From 9868e2bb975ae6524645b3b6e0d58eb81d3e19b9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 29 Jan 2024 18:33:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jvj3-gqjm-cg8p.json | 4 ++ .../GHSA-2572-4xw7-mcfc.json | 11 ++-- .../GHSA-25vp-v4qh-h9xj.json | 11 ++-- .../GHSA-39gr-m4xp-77wp.json | 38 ++++++++++++++ .../GHSA-4425-3v92-m6q6.json | 3 +- .../GHSA-4gqf-q3p9-g947.json | 11 ++-- .../GHSA-4hh7-5c39-pfhw.json | 11 ++-- .../GHSA-4jhj-g9wr-f89q.json | 11 ++-- .../GHSA-4wm4-8487-w6cr.json | 46 +++++++++++++++++ .../GHSA-5prg-h6vm-wxcf.json | 11 ++-- .../GHSA-5rh9-65g2-hc9h.json | 11 ++-- .../GHSA-627f-4vcr-fmq4.json | 9 ++-- .../GHSA-6g54-284w-pj4p.json | 2 +- .../GHSA-6j62-7qgg-9gww.json | 42 ++++++++++++++++ .../GHSA-6m93-gmrj-jf29.json | 11 ++-- .../GHSA-7695-f938-c2jf.json | 3 +- .../GHSA-78cp-c4p5-694f.json | 3 +- .../GHSA-78m6-vgh2-9c4v.json | 11 ++-- .../GHSA-79x7-r2x4-xpj2.json | 11 ++-- .../GHSA-7jm4-gcxp-f8vv.json | 46 +++++++++++++++++ .../GHSA-8523-f95g-92mc.json | 11 ++-- .../GHSA-86pm-fpxw-jjjc.json | 42 ++++++++++++++++ .../GHSA-8cww-gxv8-vfxm.json | 11 ++-- .../GHSA-8qq6-2q43-h362.json | 46 +++++++++++++++++ .../GHSA-8xmj-gvcg-7vcw.json | 11 ++-- .../GHSA-98h2-7j4h-7xc5.json | 3 +- .../GHSA-9fh5-955w-9jfh.json | 42 ++++++++++++++++ .../GHSA-9rf9-hjjr-q4r4.json | 11 ++-- .../GHSA-c822-34mg-g7p6.json | 50 +++++++++++++++++++ .../GHSA-crvx-w25m-8x7c.json | 3 +- .../GHSA-f282-55f7-242h.json | 3 +- .../GHSA-g4x3-mfpj-f335.json | 11 ++-- .../GHSA-g5jr-34r4-rv4w.json | 4 +- .../GHSA-gpvq-2fxv-3pgq.json | 9 ++-- .../GHSA-grx2-83w4-8647.json | 42 ++++++++++++++++ .../GHSA-h7m5-mp8f-v424.json | 3 +- .../GHSA-jggj-wjwc-8gg9.json | 11 ++-- .../GHSA-jh2c-2h3p-fcj3.json | 11 ++-- .../GHSA-mcx8-9rrj-7qxm.json | 4 ++ .../GHSA-mw6w-j49q-q324.json | 11 ++-- .../GHSA-mxjq-xrv7-m36q.json | 11 ++-- .../GHSA-p52v-f53f-hrr6.json | 11 ++-- .../GHSA-pcgj-qq2c-qx79.json | 46 +++++++++++++++++ .../GHSA-pv96-p9pp-9m2m.json | 2 +- .../GHSA-pvh3-5rhh-wcg5.json | 12 +++-- .../GHSA-qcxp-xh47-3g32.json | 46 +++++++++++++++++ .../GHSA-r3xx-hr64-gmm2.json | 9 ++-- .../GHSA-r7mg-69gq-5g8v.json | 11 ++-- .../GHSA-rpp9-fjv3-6cxw.json | 46 +++++++++++++++++ .../GHSA-rrr4-rqcr-8jmq.json | 42 ++++++++++++++++ .../GHSA-v7gp-f4wc-h5w4.json | 9 ++-- .../GHSA-v7v5-mxj3-9qmp.json | 42 ++++++++++++++++ .../GHSA-vwg3-8x87-rfjm.json | 9 ++-- .../GHSA-wgc3-54w5-j2pq.json | 11 ++-- .../GHSA-x697-v25m-6phv.json | 4 ++ .../GHSA-xcjc-c88c-v52w.json | 10 ++-- .../GHSA-xw3v-x6gq-q358.json | 11 ++-- 57 files changed, 852 insertions(+), 125 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-39gr-m4xp-77wp/GHSA-39gr-m4xp-77wp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4wm4-8487-w6cr/GHSA-4wm4-8487-w6cr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7jm4-gcxp-f8vv/GHSA-7jm4-gcxp-f8vv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8qq6-2q43-h362/GHSA-8qq6-2q43-h362.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json create mode 100644 advisories/unreviewed/2024/01/GHSA-c822-34mg-g7p6/GHSA-c822-34mg-g7p6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pcgj-qq2c-qx79/GHSA-pcgj-qq2c-qx79.json create mode 100644 advisories/unreviewed/2024/01/GHSA-qcxp-xh47-3g32/GHSA-qcxp-xh47-3g32.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rpp9-fjv3-6cxw/GHSA-rpp9-fjv3-6cxw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json diff --git a/advisories/unreviewed/2023/11/GHSA-jvj3-gqjm-cg8p/GHSA-jvj3-gqjm-cg8p.json b/advisories/unreviewed/2023/11/GHSA-jvj3-gqjm-cg8p/GHSA-jvj3-gqjm-cg8p.json index 89f67c5807a..0892cc4903a 100644 --- a/advisories/unreviewed/2023/11/GHSA-jvj3-gqjm-cg8p/GHSA-jvj3-gqjm-cg8p.json +++ b/advisories/unreviewed/2023/11/GHSA-jvj3-gqjm-cg8p/GHSA-jvj3-gqjm-cg8p.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:0451" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0533" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5981" diff --git a/advisories/unreviewed/2024/01/GHSA-2572-4xw7-mcfc/GHSA-2572-4xw7-mcfc.json b/advisories/unreviewed/2024/01/GHSA-2572-4xw7-mcfc/GHSA-2572-4xw7-mcfc.json index 07448468734..49e5c81b914 100644 --- a/advisories/unreviewed/2024/01/GHSA-2572-4xw7-mcfc/GHSA-2572-4xw7-mcfc.json +++ b/advisories/unreviewed/2024/01/GHSA-2572-4xw7-mcfc/GHSA-2572-4xw7-mcfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2572-4xw7-mcfc", - "modified": "2024-01-23T12:30:30Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T12:30:30Z", "aliases": [ "CVE-2024-22705" ], "details": "An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T11:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-25vp-v4qh-h9xj/GHSA-25vp-v4qh-h9xj.json b/advisories/unreviewed/2024/01/GHSA-25vp-v4qh-h9xj/GHSA-25vp-v4qh-h9xj.json index c7cb4c2db6f..7bb027be1ab 100644 --- a/advisories/unreviewed/2024/01/GHSA-25vp-v4qh-h9xj/GHSA-25vp-v4qh-h9xj.json +++ b/advisories/unreviewed/2024/01/GHSA-25vp-v4qh-h9xj/GHSA-25vp-v4qh-h9xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25vp-v4qh-h9xj", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-22662" ], "details": "TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T15:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-39gr-m4xp-77wp/GHSA-39gr-m4xp-77wp.json b/advisories/unreviewed/2024/01/GHSA-39gr-m4xp-77wp/GHSA-39gr-m4xp-77wp.json new file mode 100644 index 00000000000..d8427cee090 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-39gr-m4xp-77wp/GHSA-39gr-m4xp-77wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39gr-m4xp-77wp", + "modified": "2024-01-29T18:31:50Z", + "published": "2024-01-29T18:31:50Z", + "aliases": [ + "CVE-2023-1705" + ], + "details": "Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1705" + }, + { + "type": "WEB", + "url": "https://support.forcepoint.com/s/article/000042333" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4425-3v92-m6q6/GHSA-4425-3v92-m6q6.json b/advisories/unreviewed/2024/01/GHSA-4425-3v92-m6q6/GHSA-4425-3v92-m6q6.json index 1d76d8714b2..13d5c3841df 100644 --- a/advisories/unreviewed/2024/01/GHSA-4425-3v92-m6q6/GHSA-4425-3v92-m6q6.json +++ b/advisories/unreviewed/2024/01/GHSA-4425-3v92-m6q6/GHSA-4425-3v92-m6q6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-4gqf-q3p9-g947/GHSA-4gqf-q3p9-g947.json b/advisories/unreviewed/2024/01/GHSA-4gqf-q3p9-g947/GHSA-4gqf-q3p9-g947.json index 3ba7aec067f..16cbe62074c 100644 --- a/advisories/unreviewed/2024/01/GHSA-4gqf-q3p9-g947/GHSA-4gqf-q3p9-g947.json +++ b/advisories/unreviewed/2024/01/GHSA-4gqf-q3p9-g947/GHSA-4gqf-q3p9-g947.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gqf-q3p9-g947", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-22639" ], "details": "iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4hh7-5c39-pfhw/GHSA-4hh7-5c39-pfhw.json b/advisories/unreviewed/2024/01/GHSA-4hh7-5c39-pfhw/GHSA-4hh7-5c39-pfhw.json index 43126d49c6d..9839c6aed87 100644 --- a/advisories/unreviewed/2024/01/GHSA-4hh7-5c39-pfhw/GHSA-4hh7-5c39-pfhw.json +++ b/advisories/unreviewed/2024/01/GHSA-4hh7-5c39-pfhw/GHSA-4hh7-5c39-pfhw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hh7-5c39-pfhw", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2023-24135" ], "details": "Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary commands via manipulation of the mac parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4jhj-g9wr-f89q/GHSA-4jhj-g9wr-f89q.json b/advisories/unreviewed/2024/01/GHSA-4jhj-g9wr-f89q/GHSA-4jhj-g9wr-f89q.json index f3e59993c55..8f4085ddef5 100644 --- a/advisories/unreviewed/2024/01/GHSA-4jhj-g9wr-f89q/GHSA-4jhj-g9wr-f89q.json +++ b/advisories/unreviewed/2024/01/GHSA-4jhj-g9wr-f89q/GHSA-4jhj-g9wr-f89q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jhj-g9wr-f89q", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52328" ], "details": "Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.\n\nPlease note this vulnerability is similar, but not identical to CVE-2023-52329.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4wm4-8487-w6cr/GHSA-4wm4-8487-w6cr.json b/advisories/unreviewed/2024/01/GHSA-4wm4-8487-w6cr/GHSA-4wm4-8487-w6cr.json new file mode 100644 index 00000000000..a29d050bd2f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4wm4-8487-w6cr/GHSA-4wm4-8487-w6cr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wm4-8487-w6cr", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2024-1016" + ], + "details": "A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affects unknown code of the component PASV Command Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-252286 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1016" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/176675/Solar-FTP-Server-2.1.2-Denial-Of-Service.html" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252286" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252286" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5prg-h6vm-wxcf/GHSA-5prg-h6vm-wxcf.json b/advisories/unreviewed/2024/01/GHSA-5prg-h6vm-wxcf/GHSA-5prg-h6vm-wxcf.json index 018d8a42e02..791b31d3f64 100644 --- a/advisories/unreviewed/2024/01/GHSA-5prg-h6vm-wxcf/GHSA-5prg-h6vm-wxcf.json +++ b/advisories/unreviewed/2024/01/GHSA-5prg-h6vm-wxcf/GHSA-5prg-h6vm-wxcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5prg-h6vm-wxcf", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-38626" ], "details": "A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis is a similar, but not identical vulnerability as CVE-2023-38625.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5rh9-65g2-hc9h/GHSA-5rh9-65g2-hc9h.json b/advisories/unreviewed/2024/01/GHSA-5rh9-65g2-hc9h/GHSA-5rh9-65g2-hc9h.json index fef7806b1e0..bedb87e3bf8 100644 --- a/advisories/unreviewed/2024/01/GHSA-5rh9-65g2-hc9h/GHSA-5rh9-65g2-hc9h.json +++ b/advisories/unreviewed/2024/01/GHSA-5rh9-65g2-hc9h/GHSA-5rh9-65g2-hc9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rh9-65g2-hc9h", - "modified": "2024-01-23T15:30:58Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-22663" ], "details": "TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T15:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json b/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json index 660e466c9d5..4c071c72a09 100644 --- a/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json +++ b/advisories/unreviewed/2024/01/GHSA-627f-4vcr-fmq4/GHSA-627f-4vcr-fmq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-627f-4vcr-fmq4", - "modified": "2024-01-22T00:30:19Z", + "modified": "2024-01-29T18:31:46Z", "published": "2024-01-22T00:30:19Z", "aliases": [ "CVE-2024-23744" ], "details": "An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-21T23:15:44Z" diff --git a/advisories/unreviewed/2024/01/GHSA-6g54-284w-pj4p/GHSA-6g54-284w-pj4p.json b/advisories/unreviewed/2024/01/GHSA-6g54-284w-pj4p/GHSA-6g54-284w-pj4p.json index 9221e61d1f7..e79a4716bd4 100644 --- a/advisories/unreviewed/2024/01/GHSA-6g54-284w-pj4p/GHSA-6g54-284w-pj4p.json +++ b/advisories/unreviewed/2024/01/GHSA-6g54-284w-pj4p/GHSA-6g54-284w-pj4p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6g54-284w-pj4p", - "modified": "2024-01-24T21:30:33Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-22T21:31:07Z", "aliases": [ "CVE-2024-23676" diff --git a/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json b/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json new file mode 100644 index 00000000000..219fa4c0a3c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j62-7qgg-9gww", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2023-40551" + ], + "details": "A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40551" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-40551" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259918" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json b/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json index d6a1f112385..433f5164a1b 100644 --- a/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json +++ b/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6m93-gmrj-jf29", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-24399" ], "details": "An arbitrary file upload vulnerability in LeptonCMS v7.0.0 allows authenticated attackers to execute arbitrary code via uploading a crafted PHP file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7695-f938-c2jf/GHSA-7695-f938-c2jf.json b/advisories/unreviewed/2024/01/GHSA-7695-f938-c2jf/GHSA-7695-f938-c2jf.json index 6fcb2677a33..59be713bbde 100644 --- a/advisories/unreviewed/2024/01/GHSA-7695-f938-c2jf/GHSA-7695-f938-c2jf.json +++ b/advisories/unreviewed/2024/01/GHSA-7695-f938-c2jf/GHSA-7695-f938-c2jf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-78cp-c4p5-694f/GHSA-78cp-c4p5-694f.json b/advisories/unreviewed/2024/01/GHSA-78cp-c4p5-694f/GHSA-78cp-c4p5-694f.json index 18efb81b022..447755a19c9 100644 --- a/advisories/unreviewed/2024/01/GHSA-78cp-c4p5-694f/GHSA-78cp-c4p5-694f.json +++ b/advisories/unreviewed/2024/01/GHSA-78cp-c4p5-694f/GHSA-78cp-c4p5-694f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-78m6-vgh2-9c4v/GHSA-78m6-vgh2-9c4v.json b/advisories/unreviewed/2024/01/GHSA-78m6-vgh2-9c4v/GHSA-78m6-vgh2-9c4v.json index 642935371dd..7451b0d1d27 100644 --- a/advisories/unreviewed/2024/01/GHSA-78m6-vgh2-9c4v/GHSA-78m6-vgh2-9c4v.json +++ b/advisories/unreviewed/2024/01/GHSA-78m6-vgh2-9c4v/GHSA-78m6-vgh2-9c4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78m6-vgh2-9c4v", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-41177" ], "details": "Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker.\n\nPlease note, this vulnerability is similar to, but not identical to, CVE-2023-41178.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-79x7-r2x4-xpj2/GHSA-79x7-r2x4-xpj2.json b/advisories/unreviewed/2024/01/GHSA-79x7-r2x4-xpj2/GHSA-79x7-r2x4-xpj2.json index 4b08096dde2..588f8be0c87 100644 --- a/advisories/unreviewed/2024/01/GHSA-79x7-r2x4-xpj2/GHSA-79x7-r2x4-xpj2.json +++ b/advisories/unreviewed/2024/01/GHSA-79x7-r2x4-xpj2/GHSA-79x7-r2x4-xpj2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79x7-r2x4-xpj2", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-41176" ], "details": "Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker.\n\nPlease note, this vulnerability is similar to, but not identical to, CVE-2023-41177.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7jm4-gcxp-f8vv/GHSA-7jm4-gcxp-f8vv.json b/advisories/unreviewed/2024/01/GHSA-7jm4-gcxp-f8vv/GHSA-7jm4-gcxp-f8vv.json new file mode 100644 index 00000000000..e3b72010922 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7jm4-gcxp-f8vv/GHSA-7jm4-gcxp-f8vv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jm4-gcxp-f8vv", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2024-1009" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/login.php. The manipulation of the argument txtusername leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252278 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252278" + }, + { + "type": "WEB", + "url": "https://youtu.be/oL98TSjy89Q?si=_T6YkJZlbn7SJ4Gn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8523-f95g-92mc/GHSA-8523-f95g-92mc.json b/advisories/unreviewed/2024/01/GHSA-8523-f95g-92mc/GHSA-8523-f95g-92mc.json index 768b2fa3799..d9d423ac6e6 100644 --- a/advisories/unreviewed/2024/01/GHSA-8523-f95g-92mc/GHSA-8523-f95g-92mc.json +++ b/advisories/unreviewed/2024/01/GHSA-8523-f95g-92mc/GHSA-8523-f95g-92mc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8523-f95g-92mc", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-38624" ], "details": "A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis is a similar, but not identical vulnerability as CVE-2023-38625 through CVE-2023-38627.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json b/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json new file mode 100644 index 00000000000..561f8c8bea2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86pm-fpxw-jjjc", + "modified": "2024-01-29T18:31:50Z", + "published": "2024-01-29T18:31:50Z", + "aliases": [ + "CVE-2023-40549" + ], + "details": "An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40549" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-40549" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2241797" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json b/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json index af639290142..7ba7b3afeca 100644 --- a/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json +++ b/advisories/unreviewed/2024/01/GHSA-8cww-gxv8-vfxm/GHSA-8cww-gxv8-vfxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cww-gxv8-vfxm", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-22637" ], "details": "Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8qq6-2q43-h362/GHSA-8qq6-2q43-h362.json b/advisories/unreviewed/2024/01/GHSA-8qq6-2q43-h362/GHSA-8qq6-2q43-h362.json new file mode 100644 index 00000000000..4e4899f9efe --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8qq6-2q43-h362/GHSA-8qq6-2q43-h362.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qq6-2q43-h362", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2024-1011" + ], + "details": "A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component Leave Handler. The manipulation of the argument id leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252280.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1011" + }, + { + "type": "WEB", + "url": "https://github.com/jomskiller/Employee-Managemet-System---Broken-Access-Control" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252280" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252280" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8xmj-gvcg-7vcw/GHSA-8xmj-gvcg-7vcw.json b/advisories/unreviewed/2024/01/GHSA-8xmj-gvcg-7vcw/GHSA-8xmj-gvcg-7vcw.json index a1974633c10..0c17f6c807c 100644 --- a/advisories/unreviewed/2024/01/GHSA-8xmj-gvcg-7vcw/GHSA-8xmj-gvcg-7vcw.json +++ b/advisories/unreviewed/2024/01/GHSA-8xmj-gvcg-7vcw/GHSA-8xmj-gvcg-7vcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8xmj-gvcg-7vcw", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52329" ], "details": "Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.\n\nPlease note this vulnerability is similar, but not identical to CVE-2023-52326.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-98h2-7j4h-7xc5/GHSA-98h2-7j4h-7xc5.json b/advisories/unreviewed/2024/01/GHSA-98h2-7j4h-7xc5/GHSA-98h2-7j4h-7xc5.json index fa245efaf97..8e161540691 100644 --- a/advisories/unreviewed/2024/01/GHSA-98h2-7j4h-7xc5/GHSA-98h2-7j4h-7xc5.json +++ b/advisories/unreviewed/2024/01/GHSA-98h2-7j4h-7xc5/GHSA-98h2-7j4h-7xc5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json b/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json new file mode 100644 index 00000000000..24adb59076f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fh5-955w-9jfh", + "modified": "2024-01-29T18:31:50Z", + "published": "2024-01-29T18:31:50Z", + "aliases": [ + "CVE-2023-40546" + ], + "details": "A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain circumstances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40546" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-40546" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2241796" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9rf9-hjjr-q4r4/GHSA-9rf9-hjjr-q4r4.json b/advisories/unreviewed/2024/01/GHSA-9rf9-hjjr-q4r4/GHSA-9rf9-hjjr-q4r4.json index e04f000c42e..179d7cfa7e8 100644 --- a/advisories/unreviewed/2024/01/GHSA-9rf9-hjjr-q4r4/GHSA-9rf9-hjjr-q4r4.json +++ b/advisories/unreviewed/2024/01/GHSA-9rf9-hjjr-q4r4/GHSA-9rf9-hjjr-q4r4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rf9-hjjr-q4r4", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-22635" ], "details": "WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c822-34mg-g7p6/GHSA-c822-34mg-g7p6.json b/advisories/unreviewed/2024/01/GHSA-c822-34mg-g7p6/GHSA-c822-34mg-g7p6.json new file mode 100644 index 00000000000..a4880e15f90 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c822-34mg-g7p6/GHSA-c822-34mg-g7p6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c822-34mg-g7p6", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2024-1010" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file edit-profile.php. The manipulation of the argument fullname/phone/date of birth/address/date of appointment leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-252279.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1010" + }, + { + "type": "WEB", + "url": "https://github.com/jomskiller/Employee-Management-System---Stored-XSS" + }, + { + "type": "WEB", + "url": "https://github.com/jomskiller/Employee-Management-System---Stored-XSS/" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252279" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-crvx-w25m-8x7c/GHSA-crvx-w25m-8x7c.json b/advisories/unreviewed/2024/01/GHSA-crvx-w25m-8x7c/GHSA-crvx-w25m-8x7c.json index b2bdaca57ee..6e9ed1ff9f2 100644 --- a/advisories/unreviewed/2024/01/GHSA-crvx-w25m-8x7c/GHSA-crvx-w25m-8x7c.json +++ b/advisories/unreviewed/2024/01/GHSA-crvx-w25m-8x7c/GHSA-crvx-w25m-8x7c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-f282-55f7-242h/GHSA-f282-55f7-242h.json b/advisories/unreviewed/2024/01/GHSA-f282-55f7-242h/GHSA-f282-55f7-242h.json index e5b76a47321..fef61beb887 100644 --- a/advisories/unreviewed/2024/01/GHSA-f282-55f7-242h/GHSA-f282-55f7-242h.json +++ b/advisories/unreviewed/2024/01/GHSA-f282-55f7-242h/GHSA-f282-55f7-242h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-g4x3-mfpj-f335/GHSA-g4x3-mfpj-f335.json b/advisories/unreviewed/2024/01/GHSA-g4x3-mfpj-f335/GHSA-g4x3-mfpj-f335.json index 425aca65101..81322bdfe71 100644 --- a/advisories/unreviewed/2024/01/GHSA-g4x3-mfpj-f335/GHSA-g4x3-mfpj-f335.json +++ b/advisories/unreviewed/2024/01/GHSA-g4x3-mfpj-f335/GHSA-g4x3-mfpj-f335.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g4x3-mfpj-f335", - "modified": "2024-01-22T06:30:32Z", + "modified": "2024-01-29T18:31:46Z", "published": "2024-01-22T06:30:32Z", "aliases": [ "CVE-2023-52354" ], "details": "chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T06:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json b/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json index c96c8fcc8c5..015f53e5237 100644 --- a/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json +++ b/advisories/unreviewed/2024/01/GHSA-g5jr-34r4-rv4w/GHSA-g5jr-34r4-rv4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5jr-34r4-rv4w", - "modified": "2024-01-27T03:30:21Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-27T03:30:21Z", "aliases": [ "CVE-2023-6482" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-321" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-gpvq-2fxv-3pgq/GHSA-gpvq-2fxv-3pgq.json b/advisories/unreviewed/2024/01/GHSA-gpvq-2fxv-3pgq/GHSA-gpvq-2fxv-3pgq.json index 20406559f3b..490237b5f92 100644 --- a/advisories/unreviewed/2024/01/GHSA-gpvq-2fxv-3pgq/GHSA-gpvq-2fxv-3pgq.json +++ b/advisories/unreviewed/2024/01/GHSA-gpvq-2fxv-3pgq/GHSA-gpvq-2fxv-3pgq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpvq-2fxv-3pgq", - "modified": "2024-01-23T15:30:57Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T15:30:57Z", "aliases": [ "CVE-2024-0742" ], "details": "It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T14:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json b/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json new file mode 100644 index 00000000000..e8c3621d5db --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grx2-83w4-8647", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2023-40550" + ], + "details": "An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40550" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-40550" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h7m5-mp8f-v424/GHSA-h7m5-mp8f-v424.json b/advisories/unreviewed/2024/01/GHSA-h7m5-mp8f-v424/GHSA-h7m5-mp8f-v424.json index fd77886d374..03ee06a8d65 100644 --- a/advisories/unreviewed/2024/01/GHSA-h7m5-mp8f-v424/GHSA-h7m5-mp8f-v424.json +++ b/advisories/unreviewed/2024/01/GHSA-h7m5-mp8f-v424/GHSA-h7m5-mp8f-v424.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-jggj-wjwc-8gg9/GHSA-jggj-wjwc-8gg9.json b/advisories/unreviewed/2024/01/GHSA-jggj-wjwc-8gg9/GHSA-jggj-wjwc-8gg9.json index 07e1e309caf..7a0f46ee78d 100644 --- a/advisories/unreviewed/2024/01/GHSA-jggj-wjwc-8gg9/GHSA-jggj-wjwc-8gg9.json +++ b/advisories/unreviewed/2024/01/GHSA-jggj-wjwc-8gg9/GHSA-jggj-wjwc-8gg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jggj-wjwc-8gg9", - "modified": "2024-01-22T00:30:19Z", + "modified": "2024-01-29T18:31:46Z", "published": "2024-01-22T00:30:19Z", "aliases": [ "CVE-2023-52353" ], "details": "An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-21T23:15:44Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jh2c-2h3p-fcj3/GHSA-jh2c-2h3p-fcj3.json b/advisories/unreviewed/2024/01/GHSA-jh2c-2h3p-fcj3/GHSA-jh2c-2h3p-fcj3.json index 926caac72a0..8c2a4efefde 100644 --- a/advisories/unreviewed/2024/01/GHSA-jh2c-2h3p-fcj3/GHSA-jh2c-2h3p-fcj3.json +++ b/advisories/unreviewed/2024/01/GHSA-jh2c-2h3p-fcj3/GHSA-jh2c-2h3p-fcj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jh2c-2h3p-fcj3", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-38625" ], "details": "A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis is a similar, but not identical vulnerability as CVE-2023-38624.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json b/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json index cb447e5c6ea..20de0a8e499 100644 --- a/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json +++ b/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0567" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0533" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0567" diff --git a/advisories/unreviewed/2024/01/GHSA-mw6w-j49q-q324/GHSA-mw6w-j49q-q324.json b/advisories/unreviewed/2024/01/GHSA-mw6w-j49q-q324/GHSA-mw6w-j49q-q324.json index ea75c42f693..7f8d0ae1aae 100644 --- a/advisories/unreviewed/2024/01/GHSA-mw6w-j49q-q324/GHSA-mw6w-j49q-q324.json +++ b/advisories/unreviewed/2024/01/GHSA-mw6w-j49q-q324/GHSA-mw6w-j49q-q324.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mw6w-j49q-q324", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2023-52046" ], "details": "Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the \"Execute cron job as\" tab Input field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json b/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json index d4b13059a7d..e8e2db9dca2 100644 --- a/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json +++ b/advisories/unreviewed/2024/01/GHSA-mxjq-xrv7-m36q/GHSA-mxjq-xrv7-m36q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxjq-xrv7-m36q", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52327" ], "details": "Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.\n\nPlease note this vulnerability is similar, but not identical to CVE-2023-52328.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-p52v-f53f-hrr6/GHSA-p52v-f53f-hrr6.json b/advisories/unreviewed/2024/01/GHSA-p52v-f53f-hrr6/GHSA-p52v-f53f-hrr6.json index db72150d241..0b796c7c4f1 100644 --- a/advisories/unreviewed/2024/01/GHSA-p52v-f53f-hrr6/GHSA-p52v-f53f-hrr6.json +++ b/advisories/unreviewed/2024/01/GHSA-p52v-f53f-hrr6/GHSA-p52v-f53f-hrr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p52v-f53f-hrr6", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-38627" ], "details": "A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis is a similar, but not identical vulnerability as CVE-2023-38626.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-pcgj-qq2c-qx79/GHSA-pcgj-qq2c-qx79.json b/advisories/unreviewed/2024/01/GHSA-pcgj-qq2c-qx79/GHSA-pcgj-qq2c-qx79.json new file mode 100644 index 00000000000..d23a9727395 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pcgj-qq2c-qx79/GHSA-pcgj-qq2c-qx79.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcgj-qq2c-qx79", + "modified": "2024-01-29T18:31:49Z", + "published": "2024-01-29T18:31:49Z", + "aliases": [ + "CVE-2024-1007" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. The manipulation of the argument txtfullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252276.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252276" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=1yesMwvWcL4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pv96-p9pp-9m2m/GHSA-pv96-p9pp-9m2m.json b/advisories/unreviewed/2024/01/GHSA-pv96-p9pp-9m2m/GHSA-pv96-p9pp-9m2m.json index d11376d4f5d..a28b60af792 100644 --- a/advisories/unreviewed/2024/01/GHSA-pv96-p9pp-9m2m/GHSA-pv96-p9pp-9m2m.json +++ b/advisories/unreviewed/2024/01/GHSA-pv96-p9pp-9m2m/GHSA-pv96-p9pp-9m2m.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-pvh3-5rhh-wcg5/GHSA-pvh3-5rhh-wcg5.json b/advisories/unreviewed/2024/01/GHSA-pvh3-5rhh-wcg5/GHSA-pvh3-5rhh-wcg5.json index 0fa83a84c54..48e423de06a 100644 --- a/advisories/unreviewed/2024/01/GHSA-pvh3-5rhh-wcg5/GHSA-pvh3-5rhh-wcg5.json +++ b/advisories/unreviewed/2024/01/GHSA-pvh3-5rhh-wcg5/GHSA-pvh3-5rhh-wcg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvh3-5rhh-wcg5", - "modified": "2024-01-18T00:30:17Z", + "modified": "2024-01-29T18:31:46Z", "published": "2024-01-18T00:30:17Z", "aliases": [ "CVE-2023-6340" ], "details": "SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T00:15:38Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qcxp-xh47-3g32/GHSA-qcxp-xh47-3g32.json b/advisories/unreviewed/2024/01/GHSA-qcxp-xh47-3g32/GHSA-qcxp-xh47-3g32.json new file mode 100644 index 00000000000..b2579922022 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qcxp-xh47-3g32/GHSA-qcxp-xh47-3g32.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcxp-xh47-3g32", + "modified": "2024-01-29T18:31:49Z", + "published": "2024-01-29T18:31:49Z", + "aliases": [ + "CVE-2024-1006" + ], + "details": "A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file application/index/common.php of the component Cookie Handler. The manipulation of the argument Nod_User_Id/Nod_User_Token leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252275. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1006" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/vWuVlU2eg79t" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252275" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r3xx-hr64-gmm2/GHSA-r3xx-hr64-gmm2.json b/advisories/unreviewed/2024/01/GHSA-r3xx-hr64-gmm2/GHSA-r3xx-hr64-gmm2.json index eff32ce4426..d0e08bb8c1d 100644 --- a/advisories/unreviewed/2024/01/GHSA-r3xx-hr64-gmm2/GHSA-r3xx-hr64-gmm2.json +++ b/advisories/unreviewed/2024/01/GHSA-r3xx-hr64-gmm2/GHSA-r3xx-hr64-gmm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3xx-hr64-gmm2", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-22636" ], "details": "PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-r7mg-69gq-5g8v/GHSA-r7mg-69gq-5g8v.json b/advisories/unreviewed/2024/01/GHSA-r7mg-69gq-5g8v/GHSA-r7mg-69gq-5g8v.json index 04e7d31ce30..7afa7071901 100644 --- a/advisories/unreviewed/2024/01/GHSA-r7mg-69gq-5g8v/GHSA-r7mg-69gq-5g8v.json +++ b/advisories/unreviewed/2024/01/GHSA-r7mg-69gq-5g8v/GHSA-r7mg-69gq-5g8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7mg-69gq-5g8v", - "modified": "2024-01-23T21:30:21Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52326" ], "details": "Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.\n\nPlease note this vulnerability is similar, but not identical to CVE-2023-52327.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rpp9-fjv3-6cxw/GHSA-rpp9-fjv3-6cxw.json b/advisories/unreviewed/2024/01/GHSA-rpp9-fjv3-6cxw/GHSA-rpp9-fjv3-6cxw.json new file mode 100644 index 00000000000..9af91f70e6a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rpp9-fjv3-6cxw/GHSA-rpp9-fjv3-6cxw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpp9-fjv3-6cxw", + "modified": "2024-01-29T18:31:49Z", + "published": "2024-01-29T18:31:49Z", + "aliases": [ + "CVE-2024-1008" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Profile Page. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252277 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1008" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252277" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=z4gcLZCOcnc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json b/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json new file mode 100644 index 00000000000..d33b478e78e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rrr4-rqcr-8jmq/GHSA-rrr4-rqcr-8jmq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrr4-rqcr-8jmq", + "modified": "2024-01-29T18:31:53Z", + "published": "2024-01-29T18:31:53Z", + "aliases": [ + "CVE-2024-0788" + ], + "details": "SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0788" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/brubeck/" + }, + { + "type": "WEB", + "url": "https://www.superantispyware.com/professional-x-edition.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json b/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json index 21bdb3456fa..857d19be2e8 100644 --- a/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json +++ b/advisories/unreviewed/2024/01/GHSA-v7gp-f4wc-h5w4/GHSA-v7gp-f4wc-h5w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7gp-f4wc-h5w4", - "modified": "2024-01-22T15:30:23Z", + "modified": "2024-01-29T18:31:46Z", "published": "2024-01-22T15:30:23Z", "aliases": [ "CVE-2020-36771" ], "details": "CloudLinux\n CageFS 7.1.1-1 or below passes the authentication token as command line\n argument. In some configurations this allows local users to view it via\n the process list and gain code execution as another user.\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-214" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T14:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json b/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json new file mode 100644 index 00000000000..afa3f781a09 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v7v5-mxj3-9qmp/GHSA-v7v5-mxj3-9qmp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7v5-mxj3-9qmp", + "modified": "2024-01-29T18:31:49Z", + "published": "2024-01-29T18:31:49Z", + "aliases": [ + "CVE-2024-23441" + ], + "details": "Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23441" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/rollins/" + }, + { + "type": "WEB", + "url": "https://www.anti-virus.by/vba32" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vwg3-8x87-rfjm/GHSA-vwg3-8x87-rfjm.json b/advisories/unreviewed/2024/01/GHSA-vwg3-8x87-rfjm/GHSA-vwg3-8x87-rfjm.json index d3034eae56f..d929796765c 100644 --- a/advisories/unreviewed/2024/01/GHSA-vwg3-8x87-rfjm/GHSA-vwg3-8x87-rfjm.json +++ b/advisories/unreviewed/2024/01/GHSA-vwg3-8x87-rfjm/GHSA-vwg3-8x87-rfjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwg3-8x87-rfjm", - "modified": "2024-01-25T21:32:15Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-22638" ], "details": "liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-wgc3-54w5-j2pq/GHSA-wgc3-54w5-j2pq.json b/advisories/unreviewed/2024/01/GHSA-wgc3-54w5-j2pq/GHSA-wgc3-54w5-j2pq.json index 1b3b4b4d122..3b36ad72e1c 100644 --- a/advisories/unreviewed/2024/01/GHSA-wgc3-54w5-j2pq/GHSA-wgc3-54w5-j2pq.json +++ b/advisories/unreviewed/2024/01/GHSA-wgc3-54w5-j2pq/GHSA-wgc3-54w5-j2pq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wgc3-54w5-j2pq", - "modified": "2024-01-26T00:30:27Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-26T00:30:27Z", "aliases": [ "CVE-2024-22922" ], "details": "An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T22:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json index 2e50193d896..dee183bc44c 100644 --- a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json +++ b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0553" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0533" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0553" diff --git a/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json b/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json index 33df53220b0..5962d3f2412 100644 --- a/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json +++ b/advisories/unreviewed/2024/01/GHSA-xcjc-c88c-v52w/GHSA-xcjc-c88c-v52w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xcjc-c88c-v52w", - "modified": "2024-01-22T15:30:23Z", + "modified": "2024-01-29T18:31:47Z", "published": "2024-01-22T15:30:23Z", "aliases": [ "CVE-2020-36772" ], "details": "CloudLinux\n CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to\n the sendmail proxy command. This allows local users to read and write \narbitrary files outside the CageFS environment in a limited way.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-610", "CWE-73" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-22T15:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xw3v-x6gq-q358/GHSA-xw3v-x6gq-q358.json b/advisories/unreviewed/2024/01/GHSA-xw3v-x6gq-q358/GHSA-xw3v-x6gq-q358.json index 7c1d8ef9807..e6648ce959c 100644 --- a/advisories/unreviewed/2024/01/GHSA-xw3v-x6gq-q358/GHSA-xw3v-x6gq-q358.json +++ b/advisories/unreviewed/2024/01/GHSA-xw3v-x6gq-q358/GHSA-xw3v-x6gq-q358.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw3v-x6gq-q358", - "modified": "2024-01-23T21:30:20Z", + "modified": "2024-01-29T18:31:48Z", "published": "2024-01-23T21:30:20Z", "aliases": [ "CVE-2023-41178" ], "details": "Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided by an attacker.\n\nPlease note, this vulnerability is similar to, but not identical to, CVE-2023-41176.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T21:15:08Z"