diff --git a/advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json b/advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json new file mode 100644 index 00000000000..38ca0045e12 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-23f9-rm56-9hw4/GHSA-23f9-rm56-9hw4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23f9-rm56-9hw4", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8328" + ], + "details": "Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8328" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8033-0a98f-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8028-360e1-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json b/advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json new file mode 100644 index 00000000000..9e7190ed239 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2cvv-v79w-fm34/GHSA-2cvv-v79w-fm34.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cvv-v79w-fm34", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8329" + ], + "details": "6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8329" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json new file mode 100644 index 00000000000..060705b8e3c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4hvh-m426-wv8w/GHSA-4hvh-m426-wv8w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hvh-m426-wv8w", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45490" + ], + "details": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45490" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/issues/887" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/890" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json b/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json new file mode 100644 index 00000000000..2f8eaeb3ff0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qxm-qvmj-8v79", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45492" + ], + "details": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45492" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/issues/889" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/892" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json b/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json new file mode 100644 index 00000000000..e09c795df25 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-784x-7qm2-gp97", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45491" + ], + "details": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45491" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/issues/888" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/891" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json b/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json new file mode 100644 index 00000000000..3a0441bc002 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c2jm-97rm-g3c3/GHSA-c2jm-97rm-g3c3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2jm-97rm-g3c3", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-45488" + ], + "details": "One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45488" + }, + { + "type": "WEB", + "url": "https://support.oneidentity.com/kb/4376740/safeguard-for-privileged-passwords-security-vulnerability-notification-defect-460620" + }, + { + "type": "WEB", + "url": "https://support.oneidentity.com/product-notification/noti-00001628" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T02:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json b/advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json new file mode 100644 index 00000000000..6bb9395769c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h3rg-qv35-27xm/GHSA-h3rg-qv35-27xm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3rg-qv35-27xm", + "modified": "2024-08-30T03:30:45Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8330" + ], + "details": "6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8330" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8035-53926-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8031-a2f21-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json b/advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json new file mode 100644 index 00000000000..62c739c2519 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qpw3-95cg-p883/GHSA-qpw3-95cg-p883.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpw3-95cg-p883", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8327" + ], + "details": "Easy test\n\nOnline Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8327" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8032-a3d5c-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8028-360e1-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json b/advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json new file mode 100644 index 00000000000..21ac0db8012 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wfxq-5cv4-254v/GHSA-wfxq-5cv4-254v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfxq-5cv4-254v", + "modified": "2024-08-30T03:30:44Z", + "published": "2024-08-30T03:30:44Z", + "aliases": [ + "CVE-2024-8234" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8234" + }, + { + "type": "WEB", + "url": "https://github.com/GroundCTL2MajorTom/pocs/blob/main/zyxel_NWAW1100-N_rce.md" + }, + { + "type": "WEB", + "url": "https://webservice.zyxel.com/eol/ArchivedEOLModel.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T01:15:03Z" + } +} \ No newline at end of file