mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-2hx5-63mq-crfj GHSA-3hj2-5cwp-2349 GHSA-7p8v-5r94-xc7r GHSA-9pqv-9r37-hxh7 GHSA-fprc-fr29-2qmp GHSA-h8gm-f3pp-ppg9 GHSA-w64p-pvrc-c5w3 GHSA-xg37-4cgv-wc3c GHSA-xvh2-pw6x-f8hh GHSA-32vr-62m9-gj5v GHSA-3vx3-2qpf-jvhh GHSA-94w9-fcwh-p5jv GHSA-9qq6-35mf-f783 GHSA-c9f5-29f6-c35w GHSA-gfc3-ch46-26gp GHSA-hhqj-wp3p-mcgx GHSA-hv8c-r4r9-rxwp GHSA-jcrx-xhx2-r8m2 GHSA-jj4f-734p-h3c3 GHSA-m7m7-c2p8-w63c GHSA-mcx6-f8wc-g68m GHSA-x99p-qwh9-pfqr GHSA-xrq3-j5cq-h7p4
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2hx5-63mq-crfj",
|
||||
"modified": "2022-05-13T01:11:30Z",
|
||||
"modified": "2024-12-20T06:30:44Z",
|
||||
"published": "2022-05-13T01:11:30Z",
|
||||
"aliases": [
|
||||
"CVE-2014-6287"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3hj2-5cwp-2349",
|
||||
"modified": "2022-05-17T01:59:36Z",
|
||||
"modified": "2024-12-20T06:30:44Z",
|
||||
"published": "2022-05-17T01:59:36Z",
|
||||
"aliases": [
|
||||
"CVE-2011-1823"
|
||||
],
|
||||
"details": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -18,14 +23,26 @@
|
||||
"type": "WEB",
|
||||
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67977"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e"
|
||||
@@ -52,7 +69,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-190"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7p8v-5r94-xc7r",
|
||||
"modified": "2022-05-17T01:18:31Z",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2022-05-17T01:18:31Z",
|
||||
"aliases": [
|
||||
"CVE-2013-6282"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9pqv-9r37-hxh7",
|
||||
"modified": "2022-05-14T02:33:57Z",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2022-05-14T02:33:57Z",
|
||||
"aliases": [
|
||||
"CVE-2013-3163"
|
||||
],
|
||||
"details": "Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2013-3144 and CVE-2013-3151.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -29,6 +34,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-787",
|
||||
"CWE-94"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-fprc-fr29-2qmp",
|
||||
"modified": "2022-05-14T01:03:39Z",
|
||||
"modified": "2024-12-20T06:30:44Z",
|
||||
"published": "2022-05-14T01:03:39Z",
|
||||
"aliases": [
|
||||
"CVE-2013-7331"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h8gm-f3pp-ppg9",
|
||||
"modified": "2022-05-14T02:34:41Z",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2022-05-14T02:34:41Z",
|
||||
"aliases": [
|
||||
"CVE-2013-1331"
|
||||
],
|
||||
"details": "Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka \"Office Buffer Overflow Vulnerability.\"",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -33,7 +38,8 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-119"
|
||||
"CWE-119",
|
||||
"CWE-120"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-w64p-pvrc-c5w3",
|
||||
"modified": "2022-05-14T01:02:27Z",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2022-05-14T01:02:27Z",
|
||||
"aliases": [
|
||||
"CVE-2014-6332"
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xg37-4cgv-wc3c",
|
||||
"modified": "2022-05-17T03:13:10Z",
|
||||
"modified": "2024-12-20T06:30:44Z",
|
||||
"published": "2022-05-17T03:13:10Z",
|
||||
"aliases": [
|
||||
"CVE-2013-2596"
|
||||
],
|
||||
"details": "Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
@@ -26,6 +31,14 @@
|
||||
"type": "WEB",
|
||||
"url": "http://forum.xda-developers.com/showthread.php?t=2255491"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b4cbb197c7e7a68dbad0d491242e3ca67420c13e"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc9bbca8f650e5f738af8806317c0a041a48ae4a"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b4cbb197c7e7a68dbad0d491242e3ca67420c13e"
|
||||
@@ -80,7 +93,9 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"cwe_ids": [
|
||||
"CWE-190"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xvh2-pw6x-f8hh",
|
||||
"modified": "2022-05-17T00:22:28Z",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2022-05-17T00:22:28Z",
|
||||
"aliases": [
|
||||
"CVE-2012-4969"
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-32vr-62m9-gj5v",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44195"
|
||||
],
|
||||
"details": "A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44195"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/121564"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T04:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-3vx3-2qpf-jvhh",
|
||||
"modified": "2024-12-20T06:30:46Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-11108"
|
||||
],
|
||||
"details": "The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11108"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/7790af9d-621b-474c-b28c-c774e2a292bb"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T06:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-94w9-fcwh-p5jv",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44211"
|
||||
],
|
||||
"details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44211"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/121564"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T04:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9qq6-35mf-f783",
|
||||
"modified": "2024-12-20T06:30:46Z",
|
||||
"published": "2024-12-20T06:30:46Z",
|
||||
"aliases": [
|
||||
"CVE-2024-5955"
|
||||
],
|
||||
"details": "Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5955"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://thrive.trellix.com/s/article/000014118"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T06:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c9f5-29f6-c35w",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-21549"
|
||||
],
|
||||
"details": "Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.\n\n**Note:**\n\nThis is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21549"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/spatie/browsershot/discussions/906"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T05:15:06Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-gfc3-ch46-26gp",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44231"
|
||||
],
|
||||
"details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may be able to bypass Login Window during a software update.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44231"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/121564"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T04:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hhqj-wp3p-mcgx",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-10706"
|
||||
],
|
||||
"details": "The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10706"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/01193420-9a4c-4961-93b6-aa2e37e36be1"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T06:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hv8c-r4r9-rxwp",
|
||||
"modified": "2024-12-20T06:30:46Z",
|
||||
"published": "2024-12-20T06:30:46Z",
|
||||
"aliases": [
|
||||
"CVE-2024-8968"
|
||||
],
|
||||
"details": "The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8968"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/cab4d23e-e857-4b2f-b1ca-fbafd37524e0"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T06:15:23Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jcrx-xhx2-r8m2",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44298"
|
||||
],
|
||||
"details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44298"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/121564"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T04:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jj4f-734p-h3c3",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44223"
|
||||
],
|
||||
"details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44223"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/121564"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T04:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m7m7-c2p8-w63c",
|
||||
"modified": "2024-12-20T06:30:45Z",
|
||||
"published": "2024-12-20T06:30:45Z",
|
||||
"aliases": [
|
||||
"CVE-2024-44293"
|
||||
],
|
||||
"details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44293"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://support.apple.com/en-us/121564"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2024-12-20T04:15:05Z"
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user