From 9f1de46e9bc7731f8d038c84a041b24c24f9e647 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 27 Jul 2022 00:15:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pxhp-rhgc-5jx8.json | 4 ++ .../GHSA-3m7c-wp57-w3xx.json | 7 ++- .../GHSA-hx54-cc43-34cx.json | 7 ++- .../GHSA-23v4-qfpm-c2cx.json | 37 +++++++++++++++ .../GHSA-269h-pcpx-q5mj.json | 11 +++-- .../GHSA-276r-jxx7-v78h.json | 37 +++++++++++++++ .../GHSA-287j-mmhv-xfrf.json | 11 +++-- .../GHSA-28mf-w32g-rfg3.json | 37 +++++++++++++++ .../GHSA-295j-q39j-ww99.json | 11 +++-- .../GHSA-2cw2-wqm2-wwp4.json | 37 +++++++++++++++ .../GHSA-2cxw-4p8f-4qp7.json | 11 +++-- .../GHSA-2j64-wxj4-5fr9.json | 11 +++-- .../GHSA-2jw2-755p-5gqq.json | 11 +++-- .../GHSA-2pxw-qgwm-32jg.json | 11 +++-- .../GHSA-2r7c-m53q-845g.json | 11 +++-- .../GHSA-32j7-h4wq-r683.json | 37 +++++++++++++++ .../GHSA-38f8-6mx5-p5qh.json | 37 +++++++++++++++ .../GHSA-39jx-jr53-979c.json | 4 ++ .../GHSA-39rf-5f5g-vgx4.json | 33 ++++++++++++++ .../GHSA-3c4j-vv65-mwcv.json | 11 +++-- .../GHSA-3f4p-c6pr-fmh6.json | 37 +++++++++++++++ .../GHSA-3fjm-4hqx-7gf9.json | 37 +++++++++++++++ .../GHSA-3fvq-f7qm-q85x.json | 11 +++-- .../GHSA-3jfr-38pr-8j88.json | 11 +++-- .../GHSA-3jxm-cp2c-65rc.json | 37 +++++++++++++++ .../GHSA-3mff-x894-pfqr.json | 41 +++++++++++++++++ .../GHSA-3qc4-32h5-3h38.json | 37 +++++++++++++++ .../GHSA-3rgq-2jwj-j6gp.json | 11 +++-- .../GHSA-3xxp-73wf-27cp.json | 11 +++-- .../GHSA-476m-73jc-7mhv.json | 11 +++-- .../GHSA-4838-8mrr-rfgx.json | 11 +++-- .../GHSA-48pf-mwxq-cwx2.json | 37 +++++++++++++++ .../GHSA-49rm-rmg5-26vv.json | 33 ++++++++++++++ .../GHSA-4hv9-5559-8wgx.json | 11 +++-- .../GHSA-4j9g-hqrw-w86v.json | 11 +++-- .../GHSA-4pjh-5r8h-799v.json | 11 +++-- .../GHSA-4v3r-qxrm-f63q.json | 11 +++-- .../GHSA-4wwc-c5pq-cg6h.json | 11 +++-- .../GHSA-5267-2g9r-5cqx.json | 11 +++-- .../GHSA-58vp-q2cc-5pv6.json | 9 ++-- .../GHSA-59rw-g46v-6c42.json | 37 +++++++++++++++ .../GHSA-5mrj-5fcq-p773.json | 11 +++-- .../GHSA-5pxp-49p6-8fh4.json | 37 +++++++++++++++ .../GHSA-5qrg-8qvc-xjrw.json | 11 +++-- .../GHSA-5r9q-ggch-qw5m.json | 11 +++-- .../GHSA-5rqp-fx48-4mvw.json | 33 ++++++++++++++ .../GHSA-5v79-69x6-rrhx.json | 11 +++-- .../GHSA-5v8q-fxc8-8r6j.json | 11 +++-- .../GHSA-5vj9-mj9w-qcwf.json | 11 +++-- .../GHSA-5x79-94mx-2478.json | 11 +++-- .../GHSA-5xh9-fg67-82m2.json | 37 +++++++++++++++ .../GHSA-5xjj-cf5g-659h.json | 37 +++++++++++++++ .../GHSA-628r-386p-mrwh.json | 11 +++-- .../GHSA-62q3-hj99-8qw6.json | 11 +++-- .../GHSA-634j-pc55-xw92.json | 37 +++++++++++++++ .../GHSA-64q4-mwrq-4jhh.json | 37 +++++++++++++++ .../GHSA-677q-j3cj-x856.json | 11 +++-- .../GHSA-6h74-22qj-hmh5.json | 11 +++-- .../GHSA-6phw-cwr4-6vjp.json | 33 ++++++++++++++ .../GHSA-6r9w-h2x2-322m.json | 11 +++-- .../GHSA-6rx6-6hh2-m59m.json | 37 +++++++++++++++ .../GHSA-6vf6-7rvh-mj29.json | 9 ++-- .../GHSA-6w2c-2wm7-v55g.json | 37 +++++++++++++++ .../GHSA-6xh3-23v2-92f6.json | 37 +++++++++++++++ .../GHSA-749r-f9hv-8wjr.json | 11 +++-- .../GHSA-75p7-x4r4-gq93.json | 11 +++-- .../GHSA-76rw-mc6q-q7vr.json | 33 ++++++++++++++ .../GHSA-77x9-gpjp-4v62.json | 9 ++-- .../GHSA-79fv-frff-xcj5.json | 37 +++++++++++++++ .../GHSA-79hq-4grw-2q67.json | 37 +++++++++++++++ .../GHSA-7qjg-f43c-j3qw.json | 33 ++++++++++++++ .../GHSA-7vgx-qf84-p43j.json | 37 +++++++++++++++ .../GHSA-7w77-5fq4-867j.json | 37 +++++++++++++++ .../GHSA-7wh9-3g36-rp79.json | 11 +++-- .../GHSA-8334-x488-rmxc.json | 11 +++-- .../GHSA-8477-jhrp-5h29.json | 37 +++++++++++++++ .../GHSA-84jr-whrm-qphm.json | 11 +++-- .../GHSA-85jh-g778-mw6j.json | 9 ++-- .../GHSA-877w-h65v-8769.json | 37 +++++++++++++++ .../GHSA-87p6-38m8-6j3g.json | 11 +++-- .../GHSA-87v5-8p6x-7f5p.json | 11 +++-- .../GHSA-8m53-wx9g-89jg.json | 11 +++-- .../GHSA-8w2f-5qfq-prwh.json | 37 +++++++++++++++ .../GHSA-8wv6-p7qp-76jg.json | 37 +++++++++++++++ .../GHSA-938x-v5pf-v989.json | 11 +++-- .../GHSA-9427-ppcj-49fw.json | 11 +++-- .../GHSA-949f-px3r-jjxq.json | 37 +++++++++++++++ .../GHSA-94vg-wrxf-f4p9.json | 11 +++-- .../GHSA-9696-j5vg-rfp4.json | 11 +++-- .../GHSA-9883-vwrj-2fq8.json | 37 +++++++++++++++ .../GHSA-9r83-5mrw-rhhq.json | 33 ++++++++++++++ .../GHSA-9rpr-9f6j-h9h9.json | 11 +++-- .../GHSA-9vmx-v4h8-hfv8.json | 37 +++++++++++++++ .../GHSA-9vwq-9f96-jpj4.json | 11 +++-- .../GHSA-c45v-hmq9-f7wx.json | 11 +++-- .../GHSA-c5rh-wr27-mrw6.json | 37 +++++++++++++++ .../GHSA-c629-2vqq-2cwp.json | 11 +++-- .../GHSA-c6wv-24cx-jxcg.json | 37 +++++++++++++++ .../GHSA-c7f2-2769-qw43.json | 37 +++++++++++++++ .../GHSA-c8mv-ccvj-9h5q.json | 37 +++++++++++++++ .../GHSA-c8qm-jmpw-q7p3.json | 11 +++-- .../GHSA-cf4p-6r33-8p4m.json | 37 +++++++++++++++ .../GHSA-cf5x-xcv3-5jx9.json | 37 +++++++++++++++ .../GHSA-f2h5-vm63-v6j2.json | 37 +++++++++++++++ .../GHSA-f3c3-7x6f-c89r.json | 33 ++++++++++++++ .../GHSA-f4c3-2f77-c7v4.json | 11 +++-- .../GHSA-f55m-jv7g-wxvq.json | 9 ++-- .../GHSA-f5vc-gmmj-gpp6.json | 45 +++++++++++++++++++ .../GHSA-f6fm-2783-5jg8.json | 11 +++-- .../GHSA-f79v-v4v7-4gjw.json | 11 +++-- .../GHSA-f7p7-wp94-6pj5.json | 37 +++++++++++++++ .../GHSA-f7rc-58qh-7pq6.json | 37 +++++++++++++++ .../GHSA-f85m-jgwf-rq28.json | 9 ++-- .../GHSA-ffp2-hg47-qhm4.json | 11 +++-- .../GHSA-fmxx-46x7-2phx.json | 37 +++++++++++++++ .../GHSA-fpjm-89fw-5vc4.json | 37 +++++++++++++++ .../GHSA-fqcp-q7w4-qwrv.json | 37 +++++++++++++++ .../GHSA-fw2j-wpp5-8vp5.json | 37 +++++++++++++++ .../GHSA-fwvp-h7wj-77r3.json | 11 +++-- .../GHSA-g4qp-7gv5-8gq3.json | 37 +++++++++++++++ .../GHSA-g5gx-5qf2-m4gh.json | 11 +++-- .../GHSA-g5vg-5fhw-c8xq.json | 37 +++++++++++++++ .../GHSA-g6j5-fhvr-ffx9.json | 37 +++++++++++++++ .../GHSA-g6p9-cjgh-r556.json | 37 +++++++++++++++ .../GHSA-gcw5-wf74-74mf.json | 41 +++++++++++++++++ .../GHSA-gg94-5w6h-vjm9.json | 11 +++-- .../GHSA-ggqp-g798-mjm6.json | 37 +++++++++++++++ .../GHSA-grcw-gw5m-hcg7.json | 37 +++++++++++++++ .../GHSA-gv4v-6v97-75hc.json | 11 +++-- .../GHSA-gvcp-c7h5-4wjc.json | 11 +++-- .../GHSA-gvxq-m6mh-2m6f.json | 11 +++-- .../GHSA-h2jm-fr8x-4cj2.json | 11 +++-- .../GHSA-h2vc-2q3g-w2jv.json | 11 +++-- .../GHSA-h5w7-83f8-c5fw.json | 11 +++-- .../GHSA-h6g6-h7qh-75h9.json | 9 ++-- .../GHSA-h6mp-42gx-78qp.json | 37 +++++++++++++++ .../GHSA-h72h-3xhv-hjq4.json | 11 +++-- .../GHSA-h7r9-gcj3-gr8x.json | 11 +++-- .../GHSA-h8hf-xhcx-q243.json | 33 ++++++++++++++ .../GHSA-h8vc-j6q3-h3ww.json | 11 +++-- .../GHSA-h9fc-rmrr-c2j6.json | 37 +++++++++++++++ .../GHSA-h9hg-fr26-64m4.json | 11 +++-- .../GHSA-hg7j-9h3g-36x3.json | 11 +++-- .../GHSA-hgvm-hcc2-jv5c.json | 37 +++++++++++++++ .../GHSA-hh6r-56fp-6x7j.json | 9 ++-- .../GHSA-hqhq-637w-p2h4.json | 11 +++-- .../GHSA-hvfw-pcx7-j7qm.json | 11 +++-- .../GHSA-hwjf-m968-wwpr.json | 11 +++-- .../GHSA-j23w-523j-9593.json | 11 +++-- .../GHSA-j3f8-fr5h-vwgv.json | 9 ++-- .../GHSA-j3p7-2565-q697.json | 11 +++-- .../GHSA-j4cc-vc2r-c4mh.json | 37 +++++++++++++++ .../GHSA-j4jc-fh4v-27gw.json | 37 +++++++++++++++ .../GHSA-j6m5-w993-29q5.json | 37 +++++++++++++++ .../GHSA-j6v3-2c6w-pwpm.json | 11 +++-- .../GHSA-jc2x-6mpj-q5vm.json | 11 +++-- .../GHSA-jm6f-2xgv-f2ch.json | 37 +++++++++++++++ .../GHSA-jp9m-h4rc-45p2.json | 37 +++++++++++++++ .../GHSA-jqmm-x5xp-f3pq.json | 37 +++++++++++++++ .../GHSA-jqw6-3hr5-834x.json | 11 +++-- .../GHSA-jr74-qgjg-jjph.json | 37 +++++++++++++++ .../GHSA-jvm7-g4w5-fq7f.json | 37 +++++++++++++++ .../GHSA-jwrh-hfpc-gvqc.json | 37 +++++++++++++++ .../GHSA-m28r-9pmc-xw7c.json | 9 ++-- .../GHSA-m5hw-3f6m-j7mr.json | 37 +++++++++++++++ .../GHSA-mc7p-qhj6-3j59.json | 37 +++++++++++++++ .../GHSA-mgmx-3854-pw2c.json | 11 +++-- .../GHSA-mhfc-wpjw-4hqq.json | 11 +++-- .../GHSA-mm5x-xpmp-2mrh.json | 37 +++++++++++++++ .../GHSA-mv8m-2w22-fqhx.json | 11 +++-- .../GHSA-p3fq-qpfq-6432.json | 9 ++-- .../GHSA-p438-c5rw-cq9h.json | 11 +++-- .../GHSA-p4gj-rmqv-7h27.json | 37 +++++++++++++++ .../GHSA-p8hj-ppgc-2ffw.json | 11 +++-- .../GHSA-p8ph-2j9w-cw6h.json | 11 +++-- .../GHSA-ph48-h9vm-5725.json | 11 +++-- .../GHSA-ph6r-j576-8v79.json | 37 +++++++++++++++ .../GHSA-pj9x-gphc-5865.json | 11 +++-- .../GHSA-pjfq-94vc-mg9w.json | 37 +++++++++++++++ .../GHSA-pp3f-g5wr-f3gv.json | 33 ++++++++++++++ .../GHSA-ppp3-fm6w-x37r.json | 11 +++-- .../GHSA-pwr2-748r-w9w2.json | 11 +++-- .../GHSA-px54-jwh8-83qg.json | 37 +++++++++++++++ .../GHSA-px79-w28w-3h24.json | 9 ++-- .../GHSA-pxjq-5cp2-gh7h.json | 11 +++-- .../GHSA-pxp4-v7r3-2566.json | 11 +++-- .../GHSA-pxr7-xpvp-73cx.json | 37 +++++++++++++++ .../GHSA-q25f-hc6j-2jpw.json | 37 +++++++++++++++ .../GHSA-q2f8-7m8g-86c8.json | 37 +++++++++++++++ .../GHSA-q2fw-5hw2-93cw.json | 11 +++-- .../GHSA-q8gm-6jc5-wp2m.json | 37 +++++++++++++++ .../GHSA-qc68-fgqr-q53f.json | 11 +++-- .../GHSA-qf39-vcfc-vp3j.json | 37 +++++++++++++++ .../GHSA-qgmh-3vp9-q7p2.json | 11 +++-- .../GHSA-r6mw-9h6p-mxpf.json | 37 +++++++++++++++ .../GHSA-r7cc-f77m-gvjj.json | 37 +++++++++++++++ .../GHSA-r83c-mvm8-r3mx.json | 11 +++-- .../GHSA-rc4m-xrpj-h9xf.json | 11 +++-- .../GHSA-rf45-cv27-9v2h.json | 11 +++-- .../GHSA-rhw2-x7mx-cp6j.json | 37 +++++++++++++++ .../GHSA-rr3h-mf64-3v5w.json | 9 ++-- .../GHSA-rv9v-5h43-6cc3.json | 11 +++-- .../GHSA-rwm7-p2mh-3fpc.json | 11 +++-- .../GHSA-v2x4-9328-wv22.json | 11 +++-- .../GHSA-v3p7-5h4w-xrjg.json | 37 +++++++++++++++ .../GHSA-v52h-39q4-ccvw.json | 37 +++++++++++++++ .../GHSA-v5pv-pxh3-g9pr.json | 37 +++++++++++++++ .../GHSA-v63h-gfjw-j838.json | 11 +++-- .../GHSA-v6c6-gcwr-p5pm.json | 11 +++-- .../GHSA-v898-xxg8-qvgf.json | 37 +++++++++++++++ .../GHSA-v9jr-g692-6qhv.json | 37 +++++++++++++++ .../GHSA-v9qw-g4pq-87mj.json | 11 +++-- .../GHSA-vcxg-6fqh-c65h.json | 11 +++-- .../GHSA-vmq3-255x-fhx5.json | 11 +++-- .../GHSA-vmwq-gw9g-wqfq.json | 11 +++-- .../GHSA-vp6v-57g2-v7vw.json | 11 +++-- .../GHSA-vq3c-fhqv-p29r.json | 37 +++++++++++++++ .../GHSA-vr6j-cw8v-2q76.json | 11 +++-- .../GHSA-vr8p-pf4j-6wrh.json | 33 ++++++++++++++ .../GHSA-vv47-5mh5-w3hq.json | 33 ++++++++++++++ .../GHSA-w2fx-43f2-2mgq.json | 9 ++-- .../GHSA-w2x5-64hf-jr76.json | 37 +++++++++++++++ .../GHSA-w497-f23v-cv57.json | 9 ++-- .../GHSA-w6jm-vwx5-6mm4.json | 11 +++-- .../GHSA-w6v8-54jm-g2j3.json | 37 +++++++++++++++ .../GHSA-wc6r-37r6-6c7q.json | 37 +++++++++++++++ .../GHSA-wm34-q93c-vxx8.json | 37 +++++++++++++++ .../GHSA-wmpw-gfmr-gv4v.json | 37 +++++++++++++++ .../GHSA-wmrr-g68f-2fhj.json | 11 +++-- .../GHSA-wpcm-pg4g-v7c4.json | 33 ++++++++++++++ .../GHSA-wpw2-w3qc-gx5g.json | 11 +++-- .../GHSA-wr45-8cqr-j247.json | 37 +++++++++++++++ .../GHSA-ww23-76gw-72m2.json | 11 +++-- .../GHSA-x59p-874g-35pw.json | 11 +++-- .../GHSA-x6hw-42rg-xj9m.json | 37 +++++++++++++++ .../GHSA-xc6r-vpp5-48cq.json | 37 +++++++++++++++ .../GHSA-xgjg-q85m-vvmx.json | 37 +++++++++++++++ .../GHSA-xhmx-2vhp-f3pq.json | 11 +++-- .../GHSA-xjhj-9v89-v9m8.json | 9 ++-- .../GHSA-xm6p-r726-3x76.json | 11 +++-- .../GHSA-xq3g-5rhc-pxgj.json | 4 ++ .../GHSA-xq4f-j8wj-pf7x.json | 37 +++++++++++++++ .../GHSA-xv5j-xw3x-cwr6.json | 37 +++++++++++++++ .../GHSA-xvx2-mpv8-r9xf.json | 37 +++++++++++++++ 244 files changed, 4973 insertions(+), 500 deletions(-) create mode 100644 advisories/unreviewed/2022/07/GHSA-23v4-qfpm-c2cx/GHSA-23v4-qfpm-c2cx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-276r-jxx7-v78h/GHSA-276r-jxx7-v78h.json create mode 100644 advisories/unreviewed/2022/07/GHSA-28mf-w32g-rfg3/GHSA-28mf-w32g-rfg3.json create mode 100644 advisories/unreviewed/2022/07/GHSA-2cw2-wqm2-wwp4/GHSA-2cw2-wqm2-wwp4.json create mode 100644 advisories/unreviewed/2022/07/GHSA-32j7-h4wq-r683/GHSA-32j7-h4wq-r683.json create mode 100644 advisories/unreviewed/2022/07/GHSA-38f8-6mx5-p5qh/GHSA-38f8-6mx5-p5qh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json create mode 100644 advisories/unreviewed/2022/07/GHSA-3f4p-c6pr-fmh6/GHSA-3f4p-c6pr-fmh6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-3fjm-4hqx-7gf9/GHSA-3fjm-4hqx-7gf9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-3jxm-cp2c-65rc/GHSA-3jxm-cp2c-65rc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-3mff-x894-pfqr/GHSA-3mff-x894-pfqr.json create mode 100644 advisories/unreviewed/2022/07/GHSA-3qc4-32h5-3h38/GHSA-3qc4-32h5-3h38.json create mode 100644 advisories/unreviewed/2022/07/GHSA-48pf-mwxq-cwx2/GHSA-48pf-mwxq-cwx2.json create mode 100644 advisories/unreviewed/2022/07/GHSA-49rm-rmg5-26vv/GHSA-49rm-rmg5-26vv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5pxp-49p6-8fh4/GHSA-5pxp-49p6-8fh4.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5rqp-fx48-4mvw/GHSA-5rqp-fx48-4mvw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5xh9-fg67-82m2/GHSA-5xh9-fg67-82m2.json create mode 100644 advisories/unreviewed/2022/07/GHSA-5xjj-cf5g-659h/GHSA-5xjj-cf5g-659h.json create mode 100644 advisories/unreviewed/2022/07/GHSA-634j-pc55-xw92/GHSA-634j-pc55-xw92.json create mode 100644 advisories/unreviewed/2022/07/GHSA-64q4-mwrq-4jhh/GHSA-64q4-mwrq-4jhh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6phw-cwr4-6vjp/GHSA-6phw-cwr4-6vjp.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6rx6-6hh2-m59m/GHSA-6rx6-6hh2-m59m.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6w2c-2wm7-v55g/GHSA-6w2c-2wm7-v55g.json create mode 100644 advisories/unreviewed/2022/07/GHSA-6xh3-23v2-92f6/GHSA-6xh3-23v2-92f6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-76rw-mc6q-q7vr/GHSA-76rw-mc6q-q7vr.json create mode 100644 advisories/unreviewed/2022/07/GHSA-79fv-frff-xcj5/GHSA-79fv-frff-xcj5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-79hq-4grw-2q67/GHSA-79hq-4grw-2q67.json create mode 100644 advisories/unreviewed/2022/07/GHSA-7qjg-f43c-j3qw/GHSA-7qjg-f43c-j3qw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-7vgx-qf84-p43j/GHSA-7vgx-qf84-p43j.json create mode 100644 advisories/unreviewed/2022/07/GHSA-7w77-5fq4-867j/GHSA-7w77-5fq4-867j.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8477-jhrp-5h29/GHSA-8477-jhrp-5h29.json create mode 100644 advisories/unreviewed/2022/07/GHSA-877w-h65v-8769/GHSA-877w-h65v-8769.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-8wv6-p7qp-76jg/GHSA-8wv6-p7qp-76jg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-949f-px3r-jjxq/GHSA-949f-px3r-jjxq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9883-vwrj-2fq8/GHSA-9883-vwrj-2fq8.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9r83-5mrw-rhhq/GHSA-9r83-5mrw-rhhq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-9vmx-v4h8-hfv8/GHSA-9vmx-v4h8-hfv8.json create mode 100644 advisories/unreviewed/2022/07/GHSA-c5rh-wr27-mrw6/GHSA-c5rh-wr27-mrw6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-c6wv-24cx-jxcg/GHSA-c6wv-24cx-jxcg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-c7f2-2769-qw43/GHSA-c7f2-2769-qw43.json create mode 100644 advisories/unreviewed/2022/07/GHSA-c8mv-ccvj-9h5q/GHSA-c8mv-ccvj-9h5q.json create mode 100644 advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json create mode 100644 advisories/unreviewed/2022/07/GHSA-cf5x-xcv3-5jx9/GHSA-cf5x-xcv3-5jx9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-f2h5-vm63-v6j2/GHSA-f2h5-vm63-v6j2.json create mode 100644 advisories/unreviewed/2022/07/GHSA-f3c3-7x6f-c89r/GHSA-f3c3-7x6f-c89r.json create mode 100644 advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-f7p7-wp94-6pj5/GHSA-f7p7-wp94-6pj5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-f7rc-58qh-7pq6/GHSA-f7rc-58qh-7pq6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fmxx-46x7-2phx/GHSA-fmxx-46x7-2phx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fpjm-89fw-5vc4/GHSA-fpjm-89fw-5vc4.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fqcp-q7w4-qwrv/GHSA-fqcp-q7w4-qwrv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-fw2j-wpp5-8vp5/GHSA-fw2j-wpp5-8vp5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-g4qp-7gv5-8gq3/GHSA-g4qp-7gv5-8gq3.json create mode 100644 advisories/unreviewed/2022/07/GHSA-g5vg-5fhw-c8xq/GHSA-g5vg-5fhw-c8xq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-g6j5-fhvr-ffx9/GHSA-g6j5-fhvr-ffx9.json create mode 100644 advisories/unreviewed/2022/07/GHSA-g6p9-cjgh-r556/GHSA-g6p9-cjgh-r556.json create mode 100644 advisories/unreviewed/2022/07/GHSA-gcw5-wf74-74mf/GHSA-gcw5-wf74-74mf.json create mode 100644 advisories/unreviewed/2022/07/GHSA-ggqp-g798-mjm6/GHSA-ggqp-g798-mjm6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-grcw-gw5m-hcg7/GHSA-grcw-gw5m-hcg7.json create mode 100644 advisories/unreviewed/2022/07/GHSA-h6mp-42gx-78qp/GHSA-h6mp-42gx-78qp.json create mode 100644 advisories/unreviewed/2022/07/GHSA-h8hf-xhcx-q243/GHSA-h8hf-xhcx-q243.json create mode 100644 advisories/unreviewed/2022/07/GHSA-h9fc-rmrr-c2j6/GHSA-h9fc-rmrr-c2j6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-hgvm-hcc2-jv5c/GHSA-hgvm-hcc2-jv5c.json create mode 100644 advisories/unreviewed/2022/07/GHSA-j4cc-vc2r-c4mh/GHSA-j4cc-vc2r-c4mh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-j4jc-fh4v-27gw/GHSA-j4jc-fh4v-27gw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-j6m5-w993-29q5/GHSA-j6m5-w993-29q5.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jm6f-2xgv-f2ch/GHSA-jm6f-2xgv-f2ch.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jp9m-h4rc-45p2/GHSA-jp9m-h4rc-45p2.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jqmm-x5xp-f3pq/GHSA-jqmm-x5xp-f3pq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jr74-qgjg-jjph/GHSA-jr74-qgjg-jjph.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jvm7-g4w5-fq7f/GHSA-jvm7-g4w5-fq7f.json create mode 100644 advisories/unreviewed/2022/07/GHSA-jwrh-hfpc-gvqc/GHSA-jwrh-hfpc-gvqc.json create mode 100644 advisories/unreviewed/2022/07/GHSA-m5hw-3f6m-j7mr/GHSA-m5hw-3f6m-j7mr.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mc7p-qhj6-3j59/GHSA-mc7p-qhj6-3j59.json create mode 100644 advisories/unreviewed/2022/07/GHSA-mm5x-xpmp-2mrh/GHSA-mm5x-xpmp-2mrh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-p4gj-rmqv-7h27/GHSA-p4gj-rmqv-7h27.json create mode 100644 advisories/unreviewed/2022/07/GHSA-ph6r-j576-8v79/GHSA-ph6r-j576-8v79.json create mode 100644 advisories/unreviewed/2022/07/GHSA-pjfq-94vc-mg9w/GHSA-pjfq-94vc-mg9w.json create mode 100644 advisories/unreviewed/2022/07/GHSA-pp3f-g5wr-f3gv/GHSA-pp3f-g5wr-f3gv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-px54-jwh8-83qg/GHSA-px54-jwh8-83qg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-pxr7-xpvp-73cx/GHSA-pxr7-xpvp-73cx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-q2f8-7m8g-86c8/GHSA-q2f8-7m8g-86c8.json create mode 100644 advisories/unreviewed/2022/07/GHSA-q8gm-6jc5-wp2m/GHSA-q8gm-6jc5-wp2m.json create mode 100644 advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json create mode 100644 advisories/unreviewed/2022/07/GHSA-r6mw-9h6p-mxpf/GHSA-r6mw-9h6p-mxpf.json create mode 100644 advisories/unreviewed/2022/07/GHSA-r7cc-f77m-gvjj/GHSA-r7cc-f77m-gvjj.json create mode 100644 advisories/unreviewed/2022/07/GHSA-rhw2-x7mx-cp6j/GHSA-rhw2-x7mx-cp6j.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v3p7-5h4w-xrjg/GHSA-v3p7-5h4w-xrjg.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v52h-39q4-ccvw/GHSA-v52h-39q4-ccvw.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v5pv-pxh3-g9pr/GHSA-v5pv-pxh3-g9pr.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v898-xxg8-qvgf/GHSA-v898-xxg8-qvgf.json create mode 100644 advisories/unreviewed/2022/07/GHSA-v9jr-g692-6qhv/GHSA-v9jr-g692-6qhv.json create mode 100644 advisories/unreviewed/2022/07/GHSA-vq3c-fhqv-p29r/GHSA-vq3c-fhqv-p29r.json create mode 100644 advisories/unreviewed/2022/07/GHSA-vr8p-pf4j-6wrh/GHSA-vr8p-pf4j-6wrh.json create mode 100644 advisories/unreviewed/2022/07/GHSA-vv47-5mh5-w3hq/GHSA-vv47-5mh5-w3hq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-w2x5-64hf-jr76/GHSA-w2x5-64hf-jr76.json create mode 100644 advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wc6r-37r6-6c7q/GHSA-wc6r-37r6-6c7q.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wm34-q93c-vxx8/GHSA-wm34-q93c-vxx8.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wmpw-gfmr-gv4v/GHSA-wmpw-gfmr-gv4v.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wpcm-pg4g-v7c4/GHSA-wpcm-pg4g-v7c4.json create mode 100644 advisories/unreviewed/2022/07/GHSA-wr45-8cqr-j247/GHSA-wr45-8cqr-j247.json create mode 100644 advisories/unreviewed/2022/07/GHSA-x6hw-42rg-xj9m/GHSA-x6hw-42rg-xj9m.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xc6r-vpp5-48cq/GHSA-xc6r-vpp5-48cq.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xgjg-q85m-vvmx/GHSA-xgjg-q85m-vvmx.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xq4f-j8wj-pf7x/GHSA-xq4f-j8wj-pf7x.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xv5j-xw3x-cwr6/GHSA-xv5j-xw3x-cwr6.json create mode 100644 advisories/unreviewed/2022/07/GHSA-xvx2-mpv8-r9xf/GHSA-xvx2-mpv8-r9xf.json diff --git a/advisories/unreviewed/2022/04/GHSA-pxhp-rhgc-5jx8/GHSA-pxhp-rhgc-5jx8.json b/advisories/unreviewed/2022/04/GHSA-pxhp-rhgc-5jx8/GHSA-pxhp-rhgc-5jx8.json index 542be23a0e8..09b4c1759c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-pxhp-rhgc-5jx8/GHSA-pxhp-rhgc-5jx8.json +++ b/advisories/unreviewed/2022/04/GHSA-pxhp-rhgc-5jx8/GHSA-pxhp-rhgc-5jx8.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/" + }, { "type": "WEB", "url": "https://lua-users.org/lists/lua-l/2022-02/msg00001.html" diff --git a/advisories/unreviewed/2022/05/GHSA-3m7c-wp57-w3xx/GHSA-3m7c-wp57-w3xx.json b/advisories/unreviewed/2022/05/GHSA-3m7c-wp57-w3xx/GHSA-3m7c-wp57-w3xx.json index 3b90eedc83c..507bc758ded 100644 --- a/advisories/unreviewed/2022/05/GHSA-3m7c-wp57-w3xx/GHSA-3m7c-wp57-w3xx.json +++ b/advisories/unreviewed/2022/05/GHSA-3m7c-wp57-w3xx/GHSA-3m7c-wp57-w3xx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3m7c-wp57-w3xx", - "modified": "2022-05-24T17:47:44Z", + "modified": "2022-07-27T00:00:48Z", "published": "2022-05-24T17:47:44Z", "aliases": [ "CVE-2020-9668" ], "details": "Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling symbolic links. An unauthenticated attacker could exploit this to elevate privileges in the context of the current user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hx54-cc43-34cx/GHSA-hx54-cc43-34cx.json b/advisories/unreviewed/2022/05/GHSA-hx54-cc43-34cx/GHSA-hx54-cc43-34cx.json index be045553e09..e0e3c1d97ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx54-cc43-34cx/GHSA-hx54-cc43-34cx.json +++ b/advisories/unreviewed/2022/05/GHSA-hx54-cc43-34cx/GHSA-hx54-cc43-34cx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hx54-cc43-34cx", - "modified": "2022-05-24T19:08:06Z", + "modified": "2022-07-27T00:00:46Z", "published": "2022-05-24T19:08:06Z", "aliases": [ "CVE-2021-0291" ], "details": "An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-level resource is not being sufficiently protected, allows a network-based unauthenticated attacker to send specific traffic which partially reaches this resource. A high rate of specific traffic may lead to a partial Denial of Service (DoS) as the CPU utilization of the RE is significantly increased. The SNMP Agent Extensibility (agentx) process should only be listening to TCP port 705 on the internal routing instance. External connections destined to port 705 should not be allowed. This issue affects: Juniper Networks Junos OS: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S12; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R2-S8; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2; 20.3 versions prior to 20.3R2. Juniper Networks Junos OS Evolved versions prior to 20.3R2-EVO. This issue does not affect Juniper Networks Junos OS versions prior to 13.2R1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/07/GHSA-23v4-qfpm-c2cx/GHSA-23v4-qfpm-c2cx.json b/advisories/unreviewed/2022/07/GHSA-23v4-qfpm-c2cx/GHSA-23v4-qfpm-c2cx.json new file mode 100644 index 00000000000..1bad3990b32 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-23v4-qfpm-c2cx/GHSA-23v4-qfpm-c2cx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-23v4-qfpm-c2cx", + "modified": "2022-07-27T00:00:30Z", + "published": "2022-07-27T00:00:30Z", + "aliases": [ + "CVE-2022-30272" + ], + "details": "The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or application images can be installed. Firmware updates for the Front End Processor (FEP) module are performed via access to the SSH interface (22/TCP), where a .hex file image is transferred and a bootloader script invoked. File system, kernel, package, and bundle updates are supplied as RPM (RPM Package Manager) files while FEP updates are supplied as S-rec files. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30272" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-06" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-269h-pcpx-q5mj/GHSA-269h-pcpx-q5mj.json b/advisories/unreviewed/2022/07/GHSA-269h-pcpx-q5mj/GHSA-269h-pcpx-q5mj.json index 5abf12f3b9f..254b64e50bd 100644 --- a/advisories/unreviewed/2022/07/GHSA-269h-pcpx-q5mj/GHSA-269h-pcpx-q5mj.json +++ b/advisories/unreviewed/2022/07/GHSA-269h-pcpx-q5mj/GHSA-269h-pcpx-q5mj.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-269h-pcpx-q5mj", - "modified": "2022-07-22T00:00:30Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:30Z", "aliases": [ "CVE-2022-0977" ], "details": "Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-276r-jxx7-v78h/GHSA-276r-jxx7-v78h.json b/advisories/unreviewed/2022/07/GHSA-276r-jxx7-v78h/GHSA-276r-jxx7-v78h.json new file mode 100644 index 00000000000..b8025c5ac99 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-276r-jxx7-v78h/GHSA-276r-jxx7-v78h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-276r-jxx7-v78h", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1634" + ], + "details": "Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific user interactions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1634" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1314908" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-287j-mmhv-xfrf/GHSA-287j-mmhv-xfrf.json b/advisories/unreviewed/2022/07/GHSA-287j-mmhv-xfrf/GHSA-287j-mmhv-xfrf.json index 7c840cf36ca..85e9347580a 100644 --- a/advisories/unreviewed/2022/07/GHSA-287j-mmhv-xfrf/GHSA-287j-mmhv-xfrf.json +++ b/advisories/unreviewed/2022/07/GHSA-287j-mmhv-xfrf/GHSA-287j-mmhv-xfrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-287j-mmhv-xfrf", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20876" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-28mf-w32g-rfg3/GHSA-28mf-w32g-rfg3.json b/advisories/unreviewed/2022/07/GHSA-28mf-w32g-rfg3/GHSA-28mf-w32g-rfg3.json new file mode 100644 index 00000000000..d7eafd71635 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-28mf-w32g-rfg3/GHSA-28mf-w32g-rfg3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-28mf-w32g-rfg3", + "modified": "2022-07-27T00:00:31Z", + "published": "2022-07-27T00:00:31Z", + "aliases": [ + "CVE-2021-33057" + ], + "details": "The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33057" + }, + { + "type": "WEB", + "url": "https://arxiv.org/pdf/2205.15202.pdf" + }, + { + "type": "WEB", + "url": "https://tencent.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-295j-q39j-ww99/GHSA-295j-q39j-ww99.json b/advisories/unreviewed/2022/07/GHSA-295j-q39j-ww99/GHSA-295j-q39j-ww99.json index e1b16bb9bf5..96973850e81 100644 --- a/advisories/unreviewed/2022/07/GHSA-295j-q39j-ww99/GHSA-295j-q39j-ww99.json +++ b/advisories/unreviewed/2022/07/GHSA-295j-q39j-ww99/GHSA-295j-q39j-ww99.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-295j-q39j-ww99", - "modified": "2022-07-22T00:00:34Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:34Z", "aliases": [ "CVE-2022-20885" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2cw2-wqm2-wwp4/GHSA-2cw2-wqm2-wwp4.json b/advisories/unreviewed/2022/07/GHSA-2cw2-wqm2-wwp4/GHSA-2cw2-wqm2-wwp4.json new file mode 100644 index 00000000000..1f2bda5bc24 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-2cw2-wqm2-wwp4/GHSA-2cw2-wqm2-wwp4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-2cw2-wqm2-wwp4", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29965" + ], + "details": "The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29965" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json b/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json index d6b68559a55..ba2474ebea4 100644 --- a/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json +++ b/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2cxw-4p8f-4qp7", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-1922" ], "details": "DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2j64-wxj4-5fr9/GHSA-2j64-wxj4-5fr9.json b/advisories/unreviewed/2022/07/GHSA-2j64-wxj4-5fr9/GHSA-2j64-wxj4-5fr9.json index daedcba7a08..43c7bfc59b0 100644 --- a/advisories/unreviewed/2022/07/GHSA-2j64-wxj4-5fr9/GHSA-2j64-wxj4-5fr9.json +++ b/advisories/unreviewed/2022/07/GHSA-2j64-wxj4-5fr9/GHSA-2j64-wxj4-5fr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2j64-wxj4-5fr9", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20910" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2jw2-755p-5gqq/GHSA-2jw2-755p-5gqq.json b/advisories/unreviewed/2022/07/GHSA-2jw2-755p-5gqq/GHSA-2jw2-755p-5gqq.json index fccac7133c3..703a070c68e 100644 --- a/advisories/unreviewed/2022/07/GHSA-2jw2-755p-5gqq/GHSA-2jw2-755p-5gqq.json +++ b/advisories/unreviewed/2022/07/GHSA-2jw2-755p-5gqq/GHSA-2jw2-755p-5gqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2jw2-755p-5gqq", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34534" ], "details": "Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json b/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json index 2b3a0267589..ff450d2f7c8 100644 --- a/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json +++ b/advisories/unreviewed/2022/07/GHSA-2pxw-qgwm-32jg/GHSA-2pxw-qgwm-32jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2pxw-qgwm-32jg", - "modified": "2022-07-22T00:00:32Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-22T00:00:32Z", "aliases": [ "CVE-2022-34487" ], "details": "Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-2r7c-m53q-845g/GHSA-2r7c-m53q-845g.json b/advisories/unreviewed/2022/07/GHSA-2r7c-m53q-845g/GHSA-2r7c-m53q-845g.json index 69a6c964676..de5c1b4335e 100644 --- a/advisories/unreviewed/2022/07/GHSA-2r7c-m53q-845g/GHSA-2r7c-m53q-845g.json +++ b/advisories/unreviewed/2022/07/GHSA-2r7c-m53q-845g/GHSA-2r7c-m53q-845g.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-2r7c-m53q-845g", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20880" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-32j7-h4wq-r683/GHSA-32j7-h4wq-r683.json b/advisories/unreviewed/2022/07/GHSA-32j7-h4wq-r683/GHSA-32j7-h4wq-r683.json new file mode 100644 index 00000000000..83d0494ac8d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-32j7-h4wq-r683/GHSA-32j7-h4wq-r683.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-32j7-h4wq-r683", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1491" + ], + "details": "Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1491" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1305706" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-38f8-6mx5-p5qh/GHSA-38f8-6mx5-p5qh.json b/advisories/unreviewed/2022/07/GHSA-38f8-6mx5-p5qh/GHSA-38f8-6mx5-p5qh.json new file mode 100644 index 00000000000..0161395b297 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-38f8-6mx5-p5qh/GHSA-38f8-6mx5-p5qh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-38f8-6mx5-p5qh", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1640" + ], + "details": "Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1640" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1320592" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-39jx-jr53-979c/GHSA-39jx-jr53-979c.json b/advisories/unreviewed/2022/07/GHSA-39jx-jr53-979c/GHSA-39jx-jr53-979c.json index 9960ecccb62..1cc58fd2513 100644 --- a/advisories/unreviewed/2022/07/GHSA-39jx-jr53-979c/GHSA-39jx-jr53-979c.json +++ b/advisories/unreviewed/2022/07/GHSA-39jx-jr53-979c/GHSA-39jx-jr53-979c.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670daf" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/" + }, { "type": "WEB", "url": "https://lua-users.org/lists/lua-l/2022-05/msg00035.html" diff --git a/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json b/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json new file mode 100644 index 00000000000..03cec91043e --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-39rf-5f5g-vgx4/GHSA-39rf-5f5g-vgx4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-39rf-5f5g-vgx4", + "modified": "2022-07-27T00:00:36Z", + "published": "2022-07-27T00:00:36Z", + "aliases": [ + "CVE-2022-1651" + ], + "details": "A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the ACRN Device Model emulates virtual NICs in VM. This flaw allows a local privileged attacker to leak unauthorized kernel information, causing a denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1651" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ecd1735f14d6ac868ae5d8b7a2bf193fa11f388b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3c4j-vv65-mwcv/GHSA-3c4j-vv65-mwcv.json b/advisories/unreviewed/2022/07/GHSA-3c4j-vv65-mwcv/GHSA-3c4j-vv65-mwcv.json index e00cfe450b8..760581011c1 100644 --- a/advisories/unreviewed/2022/07/GHSA-3c4j-vv65-mwcv/GHSA-3c4j-vv65-mwcv.json +++ b/advisories/unreviewed/2022/07/GHSA-3c4j-vv65-mwcv/GHSA-3c4j-vv65-mwcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3c4j-vv65-mwcv", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:32Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2492" ], "details": "A vulnerability was found in SourceCodester Library Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. The manipulation of the argument RollNo with the input admin' AND (SELECT 2625 FROM (SELECT(SLEEP(5)))MdIL) AND 'KXmq'='KXmq&Password=1231312312 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3f4p-c6pr-fmh6/GHSA-3f4p-c6pr-fmh6.json b/advisories/unreviewed/2022/07/GHSA-3f4p-c6pr-fmh6/GHSA-3f4p-c6pr-fmh6.json new file mode 100644 index 00000000000..0fe7e9d1c4e --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-3f4p-c6pr-fmh6/GHSA-3f4p-c6pr-fmh6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-3f4p-c6pr-fmh6", + "modified": "2022-07-27T00:00:39Z", + "published": "2022-07-27T00:00:39Z", + "aliases": [ + "CVE-2022-35286" + ], + "details": "IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35286" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230814" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6607057" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3fjm-4hqx-7gf9/GHSA-3fjm-4hqx-7gf9.json b/advisories/unreviewed/2022/07/GHSA-3fjm-4hqx-7gf9/GHSA-3fjm-4hqx-7gf9.json new file mode 100644 index 00000000000..210ef532464 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-3fjm-4hqx-7gf9/GHSA-3fjm-4hqx-7gf9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-3fjm-4hqx-7gf9", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1493" + ], + "details": "Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1493" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1275414" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3fvq-f7qm-q85x/GHSA-3fvq-f7qm-q85x.json b/advisories/unreviewed/2022/07/GHSA-3fvq-f7qm-q85x/GHSA-3fvq-f7qm-q85x.json index 242cbb2d5c5..8b034f0f6bb 100644 --- a/advisories/unreviewed/2022/07/GHSA-3fvq-f7qm-q85x/GHSA-3fvq-f7qm-q85x.json +++ b/advisories/unreviewed/2022/07/GHSA-3fvq-f7qm-q85x/GHSA-3fvq-f7qm-q85x.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3fvq-f7qm-q85x", - "modified": "2022-07-20T00:00:19Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-20T00:00:19Z", "aliases": [ "CVE-2022-22417" ], "details": "IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223127.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3jfr-38pr-8j88/GHSA-3jfr-38pr-8j88.json b/advisories/unreviewed/2022/07/GHSA-3jfr-38pr-8j88/GHSA-3jfr-38pr-8j88.json index 8b0aebaae69..e0f7bc42e48 100644 --- a/advisories/unreviewed/2022/07/GHSA-3jfr-38pr-8j88/GHSA-3jfr-38pr-8j88.json +++ b/advisories/unreviewed/2022/07/GHSA-3jfr-38pr-8j88/GHSA-3jfr-38pr-8j88.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3jfr-38pr-8j88", - "modified": "2022-07-21T00:00:25Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:25Z", "aliases": [ "CVE-2022-34586" ], "details": "itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3jxm-cp2c-65rc/GHSA-3jxm-cp2c-65rc.json b/advisories/unreviewed/2022/07/GHSA-3jxm-cp2c-65rc/GHSA-3jxm-cp2c-65rc.json new file mode 100644 index 00000000000..def030570c3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-3jxm-cp2c-65rc/GHSA-3jxm-cp2c-65rc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-3jxm-cp2c-65rc", + "modified": "2022-07-27T00:00:47Z", + "published": "2022-07-27T00:00:47Z", + "aliases": [ + "CVE-2022-30706" + ], + "details": "Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30706" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN75063798/" + }, + { + "type": "WEB", + "url": "https://www.bookedscheduler.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3mff-x894-pfqr/GHSA-3mff-x894-pfqr.json b/advisories/unreviewed/2022/07/GHSA-3mff-x894-pfqr/GHSA-3mff-x894-pfqr.json new file mode 100644 index 00000000000..45802a54315 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-3mff-x894-pfqr/GHSA-3mff-x894-pfqr.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-3mff-x894-pfqr", + "modified": "2022-07-27T00:00:31Z", + "published": "2022-07-27T00:00:31Z", + "aliases": [ + "CVE-2021-40180" + ], + "details": "In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40180" + }, + { + "type": "WEB", + "url": "https://arxiv.org/pdf/2205.15202.pdf" + }, + { + "type": "WEB", + "url": "https://pan.baidu.com/s/116sAQvs1CEzCeIfpI1NZvA" + }, + { + "type": "WEB", + "url": "https://pan.baidu.com/s/1RqMrZBruZZ4OHdnXUN5xDw" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3qc4-32h5-3h38/GHSA-3qc4-32h5-3h38.json b/advisories/unreviewed/2022/07/GHSA-3qc4-32h5-3h38/GHSA-3qc4-32h5-3h38.json new file mode 100644 index 00000000000..db054f93d1d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-3qc4-32h5-3h38/GHSA-3qc4-32h5-3h38.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-3qc4-32h5-3h38", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33449" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_get_by_offset() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33449" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/162" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3rgq-2jwj-j6gp/GHSA-3rgq-2jwj-j6gp.json b/advisories/unreviewed/2022/07/GHSA-3rgq-2jwj-j6gp/GHSA-3rgq-2jwj-j6gp.json index 002d03b9964..e8eabf415d2 100644 --- a/advisories/unreviewed/2022/07/GHSA-3rgq-2jwj-j6gp/GHSA-3rgq-2jwj-j6gp.json +++ b/advisories/unreviewed/2022/07/GHSA-3rgq-2jwj-j6gp/GHSA-3rgq-2jwj-j6gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3rgq-2jwj-j6gp", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34537" ], "details": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-3xxp-73wf-27cp/GHSA-3xxp-73wf-27cp.json b/advisories/unreviewed/2022/07/GHSA-3xxp-73wf-27cp/GHSA-3xxp-73wf-27cp.json index 6c4a971c21a..6a5dbe7b886 100644 --- a/advisories/unreviewed/2022/07/GHSA-3xxp-73wf-27cp/GHSA-3xxp-73wf-27cp.json +++ b/advisories/unreviewed/2022/07/GHSA-3xxp-73wf-27cp/GHSA-3xxp-73wf-27cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-3xxp-73wf-27cp", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2021-31858" ], "details": "DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-476m-73jc-7mhv/GHSA-476m-73jc-7mhv.json b/advisories/unreviewed/2022/07/GHSA-476m-73jc-7mhv/GHSA-476m-73jc-7mhv.json index fe45eb2e569..f4288fd0fff 100644 --- a/advisories/unreviewed/2022/07/GHSA-476m-73jc-7mhv/GHSA-476m-73jc-7mhv.json +++ b/advisories/unreviewed/2022/07/GHSA-476m-73jc-7mhv/GHSA-476m-73jc-7mhv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-476m-73jc-7mhv", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34538" ], "details": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4838-8mrr-rfgx/GHSA-4838-8mrr-rfgx.json b/advisories/unreviewed/2022/07/GHSA-4838-8mrr-rfgx/GHSA-4838-8mrr-rfgx.json index 6fb6fb45558..67fb153463f 100644 --- a/advisories/unreviewed/2022/07/GHSA-4838-8mrr-rfgx/GHSA-4838-8mrr-rfgx.json +++ b/advisories/unreviewed/2022/07/GHSA-4838-8mrr-rfgx/GHSA-4838-8mrr-rfgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4838-8mrr-rfgx", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20902" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-48pf-mwxq-cwx2/GHSA-48pf-mwxq-cwx2.json b/advisories/unreviewed/2022/07/GHSA-48pf-mwxq-cwx2/GHSA-48pf-mwxq-cwx2.json new file mode 100644 index 00000000000..584c3de6530 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-48pf-mwxq-cwx2/GHSA-48pf-mwxq-cwx2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-48pf-mwxq-cwx2", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1481" + ], + "details": "Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1481" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1302949" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-49rm-rmg5-26vv/GHSA-49rm-rmg5-26vv.json b/advisories/unreviewed/2022/07/GHSA-49rm-rmg5-26vv/GHSA-49rm-rmg5-26vv.json new file mode 100644 index 00000000000..36426b2a05c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-49rm-rmg5-26vv/GHSA-49rm-rmg5-26vv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-49rm-rmg5-26vv", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-34067" + ], + "details": "Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34067" + }, + { + "type": "WEB", + "url": "https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/2022/Warehouse-Management-System" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4hv9-5559-8wgx/GHSA-4hv9-5559-8wgx.json b/advisories/unreviewed/2022/07/GHSA-4hv9-5559-8wgx/GHSA-4hv9-5559-8wgx.json index f90a946f401..f79c8622bd9 100644 --- a/advisories/unreviewed/2022/07/GHSA-4hv9-5559-8wgx/GHSA-4hv9-5559-8wgx.json +++ b/advisories/unreviewed/2022/07/GHSA-4hv9-5559-8wgx/GHSA-4hv9-5559-8wgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4hv9-5559-8wgx", - "modified": "2022-07-21T00:00:25Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:25Z", "aliases": [ "CVE-2022-34588" ], "details": "itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/timetable_insert_form.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4j9g-hqrw-w86v/GHSA-4j9g-hqrw-w86v.json b/advisories/unreviewed/2022/07/GHSA-4j9g-hqrw-w86v/GHSA-4j9g-hqrw-w86v.json index 8cc185d150c..52dc51f8050 100644 --- a/advisories/unreviewed/2022/07/GHSA-4j9g-hqrw-w86v/GHSA-4j9g-hqrw-w86v.json +++ b/advisories/unreviewed/2022/07/GHSA-4j9g-hqrw-w86v/GHSA-4j9g-hqrw-w86v.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4j9g-hqrw-w86v", - "modified": "2022-07-19T00:00:22Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:22Z", "aliases": [ "CVE-2022-34637" ], "details": "CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4pjh-5r8h-799v/GHSA-4pjh-5r8h-799v.json b/advisories/unreviewed/2022/07/GHSA-4pjh-5r8h-799v/GHSA-4pjh-5r8h-799v.json index e977a3c9bb7..1b886956d7d 100644 --- a/advisories/unreviewed/2022/07/GHSA-4pjh-5r8h-799v/GHSA-4pjh-5r8h-799v.json +++ b/advisories/unreviewed/2022/07/GHSA-4pjh-5r8h-799v/GHSA-4pjh-5r8h-799v.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4pjh-5r8h-799v", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34600" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4v3r-qxrm-f63q/GHSA-4v3r-qxrm-f63q.json b/advisories/unreviewed/2022/07/GHSA-4v3r-qxrm-f63q/GHSA-4v3r-qxrm-f63q.json index 8e75b3830d9..b793f235a5a 100644 --- a/advisories/unreviewed/2022/07/GHSA-4v3r-qxrm-f63q/GHSA-4v3r-qxrm-f63q.json +++ b/advisories/unreviewed/2022/07/GHSA-4v3r-qxrm-f63q/GHSA-4v3r-qxrm-f63q.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4v3r-qxrm-f63q", - "modified": "2022-07-14T00:00:17Z", + "modified": "2022-07-27T00:00:48Z", "published": "2022-07-14T00:00:17Z", "aliases": [ "CVE-2022-32274" ], "details": "The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-4wwc-c5pq-cg6h/GHSA-4wwc-c5pq-cg6h.json b/advisories/unreviewed/2022/07/GHSA-4wwc-c5pq-cg6h/GHSA-4wwc-c5pq-cg6h.json index 72d39af00f8..76868c65141 100644 --- a/advisories/unreviewed/2022/07/GHSA-4wwc-c5pq-cg6h/GHSA-4wwc-c5pq-cg6h.json +++ b/advisories/unreviewed/2022/07/GHSA-4wwc-c5pq-cg6h/GHSA-4wwc-c5pq-cg6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-4wwc-c5pq-cg6h", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34609" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5267-2g9r-5cqx/GHSA-5267-2g9r-5cqx.json b/advisories/unreviewed/2022/07/GHSA-5267-2g9r-5cqx/GHSA-5267-2g9r-5cqx.json index fd5c54a386b..db42d3dd24a 100644 --- a/advisories/unreviewed/2022/07/GHSA-5267-2g9r-5cqx/GHSA-5267-2g9r-5cqx.json +++ b/advisories/unreviewed/2022/07/GHSA-5267-2g9r-5cqx/GHSA-5267-2g9r-5cqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5267-2g9r-5cqx", - "modified": "2022-07-22T00:00:32Z", + "modified": "2022-07-27T00:00:39Z", "published": "2022-07-22T00:00:32Z", "aliases": [ "CVE-2022-31475" ], "details": "Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-58vp-q2cc-5pv6/GHSA-58vp-q2cc-5pv6.json b/advisories/unreviewed/2022/07/GHSA-58vp-q2cc-5pv6/GHSA-58vp-q2cc-5pv6.json index bae19de48aa..a522dbcf2ee 100644 --- a/advisories/unreviewed/2022/07/GHSA-58vp-q2cc-5pv6/GHSA-58vp-q2cc-5pv6.json +++ b/advisories/unreviewed/2022/07/GHSA-58vp-q2cc-5pv6/GHSA-58vp-q2cc-5pv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-58vp-q2cc-5pv6", - "modified": "2022-07-23T00:00:19Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:19Z", "aliases": [ "CVE-2022-27235" ], "details": "Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json b/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json new file mode 100644 index 00000000000..1a8c614d588 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-59rw-g46v-6c42", + "modified": "2022-07-27T00:00:30Z", + "published": "2022-07-27T00:00:30Z", + "aliases": [ + "CVE-2022-30271" + ], + "details": "The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30271" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-06" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5mrj-5fcq-p773/GHSA-5mrj-5fcq-p773.json b/advisories/unreviewed/2022/07/GHSA-5mrj-5fcq-p773/GHSA-5mrj-5fcq-p773.json index 82ba3907cd4..77a3381ad5a 100644 --- a/advisories/unreviewed/2022/07/GHSA-5mrj-5fcq-p773/GHSA-5mrj-5fcq-p773.json +++ b/advisories/unreviewed/2022/07/GHSA-5mrj-5fcq-p773/GHSA-5mrj-5fcq-p773.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5mrj-5fcq-p773", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34536" ], "details": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5pxp-49p6-8fh4/GHSA-5pxp-49p6-8fh4.json b/advisories/unreviewed/2022/07/GHSA-5pxp-49p6-8fh4/GHSA-5pxp-49p6-8fh4.json new file mode 100644 index 00000000000..7a9668253ad --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5pxp-49p6-8fh4/GHSA-5pxp-49p6-8fh4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5pxp-49p6-8fh4", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1496" + ], + "details": "Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1496" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1306391" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5qrg-8qvc-xjrw/GHSA-5qrg-8qvc-xjrw.json b/advisories/unreviewed/2022/07/GHSA-5qrg-8qvc-xjrw/GHSA-5qrg-8qvc-xjrw.json index 08914767d3b..3499301cd26 100644 --- a/advisories/unreviewed/2022/07/GHSA-5qrg-8qvc-xjrw/GHSA-5qrg-8qvc-xjrw.json +++ b/advisories/unreviewed/2022/07/GHSA-5qrg-8qvc-xjrw/GHSA-5qrg-8qvc-xjrw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5qrg-8qvc-xjrw", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34633" ], "details": "CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5r9q-ggch-qw5m/GHSA-5r9q-ggch-qw5m.json b/advisories/unreviewed/2022/07/GHSA-5r9q-ggch-qw5m/GHSA-5r9q-ggch-qw5m.json index 8147bf15096..ead6ef24b3a 100644 --- a/advisories/unreviewed/2022/07/GHSA-5r9q-ggch-qw5m/GHSA-5r9q-ggch-qw5m.json +++ b/advisories/unreviewed/2022/07/GHSA-5r9q-ggch-qw5m/GHSA-5r9q-ggch-qw5m.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5r9q-ggch-qw5m", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-28888" ], "details": "Spryker Commerce OS 1.4.2 allows Remote Command Execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5rqp-fx48-4mvw/GHSA-5rqp-fx48-4mvw.json b/advisories/unreviewed/2022/07/GHSA-5rqp-fx48-4mvw/GHSA-5rqp-fx48-4mvw.json new file mode 100644 index 00000000000..2684c3acb2a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5rqp-fx48-4mvw/GHSA-5rqp-fx48-4mvw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5rqp-fx48-4mvw", + "modified": "2022-07-27T00:00:47Z", + "published": "2022-07-27T00:00:47Z", + "aliases": [ + "CVE-2021-43959" + ], + "details": "Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43959" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/JSDSERVER-11898" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5v79-69x6-rrhx/GHSA-5v79-69x6-rrhx.json b/advisories/unreviewed/2022/07/GHSA-5v79-69x6-rrhx/GHSA-5v79-69x6-rrhx.json index 156e47e225f..be9b517602e 100644 --- a/advisories/unreviewed/2022/07/GHSA-5v79-69x6-rrhx/GHSA-5v79-69x6-rrhx.json +++ b/advisories/unreviewed/2022/07/GHSA-5v79-69x6-rrhx/GHSA-5v79-69x6-rrhx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5v79-69x6-rrhx", - "modified": "2022-07-19T00:00:22Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-19T00:00:22Z", "aliases": [ "CVE-2022-34636" ], "details": "CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occurs during address translation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5v8q-fxc8-8r6j/GHSA-5v8q-fxc8-8r6j.json b/advisories/unreviewed/2022/07/GHSA-5v8q-fxc8-8r6j/GHSA-5v8q-fxc8-8r6j.json index ec0af5f890f..fe2ee6957a3 100644 --- a/advisories/unreviewed/2022/07/GHSA-5v8q-fxc8-8r6j/GHSA-5v8q-fxc8-8r6j.json +++ b/advisories/unreviewed/2022/07/GHSA-5v8q-fxc8-8r6j/GHSA-5v8q-fxc8-8r6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5v8q-fxc8-8r6j", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34607" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5vj9-mj9w-qcwf/GHSA-5vj9-mj9w-qcwf.json b/advisories/unreviewed/2022/07/GHSA-5vj9-mj9w-qcwf/GHSA-5vj9-mj9w-qcwf.json index 8fc1489719a..27a5764981b 100644 --- a/advisories/unreviewed/2022/07/GHSA-5vj9-mj9w-qcwf/GHSA-5vj9-mj9w-qcwf.json +++ b/advisories/unreviewed/2022/07/GHSA-5vj9-mj9w-qcwf/GHSA-5vj9-mj9w-qcwf.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5vj9-mj9w-qcwf", - "modified": "2022-07-22T00:00:31Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:31Z", "aliases": [ "CVE-2022-0973" ], "details": "Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5x79-94mx-2478/GHSA-5x79-94mx-2478.json b/advisories/unreviewed/2022/07/GHSA-5x79-94mx-2478/GHSA-5x79-94mx-2478.json index 61fe026c38d..bb02de05b99 100644 --- a/advisories/unreviewed/2022/07/GHSA-5x79-94mx-2478/GHSA-5x79-94mx-2478.json +++ b/advisories/unreviewed/2022/07/GHSA-5x79-94mx-2478/GHSA-5x79-94mx-2478.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-5x79-94mx-2478", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20877" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5xh9-fg67-82m2/GHSA-5xh9-fg67-82m2.json b/advisories/unreviewed/2022/07/GHSA-5xh9-fg67-82m2/GHSA-5xh9-fg67-82m2.json new file mode 100644 index 00000000000..7c50907bc30 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5xh9-fg67-82m2/GHSA-5xh9-fg67-82m2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5xh9-fg67-82m2", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33453" + ], + "details": "An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33453" + }, + { + "type": "WEB", + "url": "https://github.com/ckolivas/lrzip/issues/199" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-5xjj-cf5g-659h/GHSA-5xjj-cf5g-659h.json b/advisories/unreviewed/2022/07/GHSA-5xjj-cf5g-659h/GHSA-5xjj-cf5g-659h.json new file mode 100644 index 00000000000..3d509465ed9 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-5xjj-cf5g-659h/GHSA-5xjj-cf5g-659h.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-5xjj-cf5g-659h", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33468" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33468" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/162" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json b/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json index da57630fa2a..c4cdb517a01 100644 --- a/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json +++ b/advisories/unreviewed/2022/07/GHSA-628r-386p-mrwh/GHSA-628r-386p-mrwh.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-628r-386p-mrwh", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2488" ], "details": "A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-62q3-hj99-8qw6/GHSA-62q3-hj99-8qw6.json b/advisories/unreviewed/2022/07/GHSA-62q3-hj99-8qw6/GHSA-62q3-hj99-8qw6.json index 4378c21de3b..11bed66b1dd 100644 --- a/advisories/unreviewed/2022/07/GHSA-62q3-hj99-8qw6/GHSA-62q3-hj99-8qw6.json +++ b/advisories/unreviewed/2022/07/GHSA-62q3-hj99-8qw6/GHSA-62q3-hj99-8qw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-62q3-hj99-8qw6", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-2476" ], "details": "A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x561b47a970c6 bp 0x7fff13952fb0 sp 0x7fff1394fca0 T0) ==84257==The signal is caused by a WRITE memory access. ==84257==Hint: address points to the zero page. #0 0x561b47a970c5 in main cli/wvunpack.c:834 #1 0x7efc4f5c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) #2 0x561b47a945ed in _start (/usr/local/bin/wvunpack+0xa5ed) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV cli/wvunpack.c:834 in main ==84257==ABORTING", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-634j-pc55-xw92/GHSA-634j-pc55-xw92.json b/advisories/unreviewed/2022/07/GHSA-634j-pc55-xw92/GHSA-634j-pc55-xw92.json new file mode 100644 index 00000000000..ed9b03ee7c7 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-634j-pc55-xw92/GHSA-634j-pc55-xw92.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-634j-pc55-xw92", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1497" + ], + "details": "Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1497" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1264543" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-64q4-mwrq-4jhh/GHSA-64q4-mwrq-4jhh.json b/advisories/unreviewed/2022/07/GHSA-64q4-mwrq-4jhh/GHSA-64q4-mwrq-4jhh.json new file mode 100644 index 00000000000..14a04b24a8d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-64q4-mwrq-4jhh/GHSA-64q4-mwrq-4jhh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-64q4-mwrq-4jhh", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33447" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_print() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33447" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/164" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-677q-j3cj-x856/GHSA-677q-j3cj-x856.json b/advisories/unreviewed/2022/07/GHSA-677q-j3cj-x856/GHSA-677q-j3cj-x856.json index 73e4aaa0494..00fa29790f4 100644 --- a/advisories/unreviewed/2022/07/GHSA-677q-j3cj-x856/GHSA-677q-j3cj-x856.json +++ b/advisories/unreviewed/2022/07/GHSA-677q-j3cj-x856/GHSA-677q-j3cj-x856.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-677q-j3cj-x856", - "modified": "2022-07-22T00:00:36Z", + "modified": "2022-07-27T00:00:36Z", "published": "2022-07-22T00:00:36Z", "aliases": [ "CVE-2022-20890" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6h74-22qj-hmh5/GHSA-6h74-22qj-hmh5.json b/advisories/unreviewed/2022/07/GHSA-6h74-22qj-hmh5/GHSA-6h74-22qj-hmh5.json index 1d874e00711..fb06d09619f 100644 --- a/advisories/unreviewed/2022/07/GHSA-6h74-22qj-hmh5/GHSA-6h74-22qj-hmh5.json +++ b/advisories/unreviewed/2022/07/GHSA-6h74-22qj-hmh5/GHSA-6h74-22qj-hmh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-6h74-22qj-hmh5", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-22424" ], "details": "IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6phw-cwr4-6vjp/GHSA-6phw-cwr4-6vjp.json b/advisories/unreviewed/2022/07/GHSA-6phw-cwr4-6vjp/GHSA-6phw-cwr4-6vjp.json new file mode 100644 index 00000000000..96b70a4a035 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6phw-cwr4-6vjp/GHSA-6phw-cwr4-6vjp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6phw-cwr4-6vjp", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-34988" + ], + "details": "Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34988" + }, + { + "type": "WEB", + "url": "https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/Inout-Blockchain-AltExchanger/2022/Cross-site-scripting-DOM-based-IG-js" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6r9w-h2x2-322m/GHSA-6r9w-h2x2-322m.json b/advisories/unreviewed/2022/07/GHSA-6r9w-h2x2-322m/GHSA-6r9w-h2x2-322m.json index c0e5f2f11d0..1a7f93df24b 100644 --- a/advisories/unreviewed/2022/07/GHSA-6r9w-h2x2-322m/GHSA-6r9w-h2x2-322m.json +++ b/advisories/unreviewed/2022/07/GHSA-6r9w-h2x2-322m/GHSA-6r9w-h2x2-322m.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-6r9w-h2x2-322m", - "modified": "2022-07-22T00:00:31Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:31Z", "aliases": [ "CVE-2022-0974" ], "details": "Use after free in Splitscreen in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6rx6-6hh2-m59m/GHSA-6rx6-6hh2-m59m.json b/advisories/unreviewed/2022/07/GHSA-6rx6-6hh2-m59m/GHSA-6rx6-6hh2-m59m.json new file mode 100644 index 00000000000..6e4e02c6e06 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6rx6-6hh2-m59m/GHSA-6rx6-6hh2-m59m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6rx6-6hh2-m59m", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33440" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_commit() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33440" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/163" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6vf6-7rvh-mj29/GHSA-6vf6-7rvh-mj29.json b/advisories/unreviewed/2022/07/GHSA-6vf6-7rvh-mj29/GHSA-6vf6-7rvh-mj29.json index 1eedaaaea72..7745a16a6c7 100644 --- a/advisories/unreviewed/2022/07/GHSA-6vf6-7rvh-mj29/GHSA-6vf6-7rvh-mj29.json +++ b/advisories/unreviewed/2022/07/GHSA-6vf6-7rvh-mj29/GHSA-6vf6-7rvh-mj29.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-6vf6-7rvh-mj29", - "modified": "2022-07-20T00:00:22Z", + "modified": "2022-07-27T00:00:39Z", "published": "2022-07-20T00:00:22Z", "aliases": [ "CVE-2022-2453" ], "details": "Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6w2c-2wm7-v55g/GHSA-6w2c-2wm7-v55g.json b/advisories/unreviewed/2022/07/GHSA-6w2c-2wm7-v55g/GHSA-6w2c-2wm7-v55g.json new file mode 100644 index 00000000000..d39ac745e91 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6w2c-2wm7-v55g/GHSA-6w2c-2wm7-v55g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6w2c-2wm7-v55g", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1636" + ], + "details": "Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1636" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1297283" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-6xh3-23v2-92f6/GHSA-6xh3-23v2-92f6.json b/advisories/unreviewed/2022/07/GHSA-6xh3-23v2-92f6/GHSA-6xh3-23v2-92f6.json new file mode 100644 index 00000000000..1126ed6f076 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-6xh3-23v2-92f6/GHSA-6xh3-23v2-92f6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-6xh3-23v2-92f6", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1479" + ], + "details": "Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1479" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1305190" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-749r-f9hv-8wjr/GHSA-749r-f9hv-8wjr.json b/advisories/unreviewed/2022/07/GHSA-749r-f9hv-8wjr/GHSA-749r-f9hv-8wjr.json index e1b651b2b2e..c9a59bb73b0 100644 --- a/advisories/unreviewed/2022/07/GHSA-749r-f9hv-8wjr/GHSA-749r-f9hv-8wjr.json +++ b/advisories/unreviewed/2022/07/GHSA-749r-f9hv-8wjr/GHSA-749r-f9hv-8wjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-749r-f9hv-8wjr", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2490" ], "details": "A vulnerability classified as critical has been found in SourceCodester Simple E-Learning System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument classCode with the input 1'||(SELECT 0x74666264 WHERE 5610=5610 AND (SELECT 7504 FROM(SELECT COUNT(*),CONCAT(0x7171627a71,(SELECT (ELT(7504=7504,1))),0x71717a7071,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a))||' leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-75p7-x4r4-gq93/GHSA-75p7-x4r4-gq93.json b/advisories/unreviewed/2022/07/GHSA-75p7-x4r4-gq93/GHSA-75p7-x4r4-gq93.json index da8db9332f6..48d113f2d8f 100644 --- a/advisories/unreviewed/2022/07/GHSA-75p7-x4r4-gq93/GHSA-75p7-x4r4-gq93.json +++ b/advisories/unreviewed/2022/07/GHSA-75p7-x4r4-gq93/GHSA-75p7-x4r4-gq93.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-75p7-x4r4-gq93", - "modified": "2022-07-22T00:00:32Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-22T00:00:32Z", "aliases": [ "CVE-2022-33198" ], "details": "Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-76rw-mc6q-q7vr/GHSA-76rw-mc6q-q7vr.json b/advisories/unreviewed/2022/07/GHSA-76rw-mc6q-q7vr/GHSA-76rw-mc6q-q7vr.json new file mode 100644 index 00000000000..81c1ff57584 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-76rw-mc6q-q7vr/GHSA-76rw-mc6q-q7vr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-76rw-mc6q-q7vr", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-31879" + ], + "details": "Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31879" + }, + { + "type": "WEB", + "url": "https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/2022/Online-Fire-Reporting" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-77x9-gpjp-4v62/GHSA-77x9-gpjp-4v62.json b/advisories/unreviewed/2022/07/GHSA-77x9-gpjp-4v62/GHSA-77x9-gpjp-4v62.json index f1afe240d55..6975361f32a 100644 --- a/advisories/unreviewed/2022/07/GHSA-77x9-gpjp-4v62/GHSA-77x9-gpjp-4v62.json +++ b/advisories/unreviewed/2022/07/GHSA-77x9-gpjp-4v62/GHSA-77x9-gpjp-4v62.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-77x9-gpjp-4v62", - "modified": "2022-07-21T00:00:25Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:25Z", "aliases": [ "CVE-2022-29454" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-79fv-frff-xcj5/GHSA-79fv-frff-xcj5.json b/advisories/unreviewed/2022/07/GHSA-79fv-frff-xcj5/GHSA-79fv-frff-xcj5.json new file mode 100644 index 00000000000..22473c901c7 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-79fv-frff-xcj5/GHSA-79fv-frff-xcj5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-79fv-frff-xcj5", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29962" + ], + "details": "The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29962" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-79hq-4grw-2q67/GHSA-79hq-4grw-2q67.json b/advisories/unreviewed/2022/07/GHSA-79hq-4grw-2q67/GHSA-79hq-4grw-2q67.json new file mode 100644 index 00000000000..d9813b8cdab --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-79hq-4grw-2q67/GHSA-79hq-4grw-2q67.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-79hq-4grw-2q67", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33451" + ], + "details": "An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33451" + }, + { + "type": "WEB", + "url": "https://github.com/ckolivas/lrzip/issues/198" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7qjg-f43c-j3qw/GHSA-7qjg-f43c-j3qw.json b/advisories/unreviewed/2022/07/GHSA-7qjg-f43c-j3qw/GHSA-7qjg-f43c-j3qw.json new file mode 100644 index 00000000000..ae17a45b4e5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-7qjg-f43c-j3qw/GHSA-7qjg-f43c-j3qw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-7qjg-f43c-j3qw", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-34989" + ], + "details": "Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34989" + }, + { + "type": "WEB", + "url": "https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/Md-Saiful-Islam-creativesaiful/2021/Ecommerce-project-with-php-and-mysqli-Fruits-Bazar" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7vgx-qf84-p43j/GHSA-7vgx-qf84-p43j.json b/advisories/unreviewed/2022/07/GHSA-7vgx-qf84-p43j/GHSA-7vgx-qf84-p43j.json new file mode 100644 index 00000000000..f708dfee5b6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-7vgx-qf84-p43j/GHSA-7vgx-qf84-p43j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-7vgx-qf84-p43j", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1484" + ], + "details": "Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1484" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1297429" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7w77-5fq4-867j/GHSA-7w77-5fq4-867j.json b/advisories/unreviewed/2022/07/GHSA-7w77-5fq4-867j/GHSA-7w77-5fq4-867j.json new file mode 100644 index 00000000000..97c5e6813b8 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-7w77-5fq4-867j/GHSA-7w77-5fq4-867j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-7w77-5fq4-867j", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1498" + ], + "details": "Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1498" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1297138" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-7wh9-3g36-rp79/GHSA-7wh9-3g36-rp79.json b/advisories/unreviewed/2022/07/GHSA-7wh9-3g36-rp79/GHSA-7wh9-3g36-rp79.json index f7738d6b430..a9d2f99cc8b 100644 --- a/advisories/unreviewed/2022/07/GHSA-7wh9-3g36-rp79/GHSA-7wh9-3g36-rp79.json +++ b/advisories/unreviewed/2022/07/GHSA-7wh9-3g36-rp79/GHSA-7wh9-3g36-rp79.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-7wh9-3g36-rp79", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34634" ], "details": "CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8334-x488-rmxc/GHSA-8334-x488-rmxc.json b/advisories/unreviewed/2022/07/GHSA-8334-x488-rmxc/GHSA-8334-x488-rmxc.json index 50abfed73c3..b543e7ec1b2 100644 --- a/advisories/unreviewed/2022/07/GHSA-8334-x488-rmxc/GHSA-8334-x488-rmxc.json +++ b/advisories/unreviewed/2022/07/GHSA-8334-x488-rmxc/GHSA-8334-x488-rmxc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8334-x488-rmxc", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:36Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34603" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8477-jhrp-5h29/GHSA-8477-jhrp-5h29.json b/advisories/unreviewed/2022/07/GHSA-8477-jhrp-5h29/GHSA-8477-jhrp-5h29.json new file mode 100644 index 00000000000..063eec5c265 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8477-jhrp-5h29/GHSA-8477-jhrp-5h29.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8477-jhrp-5h29", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1486" + ], + "details": "Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1486" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1314616" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-84jr-whrm-qphm/GHSA-84jr-whrm-qphm.json b/advisories/unreviewed/2022/07/GHSA-84jr-whrm-qphm/GHSA-84jr-whrm-qphm.json index 198473855d6..dc6d9af55ec 100644 --- a/advisories/unreviewed/2022/07/GHSA-84jr-whrm-qphm/GHSA-84jr-whrm-qphm.json +++ b/advisories/unreviewed/2022/07/GHSA-84jr-whrm-qphm/GHSA-84jr-whrm-qphm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-84jr-whrm-qphm", - "modified": "2022-07-23T00:00:20Z", + "modified": "2022-07-27T00:00:39Z", "published": "2022-07-23T00:00:20Z", "aliases": [ "CVE-2022-33191" ], "details": "Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-85jh-g778-mw6j/GHSA-85jh-g778-mw6j.json b/advisories/unreviewed/2022/07/GHSA-85jh-g778-mw6j/GHSA-85jh-g778-mw6j.json index 334dc75ca06..9b6dca6046e 100644 --- a/advisories/unreviewed/2022/07/GHSA-85jh-g778-mw6j/GHSA-85jh-g778-mw6j.json +++ b/advisories/unreviewed/2022/07/GHSA-85jh-g778-mw6j/GHSA-85jh-g778-mw6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-85jh-g778-mw6j", - "modified": "2022-07-20T00:00:23Z", + "modified": "2022-07-27T00:00:39Z", "published": "2022-07-20T00:00:23Z", "aliases": [ "CVE-2022-2454" ], "details": "Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-877w-h65v-8769/GHSA-877w-h65v-8769.json b/advisories/unreviewed/2022/07/GHSA-877w-h65v-8769/GHSA-877w-h65v-8769.json new file mode 100644 index 00000000000..34346b812c9 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-877w-h65v-8769/GHSA-877w-h65v-8769.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-877w-h65v-8769", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33467" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33467" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/163" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-87p6-38m8-6j3g/GHSA-87p6-38m8-6j3g.json b/advisories/unreviewed/2022/07/GHSA-87p6-38m8-6j3g/GHSA-87p6-38m8-6j3g.json index 0532f3fb38c..7cc55fa8da0 100644 --- a/advisories/unreviewed/2022/07/GHSA-87p6-38m8-6j3g/GHSA-87p6-38m8-6j3g.json +++ b/advisories/unreviewed/2022/07/GHSA-87p6-38m8-6j3g/GHSA-87p6-38m8-6j3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-87p6-38m8-6j3g", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20873" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-87v5-8p6x-7f5p/GHSA-87v5-8p6x-7f5p.json b/advisories/unreviewed/2022/07/GHSA-87v5-8p6x-7f5p/GHSA-87v5-8p6x-7f5p.json index 9f1e137f211..ac48e5b3a83 100644 --- a/advisories/unreviewed/2022/07/GHSA-87v5-8p6x-7f5p/GHSA-87v5-8p6x-7f5p.json +++ b/advisories/unreviewed/2022/07/GHSA-87v5-8p6x-7f5p/GHSA-87v5-8p6x-7f5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-87v5-8p6x-7f5p", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34608" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8m53-wx9g-89jg/GHSA-8m53-wx9g-89jg.json b/advisories/unreviewed/2022/07/GHSA-8m53-wx9g-89jg/GHSA-8m53-wx9g-89jg.json index c0633cefbbd..7f5618c7229 100644 --- a/advisories/unreviewed/2022/07/GHSA-8m53-wx9g-89jg/GHSA-8m53-wx9g-89jg.json +++ b/advisories/unreviewed/2022/07/GHSA-8m53-wx9g-89jg/GHSA-8m53-wx9g-89jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-8m53-wx9g-89jg", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34535" ], "details": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json b/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json new file mode 100644 index 00000000000..f1996fcb99c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8w2f-5qfq-prwh", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29964" + ], + "details": "The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29964" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-8wv6-p7qp-76jg/GHSA-8wv6-p7qp-76jg.json b/advisories/unreviewed/2022/07/GHSA-8wv6-p7qp-76jg/GHSA-8wv6-p7qp-76jg.json new file mode 100644 index 00000000000..966870a9875 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-8wv6-p7qp-76jg/GHSA-8wv6-p7qp-76jg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-8wv6-p7qp-76jg", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1492" + ], + "details": "Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1492" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1315040" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-938x-v5pf-v989/GHSA-938x-v5pf-v989.json b/advisories/unreviewed/2022/07/GHSA-938x-v5pf-v989/GHSA-938x-v5pf-v989.json index 51b04994fed..1f66666df8d 100644 --- a/advisories/unreviewed/2022/07/GHSA-938x-v5pf-v989/GHSA-938x-v5pf-v989.json +++ b/advisories/unreviewed/2022/07/GHSA-938x-v5pf-v989/GHSA-938x-v5pf-v989.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-938x-v5pf-v989", - "modified": "2022-07-14T00:00:17Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:17Z", "aliases": [ "CVE-2022-32096" ], "details": "Rhonabwy before v1.1.5 was discovered to contain a buffer overflow via the component r_jwe_aesgcm_key_unwrap. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted JWE token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9427-ppcj-49fw/GHSA-9427-ppcj-49fw.json b/advisories/unreviewed/2022/07/GHSA-9427-ppcj-49fw/GHSA-9427-ppcj-49fw.json index 192435d3868..71815a5a7ad 100644 --- a/advisories/unreviewed/2022/07/GHSA-9427-ppcj-49fw/GHSA-9427-ppcj-49fw.json +++ b/advisories/unreviewed/2022/07/GHSA-9427-ppcj-49fw/GHSA-9427-ppcj-49fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9427-ppcj-49fw", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-1921" ], "details": "Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-949f-px3r-jjxq/GHSA-949f-px3r-jjxq.json b/advisories/unreviewed/2022/07/GHSA-949f-px3r-jjxq/GHSA-949f-px3r-jjxq.json new file mode 100644 index 00000000000..3c44cd48ec5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-949f-px3r-jjxq/GHSA-949f-px3r-jjxq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-949f-px3r-jjxq", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1489" + ], + "details": "Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1489" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1300561" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-94vg-wrxf-f4p9/GHSA-94vg-wrxf-f4p9.json b/advisories/unreviewed/2022/07/GHSA-94vg-wrxf-f4p9/GHSA-94vg-wrxf-f4p9.json index 83e1582b371..b381015403d 100644 --- a/advisories/unreviewed/2022/07/GHSA-94vg-wrxf-f4p9/GHSA-94vg-wrxf-f4p9.json +++ b/advisories/unreviewed/2022/07/GHSA-94vg-wrxf-f4p9/GHSA-94vg-wrxf-f4p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-94vg-wrxf-f4p9", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20238" ], "details": "'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions: Android SoCAndroid ID: A-233154555", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9696-j5vg-rfp4/GHSA-9696-j5vg-rfp4.json b/advisories/unreviewed/2022/07/GHSA-9696-j5vg-rfp4/GHSA-9696-j5vg-rfp4.json index 1242d039fb9..bc03ca9a62f 100644 --- a/advisories/unreviewed/2022/07/GHSA-9696-j5vg-rfp4/GHSA-9696-j5vg-rfp4.json +++ b/advisories/unreviewed/2022/07/GHSA-9696-j5vg-rfp4/GHSA-9696-j5vg-rfp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9696-j5vg-rfp4", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20912" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9883-vwrj-2fq8/GHSA-9883-vwrj-2fq8.json b/advisories/unreviewed/2022/07/GHSA-9883-vwrj-2fq8/GHSA-9883-vwrj-2fq8.json new file mode 100644 index 00000000000..ead2e9a04e2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9883-vwrj-2fq8/GHSA-9883-vwrj-2fq8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9883-vwrj-2fq8", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1477" + ], + "details": "Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1477" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1313905" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9r83-5mrw-rhhq/GHSA-9r83-5mrw-rhhq.json b/advisories/unreviewed/2022/07/GHSA-9r83-5mrw-rhhq/GHSA-9r83-5mrw-rhhq.json new file mode 100644 index 00000000000..db77de34b40 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9r83-5mrw-rhhq/GHSA-9r83-5mrw-rhhq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9r83-5mrw-rhhq", + "modified": "2022-07-27T00:00:47Z", + "published": "2022-07-27T00:00:47Z", + "aliases": [ + "CVE-2020-36290" + ], + "details": "The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36290" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/CONFSERVER-60118" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9rpr-9f6j-h9h9/GHSA-9rpr-9f6j-h9h9.json b/advisories/unreviewed/2022/07/GHSA-9rpr-9f6j-h9h9/GHSA-9rpr-9f6j-h9h9.json index 52c476d12b0..bde77ea6be1 100644 --- a/advisories/unreviewed/2022/07/GHSA-9rpr-9f6j-h9h9/GHSA-9rpr-9f6j-h9h9.json +++ b/advisories/unreviewed/2022/07/GHSA-9rpr-9f6j-h9h9/GHSA-9rpr-9f6j-h9h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9rpr-9f6j-h9h9", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34601" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9vmx-v4h8-hfv8/GHSA-9vmx-v4h8-hfv8.json b/advisories/unreviewed/2022/07/GHSA-9vmx-v4h8-hfv8/GHSA-9vmx-v4h8-hfv8.json new file mode 100644 index 00000000000..06ed107a187 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-9vmx-v4h8-hfv8/GHSA-9vmx-v4h8-hfv8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-9vmx-v4h8-hfv8", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1501" + ], + "details": "Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1501" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1293191" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-9vwq-9f96-jpj4/GHSA-9vwq-9f96-jpj4.json b/advisories/unreviewed/2022/07/GHSA-9vwq-9f96-jpj4/GHSA-9vwq-9f96-jpj4.json index e9b3cd706c4..33fe3d95ef2 100644 --- a/advisories/unreviewed/2022/07/GHSA-9vwq-9f96-jpj4/GHSA-9vwq-9f96-jpj4.json +++ b/advisories/unreviewed/2022/07/GHSA-9vwq-9f96-jpj4/GHSA-9vwq-9f96-jpj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-9vwq-9f96-jpj4", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34539" ], "details": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c45v-hmq9-f7wx/GHSA-c45v-hmq9-f7wx.json b/advisories/unreviewed/2022/07/GHSA-c45v-hmq9-f7wx/GHSA-c45v-hmq9-f7wx.json index 6801d290292..19ded9b439c 100644 --- a/advisories/unreviewed/2022/07/GHSA-c45v-hmq9-f7wx/GHSA-c45v-hmq9-f7wx.json +++ b/advisories/unreviewed/2022/07/GHSA-c45v-hmq9-f7wx/GHSA-c45v-hmq9-f7wx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-c45v-hmq9-f7wx", - "modified": "2022-07-14T00:00:17Z", + "modified": "2022-07-27T00:00:48Z", "published": "2022-07-14T00:00:17Z", "aliases": [ "CVE-2022-32073" ], "details": "WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c5rh-wr27-mrw6/GHSA-c5rh-wr27-mrw6.json b/advisories/unreviewed/2022/07/GHSA-c5rh-wr27-mrw6/GHSA-c5rh-wr27-mrw6.json new file mode 100644 index 00000000000..479582f8517 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-c5rh-wr27-mrw6/GHSA-c5rh-wr27-mrw6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-c5rh-wr27-mrw6", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-31205" + ], + "details": "In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31205" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c629-2vqq-2cwp/GHSA-c629-2vqq-2cwp.json b/advisories/unreviewed/2022/07/GHSA-c629-2vqq-2cwp/GHSA-c629-2vqq-2cwp.json index 17a0e24c982..2469ca125a3 100644 --- a/advisories/unreviewed/2022/07/GHSA-c629-2vqq-2cwp/GHSA-c629-2vqq-2cwp.json +++ b/advisories/unreviewed/2022/07/GHSA-c629-2vqq-2cwp/GHSA-c629-2vqq-2cwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-c629-2vqq-2cwp", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:32Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2489" ], "details": "A vulnerability was found in SourceCodester Simple E-Learning System 1.0. It has been rated as critical. This issue affects some unknown processing of the file classRoom.php. The manipulation of the argument classCode with the input 1'||(SELECT 0x6770715a WHERE 8795=8795 AND (SELECT 8342 FROM(SELECT COUNT(*),CONCAT(0x7171786b71,(SELECT (ELT(8342=8342,1))),0x717a7a7671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a))||' leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c6wv-24cx-jxcg/GHSA-c6wv-24cx-jxcg.json b/advisories/unreviewed/2022/07/GHSA-c6wv-24cx-jxcg/GHSA-c6wv-24cx-jxcg.json new file mode 100644 index 00000000000..2e62654ec06 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-c6wv-24cx-jxcg/GHSA-c6wv-24cx-jxcg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-c6wv-24cx-jxcg", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33459" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in nasm_parser_directive() in modules/parsers/nasm/nasm-parse.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33459" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/167" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c7f2-2769-qw43/GHSA-c7f2-2769-qw43.json b/advisories/unreviewed/2022/07/GHSA-c7f2-2769-qw43/GHSA-c7f2-2769-qw43.json new file mode 100644 index 00000000000..f1dba0df413 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-c7f2-2769-qw43/GHSA-c7f2-2769-qw43.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-c7f2-2769-qw43", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29951" + ], + "details": "JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29951" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-172-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c8mv-ccvj-9h5q/GHSA-c8mv-ccvj-9h5q.json b/advisories/unreviewed/2022/07/GHSA-c8mv-ccvj-9h5q/GHSA-c8mv-ccvj-9h5q.json new file mode 100644 index 00000000000..bfe3ec60e7a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-c8mv-ccvj-9h5q/GHSA-c8mv-ccvj-9h5q.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-c8mv-ccvj-9h5q", + "modified": "2022-07-27T00:00:30Z", + "published": "2022-07-27T00:00:30Z", + "aliases": [ + "CVE-2022-36129" + ], + "details": "HashiCorp Vault and Vault Enterprise through 2022-07-17 have Incorrect Access Control.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36129" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2022-15-vault-enterprise-does-not-verify-existing-voter-status-when-joining-an-integrated-storage-ha-node/42420" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-c8qm-jmpw-q7p3/GHSA-c8qm-jmpw-q7p3.json b/advisories/unreviewed/2022/07/GHSA-c8qm-jmpw-q7p3/GHSA-c8qm-jmpw-q7p3.json index 3249f85e326..9020f5a1446 100644 --- a/advisories/unreviewed/2022/07/GHSA-c8qm-jmpw-q7p3/GHSA-c8qm-jmpw-q7p3.json +++ b/advisories/unreviewed/2022/07/GHSA-c8qm-jmpw-q7p3/GHSA-c8qm-jmpw-q7p3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-c8qm-jmpw-q7p3", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2486" ], "details": "A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json b/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json new file mode 100644 index 00000000000..9a8b3035276 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cf4p-6r33-8p4m", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-27105" + ], + "details": "InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27105" + }, + { + "type": "WEB", + "url": "https://gist.github.com/TheWorkingDeveloper/9b7afbfe56938294480f7613805d3b7f" + }, + { + "type": "WEB", + "url": "http://www.inmailx.com/products/inmailx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-cf5x-xcv3-5jx9/GHSA-cf5x-xcv3-5jx9.json b/advisories/unreviewed/2022/07/GHSA-cf5x-xcv3-5jx9/GHSA-cf5x-xcv3-5jx9.json new file mode 100644 index 00000000000..ba2e2d6954d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-cf5x-xcv3-5jx9/GHSA-cf5x-xcv3-5jx9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-cf5x-xcv3-5jx9", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-31207" + ], + "details": "The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This protocol has authentication flaws as reported in FSCT-2022-0057. Control logic is downloaded to PLC volatile memory using the FINS Program Area Read and Program Area Write commands or to non-volatile memory using other commands from where it can be loaded into volatile memory for execution. The logic that is loaded into and executed from the user program area exists in compiled object code form. Upon execution, these object codes are first passed to a dedicated ASIC that determines whether the object code is to be executed by the ASIC or the microprocessor. In the former case, the object code is interpreted by the ASIC whereas in the latter case the object code is passed to the microprocessor for object code interpretation by a ROM interpreter. In the abnormal case where the object code cannot be handled by either, an abnormal condition is triggered and the PLC is halted. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, thus allowing an attacker to manipulate transmitted object code to the PLC and either execute arbitrary object code commands on the ASIC or on the microprocessor interpreter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31207" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f2h5-vm63-v6j2/GHSA-f2h5-vm63-v6j2.json b/advisories/unreviewed/2022/07/GHSA-f2h5-vm63-v6j2/GHSA-f2h5-vm63-v6j2.json new file mode 100644 index 00000000000..2e319a5522c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-f2h5-vm63-v6j2/GHSA-f2h5-vm63-v6j2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-f2h5-vm63-v6j2", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33458" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in find_cc() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33458" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/170" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f3c3-7x6f-c89r/GHSA-f3c3-7x6f-c89r.json b/advisories/unreviewed/2022/07/GHSA-f3c3-7x6f-c89r/GHSA-f3c3-7x6f-c89r.json new file mode 100644 index 00000000000..54b0657cf13 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-f3c3-7x6f-c89r/GHSA-f3c3-7x6f-c89r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-f3c3-7x6f-c89r", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-2225" + ], + "details": "By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/cloudflare/advisories/security/advisories/GHSA-cg88-vx48-976c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2225" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f4c3-2f77-c7v4/GHSA-f4c3-2f77-c7v4.json b/advisories/unreviewed/2022/07/GHSA-f4c3-2f77-c7v4/GHSA-f4c3-2f77-c7v4.json index 9d4e901be0a..94b0cde3ef4 100644 --- a/advisories/unreviewed/2022/07/GHSA-f4c3-2f77-c7v4/GHSA-f4c3-2f77-c7v4.json +++ b/advisories/unreviewed/2022/07/GHSA-f4c3-2f77-c7v4/GHSA-f4c3-2f77-c7v4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-f4c3-2f77-c7v4", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20883" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f55m-jv7g-wxvq/GHSA-f55m-jv7g-wxvq.json b/advisories/unreviewed/2022/07/GHSA-f55m-jv7g-wxvq/GHSA-f55m-jv7g-wxvq.json index 91b35813cf8..7d63d7ae249 100644 --- a/advisories/unreviewed/2022/07/GHSA-f55m-jv7g-wxvq/GHSA-f55m-jv7g-wxvq.json +++ b/advisories/unreviewed/2022/07/GHSA-f55m-jv7g-wxvq/GHSA-f55m-jv7g-wxvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-f55m-jv7g-wxvq", - "modified": "2022-07-23T00:00:20Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-23T00:00:20Z", "aliases": [ "CVE-2022-33960" ], "details": "Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json b/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json new file mode 100644 index 00000000000..525aa99c8f7 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-f5vc-gmmj-gpp6/GHSA-f5vc-gmmj-gpp6.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-f5vc-gmmj-gpp6", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-33745" + ], + "details": "insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33745" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-408.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/26/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2022/07/26/3" + }, + { + "type": "WEB", + "url": "http://xenbits.xen.org/xsa/advisory-408.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f6fm-2783-5jg8/GHSA-f6fm-2783-5jg8.json b/advisories/unreviewed/2022/07/GHSA-f6fm-2783-5jg8/GHSA-f6fm-2783-5jg8.json index c273c465633..e80b096b393 100644 --- a/advisories/unreviewed/2022/07/GHSA-f6fm-2783-5jg8/GHSA-f6fm-2783-5jg8.json +++ b/advisories/unreviewed/2022/07/GHSA-f6fm-2783-5jg8/GHSA-f6fm-2783-5jg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-f6fm-2783-5jg8", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20901" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f79v-v4v7-4gjw/GHSA-f79v-v4v7-4gjw.json b/advisories/unreviewed/2022/07/GHSA-f79v-v4v7-4gjw/GHSA-f79v-v4v7-4gjw.json index e4c0974a6c0..e97f1e37301 100644 --- a/advisories/unreviewed/2022/07/GHSA-f79v-v4v7-4gjw/GHSA-f79v-v4v7-4gjw.json +++ b/advisories/unreviewed/2022/07/GHSA-f79v-v4v7-4gjw/GHSA-f79v-v4v7-4gjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-f79v-v4v7-4gjw", - "modified": "2022-07-19T00:00:22Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:22Z", "aliases": [ "CVE-2022-34643" ], "details": "RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 implements the incorrect exception priotrity when accessing memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f7p7-wp94-6pj5/GHSA-f7p7-wp94-6pj5.json b/advisories/unreviewed/2022/07/GHSA-f7p7-wp94-6pj5/GHSA-f7p7-wp94-6pj5.json new file mode 100644 index 00000000000..3ce4e53258a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-f7p7-wp94-6pj5/GHSA-f7p7-wp94-6pj5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-f7p7-wp94-6pj5", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1635" + ], + "details": "Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1635" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1319797" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f7rc-58qh-7pq6/GHSA-f7rc-58qh-7pq6.json b/advisories/unreviewed/2022/07/GHSA-f7rc-58qh-7pq6/GHSA-f7rc-58qh-7pq6.json new file mode 100644 index 00000000000..f5b370683ab --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-f7rc-58qh-7pq6/GHSA-f7rc-58qh-7pq6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-f7rc-58qh-7pq6", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1637" + ], + "details": "Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1637" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1311820" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-f85m-jgwf-rq28/GHSA-f85m-jgwf-rq28.json b/advisories/unreviewed/2022/07/GHSA-f85m-jgwf-rq28/GHSA-f85m-jgwf-rq28.json index 45c0076d19d..6e13dbce379 100644 --- a/advisories/unreviewed/2022/07/GHSA-f85m-jgwf-rq28/GHSA-f85m-jgwf-rq28.json +++ b/advisories/unreviewed/2022/07/GHSA-f85m-jgwf-rq28/GHSA-f85m-jgwf-rq28.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-f85m-jgwf-rq28", - "modified": "2022-07-19T00:00:22Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:22Z", "aliases": [ "CVE-2022-34640" ], "details": "The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a was discovered to be incorrect.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-ffp2-hg47-qhm4/GHSA-ffp2-hg47-qhm4.json b/advisories/unreviewed/2022/07/GHSA-ffp2-hg47-qhm4/GHSA-ffp2-hg47-qhm4.json index 02ba2adff6d..e1b02de1f9a 100644 --- a/advisories/unreviewed/2022/07/GHSA-ffp2-hg47-qhm4/GHSA-ffp2-hg47-qhm4.json +++ b/advisories/unreviewed/2022/07/GHSA-ffp2-hg47-qhm4/GHSA-ffp2-hg47-qhm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-ffp2-hg47-qhm4", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20903" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fmxx-46x7-2phx/GHSA-fmxx-46x7-2phx.json b/advisories/unreviewed/2022/07/GHSA-fmxx-46x7-2phx/GHSA-fmxx-46x7-2phx.json new file mode 100644 index 00000000000..c082760dbfb --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fmxx-46x7-2phx/GHSA-fmxx-46x7-2phx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fmxx-46x7-2phx", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33452" + ], + "details": "An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33452" + }, + { + "type": "WEB", + "url": "https://bugzilla.nasm.us/show_bug.cgi?id=3392757" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fpjm-89fw-5vc4/GHSA-fpjm-89fw-5vc4.json b/advisories/unreviewed/2022/07/GHSA-fpjm-89fw-5vc4/GHSA-fpjm-89fw-5vc4.json new file mode 100644 index 00000000000..f79ec9ef12e --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fpjm-89fw-5vc4/GHSA-fpjm-89fw-5vc4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fpjm-89fw-5vc4", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33441" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in exec_expr() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33441" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/165" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fqcp-q7w4-qwrv/GHSA-fqcp-q7w4-qwrv.json b/advisories/unreviewed/2022/07/GHSA-fqcp-q7w4-qwrv/GHSA-fqcp-q7w4-qwrv.json new file mode 100644 index 00000000000..660f61599f7 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fqcp-q7w4-qwrv/GHSA-fqcp-q7w4-qwrv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fqcp-q7w4-qwrv", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1641" + ], + "details": "Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interaction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1641" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1305068" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fw2j-wpp5-8vp5/GHSA-fw2j-wpp5-8vp5.json b/advisories/unreviewed/2022/07/GHSA-fw2j-wpp5-8vp5/GHSA-fw2j-wpp5-8vp5.json new file mode 100644 index 00000000000..d2737a26c64 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-fw2j-wpp5-8vp5/GHSA-fw2j-wpp5-8vp5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-fw2j-wpp5-8vp5", + "modified": "2022-07-27T00:00:31Z", + "published": "2022-07-27T00:00:31Z", + "aliases": [ + "CVE-2022-31206" + ], + "details": "The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native machine code for execution by the PLC's runtime). The resulting machine code is executed by a runtime, typically controlled by a real-time operating system. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, allowing an attacker to manipulate transmitted object code to the PLC and execute arbitrary machine code on the processor of the PLC's CPU module in the context of the runtime. In the case of at least the NJ series, an RTOS and hardware combination is used that would potentially allow for memory protection and privilege separation and thus limit the impact of code execution. However, it was not confirmed whether these sufficiently segment the runtime from the rest of the RTOS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31206" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-fwvp-h7wj-77r3/GHSA-fwvp-h7wj-77r3.json b/advisories/unreviewed/2022/07/GHSA-fwvp-h7wj-77r3/GHSA-fwvp-h7wj-77r3.json index 32be034a2a3..2712b756916 100644 --- a/advisories/unreviewed/2022/07/GHSA-fwvp-h7wj-77r3/GHSA-fwvp-h7wj-77r3.json +++ b/advisories/unreviewed/2022/07/GHSA-fwvp-h7wj-77r3/GHSA-fwvp-h7wj-77r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-fwvp-h7wj-77r3", - "modified": "2022-07-22T00:00:34Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:34Z", "aliases": [ "CVE-2022-20884" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g4qp-7gv5-8gq3/GHSA-g4qp-7gv5-8gq3.json b/advisories/unreviewed/2022/07/GHSA-g4qp-7gv5-8gq3/GHSA-g4qp-7gv5-8gq3.json new file mode 100644 index 00000000000..8ca75059483 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-g4qp-7gv5-8gq3/GHSA-g4qp-7gv5-8gq3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-g4qp-7gv5-8gq3", + "modified": "2022-07-27T00:00:39Z", + "published": "2022-07-27T00:00:39Z", + "aliases": [ + "CVE-2022-35639" + ], + "details": "IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35639" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230932" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6606969" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g5gx-5qf2-m4gh/GHSA-g5gx-5qf2-m4gh.json b/advisories/unreviewed/2022/07/GHSA-g5gx-5qf2-m4gh/GHSA-g5gx-5qf2-m4gh.json index b80e99ce527..60d833f4728 100644 --- a/advisories/unreviewed/2022/07/GHSA-g5gx-5qf2-m4gh/GHSA-g5gx-5qf2-m4gh.json +++ b/advisories/unreviewed/2022/07/GHSA-g5gx-5qf2-m4gh/GHSA-g5gx-5qf2-m4gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-g5gx-5qf2-m4gh", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20896" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g5vg-5fhw-c8xq/GHSA-g5vg-5fhw-c8xq.json b/advisories/unreviewed/2022/07/GHSA-g5vg-5fhw-c8xq/GHSA-g5vg-5fhw-c8xq.json new file mode 100644 index 00000000000..4a32809a992 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-g5vg-5fhw-c8xq/GHSA-g5vg-5fhw-c8xq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-g5vg-5fhw-c8xq", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1485" + ], + "details": "Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1485" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1299743" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g6j5-fhvr-ffx9/GHSA-g6j5-fhvr-ffx9.json b/advisories/unreviewed/2022/07/GHSA-g6j5-fhvr-ffx9/GHSA-g6j5-fhvr-ffx9.json new file mode 100644 index 00000000000..2a9e35b8d24 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-g6j5-fhvr-ffx9/GHSA-g6j5-fhvr-ffx9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-g6j5-fhvr-ffx9", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33462" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a use-after-free in expr_traverse_nodes_post() in libyasm/expr.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33462" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/165" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-g6p9-cjgh-r556/GHSA-g6p9-cjgh-r556.json b/advisories/unreviewed/2022/07/GHSA-g6p9-cjgh-r556/GHSA-g6p9-cjgh-r556.json new file mode 100644 index 00000000000..faa5a9a61d4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-g6p9-cjgh-r556/GHSA-g6p9-cjgh-r556.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-g6p9-cjgh-r556", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33455" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in do_directive() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33455" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/169" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gcw5-wf74-74mf/GHSA-gcw5-wf74-74mf.json b/advisories/unreviewed/2022/07/GHSA-gcw5-wf74-74mf/GHSA-gcw5-wf74-74mf.json new file mode 100644 index 00000000000..e3f94c794a2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-gcw5-wf74-74mf/GHSA-gcw5-wf74-74mf.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-gcw5-wf74-74mf", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-30273" + ], + "details": "The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30273" + }, + { + "type": "WEB", + "url": "https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-05" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gg94-5w6h-vjm9/GHSA-gg94-5w6h-vjm9.json b/advisories/unreviewed/2022/07/GHSA-gg94-5w6h-vjm9/GHSA-gg94-5w6h-vjm9.json index d3b3fc45e5a..4ab6b8130fd 100644 --- a/advisories/unreviewed/2022/07/GHSA-gg94-5w6h-vjm9/GHSA-gg94-5w6h-vjm9.json +++ b/advisories/unreviewed/2022/07/GHSA-gg94-5w6h-vjm9/GHSA-gg94-5w6h-vjm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gg94-5w6h-vjm9", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20911" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-ggqp-g798-mjm6/GHSA-ggqp-g798-mjm6.json b/advisories/unreviewed/2022/07/GHSA-ggqp-g798-mjm6/GHSA-ggqp-g798-mjm6.json new file mode 100644 index 00000000000..6b71ad9d840 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-ggqp-g798-mjm6/GHSA-ggqp-g798-mjm6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-ggqp-g798-mjm6", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33457" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmac_params() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33457" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/171" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-grcw-gw5m-hcg7/GHSA-grcw-gw5m-hcg7.json b/advisories/unreviewed/2022/07/GHSA-grcw-gw5m-hcg7/GHSA-grcw-gw5m-hcg7.json new file mode 100644 index 00000000000..b931d7630fd --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-grcw-gw5m-hcg7/GHSA-grcw-gw5m-hcg7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-grcw-gw5m-hcg7", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1494" + ], + "details": "Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1494" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1298122" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gv4v-6v97-75hc/GHSA-gv4v-6v97-75hc.json b/advisories/unreviewed/2022/07/GHSA-gv4v-6v97-75hc/GHSA-gv4v-6v97-75hc.json index 936adfe8b9c..e18fc80e535 100644 --- a/advisories/unreviewed/2022/07/GHSA-gv4v-6v97-75hc/GHSA-gv4v-6v97-75hc.json +++ b/advisories/unreviewed/2022/07/GHSA-gv4v-6v97-75hc/GHSA-gv4v-6v97-75hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gv4v-6v97-75hc", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2487" ], "details": "A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gvcp-c7h5-4wjc/GHSA-gvcp-c7h5-4wjc.json b/advisories/unreviewed/2022/07/GHSA-gvcp-c7h5-4wjc/GHSA-gvcp-c7h5-4wjc.json index b5d2c800077..cc5c898d1da 100644 --- a/advisories/unreviewed/2022/07/GHSA-gvcp-c7h5-4wjc/GHSA-gvcp-c7h5-4wjc.json +++ b/advisories/unreviewed/2022/07/GHSA-gvcp-c7h5-4wjc/GHSA-gvcp-c7h5-4wjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gvcp-c7h5-4wjc", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20226" ], "details": "In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213644870", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "LOW", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-gvxq-m6mh-2m6f/GHSA-gvxq-m6mh-2m6f.json b/advisories/unreviewed/2022/07/GHSA-gvxq-m6mh-2m6f/GHSA-gvxq-m6mh-2m6f.json index 237f943995c..209dcb4fa2f 100644 --- a/advisories/unreviewed/2022/07/GHSA-gvxq-m6mh-2m6f/GHSA-gvxq-m6mh-2m6f.json +++ b/advisories/unreviewed/2022/07/GHSA-gvxq-m6mh-2m6f/GHSA-gvxq-m6mh-2m6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-gvxq-m6mh-2m6f", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20899" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h2jm-fr8x-4cj2/GHSA-h2jm-fr8x-4cj2.json b/advisories/unreviewed/2022/07/GHSA-h2jm-fr8x-4cj2/GHSA-h2jm-fr8x-4cj2.json index a4ae248ee9e..1373d617334 100644 --- a/advisories/unreviewed/2022/07/GHSA-h2jm-fr8x-4cj2/GHSA-h2jm-fr8x-4cj2.json +++ b/advisories/unreviewed/2022/07/GHSA-h2jm-fr8x-4cj2/GHSA-h2jm-fr8x-4cj2.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h2jm-fr8x-4cj2", - "modified": "2022-07-22T00:00:31Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:31Z", "aliases": [ "CVE-2022-0971" ], "details": "Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h2vc-2q3g-w2jv/GHSA-h2vc-2q3g-w2jv.json b/advisories/unreviewed/2022/07/GHSA-h2vc-2q3g-w2jv/GHSA-h2vc-2q3g-w2jv.json index 610ed19156c..fe6320b722b 100644 --- a/advisories/unreviewed/2022/07/GHSA-h2vc-2q3g-w2jv/GHSA-h2vc-2q3g-w2jv.json +++ b/advisories/unreviewed/2022/07/GHSA-h2vc-2q3g-w2jv/GHSA-h2vc-2q3g-w2jv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h2vc-2q3g-w2jv", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34610" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h5w7-83f8-c5fw/GHSA-h5w7-83f8-c5fw.json b/advisories/unreviewed/2022/07/GHSA-h5w7-83f8-c5fw/GHSA-h5w7-83f8-c5fw.json index d6d3c4f5c75..a89f83f83fb 100644 --- a/advisories/unreviewed/2022/07/GHSA-h5w7-83f8-c5fw/GHSA-h5w7-83f8-c5fw.json +++ b/advisories/unreviewed/2022/07/GHSA-h5w7-83f8-c5fw/GHSA-h5w7-83f8-c5fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h5w7-83f8-c5fw", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20894" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h6g6-h7qh-75h9/GHSA-h6g6-h7qh-75h9.json b/advisories/unreviewed/2022/07/GHSA-h6g6-h7qh-75h9/GHSA-h6g6-h7qh-75h9.json index 152805ef04c..d187d5e60ef 100644 --- a/advisories/unreviewed/2022/07/GHSA-h6g6-h7qh-75h9/GHSA-h6g6-h7qh-75h9.json +++ b/advisories/unreviewed/2022/07/GHSA-h6g6-h7qh-75h9/GHSA-h6g6-h7qh-75h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h6g6-h7qh-75h9", - "modified": "2022-07-21T00:00:26Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:26Z", "aliases": [ "CVE-2021-36849" ], "details": "Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h6mp-42gx-78qp/GHSA-h6mp-42gx-78qp.json b/advisories/unreviewed/2022/07/GHSA-h6mp-42gx-78qp/GHSA-h6mp-42gx-78qp.json new file mode 100644 index 00000000000..f3f04701c72 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-h6mp-42gx-78qp/GHSA-h6mp-42gx-78qp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-h6mp-42gx-78qp", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33439" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in gc_compact_strings() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33439" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/159" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h72h-3xhv-hjq4/GHSA-h72h-3xhv-hjq4.json b/advisories/unreviewed/2022/07/GHSA-h72h-3xhv-hjq4/GHSA-h72h-3xhv-hjq4.json index 13684f17cb4..5bf044a78b9 100644 --- a/advisories/unreviewed/2022/07/GHSA-h72h-3xhv-hjq4/GHSA-h72h-3xhv-hjq4.json +++ b/advisories/unreviewed/2022/07/GHSA-h72h-3xhv-hjq4/GHSA-h72h-3xhv-hjq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h72h-3xhv-hjq4", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20882" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h7r9-gcj3-gr8x/GHSA-h7r9-gcj3-gr8x.json b/advisories/unreviewed/2022/07/GHSA-h7r9-gcj3-gr8x/GHSA-h7r9-gcj3-gr8x.json index 0ada1443c09..9396fff229a 100644 --- a/advisories/unreviewed/2022/07/GHSA-h7r9-gcj3-gr8x/GHSA-h7r9-gcj3-gr8x.json +++ b/advisories/unreviewed/2022/07/GHSA-h7r9-gcj3-gr8x/GHSA-h7r9-gcj3-gr8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h7r9-gcj3-gr8x", - "modified": "2022-07-23T00:00:19Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:19Z", "aliases": [ "CVE-2022-0978" ], "details": "Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h8hf-xhcx-q243/GHSA-h8hf-xhcx-q243.json b/advisories/unreviewed/2022/07/GHSA-h8hf-xhcx-q243/GHSA-h8hf-xhcx-q243.json new file mode 100644 index 00000000000..e125fa18274 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-h8hf-xhcx-q243/GHSA-h8hf-xhcx-q243.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-h8hf-xhcx-q243", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-36161" + ], + "details": "Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36161" + }, + { + "type": "WEB", + "url": "https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2022/Orange-Station-1.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h8vc-j6q3-h3ww/GHSA-h8vc-j6q3-h3ww.json b/advisories/unreviewed/2022/07/GHSA-h8vc-j6q3-h3ww/GHSA-h8vc-j6q3-h3ww.json index cc36c6722bb..6ed2f5b27fd 100644 --- a/advisories/unreviewed/2022/07/GHSA-h8vc-j6q3-h3ww/GHSA-h8vc-j6q3-h3ww.json +++ b/advisories/unreviewed/2022/07/GHSA-h8vc-j6q3-h3ww/GHSA-h8vc-j6q3-h3ww.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h8vc-j6q3-h3ww", - "modified": "2022-07-23T00:00:19Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:19Z", "aliases": [ "CVE-2022-0979" ], "details": "Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h9fc-rmrr-c2j6/GHSA-h9fc-rmrr-c2j6.json b/advisories/unreviewed/2022/07/GHSA-h9fc-rmrr-c2j6/GHSA-h9fc-rmrr-c2j6.json new file mode 100644 index 00000000000..00be66709c9 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-h9fc-rmrr-c2j6/GHSA-h9fc-rmrr-c2j6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-h9fc-rmrr-c2j6", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1483" + ], + "details": "Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1483" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1314754" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-h9hg-fr26-64m4/GHSA-h9hg-fr26-64m4.json b/advisories/unreviewed/2022/07/GHSA-h9hg-fr26-64m4/GHSA-h9hg-fr26-64m4.json index 487e41a659a..d5cd265a012 100644 --- a/advisories/unreviewed/2022/07/GHSA-h9hg-fr26-64m4/GHSA-h9hg-fr26-64m4.json +++ b/advisories/unreviewed/2022/07/GHSA-h9hg-fr26-64m4/GHSA-h9hg-fr26-64m4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-h9hg-fr26-64m4", - "modified": "2022-07-22T00:00:36Z", + "modified": "2022-07-27T00:00:36Z", "published": "2022-07-22T00:00:36Z", "aliases": [ "CVE-2022-20889" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hg7j-9h3g-36x3/GHSA-hg7j-9h3g-36x3.json b/advisories/unreviewed/2022/07/GHSA-hg7j-9h3g-36x3/GHSA-hg7j-9h3g-36x3.json index 5f2bebe249e..dff29b21200 100644 --- a/advisories/unreviewed/2022/07/GHSA-hg7j-9h3g-36x3/GHSA-hg7j-9h3g-36x3.json +++ b/advisories/unreviewed/2022/07/GHSA-hg7j-9h3g-36x3/GHSA-hg7j-9h3g-36x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hg7j-9h3g-36x3", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34632" ], "details": "Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hgvm-hcc2-jv5c/GHSA-hgvm-hcc2-jv5c.json b/advisories/unreviewed/2022/07/GHSA-hgvm-hcc2-jv5c/GHSA-hgvm-hcc2-jv5c.json new file mode 100644 index 00000000000..ad81dfdccd6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-hgvm-hcc2-jv5c/GHSA-hgvm-hcc2-jv5c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-hgvm-hcc2-jv5c", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1490" + ], + "details": "Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1490" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1301840" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hh6r-56fp-6x7j/GHSA-hh6r-56fp-6x7j.json b/advisories/unreviewed/2022/07/GHSA-hh6r-56fp-6x7j/GHSA-hh6r-56fp-6x7j.json index 0de1948b156..265f858396b 100644 --- a/advisories/unreviewed/2022/07/GHSA-hh6r-56fp-6x7j/GHSA-hh6r-56fp-6x7j.json +++ b/advisories/unreviewed/2022/07/GHSA-hh6r-56fp-6x7j/GHSA-hh6r-56fp-6x7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hh6r-56fp-6x7j", - "modified": "2022-07-23T00:00:19Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:19Z", "aliases": [ "CVE-2022-29495" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hqhq-637w-p2h4/GHSA-hqhq-637w-p2h4.json b/advisories/unreviewed/2022/07/GHSA-hqhq-637w-p2h4/GHSA-hqhq-637w-p2h4.json index 37970a0a19a..781a40a7054 100644 --- a/advisories/unreviewed/2022/07/GHSA-hqhq-637w-p2h4/GHSA-hqhq-637w-p2h4.json +++ b/advisories/unreviewed/2022/07/GHSA-hqhq-637w-p2h4/GHSA-hqhq-637w-p2h4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hqhq-637w-p2h4", - "modified": "2022-07-22T00:00:35Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:35Z", "aliases": [ "CVE-2022-20886" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hvfw-pcx7-j7qm/GHSA-hvfw-pcx7-j7qm.json b/advisories/unreviewed/2022/07/GHSA-hvfw-pcx7-j7qm/GHSA-hvfw-pcx7-j7qm.json index 70cdec2b3f7..246371712e7 100644 --- a/advisories/unreviewed/2022/07/GHSA-hvfw-pcx7-j7qm/GHSA-hvfw-pcx7-j7qm.json +++ b/advisories/unreviewed/2022/07/GHSA-hvfw-pcx7-j7qm/GHSA-hvfw-pcx7-j7qm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hvfw-pcx7-j7qm", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-1920" ], "details": "Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-hwjf-m968-wwpr/GHSA-hwjf-m968-wwpr.json b/advisories/unreviewed/2022/07/GHSA-hwjf-m968-wwpr/GHSA-hwjf-m968-wwpr.json index d43a07df718..9e2a46e1915 100644 --- a/advisories/unreviewed/2022/07/GHSA-hwjf-m968-wwpr/GHSA-hwjf-m968-wwpr.json +++ b/advisories/unreviewed/2022/07/GHSA-hwjf-m968-wwpr/GHSA-hwjf-m968-wwpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-hwjf-m968-wwpr", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20897" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j23w-523j-9593/GHSA-j23w-523j-9593.json b/advisories/unreviewed/2022/07/GHSA-j23w-523j-9593/GHSA-j23w-523j-9593.json index 6f9c6547f73..11829f70f28 100644 --- a/advisories/unreviewed/2022/07/GHSA-j23w-523j-9593/GHSA-j23w-523j-9593.json +++ b/advisories/unreviewed/2022/07/GHSA-j23w-523j-9593/GHSA-j23w-523j-9593.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-j23w-523j-9593", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34639" ], "details": "CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j3f8-fr5h-vwgv/GHSA-j3f8-fr5h-vwgv.json b/advisories/unreviewed/2022/07/GHSA-j3f8-fr5h-vwgv/GHSA-j3f8-fr5h-vwgv.json index ecc224cb370..2b3b356f8cb 100644 --- a/advisories/unreviewed/2022/07/GHSA-j3f8-fr5h-vwgv/GHSA-j3f8-fr5h-vwgv.json +++ b/advisories/unreviewed/2022/07/GHSA-j3f8-fr5h-vwgv/GHSA-j3f8-fr5h-vwgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-j3f8-fr5h-vwgv", - "modified": "2022-07-20T00:00:25Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-20T00:00:25Z", "aliases": [ "CVE-2022-30532" ], "details": "In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j3p7-2565-q697/GHSA-j3p7-2565-q697.json b/advisories/unreviewed/2022/07/GHSA-j3p7-2565-q697/GHSA-j3p7-2565-q697.json index cbdef28e2c0..799840a1f83 100644 --- a/advisories/unreviewed/2022/07/GHSA-j3p7-2565-q697/GHSA-j3p7-2565-q697.json +++ b/advisories/unreviewed/2022/07/GHSA-j3p7-2565-q697/GHSA-j3p7-2565-q697.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-j3p7-2565-q697", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20229" ], "details": "In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224536184", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j4cc-vc2r-c4mh/GHSA-j4cc-vc2r-c4mh.json b/advisories/unreviewed/2022/07/GHSA-j4cc-vc2r-c4mh/GHSA-j4cc-vc2r-c4mh.json new file mode 100644 index 00000000000..e98700e0af2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-j4cc-vc2r-c4mh/GHSA-j4cc-vc2r-c4mh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-j4cc-vc2r-c4mh", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33461" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a use-after-free in yasm_intnum_destroy() in libyasm/intnum.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33461" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/161" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j4jc-fh4v-27gw/GHSA-j4jc-fh4v-27gw.json b/advisories/unreviewed/2022/07/GHSA-j4jc-fh4v-27gw/GHSA-j4jc-fh4v-27gw.json new file mode 100644 index 00000000000..e4578e491ad --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-j4jc-fh4v-27gw/GHSA-j4jc-fh4v-27gw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-j4jc-fh4v-27gw", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33464" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33464" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/164" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j6m5-w993-29q5/GHSA-j6m5-w993-29q5.json b/advisories/unreviewed/2022/07/GHSA-j6m5-w993-29q5/GHSA-j6m5-w993-29q5.json new file mode 100644 index 00000000000..b8bde7e97f4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-j6m5-w993-29q5/GHSA-j6m5-w993-29q5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-j6m5-w993-29q5", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33438" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in json_parse_array() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33438" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/158" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json b/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json index c377be3325b..03f0c7e6dea 100644 --- a/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json +++ b/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-j6v3-2c6w-pwpm", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-1923" ], "details": "DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jc2x-6mpj-q5vm/GHSA-jc2x-6mpj-q5vm.json b/advisories/unreviewed/2022/07/GHSA-jc2x-6mpj-q5vm/GHSA-jc2x-6mpj-q5vm.json index 776f832504f..d56810789b3 100644 --- a/advisories/unreviewed/2022/07/GHSA-jc2x-6mpj-q5vm/GHSA-jc2x-6mpj-q5vm.json +++ b/advisories/unreviewed/2022/07/GHSA-jc2x-6mpj-q5vm/GHSA-jc2x-6mpj-q5vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-jc2x-6mpj-q5vm", - "modified": "2022-07-22T00:00:31Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:31Z", "aliases": [ "CVE-2022-0975" ], "details": "Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jm6f-2xgv-f2ch/GHSA-jm6f-2xgv-f2ch.json b/advisories/unreviewed/2022/07/GHSA-jm6f-2xgv-f2ch/GHSA-jm6f-2xgv-f2ch.json new file mode 100644 index 00000000000..81f0a897365 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jm6f-2xgv-f2ch/GHSA-jm6f-2xgv-f2ch.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jm6f-2xgv-f2ch", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33456" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in hash() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33456" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/175" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jp9m-h4rc-45p2/GHSA-jp9m-h4rc-45p2.json b/advisories/unreviewed/2022/07/GHSA-jp9m-h4rc-45p2/GHSA-jp9m-h4rc-45p2.json new file mode 100644 index 00000000000..cad7f8059ea --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jp9m-h4rc-45p2/GHSA-jp9m-h4rc-45p2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jp9m-h4rc-45p2", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33450" + ], + "details": "An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33450" + }, + { + "type": "WEB", + "url": "https://bugzilla.nasm.us/show_bug.cgi?id=3392758" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jqmm-x5xp-f3pq/GHSA-jqmm-x5xp-f3pq.json b/advisories/unreviewed/2022/07/GHSA-jqmm-x5xp-f3pq/GHSA-jqmm-x5xp-f3pq.json new file mode 100644 index 00000000000..339c32376e1 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jqmm-x5xp-f3pq/GHSA-jqmm-x5xp-f3pq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jqmm-x5xp-f3pq", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29957" + ], + "details": "The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29957" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jqw6-3hr5-834x/GHSA-jqw6-3hr5-834x.json b/advisories/unreviewed/2022/07/GHSA-jqw6-3hr5-834x/GHSA-jqw6-3hr5-834x.json index c1a0a7b0f2b..734ae5bab9a 100644 --- a/advisories/unreviewed/2022/07/GHSA-jqw6-3hr5-834x/GHSA-jqw6-3hr5-834x.json +++ b/advisories/unreviewed/2022/07/GHSA-jqw6-3hr5-834x/GHSA-jqw6-3hr5-834x.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-jqw6-3hr5-834x", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34599" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jr74-qgjg-jjph/GHSA-jr74-qgjg-jjph.json b/advisories/unreviewed/2022/07/GHSA-jr74-qgjg-jjph/GHSA-jr74-qgjg-jjph.json new file mode 100644 index 00000000000..b44dee63d4a --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jr74-qgjg-jjph/GHSA-jr74-qgjg-jjph.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jr74-qgjg-jjph", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1487" + ], + "details": "Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1487" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1304368" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jvm7-g4w5-fq7f/GHSA-jvm7-g4w5-fq7f.json b/advisories/unreviewed/2022/07/GHSA-jvm7-g4w5-fq7f/GHSA-jvm7-g4w5-fq7f.json new file mode 100644 index 00000000000..fa17914b686 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jvm7-g4w5-fq7f/GHSA-jvm7-g4w5-fq7f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jvm7-g4w5-fq7f", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33446" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_next() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33446" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/168" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-jwrh-hfpc-gvqc/GHSA-jwrh-hfpc-gvqc.json b/advisories/unreviewed/2022/07/GHSA-jwrh-hfpc-gvqc/GHSA-jwrh-hfpc-gvqc.json new file mode 100644 index 00000000000..6bd409570ec --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-jwrh-hfpc-gvqc/GHSA-jwrh-hfpc-gvqc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-jwrh-hfpc-gvqc", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1495" + ], + "details": "Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1495" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1301180" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m28r-9pmc-xw7c/GHSA-m28r-9pmc-xw7c.json b/advisories/unreviewed/2022/07/GHSA-m28r-9pmc-xw7c/GHSA-m28r-9pmc-xw7c.json index de7a7b41811..6e08e92ca01 100644 --- a/advisories/unreviewed/2022/07/GHSA-m28r-9pmc-xw7c/GHSA-m28r-9pmc-xw7c.json +++ b/advisories/unreviewed/2022/07/GHSA-m28r-9pmc-xw7c/GHSA-m28r-9pmc-xw7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-m28r-9pmc-xw7c", - "modified": "2022-07-23T00:00:20Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:20Z", "aliases": [ "CVE-2022-30998" ], "details": "Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-m5hw-3f6m-j7mr/GHSA-m5hw-3f6m-j7mr.json b/advisories/unreviewed/2022/07/GHSA-m5hw-3f6m-j7mr/GHSA-m5hw-3f6m-j7mr.json new file mode 100644 index 00000000000..f68c2e21c4d --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-m5hw-3f6m-j7mr/GHSA-m5hw-3f6m-j7mr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-m5hw-3f6m-j7mr", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1488" + ], + "details": "Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1488" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1302959" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mc7p-qhj6-3j59/GHSA-mc7p-qhj6-3j59.json b/advisories/unreviewed/2022/07/GHSA-mc7p-qhj6-3j59/GHSA-mc7p-qhj6-3j59.json new file mode 100644 index 00000000000..d6c1628edd6 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mc7p-qhj6-3j59/GHSA-mc7p-qhj6-3j59.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mc7p-qhj6-3j59", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29963" + ], + "details": "The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29963" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mgmx-3854-pw2c/GHSA-mgmx-3854-pw2c.json b/advisories/unreviewed/2022/07/GHSA-mgmx-3854-pw2c/GHSA-mgmx-3854-pw2c.json index 7effc45b5a4..8b40424e7ba 100644 --- a/advisories/unreviewed/2022/07/GHSA-mgmx-3854-pw2c/GHSA-mgmx-3854-pw2c.json +++ b/advisories/unreviewed/2022/07/GHSA-mgmx-3854-pw2c/GHSA-mgmx-3854-pw2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mgmx-3854-pw2c", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20900" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mhfc-wpjw-4hqq/GHSA-mhfc-wpjw-4hqq.json b/advisories/unreviewed/2022/07/GHSA-mhfc-wpjw-4hqq/GHSA-mhfc-wpjw-4hqq.json index ff3b103eff3..99bbf907c08 100644 --- a/advisories/unreviewed/2022/07/GHSA-mhfc-wpjw-4hqq/GHSA-mhfc-wpjw-4hqq.json +++ b/advisories/unreviewed/2022/07/GHSA-mhfc-wpjw-4hqq/GHSA-mhfc-wpjw-4hqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mhfc-wpjw-4hqq", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:48Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20225" ], "details": "In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213457638", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mm5x-xpmp-2mrh/GHSA-mm5x-xpmp-2mrh.json b/advisories/unreviewed/2022/07/GHSA-mm5x-xpmp-2mrh/GHSA-mm5x-xpmp-2mrh.json new file mode 100644 index 00000000000..d2afbd7e2ee --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-mm5x-xpmp-2mrh/GHSA-mm5x-xpmp-2mrh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-mm5x-xpmp-2mrh", + "modified": "2022-07-27T00:00:31Z", + "published": "2022-07-27T00:00:31Z", + "aliases": [ + "CVE-2022-30270" + ], + "details": "The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts (root, abuilder, acelogin, cappl, ace), all of which come with default credentials. Although the ACE1000 documentation mentions the root, abuilder and acelogin accounts and instructs users to change the default credentials, the cappl and ace accounts remain undocumented and thus are unlikely to have their credentials changed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30270" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-06" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-mv8m-2w22-fqhx/GHSA-mv8m-2w22-fqhx.json b/advisories/unreviewed/2022/07/GHSA-mv8m-2w22-fqhx/GHSA-mv8m-2w22-fqhx.json index 95c801fefe7..b4f81b85a76 100644 --- a/advisories/unreviewed/2022/07/GHSA-mv8m-2w22-fqhx/GHSA-mv8m-2w22-fqhx.json +++ b/advisories/unreviewed/2022/07/GHSA-mv8m-2w22-fqhx/GHSA-mv8m-2w22-fqhx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-mv8m-2w22-fqhx", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-27T00:00:46Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2021-29755" ], "details": "IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p3fq-qpfq-6432/GHSA-p3fq-qpfq-6432.json b/advisories/unreviewed/2022/07/GHSA-p3fq-qpfq-6432/GHSA-p3fq-qpfq-6432.json index 2c64cda9496..c41556b624a 100644 --- a/advisories/unreviewed/2022/07/GHSA-p3fq-qpfq-6432/GHSA-p3fq-qpfq-6432.json +++ b/advisories/unreviewed/2022/07/GHSA-p3fq-qpfq-6432/GHSA-p3fq-qpfq-6432.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p3fq-qpfq-6432", - "modified": "2022-07-23T00:00:25Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:25Z", "aliases": [ "CVE-2022-2494" ], "details": "Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p438-c5rw-cq9h/GHSA-p438-c5rw-cq9h.json b/advisories/unreviewed/2022/07/GHSA-p438-c5rw-cq9h/GHSA-p438-c5rw-cq9h.json index f88928308e2..39cf7ca8e48 100644 --- a/advisories/unreviewed/2022/07/GHSA-p438-c5rw-cq9h/GHSA-p438-c5rw-cq9h.json +++ b/advisories/unreviewed/2022/07/GHSA-p438-c5rw-cq9h/GHSA-p438-c5rw-cq9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p438-c5rw-cq9h", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34641" ], "details": "CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p4gj-rmqv-7h27/GHSA-p4gj-rmqv-7h27.json b/advisories/unreviewed/2022/07/GHSA-p4gj-rmqv-7h27/GHSA-p4gj-rmqv-7h27.json new file mode 100644 index 00000000000..1e5e6023a36 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-p4gj-rmqv-7h27/GHSA-p4gj-rmqv-7h27.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-p4gj-rmqv-7h27", + "modified": "2022-07-27T00:00:31Z", + "published": "2022-07-27T00:00:31Z", + "aliases": [ + "CVE-2022-30269" + ], + "details": "Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30269" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-06" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p8hj-ppgc-2ffw/GHSA-p8hj-ppgc-2ffw.json b/advisories/unreviewed/2022/07/GHSA-p8hj-ppgc-2ffw/GHSA-p8hj-ppgc-2ffw.json index aa65c73efc7..f0dd40a4fb6 100644 --- a/advisories/unreviewed/2022/07/GHSA-p8hj-ppgc-2ffw/GHSA-p8hj-ppgc-2ffw.json +++ b/advisories/unreviewed/2022/07/GHSA-p8hj-ppgc-2ffw/GHSA-p8hj-ppgc-2ffw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p8hj-ppgc-2ffw", - "modified": "2022-07-22T00:00:31Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:31Z", "aliases": [ "CVE-2022-0972" ], "details": "Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-p8ph-2j9w-cw6h/GHSA-p8ph-2j9w-cw6h.json b/advisories/unreviewed/2022/07/GHSA-p8ph-2j9w-cw6h/GHSA-p8ph-2j9w-cw6h.json index ee47b49d479..b681eec72e0 100644 --- a/advisories/unreviewed/2022/07/GHSA-p8ph-2j9w-cw6h/GHSA-p8ph-2j9w-cw6h.json +++ b/advisories/unreviewed/2022/07/GHSA-p8ph-2j9w-cw6h/GHSA-p8ph-2j9w-cw6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-p8ph-2j9w-cw6h", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20904" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-ph48-h9vm-5725/GHSA-ph48-h9vm-5725.json b/advisories/unreviewed/2022/07/GHSA-ph48-h9vm-5725/GHSA-ph48-h9vm-5725.json index ab3e8212a43..2b34beeb343 100644 --- a/advisories/unreviewed/2022/07/GHSA-ph48-h9vm-5725/GHSA-ph48-h9vm-5725.json +++ b/advisories/unreviewed/2022/07/GHSA-ph48-h9vm-5725/GHSA-ph48-h9vm-5725.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-ph48-h9vm-5725", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20879" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-ph6r-j576-8v79/GHSA-ph6r-j576-8v79.json b/advisories/unreviewed/2022/07/GHSA-ph6r-j576-8v79/GHSA-ph6r-j576-8v79.json new file mode 100644 index 00000000000..08f81d77aae --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-ph6r-j576-8v79/GHSA-ph6r-j576-8v79.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-ph6r-j576-8v79", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33437" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33437" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/160" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pj9x-gphc-5865/GHSA-pj9x-gphc-5865.json b/advisories/unreviewed/2022/07/GHSA-pj9x-gphc-5865/GHSA-pj9x-gphc-5865.json index f13ee102f82..5418aa15c8b 100644 --- a/advisories/unreviewed/2022/07/GHSA-pj9x-gphc-5865/GHSA-pj9x-gphc-5865.json +++ b/advisories/unreviewed/2022/07/GHSA-pj9x-gphc-5865/GHSA-pj9x-gphc-5865.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pj9x-gphc-5865", - "modified": "2022-07-22T00:00:35Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:35Z", "aliases": [ "CVE-2022-20887" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pjfq-94vc-mg9w/GHSA-pjfq-94vc-mg9w.json b/advisories/unreviewed/2022/07/GHSA-pjfq-94vc-mg9w/GHSA-pjfq-94vc-mg9w.json new file mode 100644 index 00000000000..f338a625647 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-pjfq-94vc-mg9w/GHSA-pjfq-94vc-mg9w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-pjfq-94vc-mg9w", + "modified": "2022-07-27T00:00:30Z", + "published": "2022-07-27T00:00:30Z", + "aliases": [ + "CVE-2022-30274" + ], + "details": "The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly, the ACE1000 RTU can route MDLC traffic over Extended Command and Management Protocol (XCMP) and Network Layer (XNL) networks via the MDLC driver. Authentication to the XNL port is protected by TEA in ECB mode using a hardcoded key.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30274" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-06" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pp3f-g5wr-f3gv/GHSA-pp3f-g5wr-f3gv.json b/advisories/unreviewed/2022/07/GHSA-pp3f-g5wr-f3gv/GHSA-pp3f-g5wr-f3gv.json new file mode 100644 index 00000000000..d2f969d0d41 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-pp3f-g5wr-f3gv/GHSA-pp3f-g5wr-f3gv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-pp3f-g5wr-f3gv", + "modified": "2022-07-27T00:00:47Z", + "published": "2022-07-27T00:00:47Z", + "aliases": [ + "CVE-2022-22686" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22686" + }, + { + "type": "WEB", + "url": "https://www.synology.com/security/advisory/Synology_SA_20_07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-ppp3-fm6w-x37r/GHSA-ppp3-fm6w-x37r.json b/advisories/unreviewed/2022/07/GHSA-ppp3-fm6w-x37r/GHSA-ppp3-fm6w-x37r.json index 107c2ec8e98..921db8d24cc 100644 --- a/advisories/unreviewed/2022/07/GHSA-ppp3-fm6w-x37r/GHSA-ppp3-fm6w-x37r.json +++ b/advisories/unreviewed/2022/07/GHSA-ppp3-fm6w-x37r/GHSA-ppp3-fm6w-x37r.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-ppp3-fm6w-x37r", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20875" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pwr2-748r-w9w2/GHSA-pwr2-748r-w9w2.json b/advisories/unreviewed/2022/07/GHSA-pwr2-748r-w9w2/GHSA-pwr2-748r-w9w2.json index 8d56c986f7c..6d334335b57 100644 --- a/advisories/unreviewed/2022/07/GHSA-pwr2-748r-w9w2/GHSA-pwr2-748r-w9w2.json +++ b/advisories/unreviewed/2022/07/GHSA-pwr2-748r-w9w2/GHSA-pwr2-748r-w9w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pwr2-748r-w9w2", - "modified": "2022-07-21T00:00:33Z", + "modified": "2022-07-27T00:00:32Z", "published": "2022-07-21T00:00:33Z", "aliases": [ "CVE-2022-2491" ], "details": "A vulnerability has been found in SourceCodester Library Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file lab.php. The manipulation of the argument Section with the input 1' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x71716b7171,0x546e4444736b7743575a666d4873746a6450616261527a67627944426946507245664143694c6a4c,0x7162706b71),NULL,NULL,NULL,NULL# leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-px54-jwh8-83qg/GHSA-px54-jwh8-83qg.json b/advisories/unreviewed/2022/07/GHSA-px54-jwh8-83qg/GHSA-px54-jwh8-83qg.json new file mode 100644 index 00000000000..7bca934b980 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-px54-jwh8-83qg/GHSA-px54-jwh8-83qg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-px54-jwh8-83qg", + "modified": "2022-07-27T00:00:39Z", + "published": "2022-07-27T00:00:39Z", + "aliases": [ + "CVE-2022-22412" + ], + "details": "IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22412" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/223019" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6607045" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-px79-w28w-3h24/GHSA-px79-w28w-3h24.json b/advisories/unreviewed/2022/07/GHSA-px79-w28w-3h24/GHSA-px79-w28w-3h24.json index 5fe63fa89d4..b85b62ca1f8 100644 --- a/advisories/unreviewed/2022/07/GHSA-px79-w28w-3h24/GHSA-px79-w28w-3h24.json +++ b/advisories/unreviewed/2022/07/GHSA-px79-w28w-3h24/GHSA-px79-w28w-3h24.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-px79-w28w-3h24", - "modified": "2022-07-19T00:00:23Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:23Z", "aliases": [ "CVE-2022-34635" ], "details": "The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pxjq-5cp2-gh7h/GHSA-pxjq-5cp2-gh7h.json b/advisories/unreviewed/2022/07/GHSA-pxjq-5cp2-gh7h/GHSA-pxjq-5cp2-gh7h.json index 9b0971abe7e..ec3c1d0cbd4 100644 --- a/advisories/unreviewed/2022/07/GHSA-pxjq-5cp2-gh7h/GHSA-pxjq-5cp2-gh7h.json +++ b/advisories/unreviewed/2022/07/GHSA-pxjq-5cp2-gh7h/GHSA-pxjq-5cp2-gh7h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pxjq-5cp2-gh7h", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:36Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34605" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pxp4-v7r3-2566/GHSA-pxp4-v7r3-2566.json b/advisories/unreviewed/2022/07/GHSA-pxp4-v7r3-2566/GHSA-pxp4-v7r3-2566.json index 42d8f49eff9..a12c43e26cc 100644 --- a/advisories/unreviewed/2022/07/GHSA-pxp4-v7r3-2566/GHSA-pxp4-v7r3-2566.json +++ b/advisories/unreviewed/2022/07/GHSA-pxp4-v7r3-2566/GHSA-pxp4-v7r3-2566.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-pxp4-v7r3-2566", - "modified": "2022-07-21T00:00:27Z", + "modified": "2022-07-27T00:00:46Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2021-38936" ], "details": "IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-pxr7-xpvp-73cx/GHSA-pxr7-xpvp-73cx.json b/advisories/unreviewed/2022/07/GHSA-pxr7-xpvp-73cx/GHSA-pxr7-xpvp-73cx.json new file mode 100644 index 00000000000..00d407c39cf --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-pxr7-xpvp-73cx/GHSA-pxr7-xpvp-73cx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-pxr7-xpvp-73cx", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33448" + ], + "details": "An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at 0x7fffe9049390.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33448" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/170" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json b/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json new file mode 100644 index 00000000000..f750ec9f86e --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-q25f-hc6j-2jpw", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29953" + ], + "details": "The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29953" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-188-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-q2f8-7m8g-86c8/GHSA-q2f8-7m8g-86c8.json b/advisories/unreviewed/2022/07/GHSA-q2f8-7m8g-86c8/GHSA-q2f8-7m8g-86c8.json new file mode 100644 index 00000000000..3ca589cc268 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-q2f8-7m8g-86c8/GHSA-q2f8-7m8g-86c8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-q2f8-7m8g-86c8", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1478" + ], + "details": "Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1478" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1299261" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-q2fw-5hw2-93cw/GHSA-q2fw-5hw2-93cw.json b/advisories/unreviewed/2022/07/GHSA-q2fw-5hw2-93cw/GHSA-q2fw-5hw2-93cw.json index 3e41206884e..da0f5990bc2 100644 --- a/advisories/unreviewed/2022/07/GHSA-q2fw-5hw2-93cw/GHSA-q2fw-5hw2-93cw.json +++ b/advisories/unreviewed/2022/07/GHSA-q2fw-5hw2-93cw/GHSA-q2fw-5hw2-93cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-q2fw-5hw2-93cw", - "modified": "2022-07-22T00:00:35Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:35Z", "aliases": [ "CVE-2022-20888" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-q8gm-6jc5-wp2m/GHSA-q8gm-6jc5-wp2m.json b/advisories/unreviewed/2022/07/GHSA-q8gm-6jc5-wp2m/GHSA-q8gm-6jc5-wp2m.json new file mode 100644 index 00000000000..15c6183c2e5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-q8gm-6jc5-wp2m/GHSA-q8gm-6jc5-wp2m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-q8gm-6jc5-wp2m", + "modified": "2022-07-27T00:00:39Z", + "published": "2022-07-27T00:00:39Z", + "aliases": [ + "CVE-2022-1648" + ], + "details": "Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1648" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/cve-assignment-publication/coordinated-cves" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qc68-fgqr-q53f/GHSA-qc68-fgqr-q53f.json b/advisories/unreviewed/2022/07/GHSA-qc68-fgqr-q53f/GHSA-qc68-fgqr-q53f.json index 270f21e6fa9..7b2795cb1a0 100644 --- a/advisories/unreviewed/2022/07/GHSA-qc68-fgqr-q53f/GHSA-qc68-fgqr-q53f.json +++ b/advisories/unreviewed/2022/07/GHSA-qc68-fgqr-q53f/GHSA-qc68-fgqr-q53f.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-qc68-fgqr-q53f", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-2122" ], "details": "DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json b/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json new file mode 100644 index 00000000000..1ee76ef4081 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-qf39-vcfc-vp3j", + "modified": "2022-07-27T00:00:30Z", + "published": "2022-07-27T00:00:30Z", + "aliases": [ + "CVE-2022-30276" + ], + "details": "The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30276" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-04" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-qgmh-3vp9-q7p2/GHSA-qgmh-3vp9-q7p2.json b/advisories/unreviewed/2022/07/GHSA-qgmh-3vp9-q7p2/GHSA-qgmh-3vp9-q7p2.json index 2506c8ad3a4..87d313972b0 100644 --- a/advisories/unreviewed/2022/07/GHSA-qgmh-3vp9-q7p2/GHSA-qgmh-3vp9-q7p2.json +++ b/advisories/unreviewed/2022/07/GHSA-qgmh-3vp9-q7p2/GHSA-qgmh-3vp9-q7p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-qgmh-3vp9-q7p2", - "modified": "2022-07-23T00:00:20Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-23T00:00:20Z", "aliases": [ "CVE-2022-34839" ], "details": "Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-r6mw-9h6p-mxpf/GHSA-r6mw-9h6p-mxpf.json b/advisories/unreviewed/2022/07/GHSA-r6mw-9h6p-mxpf/GHSA-r6mw-9h6p-mxpf.json new file mode 100644 index 00000000000..02e755b12dd --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-r6mw-9h6p-mxpf/GHSA-r6mw-9h6p-mxpf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-r6mw-9h6p-mxpf", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1364" + ], + "details": "Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1364" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1315901" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-r7cc-f77m-gvjj/GHSA-r7cc-f77m-gvjj.json b/advisories/unreviewed/2022/07/GHSA-r7cc-f77m-gvjj/GHSA-r7cc-f77m-gvjj.json new file mode 100644 index 00000000000..d815b75dc09 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-r7cc-f77m-gvjj/GHSA-r7cc-f77m-gvjj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-r7cc-f77m-gvjj", + "modified": "2022-07-27T00:00:31Z", + "published": "2022-07-27T00:00:31Z", + "aliases": [ + "CVE-2022-31204" + ], + "details": "Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31204" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-r83c-mvm8-r3mx/GHSA-r83c-mvm8-r3mx.json b/advisories/unreviewed/2022/07/GHSA-r83c-mvm8-r3mx/GHSA-r83c-mvm8-r3mx.json index a5cca2ab18a..3113aebb02d 100644 --- a/advisories/unreviewed/2022/07/GHSA-r83c-mvm8-r3mx/GHSA-r83c-mvm8-r3mx.json +++ b/advisories/unreviewed/2022/07/GHSA-r83c-mvm8-r3mx/GHSA-r83c-mvm8-r3mx.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-r83c-mvm8-r3mx", - "modified": "2022-07-23T00:00:19Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:19Z", "aliases": [ "CVE-2022-0980" ], "details": "Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rc4m-xrpj-h9xf/GHSA-rc4m-xrpj-h9xf.json b/advisories/unreviewed/2022/07/GHSA-rc4m-xrpj-h9xf/GHSA-rc4m-xrpj-h9xf.json index 7e0f103e55a..fc3316e2bba 100644 --- a/advisories/unreviewed/2022/07/GHSA-rc4m-xrpj-h9xf/GHSA-rc4m-xrpj-h9xf.json +++ b/advisories/unreviewed/2022/07/GHSA-rc4m-xrpj-h9xf/GHSA-rc4m-xrpj-h9xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rc4m-xrpj-h9xf", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20230" ], "details": "In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221859869", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rf45-cv27-9v2h/GHSA-rf45-cv27-9v2h.json b/advisories/unreviewed/2022/07/GHSA-rf45-cv27-9v2h/GHSA-rf45-cv27-9v2h.json index 74e1f176d7a..faad5b063f5 100644 --- a/advisories/unreviewed/2022/07/GHSA-rf45-cv27-9v2h/GHSA-rf45-cv27-9v2h.json +++ b/advisories/unreviewed/2022/07/GHSA-rf45-cv27-9v2h/GHSA-rf45-cv27-9v2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rf45-cv27-9v2h", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20895" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rhw2-x7mx-cp6j/GHSA-rhw2-x7mx-cp6j.json b/advisories/unreviewed/2022/07/GHSA-rhw2-x7mx-cp6j/GHSA-rhw2-x7mx-cp6j.json new file mode 100644 index 00000000000..428d24a8bde --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-rhw2-x7mx-cp6j/GHSA-rhw2-x7mx-cp6j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-rhw2-x7mx-cp6j", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33445" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_string_char_code_at() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33445" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/169" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rr3h-mf64-3v5w/GHSA-rr3h-mf64-3v5w.json b/advisories/unreviewed/2022/07/GHSA-rr3h-mf64-3v5w/GHSA-rr3h-mf64-3v5w.json index 78b780fa9fa..9725d56dc14 100644 --- a/advisories/unreviewed/2022/07/GHSA-rr3h-mf64-3v5w/GHSA-rr3h-mf64-3v5w.json +++ b/advisories/unreviewed/2022/07/GHSA-rr3h-mf64-3v5w/GHSA-rr3h-mf64-3v5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rr3h-mf64-3v5w", - "modified": "2022-07-19T00:00:22Z", + "modified": "2022-07-27T00:00:34Z", "published": "2022-07-19T00:00:22Z", "aliases": [ "CVE-2022-34642" ], "details": "The component mcontrol.action in RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 contains the incorrect mask which can cause a Denial of Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rv9v-5h43-6cc3/GHSA-rv9v-5h43-6cc3.json b/advisories/unreviewed/2022/07/GHSA-rv9v-5h43-6cc3/GHSA-rv9v-5h43-6cc3.json index f84135c3689..c2dc8d4f510 100644 --- a/advisories/unreviewed/2022/07/GHSA-rv9v-5h43-6cc3/GHSA-rv9v-5h43-6cc3.json +++ b/advisories/unreviewed/2022/07/GHSA-rv9v-5h43-6cc3/GHSA-rv9v-5h43-6cc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rv9v-5h43-6cc3", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20893" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-rwm7-p2mh-3fpc/GHSA-rwm7-p2mh-3fpc.json b/advisories/unreviewed/2022/07/GHSA-rwm7-p2mh-3fpc/GHSA-rwm7-p2mh-3fpc.json index 585f506b4f6..681902c3607 100644 --- a/advisories/unreviewed/2022/07/GHSA-rwm7-p2mh-3fpc/GHSA-rwm7-p2mh-3fpc.json +++ b/advisories/unreviewed/2022/07/GHSA-rwm7-p2mh-3fpc/GHSA-rwm7-p2mh-3fpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-rwm7-p2mh-3fpc", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:35Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-34540" ], "details": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v2x4-9328-wv22/GHSA-v2x4-9328-wv22.json b/advisories/unreviewed/2022/07/GHSA-v2x4-9328-wv22/GHSA-v2x4-9328-wv22.json index 281d00a54d1..3ea6bd8ff1f 100644 --- a/advisories/unreviewed/2022/07/GHSA-v2x4-9328-wv22/GHSA-v2x4-9328-wv22.json +++ b/advisories/unreviewed/2022/07/GHSA-v2x4-9328-wv22/GHSA-v2x4-9328-wv22.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v2x4-9328-wv22", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20234" ], "details": "In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a benign pkgTitle (e.g. Settings app) to make users enable notification access permission for the malicious app. That is, users believe they enable the notification access permission for the Settings app, but actually they enable the notification access permission for the malicious app.Once the malicious app gets the notification access permission, it can read all notifications, including users' personal information.Product: AndroidVersions: Android-12LAndroid ID: A-225189301", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v3p7-5h4w-xrjg/GHSA-v3p7-5h4w-xrjg.json b/advisories/unreviewed/2022/07/GHSA-v3p7-5h4w-xrjg/GHSA-v3p7-5h4w-xrjg.json new file mode 100644 index 00000000000..2b481c39fbb --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v3p7-5h4w-xrjg/GHSA-v3p7-5h4w-xrjg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v3p7-5h4w-xrjg", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33466" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33466" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/172" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v52h-39q4-ccvw/GHSA-v52h-39q4-ccvw.json b/advisories/unreviewed/2022/07/GHSA-v52h-39q4-ccvw/GHSA-v52h-39q4-ccvw.json new file mode 100644 index 00000000000..b467e370d31 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v52h-39q4-ccvw/GHSA-v52h-39q4-ccvw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v52h-39q4-ccvw", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1633" + ], + "details": "Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1633" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1316990" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v5pv-pxh3-g9pr/GHSA-v5pv-pxh3-g9pr.json b/advisories/unreviewed/2022/07/GHSA-v5pv-pxh3-g9pr/GHSA-v5pv-pxh3-g9pr.json new file mode 100644 index 00000000000..ad0ce1925b2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v5pv-pxh3-g9pr/GHSA-v5pv-pxh3-g9pr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v5pv-pxh3-g9pr", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1500" + ], + "details": "Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1500" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1223475" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v63h-gfjw-j838/GHSA-v63h-gfjw-j838.json b/advisories/unreviewed/2022/07/GHSA-v63h-gfjw-j838/GHSA-v63h-gfjw-j838.json index 99afad40597..b60697fd118 100644 --- a/advisories/unreviewed/2022/07/GHSA-v63h-gfjw-j838/GHSA-v63h-gfjw-j838.json +++ b/advisories/unreviewed/2022/07/GHSA-v63h-gfjw-j838/GHSA-v63h-gfjw-j838.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v63h-gfjw-j838", - "modified": "2022-07-21T00:00:25Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:25Z", "aliases": [ "CVE-2022-34590" ], "details": "Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json b/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json index befe1e22fa7..b229d3f1ede 100644 --- a/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json +++ b/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v6c6-gcwr-p5pm", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-1925" ], "details": "DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v898-xxg8-qvgf/GHSA-v898-xxg8-qvgf.json b/advisories/unreviewed/2022/07/GHSA-v898-xxg8-qvgf/GHSA-v898-xxg8-qvgf.json new file mode 100644 index 00000000000..fef6e5f2d75 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v898-xxg8-qvgf/GHSA-v898-xxg8-qvgf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v898-xxg8-qvgf", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1638" + ], + "details": "Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1638" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1316946" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v9jr-g692-6qhv/GHSA-v9jr-g692-6qhv.json b/advisories/unreviewed/2022/07/GHSA-v9jr-g692-6qhv/GHSA-v9jr-g692-6qhv.json new file mode 100644 index 00000000000..c8ec7143b23 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-v9jr-g692-6qhv/GHSA-v9jr-g692-6qhv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-v9jr-g692-6qhv", + "modified": "2022-07-27T00:00:33Z", + "published": "2022-07-27T00:00:33Z", + "aliases": [ + "CVE-2022-1482" + ], + "details": "Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1482" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1304987" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-v9qw-g4pq-87mj/GHSA-v9qw-g4pq-87mj.json b/advisories/unreviewed/2022/07/GHSA-v9qw-g4pq-87mj/GHSA-v9qw-g4pq-87mj.json index 95971bb8dac..072482cd449 100644 --- a/advisories/unreviewed/2022/07/GHSA-v9qw-g4pq-87mj/GHSA-v9qw-g4pq-87mj.json +++ b/advisories/unreviewed/2022/07/GHSA-v9qw-g4pq-87mj/GHSA-v9qw-g4pq-87mj.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-v9qw-g4pq-87mj", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:37Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20881" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vcxg-6fqh-c65h/GHSA-vcxg-6fqh-c65h.json b/advisories/unreviewed/2022/07/GHSA-vcxg-6fqh-c65h/GHSA-vcxg-6fqh-c65h.json index c93022f24fd..9fa5596fb37 100644 --- a/advisories/unreviewed/2022/07/GHSA-vcxg-6fqh-c65h/GHSA-vcxg-6fqh-c65h.json +++ b/advisories/unreviewed/2022/07/GHSA-vcxg-6fqh-c65h/GHSA-vcxg-6fqh-c65h.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vcxg-6fqh-c65h", - "modified": "2022-07-23T00:00:23Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-23T00:00:23Z", "aliases": [ "CVE-2022-20892" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vmq3-255x-fhx5/GHSA-vmq3-255x-fhx5.json b/advisories/unreviewed/2022/07/GHSA-vmq3-255x-fhx5/GHSA-vmq3-255x-fhx5.json index 4d20aa56157..044f3ca97ff 100644 --- a/advisories/unreviewed/2022/07/GHSA-vmq3-255x-fhx5/GHSA-vmq3-255x-fhx5.json +++ b/advisories/unreviewed/2022/07/GHSA-vmq3-255x-fhx5/GHSA-vmq3-255x-fhx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vmq3-255x-fhx5", - "modified": "2022-07-22T00:00:40Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-22T00:00:40Z", "aliases": [ "CVE-2022-20878" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vmwq-gw9g-wqfq/GHSA-vmwq-gw9g-wqfq.json b/advisories/unreviewed/2022/07/GHSA-vmwq-gw9g-wqfq/GHSA-vmwq-gw9g-wqfq.json index c2578fb4da4..7f1b56d2a35 100644 --- a/advisories/unreviewed/2022/07/GHSA-vmwq-gw9g-wqfq/GHSA-vmwq-gw9g-wqfq.json +++ b/advisories/unreviewed/2022/07/GHSA-vmwq-gw9g-wqfq/GHSA-vmwq-gw9g-wqfq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vmwq-gw9g-wqfq", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:48Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20224" ], "details": "In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220732646", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json b/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json index edcda0a1cf1..dd5b603b47a 100644 --- a/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json +++ b/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vp6v-57g2-v7vw", - "modified": "2022-07-20T00:00:18Z", + "modified": "2022-07-27T00:00:31Z", "published": "2022-07-20T00:00:18Z", "aliases": [ "CVE-2022-1924" ], "details": "DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vq3c-fhqv-p29r/GHSA-vq3c-fhqv-p29r.json b/advisories/unreviewed/2022/07/GHSA-vq3c-fhqv-p29r/GHSA-vq3c-fhqv-p29r.json new file mode 100644 index 00000000000..e1f30edcf55 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-vq3c-fhqv-p29r/GHSA-vq3c-fhqv-p29r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-vq3c-fhqv-p29r", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29958" + ], + "details": "JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of machine code. The logic that is downloaded to the PLC is not cryptographically authenticated, allowing an attacker to execute arbitrary machine code on the PLC's CPU module in the context of the runtime. In the case of the PC10G-CPU, and likely for other CPU modules of the TOYOPUC family, a processor without MPU or MMU is used and this no memory protection or privilege-separation capabilities are available, giving an attacker full control over the CPU.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29958" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-172-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vr6j-cw8v-2q76/GHSA-vr6j-cw8v-2q76.json b/advisories/unreviewed/2022/07/GHSA-vr6j-cw8v-2q76/GHSA-vr6j-cw8v-2q76.json index c91c2ab62cd..7edf939000e 100644 --- a/advisories/unreviewed/2022/07/GHSA-vr6j-cw8v-2q76/GHSA-vr6j-cw8v-2q76.json +++ b/advisories/unreviewed/2022/07/GHSA-vr6j-cw8v-2q76/GHSA-vr6j-cw8v-2q76.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-vr6j-cw8v-2q76", - "modified": "2022-07-22T00:00:39Z", + "modified": "2022-07-27T00:00:44Z", "published": "2022-07-22T00:00:39Z", "aliases": [ "CVE-2022-20874" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vr8p-pf4j-6wrh/GHSA-vr8p-pf4j-6wrh.json b/advisories/unreviewed/2022/07/GHSA-vr8p-pf4j-6wrh/GHSA-vr8p-pf4j-6wrh.json new file mode 100644 index 00000000000..61fc7c2fa5b --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-vr8p-pf4j-6wrh/GHSA-vr8p-pf4j-6wrh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-vr8p-pf4j-6wrh", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2022-34991" + ], + "details": "Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name and last_name parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34991" + }, + { + "type": "WEB", + "url": "https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/paymoney/2022/paymoney-3.3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-vv47-5mh5-w3hq/GHSA-vv47-5mh5-w3hq.json b/advisories/unreviewed/2022/07/GHSA-vv47-5mh5-w3hq/GHSA-vv47-5mh5-w3hq.json new file mode 100644 index 00000000000..d538a5e5b32 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-vv47-5mh5-w3hq/GHSA-vv47-5mh5-w3hq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-vv47-5mh5-w3hq", + "modified": "2022-07-27T00:00:36Z", + "published": "2022-07-27T00:00:36Z", + "aliases": [ + "CVE-2022-1671" + ], + "details": "A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1671" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ff8376ade4f668130385839cef586a0990f8ef87" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w2fx-43f2-2mgq/GHSA-w2fx-43f2-2mgq.json b/advisories/unreviewed/2022/07/GHSA-w2fx-43f2-2mgq/GHSA-w2fx-43f2-2mgq.json index 05613dd29d9..49b60efa78a 100644 --- a/advisories/unreviewed/2022/07/GHSA-w2fx-43f2-2mgq/GHSA-w2fx-43f2-2mgq.json +++ b/advisories/unreviewed/2022/07/GHSA-w2fx-43f2-2mgq/GHSA-w2fx-43f2-2mgq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w2fx-43f2-2mgq", - "modified": "2022-07-21T00:00:25Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-21T00:00:25Z", "aliases": [ "CVE-2022-29923" ], "details": "Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.4.1 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w2x5-64hf-jr76/GHSA-w2x5-64hf-jr76.json b/advisories/unreviewed/2022/07/GHSA-w2x5-64hf-jr76/GHSA-w2x5-64hf-jr76.json new file mode 100644 index 00000000000..477697611f5 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-w2x5-64hf-jr76/GHSA-w2x5-64hf-jr76.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-w2x5-64hf-jr76", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33444" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in getprop_builtin_foreign() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33444" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/166" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w497-f23v-cv57/GHSA-w497-f23v-cv57.json b/advisories/unreviewed/2022/07/GHSA-w497-f23v-cv57/GHSA-w497-f23v-cv57.json index 37f54d9c0c0..e7bff374034 100644 --- a/advisories/unreviewed/2022/07/GHSA-w497-f23v-cv57/GHSA-w497-f23v-cv57.json +++ b/advisories/unreviewed/2022/07/GHSA-w497-f23v-cv57/GHSA-w497-f23v-cv57.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w497-f23v-cv57", - "modified": "2022-07-23T00:00:20Z", + "modified": "2022-07-27T00:00:38Z", "published": "2022-07-23T00:00:20Z", "aliases": [ "CVE-2022-34650" ], "details": "Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w6jm-vwx5-6mm4/GHSA-w6jm-vwx5-6mm4.json b/advisories/unreviewed/2022/07/GHSA-w6jm-vwx5-6mm4/GHSA-w6jm-vwx5-6mm4.json index e4595425f4e..3b09f6b92a3 100644 --- a/advisories/unreviewed/2022/07/GHSA-w6jm-vwx5-6mm4/GHSA-w6jm-vwx5-6mm4.json +++ b/advisories/unreviewed/2022/07/GHSA-w6jm-vwx5-6mm4/GHSA-w6jm-vwx5-6mm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-w6jm-vwx5-6mm4", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:36Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34604" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /dotrace.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json b/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json new file mode 100644 index 00000000000..6ac941929db --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-w6v8-54jm-g2j3", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29960" + ], + "details": "Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29960" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wc6r-37r6-6c7q/GHSA-wc6r-37r6-6c7q.json b/advisories/unreviewed/2022/07/GHSA-wc6r-37r6-6c7q/GHSA-wc6r-37r6-6c7q.json new file mode 100644 index 00000000000..c0bdead9fad --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wc6r-37r6-6c7q/GHSA-wc6r-37r6-6c7q.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wc6r-37r6-6c7q", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33442" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in json_printf() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33442" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/161" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wm34-q93c-vxx8/GHSA-wm34-q93c-vxx8.json b/advisories/unreviewed/2022/07/GHSA-wm34-q93c-vxx8/GHSA-wm34-q93c-vxx8.json new file mode 100644 index 00000000000..86d11e6c6f3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wm34-q93c-vxx8/GHSA-wm34-q93c-vxx8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wm34-q93c-vxx8", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-30275" + ], + "details": "The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the Legacy Password feature. In this case, an insecure CRC of the password is present in the project file: this CRC is validated against the password in the driver configuration file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30275" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-05" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wmpw-gfmr-gv4v/GHSA-wmpw-gfmr-gv4v.json b/advisories/unreviewed/2022/07/GHSA-wmpw-gfmr-gv4v/GHSA-wmpw-gfmr-gv4v.json new file mode 100644 index 00000000000..4bd7421ffd2 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wmpw-gfmr-gv4v/GHSA-wmpw-gfmr-gv4v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wmpw-gfmr-gv4v", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33463" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr__copy_except() in libyasm/expr.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33463" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/174" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wmrr-g68f-2fhj/GHSA-wmrr-g68f-2fhj.json b/advisories/unreviewed/2022/07/GHSA-wmrr-g68f-2fhj/GHSA-wmrr-g68f-2fhj.json index 8c9502471e6..373224e2395 100644 --- a/advisories/unreviewed/2022/07/GHSA-wmrr-g68f-2fhj/GHSA-wmrr-g68f-2fhj.json +++ b/advisories/unreviewed/2022/07/GHSA-wmrr-g68f-2fhj/GHSA-wmrr-g68f-2fhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wmrr-g68f-2fhj", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:48Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20223" ], "details": "In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-223578534", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-610" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wpcm-pg4g-v7c4/GHSA-wpcm-pg4g-v7c4.json b/advisories/unreviewed/2022/07/GHSA-wpcm-pg4g-v7c4/GHSA-wpcm-pg4g-v7c4.json new file mode 100644 index 00000000000..a9384f13fac --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wpcm-pg4g-v7c4/GHSA-wpcm-pg4g-v7c4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wpcm-pg4g-v7c4", + "modified": "2022-07-27T00:00:39Z", + "published": "2022-07-27T00:00:39Z", + "aliases": [ + "CVE-2022-36412" + ], + "details": "In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36412" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/support-center/cve-2022-36412.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wpw2-w3qc-gx5g/GHSA-wpw2-w3qc-gx5g.json b/advisories/unreviewed/2022/07/GHSA-wpw2-w3qc-gx5g/GHSA-wpw2-w3qc-gx5g.json index 4e6432e05ad..7d2b986a1b6 100644 --- a/advisories/unreviewed/2022/07/GHSA-wpw2-w3qc-gx5g/GHSA-wpw2-w3qc-gx5g.json +++ b/advisories/unreviewed/2022/07/GHSA-wpw2-w3qc-gx5g/GHSA-wpw2-w3qc-gx5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-wpw2-w3qc-gx5g", - "modified": "2022-07-22T00:00:30Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:30Z", "aliases": [ "CVE-2022-0976" ], "details": "Heap buffer overflow in GPU in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-wr45-8cqr-j247/GHSA-wr45-8cqr-j247.json b/advisories/unreviewed/2022/07/GHSA-wr45-8cqr-j247/GHSA-wr45-8cqr-j247.json new file mode 100644 index 00000000000..4a47fd10af3 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-wr45-8cqr-j247/GHSA-wr45-8cqr-j247.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-wr45-8cqr-j247", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1499" + ], + "details": "Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1499" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_26.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1000408" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-ww23-76gw-72m2/GHSA-ww23-76gw-72m2.json b/advisories/unreviewed/2022/07/GHSA-ww23-76gw-72m2/GHSA-ww23-76gw-72m2.json index 8801cef7ed7..fc5406b7d4b 100644 --- a/advisories/unreviewed/2022/07/GHSA-ww23-76gw-72m2/GHSA-ww23-76gw-72m2.json +++ b/advisories/unreviewed/2022/07/GHSA-ww23-76gw-72m2/GHSA-ww23-76gw-72m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-ww23-76gw-72m2", - "modified": "2022-07-23T00:00:24Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-23T00:00:24Z", "aliases": [ "CVE-2022-20898" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x59p-874g-35pw/GHSA-x59p-874g-35pw.json b/advisories/unreviewed/2022/07/GHSA-x59p-874g-35pw/GHSA-x59p-874g-35pw.json index 0a68eeb2a70..713b093205f 100644 --- a/advisories/unreviewed/2022/07/GHSA-x59p-874g-35pw/GHSA-x59p-874g-35pw.json +++ b/advisories/unreviewed/2022/07/GHSA-x59p-874g-35pw/GHSA-x59p-874g-35pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-x59p-874g-35pw", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34606" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditvsList parameter at /dotrace.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-x6hw-42rg-xj9m/GHSA-x6hw-42rg-xj9m.json b/advisories/unreviewed/2022/07/GHSA-x6hw-42rg-xj9m/GHSA-x6hw-42rg-xj9m.json new file mode 100644 index 00000000000..d35aa7ec33e --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-x6hw-42rg-xj9m/GHSA-x6hw-42rg-xj9m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-x6hw-42rg-xj9m", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33460" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in if_condition() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33460" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/168" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xc6r-vpp5-48cq/GHSA-xc6r-vpp5-48cq.json b/advisories/unreviewed/2022/07/GHSA-xc6r-vpp5-48cq/GHSA-xc6r-vpp5-48cq.json new file mode 100644 index 00000000000..3fa7f8aa1fc --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xc6r-vpp5-48cq/GHSA-xc6r-vpp5-48cq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xc6r-vpp5-48cq", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33454" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33454" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/166" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xgjg-q85m-vvmx/GHSA-xgjg-q85m-vvmx.json b/advisories/unreviewed/2022/07/GHSA-xgjg-q85m-vvmx/GHSA-xgjg-q85m-vvmx.json new file mode 100644 index 00000000000..3917ddb53ca --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xgjg-q85m-vvmx/GHSA-xgjg-q85m-vvmx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xgjg-q85m-vvmx", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-29952" + ], + "details": "Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29952" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-188-02" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/blog/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xhmx-2vhp-f3pq/GHSA-xhmx-2vhp-f3pq.json b/advisories/unreviewed/2022/07/GHSA-xhmx-2vhp-f3pq/GHSA-xhmx-2vhp-f3pq.json index a4df429aef7..6d7d60e688a 100644 --- a/advisories/unreviewed/2022/07/GHSA-xhmx-2vhp-f3pq/GHSA-xhmx-2vhp-f3pq.json +++ b/advisories/unreviewed/2022/07/GHSA-xhmx-2vhp-f3pq/GHSA-xhmx-2vhp-f3pq.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xhmx-2vhp-f3pq", - "modified": "2022-07-14T00:00:16Z", + "modified": "2022-07-27T00:00:47Z", "published": "2022-07-14T00:00:16Z", "aliases": [ "CVE-2022-20227" ], "details": "In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216825460References: Upstream kernel", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xjhj-9v89-v9m8/GHSA-xjhj-9v89-v9m8.json b/advisories/unreviewed/2022/07/GHSA-xjhj-9v89-v9m8/GHSA-xjhj-9v89-v9m8.json index 9570f7a38d6..20178593a53 100644 --- a/advisories/unreviewed/2022/07/GHSA-xjhj-9v89-v9m8/GHSA-xjhj-9v89-v9m8.json +++ b/advisories/unreviewed/2022/07/GHSA-xjhj-9v89-v9m8/GHSA-xjhj-9v89-v9m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xjhj-9v89-v9m8", - "modified": "2022-07-22T00:00:32Z", + "modified": "2022-07-27T00:00:45Z", "published": "2022-07-22T00:00:32Z", "aliases": [ "CVE-2022-20891" ], "details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xm6p-r726-3x76/GHSA-xm6p-r726-3x76.json b/advisories/unreviewed/2022/07/GHSA-xm6p-r726-3x76/GHSA-xm6p-r726-3x76.json index 7502ca1ea84..4ad52de8fd4 100644 --- a/advisories/unreviewed/2022/07/GHSA-xm6p-r726-3x76/GHSA-xm6p-r726-3x76.json +++ b/advisories/unreviewed/2022/07/GHSA-xm6p-r726-3x76/GHSA-xm6p-r726-3x76.json @@ -1,14 +1,17 @@ { "schema_version": "1.2.0", "id": "GHSA-xm6p-r726-3x76", - "modified": "2022-07-21T00:00:32Z", + "modified": "2022-07-27T00:00:36Z", "published": "2022-07-21T00:00:32Z", "aliases": [ "CVE-2022-34602" ], "details": "H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xq3g-5rhc-pxgj/GHSA-xq3g-5rhc-pxgj.json b/advisories/unreviewed/2022/07/GHSA-xq3g-5rhc-pxgj/GHSA-xq3g-5rhc-pxgj.json index e67c2650ac5..4b7b2d53d07 100644 --- a/advisories/unreviewed/2022/07/GHSA-xq3g-5rhc-pxgj/GHSA-xq3g-5rhc-pxgj.json +++ b/advisories/unreviewed/2022/07/GHSA-xq3g-5rhc-pxgj/GHSA-xq3g-5rhc-pxgj.json @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46829" }, + { + "type": "WEB", + "url": "https://github.com/pedrib/PoC/blob/master/fuzzing/CVE-2021-46829/CVE-2021-46829.md" + }, { "type": "WEB", "url": "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/5398f04d772f7f8baf5265715696ed88db0f0512" diff --git a/advisories/unreviewed/2022/07/GHSA-xq4f-j8wj-pf7x/GHSA-xq4f-j8wj-pf7x.json b/advisories/unreviewed/2022/07/GHSA-xq4f-j8wj-pf7x/GHSA-xq4f-j8wj-pf7x.json new file mode 100644 index 00000000000..66ceab203c0 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xq4f-j8wj-pf7x/GHSA-xq4f-j8wj-pf7x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xq4f-j8wj-pf7x", + "modified": "2022-07-27T00:00:46Z", + "published": "2022-07-27T00:00:46Z", + "aliases": [ + "CVE-2021-33465" + ], + "details": "An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33465" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/173" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xv5j-xw3x-cwr6/GHSA-xv5j-xw3x-cwr6.json b/advisories/unreviewed/2022/07/GHSA-xv5j-xw3x-cwr6/GHSA-xv5j-xw3x-cwr6.json new file mode 100644 index 00000000000..c3ae14966b4 --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xv5j-xw3x-cwr6/GHSA-xv5j-xw3x-cwr6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xv5j-xw3x-cwr6", + "modified": "2022-07-27T00:00:32Z", + "published": "2022-07-27T00:00:32Z", + "aliases": [ + "CVE-2022-1639" + ], + "details": "Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1639" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1317650" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/07/GHSA-xvx2-mpv8-r9xf/GHSA-xvx2-mpv8-r9xf.json b/advisories/unreviewed/2022/07/GHSA-xvx2-mpv8-r9xf/GHSA-xvx2-mpv8-r9xf.json new file mode 100644 index 00000000000..1cfcbf2501c --- /dev/null +++ b/advisories/unreviewed/2022/07/GHSA-xvx2-mpv8-r9xf/GHSA-xvx2-mpv8-r9xf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-xvx2-mpv8-r9xf", + "modified": "2022-07-27T00:00:45Z", + "published": "2022-07-27T00:00:45Z", + "aliases": [ + "CVE-2021-33443" + ], + "details": "An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33443" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/167" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file