diff --git a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json index b7b1eedd688..a8cccf6f5a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json +++ b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv98-48f2-5vjr", - "modified": "2024-07-16T03:31:00Z", + "modified": "2024-07-29T09:36:13Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2024-26621" @@ -113,6 +113,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/16/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/29/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-gg68-f5h7-f88v/GHSA-gg68-f5h7-f88v.json b/advisories/unreviewed/2024/04/GHSA-gg68-f5h7-f88v/GHSA-gg68-f5h7-f88v.json index 029179b338c..a6ffa20ae22 100644 --- a/advisories/unreviewed/2024/04/GHSA-gg68-f5h7-f88v/GHSA-gg68-f5h7-f88v.json +++ b/advisories/unreviewed/2024/04/GHSA-gg68-f5h7-f88v/GHSA-gg68-f5h7-f88v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gg68-f5h7-f88v", - "modified": "2024-07-03T18:37:12Z", + "modified": "2024-07-29T09:36:13Z", "published": "2024-04-28T15:30:30Z", "aliases": [ "CVE-2022-48666" @@ -25,9 +25,17 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/2e7eb4c1e8af8385de22775bd0be552f59b28c9a" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ce8fad941233e81f2afb5b52a3fcddd3ba8732f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8fe4ce5836e932f5766317cb651c1ff2a4cd0506" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f818708eeeae793e12dc39f8984ed7732048a7d9" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json b/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json index 104a7a7cd25..fe9f49b92fd 100644 --- a/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json +++ b/advisories/unreviewed/2024/06/GHSA-359q-r4g4-7qxp/GHSA-359q-r4g4-7qxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-359q-r4g4-7qxp", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-07-29T09:36:13Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-36484" @@ -18,14 +18,30 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36484" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21c14c556cccd0cb54b71ec5e901e64ba84c7165" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/26afda78cda3da974fd4c287962c169e9462c495" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59801e88c99f7c3f44a4d20af6ba6417aa359b5d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5f9a04a94fd1894d7009055ab8e5832a0242dba3" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e03006548c66b979f4e5e9fc797aac4dad82822" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7de00adc9bd035d861ba4177848ca0bfa5ed1e04" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/87bdc9f6f58b4417362d6932b49b828e319f97dc" diff --git a/advisories/unreviewed/2024/07/GHSA-22mj-9hjg-cp82/GHSA-22mj-9hjg-cp82.json b/advisories/unreviewed/2024/07/GHSA-22mj-9hjg-cp82/GHSA-22mj-9hjg-cp82.json new file mode 100644 index 00000000000..84065bbc469 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-22mj-9hjg-cp82/GHSA-22mj-9hjg-cp82.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22mj-9hjg-cp82", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41090" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntap: add missing verification for short frame\n\nThe cited commit missed to check against the validity of the frame length\nin the tap_get_user_xdp() path, which could cause a corrupted skb to be\nsent downstack. Even before the skb is transmitted, the\ntap_get_user_xdp()-->skb_set_network_header() may assume the size is more\nthan ETH_HLEN. Once transmitted, this could either cause out-of-bound\naccess beyond the actual length, or confuse the underlayer with incorrect\nor inconsistent header length in the skb metadata.\n\nIn the alternative path, tap_get_user() already prohibits short frame which\nhas the length less than Ethernet header size from being transmitted.\n\nThis is to drop any frame shorter than the Ethernet header size just like\nhow tap_get_user() does.\n\nCVE: CVE-2024-41090", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41090" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73d462a38d5f782b7c872fe9ae8393d9ef5483da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7431144b406ae82807eb87d8c98e518475b0450f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8be915fc5ff9a5e296f6538be12ea75a1a93bdea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa6a5704cab861c9b2ae9f475076e1881e87f5aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e1a786b9bbb767fd1c922d424aaa8078cc542309" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5e5e63c506b93b89b01f522b6a7343585f784e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed7f2afdd0e043a397677e597ced0830b83ba0b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee93e6da30377cf2a75e16cd32bb9fcd86a61c46" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json b/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json new file mode 100644 index 00000000000..b8d4e0a19b3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-257h-x72g-4wr7/GHSA-257h-x72g-4wr7.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-257h-x72g-4wr7", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41017" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: don't walk off the end of ealist\n\nAdd a check before visiting the members of ea to\nmake sure each ea stays within the ealist.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41017" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17440dbc66ab98b410514b04987f61deedb86751" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e034f7e563ab723b93a59980e4a1bb33198ece8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6386f1b6a10e5d1ddd03db4ff6dfc55d488852ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e21574195a45fc193555fa40e99fed16565ff7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f91bd0f2941fa36449ce1a15faaa64f840d9746" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0fa70aca54c8643248e89061da23752506ec0d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dbde7bc91093fa9c2410e418b236b70fde044b73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4435f476b9bf059cd9e26a69f5b29c768d00375" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc16776a82e8df97b6c4f9a10ba95aa44cef7ba5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json b/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json new file mode 100644 index 00000000000..7b696786cc3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2hgj-xhjg-6c4p/GHSA-2hgj-xhjg-6c4p.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hgj-xhjg-6c4p", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41019" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Validate ff offset\n\nThis adds sanity checks for ff offset. There is a check\non rt->first_free at first, but walking through by ff\nwithout any check. If the second ff is a large offset.\nWe may encounter an out-of-bound read.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41019" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35652dfa8cc9a8a900ec0f1e0395781f94ffc5f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50c47879650b4c97836a0086632b3a2e300b0f06" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/617cf144c206f98978ec730b17159344fd147cb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ae7265a7b816879fd0203e83b5030d3720bbb7a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/818a257428644b8873e79c44404d8fb6598d4440" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82c94e6a7bd116724738aa67eba6f5fedf3a3319" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index d467b0a1c9e..9b1f2409f83 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-28T21:33:09Z", + "modified": "2024-07-29T09:36:14Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -49,10 +49,6 @@ "type": "WEB", "url": "https://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e19697cad09" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:4312" - }, { "type": "WEB", "url": "https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html" @@ -65,6 +61,10 @@ "type": "WEB", "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010" }, + { + "type": "WEB", + "url": "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html" + }, { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387" @@ -121,6 +121,10 @@ "type": "WEB", "url": "https://www.theregister.com/2024/07/01/regresshion_openssh" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4312" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4340" diff --git a/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json b/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json new file mode 100644 index 00000000000..e85691dd225 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3f49-4398-jj66/GHSA-3f49-4398-jj66.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f49-4398-jj66", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-7187" + ], + "details": "A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been declared as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272608. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7187" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/A3600R/UploadCustomModule.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.378291" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json b/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json new file mode 100644 index 00000000000..020aac7d7de --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-4pmw-7j2g-cfp7/GHSA-4pmw-7j2g-cfp7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmw-7j2g-cfp7", + "modified": "2024-07-29T09:36:16Z", + "published": "2024-07-29T09:36:16Z", + "aliases": [ + "CVE-2024-41143" + ], + "details": "Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41143" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN84326763" + }, + { + "type": "WEB", + "url": "https://www.skyseaclientview.net/news/240729_02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-586j-jm5r-2jfr/GHSA-586j-jm5r-2jfr.json b/advisories/unreviewed/2024/07/GHSA-586j-jm5r-2jfr/GHSA-586j-jm5r-2jfr.json new file mode 100644 index 00000000000..1e2f7e5d2cb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-586j-jm5r-2jfr/GHSA-586j-jm5r-2jfr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-586j-jm5r-2jfr", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41018" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Add a check for attr_names and oatbl\n\nAdded out-of-bound checking for *ane (ATTR_NAME_ENTRY).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41018" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/702d4930eb06dcfda85a2fa67e8a1a27bfa2a845" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b71f820f7168f1eab8378c80c7ea8a022a475bc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c114d2b88f8b226d4b2acf5a1ba0412cde6c31dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3124d51e4e7b56a732419d8dc270e807252334f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json b/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json index ae74a71662f..a4e0a1993b3 100644 --- a/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json +++ b/advisories/unreviewed/2024/07/GHSA-c77m-wh63-vhch/GHSA-c77m-wh63-vhch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c77m-wh63-vhch", - "modified": "2024-07-25T09:30:51Z", + "modified": "2024-07-29T09:36:14Z", "published": "2024-07-23T09:30:39Z", "aliases": [ "CVE-2024-41012" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3cad1bc010416c6dd780643476bc59ed742436b9" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52c87ab18c76c14d7209646ccb3283b3f5d87b22" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5661b9c7ec189406c2dde00837aaa4672efb6240" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5f5d0799eb0a01d550c21b7894e26b2d9db55763" @@ -30,6 +38,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/b6d223942c34057fdfd8f149e763fa823731b224" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d30ff33040834c3b9eee29740acd92f9c7ba2250" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc2ce1dfceaa0767211a9d963ddb029ab21c4235" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/ef8fc41cd6f95f9a4a3470f085aecf350569a0b3" diff --git a/advisories/unreviewed/2024/07/GHSA-gf92-cf44-4238/GHSA-gf92-cf44-4238.json b/advisories/unreviewed/2024/07/GHSA-gf92-cf44-4238/GHSA-gf92-cf44-4238.json new file mode 100644 index 00000000000..f61a8f3edec --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gf92-cf44-4238/GHSA-gf92-cf44-4238.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf92-cf44-4238", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41015" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: add bounds checking to ocfs2_check_dir_entry()\n\nThis adds sanity checks for ocfs2_dir_entry to make sure all members of\nocfs2_dir_entry don't stray beyond valid memory region.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41015" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13d38c00df97289e6fba2e54193959293fd910d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/255547c6bb8940a97eea94ef9d464ea5967763fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53de17ad01cb5f6f8426f597e9d5c87d4cf53bb7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/564d23cc5b216211e1694d53f7e45959396874d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/624b380074f0dc209fb8706db3295c735079f34c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/77495e5da5cb110a8fed27b052c77853fe282176" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e05a24289db90f76ff606086aadd62d068a88dcd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/edb2e67dd4626b06fd7eb37252d5067912e78d59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd65685594ee707cbf3ddf22ebb73697786ac114" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h9p7-fwj5-r8x6/GHSA-h9p7-fwj5-r8x6.json b/advisories/unreviewed/2024/07/GHSA-h9p7-fwj5-r8x6/GHSA-h9p7-fwj5-r8x6.json new file mode 100644 index 00000000000..b22a188440e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h9p7-fwj5-r8x6/GHSA-h9p7-fwj5-r8x6.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9p7-fwj5-r8x6", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-7190" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/get_price.php. The manipulation of the argument expenses_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272611.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7190" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE7-4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272611" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.380385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T08:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hggm-7hpq-mwwc/GHSA-hggm-7hpq-mwwc.json b/advisories/unreviewed/2024/07/GHSA-hggm-7hpq-mwwc/GHSA-hggm-7hpq-mwwc.json new file mode 100644 index 00000000000..3fa90b9c453 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hggm-7hpq-mwwc/GHSA-hggm-7hpq-mwwc.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hggm-7hpq-mwwc", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-7189" + ], + "details": "A vulnerability classified as critical has been found in itsourcecode Online Food Ordering System 1.0. Affected is an unknown function of the file editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272610 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7189" + }, + { + "type": "WEB", + "url": "https://github.com/L1OudFd8cl09/CVE/blob/main/25_07_2024_a.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.380209" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T08:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j4gx-xfw8-qq8h/GHSA-j4gx-xfw8-qq8h.json b/advisories/unreviewed/2024/07/GHSA-j4gx-xfw8-qq8h/GHSA-j4gx-xfw8-qq8h.json new file mode 100644 index 00000000000..8b3111fb8dd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j4gx-xfw8-qq8h/GHSA-j4gx-xfw8-qq8h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4gx-xfw8-qq8h", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41139" + ], + "details": "Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41139" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN84326763" + }, + { + "type": "WEB", + "url": "https://www.skyseaclientview.net/news/240729_02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json b/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json new file mode 100644 index 00000000000..b12840bb20d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jfpf-jvq3-6jwv/GHSA-jfpf-jvq3-6jwv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfpf-jvq3-6jwv", + "modified": "2024-07-29T09:36:13Z", + "published": "2024-07-29T09:36:13Z", + "aliases": [ + "CVE-2024-41014" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: add bounds checking to xlog_recover_process_data\n\nThere is a lack of verification of the space occupied by fixed members\nof xlog_op_header in the xlog_recover_process_data.\n\nWe can create a crafted image to trigger an out of bounds read by\nfollowing these steps:\n 1) Mount an image of xfs, and do some file operations to leave records\n 2) Before umounting, copy the image for subsequent steps to simulate\n abnormal exit. Because umount will ensure that tail_blk and\n head_blk are the same, which will result in the inability to enter\n xlog_recover_process_data\n 3) Write a tool to parse and modify the copied image in step 2\n 4) Make the end of the xlog_op_header entries only 1 byte away from\n xlog_rec_header->h_size\n 5) xlog_rec_header->h_num_logops++\n 6) Modify xlog_rec_header->h_crc\n\nFix:\nAdd a check to make sure there is sufficient space to access fixed members\nof xlog_op_header.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41014" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb63435b7c7dc112b1ae1baea5486e0a6e27b196" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jgqv-fjhv-7wxf/GHSA-jgqv-fjhv-7wxf.json b/advisories/unreviewed/2024/07/GHSA-jgqv-fjhv-7wxf/GHSA-jgqv-fjhv-7wxf.json new file mode 100644 index 00000000000..a2f40289405 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jgqv-fjhv-7wxf/GHSA-jgqv-fjhv-7wxf.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgqv-fjhv-7wxf", + "modified": "2024-07-29T09:36:16Z", + "published": "2024-07-29T09:36:16Z", + "aliases": [ + "CVE-2024-7191" + ], + "details": "A vulnerability, which was classified as critical, has been found in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/get_balance.php. The manipulation of the argument student_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272612.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7191" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE7-5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272612" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.380386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T09:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json b/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json new file mode 100644 index 00000000000..225a18078ac --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mr66-qfpc-4h9r/GHSA-mr66-qfpc-4h9r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr66-qfpc-4h9r", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:13Z", + "aliases": [ + "CVE-2024-41013" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't walk off the end of a directory data block\n\nThis adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry\nto make sure don't stray beyond valid memory region. Before patching, the\nloop simply checks that the start offset of the dup and dep is within the\nrange. So in a crafted image, if last entry is xfs_dir2_data_unused, we\ncan change dup->length to dup->length-1 and leave 1 byte of space. In the\nnext traversal, this space will be considered as dup or dep. We may\nencounter an out of bound read when accessing the fixed members.\n\nIn the patch, we make sure that the remaining bytes large enough to hold\nan unused entry before accessing xfs_dir2_data_unused and\nxfs_dir2_data_unused is XFS_DIR2_DATA_ALIGN byte aligned. We also make\nsure that the remaining bytes large enough to hold a dirent with a\nsingle-byte name before accessing xfs_dir2_data_entry.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41013" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c7fcdb6d06cdf8b19b57c17605215b06afa864a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mx68-24xf-9x5q/GHSA-mx68-24xf-9x5q.json b/advisories/unreviewed/2024/07/GHSA-mx68-24xf-9x5q/GHSA-mx68-24xf-9x5q.json new file mode 100644 index 00000000000..046289d8426 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mx68-24xf-9x5q/GHSA-mx68-24xf-9x5q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx68-24xf-9x5q", + "modified": "2024-07-29T09:36:16Z", + "published": "2024-07-29T09:36:16Z", + "aliases": [ + "CVE-2024-41881" + ], + "details": "SDoP versions prior to 1.11 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted XML file, arbitrary code may be executed on the user's environment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41881" + }, + { + "type": "WEB", + "url": "https://github.com/PhilipHazel/SDoP/commit/ff83d851b4b39ff2fd37ab2ab14365649515b023" + }, + { + "type": "WEB", + "url": "https://github.com/PhilipHazel/SDoP" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN16420523" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p862-3xjh-j934/GHSA-p862-3xjh-j934.json b/advisories/unreviewed/2024/07/GHSA-p862-3xjh-j934/GHSA-p862-3xjh-j934.json new file mode 100644 index 00000000000..2475d3fd13d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p862-3xjh-j934/GHSA-p862-3xjh-j934.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p862-3xjh-j934", + "modified": "2024-07-29T09:36:16Z", + "published": "2024-07-29T09:36:16Z", + "aliases": [ + "CVE-2024-7192" + ], + "details": "A vulnerability, which was classified as critical, was found in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/student.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272613 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7192" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE7-6.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272613" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.380387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T09:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json b/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json index db83e8c8205..789b668e34c 100644 --- a/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json +++ b/advisories/unreviewed/2024/07/GHSA-qvfw-rqcg-jh9g/GHSA-qvfw-rqcg-jh9g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvfw-rqcg-jh9g", - "modified": "2024-07-19T15:31:47Z", + "modified": "2024-07-29T09:36:13Z", "published": "2024-07-17T09:30:47Z", "aliases": [ "CVE-2024-41009" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41009" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f98f40eb1ed52af8b81f61901b6c0289ff59de4" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/47416c852f2a04d348ea66ee451cbdcf8119f225" @@ -29,6 +33,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/511804ab701c0503b72eac08217eabfd366ba069" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be35504b959f2749bab280f4671e8df96dcf836f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/cfa1a2329a691ffd991fcf7248a57d752e712881" diff --git a/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json b/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json new file mode 100644 index 00000000000..b61b86b66a0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7gc-73mm-jqxm", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41016" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()\n\nxattr in ocfs2 maybe 'non-indexed', which saved with additional space\nrequested. It's better to check if the memory is out of bound before\nmemcmp, although this possibility mainly comes from crafted poisonous\nimages.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41016" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json b/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json new file mode 100644 index 00000000000..49f2c4b4d84 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v799-6j2c-ph3p/GHSA-v799-6j2c-ph3p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v799-6j2c-ph3p", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-7188" + ], + "details": "A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272609 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7188" + }, + { + "type": "WEB", + "url": "https://github.com/bigb0x/CVEs/blob/main/quicklancer-2-4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272609" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272609" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.378279" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vh6h-g733-6v5h/GHSA-vh6h-g733-6v5h.json b/advisories/unreviewed/2024/07/GHSA-vh6h-g733-6v5h/GHSA-vh6h-g733-6v5h.json new file mode 100644 index 00000000000..b6cb3f6b3b1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vh6h-g733-6v5h/GHSA-vh6h-g733-6v5h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh6h-g733-6v5h", + "modified": "2024-07-29T09:36:16Z", + "published": "2024-07-29T09:36:16Z", + "aliases": [ + "CVE-2024-41726" + ], + "details": "Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user who can log in to the PC where the product's Windows client is installed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41726" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN84326763" + }, + { + "type": "WEB", + "url": "https://www.skyseaclientview.net/news/240729_02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x5q2-qqwh-x9rv/GHSA-x5q2-qqwh-x9rv.json b/advisories/unreviewed/2024/07/GHSA-x5q2-qqwh-x9rv/GHSA-x5q2-qqwh-x9rv.json new file mode 100644 index 00000000000..1bccda5f253 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x5q2-qqwh-x9rv/GHSA-x5q2-qqwh-x9rv.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5q2-qqwh-x9rv", + "modified": "2024-07-29T09:36:14Z", + "published": "2024-07-29T09:36:14Z", + "aliases": [ + "CVE-2024-41091" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntun: add missing verification for short frame\n\nThe cited commit missed to check against the validity of the frame length\nin the tun_xdp_one() path, which could cause a corrupted skb to be sent\ndownstack. Even before the skb is transmitted, the\ntun_xdp_one-->eth_type_trans() may access the Ethernet header although it\ncan be less than ETH_HLEN. Once transmitted, this could either cause\nout-of-bound access beyond the actual length, or confuse the underlayer\nwith incorrect or inconsistent header length in the skb metadata.\n\nIn the alternative path, tun_get_user() already prohibits short frame which\nhas the length less than Ethernet header size from being transmitted for\nIFF_TAP.\n\nThis is to drop any frame shorter than the Ethernet header size just like\nhow tun_get_user() does.\n\nCVE: CVE-2024-41091", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/049584807f1d797fc3078b68035450a9769eb5c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32b0aaba5dbc85816898167d9b5d45a22eae82e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6100e0237204890269e3f934acfc50d35fd6f319" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8418f55302fa1d2eeb73e16e345167e545c598a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5ad89b7d01ed4e66fd04734fc63d6e78536692a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-29T07:15:07Z" + } +} \ No newline at end of file