From a1e13cc2dc7d9c8c0a9e01e98fa8a20269235dbb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 11 Nov 2024 00:32:12 +0000 Subject: [PATCH] Publish Advisories GHSA-295h-f2ff-v3jj GHSA-2v5c-72gh-q5f7 GHSA-7r4m-g29q-qf8v GHSA-gpc7-8xx7-6f36 GHSA-hwrr-qggh-2777 GHSA-jrvf-vccr-mvp6 GHSA-m833-cpj5-q368 GHSA-mvm7-2x9x-6r3g GHSA-pfqm-9375-7qwm GHSA-q46c-j82q-5ggh GHSA-qxhf-m3mr-36x5 GHSA-v9pp-gjxr-78jp GHSA-w9j2-h8vr-446x GHSA-x8m2-f296-h7vh --- .../GHSA-295h-f2ff-v3jj.json | 47 +++++++++++++++ .../GHSA-2v5c-72gh-q5f7.json | 43 ++++++++++++++ .../GHSA-7r4m-g29q-qf8v.json | 39 +++++++++++++ .../GHSA-gpc7-8xx7-6f36.json | 47 +++++++++++++++ .../GHSA-hwrr-qggh-2777.json | 43 ++++++++++++++ .../GHSA-jrvf-vccr-mvp6.json | 47 +++++++++++++++ .../GHSA-m833-cpj5-q368.json | 39 +++++++++++++ .../GHSA-mvm7-2x9x-6r3g.json | 43 ++++++++++++++ .../GHSA-pfqm-9375-7qwm.json | 54 +++++++++++++++++ .../GHSA-q46c-j82q-5ggh.json | 58 +++++++++++++++++++ .../GHSA-qxhf-m3mr-36x5.json | 47 +++++++++++++++ .../GHSA-v9pp-gjxr-78jp.json | 47 +++++++++++++++ .../GHSA-w9j2-h8vr-446x.json | 47 +++++++++++++++ .../GHSA-x8m2-f296-h7vh.json | 51 ++++++++++++++++ 14 files changed, 652 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-295h-f2ff-v3jj/GHSA-295h-f2ff-v3jj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2v5c-72gh-q5f7/GHSA-2v5c-72gh-q5f7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gpc7-8xx7-6f36/GHSA-gpc7-8xx7-6f36.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mvm7-2x9x-6r3g/GHSA-mvm7-2x9x-6r3g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q46c-j82q-5ggh/GHSA-q46c-j82q-5ggh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qxhf-m3mr-36x5/GHSA-qxhf-m3mr-36x5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v9pp-gjxr-78jp/GHSA-v9pp-gjxr-78jp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x8m2-f296-h7vh/GHSA-x8m2-f296-h7vh.json diff --git a/advisories/unreviewed/2024/11/GHSA-295h-f2ff-v3jj/GHSA-295h-f2ff-v3jj.json b/advisories/unreviewed/2024/11/GHSA-295h-f2ff-v3jj/GHSA-295h-f2ff-v3jj.json new file mode 100644 index 00000000000..30b76df7a6b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-295h-f2ff-v3jj/GHSA-295h-f2ff-v3jj.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-295h-f2ff-v3jj", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2020-10368" + ], + "details": "Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a \"Spectra\" attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10368" + }, + { + "type": "WEB", + "url": "https://github.com/RPi-Distro/bluez-firmware/commit/8445a53ce2c51a77472b908a0c8f6f8e1fa5c37a" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2052676" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/fb20/aktuelles_fb20/fb20_neuigkeiten/neuigkeiten_fb20_details_203136.de.jsp" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/seemoo/team_seemoo/jiska_classen/index.en.jsp" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2v5c-72gh-q5f7/GHSA-2v5c-72gh-q5f7.json b/advisories/unreviewed/2024/11/GHSA-2v5c-72gh-q5f7/GHSA-2v5c-72gh-q5f7.json new file mode 100644 index 00000000000..d2566ea9dd5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2v5c-72gh-q5f7/GHSA-2v5c-72gh-q5f7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v5c-72gh-q5f7", + "modified": "2024-11-11T00:30:43Z", + "published": "2024-11-11T00:30:43Z", + "aliases": [ + "CVE-2024-46954" + ], + "details": "An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46954" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707788" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=55f587dd039282316f512e1bea64218fd991f934" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json b/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json new file mode 100644 index 00000000000..0e29a1a1437 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r4m-g29q-qf8v", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2021-41737" + ], + "details": "In Faust 2.23.1, an input file with the lines \"// r visualisation tCst\" and \"//process = +: L: abM-^Q;\" and \"process = route(3333333333333333333,2,1,2,3,1) : *;\" leads to stack consumption.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41737" + }, + { + "type": "WEB", + "url": "https://github.com/grame-cncm/faust/issues/653" + }, + { + "type": "WEB", + "url": "https://github.com/grame-cncm/faust/tree/e682dbeeb7cc0ec9a1fcb6872f53433e454aa233" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gpc7-8xx7-6f36/GHSA-gpc7-8xx7-6f36.json b/advisories/unreviewed/2024/11/GHSA-gpc7-8xx7-6f36/GHSA-gpc7-8xx7-6f36.json new file mode 100644 index 00000000000..114d1b200af --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gpc7-8xx7-6f36/GHSA-gpc7-8xx7-6f36.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpc7-8xx7-6f36", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2020-10367" + ], + "details": "Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a \"Spectra\" attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10367" + }, + { + "type": "WEB", + "url": "https://github.com/RPi-Distro/bluez-firmware/commit/8445a53ce2c51a77472b908a0c8f6f8e1fa5c37a" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2052676" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/fb20/aktuelles_fb20/fb20_neuigkeiten/neuigkeiten_fb20_details_203136.de.jsp" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/seemoo/team_seemoo/jiska_classen/index.en.jsp" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json b/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json new file mode 100644 index 00000000000..9fbe6cbb260 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwrr-qggh-2777", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2023-40457" + ], + "details": "The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is \"evaluating support for RFC 7606 as a future feature\" and believes that \"customers that have chosen to not require or implement RFC 7606 have done so willingly and with knowledge of what is needed to defend against these types of attacks.\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40457" + }, + { + "type": "WEB", + "url": "https://blog.benjojo.co.uk/asset/JgH8G5duO1" + }, + { + "type": "WEB", + "url": "https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling" + }, + { + "type": "WEB", + "url": "https://supportdocs.extremenetworks.com/support/documentation/extremexos-32-5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T00:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json b/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json new file mode 100644 index 00000000000..2b7cdc4627e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrvf-vccr-mvp6", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2024-46956" + ], + "details": "An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46956" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707895" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=f4151f12db32cd3ed26c24327de714bf2c3ed6ca" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html" + }, + { + "type": "WEB", + "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json b/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json new file mode 100644 index 00000000000..70c8daf0ac4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m833-cpj5-q368", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2021-35473" + ], + "details": "An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-35473" + }, + { + "type": "WEB", + "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2549" + }, + { + "type": "WEB", + "url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/tags" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mvm7-2x9x-6r3g/GHSA-mvm7-2x9x-6r3g.json b/advisories/unreviewed/2024/11/GHSA-mvm7-2x9x-6r3g/GHSA-mvm7-2x9x-6r3g.json new file mode 100644 index 00000000000..729fdd65dfb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mvm7-2x9x-6r3g/GHSA-mvm7-2x9x-6r3g.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvm7-2x9x-6r3g", + "modified": "2024-11-11T00:30:43Z", + "published": "2024-11-11T00:30:43Z", + "aliases": [ + "CVE-2024-46952" + ], + "details": "An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46952" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708001" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b1f0827c30f59a2dcbc8a39e42cace7a1de35f7f" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json b/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json new file mode 100644 index 00000000000..3fb9d0d0b86 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfqm-9375-7qwm", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2024-11059" + ], + "details": "A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11059" + }, + { + "type": "WEB", + "url": "https://github.com/Sy0ung-cmd/Cve-report/blob/main/SQLi-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283805" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283805" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.440337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T00:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q46c-j82q-5ggh/GHSA-q46c-j82q-5ggh.json b/advisories/unreviewed/2024/11/GHSA-q46c-j82q-5ggh/GHSA-q46c-j82q-5ggh.json new file mode 100644 index 00000000000..bec2a6eb2e0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q46c-j82q-5ggh/GHSA-q46c-j82q-5ggh.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q46c-j82q-5ggh", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2024-11058" + ], + "details": "A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11058" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_real_estate_ms_sqli.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283804" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283804" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.439683" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxhf-m3mr-36x5/GHSA-qxhf-m3mr-36x5.json b/advisories/unreviewed/2024/11/GHSA-qxhf-m3mr-36x5/GHSA-qxhf-m3mr-36x5.json new file mode 100644 index 00000000000..86813e93e17 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qxhf-m3mr-36x5/GHSA-qxhf-m3mr-36x5.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxhf-m3mr-36x5", + "modified": "2024-11-11T00:30:43Z", + "published": "2024-11-11T00:30:43Z", + "aliases": [ + "CVE-2024-46953" + ], + "details": "An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46953" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707793" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=1f21a45df0fa3abec4cff12951022b192dda3c00" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html" + }, + { + "type": "WEB", + "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v9pp-gjxr-78jp/GHSA-v9pp-gjxr-78jp.json b/advisories/unreviewed/2024/11/GHSA-v9pp-gjxr-78jp/GHSA-v9pp-gjxr-78jp.json new file mode 100644 index 00000000000..e7ee55ae351 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v9pp-gjxr-78jp/GHSA-v9pp-gjxr-78jp.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9pp-gjxr-78jp", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2020-10369" + ], + "details": "Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a \"Spectra\" attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10369" + }, + { + "type": "WEB", + "url": "https://github.com/RPi-Distro/bluez-firmware/commit/8445a53ce2c51a77472b908a0c8f6f8e1fa5c37a" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2052676" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/fb20/aktuelles_fb20/fb20_neuigkeiten/neuigkeiten_fb20_details_203136.de.jsp" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/seemoo/team_seemoo/jiska_classen/index.en.jsp" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json b/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json new file mode 100644 index 00000000000..c7550b2424f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9j2-h8vr-446x", + "modified": "2024-11-11T00:30:43Z", + "published": "2024-11-11T00:30:43Z", + "aliases": [ + "CVE-2024-46955" + ], + "details": "An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46955" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=707990" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=85bd9d2f4b792fe67aef22f1a4117457461b8ba6" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/ghostpdl/blob/master/doc/News.html" + }, + { + "type": "WEB", + "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20243942-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-10T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x8m2-f296-h7vh/GHSA-x8m2-f296-h7vh.json b/advisories/unreviewed/2024/11/GHSA-x8m2-f296-h7vh/GHSA-x8m2-f296-h7vh.json new file mode 100644 index 00000000000..a8542e6fdda --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x8m2-f296-h7vh/GHSA-x8m2-f296-h7vh.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8m2-f296-h7vh", + "modified": "2024-11-11T00:30:44Z", + "published": "2024-11-11T00:30:44Z", + "aliases": [ + "CVE-2020-10370" + ], + "details": "Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a \"Spectra\" attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10370" + }, + { + "type": "WEB", + "url": "https://github.com/RPi-Distro/bluez-firmware/commit/8445a53ce2c51a77472b908a0c8f6f8e1fa5c37a" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2052676" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2020-10370" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/fb20/aktuelles_fb20/fb20_neuigkeiten/neuigkeiten_fb20_details_203136.de.jsp" + }, + { + "type": "WEB", + "url": "https://www.informatik.tu-darmstadt.de/seemoo/team_seemoo/jiska_classen/index.en.jsp" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T00:15:13Z" + } +} \ No newline at end of file