From a8d45deabfa51c4969f7d5990370fcbaa5ed6a1c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 28 Nov 2024 00:40:45 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-28fq-q3c7-php2.json | 36 +++++++++++++++++++ .../GHSA-34f4-hghj-ww8r.json | 36 +++++++++++++++++++ .../GHSA-485v-466m-9mjv.json | 29 +++++++++++++++ .../GHSA-4p6c-9pp4-835h.json | 17 +++++---- .../GHSA-5p2r-c897-jgj5.json | 29 +++++++++++++++ .../GHSA-6v84-c4c3-p44c.json | 29 +++++++++++++++ .../GHSA-7485-8f3w-4mrf.json | 29 +++++++++++++++ .../GHSA-79vx-5hp8-mg9f.json | 36 +++++++++++++++++++ .../GHSA-93fw-3pcm-8m72.json | 36 +++++++++++++++++++ .../GHSA-9r96-mx8v-4w4g.json | 36 +++++++++++++++++++ .../GHSA-9vh2-j2vg-h96g.json | 36 +++++++++++++++++++ .../GHSA-c5xq-qh58-5jg9.json | 36 +++++++++++++++++++ .../GHSA-c834-6p5h-vfw8.json | 36 +++++++++++++++++++ .../GHSA-f924-xqm3-3544.json | 36 +++++++++++++++++++ .../GHSA-fvc5-85r6-6h2v.json | 29 +++++++++++++++ .../GHSA-hj2g-qp5m-cjqg.json | 36 +++++++++++++++++++ .../GHSA-hxxf-235m-72v3.json | 4 +-- .../GHSA-jpfm-vcpf-r226.json | 29 +++++++++++++++ .../GHSA-mfqc-rm3c-48wj.json | 36 +++++++++++++++++++ .../GHSA-p3fg-chrp-p7mq.json | 36 +++++++++++++++++++ .../GHSA-p5x9-86p5-59w4.json | 36 +++++++++++++++++++ .../GHSA-qv87-xf2v-gghw.json | 29 +++++++++++++++ .../GHSA-qxrp-vhvm-j765.json | 4 +-- .../GHSA-r756-r5qv-286x.json | 29 +++++++++++++++ .../GHSA-vvqh-p9p4-63x6.json | 36 +++++++++++++++++++ .../GHSA-wrfc-pvp9-mr9g.json | 4 +-- .../GHSA-wv5r-6ww5-7f4f.json | 29 +++++++++++++++ .../GHSA-wxj2-cjm8-36fx.json | 29 +++++++++++++++ .../GHSA-x578-xmfm-9w46.json | 36 +++++++++++++++++++ .../GHSA-x7vw-f2q8-qcmp.json | 36 +++++++++++++++++++ .../GHSA-xf2v-vm6q-p68c.json | 36 +++++++++++++++++++ 31 files changed, 913 insertions(+), 18 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9r96-mx8v-4w4g/GHSA-9r96-mx8v-4w4g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c834-6p5h-vfw8/GHSA-c834-6p5h-vfw8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p3fg-chrp-p7mq/GHSA-p3fg-chrp-p7mq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p5x9-86p5-59w4/GHSA-p5x9-86p5-59w4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vvqh-p9p4-63x6/GHSA-vvqh-p9p4-63x6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x7vw-f2q8-qcmp/GHSA-x7vw-f2q8-qcmp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xf2v-vm6q-p68c/GHSA-xf2v-vm6q-p68c.json diff --git a/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json b/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json new file mode 100644 index 00000000000..1e672d50830 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28fq-q3c7-php2", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2024-11789" + ], + "details": "Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24448.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11789" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1615" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json b/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json new file mode 100644 index 00000000000..d5f75344a68 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34f4-hghj-ww8r", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11800" + ], + "details": "Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24768.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11800" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1626" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json b/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json new file mode 100644 index 00000000000..3b2747e8ece --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-485v-466m-9mjv/GHSA-485v-466m-9mjv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-485v-466m-9mjv", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2017-13320" + ], + "details": "In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13320" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4p6c-9pp4-835h/GHSA-4p6c-9pp4-835h.json b/advisories/unreviewed/2024/11/GHSA-4p6c-9pp4-835h/GHSA-4p6c-9pp4-835h.json index e814d2ad46d..814b74de9bf 100644 --- a/advisories/unreviewed/2024/11/GHSA-4p6c-9pp4-835h/GHSA-4p6c-9pp4-835h.json +++ b/advisories/unreviewed/2024/11/GHSA-4p6c-9pp4-835h/GHSA-4p6c-9pp4-835h.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-4p6c-9pp4-835h", - "modified": "2024-11-08T06:30:48Z", + "modified": "2024-11-28T00:39:25Z", "published": "2024-11-08T06:30:48Z", "aliases": [ "CVE-2024-50187" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Stop the active perfmon before being destroyed\n\nUpon closing the file descriptor, the active performance monitor is not\nstopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`,\nthe active performance monitor's pointer (`vc4->active_perfmon`) is still\nretained.\n\nIf we open a new file descriptor and submit a few jobs with performance\nmonitors, the driver will attempt to stop the active performance monitor\nusing the stale pointer in `vc4->active_perfmon`. However, this pointer\nis no longer valid because the previous process has already terminated,\nand all performance monitors associated with it have been destroyed and\nfreed.\n\nTo fix this, when the active performance monitor belongs to a given\nprocess, explicitly stop it before destroying and freeing it.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,10 +37,8 @@ } ], "database_specific": { - "cwe_ids": [ - - ], - "severity": null, + "cwe_ids": [], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-08T06:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json b/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json new file mode 100644 index 00000000000..07adfe0fba5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5p2r-c897-jgj5/GHSA-5p2r-c897-jgj5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p2r-c897-jgj5", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9349" + ], + "details": "In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9349" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json b/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json new file mode 100644 index 00000000000..d35d3149863 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6v84-c4c3-p44c/GHSA-6v84-c4c3-p44c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v84-c4c3-p44c", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9352" + ], + "details": "In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9352" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json b/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json new file mode 100644 index 00000000000..75a1a459c2f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7485-8f3w-4mrf/GHSA-7485-8f3w-4mrf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7485-8f3w-4mrf", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9374" + ], + "details": "In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9374" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json b/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json new file mode 100644 index 00000000000..b7e20193b31 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79vx-5hp8-mg9f", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2024-11787" + ], + "details": "Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24413.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11787" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1614" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json b/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json new file mode 100644 index 00000000000..f815328edf6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93fw-3pcm-8m72", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11799" + ], + "details": "Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24664.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11799" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1625" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9r96-mx8v-4w4g/GHSA-9r96-mx8v-4w4g.json b/advisories/unreviewed/2024/11/GHSA-9r96-mx8v-4w4g/GHSA-9r96-mx8v-4w4g.json new file mode 100644 index 00000000000..179f2c3a6c0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9r96-mx8v-4w4g/GHSA-9r96-mx8v-4w4g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r96-mx8v-4w4g", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11797" + ], + "details": "Fuji Electric Monitouch V-SFT V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24662.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11797" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json b/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json new file mode 100644 index 00000000000..95208e318a4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vh2-j2vg-h96g", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11802" + ], + "details": "Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24770.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11802" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json b/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json new file mode 100644 index 00000000000..06121298370 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5xq-qh58-5jg9", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2024-11790" + ], + "details": "Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24449.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11790" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1616" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c834-6p5h-vfw8/GHSA-c834-6p5h-vfw8.json b/advisories/unreviewed/2024/11/GHSA-c834-6p5h-vfw8/GHSA-c834-6p5h-vfw8.json new file mode 100644 index 00000000000..ec4672d2af4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c834-6p5h-vfw8/GHSA-c834-6p5h-vfw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c834-6p5h-vfw8", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11798" + ], + "details": "Fuji Electric Monitouch V-SFT X1 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of X1 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24663.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11798" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1624" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json b/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json new file mode 100644 index 00000000000..937b58d10b7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f924-xqm3-3544", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2024-11791" + ], + "details": "Fuji Electric Monitouch V-SFT V8C File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8C files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24450.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11791" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1617" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json b/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json new file mode 100644 index 00000000000..1ac0b4cc977 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fvc5-85r6-6h2v/GHSA-fvc5-85r6-6h2v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvc5-85r6-6h2v", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9353" + ], + "details": "In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9353" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json b/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json new file mode 100644 index 00000000000..48eb11e58ed --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj2g-qp5m-cjqg", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11933" + ], + "details": "Fuji Electric Monitouch V-SFT X1 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of X1 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24548.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11933" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json b/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json index b9d8bc1a733..73be5469e07 100644 --- a/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json +++ b/advisories/unreviewed/2024/11/GHSA-hxxf-235m-72v3/GHSA-hxxf-235m-72v3.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json b/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json new file mode 100644 index 00000000000..ea8fe530a73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jpfm-vcpf-r226/GHSA-jpfm-vcpf-r226.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpfm-vcpf-r226", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9351" + ], + "details": "In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9351" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json b/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json new file mode 100644 index 00000000000..c3f30ff66c7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfqc-rm3c-48wj", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11795" + ], + "details": "Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24505.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11795" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1621" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p3fg-chrp-p7mq/GHSA-p3fg-chrp-p7mq.json b/advisories/unreviewed/2024/11/GHSA-p3fg-chrp-p7mq/GHSA-p3fg-chrp-p7mq.json new file mode 100644 index 00000000000..f37b1ea699c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p3fg-chrp-p7mq/GHSA-p3fg-chrp-p7mq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3fg-chrp-p7mq", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11794" + ], + "details": "Fuji Electric Monitouch V-SFT V10 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24504.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11794" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1620" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p5x9-86p5-59w4/GHSA-p5x9-86p5-59w4.json b/advisories/unreviewed/2024/11/GHSA-p5x9-86p5-59w4/GHSA-p5x9-86p5-59w4.json new file mode 100644 index 00000000000..50c6bc50de1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p5x9-86p5-59w4/GHSA-p5x9-86p5-59w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5x9-86p5-59w4", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2024-11793" + ], + "details": "Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V9C files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24503.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11793" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1619" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json b/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json new file mode 100644 index 00000000000..66be02e7613 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qv87-xf2v-gghw/GHSA-qv87-xf2v-gghw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv87-xf2v-gghw", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9354" + ], + "details": "In VideoFrameScheduler.cpp of VideoFrameScheduler::PLL::fit, there is a possible remote denial of service due to divide by 0. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9354" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json b/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json index 96ad1d8ccf9..de6ae1ace22 100644 --- a/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json +++ b/advisories/unreviewed/2024/11/GHSA-qxrp-vhvm-j765/GHSA-qxrp-vhvm-j765.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json b/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json new file mode 100644 index 00000000000..8b526d8d144 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r756-r5qv-286x/GHSA-r756-r5qv-286x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r756-r5qv-286x", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2018-9350" + ], + "details": "In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9350" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vvqh-p9p4-63x6/GHSA-vvqh-p9p4-63x6.json b/advisories/unreviewed/2024/11/GHSA-vvqh-p9p4-63x6/GHSA-vvqh-p9p4-63x6.json new file mode 100644 index 00000000000..fcdfe443a7f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vvqh-p9p4-63x6/GHSA-vvqh-p9p4-63x6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqh-p9p4-63x6", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11803" + ], + "details": "Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24771.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11803" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1629" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json b/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json index 0fed2a4beb7..6f650674cf7 100644 --- a/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json +++ b/advisories/unreviewed/2024/11/GHSA-wrfc-pvp9-mr9g/GHSA-wrfc-pvp9-mr9g.json @@ -13,9 +13,7 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json b/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json new file mode 100644 index 00000000000..65f3fc748a9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wv5r-6ww5-7f4f/GHSA-wv5r-6ww5-7f4f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv5r-6ww5-7f4f", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2017-13321" + ], + "details": "In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13321" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json b/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json new file mode 100644 index 00000000000..406e59ae428 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wxj2-cjm8-36fx/GHSA-wxj2-cjm8-36fx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxj2-cjm8-36fx", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2017-13323" + ], + "details": "In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13323" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-27T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json b/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json new file mode 100644 index 00000000000..75f96b5839c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x578-xmfm-9w46", + "modified": "2024-11-28T00:39:26Z", + "published": "2024-11-28T00:39:26Z", + "aliases": [ + "CVE-2024-11792" + ], + "details": "Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24502.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11792" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1618" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x7vw-f2q8-qcmp/GHSA-x7vw-f2q8-qcmp.json b/advisories/unreviewed/2024/11/GHSA-x7vw-f2q8-qcmp/GHSA-x7vw-f2q8-qcmp.json new file mode 100644 index 00000000000..3b5120e1a08 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x7vw-f2q8-qcmp/GHSA-x7vw-f2q8-qcmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7vw-f2q8-qcmp", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11796" + ], + "details": "Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V9C files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24506.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11796" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1622" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xf2v-vm6q-p68c/GHSA-xf2v-vm6q-p68c.json b/advisories/unreviewed/2024/11/GHSA-xf2v-vm6q-p68c/GHSA-xf2v-vm6q-p68c.json new file mode 100644 index 00000000000..1e36899781b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xf2v-vm6q-p68c/GHSA-xf2v-vm6q-p68c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf2v-vm6q-p68c", + "modified": "2024-11-28T00:39:27Z", + "published": "2024-11-28T00:39:27Z", + "aliases": [ + "CVE-2024-11801" + ], + "details": "Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24769.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11801" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1627" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T00:15:05Z" + } +} \ No newline at end of file