diff --git a/advisories/unreviewed/2022/03/GHSA-5q32-jq5j-qxmw/GHSA-5q32-jq5j-qxmw.json b/advisories/unreviewed/2022/03/GHSA-5q32-jq5j-qxmw/GHSA-5q32-jq5j-qxmw.json index 0544c01c72a..f330b6a9dad 100644 --- a/advisories/unreviewed/2022/03/GHSA-5q32-jq5j-qxmw/GHSA-5q32-jq5j-qxmw.json +++ b/advisories/unreviewed/2022/03/GHSA-5q32-jq5j-qxmw/GHSA-5q32-jq5j-qxmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5q32-jq5j-qxmw", - "modified": "2022-03-29T00:01:27Z", + "modified": "2024-11-18T18:30:47Z", "published": "2022-03-22T00:00:41Z", "aliases": [ "CVE-2022-26494" @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://doc.primekey.com/signserver" }, + { + "type": "WEB", + "url": "https://docs.keyfactor.com/signserver" + }, + { + "type": "WEB", + "url": "https://support.keyfactor.com/hc/en-us/articles/15618125602715-Security-Advisory-SignServer-Cross-site-scripting-issue-in-Admin-Web" + }, { "type": "WEB", "url": "https://support.primekey.com/news/posts/signserver-security-advisory-cross-site-scripting-issue-in-admin-web" diff --git a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json index 8aebda60391..7f9f923659b 100644 --- a/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json +++ b/advisories/unreviewed/2024/08/GHSA-53h7-ghj7-7gh9/GHSA-53h7-ghj7-7gh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53h7-ghj7-7gh9", - "modified": "2024-08-19T18:32:06Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-42677" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42677" }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-42677.md" + }, { "type": "WEB", "url": "https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZlfi.md" diff --git a/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json b/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json index 323592c82ec..94dfd23f31f 100644 --- a/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json +++ b/advisories/unreviewed/2024/08/GHSA-pcmw-xjj4-jxjp/GHSA-pcmw-xjj4-jxjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcmw-xjj4-jxjp", - "modified": "2024-08-15T18:31:51Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-08-15T15:30:58Z", "aliases": [ "CVE-2024-42678" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42678" }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-42678.md" + }, { "type": "WEB", "url": "https://github.com/WarmBrew/web_vul/blob/main/CYGLXT/CYxss.md" diff --git a/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json b/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json index 898d657db2e..3cc74a59653 100644 --- a/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json +++ b/advisories/unreviewed/2024/08/GHSA-v587-qwh9-6xx3/GHSA-v587-qwh9-6xx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v587-qwh9-6xx3", - "modified": "2024-08-28T21:31:28Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-08-28T21:31:28Z", "aliases": [ "CVE-2024-44761" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44761" }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-44761.md" + }, { "type": "WEB", "url": "https://github.com/WarmBrew/web_vul/blob/main/EQ/EQEMS.md" diff --git a/advisories/unreviewed/2024/11/GHSA-23p9-75pp-2wv4/GHSA-23p9-75pp-2wv4.json b/advisories/unreviewed/2024/11/GHSA-23p9-75pp-2wv4/GHSA-23p9-75pp-2wv4.json new file mode 100644 index 00000000000..6f7e0bb127b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-23p9-75pp-2wv4/GHSA-23p9-75pp-2wv4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23p9-75pp-2wv4", + "modified": "2024-11-18T18:30:55Z", + "published": "2024-11-18T18:30:55Z", + "aliases": [ + "CVE-2020-26063" + ], + "details": "A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization.\nThe vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit this vulnerability by sending malicious requests to an API endpoint. An exploit could allow the attacker to download files from or modify limited configuration options on the affected system.There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26063" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-zWkppJxL" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanx3-vrZbOqqD" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vsoln-arbfile-gtsEYxns" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-teams-xss-zLW9tD3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-23w3-wj92-2gp6/GHSA-23w3-wj92-2gp6.json b/advisories/unreviewed/2024/11/GHSA-23w3-wj92-2gp6/GHSA-23w3-wj92-2gp6.json new file mode 100644 index 00000000000..2d545735c42 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-23w3-wj92-2gp6/GHSA-23w3-wj92-2gp6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23w3-wj92-2gp6", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52573" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24521)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52573" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-278j-256r-v8r4/GHSA-278j-256r-v8r4.json b/advisories/unreviewed/2024/11/GHSA-278j-256r-v8r4/GHSA-278j-256r-v8r4.json new file mode 100644 index 00000000000..d2b8618e017 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-278j-256r-v8r4/GHSA-278j-256r-v8r4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-278j-256r-v8r4", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1285" + ], + "details": "Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.\nThe vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly.Note: Manual intervention is required to recover from this situation. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recover a device in this condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1285" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-27f6-xp4g-2f3x/GHSA-27f6-xp4g-2f3x.json b/advisories/unreviewed/2024/11/GHSA-27f6-xp4g-2f3x/GHSA-27f6-xp4g-2f3x.json new file mode 100644 index 00000000000..d99f3ae5175 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-27f6-xp4g-2f3x/GHSA-27f6-xp4g-2f3x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27f6-xp4g-2f3x", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52567" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24237)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52567" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-373m-459c-25jg/GHSA-373m-459c-25jg.json b/advisories/unreviewed/2024/11/GHSA-373m-459c-25jg/GHSA-373m-459c-25jg.json new file mode 100644 index 00000000000..3273de8ea2c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-373m-459c-25jg/GHSA-373m-459c-25jg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-373m-459c-25jg", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52422" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Terry Lin WP Githuber MD allows Stored XSS.This issue affects WP Githuber MD: from n/a through 1.16.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-githuber-md/wordpress-wp-githuber-md-plugin-1-16-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3fvw-4j76-wpj7/GHSA-3fvw-4j76-wpj7.json b/advisories/unreviewed/2024/11/GHSA-3fvw-4j76-wpj7/GHSA-3fvw-4j76-wpj7.json index 6f6866ea94b..03a90f0c383 100644 --- a/advisories/unreviewed/2024/11/GHSA-3fvw-4j76-wpj7/GHSA-3fvw-4j76-wpj7.json +++ b/advisories/unreviewed/2024/11/GHSA-3fvw-4j76-wpj7/GHSA-3fvw-4j76-wpj7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3fvw-4j76-wpj7", - "modified": "2024-11-18T06:30:36Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:36Z", "aliases": [ "CVE-2024-52922" ], "details": "In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stalls instead of complying with the peer-to-peer protocol specification.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3m64-79r5-56f2/GHSA-3m64-79r5-56f2.json b/advisories/unreviewed/2024/11/GHSA-3m64-79r5-56f2/GHSA-3m64-79r5-56f2.json index d75f912f1f6..e441cd06186 100644 --- a/advisories/unreviewed/2024/11/GHSA-3m64-79r5-56f2/GHSA-3m64-79r5-56f2.json +++ b/advisories/unreviewed/2024/11/GHSA-3m64-79r5-56f2/GHSA-3m64-79r5-56f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3m64-79r5-56f2", - "modified": "2024-11-18T09:31:14Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T09:31:14Z", "aliases": [ "CVE-2024-45791" ], "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat.\n\nThis issue affects Apache HertzBeat: before 1.6.1.\n\nUsers are recommended to upgrade to version 1.6.1, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T09:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json b/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json index faf03149369..aa8a3fd9ccc 100644 --- a/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json +++ b/advisories/unreviewed/2024/11/GHSA-3wf4-68gx-mph8/GHSA-3wf4-68gx-mph8.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wf4-68gx-mph8", - "modified": "2024-11-18T12:30:42Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T12:30:42Z", "aliases": [ "CVE-2024-11023" ], "details": "Firebase JavaScript SDK utilizes a \"FIREBASE_DEFAULTS\" cookie to store configuration data, including an \"_authTokenSyncURL\" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the \"_authTokenSyncURL\" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-46r6-92jg-22jg/GHSA-46r6-92jg-22jg.json b/advisories/unreviewed/2024/11/GHSA-46r6-92jg-22jg/GHSA-46r6-92jg-22jg.json index 1534a5d2992..cb4b05d9723 100644 --- a/advisories/unreviewed/2024/11/GHSA-46r6-92jg-22jg/GHSA-46r6-92jg-22jg.json +++ b/advisories/unreviewed/2024/11/GHSA-46r6-92jg-22jg/GHSA-46r6-92jg-22jg.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json b/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json new file mode 100644 index 00000000000..d0bba358c35 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-47rc-w5x7-93j8/GHSA-47rc-w5x7-93j8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47rc-w5x7-93j8", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52572" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain a stack based overflow vulnerability while parsing specially crafted WRL files.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24486)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52572" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json b/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json new file mode 100644 index 00000000000..2d4553b8d8a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5749-g4w5-q5jv", + "modified": "2024-11-18T18:30:59Z", + "published": "2024-11-18T18:30:59Z", + "aliases": [ + "CVE-2024-44756" + ], + "details": "NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44756" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-44756.md" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/M9ERP/M9ERP-sqli.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-57hf-r78p-7p9m/GHSA-57hf-r78p-7p9m.json b/advisories/unreviewed/2024/11/GHSA-57hf-r78p-7p9m/GHSA-57hf-r78p-7p9m.json new file mode 100644 index 00000000000..31def60c364 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-57hf-r78p-7p9m/GHSA-57hf-r78p-7p9m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57hf-r78p-7p9m", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52566" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24233)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52566" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json b/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json index 5fc69d3d1a5..aca0f809dae 100644 --- a/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json +++ b/advisories/unreviewed/2024/11/GHSA-593c-jh4c-8cw5/GHSA-593c-jh4c-8cw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-593c-jh4c-8cw5", - "modified": "2024-11-12T18:30:56Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:56Z", "aliases": [ "CVE-2024-50323" diff --git a/advisories/unreviewed/2024/11/GHSA-593h-gxfm-rj8p/GHSA-593h-gxfm-rj8p.json b/advisories/unreviewed/2024/11/GHSA-593h-gxfm-rj8p/GHSA-593h-gxfm-rj8p.json new file mode 100644 index 00000000000..e2ed031d5cb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-593h-gxfm-rj8p/GHSA-593h-gxfm-rj8p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-593h-gxfm-rj8p", + "modified": "2024-11-18T18:30:55Z", + "published": "2024-11-18T18:30:55Z", + "aliases": [ + "CVE-2020-26073" + ], + "details": "A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information.\nThe vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or user tokens.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26073" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssl-dos-7uZWwSEy" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-traversal-hQh24tmk" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-escalation-Jhqs5Skf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6r95-j355-78w9/GHSA-6r95-j355-78w9.json b/advisories/unreviewed/2024/11/GHSA-6r95-j355-78w9/GHSA-6r95-j355-78w9.json new file mode 100644 index 00000000000..7dcabdb2b25 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6r95-j355-78w9/GHSA-6r95-j355-78w9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r95-j355-78w9", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1234" + ], + "details": "A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. To be affected by this vulnerability, the vManage software must be in cluster mode.\nThis vulnerability is due to the absence of authentication for sensitive information in the cluster management interface. An attacker could exploit this vulnerability by sending a crafted request to the cluster management interface of an affected system. A successful exploit could allow the attacker to view sensitive information on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1234" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmaninfdis3-OvdR6uu8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6w35-c59m-gf96/GHSA-6w35-c59m-gf96.json b/advisories/unreviewed/2024/11/GHSA-6w35-c59m-gf96/GHSA-6w35-c59m-gf96.json new file mode 100644 index 00000000000..6a3033202c5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6w35-c59m-gf96/GHSA-6w35-c59m-gf96.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w35-c59m-gf96", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52568" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted WRL files.\nAn attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-24244)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52568" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-722m-4rr5-cvfh/GHSA-722m-4rr5-cvfh.json b/advisories/unreviewed/2024/11/GHSA-722m-4rr5-cvfh/GHSA-722m-4rr5-cvfh.json new file mode 100644 index 00000000000..db085bd7e85 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-722m-4rr5-cvfh/GHSA-722m-4rr5-cvfh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-722m-4rr5-cvfh", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1379" + ], + "details": "Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone.\nThese vulnerabilities are due to missing checks when the IP phone processes a Cisco Discovery Protocol or LLDP packet. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol or LLDP packet to the targeted IP phone. A successful exploit could allow the attacker to execute code on the affected IP phone or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition.Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1379" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-rce-dos-U2PsSkz3" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-distupd-N87eB6Z3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-74j8-m9mj-w7wj/GHSA-74j8-m9mj-w7wj.json b/advisories/unreviewed/2024/11/GHSA-74j8-m9mj-w7wj/GHSA-74j8-m9mj-w7wj.json index d2402ff432e..3b18d60b69b 100644 --- a/advisories/unreviewed/2024/11/GHSA-74j8-m9mj-w7wj/GHSA-74j8-m9mj-w7wj.json +++ b/advisories/unreviewed/2024/11/GHSA-74j8-m9mj-w7wj/GHSA-74j8-m9mj-w7wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74j8-m9mj-w7wj", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-35410" ], "details": "wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7g68-q6c8-27w9/GHSA-7g68-q6c8-27w9.json b/advisories/unreviewed/2024/11/GHSA-7g68-q6c8-27w9/GHSA-7g68-q6c8-27w9.json new file mode 100644 index 00000000000..d5421ec04fb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7g68-q6c8-27w9/GHSA-7g68-q6c8-27w9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g68-q6c8-27w9", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1444" + ], + "details": "A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.\nThis vulnerability is due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is part of the October 2021 release of the Cisco ASA, FTD, and FMC Security Advisory Bundled publication. For a complete list of the advisories and links to them, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1444" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-webui-gQLSFyPM" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7ph6-jpfh-8f79/GHSA-7ph6-jpfh-8f79.json b/advisories/unreviewed/2024/11/GHSA-7ph6-jpfh-8f79/GHSA-7ph6-jpfh-8f79.json index b43d7d5fa0b..9ac142ab0ac 100644 --- a/advisories/unreviewed/2024/11/GHSA-7ph6-jpfh-8f79/GHSA-7ph6-jpfh-8f79.json +++ b/advisories/unreviewed/2024/11/GHSA-7ph6-jpfh-8f79/GHSA-7ph6-jpfh-8f79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7ph6-jpfh-8f79", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52914" ], "details": "In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7q9w-6xw2-qfxq/GHSA-7q9w-6xw2-qfxq.json b/advisories/unreviewed/2024/11/GHSA-7q9w-6xw2-qfxq/GHSA-7q9w-6xw2-qfxq.json new file mode 100644 index 00000000000..76be1383bfa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7q9w-6xw2-qfxq/GHSA-7q9w-6xw2-qfxq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q9w-6xw2-qfxq", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1424" + ], + "details": "A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.\nThis vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could exploit this vulnerability by sending specifically malformed IKEv2 packets to an affected device. A successful exploit could allow the attacker to cause the ipsecmgr process to restart, which would disrupt ongoing IKE negotiations and result in a temporary DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1424" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-822r-5337-562q/GHSA-822r-5337-562q.json b/advisories/unreviewed/2024/11/GHSA-822r-5337-562q/GHSA-822r-5337-562q.json index 2308e6fb91a..8f93e0b12aa 100644 --- a/advisories/unreviewed/2024/11/GHSA-822r-5337-562q/GHSA-822r-5337-562q.json +++ b/advisories/unreviewed/2024/11/GHSA-822r-5337-562q/GHSA-822r-5337-562q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-822r-5337-562q", - "modified": "2024-11-12T15:30:37Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-09T15:32:34Z", "aliases": [ "CVE-2024-51593" diff --git a/advisories/unreviewed/2024/11/GHSA-8c78-wf5j-v7jx/GHSA-8c78-wf5j-v7jx.json b/advisories/unreviewed/2024/11/GHSA-8c78-wf5j-v7jx/GHSA-8c78-wf5j-v7jx.json index 13d84897bcf..611035f1be1 100644 --- a/advisories/unreviewed/2024/11/GHSA-8c78-wf5j-v7jx/GHSA-8c78-wf5j-v7jx.json +++ b/advisories/unreviewed/2024/11/GHSA-8c78-wf5j-v7jx/GHSA-8c78-wf5j-v7jx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c78-wf5j-v7jx", - "modified": "2024-11-18T09:31:14Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T09:31:14Z", "aliases": [ "CVE-2024-45505" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating).\n\nThis vulnerability can only be exploited by authorized attackers.\nThis issue affects Apache HertzBeat (incubating): before 1.6.1.\n\nUsers are recommended to upgrade to version 1.6.1, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T09:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8r46-fjj7-gr38/GHSA-8r46-fjj7-gr38.json b/advisories/unreviewed/2024/11/GHSA-8r46-fjj7-gr38/GHSA-8r46-fjj7-gr38.json index 25737c1c2f2..10b76a8a443 100644 --- a/advisories/unreviewed/2024/11/GHSA-8r46-fjj7-gr38/GHSA-8r46-fjj7-gr38.json +++ b/advisories/unreviewed/2024/11/GHSA-8r46-fjj7-gr38/GHSA-8r46-fjj7-gr38.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-8vch-5qw4-g554/GHSA-8vch-5qw4-g554.json b/advisories/unreviewed/2024/11/GHSA-8vch-5qw4-g554/GHSA-8vch-5qw4-g554.json new file mode 100644 index 00000000000..ef5c37f9919 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8vch-5qw4-g554/GHSA-8vch-5qw4-g554.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vch-5qw4-g554", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52424" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Suresh Kumar wp-login customizer allows Stored XSS.This issue affects wp-login customizer: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52424" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-login-customizer/wordpress-wp-login-customizer-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92xx-rm6p-pfrg/GHSA-92xx-rm6p-pfrg.json b/advisories/unreviewed/2024/11/GHSA-92xx-rm6p-pfrg/GHSA-92xx-rm6p-pfrg.json new file mode 100644 index 00000000000..3b45baca248 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92xx-rm6p-pfrg/GHSA-92xx-rm6p-pfrg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92xx-rm6p-pfrg", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1425" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device.\nThe vulnerability exists because confidential information is being included in HTTP requests that are exchanged between the user and the device. An attacker could exploit this vulnerability by looking at the raw HTTP requests that are sent to the interface. A successful exploit could allow the attacker to obtain some of the passwords that are configured throughout the interface.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1425" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-info-disclo-VOu2GHbZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9cj6-mqj9-659v/GHSA-9cj6-mqj9-659v.json b/advisories/unreviewed/2024/11/GHSA-9cj6-mqj9-659v/GHSA-9cj6-mqj9-659v.json new file mode 100644 index 00000000000..aa501af9e8b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9cj6-mqj9-659v/GHSA-9cj6-mqj9-659v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cj6-mqj9-659v", + "modified": "2024-11-18T18:30:55Z", + "published": "2024-11-18T18:30:55Z", + "aliases": [ + "CVE-2020-26074" + ], + "details": "A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system.\nThe vulnerability is due to improper validation of path input to the system file transfer functions. An attacker could exploit this vulnerability by sending requests that contain specially crafted path variables to the vulnerable system. A successful exploit could allow the attacker to overwrite arbitrary files, allowing the attacker to modify the system in such a way that could allow the attacker to gain escalated privileges.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26074" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssl-dos-7uZWwSEy" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-escalation-Jhqs5Skf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9m4j-24c8-q3mj/GHSA-9m4j-24c8-q3mj.json b/advisories/unreviewed/2024/11/GHSA-9m4j-24c8-q3mj/GHSA-9m4j-24c8-q3mj.json new file mode 100644 index 00000000000..7ab47dba84d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9m4j-24c8-q3mj/GHSA-9m4j-24c8-q3mj.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m4j-24c8-q3mj", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3525" + ], + "details": "A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system.\nThe vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin portal. An attacker with read or write access to the Admin portal could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to recover passwords and expose those accounts to further attack.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3525" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-cuc-imp-xss-XtpzfM5e" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-authbypass-YVJzqgk2" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-pa-trav-bMdfSTTq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-pass-disclosure-K8p2Nsgg" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json b/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json index ff97ecad05b..cec56c43cd1 100644 --- a/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json +++ b/advisories/unreviewed/2024/11/GHSA-9qrv-rvg6-cq37/GHSA-9qrv-rvg6-cq37.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/11/GHSA-9vmr-6cpv-xpw5/GHSA-9vmr-6cpv-xpw5.json b/advisories/unreviewed/2024/11/GHSA-9vmr-6cpv-xpw5/GHSA-9vmr-6cpv-xpw5.json index cd220a298bb..ab3bc8f4f09 100644 --- a/advisories/unreviewed/2024/11/GHSA-9vmr-6cpv-xpw5/GHSA-9vmr-6cpv-xpw5.json +++ b/advisories/unreviewed/2024/11/GHSA-9vmr-6cpv-xpw5/GHSA-9vmr-6cpv-xpw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vmr-6cpv-xpw5", - "modified": "2024-11-09T00:30:43Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-11-09T00:30:43Z", "aliases": [ "CVE-2024-48073" ], "details": "sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program is vulnerable to a command injection vulnerability, which could allow an attacker to pass commands to this program via command line arguments to gain elevated root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cgqw-4mgw-89pm/GHSA-cgqw-4mgw-89pm.json b/advisories/unreviewed/2024/11/GHSA-cgqw-4mgw-89pm/GHSA-cgqw-4mgw-89pm.json new file mode 100644 index 00000000000..21b892df375 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cgqw-4mgw-89pm/GHSA-cgqw-4mgw-89pm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgqw-4mgw-89pm", + "modified": "2024-11-18T18:30:59Z", + "published": "2024-11-18T18:30:59Z", + "aliases": [ + "CVE-2024-44757" + ], + "details": "An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44757" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/CVES/CVE-2024-44757.md" + }, + { + "type": "WEB", + "url": "https://github.com/WarmBrew/web_vul/blob/main/M9ERP/M9ERP-filedown-Basics.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json b/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json new file mode 100644 index 00000000000..815661b4e36 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgvw-jh5j-mgq3", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-9474" + ], + "details": "A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.\n\nCloud NGFW and Prisma Access are not impacted by this vulnerability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9474" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-9474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json b/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json index cdb44d52ac2..10af9931db9 100644 --- a/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json +++ b/advisories/unreviewed/2024/11/GHSA-cq5f-wv7p-5gfc/GHSA-cq5f-wv7p-5gfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq5f-wv7p-5gfc", - "modified": "2024-11-18T12:30:43Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T12:30:43Z", "aliases": [ "CVE-2024-48896" ], "details": "A vulnerability was found in Moodle. It is possible for users with the \"send message\" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-209" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T12:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json b/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json new file mode 100644 index 00000000000..fdc4ef907c6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-crmh-vcgf-prwv/GHSA-crmh-vcgf-prwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crmh-vcgf-prwv", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52425" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Urchenko Drozd – Addons for Elementor allows Stored XSS.This issue affects Drozd – Addons for Elementor: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/drozd-addons-for-elementor/wordpress-drozd-addons-for-elementor-plugin-1-1-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json b/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json index efb32d9533e..0c416186115 100644 --- a/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json +++ b/advisories/unreviewed/2024/11/GHSA-f632-9449-3j4w/GHSA-f632-9449-3j4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f632-9449-3j4w", - "modified": "2024-11-18T15:33:20Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T15:33:20Z", "aliases": [ "CVE-2024-52318" ], "details": "Incorrect object recycling and reuse vulnerability in Apache Tomcat.\n\nThis issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.\n\nUsers are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T13:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json b/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json index 8d1eb3b1db7..85d325b18b4 100644 --- a/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json +++ b/advisories/unreviewed/2024/11/GHSA-fjq9-452g-jg3q/GHSA-fjq9-452g-jg3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fjq9-452g-jg3q", - "modified": "2024-11-18T12:30:43Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T12:30:43Z", "aliases": [ "CVE-2024-48898" ], "details": "A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T12:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json b/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json index 3e54031a2a0..43b5e9b5324 100644 --- a/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json +++ b/advisories/unreviewed/2024/11/GHSA-frfr-qxrr-f897/GHSA-frfr-qxrr-f897.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frfr-qxrr-f897", - "modified": "2024-11-12T18:30:56Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:56Z", "aliases": [ "CVE-2024-50327" diff --git a/advisories/unreviewed/2024/11/GHSA-fx2f-v4hx-q8h6/GHSA-fx2f-v4hx-q8h6.json b/advisories/unreviewed/2024/11/GHSA-fx2f-v4hx-q8h6/GHSA-fx2f-v4hx-q8h6.json index 401e14b3379..d9b25fdb0ec 100644 --- a/advisories/unreviewed/2024/11/GHSA-fx2f-v4hx-q8h6/GHSA-fx2f-v4hx-q8h6.json +++ b/advisories/unreviewed/2024/11/GHSA-fx2f-v4hx-q8h6/GHSA-fx2f-v4hx-q8h6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fx2f-v4hx-q8h6", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52917" ], "details": "Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g2fp-6w5h-9c47/GHSA-g2fp-6w5h-9c47.json b/advisories/unreviewed/2024/11/GHSA-g2fp-6w5h-9c47/GHSA-g2fp-6w5h-9c47.json new file mode 100644 index 00000000000..a97365e4ac8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g2fp-6w5h-9c47/GHSA-g2fp-6w5h-9c47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2fp-6w5h-9c47", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1462" + ], + "details": "A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected system. To exploit this vulnerability, an attacker would need to have a valid Administrator account on an affected system.\nThe vulnerability is due to incorrect privilege assignment. An attacker could exploit this vulnerability by logging in to an affected system with an Administrator account and creating a malicious file, which the system would parse at a later time. A successful exploit could allow the attacker to obtain root privileges on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1462" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-vman-kth3c82B" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g2vx-f8p2-fq5g/GHSA-g2vx-f8p2-fq5g.json b/advisories/unreviewed/2024/11/GHSA-g2vx-f8p2-fq5g/GHSA-g2vx-f8p2-fq5g.json new file mode 100644 index 00000000000..effc77806c2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g2vx-f8p2-fq5g/GHSA-g2vx-f8p2-fq5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2vx-f8p2-fq5g", + "modified": "2024-11-18T18:30:59Z", + "published": "2024-11-18T18:30:59Z", + "aliases": [ + "CVE-2020-26066" + ], + "details": "A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.\nThe vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26066" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanx3-vrZbOqqD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g8hr-m8mg-wmfp/GHSA-g8hr-m8mg-wmfp.json b/advisories/unreviewed/2024/11/GHSA-g8hr-m8mg-wmfp/GHSA-g8hr-m8mg-wmfp.json new file mode 100644 index 00000000000..36fdf4ada06 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g8hr-m8mg-wmfp/GHSA-g8hr-m8mg-wmfp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8hr-m8mg-wmfp", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1232" + ], + "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of an affected system.\nThis vulnerability is due to insufficient access control for sensitive information that is written to an affected system. An attacker could exploit this vulnerability by accessing sensitive information that they are not authorized to access on an affected system. A successful exploit could allow the attacker to gain access to devices and other network management systems that they should not have access to.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1232" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-rce-dos-U2PsSkz3" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanvman-infodis1-YuQScHB" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-distupd-N87eB6Z3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g8j6-3mwg-7x4g/GHSA-g8j6-3mwg-7x4g.json b/advisories/unreviewed/2024/11/GHSA-g8j6-3mwg-7x4g/GHSA-g8j6-3mwg-7x4g.json new file mode 100644 index 00000000000..2f7d2df67f6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g8j6-3mwg-7x4g/GHSA-g8j6-3mwg-7x4g.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8j6-3mwg-7x4g", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1440" + ], + "details": "A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of service (DoS) condition.\nThis vulnerability is due to the incorrect handling of a specific RPKI to Router (RTR) Protocol packet header. An attacker could exploit this vulnerability by compromising the RPKI validator server and sending a specifically crafted RTR packet to an affected device. Alternatively, the attacker could use man-in-the-middle techniques to impersonate the RPKI validator server and send a specifically crafted RTR response packet over the established RTR TCP connection to the affected device. A successful exploit could allow the attacker to cause a DoS condition because the BGP process could constantly restart and BGP routing could become unstable.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is part of the September 2021 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see .", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1440" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g8x6-cf2x-c662/GHSA-g8x6-cf2x-c662.json b/advisories/unreviewed/2024/11/GHSA-g8x6-cf2x-c662/GHSA-g8x6-cf2x-c662.json new file mode 100644 index 00000000000..ec8417319d2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g8x6-cf2x-c662/GHSA-g8x6-cf2x-c662.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8x6-cf2x-c662", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52419" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Clipboard Team Copy Anything to Clipboard allows Stored XSS.This issue affects Copy Anything to Clipboard: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52419" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/copy-the-code/wordpress-copy-anything-to-clipboard-plugin-4-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json b/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json index fa6b9d80c2a..59b5518127c 100644 --- a/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json +++ b/advisories/unreviewed/2024/11/GHSA-gv5h-5655-h4mv/GHSA-gv5h-5655-h4mv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv5h-5655-h4mv", - "modified": "2024-11-18T12:30:43Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T12:30:43Z", "aliases": [ "CVE-2024-11319" ], "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-h7hm-94xj-mhpm/GHSA-h7hm-94xj-mhpm.json b/advisories/unreviewed/2024/11/GHSA-h7hm-94xj-mhpm/GHSA-h7hm-94xj-mhpm.json index ada40cec8ae..710f53da63d 100644 --- a/advisories/unreviewed/2024/11/GHSA-h7hm-94xj-mhpm/GHSA-h7hm-94xj-mhpm.json +++ b/advisories/unreviewed/2024/11/GHSA-h7hm-94xj-mhpm/GHSA-h7hm-94xj-mhpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7hm-94xj-mhpm", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52913" ], "details": "In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json b/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json index 539db496c89..34975c4b4a9 100644 --- a/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json +++ b/advisories/unreviewed/2024/11/GHSA-h7w7-g9gg-4q8w/GHSA-h7w7-g9gg-4q8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7w7-g9gg-4q8w", - "modified": "2024-11-12T18:30:57Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:57Z", "aliases": [ "CVE-2024-50329" diff --git a/advisories/unreviewed/2024/11/GHSA-hgrp-6mh3-jm92/GHSA-hgrp-6mh3-jm92.json b/advisories/unreviewed/2024/11/GHSA-hgrp-6mh3-jm92/GHSA-hgrp-6mh3-jm92.json new file mode 100644 index 00000000000..e2dc3f33b2f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hgrp-6mh3-jm92/GHSA-hgrp-6mh3-jm92.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgrp-6mh3-jm92", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3538" + ], + "details": "A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device.\nThe vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to overwrite or list arbitrary files on the affected device.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3538" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-authbypass-YVJzqgk2" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-pa-trav-bMdfSTTq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hrhq-vqf8-7fpq/GHSA-hrhq-vqf8-7fpq.json b/advisories/unreviewed/2024/11/GHSA-hrhq-vqf8-7fpq/GHSA-hrhq-vqf8-7fpq.json new file mode 100644 index 00000000000..8efa9be9837 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hrhq-vqf8-7fpq/GHSA-hrhq-vqf8-7fpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrhq-vqf8-7fpq", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52423" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Builder allows Stored XSS.This issue affects Themify Builder: from n/a through 7.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52423" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-builder/wordpress-themify-builder-plugin-7-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json b/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json index 1f052ccfcf9..3e8595f21b7 100644 --- a/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json +++ b/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9x-8m75-4vjq", - "modified": "2024-11-12T21:30:55Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T21:30:55Z", "aliases": [ "CVE-2024-51093" ], "details": "Cross Site Scripting vulnerability in Snipe-IT v.7.0.13 allows a remote attacker to escalate privileges via an unknown part of the file /users/{{user-id}}/#files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T21:15:14Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j5h7-5c44-5mjv/GHSA-j5h7-5c44-5mjv.json b/advisories/unreviewed/2024/11/GHSA-j5h7-5c44-5mjv/GHSA-j5h7-5c44-5mjv.json new file mode 100644 index 00000000000..2553fe5ff16 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j5h7-5c44-5mjv/GHSA-j5h7-5c44-5mjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5h7-5c44-5mjv", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1410" + ], + "details": "A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization.\nThe vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to modify an existing distribution list. A successful exploit could allow the attacker to modify a distribution list that belongs to a user other than themselves.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1410" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-distupd-N87eB6Z3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j69q-qfwm-m736/GHSA-j69q-qfwm-m736.json b/advisories/unreviewed/2024/11/GHSA-j69q-qfwm-m736/GHSA-j69q-qfwm-m736.json new file mode 100644 index 00000000000..71fc6f53404 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j69q-qfwm-m736/GHSA-j69q-qfwm-m736.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j69q-qfwm-m736", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-27124" + ], + "details": "A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition.\nThe vulnerability is due to improper error handling on established SSL/TLS connections. An attacker could exploit this vulnerability by establishing an SSL/TLS connection with the affected device and then sending a malicious SSL/TLS message within that connection. A successful exploit could allow the attacker to cause the device to reload.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27124" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssl-dos-7uZWwSEy" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-xss-bLZw4Ctq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sa-rv-routers-xss-K7Z5U6q3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jc5h-x77p-hhq6/GHSA-jc5h-x77p-hhq6.json b/advisories/unreviewed/2024/11/GHSA-jc5h-x77p-hhq6/GHSA-jc5h-x77p-hhq6.json index 19caabdf125..286cd8a46d8 100644 --- a/advisories/unreviewed/2024/11/GHSA-jc5h-x77p-hhq6/GHSA-jc5h-x77p-hhq6.json +++ b/advisories/unreviewed/2024/11/GHSA-jc5h-x77p-hhq6/GHSA-jc5h-x77p-hhq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc5h-x77p-hhq6", - "modified": "2024-11-18T09:31:13Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T09:31:13Z", "aliases": [ "CVE-2024-41151" ], "details": "Deserialization of Untrusted Data vulnerability in Apache HertzBeat.\n\nThis vulnerability can only be exploited by authorized attackers.\n\n\nThis issue affects Apache HertzBeat: before 1.6.1.\n\nUsers are recommended to upgrade to version 1.6.1, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T09:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jpwj-hwcf-hmr2/GHSA-jpwj-hwcf-hmr2.json b/advisories/unreviewed/2024/11/GHSA-jpwj-hwcf-hmr2/GHSA-jpwj-hwcf-hmr2.json new file mode 100644 index 00000000000..1e9b76c5dfe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jpwj-hwcf-hmr2/GHSA-jpwj-hwcf-hmr2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpwj-hwcf-hmr2", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52574" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24543)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52574" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jr7j-3vjj-9c7j/GHSA-jr7j-3vjj-9c7j.json b/advisories/unreviewed/2024/11/GHSA-jr7j-3vjj-9c7j/GHSA-jr7j-3vjj-9c7j.json index 06e7897e25d..414d83090e0 100644 --- a/advisories/unreviewed/2024/11/GHSA-jr7j-3vjj-9c7j/GHSA-jr7j-3vjj-9c7j.json +++ b/advisories/unreviewed/2024/11/GHSA-jr7j-3vjj-9c7j/GHSA-jr7j-3vjj-9c7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr7j-3vjj-9c7j", - "modified": "2024-11-17T06:30:46Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-17T06:30:46Z", "aliases": [ "CVE-2024-52876" ], "details": "Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated \"remote power off\" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-17T05:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json b/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json index 65da75d3840..7a2e5b1d0c2 100644 --- a/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json +++ b/advisories/unreviewed/2024/11/GHSA-jxvj-5w26-hpx9/GHSA-jxvj-5w26-hpx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxvj-5w26-hpx9", - "modified": "2024-11-12T18:30:56Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:56Z", "aliases": [ "CVE-2024-50328" diff --git a/advisories/unreviewed/2024/11/GHSA-jxw6-4vrc-qvm7/GHSA-jxw6-4vrc-qvm7.json b/advisories/unreviewed/2024/11/GHSA-jxw6-4vrc-qvm7/GHSA-jxw6-4vrc-qvm7.json new file mode 100644 index 00000000000..de10b47d1e1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jxw6-4vrc-qvm7/GHSA-jxw6-4vrc-qvm7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxw6-4vrc-qvm7", + "modified": "2024-11-18T18:30:59Z", + "published": "2024-11-18T18:30:59Z", + "aliases": [ + "CVE-2024-10390" + ], + "details": "The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10390" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/elfsight-telegram-chat/25288599" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/07244763-3482-4cfb-8ae4-d19f312011aa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m86g-cwq8-wqrm/GHSA-m86g-cwq8-wqrm.json b/advisories/unreviewed/2024/11/GHSA-m86g-cwq8-wqrm/GHSA-m86g-cwq8-wqrm.json index 8f224f3c80e..0dfa2146d2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-m86g-cwq8-wqrm/GHSA-m86g-cwq8-wqrm.json +++ b/advisories/unreviewed/2024/11/GHSA-m86g-cwq8-wqrm/GHSA-m86g-cwq8-wqrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m86g-cwq8-wqrm", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52915" ], "details": "Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m96v-gj29-hf2q/GHSA-m96v-gj29-hf2q.json b/advisories/unreviewed/2024/11/GHSA-m96v-gj29-hf2q/GHSA-m96v-gj29-hf2q.json new file mode 100644 index 00000000000..0cad11239e3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m96v-gj29-hf2q/GHSA-m96v-gj29-hf2q.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m96v-gj29-hf2q", + "modified": "2024-11-18T18:30:55Z", + "published": "2024-11-18T18:30:55Z", + "aliases": [ + "CVE-2020-26062" + ], + "details": "A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application.\nThe vulnerability is due to differences in authentication responses sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability by sending authentication requests to the affected application. A successful exploit could allow the attacker to confirm the names of administrative user accounts for use in further attacks.There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26062" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-zWkppJxL" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-enum-CyheP3B7" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanx3-vrZbOqqD" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vsoln-arbfile-gtsEYxns" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-teams-xss-zLW9tD3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json b/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json index 5e37c0af9fa..8fd832daf4e 100644 --- a/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json +++ b/advisories/unreviewed/2024/11/GHSA-mg54-p2wj-5ph7/GHSA-mg54-p2wj-5ph7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mg54-p2wj-5ph7", - "modified": "2024-11-18T12:30:43Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T12:30:43Z", "aliases": [ "CVE-2024-48901" ], "details": "A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-285" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T12:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mgmf-6j2f-mh6r/GHSA-mgmf-6j2f-mh6r.json b/advisories/unreviewed/2024/11/GHSA-mgmf-6j2f-mh6r/GHSA-mgmf-6j2f-mh6r.json index c0790baabab..f7f74047e53 100644 --- a/advisories/unreviewed/2024/11/GHSA-mgmf-6j2f-mh6r/GHSA-mgmf-6j2f-mh6r.json +++ b/advisories/unreviewed/2024/11/GHSA-mgmf-6j2f-mh6r/GHSA-mgmf-6j2f-mh6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgmf-6j2f-mh6r", - "modified": "2024-11-08T21:33:58Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-11-08T21:33:58Z", "aliases": [ "CVE-2024-51157" ], "details": "07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T21:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mhg9-mm8c-c683/GHSA-mhg9-mm8c-c683.json b/advisories/unreviewed/2024/11/GHSA-mhg9-mm8c-c683/GHSA-mhg9-mm8c-c683.json index 9dc4d7ae92a..b5d73d37280 100644 --- a/advisories/unreviewed/2024/11/GHSA-mhg9-mm8c-c683/GHSA-mhg9-mm8c-c683.json +++ b/advisories/unreviewed/2024/11/GHSA-mhg9-mm8c-c683/GHSA-mhg9-mm8c-c683.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhg9-mm8c-c683", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-27528" ], "details": "wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json b/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json index dbd0c2114de..c9e044d35d9 100644 --- a/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json +++ b/advisories/unreviewed/2024/11/GHSA-mq3p-r846-c5mx/GHSA-mq3p-r846-c5mx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mq3p-r846-c5mx", - "modified": "2024-11-12T18:30:56Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:56Z", "aliases": [ "CVE-2024-50324" diff --git a/advisories/unreviewed/2024/11/GHSA-mw39-wc97-cvhf/GHSA-mw39-wc97-cvhf.json b/advisories/unreviewed/2024/11/GHSA-mw39-wc97-cvhf/GHSA-mw39-wc97-cvhf.json new file mode 100644 index 00000000000..371cca2f4e5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mw39-wc97-cvhf/GHSA-mw39-wc97-cvhf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw39-wc97-cvhf", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52569" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24260)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52569" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json b/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json new file mode 100644 index 00000000000..b3ec1794aff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9x-2qwv-599p", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-0012" + ], + "details": "An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .\n\nThe risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\nThis issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software.\n\nCloud NGFW and Prisma Access are not impacted by this vulnerability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0012" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-0012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mxcf-88m3-99v7/GHSA-mxcf-88m3-99v7.json b/advisories/unreviewed/2024/11/GHSA-mxcf-88m3-99v7/GHSA-mxcf-88m3-99v7.json index 7fdb79a6158..c9572fc8f0f 100644 --- a/advisories/unreviewed/2024/11/GHSA-mxcf-88m3-99v7/GHSA-mxcf-88m3-99v7.json +++ b/advisories/unreviewed/2024/11/GHSA-mxcf-88m3-99v7/GHSA-mxcf-88m3-99v7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxcf-88m3-99v7", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52912" ], "details": "Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an abs64 logic bug.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-p966-47mp-f6w3/GHSA-p966-47mp-f6w3.json b/advisories/unreviewed/2024/11/GHSA-p966-47mp-f6w3/GHSA-p966-47mp-f6w3.json new file mode 100644 index 00000000000..7ac4198333b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p966-47mp-f6w3/GHSA-p966-47mp-f6w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p966-47mp-f6w3", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1465" + ], + "details": "A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on an affected system.\n The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to write arbitrary files on the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1465" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vman-dir-trav-Bpwc5gtm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pc9j-37p2-gmr4/GHSA-pc9j-37p2-gmr4.json b/advisories/unreviewed/2024/11/GHSA-pc9j-37p2-gmr4/GHSA-pc9j-37p2-gmr4.json new file mode 100644 index 00000000000..d13e2c81cd1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pc9j-37p2-gmr4/GHSA-pc9j-37p2-gmr4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc9j-37p2-gmr4", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52565" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24231)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52565" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json b/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json index d414815749a..07ae81d6290 100644 --- a/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json +++ b/advisories/unreviewed/2024/11/GHSA-phhx-m29g-px4m/GHSA-phhx-m29g-px4m.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phhx-m29g-px4m", - "modified": "2024-11-18T15:33:20Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T15:33:20Z", "aliases": [ "CVE-2024-3370" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software Website Template allows SQL Injection.This issue affects Website Template: before 29.04.2024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-pm93-mhpj-x843/GHSA-pm93-mhpj-x843.json b/advisories/unreviewed/2024/11/GHSA-pm93-mhpj-x843/GHSA-pm93-mhpj-x843.json new file mode 100644 index 00000000000..c0f364eda24 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pm93-mhpj-x843/GHSA-pm93-mhpj-x843.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm93-mhpj-x843", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1132" + ], + "details": "A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data.\nThis vulnerability exists because the web-management interface and certain HTTP-based APIs do not properly validate user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1132" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipphone-rce-dos-U2PsSkz3" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-path-trvsl-dZRQE8Lc" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmaninfdis3-OvdR6uu8" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanvman-infodis1-YuQScHB" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-distupd-N87eB6Z3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pqv2-m9wq-5989/GHSA-pqv2-m9wq-5989.json b/advisories/unreviewed/2024/11/GHSA-pqv2-m9wq-5989/GHSA-pqv2-m9wq-5989.json new file mode 100644 index 00000000000..1362225be61 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pqv2-m9wq-5989/GHSA-pqv2-m9wq-5989.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqv2-m9wq-5989", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3420" + ], + "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\nThe vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3420" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-xss-bLZw4Ctq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sa-rv-routers-xss-K7Z5U6q3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pv55-c55f-33qw/GHSA-pv55-c55f-33qw.json b/advisories/unreviewed/2024/11/GHSA-pv55-c55f-33qw/GHSA-pv55-c55f-33qw.json new file mode 100644 index 00000000000..3cdf5c604ac --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pv55-c55f-33qw/GHSA-pv55-c55f-33qw.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv55-c55f-33qw", + "modified": "2024-11-18T18:30:57Z", + "published": "2024-11-18T18:30:57Z", + "aliases": [ + "CVE-2021-1461" + ], + "details": "A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to install a malicious software patch on an affected device.\nThe vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1461" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pv5j-xh4q-r829/GHSA-pv5j-xh4q-r829.json b/advisories/unreviewed/2024/11/GHSA-pv5j-xh4q-r829/GHSA-pv5j-xh4q-r829.json new file mode 100644 index 00000000000..a7ae110dd10 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pv5j-xh4q-r829/GHSA-pv5j-xh4q-r829.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv5j-xh4q-r829", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52570" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24365)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52570" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-px5f-j76h-8w39/GHSA-px5f-j76h-8w39.json b/advisories/unreviewed/2024/11/GHSA-px5f-j76h-8w39/GHSA-px5f-j76h-8w39.json index 5c4dddba8fe..432f2bbe298 100644 --- a/advisories/unreviewed/2024/11/GHSA-px5f-j76h-8w39/GHSA-px5f-j76h-8w39.json +++ b/advisories/unreviewed/2024/11/GHSA-px5f-j76h-8w39/GHSA-px5f-j76h-8w39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px5f-j76h-8w39", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2019-25220" ], "details": "Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a \"Chain Width Expansion\" attack) because a node does not first verify that a presented chain has enough work before committing to store it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json b/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json index 9b74168b124..cf96c856c83 100644 --- a/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json +++ b/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3fg-4x56-mx94", - "modified": "2024-11-15T12:31:45Z", + "modified": "2024-11-18T18:30:49Z", "published": "2024-11-15T12:31:45Z", "aliases": [ "CVE-2024-11182" ], "details": "An XSS issue was discovered in \n\nMDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message \nwith \nJavaScript in an img tag. This could\n allow a remote attacker\n\nto load arbitrary JavaScript code in the context of a webmail user's browser window.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json b/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json index 596bd60fc7e..6b752876c75 100644 --- a/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json +++ b/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qcxm-3xrq-pj5f/GHSA-qcxm-3xrq-pj5f.json b/advisories/unreviewed/2024/11/GHSA-qcxm-3xrq-pj5f/GHSA-qcxm-3xrq-pj5f.json index 9caa9d42877..81dbef8c232 100644 --- a/advisories/unreviewed/2024/11/GHSA-qcxm-3xrq-pj5f/GHSA-qcxm-3xrq-pj5f.json +++ b/advisories/unreviewed/2024/11/GHSA-qcxm-3xrq-pj5f/GHSA-qcxm-3xrq-pj5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcxm-3xrq-pj5f", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52916" ], "details": "Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qr85-9w55-gxgf/GHSA-qr85-9w55-gxgf.json b/advisories/unreviewed/2024/11/GHSA-qr85-9w55-gxgf/GHSA-qr85-9w55-gxgf.json new file mode 100644 index 00000000000..0120d2d77f6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qr85-9w55-gxgf/GHSA-qr85-9w55-gxgf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr85-9w55-gxgf", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52571" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0018), Tecnomatix Plant Simulation V2404 (All versions < V2404.0007). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file.\nThis could allow an attacker to execute code in the context of the current process. (ZDI-CAN-24485)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52571" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-824503.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json b/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json index a5461dd5292..095818e8ad6 100644 --- a/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json +++ b/advisories/unreviewed/2024/11/GHSA-qvf5-hvjx-wm27/GHSA-qvf5-hvjx-wm27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvf5-hvjx-wm27", - "modified": "2024-11-18T12:30:43Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T12:30:43Z", "aliases": [ "CVE-2024-52317" ], "details": "Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests \ncould lead to request and/or response mix-up between users.\n\nThis issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.\n\nUsers are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T12:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qwp9-p9rr-h729/GHSA-qwp9-p9rr-h729.json b/advisories/unreviewed/2024/11/GHSA-qwp9-p9rr-h729/GHSA-qwp9-p9rr-h729.json index 64e8428c161..ef263efd2ca 100644 --- a/advisories/unreviewed/2024/11/GHSA-qwp9-p9rr-h729/GHSA-qwp9-p9rr-h729.json +++ b/advisories/unreviewed/2024/11/GHSA-qwp9-p9rr-h729/GHSA-qwp9-p9rr-h729.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwp9-p9rr-h729", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52919" ], "details": "Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json b/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json index 21923171eeb..aa602445036 100644 --- a/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json +++ b/advisories/unreviewed/2024/11/GHSA-qxwc-wcvf-47fq/GHSA-qxwc-wcvf-47fq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxwc-wcvf-47fq", - "modified": "2024-11-12T18:30:56Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:56Z", "aliases": [ "CVE-2024-50322" diff --git a/advisories/unreviewed/2024/11/GHSA-r24r-r242-xm9f/GHSA-r24r-r242-xm9f.json b/advisories/unreviewed/2024/11/GHSA-r24r-r242-xm9f/GHSA-r24r-r242-xm9f.json new file mode 100644 index 00000000000..eb154da7ae4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r24r-r242-xm9f/GHSA-r24r-r242-xm9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r24r-r242-xm9f", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3548" + ], + "details": "A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.\nThe vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3548" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r2ph-vgmf-8gqh/GHSA-r2ph-vgmf-8gqh.json b/advisories/unreviewed/2024/11/GHSA-r2ph-vgmf-8gqh/GHSA-r2ph-vgmf-8gqh.json index 0aa7b485303..ed570afe3fa 100644 --- a/advisories/unreviewed/2024/11/GHSA-r2ph-vgmf-8gqh/GHSA-r2ph-vgmf-8gqh.json +++ b/advisories/unreviewed/2024/11/GHSA-r2ph-vgmf-8gqh/GHSA-r2ph-vgmf-8gqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2ph-vgmf-8gqh", - "modified": "2024-11-18T06:30:36Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:36Z", "aliases": [ "CVE-2024-52940" ], "details": "AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T05:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json b/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json new file mode 100644 index 00000000000..6fc19511ea3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r59c-8gpj-2fqr/GHSA-r59c-8gpj-2fqr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r59c-8gpj-2fqr", + "modified": "2024-11-18T18:30:59Z", + "published": "2024-11-18T18:30:59Z", + "aliases": [ + "CVE-2024-48292" + ], + "details": "An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48292" + }, + { + "type": "WEB", + "url": "https://github.com/Nero22k/Disclosures/blob/main/QuickHealAV/CVE-2024-48292.md" + }, + { + "type": "WEB", + "url": "https://www.quickheal.com/download-free-antivirus" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json b/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json index 5731a55dea8..489df10ba23 100644 --- a/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json +++ b/advisories/unreviewed/2024/11/GHSA-r5rh-8593-84qf/GHSA-r5rh-8593-84qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5rh-8593-84qf", - "modified": "2024-11-12T18:30:56Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-12T18:30:56Z", "aliases": [ "CVE-2024-50326" diff --git a/advisories/unreviewed/2024/11/GHSA-rrfj-jmcg-8f47/GHSA-rrfj-jmcg-8f47.json b/advisories/unreviewed/2024/11/GHSA-rrfj-jmcg-8f47/GHSA-rrfj-jmcg-8f47.json new file mode 100644 index 00000000000..16e8c3d18f3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rrfj-jmcg-8f47/GHSA-rrfj-jmcg-8f47.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrfj-jmcg-8f47", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3532" + ], + "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\nThe vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3532" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-cuc-imp-xss-XtpzfM5e" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-authbypass-YVJzqgk2" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-pa-trav-bMdfSTTq" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rxgg-vpm5-pccw/GHSA-rxgg-vpm5-pccw.json b/advisories/unreviewed/2024/11/GHSA-rxgg-vpm5-pccw/GHSA-rxgg-vpm5-pccw.json index 63b2566013d..95b5c39a975 100644 --- a/advisories/unreviewed/2024/11/GHSA-rxgg-vpm5-pccw/GHSA-rxgg-vpm5-pccw.json +++ b/advisories/unreviewed/2024/11/GHSA-rxgg-vpm5-pccw/GHSA-rxgg-vpm5-pccw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxgg-vpm5-pccw", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52921" ], "details": "In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v42j-pqm9-9855/GHSA-v42j-pqm9-9855.json b/advisories/unreviewed/2024/11/GHSA-v42j-pqm9-9855/GHSA-v42j-pqm9-9855.json index 767c098c055..591a16c8bbe 100644 --- a/advisories/unreviewed/2024/11/GHSA-v42j-pqm9-9855/GHSA-v42j-pqm9-9855.json +++ b/advisories/unreviewed/2024/11/GHSA-v42j-pqm9-9855/GHSA-v42j-pqm9-9855.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v42j-pqm9-9855", - "modified": "2024-11-14T18:30:36Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-14T18:30:36Z", "aliases": [ "CVE-2024-50836" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and lastname parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T17:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v47w-rw59-8jc5/GHSA-v47w-rw59-8jc5.json b/advisories/unreviewed/2024/11/GHSA-v47w-rw59-8jc5/GHSA-v47w-rw59-8jc5.json new file mode 100644 index 00000000000..8bbc4342009 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v47w-rw59-8jc5/GHSA-v47w-rw59-8jc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v47w-rw59-8jc5", + "modified": "2024-11-18T18:30:58Z", + "published": "2024-11-18T18:30:58Z", + "aliases": [ + "CVE-2024-52426" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Linear Oy Linear linear allows DOM-Based XSS.This issue affects Linear: from n/a through 2.7.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52426" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/linear/wordpress-linear-plugin-2-7-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v64h-qhh7-j6qf/GHSA-v64h-qhh7-j6qf.json b/advisories/unreviewed/2024/11/GHSA-v64h-qhh7-j6qf/GHSA-v64h-qhh7-j6qf.json index 3d114584a98..52f0a42cef4 100644 --- a/advisories/unreviewed/2024/11/GHSA-v64h-qhh7-j6qf/GHSA-v64h-qhh7-j6qf.json +++ b/advisories/unreviewed/2024/11/GHSA-v64h-qhh7-j6qf/GHSA-v64h-qhh7-j6qf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vmjh-4373-j57w/GHSA-vmjh-4373-j57w.json b/advisories/unreviewed/2024/11/GHSA-vmjh-4373-j57w/GHSA-vmjh-4373-j57w.json index d829fdfbe45..6f23a0e9306 100644 --- a/advisories/unreviewed/2024/11/GHSA-vmjh-4373-j57w/GHSA-vmjh-4373-j57w.json +++ b/advisories/unreviewed/2024/11/GHSA-vmjh-4373-j57w/GHSA-vmjh-4373-j57w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vr6g-27c6-8qqc/GHSA-vr6g-27c6-8qqc.json b/advisories/unreviewed/2024/11/GHSA-vr6g-27c6-8qqc/GHSA-vr6g-27c6-8qqc.json index 413680b527b..da6871b72bf 100644 --- a/advisories/unreviewed/2024/11/GHSA-vr6g-27c6-8qqc/GHSA-vr6g-27c6-8qqc.json +++ b/advisories/unreviewed/2024/11/GHSA-vr6g-27c6-8qqc/GHSA-vr6g-27c6-8qqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vr6g-27c6-8qqc", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52918" ], "details": "Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w2jg-6vfx-xj22/GHSA-w2jg-6vfx-xj22.json b/advisories/unreviewed/2024/11/GHSA-w2jg-6vfx-xj22/GHSA-w2jg-6vfx-xj22.json index a830f32621e..76c1523dda4 100644 --- a/advisories/unreviewed/2024/11/GHSA-w2jg-6vfx-xj22/GHSA-w2jg-6vfx-xj22.json +++ b/advisories/unreviewed/2024/11/GHSA-w2jg-6vfx-xj22/GHSA-w2jg-6vfx-xj22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2jg-6vfx-xj22", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2015-20111" ], "details": "miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wqx3-8496-4xhc/GHSA-wqx3-8496-4xhc.json b/advisories/unreviewed/2024/11/GHSA-wqx3-8496-4xhc/GHSA-wqx3-8496-4xhc.json index bac360d3295..a7dc51bcff5 100644 --- a/advisories/unreviewed/2024/11/GHSA-wqx3-8496-4xhc/GHSA-wqx3-8496-4xhc.json +++ b/advisories/unreviewed/2024/11/GHSA-wqx3-8496-4xhc/GHSA-wqx3-8496-4xhc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqx3-8496-4xhc", - "modified": "2024-11-18T06:30:35Z", + "modified": "2024-11-18T18:30:54Z", "published": "2024-11-18T06:30:35Z", "aliases": [ "CVE-2024-52920" ], "details": "Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T04:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wr2h-chhq-3jh8/GHSA-wr2h-chhq-3jh8.json b/advisories/unreviewed/2024/11/GHSA-wr2h-chhq-3jh8/GHSA-wr2h-chhq-3jh8.json index 4196394dd40..4e8f051c84a 100644 --- a/advisories/unreviewed/2024/11/GHSA-wr2h-chhq-3jh8/GHSA-wr2h-chhq-3jh8.json +++ b/advisories/unreviewed/2024/11/GHSA-wr2h-chhq-3jh8/GHSA-wr2h-chhq-3jh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr2h-chhq-3jh8", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-35418" ], "details": "wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ww45-hmjq-p5q2/GHSA-ww45-hmjq-p5q2.json b/advisories/unreviewed/2024/11/GHSA-ww45-hmjq-p5q2/GHSA-ww45-hmjq-p5q2.json new file mode 100644 index 00000000000..04038e53853 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ww45-hmjq-p5q2/GHSA-ww45-hmjq-p5q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww45-hmjq-p5q2", + "modified": "2024-11-18T18:30:55Z", + "published": "2024-11-18T18:30:55Z", + "aliases": [ + "CVE-2020-26071" + ], + "details": "A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition.\nThe vulnerability is due to insufficient input validation for specific commands. An attacker could exploit this vulnerability by including crafted arguments to those specific commands. A successful exploit could allow the attacker to create or overwrite arbitrary files on the affected device, which could result in a DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26071" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vsoln-arbfile-gtsEYxns" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x469-9qwg-89hw/GHSA-x469-9qwg-89hw.json b/advisories/unreviewed/2024/11/GHSA-x469-9qwg-89hw/GHSA-x469-9qwg-89hw.json new file mode 100644 index 00000000000..b401585ce81 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x469-9qwg-89hw/GHSA-x469-9qwg-89hw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x469-9qwg-89hw", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3431" + ], + "details": "A vulnerability in the web-based management interface of Cisco Small Business RV042 Dual WAN VPN Routers and Cisco Small Business RV042G Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.\nThe vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3431" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sa-rv-routers-xss-K7Z5U6q3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x49r-92c3-x599/GHSA-x49r-92c3-x599.json b/advisories/unreviewed/2024/11/GHSA-x49r-92c3-x599/GHSA-x49r-92c3-x599.json index d8879bf5abc..638ba865290 100644 --- a/advisories/unreviewed/2024/11/GHSA-x49r-92c3-x599/GHSA-x49r-92c3-x599.json +++ b/advisories/unreviewed/2024/11/GHSA-x49r-92c3-x599/GHSA-x49r-92c3-x599.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x49r-92c3-x599", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-18T18:30:48Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2024-7295" diff --git a/advisories/unreviewed/2024/11/GHSA-x9cp-m9m5-f8xr/GHSA-x9cp-m9m5-f8xr.json b/advisories/unreviewed/2024/11/GHSA-x9cp-m9m5-f8xr/GHSA-x9cp-m9m5-f8xr.json new file mode 100644 index 00000000000..376c3ad1d5a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x9cp-m9m5-f8xr/GHSA-x9cp-m9m5-f8xr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9cp-m9m5-f8xr", + "modified": "2024-11-18T18:30:56Z", + "published": "2024-11-18T18:30:56Z", + "aliases": [ + "CVE-2020-3539" + ], + "details": "A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.\nThe vulnerability is due to a failure to limit access to resources that are intended for users with Administrator privileges. An attacker could exploit this vulnerability by convincing a user to click a malicious URL. A successful exploit could allow a low-privileged attacker to list, view, create, edit, and delete templates in the same manner as a user with Administrator privileges.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3539" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-authbypass-YVJzqgk2" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json b/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json index e9899d511fd..d413337855f 100644 --- a/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json +++ b/advisories/unreviewed/2024/11/GHSA-xcpr-7mr4-h4xq/GHSA-xcpr-7mr4-h4xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xcpr-7mr4-h4xq", - "modified": "2024-11-18T12:30:43Z", + "modified": "2024-11-18T18:30:55Z", "published": "2024-11-18T12:30:43Z", "aliases": [ "CVE-2024-52316" ], "details": "Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95.\n\nUsers are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-391" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T12:15:18Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xhwg-j3rh-2ffw/GHSA-xhwg-j3rh-2ffw.json b/advisories/unreviewed/2024/11/GHSA-xhwg-j3rh-2ffw/GHSA-xhwg-j3rh-2ffw.json new file mode 100644 index 00000000000..514621fd7cd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xhwg-j3rh-2ffw/GHSA-xhwg-j3rh-2ffw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhwg-j3rh-2ffw", + "modified": "2024-11-18T18:30:59Z", + "published": "2024-11-18T18:30:59Z", + "aliases": [ + "CVE-2020-26067" + ], + "details": "A vulnerability in the web-based interface of Cisco Webex Teams could allow an authenticated, remote attacker to conduct cross-site scripting attacks.\nThe vulnerability is due to improper validation of usernames. An attacker could exploit this vulnerability by creating an account that contains malicious HTML or script content and joining a space using the malicious account name. A successful exploit could allow the attacker to conduct cross-site scripting attacks and potentially gain access to sensitive browser-based information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26067" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-teams-xss-zLW9tD3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-18T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xj4x-m269-rcgc/GHSA-xj4x-m269-rcgc.json b/advisories/unreviewed/2024/11/GHSA-xj4x-m269-rcgc/GHSA-xj4x-m269-rcgc.json index a9136d4c392..6072f58b719 100644 --- a/advisories/unreviewed/2024/11/GHSA-xj4x-m269-rcgc/GHSA-xj4x-m269-rcgc.json +++ b/advisories/unreviewed/2024/11/GHSA-xj4x-m269-rcgc/GHSA-xj4x-m269-rcgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj4x-m269-rcgc", - "modified": "2024-11-09T00:30:42Z", + "modified": "2024-11-18T18:30:47Z", "published": "2024-11-09T00:30:42Z", "aliases": [ "CVE-2024-35420" ], "details": "wac commit 385e1 was discovered to contain a heap overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T22:15:16Z"