Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-10-28 03:31:37 +00:00
parent df414c7801
commit 9e4dabe78c
51 changed files with 294 additions and 70 deletions
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html"
},
{
"type": "WEB",
"url": "https://www.secpod.com/blog/a-secret-zyxel-firewall-and-ap-controllers-could-allow-for-administrative-access-cve-2020-29583/"
},
{
"type": "WEB",
"url": "https://www.zyxel.com/support/CVE-2020-29583.shtml"
@@ -48,7 +52,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
"CWE-312",
"CWE-522"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25h8-g2f4-5mwj",
"modified": "2023-10-25T18:32:20Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26575"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q9m-8wj3-95xg",
"modified": "2023-10-23T21:30:58Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-23T21:30:58Z",
"aliases": [
"CVE-2023-46602"
],
"details": "In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in IccXML/IccLibXML/IccUtilXml.cpp in libIccXML.a.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vmv-m3hj-2wh8",
"modified": "2023-10-28T03:30:23Z",
"published": "2023-10-28T03:30:23Z",
"aliases": [
"CVE-2023-43322"
],
"details": "ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43322"
},
{
"type": "WEB",
"url": "https://psirt.zpesystems.com/portal/en/kb/articles/security-advisory-zpe-ng-2023-001-12-10-2023"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34fg-whr2-93rc",
"modified": "2023-10-28T03:30:23Z",
"published": "2023-10-28T03:30:23Z",
"aliases": [
"CVE-2023-46467"
],
"details": "Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46467"
},
{
"type": "WEB",
"url": "https://www.sumor.top/index.php/archives/872/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34pm-grcc-xjrw",
"modified": "2023-10-25T18:32:21Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26577"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37gv-9q37-8946",
"modified": "2023-10-28T03:30:23Z",
"published": "2023-10-28T03:30:23Z",
"aliases": [
"CVE-2023-46569"
],
"details": "An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46569"
},
{
"type": "WEB",
"url": "https://github.com/radareorg/radare2/issues/22334"
},
{
"type": "WEB",
"url": "https://gist.github.com/gandalf4a/afeaf8cc958f95876f0ee245b8a002e8"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j9j-5462-cpx8",
"modified": "2023-10-22T18:30:17Z",
"modified": "2023-10-28T03:30:21Z",
"published": "2023-10-22T18:30:17Z",
"aliases": [
"CVE-2023-46303"
],
"details": "link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47h2-h6q2-ghrw",
"modified": "2023-10-23T00:30:21Z",
"modified": "2023-10-28T03:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-46319"
],
"details": "WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4869-ghp2-7x5q",
"modified": "2023-10-25T18:32:20Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26571"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f7j-xf8r-8572",
"modified": "2023-10-25T18:32:21Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26576"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r9r-cpgw-cf98",
"modified": "2023-10-25T18:32:20Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26574"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52hf-8hgx-m78v",
"modified": "2023-10-25T18:32:20Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:20Z",
"aliases": [
"CVE-2023-26570"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q42-rqhh-m4v6",
"modified": "2023-10-25T18:32:21Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-26584"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63rp-vfr8-4qw7",
"modified": "2023-10-25T18:32:21Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27375"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m4w-xmq7-g92p",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45767"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f74-9j92-993v",
"modified": "2023-10-25T18:32:21Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27254"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m68-3mc5-7wwf",
"modified": "2023-10-25T18:32:21Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-27262"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-834h-7mjv-2g94",
"modified": "2023-10-23T15:30:24Z",
"modified": "2023-10-28T03:30:21Z",
"published": "2023-10-23T15:30:24Z",
"aliases": [
"CVE-2023-42295"
],
"details": "An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rj7-wpfp-6wx5",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T03:30:22Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45764"

Some files were not shown because too many files have changed in this diff Show More