From 9301e97ecede28e78a796eeaa81c8ea483c91650 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 12 Nov 2024 18:32:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cw2r-4p82-qv79.json | 6 ++- .../GHSA-586p-749j-fhwp.json | 10 +++- .../GHSA-fhqq-8f65-5xfc.json | 10 +++- .../GHSA-mc76-5925-c5p6.json | 10 +++- .../GHSA-rg52-xrwc-xm79.json | 2 +- .../GHSA-59h3-54m2-3jm7.json | 6 ++- .../GHSA-g7f3-4crr-9hfj.json | 6 ++- .../GHSA-g636-8hgg-7gx9.json | 6 ++- .../GHSA-w2gx-4fh8-wm9f.json | 6 ++- .../GHSA-jj9v-ff2v-cgx9.json | 11 ++-- .../GHSA-x2gp-p6cx-82p9.json | 11 ++-- .../GHSA-3f3w-qrjm-6m77.json | 11 ++-- .../GHSA-q6m5-rpfj-c92f.json | 11 ++-- .../GHSA-cc4h-7j78-49pj.json | 6 ++- .../GHSA-ffhx-2rrf-9c23.json | 6 ++- .../GHSA-9vqr-5j64-p9wr.json | 11 ++-- .../GHSA-v9xm-vjq4-6r8q.json | 6 ++- .../GHSA-7c7g-wccp-rrhj.json | 6 ++- .../GHSA-94ch-6cfh-xxgc.json | 6 ++- .../GHSA-9qmq-f7gc-gf44.json | 3 +- .../GHSA-cjc3-7r36-pp49.json | 6 ++- .../GHSA-prr3-v2fg-ggg7.json | 6 ++- .../GHSA-wq2p-5pc6-wpgf.json | 10 +++- .../GHSA-2586-f3p4-hq84.json | 38 +++++++++++++ .../GHSA-268c-v4f5-27qw.json | 38 +++++++++++++ .../GHSA-2794-6m94-77f7.json | 38 +++++++++++++ .../GHSA-29cm-m432-745j.json | 38 +++++++++++++ .../GHSA-2f2h-73pp-4p79.json | 38 +++++++++++++ .../GHSA-2gmm-fh28-fr6w.json | 11 ++-- .../GHSA-2p4q-qc9j-27gx.json | 38 +++++++++++++ .../GHSA-2vwf-jqh3-5vjp.json | 2 +- .../GHSA-2w99-6h4v-j323.json | 38 +++++++++++++ .../GHSA-346c-j6cg-xp49.json | 38 +++++++++++++ .../GHSA-3638-r263-v9hp.json | 38 +++++++++++++ .../GHSA-36jr-8w83-wr8q.json | 38 +++++++++++++ .../GHSA-37x8-vc3h-28p6.json | 38 +++++++++++++ .../GHSA-3986-r924-xxjc.json | 38 +++++++++++++ .../GHSA-3g36-jm7h-4mqf.json | 38 +++++++++++++ .../GHSA-3jfq-x5rf-pxwc.json | 38 +++++++++++++ .../GHSA-3mrx-hx45-5865.json | 38 +++++++++++++ .../GHSA-3q5g-jw35-qh3g.json | 38 +++++++++++++ .../GHSA-3wr4-2chq-phgj.json | 38 +++++++++++++ .../GHSA-434f-v35r-xr4j.json | 9 ++-- .../GHSA-4449-mp9g-8844.json | 38 +++++++++++++ .../GHSA-4cgm-m7vx-9pxr.json | 38 +++++++++++++ .../GHSA-4f5h-42qx-mp6w.json | 38 +++++++++++++ .../GHSA-4g7c-wgc5-7vr9.json | 38 +++++++++++++ .../GHSA-4gq2-x5w4-7hp8.json | 2 +- .../GHSA-4jpm-2crw-5qqr.json | 38 +++++++++++++ .../GHSA-4v4m-mgj6-c8jv.json | 38 +++++++++++++ .../GHSA-4v5h-vp2v-p65r.json | 38 +++++++++++++ .../GHSA-5777-q3q8-vhh3.json | 11 ++-- .../GHSA-5888-fpmr-f2v8.json | 38 +++++++++++++ .../GHSA-593c-jh4c-8cw5.json | 38 +++++++++++++ .../GHSA-5cr8-75x7-7j9w.json | 38 +++++++++++++ .../GHSA-5ggp-35wq-jxx3.json | 38 +++++++++++++ .../GHSA-5hjf-mp3w-5847.json | 38 +++++++++++++ .../GHSA-5jpp-jp5m-8w78.json | 11 ++-- .../GHSA-5pfq-57jv-xgm6.json | 38 +++++++++++++ .../GHSA-5rq6-q8gw-qqpr.json | 11 ++-- .../GHSA-5w7v-4rv8-26wg.json | 38 +++++++++++++ .../GHSA-5whg-6vqr-5wxf.json | 38 +++++++++++++ .../GHSA-5x3v-28rm-5hqx.json | 38 +++++++++++++ .../GHSA-64fp-9m6r-66h4.json | 38 +++++++++++++ .../GHSA-6583-5qh2-wgh7.json | 38 +++++++++++++ .../GHSA-66pp-32jj-853p.json | 38 +++++++++++++ .../GHSA-67h7-pjww-p5jc.json | 38 +++++++++++++ .../GHSA-693v-cgfp-qgfp.json | 38 +++++++++++++ .../GHSA-696j-qh6c-q484.json | 35 ++++++++++++ .../GHSA-6p3c-4j57-9prp.json | 38 +++++++++++++ .../GHSA-6vf9-7q6p-x646.json | 38 +++++++++++++ .../GHSA-6vj3-8x7g-gqrq.json | 38 +++++++++++++ .../GHSA-6w96-779v-fpfh.json | 38 +++++++++++++ .../GHSA-74fm-9mx4-7hg6.json | 2 +- .../GHSA-775q-3335-qhjr.json | 1 + .../GHSA-77hr-fpmg-vvgr.json | 38 +++++++++++++ .../GHSA-79mw-jmc6-qmgj.json | 38 +++++++++++++ .../GHSA-7jpm-f32g-qv8w.json | 38 +++++++++++++ .../GHSA-7m49-66f5-827f.json | 38 +++++++++++++ .../GHSA-7wmp-2xmx-g6h8.json | 2 +- .../GHSA-7wpv-4qh2-r4fv.json | 38 +++++++++++++ .../GHSA-7xx8-v929-wp8r.json | 38 +++++++++++++ .../GHSA-88rj-8pxh-m882.json | 38 +++++++++++++ .../GHSA-8g7v-h849-8g58.json | 11 ++-- .../GHSA-8gvm-rm96-9p7v.json | 38 +++++++++++++ .../GHSA-8hgc-m8mv-wr7p.json | 38 +++++++++++++ .../GHSA-8mjq-9vqf-24jc.json | 38 +++++++++++++ .../GHSA-8pj5-4fw9-jfjq.json | 11 ++-- .../GHSA-8pwc-jhg2-h67f.json | 38 +++++++++++++ .../GHSA-8rx5-xm8f-w3w5.json | 38 +++++++++++++ .../GHSA-8rxm-6783-qh55.json | 38 +++++++++++++ .../GHSA-92jc-4j34-wj49.json | 38 +++++++++++++ .../GHSA-92qj-48rw-cjq8.json | 42 +++++++++++++++ .../GHSA-93ww-rwv5-gjg4.json | 38 +++++++++++++ .../GHSA-99w5-q9j7-6pjv.json | 38 +++++++++++++ .../GHSA-9c5m-2869-83j9.json | 38 +++++++++++++ .../GHSA-9cpc-mh5g-732x.json | 38 +++++++++++++ .../GHSA-9ffw-88h4-2w7x.json | 9 ++-- .../GHSA-9gw8-gc35-hprv.json | 38 +++++++++++++ .../GHSA-9h99-mc2q-rgfw.json | 54 +++++++++++++++++++ .../GHSA-9r9r-hwrw-4gpj.json | 38 +++++++++++++ .../GHSA-9rpx-w5w4-cq4r.json | 38 +++++++++++++ .../GHSA-c43q-qj38-7p5j.json | 38 +++++++++++++ .../GHSA-c64q-8xvp-hcjx.json | 38 +++++++++++++ .../GHSA-c6pq-f254-phcc.json | 38 +++++++++++++ .../GHSA-c6xg-p6mw-qxxr.json | 11 ++-- .../GHSA-c7hj-rgqx-4m7j.json | 38 +++++++++++++ .../GHSA-c884-h6q9-jjwg.json | 9 ++-- .../GHSA-cmh5-78pc-x57w.json | 38 +++++++++++++ .../GHSA-cx2c-rv87-9m6p.json | 38 +++++++++++++ .../GHSA-cx99-h4rf-2j49.json | 11 ++-- .../GHSA-f2vc-g638-2wm6.json | 38 +++++++++++++ .../GHSA-f3v6-qmvg-fhwg.json | 38 +++++++++++++ .../GHSA-f7x3-3w29-5xxp.json | 38 +++++++++++++ .../GHSA-fgm4-wh6f-2pxc.json | 38 +++++++++++++ .../GHSA-fgq7-v63g-3f6x.json | 42 +++++++++++++++ .../GHSA-fh4x-8p68-8qg2.json | 38 +++++++++++++ .../GHSA-fh5q-gf2c-rgx3.json | 38 +++++++++++++ .../GHSA-frfr-qxrr-f897.json | 38 +++++++++++++ .../GHSA-fxcg-68j8-mh5m.json | 11 ++-- .../GHSA-g5vp-j278-8pjh.json | 38 +++++++++++++ .../GHSA-g6gg-3vqf-rfrx.json | 11 ++-- .../GHSA-g79m-w87v-w7c8.json | 38 +++++++++++++ .../GHSA-gpjf-59wh-632x.json | 38 +++++++++++++ .../GHSA-gpm6-xpxh-fvfp.json | 38 +++++++++++++ .../GHSA-gwgp-7jjg-774v.json | 2 +- .../GHSA-h4mv-24rm-583r.json | 38 +++++++++++++ .../GHSA-h4qj-345r-3p67.json | 38 +++++++++++++ .../GHSA-h644-m8cx-x9h6.json | 11 ++-- .../GHSA-h7w7-g9gg-4q8w.json | 38 +++++++++++++ .../GHSA-h8m5-j25m-72g2.json | 11 ++-- .../GHSA-hj7x-pcrh-84jj.json | 38 +++++++++++++ .../GHSA-hjgc-jxjc-8v9j.json | 2 +- .../GHSA-hprc-66gh-5q8w.json | 38 +++++++++++++ .../GHSA-hqx6-xxcj-4chg.json | 38 +++++++++++++ .../GHSA-hw6j-ph25-g43c.json | 9 ++-- .../GHSA-hx47-p5gg-xw55.json | 38 +++++++++++++ .../GHSA-j85c-4frx-f93r.json | 38 +++++++++++++ .../GHSA-jc4h-vrmv-7c33.json | 38 +++++++++++++ .../GHSA-jcjw-frm7-94f5.json | 38 +++++++++++++ .../GHSA-jgw6-7hrc-742j.json | 38 +++++++++++++ .../GHSA-jjp9-999r-m9vg.json | 38 +++++++++++++ .../GHSA-jmf3-9f5j-cpjh.json | 38 +++++++++++++ .../GHSA-jpf2-9ppp-2c49.json | 2 +- .../GHSA-jrf6-24wc-4wx7.json | 38 +++++++++++++ .../GHSA-jxvj-5w26-hpx9.json | 38 +++++++++++++ .../GHSA-m923-5xpw-m3wf.json | 38 +++++++++++++ .../GHSA-m9rx-mmjv-j7v6.json | 38 +++++++++++++ .../GHSA-mfc7-3m73-fjf3.json | 42 +++++++++++++++ .../GHSA-mgh2-q3fc-jjmr.json | 38 +++++++++++++ .../GHSA-mm7h-86pj-q87p.json | 38 +++++++++++++ .../GHSA-mq3p-r846-c5mx.json | 38 +++++++++++++ .../GHSA-mrxr-g8pq-3495.json | 38 +++++++++++++ .../GHSA-mx5f-vqxg-86w4.json | 3 +- .../GHSA-p2rj-qgfh-h8m9.json | 38 +++++++++++++ .../GHSA-p3qp-q8pw-qf3p.json | 38 +++++++++++++ .../GHSA-p6vx-vqj8-q8r8.json | 38 +++++++++++++ .../GHSA-pg35-867h-jm8h.json | 9 ++-- .../GHSA-pgrc-8wp5-5mvq.json | 11 ++-- .../GHSA-phrc-779j-3268.json | 38 +++++++++++++ .../GHSA-pj67-hxcx-g74v.json | 9 ++-- .../GHSA-pq55-r4g8-r76q.json | 2 +- .../GHSA-pxx2-jxr9-c92g.json | 38 +++++++++++++ .../GHSA-q85x-jh7r-gh5h.json | 38 +++++++++++++ .../GHSA-q8fc-2r64-8hq5.json | 38 +++++++++++++ .../GHSA-q99x-mjmh-v8w7.json | 2 +- .../GHSA-qc59-4rgm-3c5c.json | 38 +++++++++++++ .../GHSA-qf7x-grg9-4j2x.json | 2 +- .../GHSA-qjr4-pwpg-c5m3.json | 42 +++++++++++++++ .../GHSA-qpj8-6r97-qxq6.json | 11 ++-- .../GHSA-qx56-hjgg-8xgm.json | 38 +++++++++++++ .../GHSA-qx8r-w7wr-86w4.json | 38 +++++++++++++ .../GHSA-qxf2-gf78-5hgp.json | 38 +++++++++++++ .../GHSA-qxwc-wcvf-47fq.json | 38 +++++++++++++ .../GHSA-r549-w33c-xm84.json | 38 +++++++++++++ .../GHSA-r5rh-8593-84qf.json | 38 +++++++++++++ .../GHSA-r8m4-9xm8-h9rq.json | 38 +++++++++++++ .../GHSA-rf57-p454-qrmj.json | 6 ++- .../GHSA-rgwg-49qg-75jg.json | 38 +++++++++++++ .../GHSA-v285-5c63-6rph.json | 38 +++++++++++++ .../GHSA-v8h2-p73v-3whx.json | 11 ++-- .../GHSA-v9xc-66hj-99jw.json | 38 +++++++++++++ .../GHSA-vcm2-gg9p-f48m.json | 38 +++++++++++++ .../GHSA-vcm7-8g3g-3rjm.json | 38 +++++++++++++ .../GHSA-vfrj-xg26-6g5p.json | 38 +++++++++++++ .../GHSA-vgj5-pm4f-q6gv.json | 6 ++- .../GHSA-vhc2-7wp4-4355.json | 38 +++++++++++++ .../GHSA-vpq5-56jj-vf2m.json | 2 +- .../GHSA-vv2x-chjj-4ppm.json | 38 +++++++++++++ .../GHSA-vw76-rp45-c8p9.json | 38 +++++++++++++ .../GHSA-w799-83vp-q48c.json | 38 +++++++++++++ .../GHSA-w7cf-g3rh-q9hc.json | 38 +++++++++++++ .../GHSA-w9j9-29jw-fj46.json | 38 +++++++++++++ .../GHSA-wggq-gr89-33vp.json | 9 ++-- .../GHSA-wgj3-g943-v8wv.json | 38 +++++++++++++ .../GHSA-whgf-6h8c-97q6.json | 2 +- .../GHSA-wm92-8qr7-r99c.json | 38 +++++++++++++ .../GHSA-wmm6-pgp8-29hg.json | 38 +++++++++++++ .../GHSA-wp5x-8wxv-j7j2.json | 38 +++++++++++++ .../GHSA-ww66-45gm-65fm.json | 38 +++++++++++++ .../GHSA-x3c4-52mm-7pp9.json | 38 +++++++++++++ .../GHSA-x6qj-75g5-46wg.json | 38 +++++++++++++ .../GHSA-xf4p-4gf4-v92p.json | 6 ++- .../GHSA-xqm3-rc5r-j547.json | 11 ++-- .../GHSA-xwfr-c9rv-m6pp.json | 38 +++++++++++++ 205 files changed, 5743 insertions(+), 139 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-2586-f3p4-hq84/GHSA-2586-f3p4-hq84.json create mode 100644 advisories/unreviewed/2024/11/GHSA-268c-v4f5-27qw/GHSA-268c-v4f5-27qw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-29cm-m432-745j/GHSA-29cm-m432-745j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2f2h-73pp-4p79/GHSA-2f2h-73pp-4p79.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2p4q-qc9j-27gx/GHSA-2p4q-qc9j-27gx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2w99-6h4v-j323/GHSA-2w99-6h4v-j323.json create mode 100644 advisories/unreviewed/2024/11/GHSA-346c-j6cg-xp49/GHSA-346c-j6cg-xp49.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-36jr-8w83-wr8q/GHSA-36jr-8w83-wr8q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-37x8-vc3h-28p6/GHSA-37x8-vc3h-28p6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3986-r924-xxjc/GHSA-3986-r924-xxjc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3g36-jm7h-4mqf/GHSA-3g36-jm7h-4mqf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3jfq-x5rf-pxwc/GHSA-3jfq-x5rf-pxwc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3mrx-hx45-5865/GHSA-3mrx-hx45-5865.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3q5g-jw35-qh3g/GHSA-3q5g-jw35-qh3g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3wr4-2chq-phgj/GHSA-3wr4-2chq-phgj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4449-mp9g-8844/GHSA-4449-mp9g-8844.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4cgm-m7vx-9pxr/GHSA-4cgm-m7vx-9pxr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4f5h-42qx-mp6w/GHSA-4f5h-42qx-mp6w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4g7c-wgc5-7vr9/GHSA-4g7c-wgc5-7vr9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4jpm-2crw-5qqr/GHSA-4jpm-2crw-5qqr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4v4m-mgj6-c8jv/GHSA-4v4m-mgj6-c8jv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4v5h-vp2v-p65r/GHSA-4v5h-vp2v-p65r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5888-fpmr-f2v8/GHSA-5888-fpmr-f2v8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5cr8-75x7-7j9w/GHSA-5cr8-75x7-7j9w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5ggp-35wq-jxx3/GHSA-5ggp-35wq-jxx3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5hjf-mp3w-5847/GHSA-5hjf-mp3w-5847.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5pfq-57jv-xgm6/GHSA-5pfq-57jv-xgm6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5w7v-4rv8-26wg/GHSA-5w7v-4rv8-26wg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5whg-6vqr-5wxf/GHSA-5whg-6vqr-5wxf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5x3v-28rm-5hqx/GHSA-5x3v-28rm-5hqx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-64fp-9m6r-66h4/GHSA-64fp-9m6r-66h4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6583-5qh2-wgh7/GHSA-6583-5qh2-wgh7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-66pp-32jj-853p/GHSA-66pp-32jj-853p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-67h7-pjww-p5jc/GHSA-67h7-pjww-p5jc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-693v-cgfp-qgfp/GHSA-693v-cgfp-qgfp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-696j-qh6c-q484/GHSA-696j-qh6c-q484.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6p3c-4j57-9prp/GHSA-6p3c-4j57-9prp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6vj3-8x7g-gqrq/GHSA-6vj3-8x7g-gqrq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6w96-779v-fpfh/GHSA-6w96-779v-fpfh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-77hr-fpmg-vvgr/GHSA-77hr-fpmg-vvgr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-79mw-jmc6-qmgj/GHSA-79mw-jmc6-qmgj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7jpm-f32g-qv8w/GHSA-7jpm-f32g-qv8w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7m49-66f5-827f/GHSA-7m49-66f5-827f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7wpv-4qh2-r4fv/GHSA-7wpv-4qh2-r4fv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7xx8-v929-wp8r/GHSA-7xx8-v929-wp8r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-88rj-8pxh-m882/GHSA-88rj-8pxh-m882.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8gvm-rm96-9p7v/GHSA-8gvm-rm96-9p7v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8hgc-m8mv-wr7p/GHSA-8hgc-m8mv-wr7p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8mjq-9vqf-24jc/GHSA-8mjq-9vqf-24jc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8pwc-jhg2-h67f/GHSA-8pwc-jhg2-h67f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8rx5-xm8f-w3w5/GHSA-8rx5-xm8f-w3w5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8rxm-6783-qh55/GHSA-8rxm-6783-qh55.json create mode 100644 advisories/unreviewed/2024/11/GHSA-92jc-4j34-wj49/GHSA-92jc-4j34-wj49.json create mode 100644 advisories/unreviewed/2024/11/GHSA-92qj-48rw-cjq8/GHSA-92qj-48rw-cjq8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-93ww-rwv5-gjg4/GHSA-93ww-rwv5-gjg4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9c5m-2869-83j9/GHSA-9c5m-2869-83j9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9cpc-mh5g-732x/GHSA-9cpc-mh5g-732x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9gw8-gc35-hprv/GHSA-9gw8-gc35-hprv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9h99-mc2q-rgfw/GHSA-9h99-mc2q-rgfw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9r9r-hwrw-4gpj/GHSA-9r9r-hwrw-4gpj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9rpx-w5w4-cq4r/GHSA-9rpx-w5w4-cq4r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c43q-qj38-7p5j/GHSA-c43q-qj38-7p5j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c64q-8xvp-hcjx/GHSA-c64q-8xvp-hcjx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c6pq-f254-phcc/GHSA-c6pq-f254-phcc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c7hj-rgqx-4m7j/GHSA-c7hj-rgqx-4m7j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cmh5-78pc-x57w/GHSA-cmh5-78pc-x57w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cx2c-rv87-9m6p/GHSA-cx2c-rv87-9m6p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f2vc-g638-2wm6/GHSA-f2vc-g638-2wm6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f3v6-qmvg-fhwg/GHSA-f3v6-qmvg-fhwg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f7x3-3w29-5xxp/GHSA-f7x3-3w29-5xxp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fgm4-wh6f-2pxc/GHSA-fgm4-wh6f-2pxc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fgq7-v63g-3f6x/GHSA-fgq7-v63g-3f6x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fh4x-8p68-8qg2/GHSA-fh4x-8p68-8qg2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fh5q-gf2c-rgx3/GHSA-fh5q-gf2c-rgx3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g5vp-j278-8pjh/GHSA-g5vp-j278-8pjh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gpjf-59wh-632x/GHSA-gpjf-59wh-632x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gpm6-xpxh-fvfp/GHSA-gpm6-xpxh-fvfp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h4mv-24rm-583r/GHSA-h4mv-24rm-583r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h4qj-345r-3p67/GHSA-h4qj-345r-3p67.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hj7x-pcrh-84jj/GHSA-hj7x-pcrh-84jj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hprc-66gh-5q8w/GHSA-hprc-66gh-5q8w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hqx6-xxcj-4chg/GHSA-hqx6-xxcj-4chg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hx47-p5gg-xw55/GHSA-hx47-p5gg-xw55.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j85c-4frx-f93r/GHSA-j85c-4frx-f93r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jc4h-vrmv-7c33/GHSA-jc4h-vrmv-7c33.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jgw6-7hrc-742j/GHSA-jgw6-7hrc-742j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jjp9-999r-m9vg/GHSA-jjp9-999r-m9vg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jmf3-9f5j-cpjh/GHSA-jmf3-9f5j-cpjh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jrf6-24wc-4wx7/GHSA-jrf6-24wc-4wx7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m923-5xpw-m3wf/GHSA-m923-5xpw-m3wf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m9rx-mmjv-j7v6/GHSA-m9rx-mmjv-j7v6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mfc7-3m73-fjf3/GHSA-mfc7-3m73-fjf3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mgh2-q3fc-jjmr/GHSA-mgh2-q3fc-jjmr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mm7h-86pj-q87p/GHSA-mm7h-86pj-q87p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mrxr-g8pq-3495/GHSA-mrxr-g8pq-3495.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p2rj-qgfh-h8m9/GHSA-p2rj-qgfh-h8m9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p3qp-q8pw-qf3p/GHSA-p3qp-q8pw-qf3p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p6vx-vqj8-q8r8/GHSA-p6vx-vqj8-q8r8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-phrc-779j-3268/GHSA-phrc-779j-3268.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pxx2-jxr9-c92g/GHSA-pxx2-jxr9-c92g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q85x-jh7r-gh5h/GHSA-q85x-jh7r-gh5h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q8fc-2r64-8hq5/GHSA-q8fc-2r64-8hq5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qc59-4rgm-3c5c/GHSA-qc59-4rgm-3c5c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qjr4-pwpg-c5m3/GHSA-qjr4-pwpg-c5m3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qx56-hjgg-8xgm/GHSA-qx56-hjgg-8xgm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qx8r-w7wr-86w4/GHSA-qx8r-w7wr-86w4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qxf2-gf78-5hgp/GHSA-qxf2-gf78-5hgp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r549-w33c-xm84/GHSA-r549-w33c-xm84.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r8m4-9xm8-h9rq/GHSA-r8m4-9xm8-h9rq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rgwg-49qg-75jg/GHSA-rgwg-49qg-75jg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v285-5c63-6rph/GHSA-v285-5c63-6rph.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v9xc-66hj-99jw/GHSA-v9xc-66hj-99jw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vcm2-gg9p-f48m/GHSA-vcm2-gg9p-f48m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vcm7-8g3g-3rjm/GHSA-vcm7-8g3g-3rjm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vfrj-xg26-6g5p/GHSA-vfrj-xg26-6g5p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vhc2-7wp4-4355/GHSA-vhc2-7wp4-4355.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vv2x-chjj-4ppm/GHSA-vv2x-chjj-4ppm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vw76-rp45-c8p9/GHSA-vw76-rp45-c8p9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w799-83vp-q48c/GHSA-w799-83vp-q48c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w7cf-g3rh-q9hc/GHSA-w7cf-g3rh-q9hc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w9j9-29jw-fj46/GHSA-w9j9-29jw-fj46.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wgj3-g943-v8wv/GHSA-wgj3-g943-v8wv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wm92-8qr7-r99c/GHSA-wm92-8qr7-r99c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wmm6-pgp8-29hg/GHSA-wmm6-pgp8-29hg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ww66-45gm-65fm/GHSA-ww66-45gm-65fm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x3c4-52mm-7pp9/GHSA-x3c4-52mm-7pp9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json diff --git a/advisories/github-reviewed/2023/12/GHSA-cw2r-4p82-qv79/GHSA-cw2r-4p82-qv79.json b/advisories/github-reviewed/2023/12/GHSA-cw2r-4p82-qv79/GHSA-cw2r-4p82-qv79.json index 7405ecb0caa..73c6c919863 100644 --- a/advisories/github-reviewed/2023/12/GHSA-cw2r-4p82-qv79/GHSA-cw2r-4p82-qv79.json +++ b/advisories/github-reviewed/2023/12/GHSA-cw2r-4p82-qv79/GHSA-cw2r-4p82-qv79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw2r-4p82-qv79", - "modified": "2024-10-10T19:07:21Z", + "modified": "2024-11-12T18:30:50Z", "published": "2023-12-28T16:36:59Z", "aliases": [ "CVE-2023-6681" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3267" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9281" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6681" diff --git a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json index 3831dc1079a..ce071998919 100644 --- a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json +++ b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-586p-749j-fhwp", - "modified": "2024-11-11T18:30:28Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-9675" @@ -64,6 +64,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9675" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9459" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9454" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:9051" diff --git a/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json b/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json index d2665e4987e..b9e84e45cd1 100644 --- a/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json +++ b/advisories/github-reviewed/2024/10/GHSA-fhqq-8f65-5xfc/GHSA-fhqq-8f65-5xfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhqq-8f65-5xfc", - "modified": "2024-11-11T18:30:28Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-10-01T21:31:35Z", "aliases": [ "CVE-2024-9407" @@ -169,6 +169,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:9051" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9454" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9459" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9407" diff --git a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json index f0f5258fd0d..54712278b7d 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json +++ b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mc76-5925-c5p6", - "modified": "2024-11-07T09:30:42Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9341" @@ -72,6 +72,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9341" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9459" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9454" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8846" diff --git a/advisories/unreviewed/2023/07/GHSA-rg52-xrwc-xm79/GHSA-rg52-xrwc-xm79.json b/advisories/unreviewed/2023/07/GHSA-rg52-xrwc-xm79/GHSA-rg52-xrwc-xm79.json index b76f4a533fd..1dca5969a2f 100644 --- a/advisories/unreviewed/2023/07/GHSA-rg52-xrwc-xm79/GHSA-rg52-xrwc-xm79.json +++ b/advisories/unreviewed/2023/07/GHSA-rg52-xrwc-xm79/GHSA-rg52-xrwc-xm79.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json b/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json index 7a71b20f8f9..2c1e9a587c6 100644 --- a/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json +++ b/advisories/unreviewed/2024/01/GHSA-59h3-54m2-3jm7/GHSA-59h3-54m2-3jm7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59h3-54m2-3jm7", - "modified": "2024-06-27T15:30:37Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-01-09T18:30:27Z", "aliases": [ "CVE-2024-0340" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3627" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9315" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0340" diff --git a/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json b/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json index ce63013552b..cca5aaa5aa6 100644 --- a/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json +++ b/advisories/unreviewed/2024/02/GHSA-g7f3-4crr-9hfj/GHSA-g7f3-4crr-9hfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7f3-4crr-9hfj", - "modified": "2024-07-24T18:31:15Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-02-11T15:30:30Z", "aliases": [ "CVE-2024-1151" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4831" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9315" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1151" diff --git a/advisories/unreviewed/2024/03/GHSA-g636-8hgg-7gx9/GHSA-g636-8hgg-7gx9.json b/advisories/unreviewed/2024/03/GHSA-g636-8hgg-7gx9/GHSA-g636-8hgg-7gx9.json index 52b33cce6d2..0b31884caed 100644 --- a/advisories/unreviewed/2024/03/GHSA-g636-8hgg-7gx9/GHSA-g636-8hgg-7gx9.json +++ b/advisories/unreviewed/2024/03/GHSA-g636-8hgg-7gx9/GHSA-g636-8hgg-7gx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g636-8hgg-7gx9", - "modified": "2024-07-03T00:34:09Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-03-18T15:30:48Z", "aliases": [ "CVE-2023-7250" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4241" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9185" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-7250" diff --git a/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json b/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json index f8b69dbe351..4cada6d6da7 100644 --- a/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json +++ b/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2gx-4fh8-wm9f", - "modified": "2024-04-25T18:30:38Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-03-07T00:30:49Z", "aliases": [ "CVE-2024-2236" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2236" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9404" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-2236" diff --git a/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json b/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json index e05071cc6c8..30d354abc72 100644 --- a/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json +++ b/advisories/unreviewed/2024/04/GHSA-jj9v-ff2v-cgx9/GHSA-jj9v-ff2v-cgx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jj9v-ff2v-cgx9", - "modified": "2024-06-26T00:31:36Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-04-04T09:30:36Z", "aliases": [ "CVE-2024-26804" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_tunnel: prevent perpetual headroom growth\n\nsyzkaller triggered following kasan splat:\nBUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170\nRead of size 1 at addr ffff88812fb4000e by task syz-executor183/5191\n[..]\n kasan_report+0xda/0x110 mm/kasan/report.c:588\n __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170\n skb_flow_dissect_flow_keys include/linux/skbuff.h:1514 [inline]\n ___skb_get_hash net/core/flow_dissector.c:1791 [inline]\n __skb_get_hash+0xc7/0x540 net/core/flow_dissector.c:1856\n skb_get_hash include/linux/skbuff.h:1556 [inline]\n ip_tunnel_xmit+0x1855/0x33c0 net/ipv4/ip_tunnel.c:748\n ipip_tunnel_xmit+0x3cc/0x4e0 net/ipv4/ipip.c:308\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3548 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3564\n __dev_queue_xmit+0x7c1/0x3d60 net/core/dev.c:4349\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n neigh_connected_output+0x42c/0x5d0 net/core/neighbour.c:1592\n ...\n ip_finish_output2+0x833/0x2550 net/ipv4/ip_output.c:235\n ip_finish_output+0x31/0x310 net/ipv4/ip_output.c:323\n ..\n iptunnel_xmit+0x5b4/0x9b0 net/ipv4/ip_tunnel_core.c:82\n ip_tunnel_xmit+0x1dbc/0x33c0 net/ipv4/ip_tunnel.c:831\n ipgre_xmit+0x4a1/0x980 net/ipv4/ip_gre.c:665\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3548 [inline]\n dev_hard_start_xmit+0x13d/0x6d0 net/core/dev.c:3564\n ...\n\nThe splat occurs because skb->data points past skb->head allocated area.\nThis is because neigh layer does:\n __skb_pull(skb, skb_network_offset(skb));\n\n... but skb_network_offset() returns a negative offset and __skb_pull()\narg is unsigned. IOW, we skb->data gets \"adjusted\" by a huge value.\n\nThe negative value is returned because skb->head and skb->data distance is\nmore than 64k and skb->network_header (u16) has wrapped around.\n\nThe bug is in the ip_tunnel infrastructure, which can cause\ndev->needed_headroom to increment ad infinitum.\n\nThe syzkaller reproducer consists of packets getting routed via a gre\ntunnel, and route of gre encapsulated packets pointing at another (ipip)\ntunnel. The ipip encapsulation finds gre0 as next output device.\n\nThis results in the following pattern:\n\n1). First packet is to be sent out via gre0.\nRoute lookup found an output device, ipip0.\n\n2).\nip_tunnel_xmit for gre0 bumps gre0->needed_headroom based on the future\noutput device, rt.dev->needed_headroom (ipip0).\n\n3).\nip output / start_xmit moves skb on to ipip0. which runs the same\ncode path again (xmit recursion).\n\n4).\nRouting step for the post-gre0-encap packet finds gre0 as output device\nto use for ipip0 encapsulated packet.\n\ntunl0->needed_headroom is then incremented based on the (already bumped)\ngre0 device headroom.\n\nThis repeats for every future packet:\n\ngre0->needed_headroom gets inflated because previous packets' ipip0 step\nincremented rt->dev (gre0) headroom, and ipip0 incremented because gre0\nneeded_headroom was increased.\n\nFor each subsequent packet, gre/ipip0->needed_headroom grows until\npost-expand-head reallocations result in a skb->head/data distance of\nmore than 64k.\n\nOnce that happens, skb->network_header (u16) wraps around when\npskb_expand_head tries to make sure that skb_network_offset() is unchanged\nafter the headroom expansion/reallocation.\n\nAfter this skb_network_offset(skb) returns a different (and negative)\nresult post headroom expansion.\n\nThe next trip to neigh layer (or anything else that would __skb_pull the\nnetwork header) makes skb->data point to a memory location outside\nskb->head area.\n\nv2: Cap the needed_headroom update to an arbitarily chosen upperlimit to\nprevent perpetual increase instead of dropping the headroom increment\ncompletely.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x2gp-p6cx-82p9/GHSA-x2gp-p6cx-82p9.json b/advisories/unreviewed/2024/04/GHSA-x2gp-p6cx-82p9/GHSA-x2gp-p6cx-82p9.json index f058abe8556..4d225f47403 100644 --- a/advisories/unreviewed/2024/04/GHSA-x2gp-p6cx-82p9/GHSA-x2gp-p6cx-82p9.json +++ b/advisories/unreviewed/2024/04/GHSA-x2gp-p6cx-82p9/GHSA-x2gp-p6cx-82p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x2gp-p6cx-82p9", - "modified": "2024-04-30T00:30:35Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-04-30T00:30:35Z", "aliases": [ "CVE-2024-34044" ], "details": "The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T00:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3f3w-qrjm-6m77/GHSA-3f3w-qrjm-6m77.json b/advisories/unreviewed/2024/05/GHSA-3f3w-qrjm-6m77/GHSA-3f3w-qrjm-6m77.json index bf62046bb9d..02fef5a336a 100644 --- a/advisories/unreviewed/2024/05/GHSA-3f3w-qrjm-6m77/GHSA-3f3w-qrjm-6m77.json +++ b/advisories/unreviewed/2024/05/GHSA-3f3w-qrjm-6m77/GHSA-3f3w-qrjm-6m77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f3w-qrjm-6m77", - "modified": "2024-05-17T15:31:09Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-05-17T15:31:09Z", "aliases": [ "CVE-2024-35797" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: cachestat: fix two shmem bugs\n\nWhen cachestat on shmem races with swapping and invalidation, there\nare two possible bugs:\n\n1) A swapin error can have resulted in a poisoned swap entry in the\n shmem inode's xarray. Calling get_shadow_from_swap_cache() on it\n will result in an out-of-bounds access to swapper_spaces[].\n\n Validate the entry with non_swap_entry() before going further.\n\n2) When we find a valid swap entry in the shmem's inode, the shadow\n entry in the swapcache might not exist yet: swap IO is still in\n progress and we're before __remove_mapping; swapin, invalidation,\n or swapoff have removed the shadow from swapcache after we saw the\n shmem swap entry.\n\n This will send a NULL to workingset_test_recent(). The latter\n purely operates on pointer bits, so it won't crash - node 0, memcg\n ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a\n bogus test. In theory that could result in a false \"recently\n evicted\" count.\n\n Such a false positive wouldn't be the end of the world. But for\n code clarity and (future) robustness, be explicit about this case.\n\n Bail on get_shadow_from_swap_cache() returning NULL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q6m5-rpfj-c92f/GHSA-q6m5-rpfj-c92f.json b/advisories/unreviewed/2024/05/GHSA-q6m5-rpfj-c92f/GHSA-q6m5-rpfj-c92f.json index 74e0c150e8f..10fef7edfde 100644 --- a/advisories/unreviewed/2024/05/GHSA-q6m5-rpfj-c92f/GHSA-q6m5-rpfj-c92f.json +++ b/advisories/unreviewed/2024/05/GHSA-q6m5-rpfj-c92f/GHSA-q6m5-rpfj-c92f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q6m5-rpfj-c92f", - "modified": "2024-05-19T09:34:46Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-05-19T09:34:46Z", "aliases": [ "CVE-2024-35878" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: module: prevent NULL pointer dereference in vsnprintf()\n\nIn of_modalias(), we can get passed the str and len parameters which would\ncause a kernel oops in vsnprintf() since it only allows passing a NULL ptr\nwhen the length is also 0. Also, we need to filter out the negative values\nof the len parameter as these will result in a really huge buffer since\nsnprintf() takes size_t parameter while ours is ssize_t...\n\nFound by Linux Verification Center (linuxtesting.org) with the Svace static\nanalysis tool.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T09:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json b/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json index 6c7dc3ea3c9..a11fa3287e3 100644 --- a/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json +++ b/advisories/unreviewed/2024/06/GHSA-cc4h-7j78-49pj/GHSA-cc4h-7j78-49pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc4h-7j78-49pj", - "modified": "2024-08-16T18:30:56Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-06-21T15:31:06Z", "aliases": [ "CVE-2024-6239" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:5305" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9167" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6239" diff --git a/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json b/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json index a94a266c976..4d44f56e61c 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json +++ b/advisories/unreviewed/2024/06/GHSA-ffhx-2rrf-9c23/GHSA-ffhx-2rrf-9c23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffhx-2rrf-9c23", - "modified": "2024-09-25T03:30:35Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-06-12T09:30:48Z", "aliases": [ "CVE-2024-5742" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6986" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9430" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-5742" diff --git a/advisories/unreviewed/2024/07/GHSA-9vqr-5j64-p9wr/GHSA-9vqr-5j64-p9wr.json b/advisories/unreviewed/2024/07/GHSA-9vqr-5j64-p9wr/GHSA-9vqr-5j64-p9wr.json index 25fa77acfdd..30e52ea8d70 100644 --- a/advisories/unreviewed/2024/07/GHSA-9vqr-5j64-p9wr/GHSA-9vqr-5j64-p9wr.json +++ b/advisories/unreviewed/2024/07/GHSA-9vqr-5j64-p9wr/GHSA-9vqr-5j64-p9wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vqr-5j64-p9wr", - "modified": "2024-07-16T18:31:41Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-07-09T15:30:54Z", "aliases": [ "CVE-2024-6604" ], "details": "Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json b/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json index 89123bab703..f6083ff4bc5 100644 --- a/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json +++ b/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9xm-vjq4-6r8q", - "modified": "2024-09-25T03:30:35Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-07-16T15:30:50Z", "aliases": [ "CVE-2024-6655" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6963" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9184" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6655" diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json index 0f8e17e31e8..377c360a2f9 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7g-wccp-rrhj", - "modified": "2024-10-01T06:30:47Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-08-05T15:30:53Z", "aliases": [ "CVE-2024-7409" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:7408" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9136" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7409" diff --git a/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json b/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json index 0ed7e3dc73e..5b2117a6957 100644 --- a/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json +++ b/advisories/unreviewed/2024/08/GHSA-94ch-6cfh-xxgc/GHSA-94ch-6cfh-xxgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94ch-6cfh-xxgc", - "modified": "2024-08-30T18:30:40Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-08-30T18:30:40Z", "aliases": [ "CVE-2024-8235" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8235" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9128" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8235" diff --git a/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json b/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json index ca92b845e4c..cd1eb52ee19 100644 --- a/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json +++ b/advisories/unreviewed/2024/08/GHSA-9qmq-f7gc-gf44/GHSA-9qmq-f7gc-gf44.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-cjc3-7r36-pp49/GHSA-cjc3-7r36-pp49.json b/advisories/unreviewed/2024/09/GHSA-cjc3-7r36-pp49/GHSA-cjc3-7r36-pp49.json index 8d867dba224..1588f3b502f 100644 --- a/advisories/unreviewed/2024/09/GHSA-cjc3-7r36-pp49/GHSA-cjc3-7r36-pp49.json +++ b/advisories/unreviewed/2024/09/GHSA-cjc3-7r36-pp49/GHSA-cjc3-7r36-pp49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjc3-7r36-pp49", - "modified": "2024-09-19T15:30:50Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-09-19T09:36:03Z", "aliases": [ "CVE-2024-45770" @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6848" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9452" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45770" diff --git a/advisories/unreviewed/2024/09/GHSA-prr3-v2fg-ggg7/GHSA-prr3-v2fg-ggg7.json b/advisories/unreviewed/2024/09/GHSA-prr3-v2fg-ggg7/GHSA-prr3-v2fg-ggg7.json index d8bb0122138..f69494edfe4 100644 --- a/advisories/unreviewed/2024/09/GHSA-prr3-v2fg-ggg7/GHSA-prr3-v2fg-ggg7.json +++ b/advisories/unreviewed/2024/09/GHSA-prr3-v2fg-ggg7/GHSA-prr3-v2fg-ggg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-prr3-v2fg-ggg7", - "modified": "2024-09-19T15:30:50Z", + "modified": "2024-11-12T18:30:50Z", "published": "2024-09-19T09:36:03Z", "aliases": [ "CVE-2024-45769" @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6848" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9452" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-45769" diff --git a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json index 2714ce8dcf5..e6788247dba 100644 --- a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json +++ b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq2p-5pc6-wpgf", - "modified": "2024-11-11T18:30:28Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-10-15T18:30:50Z", "aliases": [ "CVE-2024-9676" @@ -53,6 +53,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:9051" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9454" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:9459" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9676" diff --git a/advisories/unreviewed/2024/11/GHSA-2586-f3p4-hq84/GHSA-2586-f3p4-hq84.json b/advisories/unreviewed/2024/11/GHSA-2586-f3p4-hq84/GHSA-2586-f3p4-hq84.json new file mode 100644 index 00000000000..81fb310c06a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2586-f3p4-hq84/GHSA-2586-f3p4-hq84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2586-f3p4-hq84", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43598" + ], + "details": "LightGBM Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43598" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43598" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-268c-v4f5-27qw/GHSA-268c-v4f5-27qw.json b/advisories/unreviewed/2024/11/GHSA-268c-v4f5-27qw/GHSA-268c-v4f5-27qw.json new file mode 100644 index 00000000000..7178127bee1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-268c-v4f5-27qw/GHSA-268c-v4f5-27qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-268c-v4f5-27qw", + "modified": "2024-11-12T18:30:53Z", + "published": "2024-11-12T18:30:53Z", + "aliases": [ + "CVE-2024-11007" + ], + "details": "Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11007" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json b/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json new file mode 100644 index 00000000000..03a15a62c91 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2794-6m94-77f7/GHSA-2794-6m94-77f7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2794-6m94-77f7", + "modified": "2024-11-12T18:30:55Z", + "published": "2024-11-12T18:30:55Z", + "aliases": [ + "CVE-2024-47905" + ], + "details": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47905" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-29cm-m432-745j/GHSA-29cm-m432-745j.json b/advisories/unreviewed/2024/11/GHSA-29cm-m432-745j/GHSA-29cm-m432-745j.json new file mode 100644 index 00000000000..403f2dc20e6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-29cm-m432-745j/GHSA-29cm-m432-745j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29cm-m432-745j", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49001" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49001" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2f2h-73pp-4p79/GHSA-2f2h-73pp-4p79.json b/advisories/unreviewed/2024/11/GHSA-2f2h-73pp-4p79/GHSA-2f2h-73pp-4p79.json new file mode 100644 index 00000000000..2055303038d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2f2h-73pp-4p79/GHSA-2f2h-73pp-4p79.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f2h-73pp-4p79", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-43639" + ], + "details": "Windows Kerberos Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43639" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43639" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-197" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2gmm-fh28-fr6w/GHSA-2gmm-fh28-fr6w.json b/advisories/unreviewed/2024/11/GHSA-2gmm-fh28-fr6w/GHSA-2gmm-fh28-fr6w.json index 7f60f051a40..2a5b65c82f1 100644 --- a/advisories/unreviewed/2024/11/GHSA-2gmm-fh28-fr6w/GHSA-2gmm-fh28-fr6w.json +++ b/advisories/unreviewed/2024/11/GHSA-2gmm-fh28-fr6w/GHSA-2gmm-fh28-fr6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2gmm-fh28-fr6w", - "modified": "2024-11-09T00:30:43Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-09T00:30:43Z", "aliases": [ "CVE-2024-35424" ], "details": "vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2p4q-qc9j-27gx/GHSA-2p4q-qc9j-27gx.json b/advisories/unreviewed/2024/11/GHSA-2p4q-qc9j-27gx/GHSA-2p4q-qc9j-27gx.json new file mode 100644 index 00000000000..b0793a28ea5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2p4q-qc9j-27gx/GHSA-2p4q-qc9j-27gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p4q-qc9j-27gx", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43633" + ], + "details": "Windows Hyper-V Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43633" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43633" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2vwf-jqh3-5vjp/GHSA-2vwf-jqh3-5vjp.json b/advisories/unreviewed/2024/11/GHSA-2vwf-jqh3-5vjp/GHSA-2vwf-jqh3-5vjp.json index 4ebf32e2934..c08cfc50904 100644 --- a/advisories/unreviewed/2024/11/GHSA-2vwf-jqh3-5vjp/GHSA-2vwf-jqh3-5vjp.json +++ b/advisories/unreviewed/2024/11/GHSA-2vwf-jqh3-5vjp/GHSA-2vwf-jqh3-5vjp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-2w99-6h4v-j323/GHSA-2w99-6h4v-j323.json b/advisories/unreviewed/2024/11/GHSA-2w99-6h4v-j323/GHSA-2w99-6h4v-j323.json new file mode 100644 index 00000000000..42216339d87 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2w99-6h4v-j323/GHSA-2w99-6h4v-j323.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w99-6h4v-j323", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50319" + ], + "details": "An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50319" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-346c-j6cg-xp49/GHSA-346c-j6cg-xp49.json b/advisories/unreviewed/2024/11/GHSA-346c-j6cg-xp49/GHSA-346c-j6cg-xp49.json new file mode 100644 index 00000000000..07532734d08 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-346c-j6cg-xp49/GHSA-346c-j6cg-xp49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-346c-j6cg-xp49", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43640" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43640" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43640" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json b/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json new file mode 100644 index 00000000000..068b7dc508a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3638-r263-v9hp", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21976" + ], + "details": "Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21976" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7017.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-36jr-8w83-wr8q/GHSA-36jr-8w83-wr8q.json b/advisories/unreviewed/2024/11/GHSA-36jr-8w83-wr8q/GHSA-36jr-8w83-wr8q.json new file mode 100644 index 00000000000..1af9e50a27f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-36jr-8w83-wr8q/GHSA-36jr-8w83-wr8q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36jr-8w83-wr8q", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49050" + ], + "details": "Visual Studio Code Python Extension Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49050" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-501" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-37x8-vc3h-28p6/GHSA-37x8-vc3h-28p6.json b/advisories/unreviewed/2024/11/GHSA-37x8-vc3h-28p6/GHSA-37x8-vc3h-28p6.json new file mode 100644 index 00000000000..0e2838a9354 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-37x8-vc3h-28p6/GHSA-37x8-vc3h-28p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37x8-vc3h-28p6", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49007" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49007" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3986-r924-xxjc/GHSA-3986-r924-xxjc.json b/advisories/unreviewed/2024/11/GHSA-3986-r924-xxjc/GHSA-3986-r924-xxjc.json new file mode 100644 index 00000000000..0e0d8aebad2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3986-r924-xxjc/GHSA-3986-r924-xxjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3986-r924-xxjc", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-43646" + ], + "details": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43646" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43646" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3g36-jm7h-4mqf/GHSA-3g36-jm7h-4mqf.json b/advisories/unreviewed/2024/11/GHSA-3g36-jm7h-4mqf/GHSA-3g36-jm7h-4mqf.json new file mode 100644 index 00000000000..740ae705d7a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3g36-jm7h-4mqf/GHSA-3g36-jm7h-4mqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g36-jm7h-4mqf", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49056" + ], + "details": "Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49056" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-302" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3jfq-x5rf-pxwc/GHSA-3jfq-x5rf-pxwc.json b/advisories/unreviewed/2024/11/GHSA-3jfq-x5rf-pxwc/GHSA-3jfq-x5rf-pxwc.json new file mode 100644 index 00000000000..9fa2b340043 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3jfq-x5rf-pxwc/GHSA-3jfq-x5rf-pxwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jfq-x5rf-pxwc", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49008" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49008" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3mrx-hx45-5865/GHSA-3mrx-hx45-5865.json b/advisories/unreviewed/2024/11/GHSA-3mrx-hx45-5865/GHSA-3mrx-hx45-5865.json new file mode 100644 index 00000000000..a4743728309 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3mrx-hx45-5865/GHSA-3mrx-hx45-5865.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mrx-hx45-5865", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-43643" + ], + "details": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43643" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43643" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3q5g-jw35-qh3g/GHSA-3q5g-jw35-qh3g.json b/advisories/unreviewed/2024/11/GHSA-3q5g-jw35-qh3g/GHSA-3q5g-jw35-qh3g.json new file mode 100644 index 00000000000..0c16eb3c589 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3q5g-jw35-qh3g/GHSA-3q5g-jw35-qh3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q5g-jw35-qh3g", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49003" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49003" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3wr4-2chq-phgj/GHSA-3wr4-2chq-phgj.json b/advisories/unreviewed/2024/11/GHSA-3wr4-2chq-phgj/GHSA-3wr4-2chq-phgj.json new file mode 100644 index 00000000000..5feaa83b7fe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3wr4-2chq-phgj/GHSA-3wr4-2chq-phgj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wr4-2chq-phgj", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-10923" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. \n\nThis issue affects ALM Octane Management: from 16.2.100 through 24.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10923" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000036146?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json b/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json index 8403fa5b5e9..39a48b38302 100644 --- a/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json +++ b/advisories/unreviewed/2024/11/GHSA-434f-v35r-xr4j/GHSA-434f-v35r-xr4j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-434f-v35r-xr4j", - "modified": "2024-11-12T06:30:34Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T06:30:34Z", "aliases": [ "CVE-2024-9836" ], "details": "The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T06:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4449-mp9g-8844/GHSA-4449-mp9g-8844.json b/advisories/unreviewed/2024/11/GHSA-4449-mp9g-8844/GHSA-4449-mp9g-8844.json new file mode 100644 index 00000000000..c0675c6809c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4449-mp9g-8844/GHSA-4449-mp9g-8844.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4449-mp9g-8844", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49027" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49027" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4cgm-m7vx-9pxr/GHSA-4cgm-m7vx-9pxr.json b/advisories/unreviewed/2024/11/GHSA-4cgm-m7vx-9pxr/GHSA-4cgm-m7vx-9pxr.json new file mode 100644 index 00000000000..6f4ee9a95f4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4cgm-m7vx-9pxr/GHSA-4cgm-m7vx-9pxr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cgm-m7vx-9pxr", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49014" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49014" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4f5h-42qx-mp6w/GHSA-4f5h-42qx-mp6w.json b/advisories/unreviewed/2024/11/GHSA-4f5h-42qx-mp6w/GHSA-4f5h-42qx-mp6w.json new file mode 100644 index 00000000000..d6e180c836f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4f5h-42qx-mp6w/GHSA-4f5h-42qx-mp6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f5h-42qx-mp6w", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21957" + ], + "details": "Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21957" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9003.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4g7c-wgc5-7vr9/GHSA-4g7c-wgc5-7vr9.json b/advisories/unreviewed/2024/11/GHSA-4g7c-wgc5-7vr9/GHSA-4g7c-wgc5-7vr9.json new file mode 100644 index 00000000000..552d17a86d5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4g7c-wgc5-7vr9/GHSA-4g7c-wgc5-7vr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g7c-wgc5-7vr9", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21949" + ], + "details": "Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21949" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7017.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4gq2-x5w4-7hp8/GHSA-4gq2-x5w4-7hp8.json b/advisories/unreviewed/2024/11/GHSA-4gq2-x5w4-7hp8/GHSA-4gq2-x5w4-7hp8.json index bb3e060d04a..8f6c8884f12 100644 --- a/advisories/unreviewed/2024/11/GHSA-4gq2-x5w4-7hp8/GHSA-4gq2-x5w4-7hp8.json +++ b/advisories/unreviewed/2024/11/GHSA-4gq2-x5w4-7hp8/GHSA-4gq2-x5w4-7hp8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4jpm-2crw-5qqr/GHSA-4jpm-2crw-5qqr.json b/advisories/unreviewed/2024/11/GHSA-4jpm-2crw-5qqr/GHSA-4jpm-2crw-5qqr.json new file mode 100644 index 00000000000..9fd5f2ae5ed --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4jpm-2crw-5qqr/GHSA-4jpm-2crw-5qqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jpm-2crw-5qqr", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43452" + ], + "details": "Windows Registry Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43452" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43452" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4v4m-mgj6-c8jv/GHSA-4v4m-mgj6-c8jv.json b/advisories/unreviewed/2024/11/GHSA-4v4m-mgj6-c8jv/GHSA-4v4m-mgj6-c8jv.json new file mode 100644 index 00000000000..1d241b538e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4v4m-mgj6-c8jv/GHSA-4v4m-mgj6-c8jv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v4m-mgj6-c8jv", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43623" + ], + "details": "Windows NT OS Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43623" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4v5h-vp2v-p65r/GHSA-4v5h-vp2v-p65r.json b/advisories/unreviewed/2024/11/GHSA-4v5h-vp2v-p65r/GHSA-4v5h-vp2v-p65r.json new file mode 100644 index 00000000000..4fb2c57ee1f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4v5h-vp2v-p65r/GHSA-4v5h-vp2v-p65r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v5h-vp2v-p65r", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49015" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49015" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5777-q3q8-vhh3/GHSA-5777-q3q8-vhh3.json b/advisories/unreviewed/2024/11/GHSA-5777-q3q8-vhh3/GHSA-5777-q3q8-vhh3.json index 2f353f8cf9e..0f38624d41e 100644 --- a/advisories/unreviewed/2024/11/GHSA-5777-q3q8-vhh3/GHSA-5777-q3q8-vhh3.json +++ b/advisories/unreviewed/2024/11/GHSA-5777-q3q8-vhh3/GHSA-5777-q3q8-vhh3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5777-q3q8-vhh3", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-50601" ], "details": "Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed in versions 10.3.3.67, 10.4.42, and 10.5.29.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5888-fpmr-f2v8/GHSA-5888-fpmr-f2v8.json b/advisories/unreviewed/2024/11/GHSA-5888-fpmr-f2v8/GHSA-5888-fpmr-f2v8.json new file mode 100644 index 00000000000..ec74faeb0af --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5888-fpmr-f2v8/GHSA-5888-fpmr-f2v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5888-fpmr-f2v8", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43627" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43627" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43627" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json b/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json new file mode 100644 index 00000000000..5fc69d3d1a5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-593c-jh4c-8cw5", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50323" + ], + "details": "SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50323" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5cr8-75x7-7j9w/GHSA-5cr8-75x7-7j9w.json b/advisories/unreviewed/2024/11/GHSA-5cr8-75x7-7j9w/GHSA-5cr8-75x7-7j9w.json new file mode 100644 index 00000000000..dd85d11d0f5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5cr8-75x7-7j9w/GHSA-5cr8-75x7-7j9w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cr8-75x7-7j9w", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49002" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49002" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5ggp-35wq-jxx3/GHSA-5ggp-35wq-jxx3.json b/advisories/unreviewed/2024/11/GHSA-5ggp-35wq-jxx3/GHSA-5ggp-35wq-jxx3.json new file mode 100644 index 00000000000..1ce3ba22d5b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5ggp-35wq-jxx3/GHSA-5ggp-35wq-jxx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggp-35wq-jxx3", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49051" + ], + "details": "Microsoft PC Manager Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49051" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5hjf-mp3w-5847/GHSA-5hjf-mp3w-5847.json b/advisories/unreviewed/2024/11/GHSA-5hjf-mp3w-5847/GHSA-5hjf-mp3w-5847.json new file mode 100644 index 00000000000..899be313d4c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5hjf-mp3w-5847/GHSA-5hjf-mp3w-5847.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hjf-mp3w-5847", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21975" + ], + "details": "Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21975" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7017.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json b/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json index 8fb317c7003..04250c69dbd 100644 --- a/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json +++ b/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jpp-jp5m-8w78", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-46963" ], "details": "The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5pfq-57jv-xgm6/GHSA-5pfq-57jv-xgm6.json b/advisories/unreviewed/2024/11/GHSA-5pfq-57jv-xgm6/GHSA-5pfq-57jv-xgm6.json new file mode 100644 index 00000000000..2ac7afeefbd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5pfq-57jv-xgm6/GHSA-5pfq-57jv-xgm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pfq-57jv-xgm6", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43459" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43459" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43459" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json b/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json index 3f2cd06dca4..10762642ba0 100644 --- a/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json +++ b/advisories/unreviewed/2024/11/GHSA-5rq6-q8gw-qqpr/GHSA-5rq6-q8gw-qqpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rq6-q8gw-qqpr", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-52533" ], "details": "gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\\0' character.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5w7v-4rv8-26wg/GHSA-5w7v-4rv8-26wg.json b/advisories/unreviewed/2024/11/GHSA-5w7v-4rv8-26wg/GHSA-5w7v-4rv8-26wg.json new file mode 100644 index 00000000000..6e57fc4c1c6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5w7v-4rv8-26wg/GHSA-5w7v-4rv8-26wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w7v-4rv8-26wg", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49004" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49004" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5whg-6vqr-5wxf/GHSA-5whg-6vqr-5wxf.json b/advisories/unreviewed/2024/11/GHSA-5whg-6vqr-5wxf/GHSA-5whg-6vqr-5wxf.json new file mode 100644 index 00000000000..f1bd4300929 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5whg-6vqr-5wxf/GHSA-5whg-6vqr-5wxf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5whg-6vqr-5wxf", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43622" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43622" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43622" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5x3v-28rm-5hqx/GHSA-5x3v-28rm-5hqx.json b/advisories/unreviewed/2024/11/GHSA-5x3v-28rm-5hqx/GHSA-5x3v-28rm-5hqx.json new file mode 100644 index 00000000000..d55af359aea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5x3v-28rm-5hqx/GHSA-5x3v-28rm-5hqx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x3v-28rm-5hqx", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48996" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48996" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48996" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-64fp-9m6r-66h4/GHSA-64fp-9m6r-66h4.json b/advisories/unreviewed/2024/11/GHSA-64fp-9m6r-66h4/GHSA-64fp-9m6r-66h4.json new file mode 100644 index 00000000000..571c2e34247 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-64fp-9m6r-66h4/GHSA-64fp-9m6r-66h4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64fp-9m6r-66h4", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-8539" + ], + "details": "Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8539" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-267" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6583-5qh2-wgh7/GHSA-6583-5qh2-wgh7.json b/advisories/unreviewed/2024/11/GHSA-6583-5qh2-wgh7/GHSA-6583-5qh2-wgh7.json new file mode 100644 index 00000000000..01d71ccb789 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6583-5qh2-wgh7/GHSA-6583-5qh2-wgh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6583-5qh2-wgh7", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43631" + ], + "details": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43631" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-66pp-32jj-853p/GHSA-66pp-32jj-853p.json b/advisories/unreviewed/2024/11/GHSA-66pp-32jj-853p/GHSA-66pp-32jj-853p.json new file mode 100644 index 00000000000..f71416ab556 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-66pp-32jj-853p/GHSA-66pp-32jj-853p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66pp-32jj-853p", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43449" + ], + "details": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43449" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43449" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-67h7-pjww-p5jc/GHSA-67h7-pjww-p5jc.json b/advisories/unreviewed/2024/11/GHSA-67h7-pjww-p5jc/GHSA-67h7-pjww-p5jc.json new file mode 100644 index 00000000000..7f1381c06af --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-67h7-pjww-p5jc/GHSA-67h7-pjww-p5jc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67h7-pjww-p5jc", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-50331" + ], + "details": "An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50331" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-693v-cgfp-qgfp/GHSA-693v-cgfp-qgfp.json b/advisories/unreviewed/2024/11/GHSA-693v-cgfp-qgfp/GHSA-693v-cgfp-qgfp.json new file mode 100644 index 00000000000..1a6cb955908 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-693v-cgfp-qgfp/GHSA-693v-cgfp-qgfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-693v-cgfp-qgfp", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-43641" + ], + "details": "Windows Registry Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43641" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43641" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-696j-qh6c-q484/GHSA-696j-qh6c-q484.json b/advisories/unreviewed/2024/11/GHSA-696j-qh6c-q484/GHSA-696j-qh6c-q484.json new file mode 100644 index 00000000000..1f4a115c4f1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-696j-qh6c-q484/GHSA-696j-qh6c-q484.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-696j-qh6c-q484", + "modified": "2024-11-12T18:30:52Z", + "published": "2024-11-12T18:30:52Z", + "aliases": [ + "CVE-2024-10971" + ], + "details": "Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10971" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6p3c-4j57-9prp/GHSA-6p3c-4j57-9prp.json b/advisories/unreviewed/2024/11/GHSA-6p3c-4j57-9prp/GHSA-6p3c-4j57-9prp.json new file mode 100644 index 00000000000..4c1ed31ad67 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6p3c-4j57-9prp/GHSA-6p3c-4j57-9prp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p3c-4j57-9prp", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50317" + ], + "details": "A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50317" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json b/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json new file mode 100644 index 00000000000..e2dd6f55fb1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vf9-7q6p-x646", + "modified": "2024-11-12T18:31:00Z", + "published": "2024-11-12T18:31:00Z", + "aliases": [ + "CVE-2024-51720" + ], + "details": "An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51720" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140220" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6vj3-8x7g-gqrq/GHSA-6vj3-8x7g-gqrq.json b/advisories/unreviewed/2024/11/GHSA-6vj3-8x7g-gqrq/GHSA-6vj3-8x7g-gqrq.json new file mode 100644 index 00000000000..65e8c1d90b3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6vj3-8x7g-gqrq/GHSA-6vj3-8x7g-gqrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vj3-8x7g-gqrq", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-49514" + ], + "details": "Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49514" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/photoshop/apsb24-89.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6w96-779v-fpfh/GHSA-6w96-779v-fpfh.json b/advisories/unreviewed/2024/11/GHSA-6w96-779v-fpfh/GHSA-6w96-779v-fpfh.json new file mode 100644 index 00000000000..ec6ac0f89a0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6w96-779v-fpfh/GHSA-6w96-779v-fpfh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w96-779v-fpfh", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49046" + ], + "details": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49046" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-74fm-9mx4-7hg6/GHSA-74fm-9mx4-7hg6.json b/advisories/unreviewed/2024/11/GHSA-74fm-9mx4-7hg6/GHSA-74fm-9mx4-7hg6.json index 7b66a80e537..3b629277627 100644 --- a/advisories/unreviewed/2024/11/GHSA-74fm-9mx4-7hg6/GHSA-74fm-9mx4-7hg6.json +++ b/advisories/unreviewed/2024/11/GHSA-74fm-9mx4-7hg6/GHSA-74fm-9mx4-7hg6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-775q-3335-qhjr/GHSA-775q-3335-qhjr.json b/advisories/unreviewed/2024/11/GHSA-775q-3335-qhjr/GHSA-775q-3335-qhjr.json index d816b0ca75d..550afabbcd7 100644 --- a/advisories/unreviewed/2024/11/GHSA-775q-3335-qhjr/GHSA-775q-3335-qhjr.json +++ b/advisories/unreviewed/2024/11/GHSA-775q-3335-qhjr/GHSA-775q-3335-qhjr.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/11/GHSA-77hr-fpmg-vvgr/GHSA-77hr-fpmg-vvgr.json b/advisories/unreviewed/2024/11/GHSA-77hr-fpmg-vvgr/GHSA-77hr-fpmg-vvgr.json new file mode 100644 index 00000000000..2c3b8325ed2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-77hr-fpmg-vvgr/GHSA-77hr-fpmg-vvgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77hr-fpmg-vvgr", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48998" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48998" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48998" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79mw-jmc6-qmgj/GHSA-79mw-jmc6-qmgj.json b/advisories/unreviewed/2024/11/GHSA-79mw-jmc6-qmgj/GHSA-79mw-jmc6-qmgj.json new file mode 100644 index 00000000000..a86683adbb3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-79mw-jmc6-qmgj/GHSA-79mw-jmc6-qmgj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79mw-jmc6-qmgj", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49031" + ], + "details": "Microsoft Office Graphics Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49031" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7jpm-f32g-qv8w/GHSA-7jpm-f32g-qv8w.json b/advisories/unreviewed/2024/11/GHSA-7jpm-f32g-qv8w/GHSA-7jpm-f32g-qv8w.json new file mode 100644 index 00000000000..14b7197e88d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7jpm-f32g-qv8w/GHSA-7jpm-f32g-qv8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jpm-f32g-qv8w", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43624" + ], + "details": "Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43624" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43624" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7m49-66f5-827f/GHSA-7m49-66f5-827f.json b/advisories/unreviewed/2024/11/GHSA-7m49-66f5-827f/GHSA-7m49-66f5-827f.json new file mode 100644 index 00000000000..8816eb1ffc4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7m49-66f5-827f/GHSA-7m49-66f5-827f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m49-66f5-827f", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49011" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49011" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7wmp-2xmx-g6h8/GHSA-7wmp-2xmx-g6h8.json b/advisories/unreviewed/2024/11/GHSA-7wmp-2xmx-g6h8/GHSA-7wmp-2xmx-g6h8.json index 026cd40e8ba..bad55d912ee 100644 --- a/advisories/unreviewed/2024/11/GHSA-7wmp-2xmx-g6h8/GHSA-7wmp-2xmx-g6h8.json +++ b/advisories/unreviewed/2024/11/GHSA-7wmp-2xmx-g6h8/GHSA-7wmp-2xmx-g6h8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-7wpv-4qh2-r4fv/GHSA-7wpv-4qh2-r4fv.json b/advisories/unreviewed/2024/11/GHSA-7wpv-4qh2-r4fv/GHSA-7wpv-4qh2-r4fv.json new file mode 100644 index 00000000000..4ae076e6760 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7wpv-4qh2-r4fv/GHSA-7wpv-4qh2-r4fv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wpv-4qh2-r4fv", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50320" + ], + "details": "An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50320" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7xx8-v929-wp8r/GHSA-7xx8-v929-wp8r.json b/advisories/unreviewed/2024/11/GHSA-7xx8-v929-wp8r/GHSA-7xx8-v929-wp8r.json new file mode 100644 index 00000000000..dfeb05c1377 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7xx8-v929-wp8r/GHSA-7xx8-v929-wp8r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xx8-v929-wp8r", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49040" + ], + "details": "Microsoft Exchange Server Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49040" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49040" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-88rj-8pxh-m882/GHSA-88rj-8pxh-m882.json b/advisories/unreviewed/2024/11/GHSA-88rj-8pxh-m882/GHSA-88rj-8pxh-m882.json new file mode 100644 index 00000000000..1d59ec40f4d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-88rj-8pxh-m882/GHSA-88rj-8pxh-m882.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88rj-8pxh-m882", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49028" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49028" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8g7v-h849-8g58/GHSA-8g7v-h849-8g58.json b/advisories/unreviewed/2024/11/GHSA-8g7v-h849-8g58/GHSA-8g7v-h849-8g58.json index deef08f0e87..a6025346c7b 100644 --- a/advisories/unreviewed/2024/11/GHSA-8g7v-h849-8g58/GHSA-8g7v-h849-8g58.json +++ b/advisories/unreviewed/2024/11/GHSA-8g7v-h849-8g58/GHSA-8g7v-h849-8g58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g7v-h849-8g58", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-35421" ], "details": "vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8gvm-rm96-9p7v/GHSA-8gvm-rm96-9p7v.json b/advisories/unreviewed/2024/11/GHSA-8gvm-rm96-9p7v/GHSA-8gvm-rm96-9p7v.json new file mode 100644 index 00000000000..62719e5b0e9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8gvm-rm96-9p7v/GHSA-8gvm-rm96-9p7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gvm-rm96-9p7v", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49010" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49010" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8hgc-m8mv-wr7p/GHSA-8hgc-m8mv-wr7p.json b/advisories/unreviewed/2024/11/GHSA-8hgc-m8mv-wr7p/GHSA-8hgc-m8mv-wr7p.json new file mode 100644 index 00000000000..d72d5aae058 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8hgc-m8mv-wr7p/GHSA-8hgc-m8mv-wr7p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hgc-m8mv-wr7p", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43635" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43635" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8mjq-9vqf-24jc/GHSA-8mjq-9vqf-24jc.json b/advisories/unreviewed/2024/11/GHSA-8mjq-9vqf-24jc/GHSA-8mjq-9vqf-24jc.json new file mode 100644 index 00000000000..3def198289b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8mjq-9vqf-24jc/GHSA-8mjq-9vqf-24jc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mjq-9vqf-24jc", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49009" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49009" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json b/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json index 0248a9ec505..0802bff08c5 100644 --- a/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json +++ b/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pj5-4fw9-jfjq", - "modified": "2024-11-11T21:31:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-46965" ], "details": "The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8pwc-jhg2-h67f/GHSA-8pwc-jhg2-h67f.json b/advisories/unreviewed/2024/11/GHSA-8pwc-jhg2-h67f/GHSA-8pwc-jhg2-h67f.json new file mode 100644 index 00000000000..f195a37eb2e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8pwc-jhg2-h67f/GHSA-8pwc-jhg2-h67f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pwc-jhg2-h67f", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-38203" + ], + "details": "Windows Package Library Manager Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38203" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8rx5-xm8f-w3w5/GHSA-8rx5-xm8f-w3w5.json b/advisories/unreviewed/2024/11/GHSA-8rx5-xm8f-w3w5/GHSA-8rx5-xm8f-w3w5.json new file mode 100644 index 00000000000..7b1a4bef2bf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8rx5-xm8f-w3w5/GHSA-8rx5-xm8f-w3w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rx5-xm8f-w3w5", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43451" + ], + "details": "NTLM Hash Disclosure Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43451" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8rxm-6783-qh55/GHSA-8rxm-6783-qh55.json b/advisories/unreviewed/2024/11/GHSA-8rxm-6783-qh55/GHSA-8rxm-6783-qh55.json new file mode 100644 index 00000000000..f6897dcc2f2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8rxm-6783-qh55/GHSA-8rxm-6783-qh55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rxm-6783-qh55", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43498" + ], + "details": ".NET and Visual Studio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43498" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43498" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92jc-4j34-wj49/GHSA-92jc-4j34-wj49.json b/advisories/unreviewed/2024/11/GHSA-92jc-4j34-wj49/GHSA-92jc-4j34-wj49.json new file mode 100644 index 00000000000..5caec4683fe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92jc-4j34-wj49/GHSA-92jc-4j34-wj49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92jc-4j34-wj49", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43625" + ], + "details": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43625" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43625" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92qj-48rw-cjq8/GHSA-92qj-48rw-cjq8.json b/advisories/unreviewed/2024/11/GHSA-92qj-48rw-cjq8/GHSA-92qj-48rw-cjq8.json new file mode 100644 index 00000000000..59e6e117312 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92qj-48rw-cjq8/GHSA-92qj-48rw-cjq8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92qj-48rw-cjq8", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-10944" + ], + "details": "A Remote\nCode Execution vulnerability exists in the affected product. The vulnerability requires\na high level of permissions and exists due to improper input validation resulting\nin the possibility of a malicious Updated Agent being deployed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10944" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1710.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-93ww-rwv5-gjg4/GHSA-93ww-rwv5-gjg4.json b/advisories/unreviewed/2024/11/GHSA-93ww-rwv5-gjg4/GHSA-93ww-rwv5-gjg4.json new file mode 100644 index 00000000000..48c73b7145e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-93ww-rwv5-gjg4/GHSA-93ww-rwv5-gjg4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93ww-rwv5-gjg4", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43629" + ], + "details": "Windows DWM Core Library Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43629" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43629" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json b/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json new file mode 100644 index 00000000000..b854d12600b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99w5-q9j7-6pjv", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-9842" + ], + "details": "Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9842" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-267" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9c5m-2869-83j9/GHSA-9c5m-2869-83j9.json b/advisories/unreviewed/2024/11/GHSA-9c5m-2869-83j9/GHSA-9c5m-2869-83j9.json new file mode 100644 index 00000000000..ff4eed22fba --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9c5m-2869-83j9/GHSA-9c5m-2869-83j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c5m-2869-83j9", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21945" + ], + "details": "Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21945" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9cpc-mh5g-732x/GHSA-9cpc-mh5g-732x.json b/advisories/unreviewed/2024/11/GHSA-9cpc-mh5g-732x/GHSA-9cpc-mh5g-732x.json new file mode 100644 index 00000000000..6c679fd09c8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9cpc-mh5g-732x/GHSA-9cpc-mh5g-732x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cpc-mh5g-732x", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50321" + ], + "details": "An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50321" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json b/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json index 5aaa9f95142..b3bd6973370 100644 --- a/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json +++ b/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9ffw-88h4-2w7x", - "modified": "2024-11-08T18:30:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-50096" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error\n\nThe `nouveau_dmem_copy_one` function ensures that the copy push command is\nsent to the device firmware but does not track whether it was executed\nsuccessfully.\n\nIn the case of a copy error (e.g., firmware or hardware failure), the\ncopy push command will be sent via the firmware channel, and\n`nouveau_dmem_copy_one` will likely report success, leading to the\n`migrate_to_ram` function returning a dirty HIGH_USER page to the user.\n\nThis can result in a security vulnerability, as a HIGH_USER page that may\ncontain sensitive or corrupted data could be returned to the user.\n\nTo prevent this vulnerability, we allocate a zero page. Thus, in case of\nan error, a non-dirty (zero) page will be returned to the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T17:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9gw8-gc35-hprv/GHSA-9gw8-gc35-hprv.json b/advisories/unreviewed/2024/11/GHSA-9gw8-gc35-hprv/GHSA-9gw8-gc35-hprv.json new file mode 100644 index 00000000000..be952b6d7a3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9gw8-gc35-hprv/GHSA-9gw8-gc35-hprv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gw8-gc35-hprv", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49049" + ], + "details": "Visual Studio Code Remote Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49049" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9h99-mc2q-rgfw/GHSA-9h99-mc2q-rgfw.json b/advisories/unreviewed/2024/11/GHSA-9h99-mc2q-rgfw/GHSA-9h99-mc2q-rgfw.json new file mode 100644 index 00000000000..d59d24329ac --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9h99-mc2q-rgfw/GHSA-9h99-mc2q-rgfw.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h99-mc2q-rgfw", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-11138" + ], + "details": "A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11138" + }, + { + "type": "WEB", + "url": "https://github.com/falling-snow1/cve1/blob/main/DedeCMS%20V5.7.116%20has%20Remote%20Code%20Excute%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283977" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283977" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9r9r-hwrw-4gpj/GHSA-9r9r-hwrw-4gpj.json b/advisories/unreviewed/2024/11/GHSA-9r9r-hwrw-4gpj/GHSA-9r9r-hwrw-4gpj.json new file mode 100644 index 00000000000..6028a93bc73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9r9r-hwrw-4gpj/GHSA-9r9r-hwrw-4gpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r9r-hwrw-4gpj", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-49526" + ], + "details": "Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49526" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-76.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9rpx-w5w4-cq4r/GHSA-9rpx-w5w4-cq4r.json b/advisories/unreviewed/2024/11/GHSA-9rpx-w5w4-cq4r/GHSA-9rpx-w5w4-cq4r.json new file mode 100644 index 00000000000..fea5b26e257 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9rpx-w5w4-cq4r/GHSA-9rpx-w5w4-cq4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rpx-w5w4-cq4r", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49005" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49005" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c43q-qj38-7p5j/GHSA-c43q-qj38-7p5j.json b/advisories/unreviewed/2024/11/GHSA-c43q-qj38-7p5j/GHSA-c43q-qj38-7p5j.json new file mode 100644 index 00000000000..5a7b5dec8d3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c43q-qj38-7p5j/GHSA-c43q-qj38-7p5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c43q-qj38-7p5j", + "modified": "2024-11-12T18:31:00Z", + "published": "2024-11-12T18:31:00Z", + "aliases": [ + "CVE-2024-8068" + ], + "details": "Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8068" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c64q-8xvp-hcjx/GHSA-c64q-8xvp-hcjx.json b/advisories/unreviewed/2024/11/GHSA-c64q-8xvp-hcjx/GHSA-c64q-8xvp-hcjx.json new file mode 100644 index 00000000000..557e07c044a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c64q-8xvp-hcjx/GHSA-c64q-8xvp-hcjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c64q-8xvp-hcjx", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-49528" + ], + "details": "Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49528" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-76.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c6pq-f254-phcc/GHSA-c6pq-f254-phcc.json b/advisories/unreviewed/2024/11/GHSA-c6pq-f254-phcc/GHSA-c6pq-f254-phcc.json new file mode 100644 index 00000000000..aace05c78fd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c6pq-f254-phcc/GHSA-c6pq-f254-phcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6pq-f254-phcc", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-7571" + ], + "details": "Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7571" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-267" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json b/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json index 65ccfdfbf3a..382fdfa955d 100644 --- a/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json +++ b/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6xg-p6mw-qxxr", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-46962" ], "details": "The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-c7hj-rgqx-4m7j/GHSA-c7hj-rgqx-4m7j.json b/advisories/unreviewed/2024/11/GHSA-c7hj-rgqx-4m7j/GHSA-c7hj-rgqx-4m7j.json new file mode 100644 index 00000000000..78be8dea492 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c7hj-rgqx-4m7j/GHSA-c7hj-rgqx-4m7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7hj-rgqx-4m7j", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-38255" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38255" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json b/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json index 237d24d5eec..a390272ec26 100644 --- a/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json +++ b/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c884-h6q9-jjwg", - "modified": "2024-11-05T18:32:11Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-50098" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Set SDEV_OFFLINE when UFS is shut down\n\nThere is a history of deadlock if reboot is performed at the beginning\nof booting. SDEV_QUIESCE was set for all LU's scsi_devices by UFS\nshutdown, and at that time the audio driver was waiting on\nblk_mq_submit_bio() holding a mutex_lock while reading the fw binary.\nAfter that, a deadlock issue occurred while audio driver shutdown was\nwaiting for mutex_unlock of blk_mq_submit_bio(). To solve this, set\nSDEV_OFFLINE for all LUs except WLUN, so that any I/O that comes down\nafter a UFS shutdown will return an error.\n\n[ 31.907781]I[0: swapper/0: 0] 1 130705007 1651079834 11289729804 0 D( 2) 3 ffffff882e208000 * init [device_shutdown]\n[ 31.907793]I[0: swapper/0: 0] Mutex: 0xffffff8849a2b8b0: owner[0xffffff882e28cb00 kworker/6:0 :49]\n[ 31.907806]I[0: swapper/0: 0] Call trace:\n[ 31.907810]I[0: swapper/0: 0] __switch_to+0x174/0x338\n[ 31.907819]I[0: swapper/0: 0] __schedule+0x5ec/0x9cc\n[ 31.907826]I[0: swapper/0: 0] schedule+0x7c/0xe8\n[ 31.907834]I[0: swapper/0: 0] schedule_preempt_disabled+0x24/0x40\n[ 31.907842]I[0: swapper/0: 0] __mutex_lock+0x408/0xdac\n[ 31.907849]I[0: swapper/0: 0] __mutex_lock_slowpath+0x14/0x24\n[ 31.907858]I[0: swapper/0: 0] mutex_lock+0x40/0xec\n[ 31.907866]I[0: swapper/0: 0] device_shutdown+0x108/0x280\n[ 31.907875]I[0: swapper/0: 0] kernel_restart+0x4c/0x11c\n[ 31.907883]I[0: swapper/0: 0] __arm64_sys_reboot+0x15c/0x280\n[ 31.907890]I[0: swapper/0: 0] invoke_syscall+0x70/0x158\n[ 31.907899]I[0: swapper/0: 0] el0_svc_common+0xb4/0xf4\n[ 31.907909]I[0: swapper/0: 0] do_el0_svc+0x2c/0xb0\n[ 31.907918]I[0: swapper/0: 0] el0_svc+0x34/0xe0\n[ 31.907928]I[0: swapper/0: 0] el0t_64_sync_handler+0x68/0xb4\n[ 31.907937]I[0: swapper/0: 0] el0t_64_sync+0x1a0/0x1a4\n\n[ 31.908774]I[0: swapper/0: 0] 49 0 11960702 11236868007 0 D( 2) 6 ffffff882e28cb00 * kworker/6:0 [__bio_queue_enter]\n[ 31.908783]I[0: swapper/0: 0] Call trace:\n[ 31.908788]I[0: swapper/0: 0] __switch_to+0x174/0x338\n[ 31.908796]I[0: swapper/0: 0] __schedule+0x5ec/0x9cc\n[ 31.908803]I[0: swapper/0: 0] schedule+0x7c/0xe8\n[ 31.908811]I[0: swapper/0: 0] __bio_queue_enter+0xb8/0x178\n[ 31.908818]I[0: swapper/0: 0] blk_mq_submit_bio+0x194/0x67c\n[ 31.908827]I[0: swapper/0: 0] __submit_bio+0xb8/0x19c", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T18:15:13Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cmh5-78pc-x57w/GHSA-cmh5-78pc-x57w.json b/advisories/unreviewed/2024/11/GHSA-cmh5-78pc-x57w/GHSA-cmh5-78pc-x57w.json new file mode 100644 index 00000000000..8ccf26c303b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cmh5-78pc-x57w/GHSA-cmh5-78pc-x57w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmh5-78pc-x57w", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21937" + ], + "details": "Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21937" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6015.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cx2c-rv87-9m6p/GHSA-cx2c-rv87-9m6p.json b/advisories/unreviewed/2024/11/GHSA-cx2c-rv87-9m6p/GHSA-cx2c-rv87-9m6p.json new file mode 100644 index 00000000000..3f521b3b2e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cx2c-rv87-9m6p/GHSA-cx2c-rv87-9m6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx2c-rv87-9m6p", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21958" + ], + "details": "Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21958" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9007.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json b/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json index 7392521c0be..befe3490f3c 100644 --- a/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json +++ b/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx99-h4rf-2j49", - "modified": "2024-11-11T21:31:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-50667" ], "details": "The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T19:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-f2vc-g638-2wm6/GHSA-f2vc-g638-2wm6.json b/advisories/unreviewed/2024/11/GHSA-f2vc-g638-2wm6/GHSA-f2vc-g638-2wm6.json new file mode 100644 index 00000000000..b8c10241382 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f2vc-g638-2wm6/GHSA-f2vc-g638-2wm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2vc-g638-2wm6", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-38264" + ], + "details": "Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38264" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38264" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f3v6-qmvg-fhwg/GHSA-f3v6-qmvg-fhwg.json b/advisories/unreviewed/2024/11/GHSA-f3v6-qmvg-fhwg/GHSA-f3v6-qmvg-fhwg.json new file mode 100644 index 00000000000..16672aa0bf1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f3v6-qmvg-fhwg/GHSA-f3v6-qmvg-fhwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3v6-qmvg-fhwg", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43602" + ], + "details": "Azure CycleCloud Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43602" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43602" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f7x3-3w29-5xxp/GHSA-f7x3-3w29-5xxp.json b/advisories/unreviewed/2024/11/GHSA-f7x3-3w29-5xxp/GHSA-f7x3-3w29-5xxp.json new file mode 100644 index 00000000000..30de7ea63a2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f7x3-3w29-5xxp/GHSA-f7x3-3w29-5xxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7x3-3w29-5xxp", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-49527" + ], + "details": "Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49527" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/animate/apsb24-76.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fgm4-wh6f-2pxc/GHSA-fgm4-wh6f-2pxc.json b/advisories/unreviewed/2024/11/GHSA-fgm4-wh6f-2pxc/GHSA-fgm4-wh6f-2pxc.json new file mode 100644 index 00000000000..6b758a605db --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fgm4-wh6f-2pxc/GHSA-fgm4-wh6f-2pxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgm4-wh6f-2pxc", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43637" + ], + "details": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43637" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43637" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fgq7-v63g-3f6x/GHSA-fgq7-v63g-3f6x.json b/advisories/unreviewed/2024/11/GHSA-fgq7-v63g-3f6x/GHSA-fgq7-v63g-3f6x.json new file mode 100644 index 00000000000..adba8796ddd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fgq7-v63g-3f6x/GHSA-fgq7-v63g-3f6x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgq7-v63g-3f6x", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-9999" + ], + "details": "In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9999" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2024" + }, + { + "type": "WEB", + "url": "https://www.progress.com/ftp-server" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fh4x-8p68-8qg2/GHSA-fh4x-8p68-8qg2.json b/advisories/unreviewed/2024/11/GHSA-fh4x-8p68-8qg2/GHSA-fh4x-8p68-8qg2.json new file mode 100644 index 00000000000..dfe0d7a9ed4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fh4x-8p68-8qg2/GHSA-fh4x-8p68-8qg2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh4x-8p68-8qg2", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48997" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48997" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48997" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fh5q-gf2c-rgx3/GHSA-fh5q-gf2c-rgx3.json b/advisories/unreviewed/2024/11/GHSA-fh5q-gf2c-rgx3/GHSA-fh5q-gf2c-rgx3.json new file mode 100644 index 00000000000..0db961beac9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fh5q-gf2c-rgx3/GHSA-fh5q-gf2c-rgx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh5q-gf2c-rgx3", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49026" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49026" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json b/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json new file mode 100644 index 00000000000..3e54031a2a0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frfr-qxrr-f897", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50327" + ], + "details": "SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50327" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fxcg-68j8-mh5m/GHSA-fxcg-68j8-mh5m.json b/advisories/unreviewed/2024/11/GHSA-fxcg-68j8-mh5m/GHSA-fxcg-68j8-mh5m.json index ab63025263a..57808aa7011 100644 --- a/advisories/unreviewed/2024/11/GHSA-fxcg-68j8-mh5m/GHSA-fxcg-68j8-mh5m.json +++ b/advisories/unreviewed/2024/11/GHSA-fxcg-68j8-mh5m/GHSA-fxcg-68j8-mh5m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxcg-68j8-mh5m", - "modified": "2024-11-09T00:30:43Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-09T00:30:43Z", "aliases": [ "CVE-2024-35423" ], "details": "vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g5vp-j278-8pjh/GHSA-g5vp-j278-8pjh.json b/advisories/unreviewed/2024/11/GHSA-g5vp-j278-8pjh/GHSA-g5vp-j278-8pjh.json new file mode 100644 index 00000000000..68f311cd080 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g5vp-j278-8pjh/GHSA-g5vp-j278-8pjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5vp-j278-8pjh", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49048" + ], + "details": "TorchGeo Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49048" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json b/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json index b20da165419..96da93ae923 100644 --- a/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json +++ b/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6gg-3vqf-rfrx", - "modified": "2024-11-11T21:31:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-48322" ], "details": "UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json b/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json new file mode 100644 index 00000000000..d06836fcc6a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g79m-w87v-w7c8/GHSA-g79m-w87v-w7c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g79m-w87v-w7c8", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-47909" + ], + "details": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47909" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gpjf-59wh-632x/GHSA-gpjf-59wh-632x.json b/advisories/unreviewed/2024/11/GHSA-gpjf-59wh-632x/GHSA-gpjf-59wh-632x.json new file mode 100644 index 00000000000..a230a7038c6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpjf-59wh-632x/GHSA-gpjf-59wh-632x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpjf-59wh-632x", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-8495" + ], + "details": "A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8495" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gpm6-xpxh-fvfp/GHSA-gpm6-xpxh-fvfp.json b/advisories/unreviewed/2024/11/GHSA-gpm6-xpxh-fvfp/GHSA-gpm6-xpxh-fvfp.json new file mode 100644 index 00000000000..e4e38b0f39b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpm6-xpxh-fvfp/GHSA-gpm6-xpxh-fvfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpm6-xpxh-fvfp", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-11006" + ], + "details": "Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11006" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gwgp-7jjg-774v/GHSA-gwgp-7jjg-774v.json b/advisories/unreviewed/2024/11/GHSA-gwgp-7jjg-774v/GHSA-gwgp-7jjg-774v.json index e7101749a40..5d7fe819615 100644 --- a/advisories/unreviewed/2024/11/GHSA-gwgp-7jjg-774v/GHSA-gwgp-7jjg-774v.json +++ b/advisories/unreviewed/2024/11/GHSA-gwgp-7jjg-774v/GHSA-gwgp-7jjg-774v.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-h4mv-24rm-583r/GHSA-h4mv-24rm-583r.json b/advisories/unreviewed/2024/11/GHSA-h4mv-24rm-583r/GHSA-h4mv-24rm-583r.json new file mode 100644 index 00000000000..394eac5f15a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h4mv-24rm-583r/GHSA-h4mv-24rm-583r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4mv-24rm-583r", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49030" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49030" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h4qj-345r-3p67/GHSA-h4qj-345r-3p67.json b/advisories/unreviewed/2024/11/GHSA-h4qj-345r-3p67/GHSA-h4qj-345r-3p67.json new file mode 100644 index 00000000000..26bec7afed3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h4qj-345r-3p67/GHSA-h4qj-345r-3p67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4qj-345r-3p67", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49012" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49012" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h644-m8cx-x9h6/GHSA-h644-m8cx-x9h6.json b/advisories/unreviewed/2024/11/GHSA-h644-m8cx-x9h6/GHSA-h644-m8cx-x9h6.json index 7e643c29880..837cef4e859 100644 --- a/advisories/unreviewed/2024/11/GHSA-h644-m8cx-x9h6/GHSA-h644-m8cx-x9h6.json +++ b/advisories/unreviewed/2024/11/GHSA-h644-m8cx-x9h6/GHSA-h644-m8cx-x9h6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h644-m8cx-x9h6", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-35419" ], "details": "wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json b/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json new file mode 100644 index 00000000000..539db496c89 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7w7-g9gg-4q8w", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-50329" + ], + "details": "Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50329" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h8m5-j25m-72g2/GHSA-h8m5-j25m-72g2.json b/advisories/unreviewed/2024/11/GHSA-h8m5-j25m-72g2/GHSA-h8m5-j25m-72g2.json index 348527fc061..ec2307c20b0 100644 --- a/advisories/unreviewed/2024/11/GHSA-h8m5-j25m-72g2/GHSA-h8m5-j25m-72g2.json +++ b/advisories/unreviewed/2024/11/GHSA-h8m5-j25m-72g2/GHSA-h8m5-j25m-72g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8m5-j25m-72g2", - "modified": "2024-11-09T00:30:43Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-09T00:30:43Z", "aliases": [ "CVE-2024-35427" ], "details": "vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hj7x-pcrh-84jj/GHSA-hj7x-pcrh-84jj.json b/advisories/unreviewed/2024/11/GHSA-hj7x-pcrh-84jj/GHSA-hj7x-pcrh-84jj.json new file mode 100644 index 00000000000..8e618b1bff5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hj7x-pcrh-84jj/GHSA-hj7x-pcrh-84jj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj7x-pcrh-84jj", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49000" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49000" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49000" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hjgc-jxjc-8v9j/GHSA-hjgc-jxjc-8v9j.json b/advisories/unreviewed/2024/11/GHSA-hjgc-jxjc-8v9j/GHSA-hjgc-jxjc-8v9j.json index 9253ea1b764..bedd2e97db3 100644 --- a/advisories/unreviewed/2024/11/GHSA-hjgc-jxjc-8v9j/GHSA-hjgc-jxjc-8v9j.json +++ b/advisories/unreviewed/2024/11/GHSA-hjgc-jxjc-8v9j/GHSA-hjgc-jxjc-8v9j.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hprc-66gh-5q8w/GHSA-hprc-66gh-5q8w.json b/advisories/unreviewed/2024/11/GHSA-hprc-66gh-5q8w/GHSA-hprc-66gh-5q8w.json new file mode 100644 index 00000000000..813274c3065 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hprc-66gh-5q8w/GHSA-hprc-66gh-5q8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hprc-66gh-5q8w", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49032" + ], + "details": "Microsoft Office Graphics Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49032" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hqx6-xxcj-4chg/GHSA-hqx6-xxcj-4chg.json b/advisories/unreviewed/2024/11/GHSA-hqx6-xxcj-4chg/GHSA-hqx6-xxcj-4chg.json new file mode 100644 index 00000000000..aa058570292 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hqx6-xxcj-4chg/GHSA-hqx6-xxcj-4chg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqx6-xxcj-4chg", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43628" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43628" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json b/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json index 6d894bfb66d..9d3e6928663 100644 --- a/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json +++ b/advisories/unreviewed/2024/11/GHSA-hw6j-ph25-g43c/GHSA-hw6j-ph25-g43c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw6j-ph25-g43c", - "modified": "2024-11-12T06:30:35Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T06:30:35Z", "aliases": [ "CVE-2024-9835" ], "details": "The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T06:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hx47-p5gg-xw55/GHSA-hx47-p5gg-xw55.json b/advisories/unreviewed/2024/11/GHSA-hx47-p5gg-xw55/GHSA-hx47-p5gg-xw55.json new file mode 100644 index 00000000000..c0dab44b3a7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hx47-p5gg-xw55/GHSA-hx47-p5gg-xw55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx47-p5gg-xw55", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49017" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49017" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j85c-4frx-f93r/GHSA-j85c-4frx-f93r.json b/advisories/unreviewed/2024/11/GHSA-j85c-4frx-f93r/GHSA-j85c-4frx-f93r.json new file mode 100644 index 00000000000..433e90cf50a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j85c-4frx-f93r/GHSA-j85c-4frx-f93r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j85c-4frx-f93r", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49021" + ], + "details": "Microsoft SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49021" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jc4h-vrmv-7c33/GHSA-jc4h-vrmv-7c33.json b/advisories/unreviewed/2024/11/GHSA-jc4h-vrmv-7c33/GHSA-jc4h-vrmv-7c33.json new file mode 100644 index 00000000000..fc2243e7066 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jc4h-vrmv-7c33/GHSA-jc4h-vrmv-7c33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc4h-vrmv-7c33", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21946" + ], + "details": "Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21946" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9004.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json b/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json new file mode 100644 index 00000000000..a36ed8741b0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcjw-frm7-94f5", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-9843" + ], + "details": "A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9843" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jgw6-7hrc-742j/GHSA-jgw6-7hrc-742j.json b/advisories/unreviewed/2024/11/GHSA-jgw6-7hrc-742j/GHSA-jgw6-7hrc-742j.json new file mode 100644 index 00000000000..17193d1248a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jgw6-7hrc-742j/GHSA-jgw6-7hrc-742j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgw6-7hrc-742j", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48994" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48994" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48994" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jjp9-999r-m9vg/GHSA-jjp9-999r-m9vg.json b/advisories/unreviewed/2024/11/GHSA-jjp9-999r-m9vg/GHSA-jjp9-999r-m9vg.json new file mode 100644 index 00000000000..b65627ebafd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jjp9-999r-m9vg/GHSA-jjp9-999r-m9vg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjp9-999r-m9vg", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49006" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49006" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jmf3-9f5j-cpjh/GHSA-jmf3-9f5j-cpjh.json b/advisories/unreviewed/2024/11/GHSA-jmf3-9f5j-cpjh/GHSA-jmf3-9f5j-cpjh.json new file mode 100644 index 00000000000..8135d055e33 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jmf3-9f5j-cpjh/GHSA-jmf3-9f5j-cpjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmf3-9f5j-cpjh", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49039" + ], + "details": "Windows Task Scheduler Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49039" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jpf2-9ppp-2c49/GHSA-jpf2-9ppp-2c49.json b/advisories/unreviewed/2024/11/GHSA-jpf2-9ppp-2c49/GHSA-jpf2-9ppp-2c49.json index 3d6620ff4b8..619950c275f 100644 --- a/advisories/unreviewed/2024/11/GHSA-jpf2-9ppp-2c49/GHSA-jpf2-9ppp-2c49.json +++ b/advisories/unreviewed/2024/11/GHSA-jpf2-9ppp-2c49/GHSA-jpf2-9ppp-2c49.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jrf6-24wc-4wx7/GHSA-jrf6-24wc-4wx7.json b/advisories/unreviewed/2024/11/GHSA-jrf6-24wc-4wx7/GHSA-jrf6-24wc-4wx7.json new file mode 100644 index 00000000000..58c5a75af0d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jrf6-24wc-4wx7/GHSA-jrf6-24wc-4wx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrf6-24wc-4wx7", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-21974" + ], + "details": "Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21974" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7017.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json b/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json new file mode 100644 index 00000000000..65da75d3840 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxvj-5w26-hpx9", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50328" + ], + "details": "SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50328" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m923-5xpw-m3wf/GHSA-m923-5xpw-m3wf.json b/advisories/unreviewed/2024/11/GHSA-m923-5xpw-m3wf/GHSA-m923-5xpw-m3wf.json new file mode 100644 index 00000000000..b58edeb11c3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m923-5xpw-m3wf/GHSA-m923-5xpw-m3wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m923-5xpw-m3wf", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21938" + ], + "details": "Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21938" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9005.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m9rx-mmjv-j7v6/GHSA-m9rx-mmjv-j7v6.json b/advisories/unreviewed/2024/11/GHSA-m9rx-mmjv-j7v6/GHSA-m9rx-mmjv-j7v6.json new file mode 100644 index 00000000000..6c25342d318 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m9rx-mmjv-j7v6/GHSA-m9rx-mmjv-j7v6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9rx-mmjv-j7v6", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-11005" + ], + "details": "Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11005" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mfc7-3m73-fjf3/GHSA-mfc7-3m73-fjf3.json b/advisories/unreviewed/2024/11/GHSA-mfc7-3m73-fjf3/GHSA-mfc7-3m73-fjf3.json new file mode 100644 index 00000000000..c1bb07bafbc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mfc7-3m73-fjf3/GHSA-mfc7-3m73-fjf3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfc7-3m73-fjf3", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-10943" + ], + "details": "An\nauthentication bypass vulnerability exists in the affected product. The\nvulnerability exists due to shared secrets across accounts and could allow a threat\nactor to impersonate a user if the threat actor is able to enumerate additional\ninformation required during authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10943" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1710.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mgh2-q3fc-jjmr/GHSA-mgh2-q3fc-jjmr.json b/advisories/unreviewed/2024/11/GHSA-mgh2-q3fc-jjmr/GHSA-mgh2-q3fc-jjmr.json new file mode 100644 index 00000000000..bb12e1488ef --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mgh2-q3fc-jjmr/GHSA-mgh2-q3fc-jjmr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgh2-q3fc-jjmr", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-49521" + ], + "details": "Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49521" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb24-90.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mm7h-86pj-q87p/GHSA-mm7h-86pj-q87p.json b/advisories/unreviewed/2024/11/GHSA-mm7h-86pj-q87p/GHSA-mm7h-86pj-q87p.json new file mode 100644 index 00000000000..16e1ee80a8c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mm7h-86pj-q87p/GHSA-mm7h-86pj-q87p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm7h-86pj-q87p", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-11004" + ], + "details": "Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11004" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json b/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json new file mode 100644 index 00000000000..dbd0c2114de --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq3p-r846-c5mx", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50324" + ], + "details": "Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50324" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mrxr-g8pq-3495/GHSA-mrxr-g8pq-3495.json b/advisories/unreviewed/2024/11/GHSA-mrxr-g8pq-3495/GHSA-mrxr-g8pq-3495.json new file mode 100644 index 00000000000..ef7cc7b7ec8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mrxr-g8pq-3495/GHSA-mrxr-g8pq-3495.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrxr-g8pq-3495", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48995" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48995" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48995" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mx5f-vqxg-86w4/GHSA-mx5f-vqxg-86w4.json b/advisories/unreviewed/2024/11/GHSA-mx5f-vqxg-86w4/GHSA-mx5f-vqxg-86w4.json index 416f69637a0..696b636aa4c 100644 --- a/advisories/unreviewed/2024/11/GHSA-mx5f-vqxg-86w4/GHSA-mx5f-vqxg-86w4.json +++ b/advisories/unreviewed/2024/11/GHSA-mx5f-vqxg-86w4/GHSA-mx5f-vqxg-86w4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-p2rj-qgfh-h8m9/GHSA-p2rj-qgfh-h8m9.json b/advisories/unreviewed/2024/11/GHSA-p2rj-qgfh-h8m9/GHSA-p2rj-qgfh-h8m9.json new file mode 100644 index 00000000000..01047df1f3d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p2rj-qgfh-h8m9/GHSA-p2rj-qgfh-h8m9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2rj-qgfh-h8m9", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49019" + ], + "details": "Active Directory Certificate Services Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49019" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p3qp-q8pw-qf3p/GHSA-p3qp-q8pw-qf3p.json b/advisories/unreviewed/2024/11/GHSA-p3qp-q8pw-qf3p/GHSA-p3qp-q8pw-qf3p.json new file mode 100644 index 00000000000..b3948d42867 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p3qp-q8pw-qf3p/GHSA-p3qp-q8pw-qf3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3qp-q8pw-qf3p", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49043" + ], + "details": "Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49043" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p6vx-vqj8-q8r8/GHSA-p6vx-vqj8-q8r8.json b/advisories/unreviewed/2024/11/GHSA-p6vx-vqj8-q8r8/GHSA-p6vx-vqj8-q8r8.json new file mode 100644 index 00000000000..3701016d1f1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p6vx-vqj8-q8r8/GHSA-p6vx-vqj8-q8r8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6vx-vqj8-q8r8", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48993" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48993" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json b/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json index 056a7598bc9..c294b5b1d3d 100644 --- a/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json +++ b/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pg35-867h-jm8h", - "modified": "2024-11-09T00:30:43Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-09T00:30:43Z", "aliases": [ "CVE-2024-35426" ], "details": "vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json b/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json index 45e4eada29f..ced3f75455f 100644 --- a/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json +++ b/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pgrc-8wp5-5mvq", - "modified": "2024-11-11T21:31:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-51135" ], "details": "An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T19:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-phrc-779j-3268/GHSA-phrc-779j-3268.json b/advisories/unreviewed/2024/11/GHSA-phrc-779j-3268/GHSA-phrc-779j-3268.json new file mode 100644 index 00000000000..c18bc53c777 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-phrc-779j-3268/GHSA-phrc-779j-3268.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phrc-779j-3268", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-43645" + ], + "details": "Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43645" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43645" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json b/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json index b65ab1e9fc0..63fab7ea01d 100644 --- a/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json +++ b/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pj67-hxcx-g74v", - "modified": "2024-11-08T18:30:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-50099" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: probes: Remove broken LDR (literal) uprobe support\n\nThe simulate_ldr_literal() and simulate_ldrsw_literal() functions are\nunsafe to use for uprobes. Both functions were originally written for\nuse with kprobes, and access memory with plain C accesses. When uprobes\nwas added, these were reused unmodified even though they cannot safely\naccess user memory.\n\nThere are three key problems:\n\n1) The plain C accesses do not have corresponding extable entries, and\n thus if they encounter a fault the kernel will treat these as\n unintentional accesses to user memory, resulting in a BUG() which\n will kill the kernel thread, and likely lead to further issues (e.g.\n lockup or panic()).\n\n2) The plain C accesses are subject to HW PAN and SW PAN, and so when\n either is in use, any attempt to simulate an access to user memory\n will fault. Thus neither simulate_ldr_literal() nor\n simulate_ldrsw_literal() can do anything useful when simulating a\n user instruction on any system with HW PAN or SW PAN.\n\n3) The plain C accesses are privileged, as they run in kernel context,\n and in practice can access a small range of kernel virtual addresses.\n The instructions they simulate have a range of +/-1MiB, and since the\n simulated instructions must itself be a user instructions in the\n TTBR0 address range, these can address the final 1MiB of the TTBR1\n acddress range by wrapping downwards from an address in the first\n 1MiB of the TTBR0 address range.\n\n In contemporary kernels the last 8MiB of TTBR1 address range is\n reserved, and accesses to this will always fault, meaning this is no\n worse than (1).\n\n Historically, it was theoretically possible for the linear map or\n vmemmap to spill into the final 8MiB of the TTBR1 address range, but\n in practice this is extremely unlikely to occur as this would\n require either:\n\n * Having enough physical memory to fill the entire linear map all the\n way to the final 1MiB of the TTBR1 address range.\n\n * Getting unlucky with KASLR randomization of the linear map such\n that the populated region happens to overlap with the last 1MiB of\n the TTBR address range.\n\n ... and in either case if we were to spill into the final page there\n would be larger problems as the final page would alias with error\n pointers.\n\nPractically speaking, (1) and (2) are the big issues. Given there have\nbeen no reports of problems since the broken code was introduced, it\nappears that no-one is relying on probing these instructions with\nuprobes.\n\nAvoid these issues by not allowing uprobes on LDR (literal) and LDRSW\n(literal), limiting the use of simulate_ldr_literal() and\nsimulate_ldrsw_literal() to kprobes. Attempts to place uprobes on LDR\n(literal) and LDRSW (literal) will be rejected as\narm_probe_decode_insn() will return INSN_REJECTED. In future we can\nconsider introducing working uprobes support for these instructions, but\nthis will require more significant work.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T18:15:13Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pq55-r4g8-r76q/GHSA-pq55-r4g8-r76q.json b/advisories/unreviewed/2024/11/GHSA-pq55-r4g8-r76q/GHSA-pq55-r4g8-r76q.json index 5d663d43b9d..88cbb4e085e 100644 --- a/advisories/unreviewed/2024/11/GHSA-pq55-r4g8-r76q/GHSA-pq55-r4g8-r76q.json +++ b/advisories/unreviewed/2024/11/GHSA-pq55-r4g8-r76q/GHSA-pq55-r4g8-r76q.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pxx2-jxr9-c92g/GHSA-pxx2-jxr9-c92g.json b/advisories/unreviewed/2024/11/GHSA-pxx2-jxr9-c92g/GHSA-pxx2-jxr9-c92g.json new file mode 100644 index 00000000000..9e74040273e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pxx2-jxr9-c92g/GHSA-pxx2-jxr9-c92g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxx2-jxr9-c92g", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49018" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49018" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-197" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q85x-jh7r-gh5h/GHSA-q85x-jh7r-gh5h.json b/advisories/unreviewed/2024/11/GHSA-q85x-jh7r-gh5h/GHSA-q85x-jh7r-gh5h.json new file mode 100644 index 00000000000..9e7e61d58d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q85x-jh7r-gh5h/GHSA-q85x-jh7r-gh5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q85x-jh7r-gh5h", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49044" + ], + "details": "Visual Studio Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49044" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q8fc-2r64-8hq5/GHSA-q8fc-2r64-8hq5.json b/advisories/unreviewed/2024/11/GHSA-q8fc-2r64-8hq5/GHSA-q8fc-2r64-8hq5.json new file mode 100644 index 00000000000..d02b01aea03 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q8fc-2r64-8hq5/GHSA-q8fc-2r64-8hq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8fc-2r64-8hq5", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-9420" + ], + "details": "A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9420" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q99x-mjmh-v8w7/GHSA-q99x-mjmh-v8w7.json b/advisories/unreviewed/2024/11/GHSA-q99x-mjmh-v8w7/GHSA-q99x-mjmh-v8w7.json index 7aee238b331..6595963daee 100644 --- a/advisories/unreviewed/2024/11/GHSA-q99x-mjmh-v8w7/GHSA-q99x-mjmh-v8w7.json +++ b/advisories/unreviewed/2024/11/GHSA-q99x-mjmh-v8w7/GHSA-q99x-mjmh-v8w7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qc59-4rgm-3c5c/GHSA-qc59-4rgm-3c5c.json b/advisories/unreviewed/2024/11/GHSA-qc59-4rgm-3c5c/GHSA-qc59-4rgm-3c5c.json new file mode 100644 index 00000000000..e9700afde0f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qc59-4rgm-3c5c/GHSA-qc59-4rgm-3c5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc59-4rgm-3c5c", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49016" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49016" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qf7x-grg9-4j2x/GHSA-qf7x-grg9-4j2x.json b/advisories/unreviewed/2024/11/GHSA-qf7x-grg9-4j2x/GHSA-qf7x-grg9-4j2x.json index 2f7b7075847..444487135c8 100644 --- a/advisories/unreviewed/2024/11/GHSA-qf7x-grg9-4j2x/GHSA-qf7x-grg9-4j2x.json +++ b/advisories/unreviewed/2024/11/GHSA-qf7x-grg9-4j2x/GHSA-qf7x-grg9-4j2x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qjr4-pwpg-c5m3/GHSA-qjr4-pwpg-c5m3.json b/advisories/unreviewed/2024/11/GHSA-qjr4-pwpg-c5m3/GHSA-qjr4-pwpg-c5m3.json new file mode 100644 index 00000000000..c9dd3d56c8d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qjr4-pwpg-c5m3/GHSA-qjr4-pwpg-c5m3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjr4-pwpg-c5m3", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-10945" + ], + "details": "A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10945" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1710.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json b/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json index d9b3e2ce69c..7a0d8b05c2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json +++ b/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpj8-6r97-qxq6", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-46966" ], "details": "The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qx56-hjgg-8xgm/GHSA-qx56-hjgg-8xgm.json b/advisories/unreviewed/2024/11/GHSA-qx56-hjgg-8xgm/GHSA-qx56-hjgg-8xgm.json new file mode 100644 index 00000000000..61e1c132ac4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qx56-hjgg-8xgm/GHSA-qx56-hjgg-8xgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx56-hjgg-8xgm", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43447" + ], + "details": "Windows SMBv3 Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43447" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qx8r-w7wr-86w4/GHSA-qx8r-w7wr-86w4.json b/advisories/unreviewed/2024/11/GHSA-qx8r-w7wr-86w4/GHSA-qx8r-w7wr-86w4.json new file mode 100644 index 00000000000..b7ad55de0dc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qx8r-w7wr-86w4/GHSA-qx8r-w7wr-86w4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx8r-w7wr-86w4", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-21939" + ], + "details": "Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21939" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9006.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxf2-gf78-5hgp/GHSA-qxf2-gf78-5hgp.json b/advisories/unreviewed/2024/11/GHSA-qxf2-gf78-5hgp/GHSA-qxf2-gf78-5hgp.json new file mode 100644 index 00000000000..a6a987fd23e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qxf2-gf78-5hgp/GHSA-qxf2-gf78-5hgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxf2-gf78-5hgp", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43636" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43636" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43636" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json b/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json new file mode 100644 index 00000000000..21923171eeb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxwc-wcvf-47fq", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50322" + ], + "details": "Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50322" + }, + { + "type": "WEB", + "url": "https://https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r549-w33c-xm84/GHSA-r549-w33c-xm84.json b/advisories/unreviewed/2024/11/GHSA-r549-w33c-xm84/GHSA-r549-w33c-xm84.json new file mode 100644 index 00000000000..dd28f1a5726 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r549-w33c-xm84/GHSA-r549-w33c-xm84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r549-w33c-xm84", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43638" + ], + "details": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43638" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43638" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json b/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json new file mode 100644 index 00000000000..5731a55dea8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5rh-8593-84qf", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50326" + ], + "details": "SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50326" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r8m4-9xm8-h9rq/GHSA-r8m4-9xm8-h9rq.json b/advisories/unreviewed/2024/11/GHSA-r8m4-9xm8-h9rq/GHSA-r8m4-9xm8-h9rq.json new file mode 100644 index 00000000000..62d5ce04753 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r8m4-9xm8-h9rq/GHSA-r8m4-9xm8-h9rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8m4-9xm8-h9rq", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43530" + ], + "details": "Windows Update Stack Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43530" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43530" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rf57-p454-qrmj/GHSA-rf57-p454-qrmj.json b/advisories/unreviewed/2024/11/GHSA-rf57-p454-qrmj/GHSA-rf57-p454-qrmj.json index fca5f3132c5..ad35e686301 100644 --- a/advisories/unreviewed/2024/11/GHSA-rf57-p454-qrmj/GHSA-rf57-p454-qrmj.json +++ b/advisories/unreviewed/2024/11/GHSA-rf57-p454-qrmj/GHSA-rf57-p454-qrmj.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rf57-p454-qrmj", - "modified": "2024-11-12T15:30:43Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-33658" ], "details": "APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of this vulnerability may lead to privilege escalation and potentially arbitrary code execution, and impact Integrity.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-rgwg-49qg-75jg/GHSA-rgwg-49qg-75jg.json b/advisories/unreviewed/2024/11/GHSA-rgwg-49qg-75jg/GHSA-rgwg-49qg-75jg.json new file mode 100644 index 00000000000..5efb41b28bd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rgwg-49qg-75jg/GHSA-rgwg-49qg-75jg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgwg-49qg-75jg", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43621" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43621" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43621" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v285-5c63-6rph/GHSA-v285-5c63-6rph.json b/advisories/unreviewed/2024/11/GHSA-v285-5c63-6rph/GHSA-v285-5c63-6rph.json new file mode 100644 index 00000000000..7da9105bc02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v285-5c63-6rph/GHSA-v285-5c63-6rph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v285-5c63-6rph", + "modified": "2024-11-12T18:30:56Z", + "published": "2024-11-12T18:30:56Z", + "aliases": [ + "CVE-2024-50318" + ], + "details": "A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50318" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json b/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json index ca0a3ae10e0..e9e886a9af5 100644 --- a/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json +++ b/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8h2-p73v-3whx", - "modified": "2024-11-11T21:31:48Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-36061" ], "details": "EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v9xc-66hj-99jw/GHSA-v9xc-66hj-99jw.json b/advisories/unreviewed/2024/11/GHSA-v9xc-66hj-99jw/GHSA-v9xc-66hj-99jw.json new file mode 100644 index 00000000000..634408d0b64 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v9xc-66hj-99jw/GHSA-v9xc-66hj-99jw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9xc-66hj-99jw", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43626" + ], + "details": "Windows Telephony Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43626" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43626" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vcm2-gg9p-f48m/GHSA-vcm2-gg9p-f48m.json b/advisories/unreviewed/2024/11/GHSA-vcm2-gg9p-f48m/GHSA-vcm2-gg9p-f48m.json new file mode 100644 index 00000000000..667ec626f64 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vcm2-gg9p-f48m/GHSA-vcm2-gg9p-f48m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcm2-gg9p-f48m", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-43644" + ], + "details": "Windows Client-Side Caching Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43644" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43644" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vcm7-8g3g-3rjm/GHSA-vcm7-8g3g-3rjm.json b/advisories/unreviewed/2024/11/GHSA-vcm7-8g3g-3rjm/GHSA-vcm7-8g3g-3rjm.json new file mode 100644 index 00000000000..3ef9e9e7355 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vcm7-8g3g-3rjm/GHSA-vcm7-8g3g-3rjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcm7-8g3g-3rjm", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49029" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49029" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vfrj-xg26-6g5p/GHSA-vfrj-xg26-6g5p.json b/advisories/unreviewed/2024/11/GHSA-vfrj-xg26-6g5p/GHSA-vfrj-xg26-6g5p.json new file mode 100644 index 00000000000..1678778ce28 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vfrj-xg26-6g5p/GHSA-vfrj-xg26-6g5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfrj-xg26-6g5p", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49033" + ], + "details": "Microsoft Word Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49033" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vgj5-pm4f-q6gv/GHSA-vgj5-pm4f-q6gv.json b/advisories/unreviewed/2024/11/GHSA-vgj5-pm4f-q6gv/GHSA-vgj5-pm4f-q6gv.json index 9a0d286d5e1..1ca712a6464 100644 --- a/advisories/unreviewed/2024/11/GHSA-vgj5-pm4f-q6gv/GHSA-vgj5-pm4f-q6gv.json +++ b/advisories/unreviewed/2024/11/GHSA-vgj5-pm4f-q6gv/GHSA-vgj5-pm4f-q6gv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgj5-pm4f-q6gv", - "modified": "2024-11-12T15:30:43Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-33660" ], "details": "An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-vhc2-7wp4-4355/GHSA-vhc2-7wp4-4355.json b/advisories/unreviewed/2024/11/GHSA-vhc2-7wp4-4355/GHSA-vhc2-7wp4-4355.json new file mode 100644 index 00000000000..9b02058a9e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vhc2-7wp4-4355/GHSA-vhc2-7wp4-4355.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhc2-7wp4-4355", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43620" + ], + "details": "Windows Telephony Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43620" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43620" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vpq5-56jj-vf2m/GHSA-vpq5-56jj-vf2m.json b/advisories/unreviewed/2024/11/GHSA-vpq5-56jj-vf2m/GHSA-vpq5-56jj-vf2m.json index 1d8a38878c7..d15bd3f32b7 100644 --- a/advisories/unreviewed/2024/11/GHSA-vpq5-56jj-vf2m/GHSA-vpq5-56jj-vf2m.json +++ b/advisories/unreviewed/2024/11/GHSA-vpq5-56jj-vf2m/GHSA-vpq5-56jj-vf2m.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vv2x-chjj-4ppm/GHSA-vv2x-chjj-4ppm.json b/advisories/unreviewed/2024/11/GHSA-vv2x-chjj-4ppm/GHSA-vv2x-chjj-4ppm.json new file mode 100644 index 00000000000..acf3d8d2e86 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vv2x-chjj-4ppm/GHSA-vv2x-chjj-4ppm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv2x-chjj-4ppm", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-48999" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48999" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-48999" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vw76-rp45-c8p9/GHSA-vw76-rp45-c8p9.json b/advisories/unreviewed/2024/11/GHSA-vw76-rp45-c8p9/GHSA-vw76-rp45-c8p9.json new file mode 100644 index 00000000000..84532f60323 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vw76-rp45-c8p9/GHSA-vw76-rp45-c8p9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw76-rp45-c8p9", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43634" + ], + "details": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43634" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43634" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w799-83vp-q48c/GHSA-w799-83vp-q48c.json b/advisories/unreviewed/2024/11/GHSA-w799-83vp-q48c/GHSA-w799-83vp-q48c.json new file mode 100644 index 00000000000..8eb67c0ac76 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w799-83vp-q48c/GHSA-w799-83vp-q48c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w799-83vp-q48c", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43630" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43630" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w7cf-g3rh-q9hc/GHSA-w7cf-g3rh-q9hc.json b/advisories/unreviewed/2024/11/GHSA-w7cf-g3rh-q9hc/GHSA-w7cf-g3rh-q9hc.json new file mode 100644 index 00000000000..6fe4b97c29a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w7cf-g3rh-q9hc/GHSA-w7cf-g3rh-q9hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7cf-g3rh-q9hc", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-50330" + ], + "details": "SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50330" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9j9-29jw-fj46/GHSA-w9j9-29jw-fj46.json b/advisories/unreviewed/2024/11/GHSA-w9j9-29jw-fj46/GHSA-w9j9-29jw-fj46.json new file mode 100644 index 00000000000..090a96eb474 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w9j9-29jw-fj46/GHSA-w9j9-29jw-fj46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9j9-29jw-fj46", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:59Z", + "aliases": [ + "CVE-2024-49013" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49013" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json b/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json index 6eec9d81b64..e82848d9474 100644 --- a/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json +++ b/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wggq-gr89-33vp", - "modified": "2024-11-05T18:32:11Z", + "modified": "2024-11-12T18:30:51Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-50097" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fec: don't save PTP state if PTP is unsupported\n\nSome platforms (such as i.MX25 and i.MX27) do not support PTP, so on\nthese platforms fec_ptp_init() is not called and the related members\nin fep are not initialized. However, fec_ptp_save_state() is called\nunconditionally, which causes the kernel to panic. Therefore, add a\ncondition so that fec_ptp_save_state() is not called if PTP is not\nsupported.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T17:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wgj3-g943-v8wv/GHSA-wgj3-g943-v8wv.json b/advisories/unreviewed/2024/11/GHSA-wgj3-g943-v8wv/GHSA-wgj3-g943-v8wv.json new file mode 100644 index 00000000000..74f058af32e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wgj3-g943-v8wv/GHSA-wgj3-g943-v8wv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgj3-g943-v8wv", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43450" + ], + "details": "Windows DNS Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43450" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43450" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-924" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-whgf-6h8c-97q6/GHSA-whgf-6h8c-97q6.json b/advisories/unreviewed/2024/11/GHSA-whgf-6h8c-97q6/GHSA-whgf-6h8c-97q6.json index c046749ff22..c72b8cba83f 100644 --- a/advisories/unreviewed/2024/11/GHSA-whgf-6h8c-97q6/GHSA-whgf-6h8c-97q6.json +++ b/advisories/unreviewed/2024/11/GHSA-whgf-6h8c-97q6/GHSA-whgf-6h8c-97q6.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wm92-8qr7-r99c/GHSA-wm92-8qr7-r99c.json b/advisories/unreviewed/2024/11/GHSA-wm92-8qr7-r99c/GHSA-wm92-8qr7-r99c.json new file mode 100644 index 00000000000..b2f5f4567d6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wm92-8qr7-r99c/GHSA-wm92-8qr7-r99c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm92-8qr7-r99c", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43462" + ], + "details": "SQL Server Native Client Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43462" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43462" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wmm6-pgp8-29hg/GHSA-wmm6-pgp8-29hg.json b/advisories/unreviewed/2024/11/GHSA-wmm6-pgp8-29hg/GHSA-wmm6-pgp8-29hg.json new file mode 100644 index 00000000000..9e886e2b051 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wmm6-pgp8-29hg/GHSA-wmm6-pgp8-29hg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmm6-pgp8-29hg", + "modified": "2024-11-12T18:30:58Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43499" + ], + "details": ".NET and Visual Studio Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43499" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43499" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-606" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json b/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json new file mode 100644 index 00000000000..803ed650a36 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp5x-8wxv-j7j2", + "modified": "2024-11-12T18:30:55Z", + "published": "2024-11-12T18:30:55Z", + "aliases": [ + "CVE-2024-47906" + ], + "details": "Excessive binary privileges in Ivanti Connect Secure which affects versions 22.4R2 through 22.7R2.2 inclusive within the R2 release line and Ivanti Policy Secure before version 22.7R1.2 allow a local authenticated attacker to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47906" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-267" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ww66-45gm-65fm/GHSA-ww66-45gm-65fm.json b/advisories/unreviewed/2024/11/GHSA-ww66-45gm-65fm/GHSA-ww66-45gm-65fm.json new file mode 100644 index 00000000000..168618d1fbc --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ww66-45gm-65fm/GHSA-ww66-45gm-65fm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww66-45gm-65fm", + "modified": "2024-11-12T18:31:00Z", + "published": "2024-11-12T18:31:00Z", + "aliases": [ + "CVE-2024-8069" + ], + "details": "Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8069" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x3c4-52mm-7pp9/GHSA-x3c4-52mm-7pp9.json b/advisories/unreviewed/2024/11/GHSA-x3c4-52mm-7pp9/GHSA-x3c4-52mm-7pp9.json new file mode 100644 index 00000000000..8430a3a4880 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x3c4-52mm-7pp9/GHSA-x3c4-52mm-7pp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3c4-52mm-7pp9", + "modified": "2024-11-12T18:30:59Z", + "published": "2024-11-12T18:30:58Z", + "aliases": [ + "CVE-2024-43642" + ], + "details": "Windows SMB Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43642" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json b/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json new file mode 100644 index 00000000000..e7b69a69ab5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6qj-75g5-46wg", + "modified": "2024-11-12T18:30:57Z", + "published": "2024-11-12T18:30:57Z", + "aliases": [ + "CVE-2024-30133" + ], + "details": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30133" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0114725" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xf4p-4gf4-v92p/GHSA-xf4p-4gf4-v92p.json b/advisories/unreviewed/2024/11/GHSA-xf4p-4gf4-v92p/GHSA-xf4p-4gf4-v92p.json index 4c47f77c215..e956aece964 100644 --- a/advisories/unreviewed/2024/11/GHSA-xf4p-4gf4-v92p/GHSA-xf4p-4gf4-v92p.json +++ b/advisories/unreviewed/2024/11/GHSA-xf4p-4gf4-v92p/GHSA-xf4p-4gf4-v92p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf4p-4gf4-v92p", - "modified": "2024-11-12T15:30:43Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-2315" ], "details": "APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json b/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json index b3d21d4ebff..6c0ed69fc5f 100644 --- a/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json +++ b/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqm3-rc5r-j547", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T18:30:52Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-46964" ], "details": "The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json b/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json new file mode 100644 index 00000000000..e94d76cce07 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xwfr-c9rv-m6pp/GHSA-xwfr-c9rv-m6pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwfr-c9rv-m6pp", + "modified": "2024-11-12T18:30:55Z", + "published": "2024-11-12T18:30:55Z", + "aliases": [ + "CVE-2024-47907" + ], + "details": "A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47907" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T16:15:22Z" + } +} \ No newline at end of file