgvr-2q2p/GHSA-x29p-mgvr-2q2p.json
index e07497de5a9..8686c86a6b9 100644
--- a/advisories/unreviewed/2024/10/GHSA-x29p-mgvr-2q2p/GHSA-x29p-mgvr-2q2p.json
+++ b/advisories/unreviewed/2024/10/GHSA-x29p-mgvr-2q2p/GHSA-x29p-mgvr-2q2p.json
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
-
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-xvc9-v5hw-8v8j/GHSA-xvc9-v5hw-8v8j.json b/advisories/unreviewed/2024/10/GHSA-xvc9-v5hw-8v8j/GHSA-xvc9-v5hw-8v8j.json
index fad6c9d07de..2f07badbfc9 100644
--- a/advisories/unreviewed/2024/10/GHSA-xvc9-v5hw-8v8j/GHSA-xvc9-v5hw-8v8j.json
+++ b/advisories/unreviewed/2024/10/GHSA-xvc9-v5hw-8v8j/GHSA-xvc9-v5hw-8v8j.json
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvc9-v5hw-8v8j",
- "modified": "2024-10-28T21:30:36Z",
+ "modified": "2024-10-30T15:30:45Z",
"published": "2024-10-28T21:30:35Z",
"aliases": [
"CVE-2024-44278"
],
"details": "An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. A sandboxed app may be able to access sensitive user data in system logs.",
"severity": [
-
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
],
"affected": [
@@ -47,7 +50,7 @@
"cwe_ids": [
],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-28T21:15:08Z"