From 90dd1ea8276d6d0b73e0c8cd0d4bbbb842fb3245 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 16 Aug 2024 18:32:04 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-34mq-x3p9-rvrm.json | 11 ++-- .../GHSA-fpg4-3688-q56c.json | 11 ++-- .../GHSA-g22p-98cv-w94f.json | 11 ++-- .../GHSA-hj8r-465g-5vm4.json | 11 ++-- .../GHSA-mv62-4r83-58qq.json | 11 ++-- .../GHSA-8f8j-wj6q-42wj.json | 11 ++-- .../GHSA-9667-g4xx-wm5w.json | 11 ++-- .../GHSA-gvvj-6354-3j8f.json | 11 ++-- .../GHSA-hjh7-5257-gpj4.json | 11 ++-- .../GHSA-jqhq-7m2m-3xjx.json | 11 ++-- .../GHSA-mhv9-5hxr-j9mw.json | 11 ++-- .../GHSA-rr8j-4qpf-75m2.json | 11 ++-- .../GHSA-vqw3-3gm8-35vm.json | 11 ++-- .../GHSA-w7qj-9r4p-2jh6.json | 11 ++-- .../GHSA-xf53-c458-r6pv.json | 11 ++-- .../GHSA-872f-jfmv-qjp2.json | 11 ++-- .../GHSA-8qpg-h99j-c4j3.json | 11 ++-- .../GHSA-9jm5-85j2-p9f4.json | 11 ++-- .../GHSA-fm24-99vc-2vfh.json | 11 ++-- .../GHSA-j2v6-5mgp-w77v.json | 11 ++-- .../GHSA-rhvv-h8rg-3gxq.json | 2 +- .../GHSA-c6v9-vw5h-vqrm.json | 11 ++-- .../GHSA-qgm6-rxj7-629q.json | 11 ++-- .../GHSA-cc4h-7j78-49pj.json | 6 ++- .../GHSA-ff8c-r6cp-6m85.json | 6 ++- .../GHSA-hh2w-28r4-mpw7.json | 3 +- .../GHSA-p6jh-36mx-hrg4.json | 11 ++-- .../GHSA-g9rf-qc6j-h2f7.json | 9 ++-- .../GHSA-xq4f-9xp4-279p.json | 9 ++-- .../GHSA-35gp-5q9f-g9pq.json | 9 ++-- .../GHSA-3p9r-c4f8-vv7m.json | 1 + .../GHSA-423g-mrq6-vpvp.json | 11 ++-- .../GHSA-4hmr-hm34-jj9g.json | 35 +++++++++++++ .../GHSA-5236-gxxf-m73h.json | 9 ++-- .../GHSA-598c-cc55-mwv5.json | 11 ++-- .../GHSA-5m24-c4vx-fjj8.json | 3 +- .../GHSA-65q8-wrmh-rrcm.json | 39 +++++++++++++++ .../GHSA-67q8-hw3v-9fj4.json | 11 ++-- .../GHSA-84mw-hccv-m82r.json | 3 +- .../GHSA-9q7g-3c57-wvv7.json | 3 +- .../GHSA-c4j6-mvfp-j4wx.json | 47 +++++++++++++++++ .../GHSA-c75r-v5wg-3gmj.json | 1 + .../GHSA-cprr-85rg-mjvr.json | 1 + .../GHSA-f5hg-xwhp-3gj9.json | 39 +++++++++++++++ .../GHSA-j828-57c8-xr27.json | 3 +- .../GHSA-m6q3-mcjx-5646.json | 1 + .../GHSA-mcrq-g49g-vf4v.json | 3 +- .../GHSA-mj96-jcmr-6947.json | 35 +++++++++++++ .../GHSA-p7f3-v9j2-h27r.json | 39 +++++++++++++++ .../GHSA-prxw-7955-hmfm.json | 11 ++-- .../GHSA-qx8j-xj5q-v7r3.json | 50 +++++++++++++++++++ .../GHSA-rg28-x6g7-wxr5.json | 9 ++-- .../GHSA-v4x2-xrc6-7q7j.json | 3 +- .../GHSA-v574-8m96-8mp9.json | 11 ++-- .../GHSA-vf2f-4qh9-fpch.json | 35 +++++++++++++ .../GHSA-vv44-rh9q-4cc8.json | 3 +- .../GHSA-wcrf-58c6-27cg.json | 39 +++++++++++++++ .../GHSA-wp6j-mqr7-v2hf.json | 3 +- .../GHSA-wq55-fhp8-6jh8.json | 3 +- .../GHSA-xg38-j8ww-g8hg.json | 3 +- .../GHSA-xh57-2h8m-3798.json | 3 +- .../GHSA-xx83-6gm8-xx8p.json | 11 ++-- 62 files changed, 630 insertions(+), 146 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c4j6-mvfp-j4wx/GHSA-c4j6-mvfp-j4wx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p7f3-v9j2-h27r/GHSA-p7f3-v9j2-h27r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qx8j-xj5q-v7r3/GHSA-qx8j-xj5q-v7r3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json diff --git a/advisories/unreviewed/2024/02/GHSA-34mq-x3p9-rvrm/GHSA-34mq-x3p9-rvrm.json b/advisories/unreviewed/2024/02/GHSA-34mq-x3p9-rvrm/GHSA-34mq-x3p9-rvrm.json index 8dd37d975ab..b29b5670a7e 100644 --- a/advisories/unreviewed/2024/02/GHSA-34mq-x3p9-rvrm/GHSA-34mq-x3p9-rvrm.json +++ b/advisories/unreviewed/2024/02/GHSA-34mq-x3p9-rvrm/GHSA-34mq-x3p9-rvrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34mq-x3p9-rvrm", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-08-16T18:30:55Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40109" ], "details": "In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-fpg4-3688-q56c/GHSA-fpg4-3688-q56c.json b/advisories/unreviewed/2024/02/GHSA-fpg4-3688-q56c/GHSA-fpg4-3688-q56c.json index 804656eaec5..85089f5724b 100644 --- a/advisories/unreviewed/2024/02/GHSA-fpg4-3688-q56c/GHSA-fpg4-3688-q56c.json +++ b/advisories/unreviewed/2024/02/GHSA-fpg4-3688-q56c/GHSA-fpg4-3688-q56c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpg4-3688-q56c", - "modified": "2024-02-27T03:31:01Z", + "modified": "2024-08-16T18:30:55Z", "published": "2024-02-27T03:31:01Z", "aliases": [ "CVE-2024-22543" ], "details": "An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T01:15:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-g22p-98cv-w94f/GHSA-g22p-98cv-w94f.json b/advisories/unreviewed/2024/02/GHSA-g22p-98cv-w94f/GHSA-g22p-98cv-w94f.json index f5eb541cc4a..def639d861a 100644 --- a/advisories/unreviewed/2024/02/GHSA-g22p-98cv-w94f/GHSA-g22p-98cv-w94f.json +++ b/advisories/unreviewed/2024/02/GHSA-g22p-98cv-w94f/GHSA-g22p-98cv-w94f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g22p-98cv-w94f", - "modified": "2024-02-29T03:33:18Z", + "modified": "2024-08-16T18:30:55Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2023-51800" ], "details": "Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email parameters, new_term function in the tname parameter, and the edit_student function in the name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T02:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json b/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json index f24c852be4f..7659b7b8204 100644 --- a/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json +++ b/advisories/unreviewed/2024/02/GHSA-hj8r-465g-5vm4/GHSA-hj8r-465g-5vm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hj8r-465g-5vm4", - "modified": "2024-04-03T21:31:41Z", + "modified": "2024-08-16T18:30:55Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-25410" ], "details": "flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:27:58Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json b/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json index 553f56bf376..b170757f51d 100644 --- a/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json +++ b/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mv62-4r83-58qq", - "modified": "2024-02-21T18:31:02Z", + "modified": "2024-08-16T18:30:55Z", "published": "2024-02-21T18:31:02Z", "aliases": [ "CVE-2024-25288" ], "details": "SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T17:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json b/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json index 59f60757744..5533ef0a9f0 100644 --- a/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json +++ b/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8f8j-wj6q-42wj", - "modified": "2024-03-04T15:31:07Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-04T15:31:07Z", "aliases": [ "CVE-2024-27684" ], "details": "A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T14:15:41Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9667-g4xx-wm5w/GHSA-9667-g4xx-wm5w.json b/advisories/unreviewed/2024/03/GHSA-9667-g4xx-wm5w/GHSA-9667-g4xx-wm5w.json index d173a99cfd8..86aeee5ef52 100644 --- a/advisories/unreviewed/2024/03/GHSA-9667-g4xx-wm5w/GHSA-9667-g4xx-wm5w.json +++ b/advisories/unreviewed/2024/03/GHSA-9667-g4xx-wm5w/GHSA-9667-g4xx-wm5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9667-g4xx-wm5w", - "modified": "2024-03-07T03:30:41Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-07T03:30:41Z", "aliases": [ "CVE-2022-46089" ], "details": "Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T02:15:51Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gvvj-6354-3j8f/GHSA-gvvj-6354-3j8f.json b/advisories/unreviewed/2024/03/GHSA-gvvj-6354-3j8f/GHSA-gvvj-6354-3j8f.json index f49bd1ea420..a26e1cf6993 100644 --- a/advisories/unreviewed/2024/03/GHSA-gvvj-6354-3j8f/GHSA-gvvj-6354-3j8f.json +++ b/advisories/unreviewed/2024/03/GHSA-gvvj-6354-3j8f/GHSA-gvvj-6354-3j8f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvvj-6354-3j8f", - "modified": "2024-03-14T15:34:06Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-14T15:34:06Z", "aliases": [ "CVE-2024-28418" ], "details": "Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T13:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hjh7-5257-gpj4/GHSA-hjh7-5257-gpj4.json b/advisories/unreviewed/2024/03/GHSA-hjh7-5257-gpj4/GHSA-hjh7-5257-gpj4.json index be94455a4d9..90967ef68c0 100644 --- a/advisories/unreviewed/2024/03/GHSA-hjh7-5257-gpj4/GHSA-hjh7-5257-gpj4.json +++ b/advisories/unreviewed/2024/03/GHSA-hjh7-5257-gpj4/GHSA-hjh7-5257-gpj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjh7-5257-gpj4", - "modified": "2024-03-12T21:30:59Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-12T21:30:59Z", "aliases": [ "CVE-2023-43292" ], "details": "Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via a crafted payload to the Recipe Name, Procedure, and ingredients parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T21:15:55Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jqhq-7m2m-3xjx/GHSA-jqhq-7m2m-3xjx.json b/advisories/unreviewed/2024/03/GHSA-jqhq-7m2m-3xjx/GHSA-jqhq-7m2m-3xjx.json index 7ad1f2b307f..d671da5db5c 100644 --- a/advisories/unreviewed/2024/03/GHSA-jqhq-7m2m-3xjx/GHSA-jqhq-7m2m-3xjx.json +++ b/advisories/unreviewed/2024/03/GHSA-jqhq-7m2m-3xjx/GHSA-jqhq-7m2m-3xjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqhq-7m2m-3xjx", - "modified": "2024-03-05T00:31:14Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-05T00:31:14Z", "aliases": [ "CVE-2024-25164" ], "details": "iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T00:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mhv9-5hxr-j9mw/GHSA-mhv9-5hxr-j9mw.json b/advisories/unreviewed/2024/03/GHSA-mhv9-5hxr-j9mw/GHSA-mhv9-5hxr-j9mw.json index 843048836af..51d1e02d8aa 100644 --- a/advisories/unreviewed/2024/03/GHSA-mhv9-5hxr-j9mw/GHSA-mhv9-5hxr-j9mw.json +++ b/advisories/unreviewed/2024/03/GHSA-mhv9-5hxr-j9mw/GHSA-mhv9-5hxr-j9mw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhv9-5hxr-j9mw", - "modified": "2024-03-02T00:31:31Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-02T00:31:31Z", "aliases": [ "CVE-2024-27744" ], "details": "Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rr8j-4qpf-75m2/GHSA-rr8j-4qpf-75m2.json b/advisories/unreviewed/2024/03/GHSA-rr8j-4qpf-75m2/GHSA-rr8j-4qpf-75m2.json index 3eda9f3ebf6..84a18d08091 100644 --- a/advisories/unreviewed/2024/03/GHSA-rr8j-4qpf-75m2/GHSA-rr8j-4qpf-75m2.json +++ b/advisories/unreviewed/2024/03/GHSA-rr8j-4qpf-75m2/GHSA-rr8j-4qpf-75m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rr8j-4qpf-75m2", - "modified": "2024-03-07T09:30:30Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-07T09:30:30Z", "aliases": [ "CVE-2023-33676" ], "details": "Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at \"?page=items/view&id=*\" which can be escalated to the remote command execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T09:15:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vqw3-3gm8-35vm/GHSA-vqw3-3gm8-35vm.json b/advisories/unreviewed/2024/03/GHSA-vqw3-3gm8-35vm/GHSA-vqw3-3gm8-35vm.json index ee31e459351..17d4f7047bb 100644 --- a/advisories/unreviewed/2024/03/GHSA-vqw3-3gm8-35vm/GHSA-vqw3-3gm8-35vm.json +++ b/advisories/unreviewed/2024/03/GHSA-vqw3-3gm8-35vm/GHSA-vqw3-3gm8-35vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqw3-3gm8-35vm", - "modified": "2024-03-01T15:31:39Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-01T15:31:39Z", "aliases": [ "CVE-2024-27497" ], "details": "Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T15:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w7qj-9r4p-2jh6/GHSA-w7qj-9r4p-2jh6.json b/advisories/unreviewed/2024/03/GHSA-w7qj-9r4p-2jh6/GHSA-w7qj-9r4p-2jh6.json index 887432843fc..ae4184acaa3 100644 --- a/advisories/unreviewed/2024/03/GHSA-w7qj-9r4p-2jh6/GHSA-w7qj-9r4p-2jh6.json +++ b/advisories/unreviewed/2024/03/GHSA-w7qj-9r4p-2jh6/GHSA-w7qj-9r4p-2jh6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7qj-9r4p-2jh6", - "modified": "2024-03-24T00:30:32Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-24T00:30:32Z", "aliases": [ "CVE-2024-23755" ], "details": "ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-23T22:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xf53-c458-r6pv/GHSA-xf53-c458-r6pv.json b/advisories/unreviewed/2024/03/GHSA-xf53-c458-r6pv/GHSA-xf53-c458-r6pv.json index aa674027b9d..e0e6d34f399 100644 --- a/advisories/unreviewed/2024/03/GHSA-xf53-c458-r6pv/GHSA-xf53-c458-r6pv.json +++ b/advisories/unreviewed/2024/03/GHSA-xf53-c458-r6pv/GHSA-xf53-c458-r6pv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf53-c458-r6pv", - "modified": "2024-03-13T06:30:51Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-03-01T06:33:06Z", "aliases": [ "CVE-2024-25386" ], "details": "Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T06:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-872f-jfmv-qjp2/GHSA-872f-jfmv-qjp2.json b/advisories/unreviewed/2024/04/GHSA-872f-jfmv-qjp2/GHSA-872f-jfmv-qjp2.json index 525e3fd1c59..de6fb5c8896 100644 --- a/advisories/unreviewed/2024/04/GHSA-872f-jfmv-qjp2/GHSA-872f-jfmv-qjp2.json +++ b/advisories/unreviewed/2024/04/GHSA-872f-jfmv-qjp2/GHSA-872f-jfmv-qjp2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-872f-jfmv-qjp2", - "modified": "2024-04-10T21:30:32Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2023-52070" ], "details": "JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8qpg-h99j-c4j3/GHSA-8qpg-h99j-c4j3.json b/advisories/unreviewed/2024/04/GHSA-8qpg-h99j-c4j3/GHSA-8qpg-h99j-c4j3.json index 57587fa30f4..28d45559873 100644 --- a/advisories/unreviewed/2024/04/GHSA-8qpg-h99j-c4j3/GHSA-8qpg-h99j-c4j3.json +++ b/advisories/unreviewed/2024/04/GHSA-8qpg-h99j-c4j3/GHSA-8qpg-h99j-c4j3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qpg-h99j-c4j3", - "modified": "2024-04-03T03:30:30Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-04-03T03:30:30Z", "aliases": [ "CVE-2024-24724" ], "details": "Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1336" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T03:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9jm5-85j2-p9f4/GHSA-9jm5-85j2-p9f4.json b/advisories/unreviewed/2024/04/GHSA-9jm5-85j2-p9f4/GHSA-9jm5-85j2-p9f4.json index 2865869fad5..dbdd90094fc 100644 --- a/advisories/unreviewed/2024/04/GHSA-9jm5-85j2-p9f4/GHSA-9jm5-85j2-p9f4.json +++ b/advisories/unreviewed/2024/04/GHSA-9jm5-85j2-p9f4/GHSA-9jm5-85j2-p9f4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jm5-85j2-p9f4", - "modified": "2024-04-11T03:34:59Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-04-11T03:34:59Z", "aliases": [ "CVE-2023-51141" ], "details": "An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization component", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T01:22:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fm24-99vc-2vfh/GHSA-fm24-99vc-2vfh.json b/advisories/unreviewed/2024/04/GHSA-fm24-99vc-2vfh/GHSA-fm24-99vc-2vfh.json index a3437491ea5..7d6e5dc6c16 100644 --- a/advisories/unreviewed/2024/04/GHSA-fm24-99vc-2vfh/GHSA-fm24-99vc-2vfh.json +++ b/advisories/unreviewed/2024/04/GHSA-fm24-99vc-2vfh/GHSA-fm24-99vc-2vfh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fm24-99vc-2vfh", - "modified": "2024-04-17T18:31:33Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-04-17T18:31:33Z", "aliases": [ "CVE-2024-32316" ], "details": "Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T16:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j2v6-5mgp-w77v/GHSA-j2v6-5mgp-w77v.json b/advisories/unreviewed/2024/04/GHSA-j2v6-5mgp-w77v/GHSA-j2v6-5mgp-w77v.json index d9dc50d0ccd..9e9ae150b48 100644 --- a/advisories/unreviewed/2024/04/GHSA-j2v6-5mgp-w77v/GHSA-j2v6-5mgp-w77v.json +++ b/advisories/unreviewed/2024/04/GHSA-j2v6-5mgp-w77v/GHSA-j2v6-5mgp-w77v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2v6-5mgp-w77v", - "modified": "2024-04-23T15:30:35Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-04-23T15:30:35Z", "aliases": [ "CVE-2024-33212" ], "details": "Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goform/setcfm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-23T15:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json b/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json index 2d4cf63a47d..19bd9e54b68 100644 --- a/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json +++ b/advisories/unreviewed/2024/04/GHSA-rhvv-h8rg-3gxq/GHSA-rhvv-h8rg-3gxq.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-c6v9-vw5h-vqrm/GHSA-c6v9-vw5h-vqrm.json b/advisories/unreviewed/2024/05/GHSA-c6v9-vw5h-vqrm/GHSA-c6v9-vw5h-vqrm.json index ba365d03950..44a53978f94 100644 --- a/advisories/unreviewed/2024/05/GHSA-c6v9-vw5h-vqrm/GHSA-c6v9-vw5h-vqrm.json +++ b/advisories/unreviewed/2024/05/GHSA-c6v9-vw5h-vqrm/GHSA-c6v9-vw5h-vqrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6v9-vw5h-vqrm", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32609" ], "details": "HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-674" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qgm6-rxj7-629q/GHSA-qgm6-rxj7-629q.json b/advisories/unreviewed/2024/05/GHSA-qgm6-rxj7-629q/GHSA-qgm6-rxj7-629q.json index 53dbdc36d9c..adddb76a206 100644 --- a/advisories/unreviewed/2024/05/GHSA-qgm6-rxj7-629q/GHSA-qgm6-rxj7-629q.json +++ b/advisories/unreviewed/2024/05/GHSA-qgm6-rxj7-629q/GHSA-qgm6-rxj7-629q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qgm6-rxj7-629q", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29157" ], "details": "HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:31Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json b/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json index de288901552..6c7dc3ea3c9 100644 --- a/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json +++ b/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc4h-7j78-49pj", - "modified": "2024-06-21T15:31:06Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-06-21T15:31:06Z", "aliases": [ "CVE-2024-6239" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6239" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5305" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6239" diff --git a/advisories/unreviewed/2024/06/GHSA-ff8c-r6cp-6m85/GHSA-ff8c-r6cp-6m85.json b/advisories/unreviewed/2024/06/GHSA-ff8c-r6cp-6m85/GHSA-ff8c-r6cp-6m85.json index 649f3629781..c5915776e8f 100644 --- a/advisories/unreviewed/2024/06/GHSA-ff8c-r6cp-6m85/GHSA-ff8c-r6cp-6m85.json +++ b/advisories/unreviewed/2024/06/GHSA-ff8c-r6cp-6m85/GHSA-ff8c-r6cp-6m85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ff8c-r6cp-6m85", - "modified": "2024-06-13T21:30:56Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-06-13T21:30:56Z", "aliases": [ "CVE-2024-5976" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json b/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json index 2a5659e7f5a..3e2df2b172c 100644 --- a/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json +++ b/advisories/unreviewed/2024/06/GHSA-hh2w-28r4-mpw7/GHSA-hh2w-28r4-mpw7.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-379" + "CWE-379", + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p6jh-36mx-hrg4/GHSA-p6jh-36mx-hrg4.json b/advisories/unreviewed/2024/06/GHSA-p6jh-36mx-hrg4/GHSA-p6jh-36mx-hrg4.json index b9d05d44465..926c739949b 100644 --- a/advisories/unreviewed/2024/06/GHSA-p6jh-36mx-hrg4/GHSA-p6jh-36mx-hrg4.json +++ b/advisories/unreviewed/2024/06/GHSA-p6jh-36mx-hrg4/GHSA-p6jh-36mx-hrg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6jh-36mx-hrg4", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32918" ], "details": "Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g9rf-qc6j-h2f7/GHSA-g9rf-qc6j-h2f7.json b/advisories/unreviewed/2024/07/GHSA-g9rf-qc6j-h2f7/GHSA-g9rf-qc6j-h2f7.json index 7b826f67e8e..384ffe3bd56 100644 --- a/advisories/unreviewed/2024/07/GHSA-g9rf-qc6j-h2f7/GHSA-g9rf-qc6j-h2f7.json +++ b/advisories/unreviewed/2024/07/GHSA-g9rf-qc6j-h2f7/GHSA-g9rf-qc6j-h2f7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9rf-qc6j-h2f7", - "modified": "2024-07-26T09:30:31Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-07-26T09:30:31Z", "aliases": [ "CVE-2024-25090" ], "details": "Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted users, then you need to do nothing because you trust your users to author raw HTML and other web content. If you are running with untrusted users then you should upgrade to Roller 6.1.3.\n\nThis issue affects Apache Roller: from 5.0.0 before 6.1.3.\n\nUsers are recommended to upgrade to version 6.1.3, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-26T09:15:09Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xq4f-9xp4-279p/GHSA-xq4f-9xp4-279p.json b/advisories/unreviewed/2024/07/GHSA-xq4f-9xp4-279p/GHSA-xq4f-9xp4-279p.json index dbe9b1cfb2c..82841c79f3e 100644 --- a/advisories/unreviewed/2024/07/GHSA-xq4f-9xp4-279p/GHSA-xq4f-9xp4-279p.json +++ b/advisories/unreviewed/2024/07/GHSA-xq4f-9xp4-279p/GHSA-xq4f-9xp4-279p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq4f-9xp4-279p", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-27881" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json b/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json index 4f2ac4b0f1c..113e939c02c 100644 --- a/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json +++ b/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35gp-5q9f-g9pq", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34737" ], "details": "In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json b/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json index 77305dd51a8..c27982db3c7 100644 --- a/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json +++ b/advisories/unreviewed/2024/08/GHSA-3p9r-c4f8-vv7m/GHSA-3p9r-c4f8-vv7m.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json b/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json index 6b6f0ebab52..a75aaa21455 100644 --- a/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json +++ b/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-423g-mrq6-vpvp", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34739" ], "details": "In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json b/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json new file mode 100644 index 00000000000..944143945c7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hmr-hm34-jj9g", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42634" + ], + "details": "A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42634" + }, + { + "type": "WEB", + "url": "https://github.com/goldds96/Report/blob/main/Tenda/AC9/CI.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json b/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json index a182b27ee9b..dd8dc545fb4 100644 --- a/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json +++ b/advisories/unreviewed/2024/08/GHSA-5236-gxxf-m73h/GHSA-5236-gxxf-m73h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5236-gxxf-m73h", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-08-16T18:30:56Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-6134" ], "details": "The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:38Z" diff --git a/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json b/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json index e0477cc3f4b..1f6f852aa18 100644 --- a/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json +++ b/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-598c-cc55-mwv5", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34731" ], "details": "In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-368" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json b/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json index 23e6f3cbe86..93a09b26456 100644 --- a/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json +++ b/advisories/unreviewed/2024/08/GHSA-5m24-c4vx-fjj8/GHSA-5m24-c4vx-fjj8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json b/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json new file mode 100644 index 00000000000..7b2a6f9073e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65q8-wrmh-rrcm", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42639" + ], + "details": "H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42639" + }, + { + "type": "WEB", + "url": "https://palm-vertebra-fe9.notion.site/H3C-GR1100-PV100R009-was-discovered-to-contain-a-hardcoded-824141daa44f4c52a914860c6e4a7684" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/d_202308/1912371_30005_0.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json b/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json index 7fbfc3455b7..a141b3d1d27 100644 --- a/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json +++ b/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67q8-hw3v-9fj4", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34734" ], "details": "In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-453" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json b/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json index 043f1ab7310..26266a23cb8 100644 --- a/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json +++ b/advisories/unreviewed/2024/08/GHSA-84mw-hccv-m82r/GHSA-84mw-hccv-m82r.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json b/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json index 44efb1a9bec..f6549ef5b1f 100644 --- a/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json +++ b/advisories/unreviewed/2024/08/GHSA-9q7g-3c57-wvv7/GHSA-9q7g-3c57-wvv7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-c4j6-mvfp-j4wx/GHSA-c4j6-mvfp-j4wx.json b/advisories/unreviewed/2024/08/GHSA-c4j6-mvfp-j4wx/GHSA-c4j6-mvfp-j4wx.json new file mode 100644 index 00000000000..f19a5ac77d4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c4j6-mvfp-j4wx/GHSA-c4j6-mvfp-j4wx.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4j6-mvfp-j4wx", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42758" + ], + "details": "A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A malicious attacker can input XSS payloads for example when creating or editing existing page, to trigger the XSS on Dokuwiki, which is then stored in .txt file (due to nature of how Dokuwiki is designed), which presents stored XSS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42758" + }, + { + "type": "WEB", + "url": "https://github.com/samuelet/indexmenu/issues/317" + }, + { + "type": "WEB", + "url": "https://github.com/1s1ldur/CVE-2024-42758/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://github.com/dokuwiki/dokuwiki" + }, + { + "type": "WEB", + "url": "https://github.com/samuelet/indexmenu" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json b/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json index 072b11b86f5..cc723242b0d 100644 --- a/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json +++ b/advisories/unreviewed/2024/08/GHSA-c75r-v5wg-3gmj/GHSA-c75r-v5wg-3gmj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json b/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json index 97611485971..e679122d68e 100644 --- a/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json +++ b/advisories/unreviewed/2024/08/GHSA-cprr-85rg-mjvr/GHSA-cprr-85rg-mjvr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json b/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json new file mode 100644 index 00000000000..f7219913a99 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f5hg-xwhp-3gj9/GHSA-f5hg-xwhp-3gj9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5hg-xwhp-3gj9", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42638" + ], + "details": "H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42638" + }, + { + "type": "WEB", + "url": "https://palm-vertebra-fe9.notion.site/H3C-Magic-B1STV100R012-was-discovered-to-contain-a-hardcoded-2a648569ee7f4df8b570632d11032337?pvs=74" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/d_201609/956059_30005_0.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json b/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json index 108af9f8f6c..3bc7546e19a 100644 --- a/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json +++ b/advisories/unreviewed/2024/08/GHSA-j828-57c8-xr27/GHSA-j828-57c8-xr27.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json b/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json index 5f34f5d28f7..9109a6eca7a 100644 --- a/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json +++ b/advisories/unreviewed/2024/08/GHSA-m6q3-mcjx-5646/GHSA-m6q3-mcjx-5646.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json b/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json index 7182c717b7f..575155c3177 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json +++ b/advisories/unreviewed/2024/08/GHSA-mcrq-g49g-vf4v/GHSA-mcrq-g49g-vf4v.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json b/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json new file mode 100644 index 00000000000..4fa9197268f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj96-jcmr-6947", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42995" + ], + "details": "VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the \"Migration\" administrative module to disable arbitrary modules.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42995" + }, + { + "type": "WEB", + "url": "https://www.shielder.com/advisories/vtiger-migration-bac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p7f3-v9j2-h27r/GHSA-p7f3-v9j2-h27r.json b/advisories/unreviewed/2024/08/GHSA-p7f3-v9j2-h27r/GHSA-p7f3-v9j2-h27r.json new file mode 100644 index 00000000000..bfdaa3f4362 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p7f3-v9j2-h27r/GHSA-p7f3-v9j2-h27r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7f3-v9j2-h27r", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42637" + ], + "details": "H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42637" + }, + { + "type": "WEB", + "url": "https://palm-vertebra-fe9.notion.site/H3C-R3010V100R002L02-was-discovered-to-contain-a-hardcoded-d3212602f84443d4b17e3247b3e6b129" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/d_202308/1907175_30005_0.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json b/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json index 9449322c2a2..683567a2536 100644 --- a/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json +++ b/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prxw-7955-hmfm", - "modified": "2024-08-16T00:32:04Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:04Z", "aliases": [ "CVE-2024-31333" ], "details": "In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qx8j-xj5q-v7r3/GHSA-qx8j-xj5q-v7r3.json b/advisories/unreviewed/2024/08/GHSA-qx8j-xj5q-v7r3/GHSA-qx8j-xj5q-v7r3.json new file mode 100644 index 00000000000..9edf0b45508 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qx8j-xj5q-v7r3/GHSA-qx8j-xj5q-v7r3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx8j-xj5q-v7r3", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-7646" + ], + "details": "A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7646" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes/kubernetes/issues/126744" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes/ingress-nginx/pull/11719" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes/ingress-nginx/pull/11721" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/kubernetes-security-announce/c/a1__cKjWkfA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json b/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json index 175ad33712b..4d48c913feb 100644 --- a/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json +++ b/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rg28-x6g7-wxr5", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34738" ], "details": "In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json b/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json index b19fbea4b39..12f7691b083 100644 --- a/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json +++ b/advisories/unreviewed/2024/08/GHSA-v4x2-xrc6-7q7j/GHSA-v4x2-xrc6-7q7j.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json b/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json index 79d543c935d..235a92c8600 100644 --- a/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json +++ b/advisories/unreviewed/2024/08/GHSA-v574-8m96-8mp9/GHSA-v574-8m96-8mp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v574-8m96-8mp9", - "modified": "2024-08-15T21:31:19Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-15T21:31:19Z", "aliases": [ "CVE-2024-27730" ], "details": "Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T19:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json b/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json new file mode 100644 index 00000000000..7c66e802309 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf2f-4qh9-fpch", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-42994" + ], + "details": "VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the \"CompanyDetails\" operation of the \"MailManager\" module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42994" + }, + { + "type": "WEB", + "url": "https://www.shielder.com/advisories/vtiger-mailmanager-sqli" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json b/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json index 8b8d7d9a9b7..b98372e51db 100644 --- a/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json +++ b/advisories/unreviewed/2024/08/GHSA-vv44-rh9q-4cc8/GHSA-vv44-rh9q-4cc8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json b/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json new file mode 100644 index 00000000000..c870392aa68 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcrf-58c6-27cg", + "modified": "2024-08-16T18:30:57Z", + "published": "2024-08-16T18:30:57Z", + "aliases": [ + "CVE-2024-25837" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25837" + }, + { + "type": "WEB", + "url": "https://github.com/RatMD/bloghub-plugin/blob/master/CHANGELOG.md#version-139---stable" + }, + { + "type": "WEB", + "url": "https://www.getastra.com/blog/vulnerability/stored-xss-vulnerability-in-bloghub-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json b/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json index ee8aded8cd2..f9402993ac7 100644 --- a/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json +++ b/advisories/unreviewed/2024/08/GHSA-wp6j-mqr7-v2hf/GHSA-wp6j-mqr7-v2hf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json b/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json index f9569a94ed2..174eb84ae02 100644 --- a/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json +++ b/advisories/unreviewed/2024/08/GHSA-wq55-fhp8-6jh8/GHSA-wq55-fhp8-6jh8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json b/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json index 7b80f4c6a19..356fa57d961 100644 --- a/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json +++ b/advisories/unreviewed/2024/08/GHSA-xg38-j8ww-g8hg/GHSA-xg38-j8ww-g8hg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json b/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json index dd1192cb69b..e2446e9fea1 100644 --- a/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json +++ b/advisories/unreviewed/2024/08/GHSA-xh57-2h8m-3798/GHSA-xh57-2h8m-3798.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json b/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json index babae3b7de1..5e85e28e082 100644 --- a/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json +++ b/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx83-6gm8-xx8p", - "modified": "2024-08-16T00:32:05Z", + "modified": "2024-08-16T18:30:57Z", "published": "2024-08-16T00:32:05Z", "aliases": [ "CVE-2024-34741" ], "details": "In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T22:15:06Z"