From 8fd614ce126d75c1fcd20131089ffe11d89ca71a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 20 Nov 2024 00:33:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-23c2-hg9m-2pw8.json | 11 ++-- .../GHSA-4vg6-rmxw-vq23.json | 9 ++-- .../GHSA-cq85-4f5h-qqc4.json | 11 ++-- .../GHSA-qmxh-c3qm-vmrf.json | 11 ++-- .../GHSA-4cg8-w873-pfqx.json | 9 ++-- .../GHSA-mggj-wcpg-x6cm.json | 11 ++-- .../GHSA-pjvr-qvh4-frwq.json | 11 ++-- .../GHSA-63j7-4362-2cgm.json | 9 ++-- .../GHSA-8fpw-hmv9-f7c4.json | 11 ++-- .../GHSA-rvfh-h6c7-fc3c.json | 2 +- .../GHSA-5r34-776f-3434.json | 9 ++-- .../GHSA-fj5c-r5jw-5wp8.json | 9 ++-- .../GHSA-233g-c3hw-rh55.json | 35 +++++++++++++ .../GHSA-27gp-h89j-594r.json | 35 +++++++++++++ .../GHSA-27r4-945x-jq67.json | 35 +++++++++++++ .../GHSA-284g-pxp5-92cp.json | 35 +++++++++++++ .../GHSA-3h9f-v388-6w84.json | 9 ++-- .../GHSA-3p2r-95j5-h86j.json | 38 ++++++++++++++ .../GHSA-6cpp-mpjx-cx8v.json | 51 +++++++++++++++++++ .../GHSA-6wpw-4vr3-6744.json | 51 +++++++++++++++++++ .../GHSA-6x32-2mjm-x4r9.json | 35 +++++++++++++ .../GHSA-7h2g-q5x6-pwg2.json | 11 ++-- .../GHSA-8735-9wmp-4wx2.json | 35 +++++++++++++ .../GHSA-8mmp-cwxx-jp88.json | 35 +++++++++++++ .../GHSA-96vw-8v59-qqm9.json | 42 +++++++++++++++ .../GHSA-9vg7-gcq7-4hw3.json | 35 +++++++++++++ .../GHSA-cw9g-65q4-rpvj.json | 2 +- .../GHSA-f379-vp9q-4wrx.json | 38 ++++++++++++++ .../GHSA-hr5c-w8m8-mfqx.json | 35 +++++++++++++ .../GHSA-hx7h-2wvr-3q4j.json | 35 +++++++++++++ .../GHSA-mp9m-637r-pmhw.json | 38 ++++++++++++++ .../GHSA-mqmc-3v72-6q9f.json | 35 +++++++++++++ .../GHSA-p35q-vvhx-5rq6.json | 35 +++++++++++++ .../GHSA-p69h-9rqf-qr43.json | 35 +++++++++++++ .../GHSA-rhj5-4qqq-64c2.json | 35 +++++++++++++ .../GHSA-rpq5-v9pq-9j39.json | 35 +++++++++++++ .../GHSA-vq62-cwm9-ff9h.json | 38 ++++++++++++++ .../GHSA-vvf6-hv5w-4w55.json | 3 +- .../GHSA-vwxq-h662-6mgh.json | 2 +- .../GHSA-xc54-5cvr-93hc.json | 35 +++++++++++++ .../GHSA-xpq3-q67q-mw45.json | 11 ++-- 41 files changed, 953 insertions(+), 54 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json create mode 100644 advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json create mode 100644 advisories/unreviewed/2024/11/GHSA-284g-pxp5-92cp/GHSA-284g-pxp5-92cp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3p2r-95j5-h86j/GHSA-3p2r-95j5-h86j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6cpp-mpjx-cx8v/GHSA-6cpp-mpjx-cx8v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json create mode 100644 advisories/unreviewed/2024/11/GHSA-96vw-8v59-qqm9/GHSA-96vw-8v59-qqm9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9vg7-gcq7-4hw3/GHSA-9vg7-gcq7-4hw3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f379-vp9q-4wrx/GHSA-f379-vp9q-4wrx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hx7h-2wvr-3q4j/GHSA-hx7h-2wvr-3q4j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mp9m-637r-pmhw/GHSA-mp9m-637r-pmhw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p69h-9rqf-qr43/GHSA-p69h-9rqf-qr43.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vq62-cwm9-ff9h/GHSA-vq62-cwm9-ff9h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json diff --git a/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json b/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json index eae6c85957d..506aa679e42 100644 --- a/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json +++ b/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23c2-hg9m-2pw8", - "modified": "2024-02-29T21:30:52Z", + "modified": "2024-11-20T00:32:08Z", "published": "2024-02-29T21:30:52Z", "aliases": [ "CVE-2024-27660" ], "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T20:15:41Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json b/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json index 7d01d6c151f..bf1c5028b37 100644 --- a/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json +++ b/advisories/unreviewed/2024/02/GHSA-4vg6-rmxw-vq23/GHSA-4vg6-rmxw-vq23.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4vg6-rmxw-vq23", - "modified": "2024-06-10T21:30:34Z", + "modified": "2024-11-20T00:32:08Z", "published": "2024-02-15T06:31:36Z", "aliases": [ "CVE-2024-25941" ], "details": "The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside the current jail.\n\nAttacker can get information about TTYs allocated on the host or in other jails. Effectively, the information printed by \"pstat -t\" may be leaked.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T05:15:11Z" diff --git a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json index e28e16bf649..83b8e685f53 100644 --- a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json +++ b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq85-4f5h-qqc4", - "modified": "2024-03-04T09:30:29Z", + "modified": "2024-11-20T00:32:08Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1551" ], "details": "Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-565" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json b/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json index 1dd4360b7fc..ac2464d5880 100644 --- a/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json +++ b/advisories/unreviewed/2024/02/GHSA-qmxh-c3qm-vmrf/GHSA-qmxh-c3qm-vmrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmxh-c3qm-vmrf", - "modified": "2024-02-18T06:30:32Z", + "modified": "2024-11-20T00:32:08Z", "published": "2024-02-18T06:30:32Z", "aliases": [ "CVE-2023-52374" ], "details": "Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T04:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4cg8-w873-pfqx/GHSA-4cg8-w873-pfqx.json b/advisories/unreviewed/2024/03/GHSA-4cg8-w873-pfqx/GHSA-4cg8-w873-pfqx.json index 9a8d52eeeca..fa390c1e9c1 100644 --- a/advisories/unreviewed/2024/03/GHSA-4cg8-w873-pfqx/GHSA-4cg8-w873-pfqx.json +++ b/advisories/unreviewed/2024/03/GHSA-4cg8-w873-pfqx/GHSA-4cg8-w873-pfqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4cg8-w873-pfqx", - "modified": "2024-03-01T18:30:25Z", + "modified": "2024-11-20T00:32:08Z", "published": "2024-03-01T18:30:25Z", "aliases": [ "CVE-2023-52558" ], "details": "In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-131" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T17:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json b/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json index f2d041dcf74..53b473e4723 100644 --- a/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json +++ b/advisories/unreviewed/2024/04/GHSA-mggj-wcpg-x6cm/GHSA-mggj-wcpg-x6cm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mggj-wcpg-x6cm", - "modified": "2024-04-08T03:30:52Z", + "modified": "2024-11-20T00:32:08Z", "published": "2024-04-08T03:30:52Z", "aliases": [ "CVE-2023-52348" ], "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pjvr-qvh4-frwq/GHSA-pjvr-qvh4-frwq.json b/advisories/unreviewed/2024/04/GHSA-pjvr-qvh4-frwq/GHSA-pjvr-qvh4-frwq.json index a7795d0eefc..99e8cd84de2 100644 --- a/advisories/unreviewed/2024/04/GHSA-pjvr-qvh4-frwq/GHSA-pjvr-qvh4-frwq.json +++ b/advisories/unreviewed/2024/04/GHSA-pjvr-qvh4-frwq/GHSA-pjvr-qvh4-frwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjvr-qvh4-frwq", - "modified": "2024-04-30T00:30:35Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-04-30T00:30:35Z", "aliases": [ "CVE-2023-52728" ], "details": "Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T00:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-63j7-4362-2cgm/GHSA-63j7-4362-2cgm.json b/advisories/unreviewed/2024/05/GHSA-63j7-4362-2cgm/GHSA-63j7-4362-2cgm.json index 1393e977d0a..a4fc94b6d2f 100644 --- a/advisories/unreviewed/2024/05/GHSA-63j7-4362-2cgm/GHSA-63j7-4362-2cgm.json +++ b/advisories/unreviewed/2024/05/GHSA-63j7-4362-2cgm/GHSA-63j7-4362-2cgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-63j7-4362-2cgm", - "modified": "2024-05-17T18:30:42Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-05-17T18:30:42Z", "aliases": [ "CVE-2024-5072" ], "details": "Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8fpw-hmv9-f7c4/GHSA-8fpw-hmv9-f7c4.json b/advisories/unreviewed/2024/05/GHSA-8fpw-hmv9-f7c4/GHSA-8fpw-hmv9-f7c4.json index 35fa933ec3e..22035970cb7 100644 --- a/advisories/unreviewed/2024/05/GHSA-8fpw-hmv9-f7c4/GHSA-8fpw-hmv9-f7c4.json +++ b/advisories/unreviewed/2024/05/GHSA-8fpw-hmv9-f7c4/GHSA-8fpw-hmv9-f7c4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8fpw-hmv9-f7c4", - "modified": "2024-05-07T18:30:34Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-05-07T18:30:34Z", "aliases": [ "CVE-2024-33859" ], "details": "An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the \"Interesting Field\" Web UI, leading to XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rvfh-h6c7-fc3c/GHSA-rvfh-h6c7-fc3c.json b/advisories/unreviewed/2024/05/GHSA-rvfh-h6c7-fc3c/GHSA-rvfh-h6c7-fc3c.json index 6e15574ac89..889773136ea 100644 --- a/advisories/unreviewed/2024/05/GHSA-rvfh-h6c7-fc3c/GHSA-rvfh-h6c7-fc3c.json +++ b/advisories/unreviewed/2024/05/GHSA-rvfh-h6c7-fc3c/GHSA-rvfh-h6c7-fc3c.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-5r34-776f-3434/GHSA-5r34-776f-3434.json b/advisories/unreviewed/2024/07/GHSA-5r34-776f-3434/GHSA-5r34-776f-3434.json index b4990889600..db3bb3b5eb6 100644 --- a/advisories/unreviewed/2024/07/GHSA-5r34-776f-3434/GHSA-5r34-776f-3434.json +++ b/advisories/unreviewed/2024/07/GHSA-5r34-776f-3434/GHSA-5r34-776f-3434.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5r34-776f-3434", - "modified": "2024-07-17T21:31:37Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-07-04T09:32:49Z", "aliases": [ "CVE-2024-39884" ], "details": "A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   \"AddType\" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.\n\nUsers are recommended to upgrade to version 2.4.61, which fixes this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-04T09:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fj5c-r5jw-5wp8/GHSA-fj5c-r5jw-5wp8.json b/advisories/unreviewed/2024/07/GHSA-fj5c-r5jw-5wp8/GHSA-fj5c-r5jw-5wp8.json index fcc4464becd..0cab52e5742 100644 --- a/advisories/unreviewed/2024/07/GHSA-fj5c-r5jw-5wp8/GHSA-fj5c-r5jw-5wp8.json +++ b/advisories/unreviewed/2024/07/GHSA-fj5c-r5jw-5wp8/GHSA-fj5c-r5jw-5wp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fj5c-r5jw-5wp8", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-07-09T15:30:54Z", "aliases": [ "CVE-2024-6613" ], "details": "The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T15:15:13Z" diff --git a/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json b/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json new file mode 100644 index 00000000000..864cd122f0c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-233g-c3hw-rh55/GHSA-233g-c3hw-rh55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-233g-c3hw-rh55", + "modified": "2024-11-20T00:32:15Z", + "published": "2024-11-20T00:32:15Z", + "aliases": [ + "CVE-2018-9466" + ], + "details": "In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9466" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json b/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json new file mode 100644 index 00000000000..c616734fb65 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-27gp-h89j-594r/GHSA-27gp-h89j-594r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27gp-h89j-594r", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9419" + ], + "details": "In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9419" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json b/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json new file mode 100644 index 00000000000..0b65c023e83 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27r4-945x-jq67", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9412" + ], + "details": "In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9412" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-284g-pxp5-92cp/GHSA-284g-pxp5-92cp.json b/advisories/unreviewed/2024/11/GHSA-284g-pxp5-92cp/GHSA-284g-pxp5-92cp.json new file mode 100644 index 00000000000..0ff4d59335f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-284g-pxp5-92cp/GHSA-284g-pxp5-92cp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-284g-pxp5-92cp", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9433" + ], + "details": "In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9433" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json b/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json index 82734e6ca16..dffcc2bc160 100644 --- a/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json +++ b/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h9f-v388-6w84", - "modified": "2024-11-19T21:31:33Z", + "modified": "2024-11-20T00:32:14Z", "published": "2024-11-19T21:31:33Z", "aliases": [ "CVE-2024-11395" ], "details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T20:15:29Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3p2r-95j5-h86j/GHSA-3p2r-95j5-h86j.json b/advisories/unreviewed/2024/11/GHSA-3p2r-95j5-h86j/GHSA-3p2r-95j5-h86j.json new file mode 100644 index 00000000000..0826983818a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3p2r-95j5-h86j/GHSA-3p2r-95j5-h86j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p2r-95j5-h86j", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2024-30424" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30424" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpzoom-addons-for-beaver-builder/wordpress-beaver-builder-addons-by-wpzoom-plugin-1-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6cpp-mpjx-cx8v/GHSA-6cpp-mpjx-cx8v.json b/advisories/unreviewed/2024/11/GHSA-6cpp-mpjx-cx8v/GHSA-6cpp-mpjx-cx8v.json new file mode 100644 index 00000000000..110c063a50a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6cpp-mpjx-cx8v/GHSA-6cpp-mpjx-cx8v.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cpp-mpjx-cx8v", + "modified": "2024-11-20T00:32:15Z", + "published": "2024-11-20T00:32:15Z", + "aliases": [ + "CVE-2024-44309" + ], + "details": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44309" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121752" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121753" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121754" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121755" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121756" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T00:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json b/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json new file mode 100644 index 00000000000..957cb1b302e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6wpw-4vr3-6744/GHSA-6wpw-4vr3-6744.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wpw-4vr3-6744", + "modified": "2024-11-20T00:32:15Z", + "published": "2024-11-20T00:32:15Z", + "aliases": [ + "CVE-2024-44308" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44308" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121752" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121753" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121754" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121755" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121756" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T00:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json b/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json new file mode 100644 index 00000000000..19de3e5526c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6x32-2mjm-x4r9/GHSA-6x32-2mjm-x4r9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x32-2mjm-x4r9", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9432" + ], + "details": "In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to contacts, with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9432" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7h2g-q5x6-pwg2/GHSA-7h2g-q5x6-pwg2.json b/advisories/unreviewed/2024/11/GHSA-7h2g-q5x6-pwg2/GHSA-7h2g-q5x6-pwg2.json index 77593f33bae..d8b98d10652 100644 --- a/advisories/unreviewed/2024/11/GHSA-7h2g-q5x6-pwg2/GHSA-7h2g-q5x6-pwg2.json +++ b/advisories/unreviewed/2024/11/GHSA-7h2g-q5x6-pwg2/GHSA-7h2g-q5x6-pwg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h2g-q5x6-pwg2", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-27532" ], "details": "wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json b/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json new file mode 100644 index 00000000000..fce9e98cc3d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8735-9wmp-4wx2/GHSA-8735-9wmp-4wx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8735-9wmp-4wx2", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2024-44306" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44306" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120911" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T00:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json b/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json new file mode 100644 index 00000000000..052c25eedad --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8mmp-cwxx-jp88/GHSA-8mmp-cwxx-jp88.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mmp-cwxx-jp88", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9424" + ], + "details": "In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9424" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-96vw-8v59-qqm9/GHSA-96vw-8v59-qqm9.json b/advisories/unreviewed/2024/11/GHSA-96vw-8v59-qqm9/GHSA-96vw-8v59-qqm9.json new file mode 100644 index 00000000000..c6c95435f7c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-96vw-8v59-qqm9/GHSA-96vw-8v59-qqm9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96vw-8v59-qqm9", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2024-11400" + ], + "details": "The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the really_curr_tax parameter in all versions up to, and including, 1.3.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11400" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3186438" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f3158e77-39b3-4151-8f10-5824000a585a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9vg7-gcq7-4hw3/GHSA-9vg7-gcq7-4hw3.json b/advisories/unreviewed/2024/11/GHSA-9vg7-gcq7-4hw3/GHSA-9vg7-gcq7-4hw3.json new file mode 100644 index 00000000000..8884360258d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9vg7-gcq7-4hw3/GHSA-9vg7-gcq7-4hw3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vg7-gcq7-4hw3", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9440" + ], + "details": "In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9440" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json b/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json index 1e85db03519..b5c139cfa21 100644 --- a/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json +++ b/advisories/unreviewed/2024/11/GHSA-cw9g-65q4-rpvj/GHSA-cw9g-65q4-rpvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw9g-65q4-rpvj", - "modified": "2024-11-19T18:31:02Z", + "modified": "2024-11-20T00:32:10Z", "published": "2024-11-19T18:31:02Z", "aliases": [ "CVE-2024-51814" diff --git a/advisories/unreviewed/2024/11/GHSA-f379-vp9q-4wrx/GHSA-f379-vp9q-4wrx.json b/advisories/unreviewed/2024/11/GHSA-f379-vp9q-4wrx/GHSA-f379-vp9q-4wrx.json new file mode 100644 index 00000000000..d1cbe36379b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f379-vp9q-4wrx/GHSA-f379-vp9q-4wrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f379-vp9q-4wrx", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2023-27609" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NetTantra WP Roles at Registration allows Stored XSS.This issue affects WP Roles at Registration: from n/a through 0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-roles-at-registration/wordpress-wp-roles-at-registration-plugin-0-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json b/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json new file mode 100644 index 00000000000..8ed6a7128d7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hr5c-w8m8-mfqx/GHSA-hr5c-w8m8-mfqx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr5c-w8m8-mfqx", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9417" + ], + "details": "In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9417" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hx7h-2wvr-3q4j/GHSA-hx7h-2wvr-3q4j.json b/advisories/unreviewed/2024/11/GHSA-hx7h-2wvr-3q4j/GHSA-hx7h-2wvr-3q4j.json new file mode 100644 index 00000000000..e3219ac895b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hx7h-2wvr-3q4j/GHSA-hx7h-2wvr-3q4j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx7h-2wvr-3q4j", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9456" + ], + "details": "In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9456" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mp9m-637r-pmhw/GHSA-mp9m-637r-pmhw.json b/advisories/unreviewed/2024/11/GHSA-mp9m-637r-pmhw/GHSA-mp9m-637r-pmhw.json new file mode 100644 index 00000000000..61731f07ff0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mp9m-637r-pmhw/GHSA-mp9m-637r-pmhw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp9m-637r-pmhw", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2024-51669" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Vivwebs Dynamic Widgets.This issue affects Dynamic Widgets: from n/a through 1.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51669" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dynamic-widgets/wordpress-dynamic-widgets-plugin-1-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json b/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json new file mode 100644 index 00000000000..473f9d36458 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mqmc-3v72-6q9f/GHSA-mqmc-3v72-6q9f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqmc-3v72-6q9f", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9421" + ], + "details": "In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9421" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json b/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json new file mode 100644 index 00000000000..a885e434466 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p35q-vvhx-5rq6/GHSA-p35q-vvhx-5rq6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p35q-vvhx-5rq6", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9428" + ], + "details": "In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. https://source.android.com/security/bulletin/2018-07-01", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9428" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p69h-9rqf-qr43/GHSA-p69h-9rqf-qr43.json b/advisories/unreviewed/2024/11/GHSA-p69h-9rqf-qr43/GHSA-p69h-9rqf-qr43.json new file mode 100644 index 00000000000..3373dd5c64c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p69h-9rqf-qr43/GHSA-p69h-9rqf-qr43.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p69h-9rqf-qr43", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9467" + ], + "details": "In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9467" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-09-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T00:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json b/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json new file mode 100644 index 00000000000..ebafd46e7f7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rhj5-4qqq-64c2/GHSA-rhj5-4qqq-64c2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhj5-4qqq-64c2", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9420" + ], + "details": "In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9420" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json b/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json new file mode 100644 index 00000000000..751a0164de1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rpq5-v9pq-9j39/GHSA-rpq5-v9pq-9j39.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpq5-v9pq-9j39", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2018-9411" + ], + "details": "In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9411" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vq62-cwm9-ff9h/GHSA-vq62-cwm9-ff9h.json b/advisories/unreviewed/2024/11/GHSA-vq62-cwm9-ff9h/GHSA-vq62-cwm9-ff9h.json new file mode 100644 index 00000000000..9cbd10d9671 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vq62-cwm9-ff9h/GHSA-vq62-cwm9-ff9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq62-cwm9-ff9h", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2024-52392" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52392" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/w3speedster-wp/wordpress-w3speedster-plugin-7-25-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vvf6-hv5w-4w55/GHSA-vvf6-hv5w-4w55.json b/advisories/unreviewed/2024/11/GHSA-vvf6-hv5w-4w55/GHSA-vvf6-hv5w-4w55.json index 6271356cefd..84b4985d544 100644 --- a/advisories/unreviewed/2024/11/GHSA-vvf6-hv5w-4w55/GHSA-vvf6-hv5w-4w55.json +++ b/advisories/unreviewed/2024/11/GHSA-vvf6-hv5w-4w55/GHSA-vvf6-hv5w-4w55.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json b/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json index 5ddb9cb0911..a41c20d5701 100644 --- a/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json +++ b/advisories/unreviewed/2024/11/GHSA-vwxq-h662-6mgh/GHSA-vwxq-h662-6mgh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwxq-h662-6mgh", - "modified": "2024-11-19T18:31:05Z", + "modified": "2024-11-20T00:32:13Z", "published": "2024-11-19T18:31:05Z", "aliases": [ "CVE-2024-52401" diff --git a/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json b/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json new file mode 100644 index 00000000000..2e863c83b64 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xc54-5cvr-93hc/GHSA-xc54-5cvr-93hc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc54-5cvr-93hc", + "modified": "2024-11-20T00:32:14Z", + "published": "2024-11-20T00:32:14Z", + "aliases": [ + "CVE-2024-44307" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44307" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120911" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T00:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json b/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json index bbc7d5a5f40..8498df2cd4a 100644 --- a/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json +++ b/advisories/unreviewed/2024/11/GHSA-xpq3-q67q-mw45/GHSA-xpq3-q67q-mw45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xpq3-q67q-mw45", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-20T00:32:09Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-50655" ], "details": "emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T17:15:20Z"