diff --git a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json index 403daafbc14..65551f34ee2 100644 --- a/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json +++ b/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78hx-gp6g-7mj6", - "modified": "2024-08-07T18:30:39Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-03-20T18:10:36Z", "aliases": [ "CVE-2024-1394" @@ -136,7 +136,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:4146" + "url": "https://access.redhat.com/errata/RHSA-2024:1462" }, { "type": "WEB", @@ -182,6 +182,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4960" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5258" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1394" @@ -210,10 +214,6 @@ "type": "WEB", "url": "https://vuln.go.dev/ID/GO-2024-2660.json" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:1462" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1468" @@ -301,6 +301,10 @@ { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:3352" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4146" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json index c412fb1ea41..5a5926bba4d 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json +++ b/advisories/github-reviewed/2024/05/GHSA-6wvf-f2vw-3425/GHSA-6wvf-f2vw-3425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6wvf-f2vw-3425", - "modified": "2024-08-07T18:30:38Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3727" @@ -142,6 +142,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-3727" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5258" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4960" diff --git a/advisories/unreviewed/2024/03/GHSA-cg45-vc5v-xqq7/GHSA-cg45-vc5v-xqq7.json b/advisories/unreviewed/2024/03/GHSA-cg45-vc5v-xqq7/GHSA-cg45-vc5v-xqq7.json index 87d04454dfd..20327985130 100644 --- a/advisories/unreviewed/2024/03/GHSA-cg45-vc5v-xqq7/GHSA-cg45-vc5v-xqq7.json +++ b/advisories/unreviewed/2024/03/GHSA-cg45-vc5v-xqq7/GHSA-cg45-vc5v-xqq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cg45-vc5v-xqq7", - "modified": "2024-03-18T06:30:51Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-03-18T06:30:51Z", "aliases": [ "CVE-2024-29151" ], "details": "Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-311" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T06:15:05Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json b/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json index c1a6e54b9b3..c37d06adb1d 100644 --- a/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json +++ b/advisories/unreviewed/2024/03/GHSA-g692-j8f5-g9xf/GHSA-g692-j8f5-g9xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g692-j8f5-g9xf", - "modified": "2024-03-29T15:30:29Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-03-29T15:30:29Z", "aliases": [ "CVE-2024-30622" ], "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json b/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json index 42d17845ce8..2fe679b754e 100644 --- a/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json +++ b/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8xv-jmgw-wfcj", - "modified": "2024-03-28T15:30:33Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-30589" ], "details": "Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T14:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json b/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json index 7be6cd32a72..ce9121505fb 100644 --- a/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json +++ b/advisories/unreviewed/2024/04/GHSA-cpff-vh9v-hmch/GHSA-cpff-vh9v-hmch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpff-vh9v-hmch", - "modified": "2024-04-08T15:30:32Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-04-08T15:30:32Z", "aliases": [ "CVE-2024-31807" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json b/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json index 2bdc8070aa7..30a4ad38b01 100644 --- a/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json +++ b/advisories/unreviewed/2024/05/GHSA-85xr-ghj6-6m46/GHSA-85xr-ghj6-6m46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-85xr-ghj6-6m46", - "modified": "2024-06-21T21:33:58Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-05-16T18:30:32Z", "aliases": [ "CVE-2024-4603" ], "details": "Issue summary: Checking excessively long DSA keys or parameters may be very\nslow.\n\nImpact summary: Applications that use the functions EVP_PKEY_param_check()\nor EVP_PKEY_public_check() to check a DSA public key or DSA parameters may\nexperience long delays. Where the key or parameters that are being checked\nhave been obtained from an untrusted source this may lead to a Denial of\nService.\n\nThe functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform\nvarious checks on DSA parameters. Some of those computations take a long time\nif the modulus (`p` parameter) is too large.\n\nTrying to use a very large modulus is slow and OpenSSL will not allow using\npublic keys with a modulus which is over 10,000 bits in length for signature\nverification. However the key and parameter check functions do not limit\nthe modulus size when performing the checks.\n\nAn application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check()\nand supplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nThese functions are not called by OpenSSL itself on untrusted DSA keys so\nonly applications that directly call these functions may be vulnerable.\n\nAlso vulnerable are the OpenSSL pkey and pkeyparam command line applications\nwhen using the `-check` option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-834" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T16:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json b/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json index 67f4c17209c..21c9e15dfae 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json +++ b/advisories/unreviewed/2024/06/GHSA-c8xv-94wg-v5h7/GHSA-c8xv-94wg-v5h7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-121" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json b/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json index 19ec60ffdc3..075d659bc2d 100644 --- a/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json +++ b/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4645-h4xp-pj82", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40776" @@ -46,6 +46,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214124" }, + { + "type": "WEB", + "url": "https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jul/15" diff --git a/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json b/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json index 6f2607db361..cdaf3ae46a9 100644 --- a/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json +++ b/advisories/unreviewed/2024/07/GHSA-5697-p67m-73p6/GHSA-5697-p67m-73p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5697-p67m-73p6", - "modified": "2024-07-17T18:31:00Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-07-17T18:31:00Z", "aliases": [ "CVE-2024-20419" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy" + }, + { + "type": "WEB", + "url": "https://www.secpod.com/blog/critical-flaw-in-ciscos-secure-email-gateways-allows-attackers-to-control-the-device-completely" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json b/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json index 0fb9263d9ef..6b45ded606b 100644 --- a/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json +++ b/advisories/unreviewed/2024/07/GHSA-7j6x-9hgr-mv7c/GHSA-7j6x-9hgr-mv7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7j6x-9hgr-mv7c", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40779" @@ -46,6 +46,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214124" }, + { + "type": "WEB", + "url": "https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jul/15" diff --git a/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json b/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json index a20eb857d2a..c88fa232407 100644 --- a/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json +++ b/advisories/unreviewed/2024/07/GHSA-j573-cwg3-wh35/GHSA-j573-cwg3-wh35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j573-cwg3-wh35", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40780" @@ -46,6 +46,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/HT214124" }, + { + "type": "WEB", + "url": "https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jul/15" diff --git a/advisories/unreviewed/2024/08/GHSA-2crp-qj3p-4444/GHSA-2crp-qj3p-4444.json b/advisories/unreviewed/2024/08/GHSA-2crp-qj3p-4444/GHSA-2crp-qj3p-4444.json new file mode 100644 index 00000000000..ab4d7dc364d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2crp-qj3p-4444/GHSA-2crp-qj3p-4444.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2crp-qj3p-4444", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-37968" + ], + "details": "Windows DNS Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37968" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37968" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json b/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json new file mode 100644 index 00000000000..8545f26d6c3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rhx-838f-x5jw", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31310" + ], + "details": "Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the \"set temperature input selection\" command, potentially resulting in a loss of integrity and/or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31310" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2rmf-3rpp-rfgh/GHSA-2rmf-3rpp-rfgh.json b/advisories/unreviewed/2024/08/GHSA-2rmf-3rpp-rfgh/GHSA-2rmf-3rpp-rfgh.json new file mode 100644 index 00000000000..6590008d9ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2rmf-3rpp-rfgh/GHSA-2rmf-3rpp-rfgh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rmf-3rpp-rfgh", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38121" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38121" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2rw9-g27f-ppp3/GHSA-2rw9-g27f-ppp3.json b/advisories/unreviewed/2024/08/GHSA-2rw9-g27f-ppp3/GHSA-2rw9-g27f-ppp3.json new file mode 100644 index 00000000000..2c14b4c3757 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2rw9-g27f-ppp3/GHSA-2rw9-g27f-ppp3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rw9-g27f-ppp3", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38127" + ], + "details": "Windows Hyper-V Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38127" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json b/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json new file mode 100644 index 00000000000..57fced183e5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xmp-f94r-wqm9", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2022-27486" + ], + "details": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 through 6.3.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 allows an authenticated attacker to execute shell code as `root` via `execute` CLI commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27486" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2xq4-823c-q5v9/GHSA-2xq4-823c-q5v9.json b/advisories/unreviewed/2024/08/GHSA-2xq4-823c-q5v9/GHSA-2xq4-823c-q5v9.json new file mode 100644 index 00000000000..ec6182c8e16 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2xq4-823c-q5v9/GHSA-2xq4-823c-q5v9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xq4-823c-q5v9", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2021-26367" + ], + "details": "A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26367" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4004.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-356h-6p87-pgw2/GHSA-356h-6p87-pgw2.json b/advisories/unreviewed/2024/08/GHSA-356h-6p87-pgw2/GHSA-356h-6p87-pgw2.json new file mode 100644 index 00000000000..f143ddb1aae --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-356h-6p87-pgw2/GHSA-356h-6p87-pgw2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-356h-6p87-pgw2", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38160" + ], + "details": "Windows Network Virtualization Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38160" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38160" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3763-pmwr-w4qp/GHSA-3763-pmwr-w4qp.json b/advisories/unreviewed/2024/08/GHSA-3763-pmwr-w4qp/GHSA-3763-pmwr-w4qp.json new file mode 100644 index 00000000000..7f31dde2f70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3763-pmwr-w4qp/GHSA-3763-pmwr-w4qp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3763-pmwr-w4qp", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20509" + ], + "details": "An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20509" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-39fv-qp4h-m8jw/GHSA-39fv-qp4h-m8jw.json b/advisories/unreviewed/2024/08/GHSA-39fv-qp4h-m8jw/GHSA-39fv-qp4h-m8jw.json index 1f934b0ba51..ef0186a4101 100644 --- a/advisories/unreviewed/2024/08/GHSA-39fv-qp4h-m8jw/GHSA-39fv-qp4h-m8jw.json +++ b/advisories/unreviewed/2024/08/GHSA-39fv-qp4h-m8jw/GHSA-39fv-qp4h-m8jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39fv-qp4h-m8jw", - "modified": "2024-08-12T15:30:53Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:53Z", "aliases": [ "CVE-2024-27442" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privileges from the zimbra user to root, because of improper handling of input arguments. An attacker can execute arbitrary commands with elevated privileges, leading to local privilege escalation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269", + "CWE-755" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3p5j-pp53-5ghm/GHSA-3p5j-pp53-5ghm.json b/advisories/unreviewed/2024/08/GHSA-3p5j-pp53-5ghm/GHSA-3p5j-pp53-5ghm.json new file mode 100644 index 00000000000..8b30f5db151 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3p5j-pp53-5ghm/GHSA-3p5j-pp53-5ghm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p5j-pp53-5ghm", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20513" + ], + "details": "An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20513" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3phx-v48r-rmwc/GHSA-3phx-v48r-rmwc.json b/advisories/unreviewed/2024/08/GHSA-3phx-v48r-rmwc/GHSA-3phx-v48r-rmwc.json new file mode 100644 index 00000000000..db7a3b880a1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3phx-v48r-rmwc/GHSA-3phx-v48r-rmwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3phx-v48r-rmwc", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20578" + ], + "details": "A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow\nan attacker with ring0 privileges and access to the\nBIOS menu or UEFI shell to modify the communications buffer potentially\nresulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20578" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3q84-pcr7-4gjf/GHSA-3q84-pcr7-4gjf.json b/advisories/unreviewed/2024/08/GHSA-3q84-pcr7-4gjf/GHSA-3q84-pcr7-4gjf.json new file mode 100644 index 00000000000..9fc23c9487f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3q84-pcr7-4gjf/GHSA-3q84-pcr7-4gjf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q84-pcr7-4gjf", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2022-23817" + ], + "details": "Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23817" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4004.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json b/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json new file mode 100644 index 00000000000..97458115fe3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3w7r-v4fr-r43w/GHSA-3w7r-v4fr-r43w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w7r-v4fr-r43w", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31356" + ], + "details": "Incomplete system memory cleanup in SEV firmware could\nallow a privileged attacker to corrupt guest private memory, potentially\nresulting in a loss of data integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31356" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3wjg-cv7j-pjw6/GHSA-3wjg-cv7j-pjw6.json b/advisories/unreviewed/2024/08/GHSA-3wjg-cv7j-pjw6/GHSA-3wjg-cv7j-pjw6.json new file mode 100644 index 00000000000..46cada85437 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3wjg-cv7j-pjw6/GHSA-3wjg-cv7j-pjw6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wjg-cv7j-pjw6", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38141" + ], + "details": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38141" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38141" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3wvg-3mmq-332j/GHSA-3wvg-3mmq-332j.json b/advisories/unreviewed/2024/08/GHSA-3wvg-3mmq-332j/GHSA-3wvg-3mmq-332j.json index 9fbc12610c3..a8a5232a70b 100644 --- a/advisories/unreviewed/2024/08/GHSA-3wvg-3mmq-332j/GHSA-3wvg-3mmq-332j.json +++ b/advisories/unreviewed/2024/08/GHSA-3wvg-3mmq-332j/GHSA-3wvg-3mmq-332j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wvg-3mmq-332j", - "modified": "2024-08-12T15:30:52Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:52Z", "aliases": [ "CVE-2024-7408" ], "details": "This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP.\n\nSuccessful exploitation of this vulnerability could allow the attacker to cause Evil Twin attack on the targeted system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json b/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json new file mode 100644 index 00000000000..29bfddb6e70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-44gw-49w9-fmfr/GHSA-44gw-49w9-fmfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44gw-49w9-fmfr", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-36505" + ], + "details": "An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36505" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-48cg-rxmx-xw45/GHSA-48cg-rxmx-xw45.json b/advisories/unreviewed/2024/08/GHSA-48cg-rxmx-xw45/GHSA-48cg-rxmx-xw45.json index e5534949c11..bc2bf8c2306 100644 --- a/advisories/unreviewed/2024/08/GHSA-48cg-rxmx-xw45/GHSA-48cg-rxmx-xw45.json +++ b/advisories/unreviewed/2024/08/GHSA-48cg-rxmx-xw45/GHSA-48cg-rxmx-xw45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48cg-rxmx-xw45", - "modified": "2024-08-12T21:31:34Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:34Z", "aliases": [ "CVE-2024-42547" ], "details": "TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T19:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-48r4-vgjh-mw65/GHSA-48r4-vgjh-mw65.json b/advisories/unreviewed/2024/08/GHSA-48r4-vgjh-mw65/GHSA-48r4-vgjh-mw65.json new file mode 100644 index 00000000000..546df3b6407 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-48r4-vgjh-mw65/GHSA-48r4-vgjh-mw65.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48r4-vgjh-mw65", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38117" + ], + "details": "NTFS Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38117" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4q56-g7vf-vcvc/GHSA-4q56-g7vf-vcvc.json b/advisories/unreviewed/2024/08/GHSA-4q56-g7vf-vcvc/GHSA-4q56-g7vf-vcvc.json index d5588654fb6..49b5675c34c 100644 --- a/advisories/unreviewed/2024/08/GHSA-4q56-g7vf-vcvc/GHSA-4q56-g7vf-vcvc.json +++ b/advisories/unreviewed/2024/08/GHSA-4q56-g7vf-vcvc/GHSA-4q56-g7vf-vcvc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4r67-5w29-w28m/GHSA-4r67-5w29-w28m.json b/advisories/unreviewed/2024/08/GHSA-4r67-5w29-w28m/GHSA-4r67-5w29-w28m.json new file mode 100644 index 00000000000..7832ef5ba9a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4r67-5w29-w28m/GHSA-4r67-5w29-w28m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r67-5w29-w28m", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-6079" + ], + "details": "A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a malicious dll and perform a remote code execution attack.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6079" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201683.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-610" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json b/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json new file mode 100644 index 00000000000..3522b972fca --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4vr6-qr4v-xmvq/GHSA-4vr6-qr4v-xmvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vr6-qr4v-xmvq", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-26211" + ], + "details": "An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26211" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-088" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4wjp-4mm4-3wrh/GHSA-4wjp-4mm4-3wrh.json b/advisories/unreviewed/2024/08/GHSA-4wjp-4mm4-3wrh/GHSA-4wjp-4mm4-3wrh.json index 74decd259a8..25138a3318e 100644 --- a/advisories/unreviewed/2024/08/GHSA-4wjp-4mm4-3wrh/GHSA-4wjp-4mm4-3wrh.json +++ b/advisories/unreviewed/2024/08/GHSA-4wjp-4mm4-3wrh/GHSA-4wjp-4mm4-3wrh.json @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-99" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-54c4-m6wj-xg9p/GHSA-54c4-m6wj-xg9p.json b/advisories/unreviewed/2024/08/GHSA-54c4-m6wj-xg9p/GHSA-54c4-m6wj-xg9p.json new file mode 100644 index 00000000000..5c28397d795 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-54c4-m6wj-xg9p/GHSA-54c4-m6wj-xg9p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54c4-m6wj-xg9p", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-7567" + ], + "details": "A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7567" + }, + { + "type": "WEB", + "url": "https://https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1684.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json b/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json new file mode 100644 index 00000000000..6a19d6d4338 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-54xp-779j-4c34/GHSA-54xp-779j-4c34.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54xp-779j-4c34", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38137" + ], + "details": "Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38137" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38137" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-59m8-4xq6-9rfh/GHSA-59m8-4xq6-9rfh.json b/advisories/unreviewed/2024/08/GHSA-59m8-4xq6-9rfh/GHSA-59m8-4xq6-9rfh.json new file mode 100644 index 00000000000..18690018685 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-59m8-4xq6-9rfh/GHSA-59m8-4xq6-9rfh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59m8-4xq6-9rfh", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38185" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38185" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5fm2-3g7q-5j8c/GHSA-5fm2-3g7q-5j8c.json b/advisories/unreviewed/2024/08/GHSA-5fm2-3g7q-5j8c/GHSA-5fm2-3g7q-5j8c.json index e8b5b79f252..60974e3b7fe 100644 --- a/advisories/unreviewed/2024/08/GHSA-5fm2-3g7q-5j8c/GHSA-5fm2-3g7q-5j8c.json +++ b/advisories/unreviewed/2024/08/GHSA-5fm2-3g7q-5j8c/GHSA-5fm2-3g7q-5j8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5fm2-3g7q-5j8c", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42743" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenicated Attackers can send malicious packet to execute arbitary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5q47-p32p-3746/GHSA-5q47-p32p-3746.json b/advisories/unreviewed/2024/08/GHSA-5q47-p32p-3746/GHSA-5q47-p32p-3746.json new file mode 100644 index 00000000000..74086445b6b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5q47-p32p-3746/GHSA-5q47-p32p-3746.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q47-p32p-3746", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38146" + ], + "details": "Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38146" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5vvr-p8h5-fvqj/GHSA-5vvr-p8h5-fvqj.json b/advisories/unreviewed/2024/08/GHSA-5vvr-p8h5-fvqj/GHSA-5vvr-p8h5-fvqj.json new file mode 100644 index 00000000000..11fd8c10100 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5vvr-p8h5-fvqj/GHSA-5vvr-p8h5-fvqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vvr-p8h5-fvqj", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38131" + ], + "details": "Clipboard Virtual Channel Extension Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38131" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38131" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-64w6-5m24-3wqm/GHSA-64w6-5m24-3wqm.json b/advisories/unreviewed/2024/08/GHSA-64w6-5m24-3wqm/GHSA-64w6-5m24-3wqm.json index 0632446ccd3..41d5bc34d0a 100644 --- a/advisories/unreviewed/2024/08/GHSA-64w6-5m24-3wqm/GHSA-64w6-5m24-3wqm.json +++ b/advisories/unreviewed/2024/08/GHSA-64w6-5m24-3wqm/GHSA-64w6-5m24-3wqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64w6-5m24-3wqm", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42748" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6ghv-673h-jf67/GHSA-6ghv-673h-jf67.json b/advisories/unreviewed/2024/08/GHSA-6ghv-673h-jf67/GHSA-6ghv-673h-jf67.json new file mode 100644 index 00000000000..d30bea47be3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6ghv-673h-jf67/GHSA-6ghv-673h-jf67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ghv-673h-jf67", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38123" + ], + "details": "Windows Bluetooth Driver Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38123" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6jh6-jwrq-3f9r/GHSA-6jh6-jwrq-3f9r.json b/advisories/unreviewed/2024/08/GHSA-6jh6-jwrq-3f9r/GHSA-6jh6-jwrq-3f9r.json new file mode 100644 index 00000000000..3d8ceca82b2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6jh6-jwrq-3f9r/GHSA-6jh6-jwrq-3f9r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jh6-jwrq-3f9r", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38159" + ], + "details": "Windows Network Virtualization Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38159" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json b/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json index 1bc3d40376f..939b05a5516 100644 --- a/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json +++ b/advisories/unreviewed/2024/08/GHSA-6phv-2frh-h52x/GHSA-6phv-2frh-h52x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6phv-2frh-h52x", - "modified": "2024-08-12T18:30:48Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T18:30:48Z", "aliases": [ "CVE-2024-41475" ], "details": "Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T17:15:17Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6q99-x922-j9rr/GHSA-6q99-x922-j9rr.json b/advisories/unreviewed/2024/08/GHSA-6q99-x922-j9rr/GHSA-6q99-x922-j9rr.json new file mode 100644 index 00000000000..4ed26332ed9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6q99-x922-j9rr/GHSA-6q99-x922-j9rr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q99-x922-j9rr", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-7733" + ], + "details": "A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7733" + }, + { + "type": "WEB", + "url": "https://gitee.com/xjd2020/fastcms/issues/IAI8T6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274350" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json b/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json new file mode 100644 index 00000000000..c91147fcd0c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-754m-gg4c-75j7", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-41711" + ], + "details": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41711" + }, + { + "type": "WEB", + "url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0020" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-762q-jqwq-g847/GHSA-762q-jqwq-g847.json b/advisories/unreviewed/2024/08/GHSA-762q-jqwq-g847/GHSA-762q-jqwq-g847.json index aaf7589e442..dc7fcbf0801 100644 --- a/advisories/unreviewed/2024/08/GHSA-762q-jqwq-g847/GHSA-762q-jqwq-g847.json +++ b/advisories/unreviewed/2024/08/GHSA-762q-jqwq-g847/GHSA-762q-jqwq-g847.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-762q-jqwq-g847", - "modified": "2024-08-12T15:30:54Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:54Z", "aliases": [ "CVE-2024-42258" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines\n\nYves-Alexis Perez reported commit 4ef9ad19e176 (\"mm: huge_memory: don't\nforce huge page alignment on 32 bit\") didn't work for x86_32 [1]. It is\nbecause x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT.\n\n!CONFIG_64BIT should cover all 32 bit machines.\n\n[1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7cfh-j5pv-fw3c/GHSA-7cfh-j5pv-fw3c.json b/advisories/unreviewed/2024/08/GHSA-7cfh-j5pv-fw3c/GHSA-7cfh-j5pv-fw3c.json new file mode 100644 index 00000000000..f37b9da0157 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7cfh-j5pv-fw3c/GHSA-7cfh-j5pv-fw3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cfh-j5pv-fw3c", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20584" + ], + "details": "IOMMU improperly handles certain special address\nranges with invalid device table entries (DTEs), which may allow an attacker\nwith privileges and a compromised Hypervisor to\ninduce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a\nloss of guest integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20584" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7f4x-577f-7gw8/GHSA-7f4x-577f-7gw8.json b/advisories/unreviewed/2024/08/GHSA-7f4x-577f-7gw8/GHSA-7f4x-577f-7gw8.json new file mode 100644 index 00000000000..fab9c9cc533 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7f4x-577f-7gw8/GHSA-7f4x-577f-7gw8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f4x-577f-7gw8", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38155" + ], + "details": "Security Center Broker Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38155" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38155" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7qxv-p6jq-6vf6/GHSA-7qxv-p6jq-6vf6.json b/advisories/unreviewed/2024/08/GHSA-7qxv-p6jq-6vf6/GHSA-7qxv-p6jq-6vf6.json new file mode 100644 index 00000000000..19be998000e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7qxv-p6jq-6vf6/GHSA-7qxv-p6jq-6vf6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qxv-p6jq-6vf6", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38173" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38173" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38173" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json b/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json index 2f21c500913..c1248219f7c 100644 --- a/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json +++ b/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7r5c-r5ww-995h", - "modified": "2024-08-12T15:30:48Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:48Z", "aliases": [ "CVE-2023-31315" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-7wx3-r5h3-p5x3/GHSA-7wx3-r5h3-p5x3.json b/advisories/unreviewed/2024/08/GHSA-7wx3-r5h3-p5x3/GHSA-7wx3-r5h3-p5x3.json new file mode 100644 index 00000000000..bc43d2b79b5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7wx3-r5h3-p5x3/GHSA-7wx3-r5h3-p5x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wx3-r5h3-p5x3", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38186" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38186" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json b/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json new file mode 100644 index 00000000000..5785fc00275 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-82w9-g9wm-675r/GHSA-82w9-g9wm-675r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82w9-g9wm-675r", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38193" + ], + "details": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38193" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-82xh-cprj-85f2/GHSA-82xh-cprj-85f2.json b/advisories/unreviewed/2024/08/GHSA-82xh-cprj-85f2/GHSA-82xh-cprj-85f2.json new file mode 100644 index 00000000000..af07dac4715 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-82xh-cprj-85f2/GHSA-82xh-cprj-85f2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82xh-cprj-85f2", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38116" + ], + "details": "Windows IP Routing Management Snapin Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38116" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json b/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json index 3d83d564254..204e0cf5f6c 100644 --- a/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json +++ b/advisories/unreviewed/2024/08/GHSA-83cp-ppjr-7w6j/GHSA-83cp-ppjr-7w6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-83cp-ppjr-7w6j", - "modified": "2024-08-13T15:31:36Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-13T15:31:36Z", "aliases": [ "CVE-2024-42738" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T14:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-86wc-3f6v-chh4/GHSA-86wc-3f6v-chh4.json b/advisories/unreviewed/2024/08/GHSA-86wc-3f6v-chh4/GHSA-86wc-3f6v-chh4.json new file mode 100644 index 00000000000..da24e900c32 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-86wc-3f6v-chh4/GHSA-86wc-3f6v-chh4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86wc-3f6v-chh4", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38144" + ], + "details": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38144" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38144" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-877h-phh3-7f4r/GHSA-877h-phh3-7f4r.json b/advisories/unreviewed/2024/08/GHSA-877h-phh3-7f4r/GHSA-877h-phh3-7f4r.json new file mode 100644 index 00000000000..85337cf780b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-877h-phh3-7f4r/GHSA-877h-phh3-7f4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-877h-phh3-7f4r", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38177" + ], + "details": "Windows App Installer Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38177" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json b/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json new file mode 100644 index 00000000000..986abb1a614 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jq9-2rv4-gphv", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-41613" + ], + "details": "A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41613" + }, + { + "type": "WEB", + "url": "https://github.com/OoLs5/VulDiscovery/blob/main/symphony_xss_vul.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8v4p-m86x-qgww/GHSA-8v4p-m86x-qgww.json b/advisories/unreviewed/2024/08/GHSA-8v4p-m86x-qgww/GHSA-8v4p-m86x-qgww.json new file mode 100644 index 00000000000..0b0e134d547 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8v4p-m86x-qgww/GHSA-8v4p-m86x-qgww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v4p-m86x-qgww", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38197" + ], + "details": "Microsoft Teams for iOS Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38197" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38197" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json b/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json new file mode 100644 index 00000000000..d68b3429f6c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8x5q-gq29-2h75/GHSA-8x5q-gq29-2h75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x5q-gq29-2h75", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-21981" + ], + "details": "Improper key usage control in AMD Secure Processor\n(ASP) may allow an attacker with local access who has gained arbitrary code\nexecution privilege in ASP to\nextract ASP cryptographic keys, potentially resulting in loss of\nconfidentiality and integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21981" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-924r-5j98-wj3c/GHSA-924r-5j98-wj3c.json b/advisories/unreviewed/2024/08/GHSA-924r-5j98-wj3c/GHSA-924r-5j98-wj3c.json new file mode 100644 index 00000000000..ed954bd24da --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-924r-5j98-wj3c/GHSA-924r-5j98-wj3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-924r-5j98-wj3c", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38162" + ], + "details": "Azure Connected Machine Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38162" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38162" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-944q-f38w-27wf/GHSA-944q-f38w-27wf.json b/advisories/unreviewed/2024/08/GHSA-944q-f38w-27wf/GHSA-944q-f38w-27wf.json index 85f4880872c..f5a8210b384 100644 --- a/advisories/unreviewed/2024/08/GHSA-944q-f38w-27wf/GHSA-944q-f38w-27wf.json +++ b/advisories/unreviewed/2024/08/GHSA-944q-f38w-27wf/GHSA-944q-f38w-27wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-944q-f38w-27wf", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42741" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenicated Attackers can send malicious packet to execute arbitary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-992j-w4f8-px4g/GHSA-992j-w4f8-px4g.json b/advisories/unreviewed/2024/08/GHSA-992j-w4f8-px4g/GHSA-992j-w4f8-px4g.json new file mode 100644 index 00000000000..84734c6b0eb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-992j-w4f8-px4g/GHSA-992j-w4f8-px4g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-992j-w4f8-px4g", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38130" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38130" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9fw3-5q39-gcg2/GHSA-9fw3-5q39-gcg2.json b/advisories/unreviewed/2024/08/GHSA-9fw3-5q39-gcg2/GHSA-9fw3-5q39-gcg2.json index 438d519b4a0..93770bbef8b 100644 --- a/advisories/unreviewed/2024/08/GHSA-9fw3-5q39-gcg2/GHSA-9fw3-5q39-gcg2.json +++ b/advisories/unreviewed/2024/08/GHSA-9fw3-5q39-gcg2/GHSA-9fw3-5q39-gcg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fw3-5q39-gcg2", - "modified": "2024-08-12T18:30:47Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T18:30:47Z", "aliases": [ "CVE-2024-39091" ], "details": "An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T16:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json b/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json new file mode 100644 index 00000000000..9fea524ffd6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9h7f-r33v-rw4r/GHSA-9h7f-r33v-rw4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h7f-r33v-rw4r", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2021-26344" + ], + "details": "An out of bounds memory write when processing the AMD\nPSP1 Configuration Block (APCB) could allow an attacker with access the ability\nto modify the BIOS image, and the ability to sign the resulting image, to\npotentially modify the APCB block resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26344" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json b/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json new file mode 100644 index 00000000000..6ae82b779c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m5w-7xhr-393x", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31348" + ], + "details": "A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31348" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-9001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9mgf-vm6p-3g3g/GHSA-9mgf-vm6p-3g3g.json b/advisories/unreviewed/2024/08/GHSA-9mgf-vm6p-3g3g/GHSA-9mgf-vm6p-3g3g.json index 0854f906ad6..4277c2a63bf 100644 --- a/advisories/unreviewed/2024/08/GHSA-9mgf-vm6p-3g3g/GHSA-9mgf-vm6p-3g3g.json +++ b/advisories/unreviewed/2024/08/GHSA-9mgf-vm6p-3g3g/GHSA-9mgf-vm6p-3g3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mgf-vm6p-3g3g", - "modified": "2024-08-12T21:31:34Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:34Z", "aliases": [ "CVE-2024-42546" ], "details": "TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T19:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9vc7-j86j-jm7h/GHSA-9vc7-j86j-jm7h.json b/advisories/unreviewed/2024/08/GHSA-9vc7-j86j-jm7h/GHSA-9vc7-j86j-jm7h.json new file mode 100644 index 00000000000..241a95e42ba --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9vc7-j86j-jm7h/GHSA-9vc7-j86j-jm7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vc7-j86j-jm7h", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38135" + ], + "details": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38135" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c77v-cr6c-9fxw/GHSA-c77v-cr6c-9fxw.json b/advisories/unreviewed/2024/08/GHSA-c77v-cr6c-9fxw/GHSA-c77v-cr6c-9fxw.json new file mode 100644 index 00000000000..28ad81ed3c3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c77v-cr6c-9fxw/GHSA-c77v-cr6c-9fxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c77v-cr6c-9fxw", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38153" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38153" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38153" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json b/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json new file mode 100644 index 00000000000..a1afbcd5c3a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c87h-375h-xrrv/GHSA-c87h-375h-xrrv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c87h-375h-xrrv", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31341" + ], + "details": "Insufficient\nvalidation of the Input Output Control (IOCTL) input buffer in AMD μProf may\nallow an authenticated attacker to cause an out-of-bounds write, potentially\ncausing a Windows® OS crash, resulting in denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31341" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-9001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json b/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json new file mode 100644 index 00000000000..166ee743d1a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ch37-5p65-5r4w/GHSA-ch37-5p65-5r4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch37-5p65-5r4w", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20512" + ], + "details": "A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20512" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json b/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json index 2142f37d713..35facc335e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json +++ b/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch8j-4g5p-qvwx", - "modified": "2024-08-13T06:30:48Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-13T06:30:48Z", "aliases": [ "CVE-2024-6724" ], "details": "The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json b/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json new file mode 100644 index 00000000000..143c89b053e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cjjq-cwpw-fx4q/GHSA-cjjq-cwpw-fx4q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjjq-cwpw-fx4q", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2022-23815" + ], + "details": "Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23815" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4004.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cpff-q36h-wcr2/GHSA-cpff-q36h-wcr2.json b/advisories/unreviewed/2024/08/GHSA-cpff-q36h-wcr2/GHSA-cpff-q36h-wcr2.json index 21955650c44..3cd53fe1200 100644 --- a/advisories/unreviewed/2024/08/GHSA-cpff-q36h-wcr2/GHSA-cpff-q36h-wcr2.json +++ b/advisories/unreviewed/2024/08/GHSA-cpff-q36h-wcr2/GHSA-cpff-q36h-wcr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpff-q36h-wcr2", - "modified": "2024-08-12T15:30:54Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:54Z", "aliases": [ "CVE-2024-33535" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages parameter. Attackers can exploit this flaw to include arbitrary local files without authentication, potentially leading to unauthorized access to sensitive information. The vulnerability is limited to files within a specific directory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json b/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json new file mode 100644 index 00000000000..ec903f5f619 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-crf2-q686-qj4r/GHSA-crf2-q686-qj4r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crf2-q686-qj4r", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-36446" + ], + "details": "The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36446" + }, + { + "type": "WEB", + "url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0017" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cvxv-m6qx-4784/GHSA-cvxv-m6qx-4784.json b/advisories/unreviewed/2024/08/GHSA-cvxv-m6qx-4784/GHSA-cvxv-m6qx-4784.json new file mode 100644 index 00000000000..43139046279 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cvxv-m6qx-4784/GHSA-cvxv-m6qx-4784.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvxv-m6qx-4784", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38145" + ], + "details": "Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38145" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cxhc-c4pj-cchp/GHSA-cxhc-c4pj-cchp.json b/advisories/unreviewed/2024/08/GHSA-cxhc-c4pj-cchp/GHSA-cxhc-c4pj-cchp.json index 5196257ec95..83d32cedc1e 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxhc-c4pj-cchp/GHSA-cxhc-c4pj-cchp.json +++ b/advisories/unreviewed/2024/08/GHSA-cxhc-c4pj-cchp/GHSA-cxhc-c4pj-cchp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxhc-c4pj-cchp", - "modified": "2024-08-12T15:30:54Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:54Z", "aliases": [ "CVE-2024-33536" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file, accessible externally, and crafting a URL containing its location in the res parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cxr7-wqw9-gw4w/GHSA-cxr7-wqw9-gw4w.json b/advisories/unreviewed/2024/08/GHSA-cxr7-wqw9-gw4w/GHSA-cxr7-wqw9-gw4w.json new file mode 100644 index 00000000000..df0433da2f1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cxr7-wqw9-gw4w/GHSA-cxr7-wqw9-gw4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxr7-wqw9-gw4w", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38187" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38187" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f3r5-wp36-39jf/GHSA-f3r5-wp36-39jf.json b/advisories/unreviewed/2024/08/GHSA-f3r5-wp36-39jf/GHSA-f3r5-wp36-39jf.json new file mode 100644 index 00000000000..a30db31ca51 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f3r5-wp36-39jf/GHSA-f3r5-wp36-39jf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3r5-wp36-39jf", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38169" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38169" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38169" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f4f5-49rv-w5xh/GHSA-f4f5-49rv-w5xh.json b/advisories/unreviewed/2024/08/GHSA-f4f5-49rv-w5xh/GHSA-f4f5-49rv-w5xh.json new file mode 100644 index 00000000000..e6b58742bbd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f4f5-49rv-w5xh/GHSA-f4f5-49rv-w5xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4f5-49rv-w5xh", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38126" + ], + "details": "Windows Network Address Translation (NAT) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38126" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f5qp-6qph-5f2c/GHSA-f5qp-6qph-5f2c.json b/advisories/unreviewed/2024/08/GHSA-f5qp-6qph-5f2c/GHSA-f5qp-6qph-5f2c.json new file mode 100644 index 00000000000..b3030097d6f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f5qp-6qph-5f2c/GHSA-f5qp-6qph-5f2c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5qp-6qph-5f2c", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38165" + ], + "details": "Windows Compressed Folder Tampering Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38165" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38165" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fjx6-h45r-j49h/GHSA-fjx6-h45r-j49h.json b/advisories/unreviewed/2024/08/GHSA-fjx6-h45r-j49h/GHSA-fjx6-h45r-j49h.json new file mode 100644 index 00000000000..6edab45cdd6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fjx6-h45r-j49h/GHSA-fjx6-h45r-j49h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjx6-h45r-j49h", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38114" + ], + "details": "Windows IP Routing Management Snapin Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38114" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fmm4-gg8x-5cxp/GHSA-fmm4-gg8x-5cxp.json b/advisories/unreviewed/2024/08/GHSA-fmm4-gg8x-5cxp/GHSA-fmm4-gg8x-5cxp.json new file mode 100644 index 00000000000..d4dc8bcffde --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fmm4-gg8x-5cxp/GHSA-fmm4-gg8x-5cxp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmm4-gg8x-5cxp", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38118" + ], + "details": "Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38118" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fpq3-933h-fgw6/GHSA-fpq3-933h-fgw6.json b/advisories/unreviewed/2024/08/GHSA-fpq3-933h-fgw6/GHSA-fpq3-933h-fgw6.json new file mode 100644 index 00000000000..f655f464832 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fpq3-933h-fgw6/GHSA-fpq3-933h-fgw6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpq3-933h-fgw6", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38180" + ], + "details": "Windows SmartScreen Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38180" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fr76-j9qw-qp24/GHSA-fr76-j9qw-qp24.json b/advisories/unreviewed/2024/08/GHSA-fr76-j9qw-qp24/GHSA-fr76-j9qw-qp24.json new file mode 100644 index 00000000000..d486aa33721 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fr76-j9qw-qp24/GHSA-fr76-j9qw-qp24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr76-j9qw-qp24", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38157" + ], + "details": "Azure IoT SDK Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38157" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38157" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json b/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json new file mode 100644 index 00000000000..ba9b9ec98a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-frc3-7x76-jwp8/GHSA-frc3-7x76-jwp8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frc3-7x76-jwp8", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-37015" + ], + "details": "An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37015" + }, + { + "type": "WEB", + "url": "https://docs.adacore.com/corp/security-advisories/SEC.AWS-0031-v2.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/AdaCore/aws" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fv99-5wj3-4752/GHSA-fv99-5wj3-4752.json b/advisories/unreviewed/2024/08/GHSA-fv99-5wj3-4752/GHSA-fv99-5wj3-4752.json new file mode 100644 index 00000000000..5173b07c657 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fv99-5wj3-4752/GHSA-fv99-5wj3-4752.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv99-5wj3-4752", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38109" + ], + "details": "An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38109" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json b/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json new file mode 100644 index 00000000000..80c5cd0dfc0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6wf-h667-5899", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31366" + ], + "details": "Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31366" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-9001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g847-xw4j-f8wr/GHSA-g847-xw4j-f8wr.json b/advisories/unreviewed/2024/08/GHSA-g847-xw4j-f8wr/GHSA-g847-xw4j-f8wr.json index b4df7896247..22fa2da3565 100644 --- a/advisories/unreviewed/2024/08/GHSA-g847-xw4j-f8wr/GHSA-g847-xw4j-f8wr.json +++ b/advisories/unreviewed/2024/08/GHSA-g847-xw4j-f8wr/GHSA-g847-xw4j-f8wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g847-xw4j-f8wr", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42742" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenicated Attackers can send malicious packet to execute arbitary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-ggjr-j3fm-frpm/GHSA-ggjr-j3fm-frpm.json b/advisories/unreviewed/2024/08/GHSA-ggjr-j3fm-frpm/GHSA-ggjr-j3fm-frpm.json new file mode 100644 index 00000000000..d319ca9340b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ggjr-j3fm-frpm/GHSA-ggjr-j3fm-frpm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggjr-j3fm-frpm", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-38098" + ], + "details": "Azure Connected Machine Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38098" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38098" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json b/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json new file mode 100644 index 00000000000..79c894a5a4d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ggw5-pfvx-r7j9/GHSA-ggw5-pfvx-r7j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggw5-pfvx-r7j9", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2022-45862" + ], + "details": "An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45862" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-445" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gm29-ch22-6w64/GHSA-gm29-ch22-6w64.json b/advisories/unreviewed/2024/08/GHSA-gm29-ch22-6w64/GHSA-gm29-ch22-6w64.json new file mode 100644 index 00000000000..5ee4f9c7539 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gm29-ch22-6w64/GHSA-gm29-ch22-6w64.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm29-ch22-6w64", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-6618" + ], + "details": "In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6618" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-226-08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gv8h-8gmg-w82w/GHSA-gv8h-8gmg-w82w.json b/advisories/unreviewed/2024/08/GHSA-gv8h-8gmg-w82w/GHSA-gv8h-8gmg-w82w.json new file mode 100644 index 00000000000..6988bf0b0f4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gv8h-8gmg-w82w/GHSA-gv8h-8gmg-w82w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv8h-8gmg-w82w", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38161" + ], + "details": "Windows Mobile Broadband Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38161" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38161" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json b/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json index da8057ec364..0ed7a05e88c 100644 --- a/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json +++ b/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw56-mg6j-26qj", - "modified": "2024-08-08T12:30:34Z", + "modified": "2024-08-13T18:31:13Z", "published": "2024-08-08T03:30:49Z", "aliases": [ "CVE-2024-38202" diff --git a/advisories/unreviewed/2024/08/GHSA-gw64-h9cg-pccr/GHSA-gw64-h9cg-pccr.json b/advisories/unreviewed/2024/08/GHSA-gw64-h9cg-pccr/GHSA-gw64-h9cg-pccr.json new file mode 100644 index 00000000000..f9bbb2f3f42 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gw64-h9cg-pccr/GHSA-gw64-h9cg-pccr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw64-h9cg-pccr", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-29995" + ], + "details": "Windows Kerberos Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29995" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29995" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gxpr-qjxg-92q3/GHSA-gxpr-qjxg-92q3.json b/advisories/unreviewed/2024/08/GHSA-gxpr-qjxg-92q3/GHSA-gxpr-qjxg-92q3.json new file mode 100644 index 00000000000..3b38dfe7c7e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gxpr-qjxg-92q3/GHSA-gxpr-qjxg-92q3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxpr-qjxg-92q3", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-38084" + ], + "details": "Microsoft OfficePlus Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38084" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38084" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h2f3-rmwp-xjm6/GHSA-h2f3-rmwp-xjm6.json b/advisories/unreviewed/2024/08/GHSA-h2f3-rmwp-xjm6/GHSA-h2f3-rmwp-xjm6.json new file mode 100644 index 00000000000..3d7ccc1711c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h2f3-rmwp-xjm6/GHSA-h2f3-rmwp-xjm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2f3-rmwp-xjm6", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38120" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38120" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hq7f-8578-2f59/GHSA-hq7f-8578-2f59.json b/advisories/unreviewed/2024/08/GHSA-hq7f-8578-2f59/GHSA-hq7f-8578-2f59.json index bc84c57aa9b..39d36e747f5 100644 --- a/advisories/unreviewed/2024/08/GHSA-hq7f-8578-2f59/GHSA-hq7f-8578-2f59.json +++ b/advisories/unreviewed/2024/08/GHSA-hq7f-8578-2f59/GHSA-hq7f-8578-2f59.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq7f-8578-2f59", - "modified": "2024-08-12T15:30:54Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:54Z", "aliases": [ "CVE-2024-6917" ], "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection.This issue affects Veribase Order Management: before v4.010.2.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-hqpr-5v22-5x6j/GHSA-hqpr-5v22-5x6j.json b/advisories/unreviewed/2024/08/GHSA-hqpr-5v22-5x6j/GHSA-hqpr-5v22-5x6j.json new file mode 100644 index 00000000000..59d5be17437 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hqpr-5v22-5x6j/GHSA-hqpr-5v22-5x6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqpr-5v22-5x6j", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38150" + ], + "details": "Windows DWM Core Library Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38150" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38150" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j7jm-6q5x-ffr4/GHSA-j7jm-6q5x-ffr4.json b/advisories/unreviewed/2024/08/GHSA-j7jm-6q5x-ffr4/GHSA-j7jm-6q5x-ffr4.json index 27332ffb90e..11a08b9fd24 100644 --- a/advisories/unreviewed/2024/08/GHSA-j7jm-6q5x-ffr4/GHSA-j7jm-6q5x-ffr4.json +++ b/advisories/unreviewed/2024/08/GHSA-j7jm-6q5x-ffr4/GHSA-j7jm-6q5x-ffr4.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-364" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json b/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json index cc81c5f1d81..f42f4f00002 100644 --- a/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json +++ b/advisories/unreviewed/2024/08/GHSA-j85v-mpgg-r272/GHSA-j85v-mpgg-r272.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j85v-mpgg-r272", - "modified": "2024-08-13T15:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-13T15:31:35Z", "aliases": [ "CVE-2024-42736" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T14:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json b/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json index 353816d5407..741650b4687 100644 --- a/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json +++ b/advisories/unreviewed/2024/08/GHSA-jcvv-37v4-9r3f/GHSA-jcvv-37v4-9r3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jcvv-37v4-9r3f", - "modified": "2024-08-13T15:31:36Z", + "modified": "2024-08-13T18:31:15Z", "published": "2024-08-13T15:31:36Z", "aliases": [ "CVE-2024-42740" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T14:15:14Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jgf9-78f9-w5qh/GHSA-jgf9-78f9-w5qh.json b/advisories/unreviewed/2024/08/GHSA-jgf9-78f9-w5qh/GHSA-jgf9-78f9-w5qh.json new file mode 100644 index 00000000000..b53e55c705c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jgf9-78f9-w5qh/GHSA-jgf9-78f9-w5qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgf9-78f9-w5qh", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38152" + ], + "details": "Windows OLE Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38152" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38152" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jj5m-2m9j-hxjw/GHSA-jj5m-2m9j-hxjw.json b/advisories/unreviewed/2024/08/GHSA-jj5m-2m9j-hxjw/GHSA-jj5m-2m9j-hxjw.json new file mode 100644 index 00000000000..c4ab412c8cb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jj5m-2m9j-hxjw/GHSA-jj5m-2m9j-hxjw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj5m-2m9j-hxjw", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-7113" + ], + "details": "If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7113" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-226-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m37f-qr93-p7wv/GHSA-m37f-qr93-p7wv.json b/advisories/unreviewed/2024/08/GHSA-m37f-qr93-p7wv/GHSA-m37f-qr93-p7wv.json index 354584c9fbe..e436b91afc9 100644 --- a/advisories/unreviewed/2024/08/GHSA-m37f-qr93-p7wv/GHSA-m37f-qr93-p7wv.json +++ b/advisories/unreviewed/2024/08/GHSA-m37f-qr93-p7wv/GHSA-m37f-qr93-p7wv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m37f-qr93-p7wv", - "modified": "2024-08-12T18:30:47Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T18:30:47Z", "aliases": [ "CVE-2023-7249" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:L/U:Amber" diff --git a/advisories/unreviewed/2024/08/GHSA-m3fj-x3xw-vjr6/GHSA-m3fj-x3xw-vjr6.json b/advisories/unreviewed/2024/08/GHSA-m3fj-x3xw-vjr6/GHSA-m3fj-x3xw-vjr6.json new file mode 100644 index 00000000000..955b289ff2c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m3fj-x3xw-vjr6/GHSA-m3fj-x3xw-vjr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3fj-x3xw-vjr6", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38199" + ], + "details": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38199" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38199" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m7q3-2wwp-9pqp/GHSA-m7q3-2wwp-9pqp.json b/advisories/unreviewed/2024/08/GHSA-m7q3-2wwp-9pqp/GHSA-m7q3-2wwp-9pqp.json new file mode 100644 index 00000000000..10868abe4a8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m7q3-2wwp-9pqp/GHSA-m7q3-2wwp-9pqp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7q3-2wwp-9pqp", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38214" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38214" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38214" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m88f-9qc8-46xh/GHSA-m88f-9qc8-46xh.json b/advisories/unreviewed/2024/08/GHSA-m88f-9qc8-46xh/GHSA-m88f-9qc8-46xh.json new file mode 100644 index 00000000000..71ce3e20687 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m88f-9qc8-46xh/GHSA-m88f-9qc8-46xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m88f-9qc8-46xh", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38133" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38133" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38133" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-138" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m89q-7gq5-hqp7/GHSA-m89q-7gq5-hqp7.json b/advisories/unreviewed/2024/08/GHSA-m89q-7gq5-hqp7/GHSA-m89q-7gq5-hqp7.json new file mode 100644 index 00000000000..3e93ebe9a3c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m89q-7gq5-hqp7/GHSA-m89q-7gq5-hqp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m89q-7gq5-hqp7", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38191" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38191" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m9rp-3cmh-596m/GHSA-m9rp-3cmh-596m.json b/advisories/unreviewed/2024/08/GHSA-m9rp-3cmh-596m/GHSA-m9rp-3cmh-596m.json new file mode 100644 index 00000000000..428a8e26ef9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m9rp-3cmh-596m/GHSA-m9rp-3cmh-596m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9rp-3cmh-596m", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38147" + ], + "details": "Microsoft DWM Core Library Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38147" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json b/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json new file mode 100644 index 00000000000..aa33babdb98 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mcm9-3rfg-2mqm/GHSA-mcm9-3rfg-2mqm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcm9-3rfg-2mqm", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2021-26387" + ], + "details": "Insufficient access controls in ASP kernel may allow a\nprivileged attacker with access to AMD signing keys and the BIOS menu or UEFI\nshell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26387" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5002.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mgjx-cq94-rwcv/GHSA-mgjx-cq94-rwcv.json b/advisories/unreviewed/2024/08/GHSA-mgjx-cq94-rwcv/GHSA-mgjx-cq94-rwcv.json new file mode 100644 index 00000000000..ddb2e18ac80 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mgjx-cq94-rwcv/GHSA-mgjx-cq94-rwcv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgjx-cq94-rwcv", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2021-46772" + ], + "details": "Insufficient input validation in the ABL may allow a privileged\nattacker with access to the BIOS menu or UEFI shell to tamper with the\nstructure headers in SPI ROM causing an out of bounds memory read and write,\npotentially resulting in memory corruption or denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46772" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4004.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5002.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json b/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json index 483a17ecf7e..d2d30844ac7 100644 --- a/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json +++ b/advisories/unreviewed/2024/08/GHSA-mjh6-rpqh-wmw5/GHSA-mjh6-rpqh-wmw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjh6-rpqh-wmw5", - "modified": "2024-08-13T15:31:36Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-13T15:31:36Z", "aliases": [ "CVE-2024-42737" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T14:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json b/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json new file mode 100644 index 00000000000..e2f4f024c93 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9q-g6cf-hfc4", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31307" + ], + "details": "Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31307" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p425-26vx-fxgh/GHSA-p425-26vx-fxgh.json b/advisories/unreviewed/2024/08/GHSA-p425-26vx-fxgh/GHSA-p425-26vx-fxgh.json new file mode 100644 index 00000000000..51a9aceba5f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p425-26vx-fxgh/GHSA-p425-26vx-fxgh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p425-26vx-fxgh", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38138" + ], + "details": "Windows Deployment Services Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38138" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p522-8v5x-38wr/GHSA-p522-8v5x-38wr.json b/advisories/unreviewed/2024/08/GHSA-p522-8v5x-38wr/GHSA-p522-8v5x-38wr.json new file mode 100644 index 00000000000..3107be15180 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p522-8v5x-38wr/GHSA-p522-8v5x-38wr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p522-8v5x-38wr", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-6619" + ], + "details": "In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6619" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-226-08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json b/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json index 8b6df329837..827501e8a2f 100644 --- a/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json +++ b/advisories/unreviewed/2024/08/GHSA-pc7f-4968-m375/GHSA-pc7f-4968-m375.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7f-4968-m375", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-6158" ], "details": "The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its \"Category Posts\" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:38Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pjx5-g39r-v2jg/GHSA-pjx5-g39r-v2jg.json b/advisories/unreviewed/2024/08/GHSA-pjx5-g39r-v2jg/GHSA-pjx5-g39r-v2jg.json new file mode 100644 index 00000000000..bfa544480eb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pjx5-g39r-v2jg/GHSA-pjx5-g39r-v2jg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjx5-g39r-v2jg", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38148" + ], + "details": "Windows Secure Channel Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38148" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38148" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pmx7-9647-m98m/GHSA-pmx7-9647-m98m.json b/advisories/unreviewed/2024/08/GHSA-pmx7-9647-m98m/GHSA-pmx7-9647-m98m.json index 7ce2da65dce..8f0e7d04291 100644 --- a/advisories/unreviewed/2024/08/GHSA-pmx7-9647-m98m/GHSA-pmx7-9647-m98m.json +++ b/advisories/unreviewed/2024/08/GHSA-pmx7-9647-m98m/GHSA-pmx7-9647-m98m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmx7-9647-m98m", - "modified": "2024-08-12T15:30:53Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:53Z", "aliases": [ "CVE-2024-33533" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the packages parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file and crafting a URL containing its location in the packages parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pp7w-98jh-p48w/GHSA-pp7w-98jh-p48w.json b/advisories/unreviewed/2024/08/GHSA-pp7w-98jh-p48w/GHSA-pp7w-98jh-p48w.json new file mode 100644 index 00000000000..249a97dde41 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pp7w-98jh-p48w/GHSA-pp7w-98jh-p48w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp7w-98jh-p48w", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31304" + ], + "details": "Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to modify the PCIe® lane count and speed, potentially leading to a loss of availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31304" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pqfm-wrf4-hvvh/GHSA-pqfm-wrf4-hvvh.json b/advisories/unreviewed/2024/08/GHSA-pqfm-wrf4-hvvh/GHSA-pqfm-wrf4-hvvh.json new file mode 100644 index 00000000000..ad88ad3c468 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pqfm-wrf4-hvvh/GHSA-pqfm-wrf4-hvvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqfm-wrf4-hvvh", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38132" + ], + "details": "Windows Network Address Translation (NAT) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38132" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38132" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json b/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json new file mode 100644 index 00000000000..36e34cea2be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwh8-gr2w-8xpq", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31349" + ], + "details": "Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31349" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-9001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q54r-rx89-mw8v/GHSA-q54r-rx89-mw8v.json b/advisories/unreviewed/2024/08/GHSA-q54r-rx89-mw8v/GHSA-q54r-rx89-mw8v.json new file mode 100644 index 00000000000..8514bbd0dc4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q54r-rx89-mw8v/GHSA-q54r-rx89-mw8v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q54r-rx89-mw8v", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38172" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38172" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json b/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json new file mode 100644 index 00000000000..b9f395fbfe2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q5q5-qr9g-74ch/GHSA-q5q5-qr9g-74ch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5q5-qr9g-74ch", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-21757" + ], + "details": "A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21757" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-467" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qc93-c985-jh26/GHSA-qc93-c985-jh26.json b/advisories/unreviewed/2024/08/GHSA-qc93-c985-jh26/GHSA-qc93-c985-jh26.json new file mode 100644 index 00000000000..987949c2273 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qc93-c985-jh26/GHSA-qc93-c985-jh26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc93-c985-jh26", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38143" + ], + "details": "Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38143" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38143" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qg9j-4424-vrp7/GHSA-qg9j-4424-vrp7.json b/advisories/unreviewed/2024/08/GHSA-qg9j-4424-vrp7/GHSA-qg9j-4424-vrp7.json new file mode 100644 index 00000000000..3ffbdd3b8d2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qg9j-4424-vrp7/GHSA-qg9j-4424-vrp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg9j-4424-vrp7", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-38107" + ], + "details": "Windows Power Dependency Coordinator Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38107" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qpjc-7c7h-q87c/GHSA-qpjc-7c7h-q87c.json b/advisories/unreviewed/2024/08/GHSA-qpjc-7c7h-q87c/GHSA-qpjc-7c7h-q87c.json new file mode 100644 index 00000000000..5bb72fe8385 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qpjc-7c7h-q87c/GHSA-qpjc-7c7h-q87c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpjc-7c7h-q87c", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38154" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38154" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qpjx-jqj8-rqgr/GHSA-qpjx-jqj8-rqgr.json b/advisories/unreviewed/2024/08/GHSA-qpjx-jqj8-rqgr/GHSA-qpjx-jqj8-rqgr.json new file mode 100644 index 00000000000..60e92c6a59a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qpjx-jqj8-rqgr/GHSA-qpjx-jqj8-rqgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpjx-jqj8-rqgr", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38115" + ], + "details": "Windows IP Routing Management Snapin Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38115" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json b/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json new file mode 100644 index 00000000000..079df012da2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qpx5-6ww4-hp56/GHSA-qpx5-6ww4-hp56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpx5-6ww4-hp56", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31305" + ], + "details": "Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31305" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json b/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json index 678127d2b76..b5345cd0812 100644 --- a/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json +++ b/advisories/unreviewed/2024/08/GHSA-qrvg-mg33-q843/GHSA-qrvg-mg33-q843.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrvg-mg33-q843", - "modified": "2024-08-12T15:30:53Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T15:30:53Z", "aliases": [ "CVE-2024-27443" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T15:15:20Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qwxg-pc97-38hm/GHSA-qwxg-pc97-38hm.json b/advisories/unreviewed/2024/08/GHSA-qwxg-pc97-38hm/GHSA-qwxg-pc97-38hm.json new file mode 100644 index 00000000000..1850955f9cc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qwxg-pc97-38hm/GHSA-qwxg-pc97-38hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwxg-pc97-38hm", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38158" + ], + "details": "Azure IoT SDK Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38158" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38158" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r4gv-9cqf-9mwr/GHSA-r4gv-9cqf-9mwr.json b/advisories/unreviewed/2024/08/GHSA-r4gv-9cqf-9mwr/GHSA-r4gv-9cqf-9mwr.json new file mode 100644 index 00000000000..9624b3f7553 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r4gv-9cqf-9mwr/GHSA-r4gv-9cqf-9mwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4gv-9cqf-9mwr", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38196" + ], + "details": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38196" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json b/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json index 5518b38a1e0..b156140f624 100644 --- a/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json +++ b/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r979-6ffq-pvxw", - "modified": "2024-08-13T15:31:36Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-13T15:31:36Z", "aliases": [ "CVE-2024-42739" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T14:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rg5w-7m5m-gvvc/GHSA-rg5w-7m5m-gvvc.json b/advisories/unreviewed/2024/08/GHSA-rg5w-7m5m-gvvc/GHSA-rg5w-7m5m-gvvc.json new file mode 100644 index 00000000000..d18153d1ce5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rg5w-7m5m-gvvc/GHSA-rg5w-7m5m-gvvc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg5w-7m5m-gvvc", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38171" + ], + "details": "Microsoft PowerPoint Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38171" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38171" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json b/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json new file mode 100644 index 00000000000..98d57efdb2f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj66-wvw5-rcvp", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20518" + ], + "details": "Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20518" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5002.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rj7g-769q-26qq/GHSA-rj7g-769q-26qq.json b/advisories/unreviewed/2024/08/GHSA-rj7g-769q-26qq/GHSA-rj7g-769q-26qq.json new file mode 100644 index 00000000000..edd85b44062 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rj7g-769q-26qq/GHSA-rj7g-769q-26qq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj7g-769q-26qq", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38151" + ], + "details": "Windows Kernel Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38151" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rjjr-f65p-jqf6/GHSA-rjjr-f65p-jqf6.json b/advisories/unreviewed/2024/08/GHSA-rjjr-f65p-jqf6/GHSA-rjjr-f65p-jqf6.json new file mode 100644 index 00000000000..0730e2a5d51 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rjjr-f65p-jqf6/GHSA-rjjr-f65p-jqf6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjjr-f65p-jqf6", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38108" + ], + "details": "Azure Stack Hub Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38108" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rqvv-44x7-36x7/GHSA-rqvv-44x7-36x7.json b/advisories/unreviewed/2024/08/GHSA-rqvv-44x7-36x7/GHSA-rqvv-44x7-36x7.json new file mode 100644 index 00000000000..0282f9a108a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rqvv-44x7-36x7/GHSA-rqvv-44x7-36x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqvv-44x7-36x7", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38184" + ], + "details": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38184" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rrm7-wvpj-4rg7/GHSA-rrm7-wvpj-4rg7.json b/advisories/unreviewed/2024/08/GHSA-rrm7-wvpj-4rg7/GHSA-rrm7-wvpj-4rg7.json new file mode 100644 index 00000000000..aa61656c011 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rrm7-wvpj-4rg7/GHSA-rrm7-wvpj-4rg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrm7-wvpj-4rg7", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38140" + ], + "details": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38140" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38140" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rrq6-gq4w-89r8/GHSA-rrq6-gq4w-89r8.json b/advisories/unreviewed/2024/08/GHSA-rrq6-gq4w-89r8/GHSA-rrq6-gq4w-89r8.json new file mode 100644 index 00000000000..4198afc93d2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rrq6-gq4w-89r8/GHSA-rrq6-gq4w-89r8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrq6-gq4w-89r8", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-38106" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38106" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38106" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v43q-xfhp-f928/GHSA-v43q-xfhp-f928.json b/advisories/unreviewed/2024/08/GHSA-v43q-xfhp-f928/GHSA-v43q-xfhp-f928.json new file mode 100644 index 00000000000..11c57a9ff11 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v43q-xfhp-f928/GHSA-v43q-xfhp-f928.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v43q-xfhp-f928", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38198" + ], + "details": "Windows Print Spooler Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38198" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38198" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v44f-qppf-2r26/GHSA-v44f-qppf-2r26.json b/advisories/unreviewed/2024/08/GHSA-v44f-qppf-2r26/GHSA-v44f-qppf-2r26.json new file mode 100644 index 00000000000..f56292bb253 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v44f-qppf-2r26/GHSA-v44f-qppf-2r26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v44f-qppf-2r26", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38201" + ], + "details": "Azure Stack Hub Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38201" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38201" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json b/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json new file mode 100644 index 00000000000..f73b1ce9476 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v68h-j2w8-x6w3/GHSA-v68h-j2w8-x6w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v68h-j2w8-x6w3", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38211" + ], + "details": "Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38211" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json b/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json new file mode 100644 index 00000000000..986f408bd31 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v8c4-4ghf-7jv6/GHSA-v8c4-4ghf-7jv6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8c4-4ghf-7jv6", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20591" + ], + "details": "Improper re-initialization of IOMMU during the DRTM event\nmay permit an untrusted platform configuration to persist, allowing an attacker\nto read or modify hypervisor memory, potentially resulting in loss of\nconfidentiality, integrity, and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20591" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vh2g-wrh9-fr5p/GHSA-vh2g-wrh9-fr5p.json b/advisories/unreviewed/2024/08/GHSA-vh2g-wrh9-fr5p/GHSA-vh2g-wrh9-fr5p.json new file mode 100644 index 00000000000..e2fcb143721 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vh2g-wrh9-fr5p/GHSA-vh2g-wrh9-fr5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh2g-wrh9-fr5p", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38195" + ], + "details": "Azure CycleCloud Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38195" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38195" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vh8c-cg35-v939/GHSA-vh8c-cg35-v939.json b/advisories/unreviewed/2024/08/GHSA-vh8c-cg35-v939/GHSA-vh8c-cg35-v939.json new file mode 100644 index 00000000000..8376a3d928d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vh8c-cg35-v939/GHSA-vh8c-cg35-v939.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh8c-cg35-v939", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38223" + ], + "details": "Windows Initial Machine Configuration Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38223" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vmmg-w7g6-pm76/GHSA-vmmg-w7g6-pm76.json b/advisories/unreviewed/2024/08/GHSA-vmmg-w7g6-pm76/GHSA-vmmg-w7g6-pm76.json new file mode 100644 index 00000000000..44887522755 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vmmg-w7g6-pm76/GHSA-vmmg-w7g6-pm76.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmmg-w7g6-pm76", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38142" + ], + "details": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38142" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38142" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vqrw-hxh7-7p37/GHSA-vqrw-hxh7-7p37.json b/advisories/unreviewed/2024/08/GHSA-vqrw-hxh7-7p37/GHSA-vqrw-hxh7-7p37.json index 37a51fae564..e12b55eced8 100644 --- a/advisories/unreviewed/2024/08/GHSA-vqrw-hxh7-7p37/GHSA-vqrw-hxh7-7p37.json +++ b/advisories/unreviewed/2024/08/GHSA-vqrw-hxh7-7p37/GHSA-vqrw-hxh7-7p37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqrw-hxh7-7p37", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42747" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vwgp-x7mv-2x77/GHSA-vwgp-x7mv-2x77.json b/advisories/unreviewed/2024/08/GHSA-vwgp-x7mv-2x77/GHSA-vwgp-x7mv-2x77.json new file mode 100644 index 00000000000..3b53226a246 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vwgp-x7mv-2x77/GHSA-vwgp-x7mv-2x77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwgp-x7mv-2x77", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38178" + ], + "details": "Scripting Engine Memory Corruption Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38178" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vxmf-93xr-m54g/GHSA-vxmf-93xr-m54g.json b/advisories/unreviewed/2024/08/GHSA-vxmf-93xr-m54g/GHSA-vxmf-93xr-m54g.json new file mode 100644 index 00000000000..0a6e08fc76f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vxmf-93xr-m54g/GHSA-vxmf-93xr-m54g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxmf-93xr-m54g", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-38063" + ], + "details": "Windows TCP/IP Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38063" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w27q-896q-p423/GHSA-w27q-896q-p423.json b/advisories/unreviewed/2024/08/GHSA-w27q-896q-p423/GHSA-w27q-896q-p423.json new file mode 100644 index 00000000000..77705b71dfd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w27q-896q-p423/GHSA-w27q-896q-p423.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w27q-896q-p423", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38134" + ], + "details": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38134" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38134" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json b/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json index 38b94ff2d5c..c6c872acd15 100644 --- a/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json +++ b/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w287-4mr4-4v3v", - "modified": "2024-08-12T21:31:34Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:34Z", "aliases": [ "CVE-2024-41710" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.mitel.com/support/security-advisories" + }, + { + "type": "WEB", + "url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0019" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-w45g-x7x3-468c/GHSA-w45g-x7x3-468c.json b/advisories/unreviewed/2024/08/GHSA-w45g-x7x3-468c/GHSA-w45g-x7x3-468c.json new file mode 100644 index 00000000000..17f3b58398e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w45g-x7x3-468c/GHSA-w45g-x7x3-468c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w45g-x7x3-468c", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38125" + ], + "details": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38125" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-197" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json b/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json new file mode 100644 index 00000000000..054aa21d4b8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4h5-9mg2-vv6r", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-7746" + ], + "details": "Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication mechanism. \nThese transactions could have an impact on any sensitive aspect of the platform, including Confidentiality, Integrity and Availability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7746" + }, + { + "type": "WEB", + "url": "https://asrg.io/security-advisories/cve-2024-7746" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w84h-6p5r-5496/GHSA-w84h-6p5r-5496.json b/advisories/unreviewed/2024/08/GHSA-w84h-6p5r-5496/GHSA-w84h-6p5r-5496.json new file mode 100644 index 00000000000..f9f3e5cfc7c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w84h-6p5r-5496/GHSA-w84h-6p5r-5496.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w84h-6p5r-5496", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38215" + ], + "details": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38215" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38215" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w8m3-f759-q5hc/GHSA-w8m3-f759-q5hc.json b/advisories/unreviewed/2024/08/GHSA-w8m3-f759-q5hc/GHSA-w8m3-f759-q5hc.json new file mode 100644 index 00000000000..747bb9fe110 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w8m3-f759-q5hc/GHSA-w8m3-f759-q5hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8m3-f759-q5hc", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38189" + ], + "details": "Microsoft Project Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38189" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w8q7-xr64-p378/GHSA-w8q7-xr64-p378.json b/advisories/unreviewed/2024/08/GHSA-w8q7-xr64-p378/GHSA-w8q7-xr64-p378.json index 46c67427461..13243c4c1b9 100644 --- a/advisories/unreviewed/2024/08/GHSA-w8q7-xr64-p378/GHSA-w8q7-xr64-p378.json +++ b/advisories/unreviewed/2024/08/GHSA-w8q7-xr64-p378/GHSA-w8q7-xr64-p378.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8q7-xr64-p378", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42744" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenicated Attackers can send malicious packet to execute arbitary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json b/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json new file mode 100644 index 00000000000..a0b45cd9bad --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w9fr-xv2x-w94q/GHSA-w9fr-xv2x-w94q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9fr-xv2x-w94q", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38136" + ], + "details": "Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38136" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38136" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wpph-cwvv-gcmq/GHSA-wpph-cwvv-gcmq.json b/advisories/unreviewed/2024/08/GHSA-wpph-cwvv-gcmq/GHSA-wpph-cwvv-gcmq.json new file mode 100644 index 00000000000..ed21e783e10 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wpph-cwvv-gcmq/GHSA-wpph-cwvv-gcmq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpph-cwvv-gcmq", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38122" + ], + "details": "Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38122" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json b/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json new file mode 100644 index 00000000000..a9c3d8bc96a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrqr-6727-v5vq", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2024-41614" + ], + "details": "symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41614" + }, + { + "type": "WEB", + "url": "https://github.com/OoLs5/VulDiscovery/blob/main/Symphony_CMS_XSS.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wx8v-rvwg-8393/GHSA-wx8v-rvwg-8393.json b/advisories/unreviewed/2024/08/GHSA-wx8v-rvwg-8393/GHSA-wx8v-rvwg-8393.json index a52671953f3..1f950014c0f 100644 --- a/advisories/unreviewed/2024/08/GHSA-wx8v-rvwg-8393/GHSA-wx8v-rvwg-8393.json +++ b/advisories/unreviewed/2024/08/GHSA-wx8v-rvwg-8393/GHSA-wx8v-rvwg-8393.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx8v-rvwg-8393", - "modified": "2024-08-12T21:31:35Z", + "modified": "2024-08-13T18:31:14Z", "published": "2024-08-12T21:31:35Z", "aliases": [ "CVE-2024-42745" ], "details": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenicated Attackers can send malicious packet to execute arbitary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78", + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json b/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json index 8d5c6b88555..bb98fd8698e 100644 --- a/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json +++ b/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-843" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-x68w-gq35-jr9h/GHSA-x68w-gq35-jr9h.json b/advisories/unreviewed/2024/08/GHSA-x68w-gq35-jr9h/GHSA-x68w-gq35-jr9h.json new file mode 100644 index 00000000000..251faaaaca2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x68w-gq35-jr9h/GHSA-x68w-gq35-jr9h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x68w-gq35-jr9h", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38128" + ], + "details": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38128" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38128" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x6j5-wvpj-p4qv/GHSA-x6j5-wvpj-p4qv.json b/advisories/unreviewed/2024/08/GHSA-x6j5-wvpj-p4qv/GHSA-x6j5-wvpj-p4qv.json new file mode 100644 index 00000000000..4d08f764227 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6j5-wvpj-p4qv/GHSA-x6j5-wvpj-p4qv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6j5-wvpj-p4qv", + "modified": "2024-08-13T18:31:17Z", + "published": "2024-08-13T18:31:17Z", + "aliases": [ + "CVE-2024-38213" + ], + "details": "Windows Mark of the Web Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38213" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xhjv-p3gv-382p/GHSA-xhjv-p3gv-382p.json b/advisories/unreviewed/2024/08/GHSA-xhjv-p3gv-382p/GHSA-xhjv-p3gv-382p.json new file mode 100644 index 00000000000..093ba9344c2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xhjv-p3gv-382p/GHSA-xhjv-p3gv-382p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhjv-p3gv-382p", + "modified": "2024-08-13T18:31:16Z", + "published": "2024-08-13T18:31:16Z", + "aliases": [ + "CVE-2024-38170" + ], + "details": "Microsoft Excel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38170" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38170" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xjg4-fwj3-xr89/GHSA-xjg4-fwj3-xr89.json b/advisories/unreviewed/2024/08/GHSA-xjg4-fwj3-xr89/GHSA-xjg4-fwj3-xr89.json new file mode 100644 index 00000000000..5ca9d97dd21 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xjg4-fwj3-xr89/GHSA-xjg4-fwj3-xr89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjg4-fwj3-xr89", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-20510" + ], + "details": "An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20510" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json b/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json new file mode 100644 index 00000000000..7c790ce0ecb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqmq-3744-539p", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2021-46746" + ], + "details": "Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing\nkeys to c006Frrupt the return address, causing a\nstack-based buffer overrun, potentially leading to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46746" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xqmw-9249-4m7x/GHSA-xqmw-9249-4m7x.json b/advisories/unreviewed/2024/08/GHSA-xqmw-9249-4m7x/GHSA-xqmw-9249-4m7x.json new file mode 100644 index 00000000000..8e42946ea4a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xqmw-9249-4m7x/GHSA-xqmw-9249-4m7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqmw-9249-4m7x", + "modified": "2024-08-13T18:31:15Z", + "published": "2024-08-13T18:31:15Z", + "aliases": [ + "CVE-2023-31339" + ], + "details": "Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31339" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T17:15:20Z" + } +} \ No newline at end of file