mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cg2v-9v73-ccwp",
|
||||
"modified": "2025-01-02T21:31:39Z",
|
||||
"modified": "2025-03-07T18:30:53Z",
|
||||
"published": "2022-10-04T00:00:25Z",
|
||||
"aliases": [
|
||||
"CVE-2022-41082"
|
||||
@@ -35,6 +35,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://www.secpod.com/blog/microsoft-november-2022-patch-tuesday-patches-65-vulnerabilities-including-6-zero-days"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.vicarius.io/vsociety/posts/cve-2022-41082-microsoft-exchange-server-remote-code-execution-vulnerability-detection-script"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.vicarius.io/vsociety/posts/cve-2022-41082-microsoft-exchange-server-remote-code-execution-vulnerability-mitigation-script"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://packetstormsecurity.com/files/170066/Microsoft-Exchange-ProxyNotShell-Remote-Code-Execution.html"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3xqx-95w6-xjv4",
|
||||
"modified": "2023-03-10T06:30:21Z",
|
||||
"modified": "2025-03-07T18:30:54Z",
|
||||
"published": "2023-03-02T18:30:26Z",
|
||||
"aliases": [
|
||||
"CVE-2022-38734"
|
||||
@@ -25,7 +25,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-400"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-82v2-v4p5-fg34",
|
||||
"modified": "2023-03-13T18:30:41Z",
|
||||
"modified": "2025-03-07T18:30:57Z",
|
||||
"published": "2023-03-06T00:30:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-22424"
|
||||
|
||||
@@ -33,7 +33,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-86xh-6qhg-p6c2",
|
||||
"modified": "2023-03-10T15:30:43Z",
|
||||
"modified": "2025-03-07T18:30:57Z",
|
||||
"published": "2023-03-04T00:30:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-23313"
|
||||
@@ -19,6 +19,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23313"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-%28cve-2023-23313%29"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-(cve-2023-23313)"
|
||||
|
||||
@@ -33,7 +33,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-94"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fr68-cm8v-7vv6",
|
||||
"modified": "2023-03-14T15:30:16Z",
|
||||
"modified": "2025-03-07T18:30:55Z",
|
||||
"published": "2023-03-03T18:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2022-41862"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m789-8jxv-f7m3",
|
||||
"modified": "2023-03-10T15:30:42Z",
|
||||
"modified": "2025-03-07T18:30:56Z",
|
||||
"published": "2023-03-04T00:30:16Z",
|
||||
"aliases": [
|
||||
"CVE-2023-26213"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pcwc-3rj4-gj54",
|
||||
"modified": "2023-03-14T15:30:17Z",
|
||||
"modified": "2025-03-07T18:30:58Z",
|
||||
"published": "2023-03-07T00:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2022-3707"
|
||||
@@ -31,6 +31,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz%40163.com"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz@163.com"
|
||||
|
||||
@@ -34,6 +34,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-276",
|
||||
"CWE-732"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xcc8-3vrq-wjg2",
|
||||
"modified": "2023-03-14T18:30:22Z",
|
||||
"modified": "2025-03-07T18:30:54Z",
|
||||
"published": "2023-03-02T15:30:17Z",
|
||||
"aliases": [
|
||||
"CVE-2023-25358"
|
||||
@@ -23,6 +23,18 @@
|
||||
"type": "WEB",
|
||||
"url": "https://bugs.webkit.org/show_bug.cgi?id=242683"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5OKKVEUQAAGH3NHMX3WHWKRPYU4QFKTQ"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QL5OGMSHRQ26FTYWZUXVNWB2VHOSVXK"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KC7DMUX37BRCLAI4VPQYHDUVEGTNYN5A"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5OKKVEUQAAGH3NHMX3WHWKRPYU4QFKTQ"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-69v8-v8v7-vv42",
|
||||
"modified": "2024-06-27T15:30:38Z",
|
||||
"modified": "2025-03-07T18:30:58Z",
|
||||
"published": "2024-02-12T03:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2024-25739"
|
||||
@@ -35,6 +35,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://web.git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/drivers/mtd/ubi/vtbl.c?h=v6.6.24&id=d1b505c988b7"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.spinics.net/lists/kernel/msg5074816.html"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vxmc-w576-mqxx",
|
||||
"modified": "2025-02-27T15:31:49Z",
|
||||
"modified": "2025-03-07T18:30:58Z",
|
||||
"published": "2024-04-03T18:30:43Z",
|
||||
"aliases": [
|
||||
"CVE-2024-26767"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/0484e05d048b66d01d1f3c1d2306010bb57d8738"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/070fda699dfdce560755379bc428d9edada7a54e"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/71783d1ff65204d69207fd156d4b2eb1d3882375"
|
||||
|
||||
@@ -1,19 +1,28 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8jh7-gcv4-cq6q",
|
||||
"modified": "2024-05-03T06:30:35Z",
|
||||
"modified": "2025-03-07T18:30:58Z",
|
||||
"published": "2024-05-01T06:31:42Z",
|
||||
"aliases": [
|
||||
"CVE-2024-26982"
|
||||
],
|
||||
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: check the inode number is not the invalid value of zero\n\nSyskiller has produced an out of bounds access in fill_meta_index().\n\nThat out of bounds access is ultimately caused because the inode\nhas an inode number with the invalid value of zero, which was not checked.\n\nThe reason this causes the out of bounds access is due to following\nsequence of events:\n\n1. Fill_meta_index() is called to allocate (via empty_meta_index())\n and fill a metadata index. It however suffers a data read error\n and aborts, invalidating the newly returned empty metadata index.\n It does this by setting the inode number of the index to zero,\n which means unused (zero is not a valid inode number).\n\n2. When fill_meta_index() is subsequently called again on another\n read operation, locate_meta_index() returns the previous index\n because it matches the inode number of 0. Because this index\n has been returned it is expected to have been filled, and because\n it hasn't been, an out of bounds access is performed.\n\nThis patch adds a sanity check which checks that the inode number\nis not zero when the inode is created and returns -EINVAL if it is.\n\n[phillip@squashfs.org.uk: whitespace fix]\n Link: https://lkml.kernel.org/r/20240409204723.446925-1-phillip@squashfs.org.uk",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26982"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/5b99dea79650b50909c50aba24fbae00f203f013"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/7def00ebc9f2d6a581ddf46ce4541f84a10680e5"
|
||||
@@ -40,8 +49,10 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"cwe_ids": [
|
||||
"CWE-125"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-05-01T06:15:15Z"
|
||||
|
||||
@@ -29,7 +29,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-352"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -29,7 +29,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-352"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g7g4-7563-37xc",
|
||||
"modified": "2024-09-09T18:30:29Z",
|
||||
"modified": "2025-03-07T18:30:59Z",
|
||||
"published": "2024-07-12T15:31:29Z",
|
||||
"aliases": [
|
||||
"CVE-2024-40973"
|
||||
@@ -27,6 +27,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/53dbe08504442dc7ba4865c09b3bbf5fe849681b"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/eeb62bb4ca22db17f7dfe8fb8472e0442df3d92f"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/f066882293b5ad359e44c4ed24ab1811ffb0b354"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-g477-g2gm-cjmf",
|
||||
"modified": "2024-09-06T18:31:28Z",
|
||||
"modified": "2025-03-07T18:31:00Z",
|
||||
"published": "2024-09-04T21:30:31Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44953"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/3911af778f208e5f49d43ce739332b91e26bc48e"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/a4921b76bc9421d3838e167f6a17ea3112d8fe62"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/f13f1858a28c68b7fc0d72c2008d5c1f80d2e8d5"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-58m7-hfr6-rrx2",
|
||||
"modified": "2024-11-22T21:32:12Z",
|
||||
"modified": "2025-03-07T18:31:00Z",
|
||||
"published": "2024-10-23T06:31:19Z",
|
||||
"aliases": [
|
||||
"CVE-2024-50066"
|
||||
@@ -34,6 +34,14 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://project-zero.issues.chromium.org/issues/371047675"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.vicarius.io/vsociety/posts/cve-2024-50066-kernel-detection-vulnerability"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.vicarius.io/vsociety/posts/cve-2024-50066-kernel-mitigation-vulnerability"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gh27-x7g8-9fv7",
|
||||
"modified": "2024-10-22T18:32:10Z",
|
||||
"modified": "2025-03-07T18:31:00Z",
|
||||
"published": "2024-10-21T15:32:27Z",
|
||||
"aliases": [
|
||||
"CVE-2024-47754"
|
||||
@@ -34,6 +34,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/9be85491619f1953b8a29590ca630be571941ffa"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://git.kernel.org/stable/c/d48890ef8765001caff732ac6ec80a3b2e470215"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user