diff --git a/advisories/unreviewed/2022/05/GHSA-2hx5-63mq-crfj/GHSA-2hx5-63mq-crfj.json b/advisories/unreviewed/2022/05/GHSA-2hx5-63mq-crfj/GHSA-2hx5-63mq-crfj.json index 8eeb227f12b..984eed6bad6 100644 --- a/advisories/unreviewed/2022/05/GHSA-2hx5-63mq-crfj/GHSA-2hx5-63mq-crfj.json +++ b/advisories/unreviewed/2022/05/GHSA-2hx5-63mq-crfj/GHSA-2hx5-63mq-crfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hx5-63mq-crfj", - "modified": "2022-05-13T01:11:30Z", + "modified": "2024-12-20T06:30:44Z", "published": "2022-05-13T01:11:30Z", "aliases": [ "CVE-2014-6287" diff --git a/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json b/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json index 6e6ba3bce17..49cf5d87787 100644 --- a/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json +++ b/advisories/unreviewed/2022/05/GHSA-3hj2-5cwp-2349/GHSA-3hj2-5cwp-2349.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3hj2-5cwp-2349", - "modified": "2022-05-17T01:59:36Z", + "modified": "2024-12-20T06:30:44Z", "published": "2022-05-17T01:59:36Z", "aliases": [ "CVE-2011-1823" ], "details": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -18,14 +23,26 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67977" }, + { + "type": "WEB", + "url": "http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6" + }, { "type": "WEB", "url": "http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6" }, + { + "type": "WEB", + "url": "http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f" + }, { "type": "WEB", "url": "http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f" }, + { + "type": "WEB", + "url": "http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e" + }, { "type": "WEB", "url": "http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e" @@ -52,7 +69,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-7p8v-5r94-xc7r/GHSA-7p8v-5r94-xc7r.json b/advisories/unreviewed/2022/05/GHSA-7p8v-5r94-xc7r/GHSA-7p8v-5r94-xc7r.json index c6313d25a59..d62e80b3e28 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p8v-5r94-xc7r/GHSA-7p8v-5r94-xc7r.json +++ b/advisories/unreviewed/2022/05/GHSA-7p8v-5r94-xc7r/GHSA-7p8v-5r94-xc7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p8v-5r94-xc7r", - "modified": "2022-05-17T01:18:31Z", + "modified": "2024-12-20T06:30:45Z", "published": "2022-05-17T01:18:31Z", "aliases": [ "CVE-2013-6282" diff --git a/advisories/unreviewed/2022/05/GHSA-9pqv-9r37-hxh7/GHSA-9pqv-9r37-hxh7.json b/advisories/unreviewed/2022/05/GHSA-9pqv-9r37-hxh7/GHSA-9pqv-9r37-hxh7.json index 85a3dcd835e..3acac547708 100644 --- a/advisories/unreviewed/2022/05/GHSA-9pqv-9r37-hxh7/GHSA-9pqv-9r37-hxh7.json +++ b/advisories/unreviewed/2022/05/GHSA-9pqv-9r37-hxh7/GHSA-9pqv-9r37-hxh7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pqv-9r37-hxh7", - "modified": "2022-05-14T02:33:57Z", + "modified": "2024-12-20T06:30:45Z", "published": "2022-05-14T02:33:57Z", "aliases": [ "CVE-2013-3163" ], "details": "Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2013-3144 and CVE-2013-3151.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-fprc-fr29-2qmp/GHSA-fprc-fr29-2qmp.json b/advisories/unreviewed/2022/05/GHSA-fprc-fr29-2qmp/GHSA-fprc-fr29-2qmp.json index 1a53ac9d8ce..a212d5fd597 100644 --- a/advisories/unreviewed/2022/05/GHSA-fprc-fr29-2qmp/GHSA-fprc-fr29-2qmp.json +++ b/advisories/unreviewed/2022/05/GHSA-fprc-fr29-2qmp/GHSA-fprc-fr29-2qmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fprc-fr29-2qmp", - "modified": "2022-05-14T01:03:39Z", + "modified": "2024-12-20T06:30:44Z", "published": "2022-05-14T01:03:39Z", "aliases": [ "CVE-2013-7331" diff --git a/advisories/unreviewed/2022/05/GHSA-h8gm-f3pp-ppg9/GHSA-h8gm-f3pp-ppg9.json b/advisories/unreviewed/2022/05/GHSA-h8gm-f3pp-ppg9/GHSA-h8gm-f3pp-ppg9.json index 83c5087313c..03d72089285 100644 --- a/advisories/unreviewed/2022/05/GHSA-h8gm-f3pp-ppg9/GHSA-h8gm-f3pp-ppg9.json +++ b/advisories/unreviewed/2022/05/GHSA-h8gm-f3pp-ppg9/GHSA-h8gm-f3pp-ppg9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h8gm-f3pp-ppg9", - "modified": "2022-05-14T02:34:41Z", + "modified": "2024-12-20T06:30:45Z", "published": "2022-05-14T02:34:41Z", "aliases": [ "CVE-2013-1331" ], "details": "Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka \"Office Buffer Overflow Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w64p-pvrc-c5w3/GHSA-w64p-pvrc-c5w3.json b/advisories/unreviewed/2022/05/GHSA-w64p-pvrc-c5w3/GHSA-w64p-pvrc-c5w3.json index 7975bcdc130..c7da4950297 100644 --- a/advisories/unreviewed/2022/05/GHSA-w64p-pvrc-c5w3/GHSA-w64p-pvrc-c5w3.json +++ b/advisories/unreviewed/2022/05/GHSA-w64p-pvrc-c5w3/GHSA-w64p-pvrc-c5w3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w64p-pvrc-c5w3", - "modified": "2022-05-14T01:02:27Z", + "modified": "2024-12-20T06:30:45Z", "published": "2022-05-14T01:02:27Z", "aliases": [ "CVE-2014-6332" diff --git a/advisories/unreviewed/2022/05/GHSA-xg37-4cgv-wc3c/GHSA-xg37-4cgv-wc3c.json b/advisories/unreviewed/2022/05/GHSA-xg37-4cgv-wc3c/GHSA-xg37-4cgv-wc3c.json index 63620ab44af..dbc1533bc4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-xg37-4cgv-wc3c/GHSA-xg37-4cgv-wc3c.json +++ b/advisories/unreviewed/2022/05/GHSA-xg37-4cgv-wc3c/GHSA-xg37-4cgv-wc3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xg37-4cgv-wc3c", - "modified": "2022-05-17T03:13:10Z", + "modified": "2024-12-20T06:30:44Z", "published": "2022-05-17T03:13:10Z", "aliases": [ "CVE-2013-2596" ], "details": "Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -26,6 +31,14 @@ "type": "WEB", "url": "http://forum.xda-developers.com/showthread.php?t=2255491" }, + { + "type": "WEB", + "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b4cbb197c7e7a68dbad0d491242e3ca67420c13e" + }, + { + "type": "WEB", + "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fc9bbca8f650e5f738af8806317c0a041a48ae4a" + }, { "type": "WEB", "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b4cbb197c7e7a68dbad0d491242e3ca67420c13e" @@ -80,7 +93,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json b/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json index ba00c23c1f1..4297a4c3b56 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json +++ b/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvh2-pw6x-f8hh", - "modified": "2022-05-17T00:22:28Z", + "modified": "2024-12-20T06:30:45Z", "published": "2022-05-17T00:22:28Z", "aliases": [ "CVE-2012-4969" diff --git a/advisories/unreviewed/2024/12/GHSA-32vr-62m9-gj5v/GHSA-32vr-62m9-gj5v.json b/advisories/unreviewed/2024/12/GHSA-32vr-62m9-gj5v/GHSA-32vr-62m9-gj5v.json new file mode 100644 index 00000000000..e7a7df7e2e9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-32vr-62m9-gj5v/GHSA-32vr-62m9-gj5v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32vr-62m9-gj5v", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44195" + ], + "details": "A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44195" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3vx3-2qpf-jvhh/GHSA-3vx3-2qpf-jvhh.json b/advisories/unreviewed/2024/12/GHSA-3vx3-2qpf-jvhh/GHSA-3vx3-2qpf-jvhh.json new file mode 100644 index 00000000000..2b20d8cd437 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3vx3-2qpf-jvhh/GHSA-3vx3-2qpf-jvhh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vx3-2qpf-jvhh", + "modified": "2024-12-20T06:30:46Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-11108" + ], + "details": "The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11108" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7790af9d-621b-474c-b28c-c774e2a292bb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T06:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json b/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json new file mode 100644 index 00000000000..64fc2bf001b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-94w9-fcwh-p5jv/GHSA-94w9-fcwh-p5jv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94w9-fcwh-p5jv", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44211" + ], + "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44211" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9qq6-35mf-f783/GHSA-9qq6-35mf-f783.json b/advisories/unreviewed/2024/12/GHSA-9qq6-35mf-f783/GHSA-9qq6-35mf-f783.json new file mode 100644 index 00000000000..cd2661365c9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9qq6-35mf-f783/GHSA-9qq6-35mf-f783.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qq6-35mf-f783", + "modified": "2024-12-20T06:30:46Z", + "published": "2024-12-20T06:30:46Z", + "aliases": [ + "CVE-2024-5955" + ], + "details": "Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5955" + }, + { + "type": "WEB", + "url": "https://thrive.trellix.com/s/article/000014118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T06:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c9f5-29f6-c35w/GHSA-c9f5-29f6-c35w.json b/advisories/unreviewed/2024/12/GHSA-c9f5-29f6-c35w/GHSA-c9f5-29f6-c35w.json new file mode 100644 index 00000000000..072d88fee0e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c9f5-29f6-c35w/GHSA-c9f5-29f6-c35w.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9f5-29f6-c35w", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-21549" + ], + "details": "Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.\n\n**Note:**\n\nThis is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21549" + }, + { + "type": "WEB", + "url": "https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728" + }, + { + "type": "WEB", + "url": "https://github.com/spatie/browsershot/discussions/906" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gfc3-ch46-26gp/GHSA-gfc3-ch46-26gp.json b/advisories/unreviewed/2024/12/GHSA-gfc3-ch46-26gp/GHSA-gfc3-ch46-26gp.json new file mode 100644 index 00000000000..c68ca0a170a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gfc3-ch46-26gp/GHSA-gfc3-ch46-26gp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfc3-ch46-26gp", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44231" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may be able to bypass Login Window during a software update.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44231" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hhqj-wp3p-mcgx/GHSA-hhqj-wp3p-mcgx.json b/advisories/unreviewed/2024/12/GHSA-hhqj-wp3p-mcgx/GHSA-hhqj-wp3p-mcgx.json new file mode 100644 index 00000000000..1002743f63a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hhqj-wp3p-mcgx/GHSA-hhqj-wp3p-mcgx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhqj-wp3p-mcgx", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-10706" + ], + "details": "The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10706" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/01193420-9a4c-4961-93b6-aa2e37e36be1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T06:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hv8c-r4r9-rxwp/GHSA-hv8c-r4r9-rxwp.json b/advisories/unreviewed/2024/12/GHSA-hv8c-r4r9-rxwp/GHSA-hv8c-r4r9-rxwp.json new file mode 100644 index 00000000000..dd0d146cb14 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hv8c-r4r9-rxwp/GHSA-hv8c-r4r9-rxwp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv8c-r4r9-rxwp", + "modified": "2024-12-20T06:30:46Z", + "published": "2024-12-20T06:30:46Z", + "aliases": [ + "CVE-2024-8968" + ], + "details": "The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8968" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cab4d23e-e857-4b2f-b1ca-fbafd37524e0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jcrx-xhx2-r8m2/GHSA-jcrx-xhx2-r8m2.json b/advisories/unreviewed/2024/12/GHSA-jcrx-xhx2-r8m2/GHSA-jcrx-xhx2-r8m2.json new file mode 100644 index 00000000000..0932e2b4030 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jcrx-xhx2-r8m2/GHSA-jcrx-xhx2-r8m2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcrx-xhx2-r8m2", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44298" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44298" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jj4f-734p-h3c3/GHSA-jj4f-734p-h3c3.json b/advisories/unreviewed/2024/12/GHSA-jj4f-734p-h3c3/GHSA-jj4f-734p-h3c3.json new file mode 100644 index 00000000000..7f093c5233a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jj4f-734p-h3c3/GHSA-jj4f-734p-h3c3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj4f-734p-h3c3", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44223" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44223" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m7m7-c2p8-w63c/GHSA-m7m7-c2p8-w63c.json b/advisories/unreviewed/2024/12/GHSA-m7m7-c2p8-w63c/GHSA-m7m7-c2p8-w63c.json new file mode 100644 index 00000000000..e724e47fd0a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m7m7-c2p8-w63c/GHSA-m7m7-c2p8-w63c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7m7-c2p8-w63c", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44293" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44293" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mcx6-f8wc-g68m/GHSA-mcx6-f8wc-g68m.json b/advisories/unreviewed/2024/12/GHSA-mcx6-f8wc-g68m/GHSA-mcx6-f8wc-g68m.json new file mode 100644 index 00000000000..6ad4df00a01 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mcx6-f8wc-g68m/GHSA-mcx6-f8wc-g68m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcx6-f8wc-g68m", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-44292" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44292" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121564" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x99p-qwh9-pfqr/GHSA-x99p-qwh9-pfqr.json b/advisories/unreviewed/2024/12/GHSA-x99p-qwh9-pfqr/GHSA-x99p-qwh9-pfqr.json new file mode 100644 index 00000000000..3d219d412fc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x99p-qwh9-pfqr/GHSA-x99p-qwh9-pfqr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x99p-qwh9-pfqr", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2023-42867" + ], + "details": "This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42867" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120299" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xrq3-j5cq-h7p4/GHSA-xrq3-j5cq-h7p4.json b/advisories/unreviewed/2024/12/GHSA-xrq3-j5cq-h7p4/GHSA-xrq3-j5cq-h7p4.json new file mode 100644 index 00000000000..310d0805095 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xrq3-j5cq-h7p4/GHSA-xrq3-j5cq-h7p4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrq3-j5cq-h7p4", + "modified": "2024-12-20T06:30:45Z", + "published": "2024-12-20T06:30:45Z", + "aliases": [ + "CVE-2024-10555" + ], + "details": "The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10555" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fcc97635-e939-4cb4-9851-6f6ac4f6ad47" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-20T06:15:22Z" + } +} \ No newline at end of file