From 9071fc3e0e8b39cdc67fa3812c9fff7bc6c27718 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 30 Jan 2024 15:31:46 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-j5jm-hg4x-w8rx.json | 4 ++ .../GHSA-33f3-88p6-j3f9.json | 35 ++++++++++++ .../GHSA-3gqv-8h4q-fff4.json | 3 +- .../GHSA-3qmj-w5mh-5gv3.json | 35 ++++++++++++ .../GHSA-4mwf-4888-4x35.json | 8 +++ .../GHSA-4q7q-5p3p-5fcj.json | 35 ++++++++++++ .../GHSA-4q9c-68c7-fxff.json | 35 ++++++++++++ .../GHSA-54p6-86fq-2pg8.json | 38 +++++++++++++ .../GHSA-597m-g6ch-mrf9.json | 38 +++++++++++++ .../GHSA-5m9g-m2vj-47r4.json | 54 +++++++++++++++++++ .../GHSA-5mh9-hrrq-46qr.json | 46 ++++++++++++++++ .../GHSA-7j85-cwr3-f2w3.json | 35 ++++++++++++ .../GHSA-93px-8x98-j7p2.json | 11 ++-- .../GHSA-9mw7-8x3h-gcqc.json | 11 ++-- .../GHSA-c6mw-5fmv-25qx.json | 11 ++-- .../GHSA-c978-j9mm-m34q.json | 11 ++-- .../GHSA-f63q-6c68-mrcx.json | 9 ++-- .../GHSA-ff22-5jp8-224r.json | 8 +++ .../GHSA-fgx5-x337-5fv2.json | 46 ++++++++++++++++ .../GHSA-g2f8-pfg4-3w3q.json | 35 ++++++++++++ .../GHSA-h56c-gcxc-4q77.json | 35 ++++++++++++ .../GHSA-jm98-mxmf-qcjw.json | 35 ++++++++++++ .../GHSA-mfm9-9c5w-7f5g.json | 11 ++-- .../GHSA-mr4x-vwjp-hm5f.json | 46 ++++++++++++++++ .../GHSA-p52c-9f7h-pxpj.json | 11 ++-- .../GHSA-r9gf-434r-vm83.json | 35 ++++++++++++ .../GHSA-v23q-xxwx-66fg.json | 46 ++++++++++++++++ .../GHSA-v4r8-6m3f-gvv4.json | 10 +++- .../GHSA-w5f8-jmcg-4qrj.json | 35 ++++++++++++ .../GHSA-w85m-xv37-g9v4.json | 9 ++-- .../GHSA-wfhp-x3v9-6957.json | 38 +++++++++++++ .../GHSA-wph3-4v72-8x34.json | 11 ++-- .../GHSA-x77j-46hj-595v.json | 9 ++-- 33 files changed, 800 insertions(+), 39 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json create mode 100644 advisories/unreviewed/2024/01/GHSA-54p6-86fq-2pg8/GHSA-54p6-86fq-2pg8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-597m-g6ch-mrf9/GHSA-597m-g6ch-mrf9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5mh9-hrrq-46qr/GHSA-5mh9-hrrq-46qr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fgx5-x337-5fv2/GHSA-fgx5-x337-5fv2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-mr4x-vwjp-hm5f/GHSA-mr4x-vwjp-hm5f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v23q-xxwx-66fg/GHSA-v23q-xxwx-66fg.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wfhp-x3v9-6957/GHSA-wfhp-x3v9-6957.json diff --git a/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json b/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json index 2279296a348..b5fa2b1c9dd 100644 --- a/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json +++ b/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://github.com/eeenvik1/CVE-2023-51764" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00020.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JQ5WXFCW2N6G2PH3JXDTYW5PH5EBQEGO/" diff --git a/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json b/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json new file mode 100644 index 00000000000..04e1b0031f9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-33f3-88p6-j3f9/GHSA-33f3-88p6-j3f9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33f3-88p6-j3f9", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-24324" + ], + "details": "TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24324" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A8000RU/TOTOlink%20A8000RU%20hard%20code.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3gqv-8h4q-fff4/GHSA-3gqv-8h4q-fff4.json b/advisories/unreviewed/2024/01/GHSA-3gqv-8h4q-fff4/GHSA-3gqv-8h4q-fff4.json index 5c82c6426a4..be2bdd2e7c1 100644 --- a/advisories/unreviewed/2024/01/GHSA-3gqv-8h4q-fff4/GHSA-3gqv-8h4q-fff4.json +++ b/advisories/unreviewed/2024/01/GHSA-3gqv-8h4q-fff4/GHSA-3gqv-8h4q-fff4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-277" + "CWE-277", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json b/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json new file mode 100644 index 00000000000..c3409f72024 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3qmj-w5mh-5gv3/GHSA-3qmj-w5mh-5gv3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qmj-w5mh-5gv3", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24329" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24329" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/10/TOTOlink%20A3300R%20setPortForwardRules.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json b/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json index 9a2cf544643..c1d49493131 100644 --- a/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json +++ b/advisories/unreviewed/2024/01/GHSA-4mwf-4888-4x35/GHSA-4mwf-4888-4x35.json @@ -36,6 +36,14 @@ { "type": "WEB", "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1031" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json b/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json new file mode 100644 index 00000000000..720adaf82ed --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4q7q-5p3p-5fcj/GHSA-4q7q-5p3p-5fcj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q7q-5p3p-5fcj", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24328" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24328" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/12/TOTOlink%20A3300R%20setMacFilterRules.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json b/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json new file mode 100644 index 00000000000..9dc8444be43 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4q9c-68c7-fxff/GHSA-4q9c-68c7-fxff.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q9c-68c7-fxff", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24327" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24327" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/7/TOTOlink%20A3300R%20setIpv6Cfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-54p6-86fq-2pg8/GHSA-54p6-86fq-2pg8.json b/advisories/unreviewed/2024/01/GHSA-54p6-86fq-2pg8/GHSA-54p6-86fq-2pg8.json new file mode 100644 index 00000000000..19f8bf7bd5b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-54p6-86fq-2pg8/GHSA-54p6-86fq-2pg8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54p6-86fq-2pg8", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-0674" + ], + "details": "Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause the watchdog process to run as root and execute the payload stored in the updatescript.js.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0674" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-lamassu-bitcoin-atm-douro-machines" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-597m-g6ch-mrf9/GHSA-597m-g6ch-mrf9.json b/advisories/unreviewed/2024/01/GHSA-597m-g6ch-mrf9/GHSA-597m-g6ch-mrf9.json new file mode 100644 index 00000000000..c63120cac66 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-597m-g6ch-mrf9/GHSA-597m-g6ch-mrf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-597m-g6ch-mrf9", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-0676" + ], + "details": "Weak password requirement vulnerability \n\nin Lamassu Bitcoin ATM Douro machines, in its 7.1 version\n\n, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0676" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-lamassu-bitcoin-atm-douro-machines" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json b/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json new file mode 100644 index 00000000000..f7087391f86 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5m9g-m2vj-47r4/GHSA-5m9g-m2vj-47r4.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m9g-m2vj-47r4", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-0564" + ], + "details": "A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is \"max page sharing=256\", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's \"max page share\". Through these operations, the attacker can leak the victim's page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0564" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0564" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1680513" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258514" + }, + { + "type": "WEB", + "url": "https://link.springer.com/conference/wisa" + }, + { + "type": "WEB", + "url": "https://wisa.or.kr/accepted" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5mh9-hrrq-46qr/GHSA-5mh9-hrrq-46qr.json b/advisories/unreviewed/2024/01/GHSA-5mh9-hrrq-46qr/GHSA-5mh9-hrrq-46qr.json new file mode 100644 index 00000000000..525427be673 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5mh9-hrrq-46qr/GHSA-5mh9-hrrq-46qr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mh9-hrrq-46qr", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-1032" + ], + "details": "A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of the component Test Connection Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252307.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1032" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/6ISYe2urjlkI" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252307" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json b/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json new file mode 100644 index 00000000000..3e0648dbad1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7j85-cwr3-f2w3/GHSA-7j85-cwr3-f2w3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j85-cwr3-f2w3", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24332" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24332" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/9/TOTOlink%20A3300R%20setUrlFilterRules.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json index 5988636f9dd..7c9f5c929a2 100644 --- a/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json +++ b/advisories/unreviewed/2024/01/GHSA-93px-8x98-j7p2/GHSA-93px-8x98-j7p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93px-8x98-j7p2", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T15:30:22Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23222" ], "details": "A type confusion issue was addressed with improved checks. This issue is fixed in tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -77,9 +80,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9mw7-8x3h-gcqc/GHSA-9mw7-8x3h-gcqc.json b/advisories/unreviewed/2024/01/GHSA-9mw7-8x3h-gcqc/GHSA-9mw7-8x3h-gcqc.json index 61c807e1bec..803d3936b32 100644 --- a/advisories/unreviewed/2024/01/GHSA-9mw7-8x3h-gcqc/GHSA-9mw7-8x3h-gcqc.json +++ b/advisories/unreviewed/2024/01/GHSA-9mw7-8x3h-gcqc/GHSA-9mw7-8x3h-gcqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mw7-8x3h-gcqc", - "modified": "2024-01-16T18:31:09Z", + "modified": "2024-01-30T15:30:20Z", "published": "2024-01-16T18:31:09Z", "aliases": [ "CVE-2023-3771" ], "details": "The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T16:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json b/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json index e58851fcd5d..18a096f6a44 100644 --- a/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json +++ b/advisories/unreviewed/2024/01/GHSA-c6mw-5fmv-25qx/GHSA-c6mw-5fmv-25qx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6mw-5fmv-25qx", - "modified": "2024-01-23T03:31:08Z", + "modified": "2024-01-30T15:30:21Z", "published": "2024-01-23T03:31:08Z", "aliases": [ "CVE-2024-23219" ], "details": "The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T01:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c978-j9mm-m34q/GHSA-c978-j9mm-m34q.json b/advisories/unreviewed/2024/01/GHSA-c978-j9mm-m34q/GHSA-c978-j9mm-m34q.json index 46f83a13607..ea7437bc85f 100644 --- a/advisories/unreviewed/2024/01/GHSA-c978-j9mm-m34q/GHSA-c978-j9mm-m34q.json +++ b/advisories/unreviewed/2024/01/GHSA-c978-j9mm-m34q/GHSA-c978-j9mm-m34q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c978-j9mm-m34q", - "modified": "2024-01-16T21:31:21Z", + "modified": "2024-01-30T15:30:20Z", "published": "2024-01-16T21:31:21Z", "aliases": [ "CVE-2023-49351" ], "details": "A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-f63q-6c68-mrcx/GHSA-f63q-6c68-mrcx.json b/advisories/unreviewed/2024/01/GHSA-f63q-6c68-mrcx/GHSA-f63q-6c68-mrcx.json index f417a5fe7e6..30f34b83412 100644 --- a/advisories/unreviewed/2024/01/GHSA-f63q-6c68-mrcx/GHSA-f63q-6c68-mrcx.json +++ b/advisories/unreviewed/2024/01/GHSA-f63q-6c68-mrcx/GHSA-f63q-6c68-mrcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f63q-6c68-mrcx", - "modified": "2024-01-16T18:31:11Z", + "modified": "2024-01-30T15:30:20Z", "published": "2024-01-16T18:31:11Z", "aliases": [ "CVE-2024-23347" ], "details": "Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T18:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json index 1de61f25eac..a8133ac3a67 100644 --- a/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json +++ b/advisories/unreviewed/2024/01/GHSA-ff22-5jp8-224r/GHSA-ff22-5jp8-224r.json @@ -56,6 +56,14 @@ { "type": "WEB", "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1035" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/30/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fgx5-x337-5fv2/GHSA-fgx5-x337-5fv2.json b/advisories/unreviewed/2024/01/GHSA-fgx5-x337-5fv2/GHSA-fgx5-x337-5fv2.json new file mode 100644 index 00000000000..f9558a7920d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fgx5-x337-5fv2/GHSA-fgx5-x337-5fv2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgx5-x337-5fv2", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-1034" + ], + "details": "A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252309 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1034" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/ABYkFE4wRPW5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252309" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252309" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json b/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json new file mode 100644 index 00000000000..f5b64ad371f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g2f8-pfg4-3w3q/GHSA-g2f8-pfg4-3w3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2f8-pfg4-3w3q", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24331" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24331" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/13/TOTOlink%20A3300R%20setWiFiScheduleCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json b/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json new file mode 100644 index 00000000000..4011b1943d0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h56c-gcxc-4q77/GHSA-h56c-gcxc-4q77.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h56c-gcxc-4q77", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24333" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24333" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/15/TOTOlink%20A3300R%20setWiFiAclRules.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json b/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json new file mode 100644 index 00000000000..8c923343c23 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jm98-mxmf-qcjw/GHSA-jm98-mxmf-qcjw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm98-mxmf-qcjw", + "modified": "2024-01-30T15:30:23Z", + "published": "2024-01-30T15:30:23Z", + "aliases": [ + "CVE-2024-24330" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24330" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/14/TOTOlink%20A3300R%20setRemoteCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mfm9-9c5w-7f5g/GHSA-mfm9-9c5w-7f5g.json b/advisories/unreviewed/2024/01/GHSA-mfm9-9c5w-7f5g/GHSA-mfm9-9c5w-7f5g.json index 4a251e5c41e..76ab25491b6 100644 --- a/advisories/unreviewed/2024/01/GHSA-mfm9-9c5w-7f5g/GHSA-mfm9-9c5w-7f5g.json +++ b/advisories/unreviewed/2024/01/GHSA-mfm9-9c5w-7f5g/GHSA-mfm9-9c5w-7f5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfm9-9c5w-7f5g", - "modified": "2024-01-23T00:30:31Z", + "modified": "2024-01-30T15:30:21Z", "published": "2024-01-23T00:30:31Z", "aliases": [ "CVE-2021-42141" ], "details": "An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T23:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mr4x-vwjp-hm5f/GHSA-mr4x-vwjp-hm5f.json b/advisories/unreviewed/2024/01/GHSA-mr4x-vwjp-hm5f/GHSA-mr4x-vwjp-hm5f.json new file mode 100644 index 00000000000..6831b4fae6f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mr4x-vwjp-hm5f/GHSA-mr4x-vwjp-hm5f.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr4x-vwjp-hm5f", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-1031" + ], + "details": "A vulnerability was found in CodeAstro Expense Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file templates/5-Add-Expenses.php of the component Add Expenses Page. The manipulation of the argument item leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252304.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1031" + }, + { + "type": "WEB", + "url": "https://docs.qq.com/doc/DYmhqV3piekZ5dlZi" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252304" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252304" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p52c-9f7h-pxpj/GHSA-p52c-9f7h-pxpj.json b/advisories/unreviewed/2024/01/GHSA-p52c-9f7h-pxpj/GHSA-p52c-9f7h-pxpj.json index 7c459be0820..5fe407a32cb 100644 --- a/advisories/unreviewed/2024/01/GHSA-p52c-9f7h-pxpj/GHSA-p52c-9f7h-pxpj.json +++ b/advisories/unreviewed/2024/01/GHSA-p52c-9f7h-pxpj/GHSA-p52c-9f7h-pxpj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p52c-9f7h-pxpj", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-01-30T15:30:21Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2024-0606" ], "details": "An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T19:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json b/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json new file mode 100644 index 00000000000..9c4b3dd4c5f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r9gf-434r-vm83/GHSA-r9gf-434r-vm83.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9gf-434r-vm83", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-24326" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24326" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/8/TOTOlink%20A3300R%20setStaticDhcpRules.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v23q-xxwx-66fg/GHSA-v23q-xxwx-66fg.json b/advisories/unreviewed/2024/01/GHSA-v23q-xxwx-66fg/GHSA-v23q-xxwx-66fg.json new file mode 100644 index 00000000000..165021236b9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v23q-xxwx-66fg/GHSA-v23q-xxwx-66fg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v23q-xxwx-66fg", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-1033" + ], + "details": "A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is the function agent of the file /application/index/controller/Datament.php. The manipulation of the argument api leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252308.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1033" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/nD654ot6zRQZ" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252308" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json b/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json index 85eae2d046d..ac68dc16587 100644 --- a/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json +++ b/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4r8-6m3f-gvv4", - "modified": "2024-01-10T18:30:24Z", + "modified": "2024-01-30T15:30:20Z", "published": "2024-01-03T09:30:33Z", "aliases": [ "CVE-2023-6747" @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://fooplugins.com/foogallery-wordpress-gallery-plugin/pricing/" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/foogallery/tags/2.4.9/includes/class-gallery-advanced-settings.php?rev=3027668#L149" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/foogallery/tags/2.4.9/includes/functions.php#L1609" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dce8ac32-cab8-4e05-bf6f-cc348d0c9472?source=cve" diff --git a/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json b/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json new file mode 100644 index 00000000000..9387dc5f314 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w5f8-jmcg-4qrj/GHSA-w5f8-jmcg-4qrj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5f8-jmcg-4qrj", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-24325" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24325" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/11/TOTOlink%20A3300R%20setParentalRules.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w85m-xv37-g9v4/GHSA-w85m-xv37-g9v4.json b/advisories/unreviewed/2024/01/GHSA-w85m-xv37-g9v4/GHSA-w85m-xv37-g9v4.json index b44f668daa4..ce87a07cc43 100644 --- a/advisories/unreviewed/2024/01/GHSA-w85m-xv37-g9v4/GHSA-w85m-xv37-g9v4.json +++ b/advisories/unreviewed/2024/01/GHSA-w85m-xv37-g9v4/GHSA-w85m-xv37-g9v4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w85m-xv37-g9v4", - "modified": "2024-01-19T21:30:35Z", + "modified": "2024-01-30T15:30:21Z", "published": "2024-01-19T21:30:35Z", "aliases": [ "CVE-2023-47035" ], "details": "RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-19T20:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-wfhp-x3v9-6957/GHSA-wfhp-x3v9-6957.json b/advisories/unreviewed/2024/01/GHSA-wfhp-x3v9-6957/GHSA-wfhp-x3v9-6957.json new file mode 100644 index 00000000000..dfba661921b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wfhp-x3v9-6957/GHSA-wfhp-x3v9-6957.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfhp-x3v9-6957", + "modified": "2024-01-30T15:30:22Z", + "published": "2024-01-30T15:30:22Z", + "aliases": [ + "CVE-2024-0675" + ], + "details": "Vulnerability of improper checking for unusual or exceptional conditions\n\nin Lamassu Bitcoin ATM Douro machines, in its 7.1 version,\n\n the exploitation of which could allow an attacker with physical access to the ATM to escape kiosk mode, access the underlying Xwindow interface and execute arbitrary commands as an unprivileged user.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0675" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-lamassu-bitcoin-atm-douro-machines" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-30T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wph3-4v72-8x34/GHSA-wph3-4v72-8x34.json b/advisories/unreviewed/2024/01/GHSA-wph3-4v72-8x34/GHSA-wph3-4v72-8x34.json index 6281b71b712..bff846dd119 100644 --- a/advisories/unreviewed/2024/01/GHSA-wph3-4v72-8x34/GHSA-wph3-4v72-8x34.json +++ b/advisories/unreviewed/2024/01/GHSA-wph3-4v72-8x34/GHSA-wph3-4v72-8x34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wph3-4v72-8x34", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-01-30T15:30:21Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2024-0605" ], "details": "Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T19:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-x77j-46hj-595v/GHSA-x77j-46hj-595v.json b/advisories/unreviewed/2024/01/GHSA-x77j-46hj-595v/GHSA-x77j-46hj-595v.json index 1fdf8077d2c..ddc7e04ae93 100644 --- a/advisories/unreviewed/2024/01/GHSA-x77j-46hj-595v/GHSA-x77j-46hj-595v.json +++ b/advisories/unreviewed/2024/01/GHSA-x77j-46hj-595v/GHSA-x77j-46hj-595v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x77j-46hj-595v", - "modified": "2024-01-19T21:30:35Z", + "modified": "2024-01-30T15:30:21Z", "published": "2024-01-19T21:30:35Z", "aliases": [ "CVE-2023-33295" ], "details": "Cohesity DataProtect 6.8.1 and 6.6.0d was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-19T20:15:10Z"