diff --git a/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json b/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json index 7504303da41..d96ffc1889d 100644 --- a/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json +++ b/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4452-v8jv-h496", - "modified": "2024-02-16T03:30:51Z", + "modified": "2024-08-06T18:30:48Z", "published": "2024-02-16T03:30:51Z", "aliases": [ "CVE-2024-25413" ], "details": "A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:51Z" diff --git a/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json b/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json index 2821d82f68d..73107ad6b0b 100644 --- a/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json +++ b/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgjv-qpvm-qjx7", - "modified": "2024-02-20T21:30:25Z", + "modified": "2024-08-06T18:30:48Z", "published": "2024-02-20T21:30:25Z", "aliases": [ "CVE-2023-46967" ], "details": "Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T21:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json b/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json index 95f31a48fae..9a667b35c85 100644 --- a/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json +++ b/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whq9-vwxq-6f23", - "modified": "2024-02-09T18:31:07Z", + "modified": "2024-08-06T18:30:48Z", "published": "2024-02-05T18:31:37Z", "aliases": [ "CVE-2024-0953" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1837916" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-36" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json b/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json index fdb89aa8f77..fc9b38e311b 100644 --- a/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json +++ b/advisories/unreviewed/2024/03/GHSA-29pw-vrcf-rqvp/GHSA-29pw-vrcf-rqvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29pw-vrcf-rqvp", - "modified": "2024-03-20T15:32:23Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-20T15:32:23Z", "aliases": [ "CVE-2024-28283" ], "details": "There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T21:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2c59-j8fr-6828/GHSA-2c59-j8fr-6828.json b/advisories/unreviewed/2024/03/GHSA-2c59-j8fr-6828/GHSA-2c59-j8fr-6828.json index a498ec6800b..9904881b4f6 100644 --- a/advisories/unreviewed/2024/03/GHSA-2c59-j8fr-6828/GHSA-2c59-j8fr-6828.json +++ b/advisories/unreviewed/2024/03/GHSA-2c59-j8fr-6828/GHSA-2c59-j8fr-6828.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2c59-j8fr-6828", - "modified": "2024-03-21T03:36:45Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2023-49979" ], "details": "A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-548" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:49:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-36f2-v56q-6v2j/GHSA-36f2-v56q-6v2j.json b/advisories/unreviewed/2024/03/GHSA-36f2-v56q-6v2j/GHSA-36f2-v56q-6v2j.json index 7798750e3a2..f901bea0d56 100644 --- a/advisories/unreviewed/2024/03/GHSA-36f2-v56q-6v2j/GHSA-36f2-v56q-6v2j.json +++ b/advisories/unreviewed/2024/03/GHSA-36f2-v56q-6v2j/GHSA-36f2-v56q-6v2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36f2-v56q-6v2j", - "modified": "2024-03-27T06:30:31Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-27T06:30:31Z", "aliases": [ "CVE-2023-40290" ], "details": "An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7444-32c7-cjv4/GHSA-7444-32c7-cjv4.json b/advisories/unreviewed/2024/03/GHSA-7444-32c7-cjv4/GHSA-7444-32c7-cjv4.json index 418f84ec370..5f39292dbfd 100644 --- a/advisories/unreviewed/2024/03/GHSA-7444-32c7-cjv4/GHSA-7444-32c7-cjv4.json +++ b/advisories/unreviewed/2024/03/GHSA-7444-32c7-cjv4/GHSA-7444-32c7-cjv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7444-32c7-cjv4", - "modified": "2024-03-21T06:33:01Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-21T06:33:01Z", "aliases": [ "CVE-2023-48901" ], "details": "A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter \"id\" within the getPhotosByCarId function call in details.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T04:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-76jh-m3c4-gxgj/GHSA-76jh-m3c4-gxgj.json b/advisories/unreviewed/2024/03/GHSA-76jh-m3c4-gxgj/GHSA-76jh-m3c4-gxgj.json index 2edc6360487..e4a16e6cef6 100644 --- a/advisories/unreviewed/2024/03/GHSA-76jh-m3c4-gxgj/GHSA-76jh-m3c4-gxgj.json +++ b/advisories/unreviewed/2024/03/GHSA-76jh-m3c4-gxgj/GHSA-76jh-m3c4-gxgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76jh-m3c4-gxgj", - "modified": "2024-03-26T18:32:05Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-26T18:32:05Z", "aliases": [ "CVE-2024-2915" ], "details": "Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T16:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8w7r-5fhv-vwj9/GHSA-8w7r-5fhv-vwj9.json b/advisories/unreviewed/2024/03/GHSA-8w7r-5fhv-vwj9/GHSA-8w7r-5fhv-vwj9.json index 54b1164df95..15c03df628d 100644 --- a/advisories/unreviewed/2024/03/GHSA-8w7r-5fhv-vwj9/GHSA-8w7r-5fhv-vwj9.json +++ b/advisories/unreviewed/2024/03/GHSA-8w7r-5fhv-vwj9/GHSA-8w7r-5fhv-vwj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w7r-5fhv-vwj9", - "modified": "2024-03-01T06:33:06Z", + "modified": "2024-08-06T18:30:48Z", "published": "2024-03-01T06:33:06Z", "aliases": [ "CVE-2024-25293" ], "details": "mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T06:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-92jp-q2g9-wmq7/GHSA-92jp-q2g9-wmq7.json b/advisories/unreviewed/2024/03/GHSA-92jp-q2g9-wmq7/GHSA-92jp-q2g9-wmq7.json index 873a62b0eae..6ddd653960e 100644 --- a/advisories/unreviewed/2024/03/GHSA-92jp-q2g9-wmq7/GHSA-92jp-q2g9-wmq7.json +++ b/advisories/unreviewed/2024/03/GHSA-92jp-q2g9-wmq7/GHSA-92jp-q2g9-wmq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92jp-q2g9-wmq7", - "modified": "2024-03-21T03:36:47Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-21T03:36:47Z", "aliases": [ "CVE-2024-2053" ], "details": "The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the \"www-data\" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the \"www-data\" user.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-23" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:52:27Z" diff --git a/advisories/unreviewed/2024/03/GHSA-92q8-mrj6-9v42/GHSA-92q8-mrj6-9v42.json b/advisories/unreviewed/2024/03/GHSA-92q8-mrj6-9v42/GHSA-92q8-mrj6-9v42.json index 0aa1c6d86cf..a301b1222e2 100644 --- a/advisories/unreviewed/2024/03/GHSA-92q8-mrj6-9v42/GHSA-92q8-mrj6-9v42.json +++ b/advisories/unreviewed/2024/03/GHSA-92q8-mrj6-9v42/GHSA-92q8-mrj6-9v42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92q8-mrj6-9v42", - "modified": "2024-03-27T06:30:31Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-27T06:30:31Z", "aliases": [ "CVE-2023-40289" ], "details": "A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cv7f-2fw2-8wrg/GHSA-cv7f-2fw2-8wrg.json b/advisories/unreviewed/2024/03/GHSA-cv7f-2fw2-8wrg/GHSA-cv7f-2fw2-8wrg.json index 7d8fd24f4e4..8c178db5acc 100644 --- a/advisories/unreviewed/2024/03/GHSA-cv7f-2fw2-8wrg/GHSA-cv7f-2fw2-8wrg.json +++ b/advisories/unreviewed/2024/03/GHSA-cv7f-2fw2-8wrg/GHSA-cv7f-2fw2-8wrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv7f-2fw2-8wrg", - "modified": "2024-03-27T06:30:31Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-27T06:30:31Z", "aliases": [ "CVE-2023-45927" ], "details": "S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-703" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ghf9-8669-q7h4/GHSA-ghf9-8669-q7h4.json b/advisories/unreviewed/2024/03/GHSA-ghf9-8669-q7h4/GHSA-ghf9-8669-q7h4.json index 9c52cdd8c86..f57cc5f3b90 100644 --- a/advisories/unreviewed/2024/03/GHSA-ghf9-8669-q7h4/GHSA-ghf9-8669-q7h4.json +++ b/advisories/unreviewed/2024/03/GHSA-ghf9-8669-q7h4/GHSA-ghf9-8669-q7h4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghf9-8669-q7h4", - "modified": "2024-03-02T00:31:32Z", + "modified": "2024-08-06T18:30:48Z", "published": "2024-03-02T00:31:32Z", "aliases": [ "CVE-2024-24511" ], "details": "Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T23:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json b/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json index 693db71899f..d6efa9f18b2 100644 --- a/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json +++ b/advisories/unreviewed/2024/03/GHSA-gwqv-mxv2-3769/GHSA-gwqv-mxv2-3769.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwqv-mxv2-3769", - "modified": "2024-03-26T15:30:50Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-26T15:30:50Z", "aliases": [ "CVE-2024-29684" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T14:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h2ph-x33p-jmpm/GHSA-h2ph-x33p-jmpm.json b/advisories/unreviewed/2024/03/GHSA-h2ph-x33p-jmpm/GHSA-h2ph-x33p-jmpm.json index bf0b19b7d4b..2f1f04e6f32 100644 --- a/advisories/unreviewed/2024/03/GHSA-h2ph-x33p-jmpm/GHSA-h2ph-x33p-jmpm.json +++ b/advisories/unreviewed/2024/03/GHSA-h2ph-x33p-jmpm/GHSA-h2ph-x33p-jmpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2ph-x33p-jmpm", - "modified": "2024-03-21T06:33:03Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-21T06:33:03Z", "aliases": [ "CVE-2024-22724" ], "details": "An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hmmj-whc7-2qjg/GHSA-hmmj-whc7-2qjg.json b/advisories/unreviewed/2024/03/GHSA-hmmj-whc7-2qjg/GHSA-hmmj-whc7-2qjg.json index eadf1ecbade..5887c951f0a 100644 --- a/advisories/unreviewed/2024/03/GHSA-hmmj-whc7-2qjg/GHSA-hmmj-whc7-2qjg.json +++ b/advisories/unreviewed/2024/03/GHSA-hmmj-whc7-2qjg/GHSA-hmmj-whc7-2qjg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmmj-whc7-2qjg", - "modified": "2024-03-13T15:31:05Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-13T15:31:05Z", "aliases": [ "CVE-2024-28675" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T14:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json b/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json index 0f263f9e307..2935c76ba42 100644 --- a/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json +++ b/advisories/unreviewed/2024/03/GHSA-j8r5-8r3h-439x/GHSA-j8r5-8r3h-439x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8r5-8r3h-439x", - "modified": "2024-03-26T15:30:50Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-26T15:30:50Z", "aliases": [ "CVE-2023-50895" ], "details": "In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functionality allow remote authenticated administrative users to execute arbitrary Groovy code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T15:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qfrj-3cjf-95fh/GHSA-qfrj-3cjf-95fh.json b/advisories/unreviewed/2024/03/GHSA-qfrj-3cjf-95fh/GHSA-qfrj-3cjf-95fh.json index 4d93cb98430..139777b8f9a 100644 --- a/advisories/unreviewed/2024/03/GHSA-qfrj-3cjf-95fh/GHSA-qfrj-3cjf-95fh.json +++ b/advisories/unreviewed/2024/03/GHSA-qfrj-3cjf-95fh/GHSA-qfrj-3cjf-95fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfrj-3cjf-95fh", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20027" ], "details": "In da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541633.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r2f8-jcm8-g23c/GHSA-r2f8-jcm8-g23c.json b/advisories/unreviewed/2024/03/GHSA-r2f8-jcm8-g23c/GHSA-r2f8-jcm8-g23c.json index f657264d6aa..d4c2a0be791 100644 --- a/advisories/unreviewed/2024/03/GHSA-r2f8-jcm8-g23c/GHSA-r2f8-jcm8-g23c.json +++ b/advisories/unreviewed/2024/03/GHSA-r2f8-jcm8-g23c/GHSA-r2f8-jcm8-g23c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2f8-jcm8-g23c", - "modified": "2024-03-27T03:31:17Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25735" ], "details": "An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rmwv-r5xx-8jvp/GHSA-rmwv-r5xx-8jvp.json b/advisories/unreviewed/2024/03/GHSA-rmwv-r5xx-8jvp/GHSA-rmwv-r5xx-8jvp.json index f000a449f1a..a8d01d2db07 100644 --- a/advisories/unreviewed/2024/03/GHSA-rmwv-r5xx-8jvp/GHSA-rmwv-r5xx-8jvp.json +++ b/advisories/unreviewed/2024/03/GHSA-rmwv-r5xx-8jvp/GHSA-rmwv-r5xx-8jvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmwv-r5xx-8jvp", - "modified": "2024-03-02T00:31:31Z", + "modified": "2024-08-06T18:30:48Z", "published": "2024-03-02T00:31:31Z", "aliases": [ "CVE-2023-49540" ], "details": "Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v3wm-2xxw-69qc/GHSA-v3wm-2xxw-69qc.json b/advisories/unreviewed/2024/03/GHSA-v3wm-2xxw-69qc/GHSA-v3wm-2xxw-69qc.json index 540452c5365..6ef8fb45890 100644 --- a/advisories/unreviewed/2024/03/GHSA-v3wm-2xxw-69qc/GHSA-v3wm-2xxw-69qc.json +++ b/advisories/unreviewed/2024/03/GHSA-v3wm-2xxw-69qc/GHSA-v3wm-2xxw-69qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3wm-2xxw-69qc", - "modified": "2024-03-04T03:30:25Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-04T03:30:25Z", "aliases": [ "CVE-2024-20005" ], "details": "In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355599; Issue ID: ALPS08355599.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wj9m-j983-c5jg/GHSA-wj9m-j983-c5jg.json b/advisories/unreviewed/2024/03/GHSA-wj9m-j983-c5jg/GHSA-wj9m-j983-c5jg.json index 320dcea6e51..c293a47115e 100644 --- a/advisories/unreviewed/2024/03/GHSA-wj9m-j983-c5jg/GHSA-wj9m-j983-c5jg.json +++ b/advisories/unreviewed/2024/03/GHSA-wj9m-j983-c5jg/GHSA-wj9m-j983-c5jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wj9m-j983-c5jg", - "modified": "2024-03-13T15:31:03Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-13T15:31:03Z", "aliases": [ "CVE-2024-28431" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T13:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xm2p-hxq8-xj3q/GHSA-xm2p-hxq8-xj3q.json b/advisories/unreviewed/2024/03/GHSA-xm2p-hxq8-xj3q/GHSA-xm2p-hxq8-xj3q.json index d40677f681e..1f9bf51c86c 100644 --- a/advisories/unreviewed/2024/03/GHSA-xm2p-hxq8-xj3q/GHSA-xm2p-hxq8-xj3q.json +++ b/advisories/unreviewed/2024/03/GHSA-xm2p-hxq8-xj3q/GHSA-xm2p-hxq8-xj3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xm2p-hxq8-xj3q", - "modified": "2024-03-05T18:31:13Z", + "modified": "2024-08-06T18:30:49Z", "published": "2024-03-05T18:31:13Z", "aliases": [ "CVE-2024-27564" ], "details": "A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T17:15:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json b/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json index cb16c690eaf..5c4a052b220 100644 --- a/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json +++ b/advisories/unreviewed/2024/05/GHSA-fxqv-fm95-w2rw/GHSA-fxqv-fm95-w2rw.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-p795-v7xm-xvv6/GHSA-p795-v7xm-xvv6.json b/advisories/unreviewed/2024/05/GHSA-p795-v7xm-xvv6/GHSA-p795-v7xm-xvv6.json index 09e945df4cd..4f198420776 100644 --- a/advisories/unreviewed/2024/05/GHSA-p795-v7xm-xvv6/GHSA-p795-v7xm-xvv6.json +++ b/advisories/unreviewed/2024/05/GHSA-p795-v7xm-xvv6/GHSA-p795-v7xm-xvv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p795-v7xm-xvv6", - "modified": "2024-05-03T15:30:52Z", + "modified": "2024-08-06T18:30:50Z", "published": "2024-05-03T15:30:52Z", "aliases": [ "CVE-2024-33787" ], "details": "Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerability via the tuser_Number parameter at search_user.aspx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T13:15:22Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4j3p-3m7m-jgp4/GHSA-4j3p-3m7m-jgp4.json b/advisories/unreviewed/2024/06/GHSA-4j3p-3m7m-jgp4/GHSA-4j3p-3m7m-jgp4.json index 5af04f6f001..ef0739bbfc9 100644 --- a/advisories/unreviewed/2024/06/GHSA-4j3p-3m7m-jgp4/GHSA-4j3p-3m7m-jgp4.json +++ b/advisories/unreviewed/2024/06/GHSA-4j3p-3m7m-jgp4/GHSA-4j3p-3m7m-jgp4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-312" + "CWE-312", + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json b/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json index 605801a713b..38e4ad0b477 100644 --- a/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json +++ b/advisories/unreviewed/2024/06/GHSA-9h7v-6cr6-hcpx/GHSA-9h7v-6cr6-hcpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h7v-6cr6-hcpx", - "modified": "2024-07-18T18:31:42Z", + "modified": "2024-08-06T18:30:50Z", "published": "2024-06-18T12:30:41Z", "aliases": [ "CVE-2024-5953" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4633" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4997" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5953" diff --git a/advisories/unreviewed/2024/06/GHSA-frc3-jmxc-4pmx/GHSA-frc3-jmxc-4pmx.json b/advisories/unreviewed/2024/06/GHSA-frc3-jmxc-4pmx/GHSA-frc3-jmxc-4pmx.json index 00eb3c34d8e..1d50f9b2508 100644 --- a/advisories/unreviewed/2024/06/GHSA-frc3-jmxc-4pmx/GHSA-frc3-jmxc-4pmx.json +++ b/advisories/unreviewed/2024/06/GHSA-frc3-jmxc-4pmx/GHSA-frc3-jmxc-4pmx.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rj29-jj8r-f77v/GHSA-rj29-jj8r-f77v.json b/advisories/unreviewed/2024/06/GHSA-rj29-jj8r-f77v/GHSA-rj29-jj8r-f77v.json index 2413397f5ac..527aa1d5a3d 100644 --- a/advisories/unreviewed/2024/06/GHSA-rj29-jj8r-f77v/GHSA-rj29-jj8r-f77v.json +++ b/advisories/unreviewed/2024/06/GHSA-rj29-jj8r-f77v/GHSA-rj29-jj8r-f77v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rj29-jj8r-f77v", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-08-06T18:30:50Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-35326" ], "details": "libyaml v0.2.5 is vulnerable to Buffer Overflow. Affected by this issue is the function yaml_emitter_emit of the file /src/libyaml/src/emitter.c. The manipulation leads to a double-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T17:15:50Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2fpj-qhmc-jpvc/GHSA-2fpj-qhmc-jpvc.json b/advisories/unreviewed/2024/07/GHSA-2fpj-qhmc-jpvc/GHSA-2fpj-qhmc-jpvc.json index e9fe6fc771d..934c1aa3124 100644 --- a/advisories/unreviewed/2024/07/GHSA-2fpj-qhmc-jpvc/GHSA-2fpj-qhmc-jpvc.json +++ b/advisories/unreviewed/2024/07/GHSA-2fpj-qhmc-jpvc/GHSA-2fpj-qhmc-jpvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2fpj-qhmc-jpvc", - "modified": "2024-07-09T18:30:53Z", + "modified": "2024-08-06T18:30:50Z", "published": "2024-07-09T18:30:53Z", "aliases": [ "CVE-2024-6237" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/389ds/389-ds-base/issues/5989" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4997" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6237" diff --git a/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json b/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json new file mode 100644 index 00000000000..06aa7d038b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2355-2h8c-mw45/GHSA-2355-2h8c-mw45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2355-2h8c-mw45", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7003" + ], + "details": "Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7003" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/338233148" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-32j6-235r-7fmm/GHSA-32j6-235r-7fmm.json b/advisories/unreviewed/2024/08/GHSA-32j6-235r-7fmm/GHSA-32j6-235r-7fmm.json new file mode 100644 index 00000000000..a4e9450460a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-32j6-235r-7fmm/GHSA-32j6-235r-7fmm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32j6-235r-7fmm", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6989" + ], + "details": "Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6989" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/349342289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3576-52wp-c4mh/GHSA-3576-52wp-c4mh.json b/advisories/unreviewed/2024/08/GHSA-3576-52wp-c4mh/GHSA-3576-52wp-c4mh.json new file mode 100644 index 00000000000..f8748c62641 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3576-52wp-c4mh/GHSA-3576-52wp-c4mh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3576-52wp-c4mh", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7502" + ], + "details": "A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7502" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-219-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json b/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json new file mode 100644 index 00000000000..d768b9fdfa5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-366c-rrqj-7gmp/GHSA-366c-rrqj-7gmp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-366c-rrqj-7gmp", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6994" + ], + "details": "Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6994" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339686368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3hrv-ghrw-48w6/GHSA-3hrv-ghrw-48w6.json b/advisories/unreviewed/2024/08/GHSA-3hrv-ghrw-48w6/GHSA-3hrv-ghrw-48w6.json new file mode 100644 index 00000000000..2f00cbcfd87 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3hrv-ghrw-48w6/GHSA-3hrv-ghrw-48w6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hrv-ghrw-48w6", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-23464" + ], + "details": "In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23464" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=Windows&applicable_version=4.2.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json b/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json new file mode 100644 index 00000000000..298e37a8a48 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3v8g-fm64-g4mc/GHSA-3v8g-fm64-g4mc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v8g-fm64-g4mc", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6991" + ], + "details": "Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6991" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/346618785" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json b/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json new file mode 100644 index 00000000000..853346c366d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-42jh-6qqc-g99m/GHSA-42jh-6qqc-g99m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42jh-6qqc-g99m", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-39229" + ], + "details": "An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications via a man-in-the-middle attack when DDNS clients are reporting data to the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39229" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/DDNS%20data%20is%20not%20encrypted.md" + }, + { + "type": "WEB", + "url": "http://ar750ar750sar300mar300m16mt300n-v2b1300mt1300sft1200x750.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T17:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json b/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json index 9c630aa9e75..5062583d887 100644 --- a/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json +++ b/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54v7-45g9-xcqh", - "modified": "2024-08-06T06:30:38Z", + "modified": "2024-08-06T18:30:56Z", "published": "2024-08-06T06:30:38Z", "aliases": [ "CVE-2024-6651" ], "details": "The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T06:15:35Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5w43-pfc6-5944/GHSA-5w43-pfc6-5944.json b/advisories/unreviewed/2024/08/GHSA-5w43-pfc6-5944/GHSA-5w43-pfc6-5944.json new file mode 100644 index 00000000000..482f591284a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5w43-pfc6-5944/GHSA-5w43-pfc6-5944.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w43-pfc6-5944", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6995" + ], + "details": "Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6995" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/343938078" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json b/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json new file mode 100644 index 00000000000..028f3e79302 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5x3f-3wg2-mc2h/GHSA-5x3f-3wg2-mc2h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x3f-3wg2-mc2h", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-43113" + ], + "details": "The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43113" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874964" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-63rm-c268-28fh/GHSA-63rm-c268-28fh.json b/advisories/unreviewed/2024/08/GHSA-63rm-c268-28fh/GHSA-63rm-c268-28fh.json new file mode 100644 index 00000000000..34315bdbfb8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-63rm-c268-28fh/GHSA-63rm-c268-28fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63rm-c268-28fh", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-23460" + ], + "details": "The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23460" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=macos&applicable_version=4.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json b/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json index 37597be3db1..808415f84f0 100644 --- a/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json +++ b/advisories/unreviewed/2024/08/GHSA-69x6-6jqx-q847/GHSA-69x6-6jqx-q847.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69x6-6jqx-q847", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-06T18:30:56Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7527" ], "details": "Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6hm4-mg77-jxqp/GHSA-6hm4-mg77-jxqp.json b/advisories/unreviewed/2024/08/GHSA-6hm4-mg77-jxqp/GHSA-6hm4-mg77-jxqp.json index 47f5e935ab8..45886fae314 100644 --- a/advisories/unreviewed/2024/08/GHSA-6hm4-mg77-jxqp/GHSA-6hm4-mg77-jxqp.json +++ b/advisories/unreviewed/2024/08/GHSA-6hm4-mg77-jxqp/GHSA-6hm4-mg77-jxqp.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-121" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json b/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json index e299fb5545a..074f2112333 100644 --- a/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json +++ b/advisories/unreviewed/2024/08/GHSA-7j5g-jfh2-w58c/GHSA-7j5g-jfh2-w58c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j5g-jfh2-w58c", - "modified": "2024-08-06T15:30:53Z", + "modified": "2024-08-06T18:30:56Z", "published": "2024-08-06T15:30:53Z", "aliases": [ "CVE-2024-7520" ], "details": "A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129 and Firefox ESR < 128.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T13:15:57Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json b/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json new file mode 100644 index 00000000000..ba0b7a5778a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8j3m-968h-m85q/GHSA-8j3m-968h-m85q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j3m-968h-m85q", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-39227" + ], + "details": "GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell injection vulnerability via the interface check_ovpn_client_config.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39227" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Access%20to%20the%20C%20library%20without%20logging%20in.md" + }, + { + "type": "WEB", + "url": "http://ar750ar750sar300mar300m16mt300n-v2b1300mt1300sft1200x750.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8pww-55pm-85vv/GHSA-8pww-55pm-85vv.json b/advisories/unreviewed/2024/08/GHSA-8pww-55pm-85vv/GHSA-8pww-55pm-85vv.json new file mode 100644 index 00000000000..0e8e90f0bb1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8pww-55pm-85vv/GHSA-8pww-55pm-85vv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pww-55pm-85vv", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-39225" + ], + "details": "GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote code execution (RCE) vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39225" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Bypass%20the%20login%20mechanism.md" + }, + { + "type": "WEB", + "url": "http://ar750ar750sar300mar300m16mt300n-v2b1300mt1300sft1200x750.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json b/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json index d2411f350a2..865a9eb534b 100644 --- a/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json +++ b/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8x2c-hh3c-77q8", - "modified": "2024-08-05T18:31:43Z", + "modified": "2024-08-06T18:30:51Z", "published": "2024-08-05T18:31:43Z", "aliases": [ "CVE-2024-40530" ], "details": "Insecure Permissions vulnerability in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to execute arbitrary code via modification of the X-Forwarded-For header component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T16:15:36Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json b/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json new file mode 100644 index 00000000000..b01470b858b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qmq-f7gc-gf44", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-39226" + ], + "details": "GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain insecure permissions in the endpoint /cgi-bin/glc. This vulnerability allows unauthenticated attackers to execute arbitrary code or possibly a directory traversal via crafted JSON data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39226" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/s2s%20interface%20shell%20injection.md" + }, + { + "type": "WEB", + "url": "http://ar750ar750sar300mar300m16mt300n-v2b1300mt1300sft1200x750.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9x82-vrjw-2m6c/GHSA-9x82-vrjw-2m6c.json b/advisories/unreviewed/2024/08/GHSA-9x82-vrjw-2m6c/GHSA-9x82-vrjw-2m6c.json new file mode 100644 index 00000000000..d3759117f84 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9x82-vrjw-2m6c/GHSA-9x82-vrjw-2m6c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x82-vrjw-2m6c", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6999" + ], + "details": "Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6999" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/340893685" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json b/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json new file mode 100644 index 00000000000..e15196e7c9e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c6ch-gp25-6cpv/GHSA-c6ch-gp25-6cpv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6ch-gp25-6cpv", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6998" + ], + "details": "Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6998" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/340098902" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cccm-3vq5-cxqg/GHSA-cccm-3vq5-cxqg.json b/advisories/unreviewed/2024/08/GHSA-cccm-3vq5-cxqg/GHSA-cccm-3vq5-cxqg.json index c16e958f6ad..081e78f692a 100644 --- a/advisories/unreviewed/2024/08/GHSA-cccm-3vq5-cxqg/GHSA-cccm-3vq5-cxqg.json +++ b/advisories/unreviewed/2024/08/GHSA-cccm-3vq5-cxqg/GHSA-cccm-3vq5-cxqg.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-27" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-chgg-fhrr-fjmm/GHSA-chgg-fhrr-fjmm.json b/advisories/unreviewed/2024/08/GHSA-chgg-fhrr-fjmm/GHSA-chgg-fhrr-fjmm.json index c127d94eb22..901dba960c9 100644 --- a/advisories/unreviewed/2024/08/GHSA-chgg-fhrr-fjmm/GHSA-chgg-fhrr-fjmm.json +++ b/advisories/unreviewed/2024/08/GHSA-chgg-fhrr-fjmm/GHSA-chgg-fhrr-fjmm.json @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-121" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-cj7q-2c3r-w7p4/GHSA-cj7q-2c3r-w7p4.json b/advisories/unreviewed/2024/08/GHSA-cj7q-2c3r-w7p4/GHSA-cj7q-2c3r-w7p4.json new file mode 100644 index 00000000000..723cf03883d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cj7q-2c3r-w7p4/GHSA-cj7q-2c3r-w7p4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj7q-2c3r-w7p4", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-23483" + ], + "details": "An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23483" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=macos&applicable_version=4.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json b/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json new file mode 100644 index 00000000000..d89d0eb0b0d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cr8r-7g9p-hcx6/GHSA-cr8r-7g9p-hcx6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr8r-7g9p-hcx6", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-43111" + ], + "details": "Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43111" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874907" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json b/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json index 6dcdad1260d..80b0ad4afbd 100644 --- a/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json +++ b/advisories/unreviewed/2024/08/GHSA-fj4r-983x-g27c/GHSA-fj4r-983x-g27c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fj4r-983x-g27c", - "modified": "2024-08-02T21:31:34Z", + "modified": "2024-08-06T18:30:50Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38887" ], "details": "An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T21:16:30Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fvf5-wm7j-89hj/GHSA-fvf5-wm7j-89hj.json b/advisories/unreviewed/2024/08/GHSA-fvf5-wm7j-89hj/GHSA-fvf5-wm7j-89hj.json new file mode 100644 index 00000000000..9ecb4b76e4a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fvf5-wm7j-89hj/GHSA-fvf5-wm7j-89hj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvf5-wm7j-89hj", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7004" + ], + "details": "Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7004" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40063014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g494-wr54-xx2g/GHSA-g494-wr54-xx2g.json b/advisories/unreviewed/2024/08/GHSA-g494-wr54-xx2g/GHSA-g494-wr54-xx2g.json new file mode 100644 index 00000000000..62501295807 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g494-wr54-xx2g/GHSA-g494-wr54-xx2g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g494-wr54-xx2g", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7000" + ], + "details": "Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7000" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339877158" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gx6v-2mjc-2j33/GHSA-gx6v-2mjc-2j33.json b/advisories/unreviewed/2024/08/GHSA-gx6v-2mjc-2j33/GHSA-gx6v-2mjc-2j33.json new file mode 100644 index 00000000000..19c4c1aac13 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gx6v-2mjc-2j33/GHSA-gx6v-2mjc-2j33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx6v-2mjc-2j33", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-23456" + ], + "details": "Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23456" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=windows&applicable_version=4.2.0.190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hp2w-73jh-3x82/GHSA-hp2w-73jh-3x82.json b/advisories/unreviewed/2024/08/GHSA-hp2w-73jh-3x82/GHSA-hp2w-73jh-3x82.json new file mode 100644 index 00000000000..8f8e1e38012 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hp2w-73jh-3x82/GHSA-hp2w-73jh-3x82.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp2w-73jh-3x82", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-41616" + ], + "details": "D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41616" + }, + { + "type": "WEB", + "url": "https://github.com/LYaoBoL/IOTsec/blob/main/D-Link/DIR300/CVE-2024-41616" + }, + { + "type": "WEB", + "url": "https://github.com/LYaoBoL/IOTsec/blob/main/D-Link/DIR300/D-Link300.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hrw8-hpf8-7q72/GHSA-hrw8-hpf8-7q72.json b/advisories/unreviewed/2024/08/GHSA-hrw8-hpf8-7q72/GHSA-hrw8-hpf8-7q72.json new file mode 100644 index 00000000000..1e9ee73fcc0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hrw8-hpf8-7q72/GHSA-hrw8-hpf8-7q72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrw8-hpf8-7q72", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2023-28806" + ], + "details": "An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28806" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=windows&applicable_version=4.2.0.190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jq39-hww2-p4f4/GHSA-jq39-hww2-p4f4.json b/advisories/unreviewed/2024/08/GHSA-jq39-hww2-p4f4/GHSA-jq39-hww2-p4f4.json new file mode 100644 index 00000000000..c1680f150bd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jq39-hww2-p4f4/GHSA-jq39-hww2-p4f4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq39-hww2-p4f4", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6720" + ], + "details": "The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6720" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d1449be1-ae85-46f4-b5ba-390d25b87723" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mh7h-j839-pxpp/GHSA-mh7h-j839-pxpp.json b/advisories/unreviewed/2024/08/GHSA-mh7h-j839-pxpp/GHSA-mh7h-j839-pxpp.json new file mode 100644 index 00000000000..f3e59c3e89c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mh7h-j839-pxpp/GHSA-mh7h-j839-pxpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh7h-j839-pxpp", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7564" + ], + "details": "Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the get_response_json_result endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-24680.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7564" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mr4g-jrgx-66c6/GHSA-mr4g-jrgx-66c6.json b/advisories/unreviewed/2024/08/GHSA-mr4g-jrgx-66c6/GHSA-mr4g-jrgx-66c6.json new file mode 100644 index 00000000000..4b951096666 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mr4g-jrgx-66c6/GHSA-mr4g-jrgx-66c6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr4g-jrgx-66c6", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-23458" + ], + "details": "While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23458" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2023?applicable_category=windows&applicable_version=4.2.0.190" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p739-c89q-vj36/GHSA-p739-c89q-vj36.json b/advisories/unreviewed/2024/08/GHSA-p739-c89q-vj36/GHSA-p739-c89q-vj36.json new file mode 100644 index 00000000000..25b0eee5207 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p739-c89q-vj36/GHSA-p739-c89q-vj36.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p739-c89q-vj36", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6996" + ], + "details": "Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6996" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/333708039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json b/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json new file mode 100644 index 00000000000..24e42038c30 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqvj-7wmm-mjvv", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7001" + ], + "details": "Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7001" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/347509736" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json b/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json index 48570b141a1..a269eba075d 100644 --- a/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json +++ b/advisories/unreviewed/2024/08/GHSA-r7x6-6cmj-2972/GHSA-r7x6-6cmj-2972.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7x6-6cmj-2972", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-06T18:30:56Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-30170" ], "details": "PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and in major version 34.0 and later,", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T14:16:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json b/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json index 984845add11..dc3da3da35d 100644 --- a/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json +++ b/advisories/unreviewed/2024/08/GHSA-r94j-mwf9-qj2r/GHSA-r94j-mwf9-qj2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r94j-mwf9-qj2r", - "modified": "2024-08-02T21:31:34Z", + "modified": "2024-08-06T18:30:50Z", "published": "2024-08-02T21:31:34Z", "aliases": [ "CVE-2024-38891" ], "details": "An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T21:16:30Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rf88-px5j-vhj4/GHSA-rf88-px5j-vhj4.json b/advisories/unreviewed/2024/08/GHSA-rf88-px5j-vhj4/GHSA-rf88-px5j-vhj4.json new file mode 100644 index 00000000000..216e9bdb601 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rf88-px5j-vhj4/GHSA-rf88-px5j-vhj4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf88-px5j-vhj4", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-39228" + ], + "details": "GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 were discovered to contain a shell injection vulnerability via the interface check_config.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39228" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Ovpn%20interface%20shell%20injection.md" + }, + { + "type": "WEB", + "url": "http://ar750ar750sar300mar300m16mt300n-v2b1300mt1300sft1200x750.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vx44-h683-36m9/GHSA-vx44-h683-36m9.json b/advisories/unreviewed/2024/08/GHSA-vx44-h683-36m9/GHSA-vx44-h683-36m9.json new file mode 100644 index 00000000000..fde617db463 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vx44-h683-36m9/GHSA-vx44-h683-36m9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx44-h683-36m9", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-39751" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 297429", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39751" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297429" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7160580" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w28c-f4w5-mfwh/GHSA-w28c-f4w5-mfwh.json b/advisories/unreviewed/2024/08/GHSA-w28c-f4w5-mfwh/GHSA-w28c-f4w5-mfwh.json new file mode 100644 index 00000000000..58eeb37b79c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w28c-f4w5-mfwh/GHSA-w28c-f4w5-mfwh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w28c-f4w5-mfwh", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-7005" + ], + "details": "Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7005" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40068800" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20", + "CWE-807" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json b/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json new file mode 100644 index 00000000000..1a754aa8849 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wpvc-jgp6-vg6f/GHSA-wpvc-jgp6-vg6f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpvc-jgp6-vg6f", + "modified": "2024-08-06T18:30:57Z", + "published": "2024-08-06T18:30:57Z", + "aliases": [ + "CVE-2024-6988" + ], + "details": "Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6988" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/349198731" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json b/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json index cd50d97b5b0..75891bbe66d 100644 --- a/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json +++ b/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww7v-5cpr-4v77", - "modified": "2024-08-05T18:31:43Z", + "modified": "2024-08-06T18:30:52Z", "published": "2024-08-05T18:31:43Z", "aliases": [ "CVE-2024-40498" ], "details": "SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T17:15:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x2r7-v693-3xwx/GHSA-x2r7-v693-3xwx.json b/advisories/unreviewed/2024/08/GHSA-x2r7-v693-3xwx/GHSA-x2r7-v693-3xwx.json new file mode 100644 index 00000000000..23913141df9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x2r7-v693-3xwx/GHSA-x2r7-v693-3xwx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2r7-v693-3xwx", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-41333" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41333" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/179891/Tourism-Management-System-2.0-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/in/sampath-kumar-kadajari-4b18891a7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json b/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json new file mode 100644 index 00000000000..666aa1de552 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xmm2-x5jc-rvmh/GHSA-xmm2-x5jc-rvmh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmm2-x5jc-rvmh", + "modified": "2024-08-06T18:30:56Z", + "published": "2024-08-06T18:30:56Z", + "aliases": [ + "CVE-2024-43112" + ], + "details": "Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43112" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874910" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T16:15:49Z" + } +} \ No newline at end of file