diff --git a/advisories/unreviewed/2022/05/GHSA-3hc7-7vjp-8x77/GHSA-3hc7-7vjp-8x77.json b/advisories/unreviewed/2022/05/GHSA-3hc7-7vjp-8x77/GHSA-3hc7-7vjp-8x77.json index 7556476ef6f..891d0e0a008 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hc7-7vjp-8x77/GHSA-3hc7-7vjp-8x77.json +++ b/advisories/unreviewed/2022/05/GHSA-3hc7-7vjp-8x77/GHSA-3hc7-7vjp-8x77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3hc7-7vjp-8x77", - "modified": "2022-05-24T19:11:55Z", + "modified": "2024-12-17T18:33:40Z", "published": "2022-05-24T19:11:55Z", "aliases": [ "CVE-2021-24561" ], "details": "The WP SMS WordPress plugin before 5.4.13 does not sanitise the \"wp_group_name\" parameter before outputting it back in the \"Groups\" page, leading to an Authenticated Stored Cross-Site Scripting issue", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-6p7p-7664-cqrj/GHSA-6p7p-7664-cqrj.json b/advisories/unreviewed/2022/05/GHSA-6p7p-7664-cqrj/GHSA-6p7p-7664-cqrj.json index a048627d54f..1f2a36b2d71 100644 --- a/advisories/unreviewed/2022/05/GHSA-6p7p-7664-cqrj/GHSA-6p7p-7664-cqrj.json +++ b/advisories/unreviewed/2022/05/GHSA-6p7p-7664-cqrj/GHSA-6p7p-7664-cqrj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p7p-7664-cqrj", - "modified": "2022-05-24T16:53:42Z", + "modified": "2024-12-17T18:33:39Z", "published": "2022-05-24T16:53:42Z", "aliases": [ "CVE-2019-13511" ], "details": "Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -41,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-416" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-fj59-4p8f-vjgf/GHSA-fj59-4p8f-vjgf.json b/advisories/unreviewed/2022/05/GHSA-fj59-4p8f-vjgf/GHSA-fj59-4p8f-vjgf.json index 3fbfddf1115..72552335184 100644 --- a/advisories/unreviewed/2022/05/GHSA-fj59-4p8f-vjgf/GHSA-fj59-4p8f-vjgf.json +++ b/advisories/unreviewed/2022/05/GHSA-fj59-4p8f-vjgf/GHSA-fj59-4p8f-vjgf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fj59-4p8f-vjgf", - "modified": "2022-05-24T16:53:41Z", + "modified": "2024-12-17T18:33:39Z", "published": "2022-05-24T16:53:41Z", "aliases": [ "CVE-2019-13510" ], "details": "Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -68,7 +73,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json b/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json index 61fbd2da53d..080bed662c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json +++ b/advisories/unreviewed/2022/05/GHSA-qh85-2qpc-6734/GHSA-qh85-2qpc-6734.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qh85-2qpc-6734", - "modified": "2022-05-24T17:07:31Z", + "modified": "2024-12-17T18:33:40Z", "published": "2022-05-24T17:07:31Z", "aliases": [ "CVE-2019-13519" ], "details": "A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-843" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json b/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json index 6cddcbf5a57..bc5b19e0955 100644 --- a/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json +++ b/advisories/unreviewed/2022/05/GHSA-rr25-rmv3-92rm/GHSA-rr25-rmv3-92rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rr25-rmv3-92rm", - "modified": "2022-05-24T17:07:31Z", + "modified": "2024-12-17T18:33:40Z", "published": "2022-05-24T17:07:31Z", "aliases": [ "CVE-2019-13521" ], "details": "A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-357" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-4gwx-43qv-72j5/GHSA-4gwx-43qv-72j5.json b/advisories/unreviewed/2023/06/GHSA-4gwx-43qv-72j5/GHSA-4gwx-43qv-72j5.json index 46539732441..c77e70a9a7d 100644 --- a/advisories/unreviewed/2023/06/GHSA-4gwx-43qv-72j5/GHSA-4gwx-43qv-72j5.json +++ b/advisories/unreviewed/2023/06/GHSA-4gwx-43qv-72j5/GHSA-4gwx-43qv-72j5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-6mgq-6mpr-4mmx/GHSA-6mgq-6mpr-4mmx.json b/advisories/unreviewed/2023/06/GHSA-6mgq-6mpr-4mmx/GHSA-6mgq-6mpr-4mmx.json index 00b2ec0a2df..6eddf143d73 100644 --- a/advisories/unreviewed/2023/06/GHSA-6mgq-6mpr-4mmx/GHSA-6mgq-6mpr-4mmx.json +++ b/advisories/unreviewed/2023/06/GHSA-6mgq-6mpr-4mmx/GHSA-6mgq-6mpr-4mmx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-72pv-287m-jppg/GHSA-72pv-287m-jppg.json b/advisories/unreviewed/2023/06/GHSA-72pv-287m-jppg/GHSA-72pv-287m-jppg.json index 23af15473e0..b12c4469241 100644 --- a/advisories/unreviewed/2023/06/GHSA-72pv-287m-jppg/GHSA-72pv-287m-jppg.json +++ b/advisories/unreviewed/2023/06/GHSA-72pv-287m-jppg/GHSA-72pv-287m-jppg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-7v38-8rx6-7rw9/GHSA-7v38-8rx6-7rw9.json b/advisories/unreviewed/2023/06/GHSA-7v38-8rx6-7rw9/GHSA-7v38-8rx6-7rw9.json index 9559c05a8a3..ef93152a37d 100644 --- a/advisories/unreviewed/2023/06/GHSA-7v38-8rx6-7rw9/GHSA-7v38-8rx6-7rw9.json +++ b/advisories/unreviewed/2023/06/GHSA-7v38-8rx6-7rw9/GHSA-7v38-8rx6-7rw9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-8cfj-r8cf-wm37/GHSA-8cfj-r8cf-wm37.json b/advisories/unreviewed/2023/06/GHSA-8cfj-r8cf-wm37/GHSA-8cfj-r8cf-wm37.json index d18d3e0888f..60dc15940d1 100644 --- a/advisories/unreviewed/2023/06/GHSA-8cfj-r8cf-wm37/GHSA-8cfj-r8cf-wm37.json +++ b/advisories/unreviewed/2023/06/GHSA-8cfj-r8cf-wm37/GHSA-8cfj-r8cf-wm37.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-cjwm-wvj7-g2p6/GHSA-cjwm-wvj7-g2p6.json b/advisories/unreviewed/2023/06/GHSA-cjwm-wvj7-g2p6/GHSA-cjwm-wvj7-g2p6.json index da07a82c1b8..b1bda9ec466 100644 --- a/advisories/unreviewed/2023/06/GHSA-cjwm-wvj7-g2p6/GHSA-cjwm-wvj7-g2p6.json +++ b/advisories/unreviewed/2023/06/GHSA-cjwm-wvj7-g2p6/GHSA-cjwm-wvj7-g2p6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1188" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-cx35-frj6-3wjx/GHSA-cx35-frj6-3wjx.json b/advisories/unreviewed/2023/06/GHSA-cx35-frj6-3wjx/GHSA-cx35-frj6-3wjx.json index 391bc668a48..1f698c84efd 100644 --- a/advisories/unreviewed/2023/06/GHSA-cx35-frj6-3wjx/GHSA-cx35-frj6-3wjx.json +++ b/advisories/unreviewed/2023/06/GHSA-cx35-frj6-3wjx/GHSA-cx35-frj6-3wjx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-g83h-qmpp-jpwq/GHSA-g83h-qmpp-jpwq.json b/advisories/unreviewed/2023/06/GHSA-g83h-qmpp-jpwq/GHSA-g83h-qmpp-jpwq.json index ee6f5f27603..6d68ed7f66e 100644 --- a/advisories/unreviewed/2023/06/GHSA-g83h-qmpp-jpwq/GHSA-g83h-qmpp-jpwq.json +++ b/advisories/unreviewed/2023/06/GHSA-g83h-qmpp-jpwq/GHSA-g83h-qmpp-jpwq.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-mpcc-6v35-3pvf/GHSA-mpcc-6v35-3pvf.json b/advisories/unreviewed/2023/06/GHSA-mpcc-6v35-3pvf/GHSA-mpcc-6v35-3pvf.json index b897eeff6c3..5bee27ac77d 100644 --- a/advisories/unreviewed/2023/06/GHSA-mpcc-6v35-3pvf/GHSA-mpcc-6v35-3pvf.json +++ b/advisories/unreviewed/2023/06/GHSA-mpcc-6v35-3pvf/GHSA-mpcc-6v35-3pvf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-q6mf-24rq-66wc/GHSA-q6mf-24rq-66wc.json b/advisories/unreviewed/2023/06/GHSA-q6mf-24rq-66wc/GHSA-q6mf-24rq-66wc.json index 4930a9884a7..24cf0e1b727 100644 --- a/advisories/unreviewed/2023/06/GHSA-q6mf-24rq-66wc/GHSA-q6mf-24rq-66wc.json +++ b/advisories/unreviewed/2023/06/GHSA-q6mf-24rq-66wc/GHSA-q6mf-24rq-66wc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-rvxr-6f5h-jvh9/GHSA-rvxr-6f5h-jvh9.json b/advisories/unreviewed/2023/06/GHSA-rvxr-6f5h-jvh9/GHSA-rvxr-6f5h-jvh9.json index 49a236252c2..76f285880da 100644 --- a/advisories/unreviewed/2023/06/GHSA-rvxr-6f5h-jvh9/GHSA-rvxr-6f5h-jvh9.json +++ b/advisories/unreviewed/2023/06/GHSA-rvxr-6f5h-jvh9/GHSA-rvxr-6f5h-jvh9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-rw94-xc46-wxfw/GHSA-rw94-xc46-wxfw.json b/advisories/unreviewed/2023/06/GHSA-rw94-xc46-wxfw/GHSA-rw94-xc46-wxfw.json index 6491ca10203..33917b15544 100644 --- a/advisories/unreviewed/2023/06/GHSA-rw94-xc46-wxfw/GHSA-rw94-xc46-wxfw.json +++ b/advisories/unreviewed/2023/06/GHSA-rw94-xc46-wxfw/GHSA-rw94-xc46-wxfw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-v7xg-323f-v8p9/GHSA-v7xg-323f-v8p9.json b/advisories/unreviewed/2023/06/GHSA-v7xg-323f-v8p9/GHSA-v7xg-323f-v8p9.json index 7fa50eaadc6..6077549a071 100644 --- a/advisories/unreviewed/2023/06/GHSA-v7xg-323f-v8p9/GHSA-v7xg-323f-v8p9.json +++ b/advisories/unreviewed/2023/06/GHSA-v7xg-323f-v8p9/GHSA-v7xg-323f-v8p9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1188" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-x86v-p8fr-6c2m/GHSA-x86v-p8fr-6c2m.json b/advisories/unreviewed/2023/06/GHSA-x86v-p8fr-6c2m/GHSA-x86v-p8fr-6c2m.json index 810ca99a262..95884e7adfa 100644 --- a/advisories/unreviewed/2023/06/GHSA-x86v-p8fr-6c2m/GHSA-x86v-p8fr-6c2m.json +++ b/advisories/unreviewed/2023/06/GHSA-x86v-p8fr-6c2m/GHSA-x86v-p8fr-6c2m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-384" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-xc66-p5pg-2c2c/GHSA-xc66-p5pg-2c2c.json b/advisories/unreviewed/2023/06/GHSA-xc66-p5pg-2c2c/GHSA-xc66-p5pg-2c2c.json index 28382ae6429..f5eb2976abe 100644 --- a/advisories/unreviewed/2023/06/GHSA-xc66-p5pg-2c2c/GHSA-xc66-p5pg-2c2c.json +++ b/advisories/unreviewed/2023/06/GHSA-xc66-p5pg-2c2c/GHSA-xc66-p5pg-2c2c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json b/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json index c65f2bc6051..fb26b953655 100644 --- a/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json +++ b/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-6jh6-8262-gqc4/GHSA-6jh6-8262-gqc4.json b/advisories/unreviewed/2024/05/GHSA-6jh6-8262-gqc4/GHSA-6jh6-8262-gqc4.json index 06fc08ef4c2..a597dd6e30e 100644 --- a/advisories/unreviewed/2024/05/GHSA-6jh6-8262-gqc4/GHSA-6jh6-8262-gqc4.json +++ b/advisories/unreviewed/2024/05/GHSA-6jh6-8262-gqc4/GHSA-6jh6-8262-gqc4.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json b/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json index b1b2a5f8586..5ee1a750a3e 100644 --- a/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json +++ b/advisories/unreviewed/2024/05/GHSA-qxxc-w5wg-5w4v/GHSA-qxxc-w5wg-5w4v.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x93h-5q4r-cgp7/GHSA-x93h-5q4r-cgp7.json b/advisories/unreviewed/2024/05/GHSA-x93h-5q4r-cgp7/GHSA-x93h-5q4r-cgp7.json index 5361e777fda..76cb8a26dde 100644 --- a/advisories/unreviewed/2024/05/GHSA-x93h-5q4r-cgp7/GHSA-x93h-5q4r-cgp7.json +++ b/advisories/unreviewed/2024/05/GHSA-x93h-5q4r-cgp7/GHSA-x93h-5q4r-cgp7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x93h-5q4r-cgp7", - "modified": "2024-05-07T21:31:46Z", + "modified": "2024-12-17T18:33:43Z", "published": "2024-05-07T21:31:46Z", "aliases": [ "CVE-2024-0027" ], "details": "In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json b/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json index 7d99a5a9247..76775bc7a5f 100644 --- a/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json +++ b/advisories/unreviewed/2024/05/GHSA-xpq8-mc3r-r862/GHSA-xpq8-mc3r-r862.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-280" + "CWE-280", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-6rw7-r5pp-274m/GHSA-6rw7-r5pp-274m.json b/advisories/unreviewed/2024/07/GHSA-6rw7-r5pp-274m/GHSA-6rw7-r5pp-274m.json index 8eecf46f817..6eca23a77a2 100644 --- a/advisories/unreviewed/2024/07/GHSA-6rw7-r5pp-274m/GHSA-6rw7-r5pp-274m.json +++ b/advisories/unreviewed/2024/07/GHSA-6rw7-r5pp-274m/GHSA-6rw7-r5pp-274m.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-441" + "CWE-441", + "CWE-610" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-g2w4-xpfp-74f3/GHSA-g2w4-xpfp-74f3.json b/advisories/unreviewed/2024/07/GHSA-g2w4-xpfp-74f3/GHSA-g2w4-xpfp-74f3.json index a8a4e306b1f..5b669c7dd7b 100644 --- a/advisories/unreviewed/2024/07/GHSA-g2w4-xpfp-74f3/GHSA-g2w4-xpfp-74f3.json +++ b/advisories/unreviewed/2024/07/GHSA-g2w4-xpfp-74f3/GHSA-g2w4-xpfp-74f3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-phhv-843p-5rr5/GHSA-phhv-843p-5rr5.json b/advisories/unreviewed/2024/07/GHSA-phhv-843p-5rr5/GHSA-phhv-843p-5rr5.json index 0810cf4df2d..cedfd09422d 100644 --- a/advisories/unreviewed/2024/07/GHSA-phhv-843p-5rr5/GHSA-phhv-843p-5rr5.json +++ b/advisories/unreviewed/2024/07/GHSA-phhv-843p-5rr5/GHSA-phhv-843p-5rr5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-rqh7-55gr-2vcc/GHSA-rqh7-55gr-2vcc.json b/advisories/unreviewed/2024/07/GHSA-rqh7-55gr-2vcc/GHSA-rqh7-55gr-2vcc.json index b84f205da03..69ab7f9ff64 100644 --- a/advisories/unreviewed/2024/07/GHSA-rqh7-55gr-2vcc/GHSA-rqh7-55gr-2vcc.json +++ b/advisories/unreviewed/2024/07/GHSA-rqh7-55gr-2vcc/GHSA-rqh7-55gr-2vcc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-362" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-vqgf-5288-7fgg/GHSA-vqgf-5288-7fgg.json b/advisories/unreviewed/2024/07/GHSA-vqgf-5288-7fgg/GHSA-vqgf-5288-7fgg.json index 27a68ef7677..0165285e0e1 100644 --- a/advisories/unreviewed/2024/07/GHSA-vqgf-5288-7fgg/GHSA-vqgf-5288-7fgg.json +++ b/advisories/unreviewed/2024/07/GHSA-vqgf-5288-7fgg/GHSA-vqgf-5288-7fgg.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json b/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json index 409dc61fc8b..56c735c948a 100644 --- a/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json +++ b/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json b/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json index c7d569561d9..4d9d7b04091 100644 --- a/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json +++ b/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json @@ -46,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-368" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json b/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json index db60065ae72..b2d4c159b4e 100644 --- a/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json +++ b/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-91" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json b/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json index 4080dcc9548..1f10961c836 100644 --- a/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json +++ b/advisories/unreviewed/2024/11/GHSA-5mv2-m792-g4pg/GHSA-5mv2-m792-g4pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mv2-m792-g4pg", - "modified": "2024-11-26T21:32:24Z", + "modified": "2024-12-17T18:33:44Z", "published": "2024-11-26T21:32:24Z", "aliases": [ "CVE-2019-17082" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-306" + "CWE-306", + "CWE-522" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-2qgh-37rm-mv6x/GHSA-2qgh-37rm-mv6x.json b/advisories/unreviewed/2024/12/GHSA-2qgh-37rm-mv6x/GHSA-2qgh-37rm-mv6x.json new file mode 100644 index 00000000000..8395ee192f3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2qgh-37rm-mv6x/GHSA-2qgh-37rm-mv6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qgh-37rm-mv6x", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-10476" + ], + "details": "Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may allow an attacker to shut down or otherwise impact the availability of the system. Note: BD Synapsys™ Informatics\nSolution is only in scope of\nthis vulnerability when\ninstalled on a NUC server. BD Synapsys™\nInformatics Solution installed\non a customer-provided virtual machine or on the BD Kiestra™ SCU hardware is\nnot in scope.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10476" + }, + { + "type": "WEB", + "url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-cybersecurity-vulnerability-bulletin-diagnostic-solutions-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3785-cv6x-mm3h/GHSA-3785-cv6x-mm3h.json b/advisories/unreviewed/2024/12/GHSA-3785-cv6x-mm3h/GHSA-3785-cv6x-mm3h.json index 864000390fc..d43923b8b0f 100644 --- a/advisories/unreviewed/2024/12/GHSA-3785-cv6x-mm3h/GHSA-3785-cv6x-mm3h.json +++ b/advisories/unreviewed/2024/12/GHSA-3785-cv6x-mm3h/GHSA-3785-cv6x-mm3h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3785-cv6x-mm3h", - "modified": "2024-12-17T00:31:17Z", + "modified": "2024-12-17T18:33:47Z", "published": "2024-12-17T00:31:17Z", "aliases": [ "CVE-2024-37776" ], "details": "A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T22:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4fj3-xj7w-f7cv/GHSA-4fj3-xj7w-f7cv.json b/advisories/unreviewed/2024/12/GHSA-4fj3-xj7w-f7cv/GHSA-4fj3-xj7w-f7cv.json index 51a91949925..05e80c7ae2c 100644 --- a/advisories/unreviewed/2024/12/GHSA-4fj3-xj7w-f7cv/GHSA-4fj3-xj7w-f7cv.json +++ b/advisories/unreviewed/2024/12/GHSA-4fj3-xj7w-f7cv/GHSA-4fj3-xj7w-f7cv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4fj3-xj7w-f7cv", - "modified": "2024-12-17T15:31:44Z", + "modified": "2024-12-17T18:33:48Z", "published": "2024-12-17T15:31:43Z", "aliases": [ "CVE-2024-36832" ], "details": "A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receives a carefully constructed HTTP request, it will crash and exit due to a null pointer reference, leading to a denial of service attack to the device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T15:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-58x6-9vjj-69q7/GHSA-58x6-9vjj-69q7.json b/advisories/unreviewed/2024/12/GHSA-58x6-9vjj-69q7/GHSA-58x6-9vjj-69q7.json index 599c9057cae..49cbf2ebbf4 100644 --- a/advisories/unreviewed/2024/12/GHSA-58x6-9vjj-69q7/GHSA-58x6-9vjj-69q7.json +++ b/advisories/unreviewed/2024/12/GHSA-58x6-9vjj-69q7/GHSA-58x6-9vjj-69q7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-58x6-9vjj-69q7", - "modified": "2024-12-16T21:30:56Z", + "modified": "2024-12-17T18:33:47Z", "published": "2024-12-16T21:30:56Z", "aliases": [ "CVE-2024-55104" ], "details": "Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-65c3-x7x6-jmfm/GHSA-65c3-x7x6-jmfm.json b/advisories/unreviewed/2024/12/GHSA-65c3-x7x6-jmfm/GHSA-65c3-x7x6-jmfm.json index 0fc08139572..a51596f014b 100644 --- a/advisories/unreviewed/2024/12/GHSA-65c3-x7x6-jmfm/GHSA-65c3-x7x6-jmfm.json +++ b/advisories/unreviewed/2024/12/GHSA-65c3-x7x6-jmfm/GHSA-65c3-x7x6-jmfm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65c3-x7x6-jmfm", - "modified": "2024-12-16T21:30:57Z", + "modified": "2024-12-17T18:33:47Z", "published": "2024-12-16T21:30:57Z", "aliases": [ "CVE-2024-55557" ], "details": "ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json b/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json new file mode 100644 index 00000000000..1e29d8fb8ab --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67wj-vrrp-x2fv/GHSA-67wj-vrrp-x2fv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67wj-vrrp-x2fv", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12198" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12198" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json b/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json new file mode 100644 index 00000000000..a38c8e3a673 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6ghv-cm9w-9m65/GHSA-6ghv-cm9w-9m65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ghv-cm9w-9m65", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12192" + ], + "details": "A maliciously crafted DWF file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12192" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json b/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json new file mode 100644 index 00000000000..1939c8faef4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6rh6-g778-wcww/GHSA-6rh6-g778-wcww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rh6-g778-wcww", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12670" + ], + "details": "A maliciously crafted DWF file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12670" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7m58-crjp-grq7/GHSA-7m58-crjp-grq7.json b/advisories/unreviewed/2024/12/GHSA-7m58-crjp-grq7/GHSA-7m58-crjp-grq7.json new file mode 100644 index 00000000000..97e23ae4461 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7m58-crjp-grq7/GHSA-7m58-crjp-grq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m58-crjp-grq7", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-49820" + ], + "details": "IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49820" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json b/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json new file mode 100644 index 00000000000..78dd772476b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7w93-5823-j96v/GHSA-7w93-5823-j96v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w93-5823-j96v", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-54662" + ], + "details": "Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54662" + }, + { + "type": "WEB", + "url": "https://www.inet.no/dante" + }, + { + "type": "WEB", + "url": "https://www.inet.no/dante/advisory-2024-12-16.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json b/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json new file mode 100644 index 00000000000..9366fbae2f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93c3-577v-mcj3", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-49819" + ], + "details": "IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49819" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-94mp-gc2x-rqm6/GHSA-94mp-gc2x-rqm6.json b/advisories/unreviewed/2024/12/GHSA-94mp-gc2x-rqm6/GHSA-94mp-gc2x-rqm6.json index b60c69adcd1..89b1718e502 100644 --- a/advisories/unreviewed/2024/12/GHSA-94mp-gc2x-rqm6/GHSA-94mp-gc2x-rqm6.json +++ b/advisories/unreviewed/2024/12/GHSA-94mp-gc2x-rqm6/GHSA-94mp-gc2x-rqm6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-94mp-gc2x-rqm6", - "modified": "2024-12-17T00:31:17Z", + "modified": "2024-12-17T18:33:47Z", "published": "2024-12-17T00:31:17Z", "aliases": [ "CVE-2024-52949" ], "details": "iptraf-ng 1.2.1 has a stack-based buffer overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T22:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9cg3-fgfh-g8ww/GHSA-9cg3-fgfh-g8ww.json b/advisories/unreviewed/2024/12/GHSA-9cg3-fgfh-g8ww/GHSA-9cg3-fgfh-g8ww.json index 90168a20ce3..b18d74a5e23 100644 --- a/advisories/unreviewed/2024/12/GHSA-9cg3-fgfh-g8ww/GHSA-9cg3-fgfh-g8ww.json +++ b/advisories/unreviewed/2024/12/GHSA-9cg3-fgfh-g8ww/GHSA-9cg3-fgfh-g8ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9cg3-fgfh-g8ww", - "modified": "2024-12-16T21:30:56Z", + "modified": "2024-12-17T18:33:46Z", "published": "2024-12-16T21:30:56Z", "aliases": [ "CVE-2024-55100" ], "details": "A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json b/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json new file mode 100644 index 00000000000..c47b6adf3c3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9w23-rv5f-3ch2/GHSA-9w23-rv5f-3ch2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w23-rv5f-3ch2", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12191" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12191" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cr9c-4pg9-32j3/GHSA-cr9c-4pg9-32j3.json b/advisories/unreviewed/2024/12/GHSA-cr9c-4pg9-32j3/GHSA-cr9c-4pg9-32j3.json new file mode 100644 index 00000000000..3a860a310d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cr9c-4pg9-32j3/GHSA-cr9c-4pg9-32j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr9c-4pg9-32j3", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-42194" + ], + "details": "An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42194" + }, + { + "type": "WEB", + "url": "https://https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json b/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json new file mode 100644 index 00000000000..74fbf03aa96 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvm4-cfc7-c54q", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-49816" + ], + "details": "IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49816" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f3g2-9hcq-jr47/GHSA-f3g2-9hcq-jr47.json b/advisories/unreviewed/2024/12/GHSA-f3g2-9hcq-jr47/GHSA-f3g2-9hcq-jr47.json index 169a2507be3..f6518b1533d 100644 --- a/advisories/unreviewed/2024/12/GHSA-f3g2-9hcq-jr47/GHSA-f3g2-9hcq-jr47.json +++ b/advisories/unreviewed/2024/12/GHSA-f3g2-9hcq-jr47/GHSA-f3g2-9hcq-jr47.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f3g2-9hcq-jr47", - "modified": "2024-12-17T00:31:18Z", + "modified": "2024-12-17T18:33:48Z", "published": "2024-12-17T00:31:18Z", "aliases": [ "CVE-2024-55451" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T23:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json b/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json new file mode 100644 index 00000000000..bdf797d319b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f5q3-r2wq-xch4/GHSA-f5q3-r2wq-xch4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5q3-r2wq-xch4", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12199" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12199" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json b/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json new file mode 100644 index 00000000000..53f5a11a4a5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fgg7-f8f3-3g3h/GHSA-fgg7-f8f3-3g3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgg7-f8f3-3g3h", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-11422" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11422" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fx48-mhc8-xx2j/GHSA-fx48-mhc8-xx2j.json b/advisories/unreviewed/2024/12/GHSA-fx48-mhc8-xx2j/GHSA-fx48-mhc8-xx2j.json index d7ef5f628aa..ef4d93afc7f 100644 --- a/advisories/unreviewed/2024/12/GHSA-fx48-mhc8-xx2j/GHSA-fx48-mhc8-xx2j.json +++ b/advisories/unreviewed/2024/12/GHSA-fx48-mhc8-xx2j/GHSA-fx48-mhc8-xx2j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fx48-mhc8-xx2j", - "modified": "2024-12-17T15:31:44Z", + "modified": "2024-12-17T18:33:49Z", "published": "2024-12-17T15:31:44Z", "aliases": [ "CVE-2024-37606" ], "details": "A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T15:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json b/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json new file mode 100644 index 00000000000..3721d8c2c1a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g79x-gv43-8472/GHSA-g79x-gv43-8472.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g79x-gv43-8472", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12179" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12179" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gf85-q5rv-vmw6/GHSA-gf85-q5rv-vmw6.json b/advisories/unreviewed/2024/12/GHSA-gf85-q5rv-vmw6/GHSA-gf85-q5rv-vmw6.json index 9b98bc93dc0..31809d14cae 100644 --- a/advisories/unreviewed/2024/12/GHSA-gf85-q5rv-vmw6/GHSA-gf85-q5rv-vmw6.json +++ b/advisories/unreviewed/2024/12/GHSA-gf85-q5rv-vmw6/GHSA-gf85-q5rv-vmw6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gf85-q5rv-vmw6", - "modified": "2024-12-17T15:31:43Z", + "modified": "2024-12-17T18:33:48Z", "published": "2024-12-17T15:31:43Z", "aliases": [ "CVE-2024-36831" ], "details": "A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T15:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json b/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json new file mode 100644 index 00000000000..4bc6434457e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gq79-6cpg-v72r/GHSA-gq79-6cpg-v72r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq79-6cpg-v72r", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12194" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12194" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hf47-p558-hhmv/GHSA-hf47-p558-hhmv.json b/advisories/unreviewed/2024/12/GHSA-hf47-p558-hhmv/GHSA-hf47-p558-hhmv.json index e1f4a365f78..97f04807f39 100644 --- a/advisories/unreviewed/2024/12/GHSA-hf47-p558-hhmv/GHSA-hf47-p558-hhmv.json +++ b/advisories/unreviewed/2024/12/GHSA-hf47-p558-hhmv/GHSA-hf47-p558-hhmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hf47-p558-hhmv", - "modified": "2024-12-17T00:31:18Z", + "modified": "2024-12-17T18:33:48Z", "published": "2024-12-17T00:31:18Z", "aliases": [ "CVE-2024-55554" ], "details": "Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T22:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hjq7-734v-xhcw/GHSA-hjq7-734v-xhcw.json b/advisories/unreviewed/2024/12/GHSA-hjq7-734v-xhcw/GHSA-hjq7-734v-xhcw.json new file mode 100644 index 00000000000..0f3c1076074 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hjq7-734v-xhcw/GHSA-hjq7-734v-xhcw.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjq7-734v-xhcw", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-53144" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE\n\nThis aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4\n(\"Bluetooth: Always request for user confirmation for Just Works\")\nalways request user confirmation with confirm_hint set since the\nlikes of bluetoothd have dedicated policy around JUST_WORKS method\n(e.g. main.conf:JustWorksRepairing).\n\nCVE: CVE-2024-8805", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53144" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5291ff856d2c5177b4fe9c18828312be30213193" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/830c03e58beb70b99349760f822e505ecb4eeb7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad7adfb95f64a761e4784381e47bee1a362eb30d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b25e11f978b63cb7857890edb3a698599cddb10e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d17c631ba04e960eb6f8728b10d585de20ac4f71" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json b/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json new file mode 100644 index 00000000000..7d5adf69462 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hmwf-p83m-gr4q/GHSA-hmwf-p83m-gr4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmwf-p83m-gr4q", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12669" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12669" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json b/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json new file mode 100644 index 00000000000..a8e298cc580 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jgvv-pcgx-gv2f/GHSA-jgvv-pcgx-gv2f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgvv-pcgx-gv2f", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12200" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12200" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mm54-vj99-7qc8/GHSA-mm54-vj99-7qc8.json b/advisories/unreviewed/2024/12/GHSA-mm54-vj99-7qc8/GHSA-mm54-vj99-7qc8.json index fbce5e1e44f..b6dc3781d2e 100644 --- a/advisories/unreviewed/2024/12/GHSA-mm54-vj99-7qc8/GHSA-mm54-vj99-7qc8.json +++ b/advisories/unreviewed/2024/12/GHSA-mm54-vj99-7qc8/GHSA-mm54-vj99-7qc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mm54-vj99-7qc8", - "modified": "2024-12-16T21:30:57Z", + "modified": "2024-12-17T18:33:47Z", "published": "2024-12-16T21:30:56Z", "aliases": [ "CVE-2024-55103" ], "details": "Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T21:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json b/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json new file mode 100644 index 00000000000..9b356d5316b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mmp3-h84f-cq76/GHSA-mmp3-h84f-cq76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmp3-h84f-cq76", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12671" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12671" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json b/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json new file mode 100644 index 00000000000..e29dc403e4a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p92v-v2pv-248f/GHSA-p92v-v2pv-248f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p92v-v2pv-248f", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12178" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12178" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p986-vg8j-hhh7/GHSA-p986-vg8j-hhh7.json b/advisories/unreviewed/2024/12/GHSA-p986-vg8j-hhh7/GHSA-p986-vg8j-hhh7.json new file mode 100644 index 00000000000..e4d54c31668 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p986-vg8j-hhh7/GHSA-p986-vg8j-hhh7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p986-vg8j-hhh7", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-49817" + ], + "details": "IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49817" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-260" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json b/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json new file mode 100644 index 00000000000..b41bcd59461 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pjwc-96x8-qh73/GHSA-pjwc-96x8-qh73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjwc-96x8-qh73", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12197" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12197" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json b/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json new file mode 100644 index 00000000000..818f8d751e8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qgwv-xwcw-8vxj/GHSA-qgwv-xwcw-8vxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgwv-xwcw-8vxj", + "modified": "2024-12-17T18:33:49Z", + "published": "2024-12-17T18:33:49Z", + "aliases": [ + "CVE-2024-12193" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12193" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rmhp-cwvx-258p/GHSA-rmhp-cwvx-258p.json b/advisories/unreviewed/2024/12/GHSA-rmhp-cwvx-258p/GHSA-rmhp-cwvx-258p.json index e3fb8e15020..5e723a9f01c 100644 --- a/advisories/unreviewed/2024/12/GHSA-rmhp-cwvx-258p/GHSA-rmhp-cwvx-258p.json +++ b/advisories/unreviewed/2024/12/GHSA-rmhp-cwvx-258p/GHSA-rmhp-cwvx-258p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rmhp-cwvx-258p", - "modified": "2024-12-17T15:31:44Z", + "modified": "2024-12-17T18:33:49Z", "published": "2024-12-17T15:31:44Z", "aliases": [ "CVE-2024-37607" ], "details": "A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T15:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v8wv-77r8-pv46/GHSA-v8wv-77r8-pv46.json b/advisories/unreviewed/2024/12/GHSA-v8wv-77r8-pv46/GHSA-v8wv-77r8-pv46.json new file mode 100644 index 00000000000..762d5908d6e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v8wv-77r8-pv46/GHSA-v8wv-77r8-pv46.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8wv-77r8-pv46", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-55496" + ], + "details": "A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55496" + }, + { + "type": "WEB", + "url": "https://github.com/wpc1122/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org/bookstore-management-system-php-mysql-project.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vhwq-33mx-jmx5/GHSA-vhwq-33mx-jmx5.json b/advisories/unreviewed/2024/12/GHSA-vhwq-33mx-jmx5/GHSA-vhwq-33mx-jmx5.json index 635178e95a9..fb278be3806 100644 --- a/advisories/unreviewed/2024/12/GHSA-vhwq-33mx-jmx5/GHSA-vhwq-33mx-jmx5.json +++ b/advisories/unreviewed/2024/12/GHSA-vhwq-33mx-jmx5/GHSA-vhwq-33mx-jmx5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhwq-33mx-jmx5", - "modified": "2024-12-17T00:31:17Z", + "modified": "2024-12-17T18:33:47Z", "published": "2024-12-17T00:31:17Z", "aliases": [ "CVE-2024-37773" ], "details": "An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T22:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w863-c2hv-xjc5/GHSA-w863-c2hv-xjc5.json b/advisories/unreviewed/2024/12/GHSA-w863-c2hv-xjc5/GHSA-w863-c2hv-xjc5.json index 4612dd515b0..a02f051d3a4 100644 --- a/advisories/unreviewed/2024/12/GHSA-w863-c2hv-xjc5/GHSA-w863-c2hv-xjc5.json +++ b/advisories/unreviewed/2024/12/GHSA-w863-c2hv-xjc5/GHSA-w863-c2hv-xjc5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w863-c2hv-xjc5", - "modified": "2024-12-17T15:31:44Z", + "modified": "2024-12-17T18:33:48Z", "published": "2024-12-17T15:31:43Z", "aliases": [ "CVE-2024-37605" ], "details": "A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-17T15:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xhw8-46vj-3gq5/GHSA-xhw8-46vj-3gq5.json b/advisories/unreviewed/2024/12/GHSA-xhw8-46vj-3gq5/GHSA-xhw8-46vj-3gq5.json new file mode 100644 index 00000000000..621c43d2761 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xhw8-46vj-3gq5/GHSA-xhw8-46vj-3gq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhw8-46vj-3gq5", + "modified": "2024-12-17T18:33:50Z", + "published": "2024-12-17T18:33:50Z", + "aliases": [ + "CVE-2024-49818" + ], + "details": "IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 \n\ncould allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49818" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-17T18:15:24Z" + } +} \ No newline at end of file