From a7aaec248ef897ba804f7aa5f2515ec0a6bbc146 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 1 Nov 2024 18:33:16 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cf4p-6r33-8p4m.json | 6 +- .../GHSA-5j9x-rwmq-vjhg.json | 11 ++-- .../GHSA-g5q9-8p2x-frc4.json | 9 ++- .../GHSA-jc2v-m93g-6fw8.json | 9 ++- .../GHSA-mf2m-vhfh-2qjv.json | 9 ++- .../GHSA-rfvx-8c45-w4c7.json | 9 ++- .../GHSA-3vh7-ff9w-cqhq.json | 11 ++-- .../GHSA-6xqq-cq8f-hvfc.json | 9 ++- .../GHSA-9v27-xwh4-23q8.json | 11 ++-- .../GHSA-cfwx-rw48-864r.json | 9 ++- .../GHSA-gwm5-cvp5-fmgc.json | 11 ++-- .../GHSA-h8c2-5xf3-fx2x.json | 11 ++-- .../GHSA-jj48-3v62-2vf9.json | 11 ++-- .../GHSA-jqqf-xwf4-j9pw.json | 11 ++-- .../GHSA-m3gq-f9rc-qmwx.json | 9 ++- .../GHSA-pwc2-x7qx-wmwx.json | 11 ++-- .../GHSA-r9r6-c43w-4hr8.json | 11 ++-- .../GHSA-wq6p-vr95-qw42.json | 11 ++-- .../GHSA-4q8v-gqw7-8xpx.json | 9 ++- .../GHSA-7g5r-fqfh-59j6.json | 9 ++- .../GHSA-8mpx-pv9q-6xpj.json | 11 ++-- .../GHSA-8wqx-m7xx-m8vw.json | 11 ++-- .../GHSA-9rp8-67w7-gf47.json | 9 ++- .../GHSA-9x99-qq28-ff9g.json | 11 ++-- .../GHSA-fr2p-5jh8-4366.json | 11 ++-- .../GHSA-gvxc-64wh-vgv2.json | 9 ++- .../GHSA-hq45-85qj-9w7c.json | 9 ++- .../GHSA-hvc4-mjv4-5mw6.json | 9 ++- .../GHSA-qcgh-63vj-9xp8.json | 9 ++- .../GHSA-w36m-8p9q-xcc9.json | 11 ++-- .../GHSA-wmwr-w663-h5f9.json | 9 ++- .../GHSA-x5w9-633f-fvmj.json | 2 +- .../GHSA-xhpx-f3qp-rwvq.json | 11 ++-- .../GHSA-xpw7-h5wm-8q7v.json | 2 +- .../GHSA-4gxv-hggr-2473.json | 9 ++- .../GHSA-7w57-r874-fx7f.json | 9 ++- .../GHSA-c84w-j8mj-57ch.json | 9 ++- .../GHSA-h8c2-87vw-jwfw.json | 11 ++-- .../GHSA-h9p9-4f35-pxjm.json | 9 ++- .../GHSA-rr8j-q4x4-g24r.json | 9 ++- .../GHSA-vxpv-rv2q-v5r7.json | 11 ++-- .../GHSA-wf38-7v3f-5mjp.json | 9 ++- .../GHSA-427c-cc94-833h.json | 11 ++-- .../GHSA-42m3-r5g5-mfwp.json | 11 ++-- .../GHSA-77rx-fhp5-rj33.json | 9 ++- .../GHSA-h5r4-f5wx-726x.json | 9 ++- .../GHSA-j698-35hc-3jf8.json | 11 ++-- .../GHSA-jghm-p5v7-jx64.json | 9 ++- .../GHSA-qr6m-fxwf-qgc5.json | 11 ++-- .../GHSA-r4g5-x2h5-r8gg.json | 9 ++- .../GHSA-6f25-rhcc-g7hw.json | 9 ++- .../GHSA-22g9-2j29-w93q.json | 11 ++-- .../GHSA-2hgc-9gxp-9fq8.json | 3 +- .../GHSA-3f7c-8v7j-hgxr.json | 11 ++-- .../GHSA-48wg-55fj-pvx6.json | 11 ++-- .../GHSA-4qxh-72x2-v8fc.json | 2 +- .../GHSA-4xwj-gw53-4w3v.json | 9 ++- .../GHSA-55gj-r32f-c39x.json | 3 +- .../GHSA-5xfg-p7qv-vv3x.json | 3 +- .../GHSA-635w-qqhj-gvhx.json | 11 ++-- .../GHSA-643h-952w-33f5.json | 9 ++- .../GHSA-6gp9-mxjv-gqwr.json | 3 +- .../GHSA-6rhp-8rx2-2869.json | 11 ++-- .../GHSA-7368-g948-r7pg.json | 11 ++-- .../GHSA-74p3-prxf-24w8.json | 3 +- .../GHSA-76p7-w946-wvch.json | 11 ++-- .../GHSA-82vq-g77c-v2h9.json | 11 ++-- .../GHSA-8993-6q23-6mm7.json | 3 +- .../GHSA-8pxm-8fqw-jp9p.json | 11 ++-- .../GHSA-93cx-f9gg-q2wg.json | 3 +- .../GHSA-95j2-w8x7-hm88.json | 15 +++-- .../GHSA-cfxq-8762-vx3v.json | 15 +++-- .../GHSA-cpxh-jwhh-m496.json | 15 +++-- .../GHSA-f928-7mj9-m8wx.json | 1 + .../GHSA-fh83-rw64-jhh7.json | 9 ++- .../GHSA-frcc-xjfw-r9vq.json | 3 +- .../GHSA-frcg-5998-rxxh.json | 11 ++-- .../GHSA-ggr3-2w79-8rhj.json | 11 ++-- .../GHSA-gjf9-pfmc-2689.json | 3 +- .../GHSA-gr3v-53cp-cg7h.json | 9 ++- .../GHSA-h3xr-p2v4-jv9v.json | 9 ++- .../GHSA-hjjp-8vgj-3j9q.json | 3 +- .../GHSA-hm8j-9qjw-g376.json | 9 ++- .../GHSA-hxw6-pfp4-6vc8.json | 2 +- .../GHSA-jh2f-6jmr-qxf8.json | 11 ++-- .../GHSA-jrcg-6c8x-ff3h.json | 3 +- .../GHSA-m3gr-45jc-g2rp.json | 9 ++- .../GHSA-m72x-w5r4-mxj9.json | 9 ++- .../GHSA-mvx2-276h-w78v.json | 15 +++-- .../GHSA-pj65-96p4-vhw4.json | 3 +- .../GHSA-pj9f-9jr9-4wm7.json | 1 + .../GHSA-qr43-43pm-fwh2.json | 11 ++-- .../GHSA-rjp6-prx7-2cj4.json | 9 ++- .../GHSA-v93x-fw33-f4pw.json | 3 +- .../GHSA-x22r-xgr5-23hh.json | 6 +- .../GHSA-xr9g-f9v2-9m3h.json | 6 +- .../GHSA-2657-8gwf-j8hg.json | 54 +++++++++++++++++ .../GHSA-3q78-4j93-p8qr.json | 35 +++++++++++ .../GHSA-426m-8vmg-c647.json | 35 +++++++++++ .../GHSA-4c48-48vf-pffv.json | 35 +++++++++++ .../GHSA-4fhq-xw64-436p.json | 35 +++++++++++ .../GHSA-798f-vv9g-f5gg.json | 35 +++++++++++ .../GHSA-7v6m-5xcw-rjqw.json | 38 ++++++++++++ .../GHSA-94gg-72cx-mg6f.json | 35 +++++++++++ .../GHSA-c5hw-25wh-7q5r.json | 35 +++++++++++ .../GHSA-f96w-x82r-jx85.json | 35 +++++++++++ .../GHSA-g38v-wv6x-qc6c.json | 39 +++++++++++++ .../GHSA-hrrg-wvpp-2p2q.json | 39 +++++++++++++ .../GHSA-j6r2-9gj9-jmvp.json | 38 ++++++++++++ .../GHSA-m3v4-qcj6-c3h3.json | 58 +++++++++++++++++++ .../GHSA-m6q8-w66q-7qgr.json | 54 +++++++++++++++++ .../GHSA-mw4g-w7hh-rjpc.json | 38 ++++++++++++ .../GHSA-p4mp-f632-xp5q.json | 39 +++++++++++++ .../GHSA-prm4-7jr7-cm97.json | 39 +++++++++++++ .../GHSA-rcx3-jx8c-54gq.json | 39 +++++++++++++ .../GHSA-rfpm-vfqf-wj57.json | 38 ++++++++++++ .../GHSA-rrg7-hv9c-7q66.json | 35 +++++++++++ .../GHSA-vvmx-2vhq-c359.json | 39 +++++++++++++ .../GHSA-x4vq-mwg4-r55q.json | 39 +++++++++++++ .../GHSA-xfcf-4825-2xx2.json | 35 +++++++++++ .../GHSA-xmg5-8cgx-r6mh.json | 58 +++++++++++++++++++ 121 files changed, 1545 insertions(+), 281 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-2657-8gwf-j8hg/GHSA-2657-8gwf-j8hg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3q78-4j93-p8qr/GHSA-3q78-4j93-p8qr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4c48-48vf-pffv/GHSA-4c48-48vf-pffv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4fhq-xw64-436p/GHSA-4fhq-xw64-436p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-798f-vv9g-f5gg/GHSA-798f-vv9g-f5gg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-94gg-72cx-mg6f/GHSA-94gg-72cx-mg6f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c5hw-25wh-7q5r/GHSA-c5hw-25wh-7q5r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f96w-x82r-jx85/GHSA-f96w-x82r-jx85.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g38v-wv6x-qc6c/GHSA-g38v-wv6x-qc6c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m3v4-qcj6-c3h3/GHSA-m3v4-qcj6-c3h3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m6q8-w66q-7qgr/GHSA-m6q8-w66q-7qgr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mw4g-w7hh-rjpc/GHSA-mw4g-w7hh-rjpc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p4mp-f632-xp5q/GHSA-p4mp-f632-xp5q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-prm4-7jr7-cm97/GHSA-prm4-7jr7-cm97.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xfcf-4825-2xx2/GHSA-xfcf-4825-2xx2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xmg5-8cgx-r6mh/GHSA-xmg5-8cgx-r6mh.json diff --git a/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json b/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json index d9e8d8386b5..fa5a4d79f07 100644 --- a/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json +++ b/advisories/unreviewed/2022/07/GHSA-cf4p-6r33-8p4m/GHSA-cf4p-6r33-8p4m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf4p-6r33-8p4m", - "modified": "2022-08-03T00:00:54Z", + "modified": "2024-11-01T18:31:24Z", "published": "2022-07-27T00:00:32Z", "aliases": [ "CVE-2022-27105" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27105" }, + { + "type": "WEB", + "url": "https://gist.github.com/0xVavaldi/9b7afbfe56938294480f7613805d3b7f" + }, { "type": "WEB", "url": "https://gist.github.com/TheWorkingDeveloper/9b7afbfe56938294480f7613805d3b7f" diff --git a/advisories/unreviewed/2024/02/GHSA-5j9x-rwmq-vjhg/GHSA-5j9x-rwmq-vjhg.json b/advisories/unreviewed/2024/02/GHSA-5j9x-rwmq-vjhg/GHSA-5j9x-rwmq-vjhg.json index 760d31228d7..d797b4ca28c 100644 --- a/advisories/unreviewed/2024/02/GHSA-5j9x-rwmq-vjhg/GHSA-5j9x-rwmq-vjhg.json +++ b/advisories/unreviewed/2024/02/GHSA-5j9x-rwmq-vjhg/GHSA-5j9x-rwmq-vjhg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5j9x-rwmq-vjhg", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2023-40085" ], "details": "In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T19:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json b/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json index 1f237ebbe8a..23d54aedc06 100644 --- a/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json +++ b/advisories/unreviewed/2024/02/GHSA-g5q9-8p2x-frc4/GHSA-g5q9-8p2x-frc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5q9-8p2x-frc4", - "modified": "2024-02-18T09:30:47Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-02-18T09:30:47Z", "aliases": [ "CVE-2023-52380" ], "details": "Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T07:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jc2v-m93g-6fw8/GHSA-jc2v-m93g-6fw8.json b/advisories/unreviewed/2024/02/GHSA-jc2v-m93g-6fw8/GHSA-jc2v-m93g-6fw8.json index 39fe0f618b5..e68bb0e8a8a 100644 --- a/advisories/unreviewed/2024/02/GHSA-jc2v-m93g-6fw8/GHSA-jc2v-m93g-6fw8.json +++ b/advisories/unreviewed/2024/02/GHSA-jc2v-m93g-6fw8/GHSA-jc2v-m93g-6fw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc2v-m93g-6fw8", - "modified": "2024-02-28T09:30:37Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47000" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix inode leak on getattr error in __fh_to_dentry", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json index 707552b0b4d..8f71e6ab3f5 100644 --- a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json +++ b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf2m-vhfh-2qjv", - "modified": "2024-03-04T09:30:29Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1549" ], "details": "If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rfvx-8c45-w4c7/GHSA-rfvx-8c45-w4c7.json b/advisories/unreviewed/2024/02/GHSA-rfvx-8c45-w4c7/GHSA-rfvx-8c45-w4c7.json index fd80c79969e..825bf5bdc07 100644 --- a/advisories/unreviewed/2024/02/GHSA-rfvx-8c45-w4c7/GHSA-rfvx-8c45-w4c7.json +++ b/advisories/unreviewed/2024/02/GHSA-rfvx-8c45-w4c7/GHSA-rfvx-8c45-w4c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfvx-8c45-w4c7", - "modified": "2024-02-27T21:31:27Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46957" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/kprobe: fix kernel panic when invoking sys_read traced by kprobe\n\nThe execution of sys_read end up hitting a BUG_ON() in __find_get_block\nafter installing kprobe at sys_read, the BUG message like the following:\n\n[ 65.708663] ------------[ cut here ]------------\n[ 65.709987] kernel BUG at fs/buffer.c:1251!\n[ 65.711283] Kernel BUG [#1]\n[ 65.712032] Modules linked in:\n[ 65.712925] CPU: 0 PID: 51 Comm: sh Not tainted 5.12.0-rc4 #1\n[ 65.714407] Hardware name: riscv-virtio,qemu (DT)\n[ 65.715696] epc : __find_get_block+0x218/0x2c8\n[ 65.716835] ra : __getblk_gfp+0x1c/0x4a\n[ 65.717831] epc : ffffffe00019f11e ra : ffffffe00019f56a sp : ffffffe002437930\n[ 65.719553] gp : ffffffe000f06030 tp : ffffffe0015abc00 t0 : ffffffe00191e038\n[ 65.721290] t1 : ffffffe00191e038 t2 : 000000000000000a s0 : ffffffe002437960\n[ 65.723051] s1 : ffffffe00160ad00 a0 : ffffffe00160ad00 a1 : 000000000000012a\n[ 65.724772] a2 : 0000000000000400 a3 : 0000000000000008 a4 : 0000000000000040\n[ 65.726545] a5 : 0000000000000000 a6 : ffffffe00191e000 a7 : 0000000000000000\n[ 65.728308] s2 : 000000000000012a s3 : 0000000000000400 s4 : 0000000000000008\n[ 65.730049] s5 : 000000000000006c s6 : ffffffe00240f800 s7 : ffffffe000f080a8\n[ 65.731802] s8 : 0000000000000001 s9 : 000000000000012a s10: 0000000000000008\n[ 65.733516] s11: 0000000000000008 t3 : 00000000000003ff t4 : 000000000000000f\n[ 65.734434] t5 : 00000000000003ff t6 : 0000000000040000\n[ 65.734613] status: 0000000000000100 badaddr: 0000000000000000 cause: 0000000000000003\n[ 65.734901] Call Trace:\n[ 65.735076] [] __find_get_block+0x218/0x2c8\n[ 65.735417] [] __ext4_get_inode_loc+0xb2/0x2f6\n[ 65.735618] [] ext4_get_inode_loc+0x3a/0x8a\n[ 65.735802] [] ext4_reserve_inode_write+0x2e/0x8c\n[ 65.735999] [] __ext4_mark_inode_dirty+0x4c/0x18e\n[ 65.736208] [] ext4_dirty_inode+0x46/0x66\n[ 65.736387] [] __mark_inode_dirty+0x12c/0x3da\n[ 65.736576] [] touch_atime+0x146/0x150\n[ 65.736748] [] filemap_read+0x234/0x246\n[ 65.736920] [] generic_file_read_iter+0xc0/0x114\n[ 65.737114] [] ext4_file_read_iter+0x42/0xea\n[ 65.737310] [] new_sync_read+0xe2/0x15a\n[ 65.737483] [] vfs_read+0xca/0xf2\n[ 65.737641] [] ksys_read+0x5e/0xc8\n[ 65.737816] [] sys_read+0xe/0x16\n[ 65.737973] [] ret_from_syscall+0x0/0x2\n[ 65.738858] ---[ end trace fe93f985456c935d ]---\n\nA simple reproducer looks like:\n\techo 'p:myprobe sys_read fd=%a0 buf=%a1 count=%a2' > /sys/kernel/debug/tracing/kprobe_events\n\techo 1 > /sys/kernel/debug/tracing/events/kprobes/myprobe/enable\n\tcat /sys/kernel/debug/tracing/trace\n\nHere's what happens to hit that BUG_ON():\n\n1) After installing kprobe at entry of sys_read, the first instruction\n is replaced by 'ebreak' instruction on riscv64 platform.\n\n2) Once kernel reach the 'ebreak' instruction at the entry of sys_read,\n it trap into the riscv breakpoint handler, where it do something to\n setup for coming single-step of origin instruction, including backup\n the 'sstatus' in pt_regs, followed by disable interrupt during single\n stepping via clear 'SIE' bit of 'sstatus' in pt_regs.\n\n3) Then kernel restore to the instruction slot contains two instructions,\n one is original instruction at entry of sys_read, the other is 'ebreak'.\n Here it trigger a 'Instruction page fault' exception (value at 'scause'\n is '0xc'), if PF is not filled into PageTabe for that slot yet.\n\n4) Again kernel trap into page fault exception handler, where it choose\n different policy according to the state of running kprobe. Because\n afte 2) the state is KPROBE_HIT_SS, so kernel reset the current kp\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3vh7-ff9w-cqhq/GHSA-3vh7-ff9w-cqhq.json b/advisories/unreviewed/2024/03/GHSA-3vh7-ff9w-cqhq/GHSA-3vh7-ff9w-cqhq.json index 0924d996b6a..cf7a869ea9a 100644 --- a/advisories/unreviewed/2024/03/GHSA-3vh7-ff9w-cqhq/GHSA-3vh7-ff9w-cqhq.json +++ b/advisories/unreviewed/2024/03/GHSA-3vh7-ff9w-cqhq/GHSA-3vh7-ff9w-cqhq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vh7-ff9w-cqhq", - "modified": "2024-03-14T00:31:04Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23201" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -69,9 +72,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6xqq-cq8f-hvfc/GHSA-6xqq-cq8f-hvfc.json b/advisories/unreviewed/2024/03/GHSA-6xqq-cq8f-hvfc/GHSA-6xqq-cq8f-hvfc.json index 5f8272cb800..5dc832f523d 100644 --- a/advisories/unreviewed/2024/03/GHSA-6xqq-cq8f-hvfc/GHSA-6xqq-cq8f-hvfc.json +++ b/advisories/unreviewed/2024/03/GHSA-6xqq-cq8f-hvfc/GHSA-6xqq-cq8f-hvfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xqq-cq8f-hvfc", - "modified": "2024-03-06T09:30:27Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-06T09:30:27Z", "aliases": [ "CVE-2023-52591" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nreiserfs: Avoid touching renamed directory if parent does not change\n\nThe VFS will not be locking moved directory if its parent does not\nchange. Change reiserfs rename code to avoid touching renamed directory\nif its parent does not change as without locking that can corrupt the\nfilesystem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json b/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json index eff2732757d..bbfaa4b8730 100644 --- a/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json +++ b/advisories/unreviewed/2024/03/GHSA-9v27-xwh4-23q8/GHSA-9v27-xwh4-23q8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v27-xwh4-23q8", - "modified": "2024-03-20T15:32:23Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-20T15:32:23Z", "aliases": [ "CVE-2024-28715" ], "details": "Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T21:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cfwx-rw48-864r/GHSA-cfwx-rw48-864r.json b/advisories/unreviewed/2024/03/GHSA-cfwx-rw48-864r/GHSA-cfwx-rw48-864r.json index bf6b49d77e8..e06574496a5 100644 --- a/advisories/unreviewed/2024/03/GHSA-cfwx-rw48-864r/GHSA-cfwx-rw48-864r.json +++ b/advisories/unreviewed/2024/03/GHSA-cfwx-rw48-864r/GHSA-cfwx-rw48-864r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfwx-rw48-864r", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20026" ], "details": "In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541632.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json b/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json index c2bbfb5d15a..e5b0371a4ff 100644 --- a/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json +++ b/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwm5-cvp5-fmgc", - "modified": "2024-03-06T03:30:29Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-06T03:30:29Z", "aliases": [ "CVE-2023-49973" ], "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T01:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json b/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json index a4160235828..823b94e6862 100644 --- a/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json +++ b/advisories/unreviewed/2024/03/GHSA-h8c2-5xf3-fx2x/GHSA-h8c2-5xf3-fx2x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8c2-5xf3-fx2x", - "modified": "2024-03-20T15:32:45Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-20T15:32:45Z", "aliases": [ "CVE-2024-28571" ], "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the fill_input_buffer() function when reading images in JPEG format.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T06:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jj48-3v62-2vf9/GHSA-jj48-3v62-2vf9.json b/advisories/unreviewed/2024/03/GHSA-jj48-3v62-2vf9/GHSA-jj48-3v62-2vf9.json index 11a03030b57..ef81d393008 100644 --- a/advisories/unreviewed/2024/03/GHSA-jj48-3v62-2vf9/GHSA-jj48-3v62-2vf9.json +++ b/advisories/unreviewed/2024/03/GHSA-jj48-3v62-2vf9/GHSA-jj48-3v62-2vf9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jj48-3v62-2vf9", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52576" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm, kexec, ima: Use memblock_free_late() from ima_free_kexec_buffer()\n\nThe code calling ima_free_kexec_buffer() runs long after the memblock\nallocator has already been torn down, potentially resulting in a use\nafter free in memblock_isolate_range().\n\nWith KASAN or KFENCE, this use after free will result in a BUG\nfrom the idle task, and a subsequent kernel panic.\n\nSwitch ima_free_kexec_buffer() over to memblock_free_late() to avoid\nthat bug.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jqqf-xwf4-j9pw/GHSA-jqqf-xwf4-j9pw.json b/advisories/unreviewed/2024/03/GHSA-jqqf-xwf4-j9pw/GHSA-jqqf-xwf4-j9pw.json index 1a389fafa89..75c879ab4c2 100644 --- a/advisories/unreviewed/2024/03/GHSA-jqqf-xwf4-j9pw/GHSA-jqqf-xwf4-j9pw.json +++ b/advisories/unreviewed/2024/03/GHSA-jqqf-xwf4-j9pw/GHSA-jqqf-xwf4-j9pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqqf-xwf4-j9pw", - "modified": "2024-03-13T18:31:34Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-28679" ], "details": "DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T16:15:30Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m3gq-f9rc-qmwx/GHSA-m3gq-f9rc-qmwx.json b/advisories/unreviewed/2024/03/GHSA-m3gq-f9rc-qmwx/GHSA-m3gq-f9rc-qmwx.json index a59339e6d08..ecf9ef10c5d 100644 --- a/advisories/unreviewed/2024/03/GHSA-m3gq-f9rc-qmwx/GHSA-m3gq-f9rc-qmwx.json +++ b/advisories/unreviewed/2024/03/GHSA-m3gq-f9rc-qmwx/GHSA-m3gq-f9rc-qmwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3gq-f9rc-qmwx", - "modified": "2024-03-06T00:31:26Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-1900" ], "details": "Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365. \n\nThe user will stay authenticated until the Devolutions Server token expiration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pwc2-x7qx-wmwx/GHSA-pwc2-x7qx-wmwx.json b/advisories/unreviewed/2024/03/GHSA-pwc2-x7qx-wmwx/GHSA-pwc2-x7qx-wmwx.json index 43ed70be5eb..5a53d94ca6e 100644 --- a/advisories/unreviewed/2024/03/GHSA-pwc2-x7qx-wmwx/GHSA-pwc2-x7qx-wmwx.json +++ b/advisories/unreviewed/2024/03/GHSA-pwc2-x7qx-wmwx/GHSA-pwc2-x7qx-wmwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwc2-x7qx-wmwx", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-03-03T00:30:31Z", "aliases": [ "CVE-2023-52518" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_codec: Fix leaking content of local_codecs\n\nThe following memory leak can be observed when the controller supports\ncodecs which are stored in local_codecs list but the elements are never\nfreed:\n\nunreferenced object 0xffff88800221d840 (size 32):\n comm \"kworker/u3:0\", pid 36, jiffies 4294898739 (age 127.060s)\n hex dump (first 32 bytes):\n f8 d3 02 03 80 88 ff ff 80 d8 21 02 80 88 ff ff ..........!.....\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] __kmalloc+0x47/0x120\n [] hci_codec_list_add.isra.0+0x2d/0x160\n [] hci_read_codec_capabilities+0x183/0x270\n [] hci_read_supported_codecs+0x1bb/0x2d0\n [] hci_read_local_codecs_sync+0x3e/0x60\n [] hci_dev_open_sync+0x943/0x11e0\n [] hci_power_on+0x10d/0x3f0\n [] process_one_work+0x404/0x800\n [] worker_thread+0x374/0x670\n [] kthread+0x188/0x1c0\n [] ret_from_fork+0x2b/0x50\n [] ret_from_fork_asm+0x1a/0x30", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r9r6-c43w-4hr8/GHSA-r9r6-c43w-4hr8.json b/advisories/unreviewed/2024/03/GHSA-r9r6-c43w-4hr8/GHSA-r9r6-c43w-4hr8.json index a2e9e1e6bbb..3f7851f1110 100644 --- a/advisories/unreviewed/2024/03/GHSA-r9r6-c43w-4hr8/GHSA-r9r6-c43w-4hr8.json +++ b/advisories/unreviewed/2024/03/GHSA-r9r6-c43w-4hr8/GHSA-r9r6-c43w-4hr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r9r6-c43w-4hr8", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-11-01T18:31:24Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52529" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: sony: Fix a potential memory leak in sony_probe()\n\nIf an error occurs after a successful usb_alloc_urb() call, usb_free_urb()\nshould be called.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wq6p-vr95-qw42/GHSA-wq6p-vr95-qw42.json b/advisories/unreviewed/2024/03/GHSA-wq6p-vr95-qw42/GHSA-wq6p-vr95-qw42.json index 422e968b432..aebd35940dd 100644 --- a/advisories/unreviewed/2024/03/GHSA-wq6p-vr95-qw42/GHSA-wq6p-vr95-qw42.json +++ b/advisories/unreviewed/2024/03/GHSA-wq6p-vr95-qw42/GHSA-wq6p-vr95-qw42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq6p-vr95-qw42", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20033" ], "details": "In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08499945; Issue ID: ALPS08499945.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json b/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json index 4cf2a124d33..6d7779bdc06 100644 --- a/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json +++ b/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4q8v-gqw7-8xpx", - "modified": "2024-04-04T09:30:35Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26789" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: arm64/neonbs - fix out-of-bounds access on short input\n\nThe bit-sliced implementation of AES-CTR operates on blocks of 128\nbytes, and will fall back to the plain NEON version for tail blocks or\ninputs that are shorter than 128 bytes to begin with.\n\nIt will call straight into the plain NEON asm helper, which performs all\nmemory accesses in granules of 16 bytes (the size of a NEON register).\nFor this reason, the associated plain NEON glue code will copy inputs\nshorter than 16 bytes into a temporary buffer, given that this is a rare\noccurrence and it is not worth the effort to work around this in the asm\ncode.\n\nThe fallback from the bit-sliced NEON version fails to take this into\naccount, potentially resulting in out-of-bounds accesses. So clone the\nsame workaround, and use a temp buffer for short in/outputs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json b/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json index 1fa122e2fab..ee6a0b13688 100644 --- a/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json +++ b/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7g5r-fqfh-59j6", - "modified": "2024-04-04T09:30:36Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-04T09:30:36Z", "aliases": [ "CVE-2024-26799" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: Fix uninitialized pointer dmactl\n\nIn the case where __lpass_get_dmactl_handle is called and the driver\nid dai_id is invalid the pointer dmactl is not being assigned a value,\nand dmactl contains a garbage value since it has not been initialized\nand so the null check may not work. Fix this to initialize dmactl to\nNULL. One could argue that modern compilers will set this to zero, but\nit is useful to keep this initialized as per the same way in functions\n__lpass_platform_codec_intf_init and lpass_cdc_dma_daiops_hw_params.\n\nCleans up clang scan build warning:\nsound/soc/qcom/lpass-cdc-dma.c:275:7: warning: Branch condition\nevaluates to a garbage value [core.uninitialized.Branch]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8mpx-pv9q-6xpj/GHSA-8mpx-pv9q-6xpj.json b/advisories/unreviewed/2024/04/GHSA-8mpx-pv9q-6xpj/GHSA-8mpx-pv9q-6xpj.json index d31412559f9..2d325fffa76 100644 --- a/advisories/unreviewed/2024/04/GHSA-8mpx-pv9q-6xpj/GHSA-8mpx-pv9q-6xpj.json +++ b/advisories/unreviewed/2024/04/GHSA-8mpx-pv9q-6xpj/GHSA-8mpx-pv9q-6xpj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mpx-pv9q-6xpj", - "modified": "2024-04-30T15:30:37Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-30T15:30:37Z", "aliases": [ "CVE-2024-33270" ], "details": "An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive information via the uploadfiles.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8wqx-m7xx-m8vw/GHSA-8wqx-m7xx-m8vw.json b/advisories/unreviewed/2024/04/GHSA-8wqx-m7xx-m8vw/GHSA-8wqx-m7xx-m8vw.json index 5e6cb7c2fe0..6c6a1276256 100644 --- a/advisories/unreviewed/2024/04/GHSA-8wqx-m7xx-m8vw/GHSA-8wqx-m7xx-m8vw.json +++ b/advisories/unreviewed/2024/04/GHSA-8wqx-m7xx-m8vw/GHSA-8wqx-m7xx-m8vw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wqx-m7xx-m8vw", - "modified": "2024-04-12T06:33:24Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-12T06:33:24Z", "aliases": [ "CVE-2023-44856" ], "details": "Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the rstat, sender, and recipients' parameters of the sub_21D24 function in the acu_web file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T05:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json b/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json index 73512fbee92..4856f11b9f9 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json +++ b/advisories/unreviewed/2024/04/GHSA-9rp8-67w7-gf47/GHSA-9rp8-67w7-gf47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rp8-67w7-gf47", - "modified": "2024-06-26T00:31:36Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-04T12:30:57Z", "aliases": [ "CVE-2024-26808" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain\n\nRemove netdevice from inet/ingress basechain in case NETDEV_UNREGISTER\nevent is reported, otherwise a stale reference to netdevice remains in\nthe hook list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9x99-qq28-ff9g/GHSA-9x99-qq28-ff9g.json b/advisories/unreviewed/2024/04/GHSA-9x99-qq28-ff9g/GHSA-9x99-qq28-ff9g.json index 0439c20b4bb..dd2109bfb72 100644 --- a/advisories/unreviewed/2024/04/GHSA-9x99-qq28-ff9g/GHSA-9x99-qq28-ff9g.json +++ b/advisories/unreviewed/2024/04/GHSA-9x99-qq28-ff9g/GHSA-9x99-qq28-ff9g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9x99-qq28-ff9g", - "modified": "2024-04-30T09:30:45Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-30T09:30:45Z", "aliases": [ "CVE-2024-31837" ], "details": "DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE-2017-7938.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-134" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T07:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fr2p-5jh8-4366/GHSA-fr2p-5jh8-4366.json b/advisories/unreviewed/2024/04/GHSA-fr2p-5jh8-4366/GHSA-fr2p-5jh8-4366.json index e48556cd332..15f3781b4fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-fr2p-5jh8-4366/GHSA-fr2p-5jh8-4366.json +++ b/advisories/unreviewed/2024/04/GHSA-fr2p-5jh8-4366/GHSA-fr2p-5jh8-4366.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fr2p-5jh8-4366", - "modified": "2024-04-22T15:30:41Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-22T15:30:41Z", "aliases": [ "CVE-2023-38291" ], "details": "An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: TCL A3X (TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vAAZ:user/release-keys, TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vAB3:user/release-keys, TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vAB7:user/release-keys, TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vABA:user/release-keys, TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vABM:user/release-keys, TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vABP:user/release-keys, and TCL/A600DL/Delhi_TF:11/RKQ1.201202.002/vABS:user/release-keys); TCL 10L (TCL/T770B/T1_LITE:10/QKQ1.200329.002/3CJ0:user/release-keys and TCL/T770B/T1_LITE:11/RKQ1.210107.001/8BIC:user/release-keys); Motorola Moto G Pure (motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-2/74844:user/release-keys, motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-7/5cde8:user/release-keys, motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-10/d67faa:user/release-keys, motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-13/b4a29:user/release-keys, motorola/ellis_trac/ellis:12/S3RH32.20-42-10/1c2540:user/release-keys, motorola/ellis_trac/ellis:12/S3RHS32.20-42-13-2-1/6368dd:user/release-keys, motorola/ellis_a/ellis:11/RRH31.Q3-46-50-2/20fec:user/release-keys, motorola/ellis_vzw/ellis:11/RRH31.Q3-46-138/103bd:user/release-keys, motorola/ellis_vzw/ellis:11/RRHS31.Q3-46-138-2/e5502:user/release-keys, and motorola/ellis_vzw/ellis:12/S3RHS32.20-42-10-14-2/5e0b0:user/release-keys); and Motorola Moto G Power (motorola/tonga_g/tonga:11/RRQ31.Q3-68-16-2/e5877:user/release-keys and motorola/tonga_g/tonga:12/S3RQS32.20-42-10-6/f876d3:user/release-keys). This malicious app reads from the \"ro.boot.wifimacaddr\" system property to indirectly obtain the Wi-Fi MAC address.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-22T15:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json b/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json index 6e5dc83f1d3..eaf71847d1c 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json +++ b/advisories/unreviewed/2024/04/GHSA-gvxc-64wh-vgv2/GHSA-gvxc-64wh-vgv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvxc-64wh-vgv2", - "modified": "2024-04-10T21:30:30Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-10T21:30:30Z", "aliases": [ "CVE-2021-47185" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: tty_buffer: Fix the softlockup issue in flush_to_ldisc\n\nWhen running ltp testcase(ltp/testcases/kernel/pty/pty04.c) with arm64, there is a soft lockup,\nwhich look like this one:\n\n Workqueue: events_unbound flush_to_ldisc\n Call trace:\n dump_backtrace+0x0/0x1ec\n show_stack+0x24/0x30\n dump_stack+0xd0/0x128\n panic+0x15c/0x374\n watchdog_timer_fn+0x2b8/0x304\n __run_hrtimer+0x88/0x2c0\n __hrtimer_run_queues+0xa4/0x120\n hrtimer_interrupt+0xfc/0x270\n arch_timer_handler_phys+0x40/0x50\n handle_percpu_devid_irq+0x94/0x220\n __handle_domain_irq+0x88/0xf0\n gic_handle_irq+0x84/0xfc\n el1_irq+0xc8/0x180\n slip_unesc+0x80/0x214 [slip]\n tty_ldisc_receive_buf+0x64/0x80\n tty_port_default_receive_buf+0x50/0x90\n flush_to_ldisc+0xbc/0x110\n process_one_work+0x1d4/0x4b0\n worker_thread+0x180/0x430\n kthread+0x11c/0x120\n\nIn the testcase pty04, The first process call the write syscall to send\ndata to the pty master. At the same time, the workqueue will do the\nflush_to_ldisc to pop data in a loop until there is no more data left.\nWhen the sender and workqueue running in different core, the sender sends\ndata fastly in full time which will result in workqueue doing work in loop\nfor a long time and occuring softlockup in flush_to_ldisc with kernel\nconfigured without preempt. So I add need_resched check and cond_resched\nin the flush_to_ldisc loop to avoid it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hq45-85qj-9w7c/GHSA-hq45-85qj-9w7c.json b/advisories/unreviewed/2024/04/GHSA-hq45-85qj-9w7c/GHSA-hq45-85qj-9w7c.json index 16883a92ddc..3b3727ab3d4 100644 --- a/advisories/unreviewed/2024/04/GHSA-hq45-85qj-9w7c/GHSA-hq45-85qj-9w7c.json +++ b/advisories/unreviewed/2024/04/GHSA-hq45-85qj-9w7c/GHSA-hq45-85qj-9w7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq45-85qj-9w7c", - "modified": "2024-04-03T18:30:43Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-03T18:30:43Z", "aliases": [ "CVE-2024-26769" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: avoid deadlock on delete association path\n\nWhen deleting an association the shutdown path is deadlocking because we\ntry to flush the nvmet_wq nested. Avoid this by deadlock by deferring\nthe put work into its own work item.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json b/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json index cc0f6aaeacf..26786cee809 100644 --- a/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json +++ b/advisories/unreviewed/2024/04/GHSA-hvc4-mjv4-5mw6/GHSA-hvc4-mjv4-5mw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvc4-mjv4-5mw6", - "modified": "2024-06-10T18:30:56Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-25T09:32:09Z", "aliases": [ "CVE-2023-6237" ], "details": "Issue summary: Checking excessively long invalid RSA public keys may take\na long time.\n\nImpact summary: Applications that use the function EVP_PKEY_public_check()\nto check RSA public keys may experience long delays. Where the key that\nis being checked has been obtained from an untrusted source this may lead\nto a Denial of Service.\n\nWhen function EVP_PKEY_public_check() is called on RSA public keys,\na computation is done to confirm that the RSA modulus, n, is composite.\nFor valid RSA keys, n is a product of two or more large primes and this\ncomputation completes quickly. However, if n is an overly large prime,\nthen this computation would take a long time.\n\nAn application that calls EVP_PKEY_public_check() and supplies an RSA key\nobtained from an untrusted source could be vulnerable to a Denial of Service\nattack.\n\nThe function EVP_PKEY_public_check() is not called from other OpenSSL\nfunctions however it is called from the OpenSSL pkey command line\napplication. For that reason that application is also vulnerable if used\nwith the '-pubin' and '-check' options on untrusted data.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ "CWE-606" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-25T07:15:45Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qcgh-63vj-9xp8/GHSA-qcgh-63vj-9xp8.json b/advisories/unreviewed/2024/04/GHSA-qcgh-63vj-9xp8/GHSA-qcgh-63vj-9xp8.json index fcb252d9a37..75fb0c13d25 100644 --- a/advisories/unreviewed/2024/04/GHSA-qcgh-63vj-9xp8/GHSA-qcgh-63vj-9xp8.json +++ b/advisories/unreviewed/2024/04/GHSA-qcgh-63vj-9xp8/GHSA-qcgh-63vj-9xp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcgh-63vj-9xp8", - "modified": "2024-06-27T15:30:38Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-03T18:30:43Z", "aliases": [ "CVE-2024-26772" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal()\n\nPlaces the logic for checking if the group's block bitmap is corrupt under\nthe protection of the group lock to avoid allocating blocks from the group\nwith a corrupted block bitmap.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json b/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json index 95962ed9e84..cbd0afe280d 100644 --- a/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json +++ b/advisories/unreviewed/2024/04/GHSA-w36m-8p9q-xcc9/GHSA-w36m-8p9q-xcc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w36m-8p9q-xcc9", - "modified": "2024-04-08T03:30:52Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-08T03:30:52Z", "aliases": [ "CVE-2023-52347" ], "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wmwr-w663-h5f9/GHSA-wmwr-w663-h5f9.json b/advisories/unreviewed/2024/04/GHSA-wmwr-w663-h5f9/GHSA-wmwr-w663-h5f9.json index b54b3989065..d77395c7f3a 100644 --- a/advisories/unreviewed/2024/04/GHSA-wmwr-w663-h5f9/GHSA-wmwr-w663-h5f9.json +++ b/advisories/unreviewed/2024/04/GHSA-wmwr-w663-h5f9/GHSA-wmwr-w663-h5f9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmwr-w663-h5f9", - "modified": "2024-04-17T12:32:04Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-17T12:32:04Z", "aliases": [ "CVE-2024-26847" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/rtas: use correct function name for resetting TCE tables\n\nThe PAPR spec spells the function name as\n\n \"ibm,reset-pe-dma-windows\"\n\nbut in practice firmware uses the singular form:\n\n \"ibm,reset-pe-dma-window\"\n\nin the device tree. Since we have the wrong spelling in the RTAS\nfunction table, reverse lookups (token -> name) fail and warn:\n\n unexpected failed lookup for token 86\n WARNING: CPU: 1 PID: 545 at arch/powerpc/kernel/rtas.c:659 __do_enter_rtas_trace+0x2a4/0x2b4\n CPU: 1 PID: 545 Comm: systemd-udevd Not tainted 6.8.0-rc4 #30\n Hardware name: IBM,9105-22A POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NL1060_028) hv:phyp pSeries\n NIP [c0000000000417f0] __do_enter_rtas_trace+0x2a4/0x2b4\n LR [c0000000000417ec] __do_enter_rtas_trace+0x2a0/0x2b4\n Call Trace:\n __do_enter_rtas_trace+0x2a0/0x2b4 (unreliable)\n rtas_call+0x1f8/0x3e0\n enable_ddw.constprop.0+0x4d0/0xc84\n dma_iommu_dma_supported+0xe8/0x24c\n dma_set_mask+0x5c/0xd8\n mlx5_pci_init.constprop.0+0xf0/0x46c [mlx5_core]\n probe_one+0xfc/0x32c [mlx5_core]\n local_pci_probe+0x68/0x12c\n pci_call_probe+0x68/0x1ec\n pci_device_probe+0xbc/0x1a8\n really_probe+0x104/0x570\n __driver_probe_device+0xb8/0x224\n driver_probe_device+0x54/0x130\n __driver_attach+0x158/0x2b0\n bus_for_each_dev+0xa8/0x120\n driver_attach+0x34/0x48\n bus_add_driver+0x174/0x304\n driver_register+0x8c/0x1c4\n __pci_register_driver+0x68/0x7c\n mlx5_init+0xb8/0x118 [mlx5_core]\n do_one_initcall+0x60/0x388\n do_init_module+0x7c/0x2a4\n init_module_from_file+0xb4/0x108\n idempotent_init_module+0x184/0x34c\n sys_finit_module+0x90/0x114\n\nAnd oopses are possible when lockdep is enabled or the RTAS\ntracepoints are active, since those paths dereference the result of\nthe lookup.\n\nUse the correct spelling to match firmware's behavior, adjusting the\nrelated constants to match.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x5w9-633f-fvmj/GHSA-x5w9-633f-fvmj.json b/advisories/unreviewed/2024/04/GHSA-x5w9-633f-fvmj/GHSA-x5w9-633f-fvmj.json index 525466ae4c4..60940c0016c 100644 --- a/advisories/unreviewed/2024/04/GHSA-x5w9-633f-fvmj/GHSA-x5w9-633f-fvmj.json +++ b/advisories/unreviewed/2024/04/GHSA-x5w9-633f-fvmj/GHSA-x5w9-633f-fvmj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-xhpx-f3qp-rwvq/GHSA-xhpx-f3qp-rwvq.json b/advisories/unreviewed/2024/04/GHSA-xhpx-f3qp-rwvq/GHSA-xhpx-f3qp-rwvq.json index 5b9ca26ca7f..401b6709782 100644 --- a/advisories/unreviewed/2024/04/GHSA-xhpx-f3qp-rwvq/GHSA-xhpx-f3qp-rwvq.json +++ b/advisories/unreviewed/2024/04/GHSA-xhpx-f3qp-rwvq/GHSA-xhpx-f3qp-rwvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhpx-f3qp-rwvq", - "modified": "2024-04-30T00:30:35Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-04-30T00:30:35Z", "aliases": [ "CVE-2024-34046" ], "details": "The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T00:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xpw7-h5wm-8q7v/GHSA-xpw7-h5wm-8q7v.json b/advisories/unreviewed/2024/04/GHSA-xpw7-h5wm-8q7v/GHSA-xpw7-h5wm-8q7v.json index 55ad4ee0fa7..6ce04b0392d 100644 --- a/advisories/unreviewed/2024/04/GHSA-xpw7-h5wm-8q7v/GHSA-xpw7-h5wm-8q7v.json +++ b/advisories/unreviewed/2024/04/GHSA-xpw7-h5wm-8q7v/GHSA-xpw7-h5wm-8q7v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-4gxv-hggr-2473/GHSA-4gxv-hggr-2473.json b/advisories/unreviewed/2024/05/GHSA-4gxv-hggr-2473/GHSA-4gxv-hggr-2473.json index 93cdc4740be..163a84e8f4f 100644 --- a/advisories/unreviewed/2024/05/GHSA-4gxv-hggr-2473/GHSA-4gxv-hggr-2473.json +++ b/advisories/unreviewed/2024/05/GHSA-4gxv-hggr-2473/GHSA-4gxv-hggr-2473.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gxv-hggr-2473", - "modified": "2024-05-21T15:31:45Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-05-21T15:31:45Z", "aliases": [ "CVE-2021-47408" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: serialize hash resizes and cleanups\n\nSyzbot was able to trigger the following warning [1]\n\nNo repro found by syzbot yet but I was able to trigger similar issue\nby having 2 scripts running in parallel, changing conntrack hash sizes,\nand:\n\nfor j in `seq 1 1000` ; do unshare -n /bin/true >/dev/null ; done\n\nIt would take more than 5 minutes for net_namespace structures\nto be cleaned up.\n\nThis is because nf_ct_iterate_cleanup() has to restart everytime\na resize happened.\n\nBy adding a mutex, we can serialize hash resizes and cleanups\nand also make get_next_corpse() faster by skipping over empty\nbuckets.\n\nEven without resizes in the picture, this patch considerably\nspeeds up network namespace dismantles.\n\n[1]\nINFO: task syz-executor.0:8312 can't die for more than 144 seconds.\ntask:syz-executor.0 state:R running task stack:25672 pid: 8312 ppid: 6573 flags:0x00004006\nCall Trace:\n context_switch kernel/sched/core.c:4955 [inline]\n __schedule+0x940/0x26f0 kernel/sched/core.c:6236\n preempt_schedule_common+0x45/0xc0 kernel/sched/core.c:6408\n preempt_schedule_thunk+0x16/0x18 arch/x86/entry/thunk_64.S:35\n __local_bh_enable_ip+0x109/0x120 kernel/softirq.c:390\n local_bh_enable include/linux/bottom_half.h:32 [inline]\n get_next_corpse net/netfilter/nf_conntrack_core.c:2252 [inline]\n nf_ct_iterate_cleanup+0x15a/0x450 net/netfilter/nf_conntrack_core.c:2275\n nf_conntrack_cleanup_net_list+0x14c/0x4f0 net/netfilter/nf_conntrack_core.c:2469\n ops_exit_list+0x10d/0x160 net/core/net_namespace.c:171\n setup_net+0x639/0xa30 net/core/net_namespace.c:349\n copy_net_ns+0x319/0x760 net/core/net_namespace.c:470\n create_new_namespaces+0x3f6/0xb20 kernel/nsproxy.c:110\n unshare_nsproxy_namespaces+0xc1/0x1f0 kernel/nsproxy.c:226\n ksys_unshare+0x445/0x920 kernel/fork.c:3128\n __do_sys_unshare kernel/fork.c:3202 [inline]\n __se_sys_unshare kernel/fork.c:3200 [inline]\n __x64_sys_unshare+0x2d/0x40 kernel/fork.c:3200\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f63da68e739\nRSP: 002b:00007f63d7c05188 EFLAGS: 00000246 ORIG_RAX: 0000000000000110\nRAX: ffffffffffffffda RBX: 00007f63da792f80 RCX: 00007f63da68e739\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000040000000\nRBP: 00007f63da6e8cc4 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007f63da792f80\nR13: 00007fff50b75d3f R14: 00007f63d7c05300 R15: 0000000000022000\n\nShowing all locks held in the system:\n1 lock held by khungtaskd/27:\n #0: ffffffff8b980020 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x53/0x260 kernel/locking/lockdep.c:6446\n2 locks held by kworker/u4:2/153:\n #0: ffff888010c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: arch_atomic64_set arch/x86/include/asm/atomic64_64.h:34 [inline]\n #0: ffff888010c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: arch_atomic_long_set include/linux/atomic/atomic-long.h:41 [inline]\n #0: ffff888010c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: atomic_long_set include/linux/atomic/atomic-instrumented.h:1198 [inline]\n #0: ffff888010c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: set_work_data kernel/workqueue.c:634 [inline]\n #0: ffff888010c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: set_work_pool_and_clear_pending kernel/workqueue.c:661 [inline]\n #0: ffff888010c69138 ((wq_completion)events_unbound){+.+.}-{0:0}, at: process_one_work+0x896/0x1690 kernel/workqueue.c:2268\n #1: ffffc9000140fdb0 ((kfence_timer).work){+.+.}-{0:0}, at: process_one_work+0x8ca/0x1690 kernel/workqueue.c:2272\n1 lock held by systemd-udevd/2970:\n1 lock held by in:imklog/6258:\n #0: ffff88807f970ff0 (&f->f_pos_lock){+.+.}-{3:3}, at: __fdget_pos+0xe9/0x100 fs/file.c:990\n3 locks held by kworker/1:6/8158:\n1 lock held by syz-executor.0/8312:\n2 locks held by kworker/u4:13/9320:\n1 lock held by\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:26Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json b/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json index a93cd168393..0f9b2e3b212 100644 --- a/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json +++ b/advisories/unreviewed/2024/05/GHSA-7w57-r874-fx7f/GHSA-7w57-r874-fx7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7w57-r874-fx7f", - "modified": "2024-05-19T09:34:46Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-05-19T09:34:46Z", "aliases": [ "CVE-2024-35865" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential UAF in smb2_is_valid_oplock_break()\n\nSkip sessions that are being teared down (status == SES_EXITING) to\navoid UAF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T09:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json b/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json index 5da5d2efa0d..63b424b740f 100644 --- a/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json +++ b/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c84w-j8mj-57ch", - "modified": "2024-05-22T09:31:46Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-05-22T09:31:46Z", "aliases": [ "CVE-2021-47476" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: ni_usb6501: fix NULL-deref in command paths\n\nThe driver uses endpoint-sized USB transfer buffers but had no sanity\nchecks on the sizes. This can lead to zero-size-pointer dereferences or\noverflowed transfer buffers in ni6501_port_command() and\nni6501_counter_command() if a (malicious) device has smaller max-packet\nsizes than expected (or when doing descriptor fuzz testing).\n\nAdd the missing sanity checks to probe().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T09:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json b/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json index 345880768f0..632708ff1e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json +++ b/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8c2-87vw-jwfw", - "modified": "2024-05-22T09:31:45Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-05-22T09:31:44Z", "aliases": [ "CVE-2021-47440" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: encx24j600: check error in devm_regmap_init_encx24j600\n\ndevm_regmap_init may return error which caused by like out of memory,\nthis will results in null pointer dereference later when reading\nor writing register:\n\ngeneral protection fault in encx24j600_spi_probe\nKASAN: null-ptr-deref in range [0x0000000000000090-0x0000000000000097]\nCPU: 0 PID: 286 Comm: spi-encx24j600- Not tainted 5.15.0-rc2-00142-g9978db750e31-dirty #11 9c53a778c1306b1b02359f3c2bbedc0222cba652\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nRIP: 0010:regcache_cache_bypass drivers/base/regmap/regcache.c:540\nCode: 54 41 89 f4 55 53 48 89 fb 48 83 ec 08 e8 26 94 a8 fe 48 8d bb a0 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 4a 03 00 00 4c 8d ab b0 00 00 00 48 8b ab a0 00\nRSP: 0018:ffffc900010476b8 EFLAGS: 00010207\nRAX: dffffc0000000000 RBX: fffffffffffffff4 RCX: 0000000000000000\nRDX: 0000000000000012 RSI: ffff888002de0000 RDI: 0000000000000094\nRBP: ffff888013c9a000 R08: 0000000000000000 R09: fffffbfff3f9cc6a\nR10: ffffc900010476e8 R11: fffffbfff3f9cc69 R12: 0000000000000001\nR13: 000000000000000a R14: ffff888013c9af54 R15: ffff888013c9ad08\nFS: 00007ffa984ab580(0000) GS:ffff88801fe00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055a6384136c8 CR3: 000000003bbe6003 CR4: 0000000000770ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n encx24j600_spi_probe drivers/net/ethernet/microchip/encx24j600.c:459\n spi_probe drivers/spi/spi.c:397\n really_probe drivers/base/dd.c:517\n __driver_probe_device drivers/base/dd.c:751\n driver_probe_device drivers/base/dd.c:782\n __device_attach_driver drivers/base/dd.c:899\n bus_for_each_drv drivers/base/bus.c:427\n __device_attach drivers/base/dd.c:971\n bus_probe_device drivers/base/bus.c:487\n device_add drivers/base/core.c:3364\n __spi_add_device drivers/spi/spi.c:599\n spi_add_device drivers/spi/spi.c:641\n spi_new_device drivers/spi/spi.c:717\n new_device_store+0x18c/0x1f1 [spi_stub 4e02719357f1ff33f5a43d00630982840568e85e]\n dev_attr_store drivers/base/core.c:2074\n sysfs_kf_write fs/sysfs/file.c:139\n kernfs_fop_write_iter fs/kernfs/file.c:300\n new_sync_write fs/read_write.c:508 (discriminator 4)\n vfs_write fs/read_write.c:594\n ksys_write fs/read_write.c:648\n do_syscall_64 arch/x86/entry/common.c:50\n entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:113\n\nAdd error check in devm_regmap_init_encx24j600 to avoid this situation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h9p9-4f35-pxjm/GHSA-h9p9-4f35-pxjm.json b/advisories/unreviewed/2024/05/GHSA-h9p9-4f35-pxjm/GHSA-h9p9-4f35-pxjm.json index a40d5c25424..2d64a5b6780 100644 --- a/advisories/unreviewed/2024/05/GHSA-h9p9-4f35-pxjm/GHSA-h9p9-4f35-pxjm.json +++ b/advisories/unreviewed/2024/05/GHSA-h9p9-4f35-pxjm/GHSA-h9p9-4f35-pxjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9p9-4f35-pxjm", - "modified": "2024-05-21T15:31:45Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-05-21T15:31:45Z", "aliases": [ "CVE-2021-47419" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_taprio: properly cancel timer from taprio_destroy()\n\nThere is a comment in qdisc_create() about us not calling ops->reset()\nin some cases.\n\nerr_out4:\n\t/*\n\t * Any broken qdiscs that would require a ops->reset() here?\n\t * The qdisc was never in action so it shouldn't be necessary.\n\t */\n\nAs taprio sets a timer before actually receiving a packet, we need\nto cancel it from ops->destroy, just in case ops->reset has not\nbeen called.\n\nsyzbot reported:\n\nODEBUG: free active (active state 0) object type: hrtimer hint: advance_sched+0x0/0x9a0 arch/x86/include/asm/atomic64_64.h:22\nWARNING: CPU: 0 PID: 8441 at lib/debugobjects.c:505 debug_print_object+0x16e/0x250 lib/debugobjects.c:505\nModules linked in:\nCPU: 0 PID: 8441 Comm: syz-executor813 Not tainted 5.14.0-rc6-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:debug_print_object+0x16e/0x250 lib/debugobjects.c:505\nCode: ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 af 00 00 00 48 8b 14 dd e0 d3 e3 89 4c 89 ee 48 c7 c7 e0 c7 e3 89 e8 5b 86 11 05 <0f> 0b 83 05 85 03 92 09 01 48 83 c4 18 5b 5d 41 5c 41 5d 41 5e c3\nRSP: 0018:ffffc9000130f330 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: 0000000000000003 RCX: 0000000000000000\nRDX: ffff88802baeb880 RSI: ffffffff815d87b5 RDI: fffff52000261e58\nRBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffffff815d25ee R11: 0000000000000000 R12: ffffffff898dd020\nR13: ffffffff89e3ce20 R14: ffffffff81653630 R15: dffffc0000000000\nFS: 0000000000f0d300(0000) GS:ffff8880b9d00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffb64b3e000 CR3: 0000000036557000 CR4: 00000000001506e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n __debug_check_no_obj_freed lib/debugobjects.c:987 [inline]\n debug_check_no_obj_freed+0x301/0x420 lib/debugobjects.c:1018\n slab_free_hook mm/slub.c:1603 [inline]\n slab_free_freelist_hook+0x171/0x240 mm/slub.c:1653\n slab_free mm/slub.c:3213 [inline]\n kfree+0xe4/0x540 mm/slub.c:4267\n qdisc_create+0xbcf/0x1320 net/sched/sch_api.c:1299\n tc_modify_qdisc+0x4c8/0x1a60 net/sched/sch_api.c:1663\n rtnetlink_rcv_msg+0x413/0xb80 net/core/rtnetlink.c:5571\n netlink_rcv_skb+0x153/0x420 net/netlink/af_netlink.c:2504\n netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]\n netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1340\n netlink_sendmsg+0x86d/0xdb0 net/netlink/af_netlink.c:1929\n sock_sendmsg_nosec net/socket.c:704 [inline]\n sock_sendmsg+0xcf/0x120 net/socket.c:724\n ____sys_sendmsg+0x6e8/0x810 net/socket.c:2403\n ___sys_sendmsg+0xf3/0x170 net/socket.c:2457\n __sys_sendmsg+0xe5/0x1b0 net/socket.c:2486\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:27Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json b/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json index c1b96dd046f..69a44fe0370 100644 --- a/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json +++ b/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rr8j-q4x4-g24r", - "modified": "2024-05-01T15:30:36Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27058" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntmpfs: fix race on handling dquot rbtree\n\nA syzkaller reproducer found a race while attempting to remove dquot\ninformation from the rb tree.\n\nFetching the rb_tree root node must also be protected by the\ndqopt->dqio_sem, otherwise, giving the right timing, shmem_release_dquot()\nwill trigger a warning because it couldn't find a node in the tree, when\nthe real reason was the root node changing before the search starts:\n\nThread 1\t\t\t\tThread 2\n- shmem_release_dquot()\t\t\t- shmem_{acquire,release}_dquot()\n\n- fetch ROOT\t\t\t\t- Fetch ROOT\n\n\t\t\t\t\t- acquire dqio_sem\n- wait dqio_sem\n\n\t\t\t\t\t- do something, triger a tree rebalance\n\t\t\t\t\t- release dqio_sem\n\n- acquire dqio_sem\n- start searching for the node, but\n from the wrong location, missing\n the node, and triggering a warning.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vxpv-rv2q-v5r7/GHSA-vxpv-rv2q-v5r7.json b/advisories/unreviewed/2024/05/GHSA-vxpv-rv2q-v5r7/GHSA-vxpv-rv2q-v5r7.json index c8092a35b66..2592612f041 100644 --- a/advisories/unreviewed/2024/05/GHSA-vxpv-rv2q-v5r7/GHSA-vxpv-rv2q-v5r7.json +++ b/advisories/unreviewed/2024/05/GHSA-vxpv-rv2q-v5r7/GHSA-vxpv-rv2q-v5r7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vxpv-rv2q-v5r7", - "modified": "2024-05-01T15:30:35Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-05-01T15:30:35Z", "aliases": [ "CVE-2024-27041" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix NULL checks for adev->dm.dc in amdgpu_dm_fini()\n\nSince 'adev->dm.dc' in amdgpu_dm_fini() might turn out to be NULL\nbefore the call to dc_enable_dmub_notifications(), check\nbeforehand to ensure there will not be a possible NULL-ptr-deref\nthere.\n\nAlso, since commit 1e88eb1b2c25 (\"drm/amd/display: Drop\nCONFIG_DRM_AMD_DC_HDCP\") there are two separate checks for NULL in\n'adev->dm.dc' before dc_deinit_callbacks() and dc_dmub_srv_destroy().\nClean up by combining them all under one 'if'.\n\nFound by Linux Verification Center (linuxtesting.org) with static\nanalysis tool SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json b/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json index 540fc958f33..0dc7b10bb72 100644 --- a/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json +++ b/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wf38-7v3f-5mjp", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-11-01T18:31:25Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47267" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: fix various gadget panics on 10gbps cabling\n\nusb_assign_descriptors() is called with 5 parameters,\nthe last 4 of which are the usb_descriptor_header for:\n full-speed (USB1.1 - 12Mbps [including USB1.0 low-speed @ 1.5Mbps),\n high-speed (USB2.0 - 480Mbps),\n super-speed (USB3.0 - 5Gbps),\n super-speed-plus (USB3.1 - 10Gbps).\n\nThe differences between full/high/super-speed descriptors are usually\nsubstantial (due to changes in the maximum usb block size from 64 to 512\nto 1024 bytes and other differences in the specs), while the difference\nbetween 5 and 10Gbps descriptors may be as little as nothing\n(in many cases the same tuning is simply good enough).\n\nHowever if a gadget driver calls usb_assign_descriptors() with\na NULL descriptor for super-speed-plus and is then used on a max 10gbps\nconfiguration, the kernel will crash with a null pointer dereference,\nwhen a 10gbps capable device port + cable + host port combination shows up.\n(This wouldn't happen if the gadget max-speed was set to 5gbps, but\nit of course defaults to the maximum, and there's no real reason to\nartificially limit it)\n\nThe fix is to simply use the 5gbps descriptor as the 10gbps descriptor,\nif a 10gbps descriptor wasn't provided.\n\nObviously this won't fix the problem if the 5gbps descriptor is also\nNULL, but such cases can't be so trivially solved (and any such gadgets\nare unlikely to be used with USB3 ports any way).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-427c-cc94-833h/GHSA-427c-cc94-833h.json b/advisories/unreviewed/2024/06/GHSA-427c-cc94-833h/GHSA-427c-cc94-833h.json index 27123ee11d7..208e298f569 100644 --- a/advisories/unreviewed/2024/06/GHSA-427c-cc94-833h/GHSA-427c-cc94-833h.json +++ b/advisories/unreviewed/2024/06/GHSA-427c-cc94-833h/GHSA-427c-cc94-833h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-427c-cc94-833h", - "modified": "2024-06-25T21:31:14Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-25T21:31:14Z", "aliases": [ "CVE-2024-36819" ], "details": "MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the \"Client Name\" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T19:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-42m3-r5g5-mfwp/GHSA-42m3-r5g5-mfwp.json b/advisories/unreviewed/2024/06/GHSA-42m3-r5g5-mfwp/GHSA-42m3-r5g5-mfwp.json index 962fb71d29e..03509ac9d57 100644 --- a/advisories/unreviewed/2024/06/GHSA-42m3-r5g5-mfwp/GHSA-42m3-r5g5-mfwp.json +++ b/advisories/unreviewed/2024/06/GHSA-42m3-r5g5-mfwp/GHSA-42m3-r5g5-mfwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42m3-r5g5-mfwp", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32920" ], "details": "In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-77rx-fhp5-rj33/GHSA-77rx-fhp5-rj33.json b/advisories/unreviewed/2024/06/GHSA-77rx-fhp5-rj33/GHSA-77rx-fhp5-rj33.json index d7c391eaf11..c286a788ad2 100644 --- a/advisories/unreviewed/2024/06/GHSA-77rx-fhp5-rj33/GHSA-77rx-fhp5-rj33.json +++ b/advisories/unreviewed/2024/06/GHSA-77rx-fhp5-rj33/GHSA-77rx-fhp5-rj33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77rx-fhp5-rj33", - "modified": "2024-06-27T15:30:39Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38565" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ar5523: enable proper endpoint verification\n\nSyzkaller reports [1] hitting a warning about an endpoint in use\nnot having an expected type to it.\n\nFix the issue by checking for the existence of all proper\nendpoints with their according types intact.\n\nSadly, this patch has not been tested on real hardware.\n\n[1] Syzkaller report:\n------------[ cut here ]------------\nusb 1-1: BOGUS urb xfer, pipe 3 != type 1\nWARNING: CPU: 0 PID: 3643 at drivers/usb/core/urb.c:504 usb_submit_urb+0xed6/0x1880 drivers/usb/core/urb.c:504\n...\nCall Trace:\n \n ar5523_cmd+0x41b/0x780 drivers/net/wireless/ath/ar5523/ar5523.c:275\n ar5523_cmd_read drivers/net/wireless/ath/ar5523/ar5523.c:302 [inline]\n ar5523_host_available drivers/net/wireless/ath/ar5523/ar5523.c:1376 [inline]\n ar5523_probe+0x14b0/0x1d10 drivers/net/wireless/ath/ar5523/ar5523.c:1655\n usb_probe_interface+0x30f/0x7f0 drivers/usb/core/driver.c:396\n call_driver_probe drivers/base/dd.c:560 [inline]\n really_probe+0x249/0xb90 drivers/base/dd.c:639\n __driver_probe_device+0x1df/0x4d0 drivers/base/dd.c:778\n driver_probe_device+0x4c/0x1a0 drivers/base/dd.c:808\n __device_attach_driver+0x1d4/0x2e0 drivers/base/dd.c:936\n bus_for_each_drv+0x163/0x1e0 drivers/base/bus.c:427\n __device_attach+0x1e4/0x530 drivers/base/dd.c:1008\n bus_probe_device+0x1e8/0x2a0 drivers/base/bus.c:487\n device_add+0xbd9/0x1e90 drivers/base/core.c:3517\n usb_set_configuration+0x101d/0x1900 drivers/usb/core/message.c:2170\n usb_generic_driver_probe+0xbe/0x100 drivers/usb/core/generic.c:238\n usb_probe_device+0xd8/0x2c0 drivers/usb/core/driver.c:293\n call_driver_probe drivers/base/dd.c:560 [inline]\n really_probe+0x249/0xb90 drivers/base/dd.c:639\n __driver_probe_device+0x1df/0x4d0 drivers/base/dd.c:778\n driver_probe_device+0x4c/0x1a0 drivers/base/dd.c:808\n __device_attach_driver+0x1d4/0x2e0 drivers/base/dd.c:936\n bus_for_each_drv+0x163/0x1e0 drivers/base/bus.c:427\n __device_attach+0x1e4/0x530 drivers/base/dd.c:1008\n bus_probe_device+0x1e8/0x2a0 drivers/base/bus.c:487\n device_add+0xbd9/0x1e90 drivers/base/core.c:3517\n usb_new_device.cold+0x685/0x10ad drivers/usb/core/hub.c:2573\n hub_port_connect drivers/usb/core/hub.c:5353 [inline]\n hub_port_connect_change drivers/usb/core/hub.c:5497 [inline]\n port_event drivers/usb/core/hub.c:5653 [inline]\n hub_event+0x26cb/0x45d0 drivers/usb/core/hub.c:5735\n process_one_work+0x9bf/0x1710 kernel/workqueue.c:2289\n worker_thread+0x669/0x1090 kernel/workqueue.c:2436\n kthread+0x2e8/0x3a0 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h5r4-f5wx-726x/GHSA-h5r4-f5wx-726x.json b/advisories/unreviewed/2024/06/GHSA-h5r4-f5wx-726x/GHSA-h5r4-f5wx-726x.json index 070cc2e0dd6..dffb1bb6699 100644 --- a/advisories/unreviewed/2024/06/GHSA-h5r4-f5wx-726x/GHSA-h5r4-f5wx-726x.json +++ b/advisories/unreviewed/2024/06/GHSA-h5r4-f5wx-726x/GHSA-h5r4-f5wx-726x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5r4-f5wx-726x", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38540" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq\n\nUndefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called\nwith hwq_attr->aux_depth != 0 and hwq_attr->aux_stride == 0.\nIn that case, \"roundup_pow_of_two(hwq_attr->aux_stride)\" gets called.\nroundup_pow_of_two is documented as undefined for 0.\n\nFix it in the one caller that had this combination.\n\nThe undefined behavior was detected by UBSAN:\n UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13\n shift exponent 64 is too large for 64-bit type 'long unsigned int'\n CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4\n Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023\n Call Trace:\n \n dump_stack_lvl+0x5d/0x80\n ubsan_epilogue+0x5/0x30\n __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec\n __roundup_pow_of_two+0x25/0x35 [bnxt_re]\n bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]\n bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]\n bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __kmalloc+0x1b6/0x4f0\n ? create_qp.part.0+0x128/0x1c0 [ib_core]\n ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]\n create_qp.part.0+0x128/0x1c0 [ib_core]\n ib_create_qp_kernel+0x50/0xd0 [ib_core]\n create_mad_qp+0x8e/0xe0 [ib_core]\n ? __pfx_qp_event_handler+0x10/0x10 [ib_core]\n ib_mad_init_device+0x2be/0x680 [ib_core]\n add_client_context+0x10d/0x1a0 [ib_core]\n enable_device_and_get+0xe0/0x1d0 [ib_core]\n ib_register_device+0x53c/0x630 [ib_core]\n ? srso_alias_return_thunk+0x5/0xfbef5\n bnxt_re_probe+0xbd8/0xe50 [bnxt_re]\n ? __pfx_bnxt_re_probe+0x10/0x10 [bnxt_re]\n auxiliary_bus_probe+0x49/0x80\n ? driver_sysfs_add+0x57/0xc0\n really_probe+0xde/0x340\n ? pm_runtime_barrier+0x54/0x90\n ? __pfx___driver_attach+0x10/0x10\n __driver_probe_device+0x78/0x110\n driver_probe_device+0x1f/0xa0\n __driver_attach+0xba/0x1c0\n bus_for_each_dev+0x8f/0xe0\n bus_add_driver+0x146/0x220\n driver_register+0x72/0xd0\n __auxiliary_driver_register+0x6e/0xd0\n ? __pfx_bnxt_re_mod_init+0x10/0x10 [bnxt_re]\n bnxt_re_mod_init+0x3e/0xff0 [bnxt_re]\n ? __pfx_bnxt_re_mod_init+0x10/0x10 [bnxt_re]\n do_one_initcall+0x5b/0x310\n do_init_module+0x90/0x250\n init_module_from_file+0x86/0xc0\n idempotent_init_module+0x121/0x2b0\n __x64_sys_finit_module+0x5e/0xb0\n do_syscall_64+0x82/0x160\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? syscall_exit_to_user_mode_prepare+0x149/0x170\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? syscall_exit_to_user_mode+0x75/0x230\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? do_syscall_64+0x8e/0x160\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __count_memcg_events+0x69/0x100\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? count_memcg_events.constprop.0+0x1a/0x30\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? handle_mm_fault+0x1f0/0x300\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? do_user_addr_fault+0x34e/0x640\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? srso_alias_return_thunk+0x5/0xfbef5\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f4e5132821d\n Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e3 db 0c 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffca9c906a8 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n RAX: ffffffffffffffda RBX: 0000563ec8a8f130 RCX: 00007f4e5132821d\n RDX: 0000000000000000 RSI: 00007f4e518fa07d RDI: 000000000000003b\n RBP: 00007ffca9c90760 R08: 00007f4e513f6b20 R09: 00007ffca9c906f0\n R10: 0000563ec8a8faa0 R11: 0000000000000246 R12: 00007f4e518fa07d\n R13: 0000000000020000 R14: 0000563ec8409e90 R15: 0000563ec8a8fa60\n \n ---[ end trace ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j698-35hc-3jf8/GHSA-j698-35hc-3jf8.json b/advisories/unreviewed/2024/06/GHSA-j698-35hc-3jf8/GHSA-j698-35hc-3jf8.json index 0472aff15e7..cac15add9e3 100644 --- a/advisories/unreviewed/2024/06/GHSA-j698-35hc-3jf8/GHSA-j698-35hc-3jf8.json +++ b/advisories/unreviewed/2024/06/GHSA-j698-35hc-3jf8/GHSA-j698-35hc-3jf8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j698-35hc-3jf8", - "modified": "2024-06-27T15:30:39Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38559" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qedf: Ensure the copied buf is NUL terminated\n\nCurrently, we allocate a count-sized kernel buffer and copy count from\nuserspace to that buffer. Later, we use kstrtouint on this buffer but we\ndon't ensure that the string is terminated inside the buffer, this can\nlead to OOB read when using kstrtouint. Fix this issue by using\nmemdup_user_nul instead of memdup_user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jghm-p5v7-jx64/GHSA-jghm-p5v7-jx64.json b/advisories/unreviewed/2024/06/GHSA-jghm-p5v7-jx64/GHSA-jghm-p5v7-jx64.json index 7f818a31625..8fb635975c1 100644 --- a/advisories/unreviewed/2024/06/GHSA-jghm-p5v7-jx64/GHSA-jghm-p5v7-jx64.json +++ b/advisories/unreviewed/2024/06/GHSA-jghm-p5v7-jx64/GHSA-jghm-p5v7-jx64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jghm-p5v7-jx64", - "modified": "2024-06-18T21:30:36Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-18T21:30:36Z", "aliases": [ "CVE-2024-36977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: Wait unconditionally after issuing EndXfer command\n\nCurrently all controller IP/revisions except DWC3_usb3 >= 310a\nwait 1ms unconditionally for ENDXFER completion when IOC is not\nset. This is because DWC_usb3 controller revisions >= 3.10a\nsupports GUCTL2[14: Rst_actbitlater] bit which allows polling\nCMDACT bit to know whether ENDXFER command is completed.\n\nConsider a case where an IN request was queued, and parallelly\nsoft_disconnect was called (due to ffs_epfile_release). This\neventually calls stop_active_transfer with IOC cleared, hence\nsend_gadget_ep_cmd() skips waiting for CMDACT cleared during\nEndXfer. For DWC3 controllers with revisions >= 310a, we don't\nforcefully wait for 1ms either, and we proceed by unmapping the\nrequests. If ENDXFER didn't complete by this time, it leads to\nSMMU faults since the controller would still be accessing those\nrequests.\n\nFix this by ensuring ENDXFER completion by adding 1ms delay in\n__dwc3_stop_active_transfer() unconditionally.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T20:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qr6m-fxwf-qgc5/GHSA-qr6m-fxwf-qgc5.json b/advisories/unreviewed/2024/06/GHSA-qr6m-fxwf-qgc5/GHSA-qr6m-fxwf-qgc5.json index bfd020d59af..3aa1982f66f 100644 --- a/advisories/unreviewed/2024/06/GHSA-qr6m-fxwf-qgc5/GHSA-qr6m-fxwf-qgc5.json +++ b/advisories/unreviewed/2024/06/GHSA-qr6m-fxwf-qgc5/GHSA-qr6m-fxwf-qgc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qr6m-fxwf-qgc5", - "modified": "2024-06-26T18:30:28Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-26T18:30:28Z", "aliases": [ "CVE-2024-35545" ], "details": "MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T18:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json b/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json index 3a28a6289d1..a0d073bbb90 100644 --- a/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json +++ b/advisories/unreviewed/2024/06/GHSA-r4g5-x2h5-r8gg/GHSA-r4g5-x2h5-r8gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4g5-x2h5-r8gg", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38550" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: kirkwood: Fix potential NULL dereference\n\nIn kirkwood_dma_hw_params() mv_mbus_dram_info() returns NULL if\nCONFIG_PLAT_ORION macro is not defined.\nFix this bug by adding NULL check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6f25-rhcc-g7hw/GHSA-6f25-rhcc-g7hw.json b/advisories/unreviewed/2024/07/GHSA-6f25-rhcc-g7hw/GHSA-6f25-rhcc-g7hw.json index 2fa42b7b07b..5414f8c2bab 100644 --- a/advisories/unreviewed/2024/07/GHSA-6f25-rhcc-g7hw/GHSA-6f25-rhcc-g7hw.json +++ b/advisories/unreviewed/2024/07/GHSA-6f25-rhcc-g7hw/GHSA-6f25-rhcc-g7hw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f25-rhcc-g7hw", - "modified": "2024-07-26T18:30:38Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-07-26T18:30:38Z", "aliases": [ "CVE-2024-27358" ], "details": "An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security through 23.x for macOS. Local users can block an admin from completing an installation, aka a Denial-of-Service (DoS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-26T17:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-22g9-2j29-w93q/GHSA-22g9-2j29-w93q.json b/advisories/unreviewed/2024/10/GHSA-22g9-2j29-w93q/GHSA-22g9-2j29-w93q.json index 18e3ca17aa4..a789ee16a97 100644 --- a/advisories/unreviewed/2024/10/GHSA-22g9-2j29-w93q/GHSA-22g9-2j29-w93q.json +++ b/advisories/unreviewed/2024/10/GHSA-22g9-2j29-w93q/GHSA-22g9-2j29-w93q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22g9-2j29-w93q", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50088" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix uninitialized pointer free in add_inode_ref()\n\nThe add_inode_ref() function does not initialize the \"name\" struct when\nit is declared. If any of the following calls to \"read_one_inode()\nreturns NULL,\n\n\tdir = read_one_inode(root, parent_objectid);\n\tif (!dir) {\n\t\tret = -ENOENT;\n\t\tgoto out;\n\t}\n\n\tinode = read_one_inode(root, inode_objectid);\n\tif (!inode) {\n\t\tret = -EIO;\n\t\tgoto out;\n\t}\n\nthen \"name.name\" would be freed on \"out\" before being initialized.\n\nout:\n\t...\n\tkfree(name.name);\n\nThis issue was reported by Coverity with CID 1526744.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-824" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2hgc-9gxp-9fq8/GHSA-2hgc-9gxp-9fq8.json b/advisories/unreviewed/2024/10/GHSA-2hgc-9gxp-9fq8/GHSA-2hgc-9gxp-9fq8.json index 1821df82972..8cd048ef28f 100644 --- a/advisories/unreviewed/2024/10/GHSA-2hgc-9gxp-9fq8/GHSA-2hgc-9gxp-9fq8.json +++ b/advisories/unreviewed/2024/10/GHSA-2hgc-9gxp-9fq8/GHSA-2hgc-9gxp-9fq8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-3f7c-8v7j-hgxr/GHSA-3f7c-8v7j-hgxr.json b/advisories/unreviewed/2024/10/GHSA-3f7c-8v7j-hgxr/GHSA-3f7c-8v7j-hgxr.json index 6266c79159a..18958b0d0a6 100644 --- a/advisories/unreviewed/2024/10/GHSA-3f7c-8v7j-hgxr/GHSA-3f7c-8v7j-hgxr.json +++ b/advisories/unreviewed/2024/10/GHSA-3f7c-8v7j-hgxr/GHSA-3f7c-8v7j-hgxr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f7c-8v7j-hgxr", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-51065" ], "details": "Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-48wg-55fj-pvx6/GHSA-48wg-55fj-pvx6.json b/advisories/unreviewed/2024/10/GHSA-48wg-55fj-pvx6/GHSA-48wg-55fj-pvx6.json index 8ddca7f63d0..3ffe578dca9 100644 --- a/advisories/unreviewed/2024/10/GHSA-48wg-55fj-pvx6/GHSA-48wg-55fj-pvx6.json +++ b/advisories/unreviewed/2024/10/GHSA-48wg-55fj-pvx6/GHSA-48wg-55fj-pvx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48wg-55fj-pvx6", - "modified": "2024-10-21T21:30:49Z", + "modified": "2024-11-01T18:31:27Z", "published": "2024-10-21T21:30:49Z", "aliases": [ "CVE-2024-50007" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: asihpi: Fix potential OOB array access\n\nASIHPI driver stores some values in the static array upon a response\nfrom the driver, and its index depends on the firmware. We shouldn't\ntrust it blindly.\n\nThis patch adds a sanity check of the array index to fit in the array\nsize.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4qxh-72x2-v8fc/GHSA-4qxh-72x2-v8fc.json b/advisories/unreviewed/2024/10/GHSA-4qxh-72x2-v8fc/GHSA-4qxh-72x2-v8fc.json index a163a88f17d..fb15965899e 100644 --- a/advisories/unreviewed/2024/10/GHSA-4qxh-72x2-v8fc/GHSA-4qxh-72x2-v8fc.json +++ b/advisories/unreviewed/2024/10/GHSA-4qxh-72x2-v8fc/GHSA-4qxh-72x2-v8fc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qxh-72x2-v8fc", - "modified": "2024-10-30T00:31:05Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-30T00:31:05Z", "aliases": [ "CVE-2024-8896" diff --git a/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json b/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json index 896b5588683..c9a36ebd0ed 100644 --- a/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json +++ b/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4xwj-gw53-4w3v", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49974" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Limit the number of concurrent async COPY operations\n\nNothing appears to limit the number of concurrent async COPY\noperations that clients can start. In addition, AFAICT each async\nCOPY can copy an unlimited number of 4MB chunks, so can run for a\nlong time. Thus IMO async COPY can become a DoS vector.\n\nAdd a restriction mechanism that bounds the number of concurrent\nbackground COPY operations. Start simple and try to be fair -- this\npatch implements a per-namespace limit.\n\nAn async COPY request that occurs while this limit is exceeded gets\nNFS4ERR_DELAY. The requesting client can choose to send the request\nagain after a delay or fall back to a traditional read/write style\ncopy.\n\nIf there is need to make the mechanism more sophisticated, we can\nvisit that in future patches.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-55gj-r32f-c39x/GHSA-55gj-r32f-c39x.json b/advisories/unreviewed/2024/10/GHSA-55gj-r32f-c39x/GHSA-55gj-r32f-c39x.json index f6dc60c14d8..50e115ab7a2 100644 --- a/advisories/unreviewed/2024/10/GHSA-55gj-r32f-c39x/GHSA-55gj-r32f-c39x.json +++ b/advisories/unreviewed/2024/10/GHSA-55gj-r32f-c39x/GHSA-55gj-r32f-c39x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5xfg-p7qv-vv3x/GHSA-5xfg-p7qv-vv3x.json b/advisories/unreviewed/2024/10/GHSA-5xfg-p7qv-vv3x/GHSA-5xfg-p7qv-vv3x.json index fcb1a78fa29..fd2aab3cd94 100644 --- a/advisories/unreviewed/2024/10/GHSA-5xfg-p7qv-vv3x/GHSA-5xfg-p7qv-vv3x.json +++ b/advisories/unreviewed/2024/10/GHSA-5xfg-p7qv-vv3x/GHSA-5xfg-p7qv-vv3x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-635w-qqhj-gvhx/GHSA-635w-qqhj-gvhx.json b/advisories/unreviewed/2024/10/GHSA-635w-qqhj-gvhx/GHSA-635w-qqhj-gvhx.json index fd4cf031e62..f54f5f75a3f 100644 --- a/advisories/unreviewed/2024/10/GHSA-635w-qqhj-gvhx/GHSA-635w-qqhj-gvhx.json +++ b/advisories/unreviewed/2024/10/GHSA-635w-qqhj-gvhx/GHSA-635w-qqhj-gvhx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-635w-qqhj-gvhx", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-39332" ], "details": "Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-643h-952w-33f5/GHSA-643h-952w-33f5.json b/advisories/unreviewed/2024/10/GHSA-643h-952w-33f5/GHSA-643h-952w-33f5.json index dc60c0ecb0a..67a10996f0a 100644 --- a/advisories/unreviewed/2024/10/GHSA-643h-952w-33f5/GHSA-643h-952w-33f5.json +++ b/advisories/unreviewed/2024/10/GHSA-643h-952w-33f5/GHSA-643h-952w-33f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-643h-952w-33f5", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50072" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Use code segment selector for VERW operand\n\nRobert Gill reported below #GP in 32-bit mode when dosemu software was\nexecuting vm86() system call:\n\n general protection fault: 0000 [#1] PREEMPT SMP\n CPU: 4 PID: 4610 Comm: dosemu.bin Not tainted 6.6.21-gentoo-x86 #1\n Hardware name: Dell Inc. PowerEdge 1950/0H723K, BIOS 2.7.0 10/30/2010\n EIP: restore_all_switch_stack+0xbe/0xcf\n EAX: 00000000 EBX: 00000000 ECX: 00000000 EDX: 00000000\n ESI: 00000000 EDI: 00000000 EBP: 00000000 ESP: ff8affdc\n DS: 0000 ES: 0000 FS: 0000 GS: 0033 SS: 0068 EFLAGS: 00010046\n CR0: 80050033 CR2: 00c2101c CR3: 04b6d000 CR4: 000406d0\n Call Trace:\n show_regs+0x70/0x78\n die_addr+0x29/0x70\n exc_general_protection+0x13c/0x348\n exc_bounds+0x98/0x98\n handle_exception+0x14d/0x14d\n exc_bounds+0x98/0x98\n restore_all_switch_stack+0xbe/0xcf\n exc_bounds+0x98/0x98\n restore_all_switch_stack+0xbe/0xcf\n\nThis only happens in 32-bit mode when VERW based mitigations like MDS/RFDS\nare enabled. This is because segment registers with an arbitrary user value\ncan result in #GP when executing VERW. Intel SDM vol. 2C documents the\nfollowing behavior for VERW instruction:\n\n #GP(0) - If a memory operand effective address is outside the CS, DS, ES,\n\t FS, or GS segment limit.\n\nCLEAR_CPU_BUFFERS macro executes VERW instruction before returning to user\nspace. Use %cs selector to reference VERW operand. This ensures VERW will\nnot #GP for an arbitrary user %ds.\n\n[ mingo: Fixed the SOB chain. ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6gp9-mxjv-gqwr/GHSA-6gp9-mxjv-gqwr.json b/advisories/unreviewed/2024/10/GHSA-6gp9-mxjv-gqwr/GHSA-6gp9-mxjv-gqwr.json index 1fece5ffe69..afb251b0600 100644 --- a/advisories/unreviewed/2024/10/GHSA-6gp9-mxjv-gqwr/GHSA-6gp9-mxjv-gqwr.json +++ b/advisories/unreviewed/2024/10/GHSA-6gp9-mxjv-gqwr/GHSA-6gp9-mxjv-gqwr.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-6rhp-8rx2-2869/GHSA-6rhp-8rx2-2869.json b/advisories/unreviewed/2024/10/GHSA-6rhp-8rx2-2869/GHSA-6rhp-8rx2-2869.json index 5aa3c949d38..7e755566458 100644 --- a/advisories/unreviewed/2024/10/GHSA-6rhp-8rx2-2869/GHSA-6rhp-8rx2-2869.json +++ b/advisories/unreviewed/2024/10/GHSA-6rhp-8rx2-2869/GHSA-6rhp-8rx2-2869.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6rhp-8rx2-2869", - "modified": "2024-10-21T21:30:49Z", + "modified": "2024-11-01T18:31:27Z", "published": "2024-10-21T21:30:49Z", "aliases": [ "CVE-2024-50006" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix i_data_sem unlock order in ext4_ind_migrate()\n\nFuzzing reports a possible deadlock in jbd2_log_wait_commit.\n\nThis issue is triggered when an EXT4_IOC_MIGRATE ioctl is set to require\nsynchronous updates because the file descriptor is opened with O_SYNC.\nThis can lead to the jbd2_journal_stop() function calling\njbd2_might_wait_for_commit(), potentially causing a deadlock if the\nEXT4_IOC_MIGRATE call races with a write(2) system call.\n\nThis problem only arises when CONFIG_PROVE_LOCKING is enabled. In this\ncase, the jbd2_might_wait_for_commit macro locks jbd2_handle in the\njbd2_journal_stop function while i_data_sem is locked. This triggers\nlockdep because the jbd2_journal_start function might also lock the same\njbd2_handle simultaneously.\n\nFound by Linux Verification Center (linuxtesting.org) with syzkaller.\n\nRule: add", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7368-g948-r7pg/GHSA-7368-g948-r7pg.json b/advisories/unreviewed/2024/10/GHSA-7368-g948-r7pg/GHSA-7368-g948-r7pg.json index 248e65ac89e..1c2f7a17c37 100644 --- a/advisories/unreviewed/2024/10/GHSA-7368-g948-r7pg/GHSA-7368-g948-r7pg.json +++ b/advisories/unreviewed/2024/10/GHSA-7368-g948-r7pg/GHSA-7368-g948-r7pg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7368-g948-r7pg", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-51060" ], "details": "Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-74p3-prxf-24w8/GHSA-74p3-prxf-24w8.json b/advisories/unreviewed/2024/10/GHSA-74p3-prxf-24w8/GHSA-74p3-prxf-24w8.json index 9775ed0b6cc..8d521431bfb 100644 --- a/advisories/unreviewed/2024/10/GHSA-74p3-prxf-24w8/GHSA-74p3-prxf-24w8.json +++ b/advisories/unreviewed/2024/10/GHSA-74p3-prxf-24w8/GHSA-74p3-prxf-24w8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-76p7-w946-wvch/GHSA-76p7-w946-wvch.json b/advisories/unreviewed/2024/10/GHSA-76p7-w946-wvch/GHSA-76p7-w946-wvch.json index 503c88107c5..0f1d744b635 100644 --- a/advisories/unreviewed/2024/10/GHSA-76p7-w946-wvch/GHSA-76p7-w946-wvch.json +++ b/advisories/unreviewed/2024/10/GHSA-76p7-w946-wvch/GHSA-76p7-w946-wvch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76p7-w946-wvch", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: Fix use-after-free in gsm_cleanup_mux\n\nBUG: KASAN: slab-use-after-free in gsm_cleanup_mux+0x77b/0x7b0\ndrivers/tty/n_gsm.c:3160 [n_gsm]\nRead of size 8 at addr ffff88815fe99c00 by task poc/3379\nCPU: 0 UID: 0 PID: 3379 Comm: poc Not tainted 6.11.0+ #56\nHardware name: VMware, Inc. VMware Virtual Platform/440BX\nDesktop Reference Platform, BIOS 6.00 11/12/2020\nCall Trace:\n \n gsm_cleanup_mux+0x77b/0x7b0 drivers/tty/n_gsm.c:3160 [n_gsm]\n __pfx_gsm_cleanup_mux+0x10/0x10 drivers/tty/n_gsm.c:3124 [n_gsm]\n __pfx_sched_clock_cpu+0x10/0x10 kernel/sched/clock.c:389\n update_load_avg+0x1c1/0x27b0 kernel/sched/fair.c:4500\n __pfx_min_vruntime_cb_rotate+0x10/0x10 kernel/sched/fair.c:846\n __rb_insert_augmented+0x492/0xbf0 lib/rbtree.c:161\n gsmld_ioctl+0x395/0x1450 drivers/tty/n_gsm.c:3408 [n_gsm]\n _raw_spin_lock_irqsave+0x92/0xf0 arch/x86/include/asm/atomic.h:107\n __pfx_gsmld_ioctl+0x10/0x10 drivers/tty/n_gsm.c:3822 [n_gsm]\n ktime_get+0x5e/0x140 kernel/time/timekeeping.c:195\n ldsem_down_read+0x94/0x4e0 arch/x86/include/asm/atomic64_64.h:79\n __pfx_ldsem_down_read+0x10/0x10 drivers/tty/tty_ldsem.c:338\n __pfx_do_vfs_ioctl+0x10/0x10 fs/ioctl.c:805\n tty_ioctl+0x643/0x1100 drivers/tty/tty_io.c:2818\n\nAllocated by task 65:\n gsm_data_alloc.constprop.0+0x27/0x190 drivers/tty/n_gsm.c:926 [n_gsm]\n gsm_send+0x2c/0x580 drivers/tty/n_gsm.c:819 [n_gsm]\n gsm1_receive+0x547/0xad0 drivers/tty/n_gsm.c:3038 [n_gsm]\n gsmld_receive_buf+0x176/0x280 drivers/tty/n_gsm.c:3609 [n_gsm]\n tty_ldisc_receive_buf+0x101/0x1e0 drivers/tty/tty_buffer.c:391\n tty_port_default_receive_buf+0x61/0xa0 drivers/tty/tty_port.c:39\n flush_to_ldisc+0x1b0/0x750 drivers/tty/tty_buffer.c:445\n process_scheduled_works+0x2b0/0x10d0 kernel/workqueue.c:3229\n worker_thread+0x3dc/0x950 kernel/workqueue.c:3391\n kthread+0x2a3/0x370 kernel/kthread.c:389\n ret_from_fork+0x2d/0x70 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:257\n\nFreed by task 3367:\n kfree+0x126/0x420 mm/slub.c:4580\n gsm_cleanup_mux+0x36c/0x7b0 drivers/tty/n_gsm.c:3160 [n_gsm]\n gsmld_ioctl+0x395/0x1450 drivers/tty/n_gsm.c:3408 [n_gsm]\n tty_ioctl+0x643/0x1100 drivers/tty/tty_io.c:2818\n\n[Analysis]\ngsm_msg on the tx_ctrl_list or tx_data_list of gsm_mux\ncan be freed by multi threads through ioctl,which leads\nto the occurrence of uaf. Protect it by gsm tx lock.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-82vq-g77c-v2h9/GHSA-82vq-g77c-v2h9.json b/advisories/unreviewed/2024/10/GHSA-82vq-g77c-v2h9/GHSA-82vq-g77c-v2h9.json index 66a0008c86a..e31fff21790 100644 --- a/advisories/unreviewed/2024/10/GHSA-82vq-g77c-v2h9/GHSA-82vq-g77c-v2h9.json +++ b/advisories/unreviewed/2024/10/GHSA-82vq-g77c-v2h9/GHSA-82vq-g77c-v2h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82vq-g77c-v2h9", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50076" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt: prevent kernel-infoleak in con_font_get()\n\nfont.data may not initialize all memory spaces depending on the implementation\nof vc->vc_sw->con_font_get. This may cause info-leak, so to prevent this, it\nis safest to modify it to initialize the allocated memory space to 0, and it\ngenerally does not affect the overall performance of the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-909" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8993-6q23-6mm7/GHSA-8993-6q23-6mm7.json b/advisories/unreviewed/2024/10/GHSA-8993-6q23-6mm7/GHSA-8993-6q23-6mm7.json index 5cbf92c52b9..1c374696a31 100644 --- a/advisories/unreviewed/2024/10/GHSA-8993-6q23-6mm7/GHSA-8993-6q23-6mm7.json +++ b/advisories/unreviewed/2024/10/GHSA-8993-6q23-6mm7/GHSA-8993-6q23-6mm7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8pxm-8fqw-jp9p/GHSA-8pxm-8fqw-jp9p.json b/advisories/unreviewed/2024/10/GHSA-8pxm-8fqw-jp9p/GHSA-8pxm-8fqw-jp9p.json index eda0d22babf..5805908c8c5 100644 --- a/advisories/unreviewed/2024/10/GHSA-8pxm-8fqw-jp9p/GHSA-8pxm-8fqw-jp9p.json +++ b/advisories/unreviewed/2024/10/GHSA-8pxm-8fqw-jp9p/GHSA-8pxm-8fqw-jp9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pxm-8fqw-jp9p", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-51063" ], "details": "Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-93cx-f9gg-q2wg/GHSA-93cx-f9gg-q2wg.json b/advisories/unreviewed/2024/10/GHSA-93cx-f9gg-q2wg/GHSA-93cx-f9gg-q2wg.json index 1d4454af7dd..6fdbc79af95 100644 --- a/advisories/unreviewed/2024/10/GHSA-93cx-f9gg-q2wg/GHSA-93cx-f9gg-q2wg.json +++ b/advisories/unreviewed/2024/10/GHSA-93cx-f9gg-q2wg/GHSA-93cx-f9gg-q2wg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-95j2-w8x7-hm88/GHSA-95j2-w8x7-hm88.json b/advisories/unreviewed/2024/10/GHSA-95j2-w8x7-hm88/GHSA-95j2-w8x7-hm88.json index a15f43b6f1e..9e8bbc79742 100644 --- a/advisories/unreviewed/2024/10/GHSA-95j2-w8x7-hm88/GHSA-95j2-w8x7-hm88.json +++ b/advisories/unreviewed/2024/10/GHSA-95j2-w8x7-hm88/GHSA-95j2-w8x7-hm88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95j2-w8x7-hm88", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-39720" ], "details": "An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" + } ], "affected": [ @@ -22,6 +25,10 @@ "type": "WEB", "url": "https://github.com/ollama/ollama/compare/v0.1.45...v0.1.46#diff-782c2737eecfa83b7cb46a77c8bdaf40023e7067baccd4f806ac5517b4563131L417" }, + { + "type": "WEB", + "url": "https://oligo.security/blog/more-models-more-probllms" + }, { "type": "WEB", "url": "https://oligosecurity.webflow.io/blog/more-models-more-probllms" @@ -29,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T20:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cfxq-8762-vx3v/GHSA-cfxq-8762-vx3v.json b/advisories/unreviewed/2024/10/GHSA-cfxq-8762-vx3v/GHSA-cfxq-8762-vx3v.json index 8746065169a..f47fa286c31 100644 --- a/advisories/unreviewed/2024/10/GHSA-cfxq-8762-vx3v/GHSA-cfxq-8762-vx3v.json +++ b/advisories/unreviewed/2024/10/GHSA-cfxq-8762-vx3v/GHSA-cfxq-8762-vx3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfxq-8762-vx3v", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-39722" ], "details": "An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://oligosecurity.webflow.io/blog/more-models-more-probllms" + }, + { + "type": "WEB", + "url": "https://www.oligo.security/blog/more-models-more-probllms" } ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cpxh-jwhh-m496/GHSA-cpxh-jwhh-m496.json b/advisories/unreviewed/2024/10/GHSA-cpxh-jwhh-m496/GHSA-cpxh-jwhh-m496.json index d3449c6d2f6..0f1911c9a81 100644 --- a/advisories/unreviewed/2024/10/GHSA-cpxh-jwhh-m496/GHSA-cpxh-jwhh-m496.json +++ b/advisories/unreviewed/2024/10/GHSA-cpxh-jwhh-m496/GHSA-cpxh-jwhh-m496.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpxh-jwhh-m496", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-39719" ], "details": "An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the \"File does not exist\" error message to the attacker, providing a primitive for file existence on the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://oligosecurity.webflow.io/blog/more-models-more-probllms" + }, + { + "type": "WEB", + "url": "https://www.oligo.security/blog/more-models-more-probllms" } ], "database_specific": { "cwe_ids": [ - + "CWE-209" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T20:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json b/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json index d60e170cac4..31ae86d5fac 100644 --- a/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json +++ b/advisories/unreviewed/2024/10/GHSA-f928-7mj9-m8wx/GHSA-f928-7mj9-m8wx.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json b/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json index 09a0a1d18a2..a0828410a2c 100644 --- a/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json +++ b/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh83-rw64-jhh7", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49973" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nr8169: add tally counter fields added with RTL8125\n\nRTL8125 added fields to the tally counter, what may result in the chip\ndma'ing these new fields to unallocated memory. Therefore make sure\nthat the allocated memory area is big enough to hold all of the\ntally counter values, even if we use only parts of it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-frcc-xjfw-r9vq/GHSA-frcc-xjfw-r9vq.json b/advisories/unreviewed/2024/10/GHSA-frcc-xjfw-r9vq/GHSA-frcc-xjfw-r9vq.json index 6c9a50f399c..bf4eb5f4f7b 100644 --- a/advisories/unreviewed/2024/10/GHSA-frcc-xjfw-r9vq/GHSA-frcc-xjfw-r9vq.json +++ b/advisories/unreviewed/2024/10/GHSA-frcc-xjfw-r9vq/GHSA-frcc-xjfw-r9vq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-frcg-5998-rxxh/GHSA-frcg-5998-rxxh.json b/advisories/unreviewed/2024/10/GHSA-frcg-5998-rxxh/GHSA-frcg-5998-rxxh.json index 51100a693b0..f1b00d2f876 100644 --- a/advisories/unreviewed/2024/10/GHSA-frcg-5998-rxxh/GHSA-frcg-5998-rxxh.json +++ b/advisories/unreviewed/2024/10/GHSA-frcg-5998-rxxh/GHSA-frcg-5998-rxxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frcg-5998-rxxh", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-51064" ], "details": "Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-ggr3-2w79-8rhj/GHSA-ggr3-2w79-8rhj.json b/advisories/unreviewed/2024/10/GHSA-ggr3-2w79-8rhj/GHSA-ggr3-2w79-8rhj.json index e5e11ac407a..c885c6fa3d0 100644 --- a/advisories/unreviewed/2024/10/GHSA-ggr3-2w79-8rhj/GHSA-ggr3-2w79-8rhj.json +++ b/advisories/unreviewed/2024/10/GHSA-ggr3-2w79-8rhj/GHSA-ggr3-2w79-8rhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggr3-2w79-8rhj", - "modified": "2024-10-21T21:30:49Z", + "modified": "2024-11-01T18:31:27Z", "published": "2024-10-21T21:30:49Z", "aliases": [ "CVE-2024-50009" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: amd-pstate: add check for cpufreq_cpu_get's return value\n\ncpufreq_cpu_get may return NULL. To avoid NULL-dereference check it\nand return in case of error.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json b/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json index e29bded90df..a1c59571905 100644 --- a/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json +++ b/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-gr3v-53cp-cg7h/GHSA-gr3v-53cp-cg7h.json b/advisories/unreviewed/2024/10/GHSA-gr3v-53cp-cg7h/GHSA-gr3v-53cp-cg7h.json index 9c6257479e0..4f7a1cc5e72 100644 --- a/advisories/unreviewed/2024/10/GHSA-gr3v-53cp-cg7h/GHSA-gr3v-53cp-cg7h.json +++ b/advisories/unreviewed/2024/10/GHSA-gr3v-53cp-cg7h/GHSA-gr3v-53cp-cg7h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr3v-53cp-cg7h", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50078" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Call iso_exit() on module unload\n\nIf iso_init() has been called, iso_exit() must be called on module\nunload. Without that, the struct proto that iso_init() registered with\nproto_register() becomes invalid, which could cause unpredictable\nproblems later. In my case, with CONFIG_LIST_HARDENED and\nCONFIG_BUG_ON_DATA_CORRUPTION enabled, loading the module again usually\ntriggers this BUG():\n\n list_add corruption. next->prev should be prev (ffffffffb5355fd0),\n but was 0000000000000068. (next=ffffffffc0a010d0).\n ------------[ cut here ]------------\n kernel BUG at lib/list_debug.c:29!\n Oops: invalid opcode: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 4159 Comm: modprobe Not tainted 6.10.11-4+bt2-ao-desktop #1\n RIP: 0010:__list_add_valid_or_report+0x61/0xa0\n ...\n __list_add_valid_or_report+0x61/0xa0\n proto_register+0x299/0x320\n hci_sock_init+0x16/0xc0 [bluetooth]\n bt_init+0x68/0xd0 [bluetooth]\n __pfx_bt_init+0x10/0x10 [bluetooth]\n do_one_initcall+0x80/0x2f0\n do_init_module+0x8b/0x230\n __do_sys_init_module+0x15f/0x190\n do_syscall_64+0x68/0x110\n ...", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json b/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json index 98859860c7c..8f9cd93e45b 100644 --- a/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json +++ b/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3xr-p2v4-jv9v", - "modified": "2024-10-11T15:30:32Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-10-11T15:30:32Z", "aliases": [ "CVE-2024-45315" ], "details": "The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-59" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T13:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hjjp-8vgj-3j9q/GHSA-hjjp-8vgj-3j9q.json b/advisories/unreviewed/2024/10/GHSA-hjjp-8vgj-3j9q/GHSA-hjjp-8vgj-3j9q.json index 948949d8ebf..a4bfc848d53 100644 --- a/advisories/unreviewed/2024/10/GHSA-hjjp-8vgj-3j9q/GHSA-hjjp-8vgj-3j9q.json +++ b/advisories/unreviewed/2024/10/GHSA-hjjp-8vgj-3j9q/GHSA-hjjp-8vgj-3j9q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-hm8j-9qjw-g376/GHSA-hm8j-9qjw-g376.json b/advisories/unreviewed/2024/10/GHSA-hm8j-9qjw-g376/GHSA-hm8j-9qjw-g376.json index 725f326bd13..ad46a2326e3 100644 --- a/advisories/unreviewed/2024/10/GHSA-hm8j-9qjw-g376/GHSA-hm8j-9qjw-g376.json +++ b/advisories/unreviewed/2024/10/GHSA-hm8j-9qjw-g376/GHSA-hm8j-9qjw-g376.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hm8j-9qjw-g376", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50077" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix multiple init when debugfs is disabled\n\nIf bt_debugfs is not created successfully, which happens if either\nCONFIG_DEBUG_FS or CONFIG_DEBUG_FS_ALLOW_ALL is unset, then iso_init()\nreturns early and does not set iso_inited to true. This means that a\nsubsequent call to iso_init() will result in duplicate calls to\nproto_register(), bt_sock_register(), etc.\n\nWith CONFIG_LIST_HARDENED and CONFIG_BUG_ON_DATA_CORRUPTION enabled, the\nduplicate call to proto_register() triggers this BUG():\n\n list_add double add: new=ffffffffc0b280d0, prev=ffffffffbab56250,\n next=ffffffffc0b280d0.\n ------------[ cut here ]------------\n kernel BUG at lib/list_debug.c:35!\n Oops: invalid opcode: 0000 [#1] PREEMPT SMP PTI\n CPU: 2 PID: 887 Comm: bluetoothd Not tainted 6.10.11-1-ao-desktop #1\n RIP: 0010:__list_add_valid_or_report+0x9a/0xa0\n ...\n __list_add_valid_or_report+0x9a/0xa0\n proto_register+0x2b5/0x340\n iso_init+0x23/0x150 [bluetooth]\n set_iso_socket_func+0x68/0x1b0 [bluetooth]\n kmem_cache_free+0x308/0x330\n hci_sock_sendmsg+0x990/0x9e0 [bluetooth]\n __sock_sendmsg+0x7b/0x80\n sock_write_iter+0x9a/0x110\n do_iter_readv_writev+0x11d/0x220\n vfs_writev+0x180/0x3e0\n do_writev+0xca/0x100\n ...\n\nThis change removes the early return. The check for iso_debugfs being\nNULL was unnecessary, it is always NULL when iso_inited is false.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hxw6-pfp4-6vc8/GHSA-hxw6-pfp4-6vc8.json b/advisories/unreviewed/2024/10/GHSA-hxw6-pfp4-6vc8/GHSA-hxw6-pfp4-6vc8.json index 42ee79ecd87..69a5dd48cf3 100644 --- a/advisories/unreviewed/2024/10/GHSA-hxw6-pfp4-6vc8/GHSA-hxw6-pfp4-6vc8.json +++ b/advisories/unreviewed/2024/10/GHSA-hxw6-pfp4-6vc8/GHSA-hxw6-pfp4-6vc8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jh2f-6jmr-qxf8/GHSA-jh2f-6jmr-qxf8.json b/advisories/unreviewed/2024/10/GHSA-jh2f-6jmr-qxf8/GHSA-jh2f-6jmr-qxf8.json index 6cd11182c53..cab5ce43d4f 100644 --- a/advisories/unreviewed/2024/10/GHSA-jh2f-6jmr-qxf8/GHSA-jh2f-6jmr-qxf8.json +++ b/advisories/unreviewed/2024/10/GHSA-jh2f-6jmr-qxf8/GHSA-jh2f-6jmr-qxf8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jh2f-6jmr-qxf8", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2023-52044" ], "details": "Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json b/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json index dd9bb1d941f..6103d148cb2 100644 --- a/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json +++ b/advisories/unreviewed/2024/10/GHSA-jrcg-6c8x-ff3h/GHSA-jrcg-6c8x-ff3h.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-330" + "CWE-330", + "CWE-331" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json b/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json index 6f6131f9be1..212bb350670 100644 --- a/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json +++ b/advisories/unreviewed/2024/10/GHSA-m3gr-45jc-g2rp/GHSA-m3gr-45jc-g2rp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3gr-45jc-g2rp", - "modified": "2024-10-14T09:30:54Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-10-14T09:30:54Z", "aliases": [ "CVE-2024-46911" ], "details": "Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an escalation of privileges attack. This issue affects Apache Roller before 6.1.4.\n\nRoller users who run multi-blog/user Roller websites are recommended to upgrade to version 6.1.4, which fixes the issue.\n\nRoller 6.1.4 release announcement:  https://lists.apache.org/thread/3c3f6rwqptyw6wdc95654fq5vlosqdpw", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T09:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m72x-w5r4-mxj9/GHSA-m72x-w5r4-mxj9.json b/advisories/unreviewed/2024/10/GHSA-m72x-w5r4-mxj9/GHSA-m72x-w5r4-mxj9.json index 1382e1d53cd..8fcc30be043 100644 --- a/advisories/unreviewed/2024/10/GHSA-m72x-w5r4-mxj9/GHSA-m72x-w5r4-mxj9.json +++ b/advisories/unreviewed/2024/10/GHSA-m72x-w5r4-mxj9/GHSA-m72x-w5r4-mxj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m72x-w5r4-mxj9", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-48200" ], "details": "An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T19:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mvx2-276h-w78v/GHSA-mvx2-276h-w78v.json b/advisories/unreviewed/2024/10/GHSA-mvx2-276h-w78v/GHSA-mvx2-276h-w78v.json index 0da1c67ea4b..f190f5ccc89 100644 --- a/advisories/unreviewed/2024/10/GHSA-mvx2-276h-w78v/GHSA-mvx2-276h-w78v.json +++ b/advisories/unreviewed/2024/10/GHSA-mvx2-276h-w78v/GHSA-mvx2-276h-w78v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mvx2-276h-w78v", - "modified": "2024-10-31T21:31:45Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-31T21:31:45Z", "aliases": [ "CVE-2024-39721" ], "details": "An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,13 +32,17 @@ { "type": "WEB", "url": "https://oligosecurity.webflow.io/blog/more-models-more-probllms" + }, + { + "type": "WEB", + "url": "https://www.oligo.security/blog/more-models-more-probllms" } ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T20:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pj65-96p4-vhw4/GHSA-pj65-96p4-vhw4.json b/advisories/unreviewed/2024/10/GHSA-pj65-96p4-vhw4/GHSA-pj65-96p4-vhw4.json index 38dfd1a5e66..fcbc0df0f6c 100644 --- a/advisories/unreviewed/2024/10/GHSA-pj65-96p4-vhw4/GHSA-pj65-96p4-vhw4.json +++ b/advisories/unreviewed/2024/10/GHSA-pj65-96p4-vhw4/GHSA-pj65-96p4-vhw4.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json b/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json index 90e1c311c29..c05a53269b9 100644 --- a/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json +++ b/advisories/unreviewed/2024/10/GHSA-pj9f-9jr9-4wm7/GHSA-pj9f-9jr9-4wm7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-36" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-qr43-43pm-fwh2/GHSA-qr43-43pm-fwh2.json b/advisories/unreviewed/2024/10/GHSA-qr43-43pm-fwh2/GHSA-qr43-43pm-fwh2.json index 17a3152b824..b43d0d79358 100644 --- a/advisories/unreviewed/2024/10/GHSA-qr43-43pm-fwh2/GHSA-qr43-43pm-fwh2.json +++ b/advisories/unreviewed/2024/10/GHSA-qr43-43pm-fwh2/GHSA-qr43-43pm-fwh2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qr43-43pm-fwh2", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-11-01T18:31:27Z", "published": "2024-10-21T21:30:49Z", "aliases": [ "CVE-2024-50011" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: soc-acpi-intel-rpl-match: add missing empty item\n\nThere is no links_num in struct snd_soc_acpi_mach {}, and we test\n!link->num_adr as a condition to end the loop in hda_sdw_machine_select().\nSo an empty item in struct snd_soc_acpi_link_adr array is required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rjp6-prx7-2cj4/GHSA-rjp6-prx7-2cj4.json b/advisories/unreviewed/2024/10/GHSA-rjp6-prx7-2cj4/GHSA-rjp6-prx7-2cj4.json index f7c579ab415..701ff49a5f7 100644 --- a/advisories/unreviewed/2024/10/GHSA-rjp6-prx7-2cj4/GHSA-rjp6-prx7-2cj4.json +++ b/advisories/unreviewed/2024/10/GHSA-rjp6-prx7-2cj4/GHSA-rjp6-prx7-2cj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rjp6-prx7-2cj4", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-11-01T18:31:32Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50075" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: tegra: fix checked USB2 port number\n\nIf USB virtualizatoin is enabled, USB2 ports are shared between all\nVirtual Functions. The USB2 port number owned by an USB2 root hub in\na Virtual Function may be less than total USB2 phy number supported\nby the Tegra XUSB controller.\n\nUsing total USB2 phy number as port number to check all PORTSC values\nwould cause invalid memory access.\n\n[ 116.923438] Unable to handle kernel paging request at virtual address 006c622f7665642f\n...\n[ 117.213640] Call trace:\n[ 117.216783] tegra_xusb_enter_elpg+0x23c/0x658\n[ 117.222021] tegra_xusb_runtime_suspend+0x40/0x68\n[ 117.227260] pm_generic_runtime_suspend+0x30/0x50\n[ 117.232847] __rpm_callback+0x84/0x3c0\n[ 117.237038] rpm_suspend+0x2dc/0x740\n[ 117.241229] pm_runtime_work+0xa0/0xb8\n[ 117.245769] process_scheduled_works+0x24c/0x478\n[ 117.251007] worker_thread+0x23c/0x328\n[ 117.255547] kthread+0x104/0x1b0\n[ 117.259389] ret_from_fork+0x10/0x20\n[ 117.263582] Code: 54000222 f9461ae8 f8747908 b4ffff48 (f9400100)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v93x-fw33-f4pw/GHSA-v93x-fw33-f4pw.json b/advisories/unreviewed/2024/10/GHSA-v93x-fw33-f4pw/GHSA-v93x-fw33-f4pw.json index 053eac4937d..08dabdfe298 100644 --- a/advisories/unreviewed/2024/10/GHSA-v93x-fw33-f4pw/GHSA-v93x-fw33-f4pw.json +++ b/advisories/unreviewed/2024/10/GHSA-v93x-fw33-f4pw/GHSA-v93x-fw33-f4pw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json b/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json index 79588739630..421dc2958a1 100644 --- a/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json +++ b/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x22r-xgr5-23hh", - "modified": "2024-10-16T18:31:34Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-43683" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-improper-verification-of-host-header" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json b/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json index cd2a1049070..a58fe005b2a 100644 --- a/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json +++ b/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xr9g-f9v2-9m3h", - "modified": "2024-10-17T18:31:33Z", + "modified": "2024-11-01T18:31:26Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-43684" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-cross-site-request-forgery" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-2657-8gwf-j8hg/GHSA-2657-8gwf-j8hg.json b/advisories/unreviewed/2024/11/GHSA-2657-8gwf-j8hg/GHSA-2657-8gwf-j8hg.json new file mode 100644 index 00000000000..736794b41e2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2657-8gwf-j8hg/GHSA-2657-8gwf-j8hg.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2657-8gwf-j8hg", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:32Z", + "aliases": [ + "CVE-2024-10660" + ], + "details": "A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10660" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/9d33a5d8-87b1-482b-8642-a8fcf27585ba?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282675" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282675" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.434863" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3q78-4j93-p8qr/GHSA-3q78-4j93-p8qr.json b/advisories/unreviewed/2024/11/GHSA-3q78-4j93-p8qr/GHSA-3q78-4j93-p8qr.json new file mode 100644 index 00000000000..f898f29a671 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3q78-4j93-p8qr/GHSA-3q78-4j93-p8qr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q78-4j93-p8qr", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51252" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51252" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json b/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json new file mode 100644 index 00000000000..ae17d10a082 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-426m-8vmg-c647", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-48217" + ], + "details": "An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48217" + }, + { + "type": "WEB", + "url": "https://github.com/ajrielrm/CVE-2024-48217" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4c48-48vf-pffv/GHSA-4c48-48vf-pffv.json b/advisories/unreviewed/2024/11/GHSA-4c48-48vf-pffv/GHSA-4c48-48vf-pffv.json new file mode 100644 index 00000000000..4f9c7b8ef1d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4c48-48vf-pffv/GHSA-4c48-48vf-pffv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c48-48vf-pffv", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-22733" + ], + "details": "TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22733" + }, + { + "type": "WEB", + "url": "https://lenoctambule.dev/post/dos-on-tp-link-web-admin-panel" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4fhq-xw64-436p/GHSA-4fhq-xw64-436p.json b/advisories/unreviewed/2024/11/GHSA-4fhq-xw64-436p/GHSA-4fhq-xw64-436p.json new file mode 100644 index 00000000000..2ef470e2360 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4fhq-xw64-436p/GHSA-4fhq-xw64-436p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fhq-xw64-436p", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51244" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51244" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-798f-vv9g-f5gg/GHSA-798f-vv9g-f5gg.json b/advisories/unreviewed/2024/11/GHSA-798f-vv9g-f5gg/GHSA-798f-vv9g-f5gg.json new file mode 100644 index 00000000000..2e74f5736df --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-798f-vv9g-f5gg/GHSA-798f-vv9g-f5gg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-798f-vv9g-f5gg", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51248" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51248" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json b/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json new file mode 100644 index 00000000000..248c31c217b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7v6m-5xcw-rjqw/GHSA-7v6m-5xcw-rjqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v6m-5xcw-rjqw", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-41745" + ], + "details": "IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41745" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174576" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-94gg-72cx-mg6f/GHSA-94gg-72cx-mg6f.json b/advisories/unreviewed/2024/11/GHSA-94gg-72cx-mg6f/GHSA-94gg-72cx-mg6f.json new file mode 100644 index 00000000000..3d13bd8c9a7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-94gg-72cx-mg6f/GHSA-94gg-72cx-mg6f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94gg-72cx-mg6f", + "modified": "2024-11-01T18:31:32Z", + "published": "2024-11-01T18:31:32Z", + "aliases": [ + "CVE-2024-40490" + ], + "details": "An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40490" + }, + { + "type": "WEB", + "url": "https://github.com/sbpp/sourcebans-pp/issues/975" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c5hw-25wh-7q5r/GHSA-c5hw-25wh-7q5r.json b/advisories/unreviewed/2024/11/GHSA-c5hw-25wh-7q5r/GHSA-c5hw-25wh-7q5r.json new file mode 100644 index 00000000000..27dee570302 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c5hw-25wh-7q5r/GHSA-c5hw-25wh-7q5r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5hw-25wh-7q5r", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-48410" + ], + "details": "Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48410" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Youns92/e7cd3f5d18ab089320f72c51fa3977de" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f96w-x82r-jx85/GHSA-f96w-x82r-jx85.json b/advisories/unreviewed/2024/11/GHSA-f96w-x82r-jx85/GHSA-f96w-x82r-jx85.json new file mode 100644 index 00000000000..16c08d12e51 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f96w-x82r-jx85/GHSA-f96w-x82r-jx85.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f96w-x82r-jx85", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51247" + ], + "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51247" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g38v-wv6x-qc6c/GHSA-g38v-wv6x-qc6c.json b/advisories/unreviewed/2024/11/GHSA-g38v-wv6x-qc6c/GHSA-g38v-wv6x-qc6c.json new file mode 100644 index 00000000000..aef78301767 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g38v-wv6x-qc6c/GHSA-g38v-wv6x-qc6c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g38v-wv6x-qc6c", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51432" + ], + "details": "Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51432" + }, + { + "type": "WEB", + "url": "https://en.fiberhome.com" + }, + { + "type": "WEB", + "url": "https://github.com/MatJosephs/CVEs/tree/main/CVE-2024-51432" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json b/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json new file mode 100644 index 00000000000..7f1f9d646fa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hrrg-wvpp-2p2q/GHSA-hrrg-wvpp-2p2q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrrg-wvpp-2p2q", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-28265" + ], + "details": "IBOS v4.5.5 has an arbitrary file deletion vulnerability via \\system\\modules\\dashboard\\controllers\\LoginController.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28265" + }, + { + "type": "WEB", + "url": "https://github.com/A7cc/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://gitee.com/ibos/IBOS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json b/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json new file mode 100644 index 00000000000..e0ef0681813 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j6r2-9gj9-jmvp/GHSA-j6r2-9gj9-jmvp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6r2-9gj9-jmvp", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-41738" + ], + "details": "IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41738" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174572" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-598" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m3v4-qcj6-c3h3/GHSA-m3v4-qcj6-c3h3.json b/advisories/unreviewed/2024/11/GHSA-m3v4-qcj6-c3h3/GHSA-m3v4-qcj6-c3h3.json new file mode 100644 index 00000000000..b2c82263887 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m3v4-qcj6-c3h3/GHSA-m3v4-qcj6-c3h3.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3v4-qcj6-c3h3", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-10661" + ], + "details": "A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argument scanList leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10661" + }, + { + "type": "WEB", + "url": "https://github.com/theRaz0r/iot-mycve/blob/main/tenda_ac15_stackflow_formDLNAserver/tenda_ac15_stackflow_formDLNAserver.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282676" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282676" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.434932" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m6q8-w66q-7qgr/GHSA-m6q8-w66q-7qgr.json b/advisories/unreviewed/2024/11/GHSA-m6q8-w66q-7qgr/GHSA-m6q8-w66q-7qgr.json new file mode 100644 index 00000000000..d6993ea4580 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m6q8-w66q-7qgr/GHSA-m6q8-w66q-7qgr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6q8-w66q-7qgr", + "modified": "2024-11-01T18:31:32Z", + "published": "2024-11-01T18:31:32Z", + "aliases": [ + "CVE-2024-10659" + ], + "details": "A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthoriseTempletService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10659" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/eaefcf21-6a72-48f8-bc18-a4889512bfe5?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.434862" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mw4g-w7hh-rjpc/GHSA-mw4g-w7hh-rjpc.json b/advisories/unreviewed/2024/11/GHSA-mw4g-w7hh-rjpc/GHSA-mw4g-w7hh-rjpc.json new file mode 100644 index 00000000000..fb2a6bf84e7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mw4g-w7hh-rjpc/GHSA-mw4g-w7hh-rjpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw4g-w7hh-rjpc", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-41741" + ], + "details": "IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41741" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174572" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p4mp-f632-xp5q/GHSA-p4mp-f632-xp5q.json b/advisories/unreviewed/2024/11/GHSA-p4mp-f632-xp5q/GHSA-p4mp-f632-xp5q.json new file mode 100644 index 00000000000..d2207605e2b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p4mp-f632-xp5q/GHSA-p4mp-f632-xp5q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4mp-f632-xp5q", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:32Z", + "aliases": [ + "CVE-2024-51377" + ], + "details": "An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51377" + }, + { + "type": "WEB", + "url": "https://github.com/ladybirdweb/faveo-helpdesk/issues/8303" + }, + { + "type": "WEB", + "url": "https://github.com/Asadiqbal2/Vulnerabilities-Research/tree/main/CVE-2024-51377" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-prm4-7jr7-cm97/GHSA-prm4-7jr7-cm97.json b/advisories/unreviewed/2024/11/GHSA-prm4-7jr7-cm97/GHSA-prm4-7jr7-cm97.json new file mode 100644 index 00000000000..c54ecf18aff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-prm4-7jr7-cm97/GHSA-prm4-7jr7-cm97.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prm4-7jr7-cm97", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51431" + ], + "details": "LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51431" + }, + { + "type": "WEB", + "url": "https://github.com/MatJosephs/CVEs/tree/main/CVE-2024-51431" + }, + { + "type": "WEB", + "url": "https://www.lb-link.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json b/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json new file mode 100644 index 00000000000..fc1b1d77262 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rcx3-jx8c-54gq/GHSA-rcx3-jx8c-54gq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcx3-jx8c-54gq", + "modified": "2024-11-01T18:31:32Z", + "published": "2024-11-01T18:31:32Z", + "aliases": [ + "CVE-2024-51398" + ], + "details": "Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51398" + }, + { + "type": "WEB", + "url": "https://github.com/HuhaiOvO/Altai/blob/main/Altai%20IX500%20Indoor%202%C3%972%20802.11ac%20Wave%202%20AP%20wake%20password.docx" + }, + { + "type": "WEB", + "url": "https://github.com/HuhaiOvO/Altai/blob/main/Altai_IX500_Weak_Password.yaml" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json b/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json new file mode 100644 index 00000000000..6f62f63b2cd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rfpm-vfqf-wj57/GHSA-rfpm-vfqf-wj57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfpm-vfqf-wj57", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-41744" + ], + "details": "IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41744" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174576" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json b/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json new file mode 100644 index 00000000000..8450c501607 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rrg7-hv9c-7q66/GHSA-rrg7-hv9c-7q66.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrg7-hv9c-7q66", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51399" + ], + "details": "Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can lead to data breaches and identity theft.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51399" + }, + { + "type": "WEB", + "url": "https://github.com/HuhaiOvO/Altai/blob/main/Altai%20IX500%20Indoor%202%C3%972%20802.11ac%20Wave%202%20AP%20file%20read.docx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json b/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json new file mode 100644 index 00000000000..78a16c226fa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vvmx-2vhq-c359/GHSA-vvmx-2vhq-c359.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvmx-2vhq-c359", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-48352" + ], + "details": "Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48352" + }, + { + "type": "WEB", + "url": "https://www.yealink.com/en/trust-center/security-advisories/e5c848c55b894231" + }, + { + "type": "WEB", + "url": "http://yealink.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json b/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json new file mode 100644 index 00000000000..77f07881c00 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x4vq-mwg4-r55q/GHSA-x4vq-mwg4-r55q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4vq-mwg4-r55q", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-48353" + ], + "details": "Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48353" + }, + { + "type": "WEB", + "url": "https://www.yealink.com/en/trust-center/security-advisories/b1998ab629254ca3" + }, + { + "type": "WEB", + "url": "http://yealink.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xfcf-4825-2xx2/GHSA-xfcf-4825-2xx2.json b/advisories/unreviewed/2024/11/GHSA-xfcf-4825-2xx2/GHSA-xfcf-4825-2xx2.json new file mode 100644 index 00000000000..8c7383c3d0e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xfcf-4825-2xx2/GHSA-xfcf-4825-2xx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfcf-4825-2xx2", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-51245" + ], + "details": "In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51245" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xmg5-8cgx-r6mh/GHSA-xmg5-8cgx-r6mh.json b/advisories/unreviewed/2024/11/GHSA-xmg5-8cgx-r6mh/GHSA-xmg5-8cgx-r6mh.json new file mode 100644 index 00000000000..03a7c0549a5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xmg5-8cgx-r6mh/GHSA-xmg5-8cgx-r6mh.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmg5-8cgx-r6mh", + "modified": "2024-11-01T18:31:33Z", + "published": "2024-11-01T18:31:33Z", + "aliases": [ + "CVE-2024-10662" + ], + "details": "A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10662" + }, + { + "type": "WEB", + "url": "https://github.com/theRaz0r/iot-mycve/blob/main/tenda_ac15_stackflow_formSetDeviceName/tenda_ac15_stackflow_formSetDeviceName.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282677" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282677" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.434933" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-01T16:15:07Z" + } +} \ No newline at end of file