Publish Advisories

GHSA-2hx5-63mq-crfj
GHSA-3hj2-5cwp-2349
GHSA-7p8v-5r94-xc7r
GHSA-9pqv-9r37-hxh7
GHSA-fprc-fr29-2qmp
GHSA-h8gm-f3pp-ppg9
GHSA-w64p-pvrc-c5w3
GHSA-xg37-4cgv-wc3c
GHSA-xvh2-pw6x-f8hh
GHSA-32vr-62m9-gj5v
GHSA-3vx3-2qpf-jvhh
GHSA-94w9-fcwh-p5jv
GHSA-9qq6-35mf-f783
GHSA-c9f5-29f6-c35w
GHSA-gfc3-ch46-26gp
GHSA-hhqj-wp3p-mcgx
GHSA-hv8c-r4r9-rxwp
GHSA-jcrx-xhx2-r8m2
GHSA-jj4f-734p-h3c3
GHSA-m7m7-c2p8-w63c
GHSA-mcx6-f8wc-g68m
GHSA-x99p-qwh9-pfqr
GHSA-xrq3-j5cq-h7p4
This commit is contained in:
advisory-database[bot]
2024-12-20 06:32:15 +00:00
parent a45159215a
commit a76386c4ad
23 changed files with 494 additions and 16 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2hx5-63mq-crfj",
"modified": "2022-05-13T01:11:30Z",
"modified": "2024-12-20T06:30:44Z",
"published": "2022-05-13T01:11:30Z",
"aliases": [
"CVE-2014-6287"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hj2-5cwp-2349",
"modified": "2022-05-17T01:59:36Z",
"modified": "2024-12-20T06:30:44Z",
"published": "2022-05-17T01:59:36Z",
"aliases": [
"CVE-2011-1823"
],
"details": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -18,14 +23,26 @@
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67977"
},
{
"type": "WEB",
"url": "http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6"
},
{
"type": "WEB",
"url": "http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6"
},
{
"type": "WEB",
"url": "http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f"
},
{
"type": "WEB",
"url": "http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f"
},
{
"type": "WEB",
"url": "http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e"
},
{
"type": "WEB",
"url": "http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e"
@@ -52,7 +69,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-190"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7p8v-5r94-xc7r",
"modified": "2022-05-17T01:18:31Z",
"modified": "2024-12-20T06:30:45Z",
"published": "2022-05-17T01:18:31Z",
"aliases": [
"CVE-2013-6282"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pqv-9r37-hxh7",
"modified": "2022-05-14T02:33:57Z",
"modified": "2024-12-20T06:30:45Z",
"published": "2022-05-14T02:33:57Z",
"aliases": [
"CVE-2013-3163"
],
"details": "Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2013-3144 and CVE-2013-3151.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -29,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787",
"CWE-94"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fprc-fr29-2qmp",
"modified": "2022-05-14T01:03:39Z",
"modified": "2024-12-20T06:30:44Z",
"published": "2022-05-14T01:03:39Z",
"aliases": [
"CVE-2013-7331"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8gm-f3pp-ppg9",
"modified": "2022-05-14T02:34:41Z",
"modified": "2024-12-20T06:30:45Z",
"published": "2022-05-14T02:34:41Z",
"aliases": [
"CVE-2013-1331"
],
"details": "Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka \"Office Buffer Overflow Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -33,7 +38,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w64p-pvrc-c5w3",
"modified": "2022-05-14T01:02:27Z",
"modified": "2024-12-20T06:30:45Z",
"published": "2022-05-14T01:02:27Z",
"aliases": [
"CVE-2014-6332"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xg37-4cgv-wc3c",
"modified": "2022-05-17T03:13:10Z",
"modified": "2024-12-20T06:30:44Z",
"published": "2022-05-17T03:13:10Z",
"aliases": [
"CVE-2013-2596"
],
"details": "Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -26,6 +31,14 @@
"type": "WEB",
"url": "http://forum.xda-developers.com/showthread.php?t=2255491"
},
{
"type": "WEB",
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b4cbb197c7e7a68dbad0d491242e3ca67420c13e"
},
{
"type": "WEB",
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc9bbca8f650e5f738af8806317c0a041a48ae4a"
},
{
"type": "WEB",
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b4cbb197c7e7a68dbad0d491242e3ca67420c13e"
@@ -80,7 +93,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-190"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvh2-pw6x-f8hh",
"modified": "2022-05-17T00:22:28Z",
"modified": "2024-12-20T06:30:45Z",
"published": "2022-05-17T00:22:28Z",
"aliases": [
"CVE-2012-4969"
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32vr-62m9-gj5v",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-44195"
],
"details": "A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44195"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/121564"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T04:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vx3-2qpf-jvhh",
"modified": "2024-12-20T06:30:46Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-11108"
],
"details": "The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11108"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/7790af9d-621b-474c-b28c-c774e2a292bb"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T06:15:22Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94w9-fcwh-p5jv",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-44211"
],
"details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44211"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/121564"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T04:15:05Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qq6-35mf-f783",
"modified": "2024-12-20T06:30:46Z",
"published": "2024-12-20T06:30:46Z",
"aliases": [
"CVE-2024-5955"
],
"details": "Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5955"
},
{
"type": "WEB",
"url": "https://thrive.trellix.com/s/article/000014118"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T06:15:22Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c9f5-29f6-c35w",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-21549"
],
"details": "Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.\n\n**Note:**\n\nThis is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21549"
},
{
"type": "WEB",
"url": "https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728"
},
{
"type": "WEB",
"url": "https://github.com/spatie/browsershot/discussions/906"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T05:15:06Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfc3-ch46-26gp",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-44231"
],
"details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may be able to bypass Login Window during a software update.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44231"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/121564"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T04:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhqj-wp3p-mcgx",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-10706"
],
"details": "The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10706"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/01193420-9a4c-4961-93b6-aa2e37e36be1"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T06:15:22Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv8c-r4r9-rxwp",
"modified": "2024-12-20T06:30:46Z",
"published": "2024-12-20T06:30:46Z",
"aliases": [
"CVE-2024-8968"
],
"details": "The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8968"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/cab4d23e-e857-4b2f-b1ca-fbafd37524e0"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T06:15:23Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcrx-xhx2-r8m2",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-44298"
],
"details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44298"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/121564"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T04:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj4f-734p-h3c3",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-44223"
],
"details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44223"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/121564"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T04:15:05Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7m7-c2p8-w63c",
"modified": "2024-12-20T06:30:45Z",
"published": "2024-12-20T06:30:45Z",
"aliases": [
"CVE-2024-44293"
],
"details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44293"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/121564"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-20T04:15:05Z"
}
}

Some files were not shown because too many files have changed in this diff Show More