Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-12 18:32:22 +00:00
parent e30e2d6fb1
commit 9301e97ece
205 changed files with 5743 additions and 139 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cw2r-4p82-qv79",
"modified": "2024-10-10T19:07:21Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2023-12-28T16:36:59Z",
"aliases": [
"CVE-2023-6681"
@@ -52,6 +52,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3267"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9281"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6681"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-586p-749j-fhwp",
"modified": "2024-11-11T18:30:28Z",
"modified": "2024-11-12T18:30:51Z",
"published": "2024-10-09T15:32:21Z",
"aliases": [
"CVE-2024-9675"
@@ -64,6 +64,14 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9675"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9459"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9454"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9051"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhqq-8f65-5xfc",
"modified": "2024-11-11T18:30:28Z",
"modified": "2024-11-12T18:30:51Z",
"published": "2024-10-01T21:31:35Z",
"aliases": [
"CVE-2024-9407"
@@ -169,6 +169,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9051"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9454"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9459"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9407"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mc76-5925-c5p6",
"modified": "2024-11-07T09:30:42Z",
"modified": "2024-11-12T18:30:51Z",
"published": "2024-10-01T21:31:34Z",
"aliases": [
"CVE-2024-9341"
@@ -72,6 +72,14 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-9341"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9459"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9454"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:8846"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59h3-54m2-3jm7",
"modified": "2024-06-27T15:30:37Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-01-09T18:30:27Z",
"aliases": [
"CVE-2024-0340"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3627"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9315"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0340"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7f3-4crr-9hfj",
"modified": "2024-07-24T18:31:15Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-02-11T15:30:30Z",
"aliases": [
"CVE-2024-1151"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4831"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9315"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1151"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g636-8hgg-7gx9",
"modified": "2024-07-03T00:34:09Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-03-18T15:30:48Z",
"aliases": [
"CVE-2023-7250"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4241"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9185"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-7250"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2gx-4fh8-wm9f",
"modified": "2024-04-25T18:30:38Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-03-07T00:30:49Z",
"aliases": [
"CVE-2024-2236"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9404"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-2236"
File diff suppressed because one or more lines are too long
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x2gp-p6cx-82p9",
"modified": "2024-04-30T00:30:35Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-04-30T00:30:35Z",
"aliases": [
"CVE-2024-34044"
],
"details": "The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-30T00:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f3w-qrjm-6m77",
"modified": "2024-05-17T15:31:09Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-05-17T15:31:09Z",
"aliases": [
"CVE-2024-35797"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: cachestat: fix two shmem bugs\n\nWhen cachestat on shmem races with swapping and invalidation, there\nare two possible bugs:\n\n1) A swapin error can have resulted in a poisoned swap entry in the\n shmem inode's xarray. Calling get_shadow_from_swap_cache() on it\n will result in an out-of-bounds access to swapper_spaces[].\n\n Validate the entry with non_swap_entry() before going further.\n\n2) When we find a valid swap entry in the shmem's inode, the shadow\n entry in the swapcache might not exist yet: swap IO is still in\n progress and we're before __remove_mapping; swapin, invalidation,\n or swapoff have removed the shadow from swapcache after we saw the\n shmem swap entry.\n\n This will send a NULL to workingset_test_recent(). The latter\n purely operates on pointer bits, so it won't crash - node 0, memcg\n ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a\n bogus test. In theory that could result in a false \"recently\n evicted\" count.\n\n Such a false positive wouldn't be the end of the world. But for\n code clarity and (future) robustness, be explicit about this case.\n\n Bail on get_shadow_from_swap_cache() returning NULL.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:11Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6m5-rpfj-c92f",
"modified": "2024-05-19T09:34:46Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-05-19T09:34:46Z",
"aliases": [
"CVE-2024-35878"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: module: prevent NULL pointer dereference in vsnprintf()\n\nIn of_modalias(), we can get passed the str and len parameters which would\ncause a kernel oops in vsnprintf() since it only allows passing a NULL ptr\nwhen the length is also 0. Also, we need to filter out the negative values\nof the len parameter as these will result in a really huge buffer since\nsnprintf() takes size_t parameter while ours is ssize_t...\n\nFound by Linux Verification Center (linuxtesting.org) with the Svace static\nanalysis tool.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T09:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc4h-7j78-49pj",
"modified": "2024-08-16T18:30:56Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-06-21T15:31:06Z",
"aliases": [
"CVE-2024-6239"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:5305"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9167"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-6239"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffhx-2rrf-9c23",
"modified": "2024-09-25T03:30:35Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-06-12T09:30:48Z",
"aliases": [
"CVE-2024-5742"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6986"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9430"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-5742"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vqr-5j64-p9wr",
"modified": "2024-07-16T18:31:41Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-07-09T15:30:54Z",
"aliases": [
"CVE-2024-6604"
],
"details": "Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-09T15:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9xm-vjq4-6r8q",
"modified": "2024-09-25T03:30:35Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-07-16T15:30:50Z",
"aliases": [
"CVE-2024-6655"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:6963"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9184"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-6655"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c7g-wccp-rrhj",
"modified": "2024-10-01T06:30:47Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-08-05T15:30:53Z",
"aliases": [
"CVE-2024-7409"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:7408"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9136"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-7409"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94ch-6cfh-xxgc",
"modified": "2024-08-30T18:30:40Z",
"modified": "2024-11-12T18:30:50Z",
"published": "2024-08-30T18:30:40Z",
"aliases": [
"CVE-2024-8235"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8235"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:9128"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-8235"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
"CWE-22",
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More