diff --git a/advisories/unreviewed/2024/02/GHSA-2c3h-gr5x-3fh2/GHSA-2c3h-gr5x-3fh2.json b/advisories/unreviewed/2024/02/GHSA-2c3h-gr5x-3fh2/GHSA-2c3h-gr5x-3fh2.json index 2ce10f2a25e..8235249c701 100644 --- a/advisories/unreviewed/2024/02/GHSA-2c3h-gr5x-3fh2/GHSA-2c3h-gr5x-3fh2.json +++ b/advisories/unreviewed/2024/02/GHSA-2c3h-gr5x-3fh2/GHSA-2c3h-gr5x-3fh2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2c3h-gr5x-3fh2", - "modified": "2024-05-01T18:30:35Z", + "modified": "2024-05-07T06:30:35Z", "published": "2024-02-21T09:31:00Z", "aliases": [ "CVE-2023-42843" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42843" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213981" diff --git a/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json b/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json index 87ee1fc4cb4..408c44421ac 100644 --- a/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json +++ b/advisories/unreviewed/2024/03/GHSA-62qm-vc7f-rm93/GHSA-62qm-vc7f-rm93.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62qm-vc7f-rm93", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-05-07T06:30:35Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23254" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23254" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214081" diff --git a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json index 579ffe6b268..7d33b8d0010 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json +++ b/advisories/unreviewed/2024/03/GHSA-6cvp-282g-6jp8/GHSA-6cvp-282g-6jp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cvp-282g-6jp8", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-05-07T06:30:36Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42950" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42950" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214035" diff --git a/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json b/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json index 21cde7c6da7..e3e877be8bb 100644 --- a/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json +++ b/advisories/unreviewed/2024/03/GHSA-jprr-pf4r-gvp5/GHSA-jprr-pf4r-gvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jprr-pf4r-gvp5", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-05-07T06:30:36Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42956" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42956" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT214035" diff --git a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json index a9182c18972..0f39b5d5822 100644 --- a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json +++ b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppgm-9w39-cx97", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-05-07T06:30:35Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23284" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI" diff --git a/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json b/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json index 1504be89d21..9138dc08f6d 100644 --- a/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json +++ b/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc99-8rmf-q4mv", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-05-07T06:30:35Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23280" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI" diff --git a/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json b/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json index 4fd03d03bb5..1d6224859d9 100644 --- a/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json +++ b/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrrw-7rr2-829v", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-05-07T06:30:35Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23263" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI" diff --git a/advisories/unreviewed/2024/05/GHSA-34vc-vhj3-rw45/GHSA-34vc-vhj3-rw45.json b/advisories/unreviewed/2024/05/GHSA-34vc-vhj3-rw45/GHSA-34vc-vhj3-rw45.json new file mode 100644 index 00000000000..65de5f0182b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-34vc-vhj3-rw45/GHSA-34vc-vhj3-rw45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34vc-vhj3-rw45", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-22472" + ], + "details": "\nA buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution\n\nThis issue affects all versions of Silicon LabsĀ 500 Series SDK prior to v6.85.2\n\nrunning on Silicon Labs 500 series Z-wave devices.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22472" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/068Vm000004rZwm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-423h-mr5w-x796/GHSA-423h-mr5w-x796.json b/advisories/unreviewed/2024/05/GHSA-423h-mr5w-x796/GHSA-423h-mr5w-x796.json new file mode 100644 index 00000000000..3edf58e9a90 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-423h-mr5w-x796/GHSA-423h-mr5w-x796.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-423h-mr5w-x796", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20859" + ], + "details": "Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20859" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5cp5-vw87-7438/GHSA-5cp5-vw87-7438.json b/advisories/unreviewed/2024/05/GHSA-5cp5-vw87-7438/GHSA-5cp5-vw87-7438.json new file mode 100644 index 00000000000..3353440432b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5cp5-vw87-7438/GHSA-5cp5-vw87-7438.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cp5-vw87-7438", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20868" + ], + "details": "Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20868" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7hfh-v896-8423/GHSA-7hfh-v896-8423.json b/advisories/unreviewed/2024/05/GHSA-7hfh-v896-8423/GHSA-7hfh-v896-8423.json new file mode 100644 index 00000000000..c793ec7508e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7hfh-v896-8423/GHSA-7hfh-v896-8423.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hfh-v896-8423", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20871" + ], + "details": "Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20871" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8vh3-cqvx-p653/GHSA-8vh3-cqvx-p653.json b/advisories/unreviewed/2024/05/GHSA-8vh3-cqvx-p653/GHSA-8vh3-cqvx-p653.json new file mode 100644 index 00000000000..38b44b24566 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8vh3-cqvx-p653/GHSA-8vh3-cqvx-p653.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vh3-cqvx-p653", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20855" + ], + "details": "Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20855" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-992p-cx4j-cc56/GHSA-992p-cx4j-cc56.json b/advisories/unreviewed/2024/05/GHSA-992p-cx4j-cc56/GHSA-992p-cx4j-cc56.json new file mode 100644 index 00000000000..6eb5b78a529 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-992p-cx4j-cc56/GHSA-992p-cx4j-cc56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-992p-cx4j-cc56", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20869" + ], + "details": "Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20869" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9x5v-3vg8-q3c9/GHSA-9x5v-3vg8-q3c9.json b/advisories/unreviewed/2024/05/GHSA-9x5v-3vg8-q3c9/GHSA-9x5v-3vg8-q3c9.json new file mode 100644 index 00000000000..8d96f672a0a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9x5v-3vg8-q3c9/GHSA-9x5v-3vg8-q3c9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x5v-3vg8-q3c9", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20866" + ], + "details": "Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20866" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-ggv3-6xpg-23p3/GHSA-ggv3-6xpg-23p3.json b/advisories/unreviewed/2024/05/GHSA-ggv3-6xpg-23p3/GHSA-ggv3-6xpg-23p3.json new file mode 100644 index 00000000000..a04d5ab74e5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-ggv3-6xpg-23p3/GHSA-ggv3-6xpg-23p3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggv3-6xpg-23p3", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20867" + ], + "details": "Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20867" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json b/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json new file mode 100644 index 00000000000..a27fdd8cca2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j33j-2cp2-2wjw", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20862" + ], + "details": "Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20862" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j89p-fgqw-hjm3/GHSA-j89p-fgqw-hjm3.json b/advisories/unreviewed/2024/05/GHSA-j89p-fgqw-hjm3/GHSA-j89p-fgqw-hjm3.json new file mode 100644 index 00000000000..767c94e3dea --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j89p-fgqw-hjm3/GHSA-j89p-fgqw-hjm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j89p-fgqw-hjm3", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20864" + ], + "details": "Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20864" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json b/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json index 343d2eb1c7b..a2258274daf 100644 --- a/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json +++ b/advisories/unreviewed/2024/05/GHSA-jcv7-6v4q-4m7x/GHSA-jcv7-6v4q-4m7x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcv7-6v4q-4m7x", - "modified": "2024-05-07T03:30:35Z", + "modified": "2024-05-07T06:30:36Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2024-3661" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://datatracker.ietf.org/doc/html/rfc3442#section-7" }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=40279632" + }, { "type": "WEB", "url": "https://tunnelvisionbug.com" diff --git a/advisories/unreviewed/2024/05/GHSA-m7gx-pf5v-mw6f/GHSA-m7gx-pf5v-mw6f.json b/advisories/unreviewed/2024/05/GHSA-m7gx-pf5v-mw6f/GHSA-m7gx-pf5v-mw6f.json new file mode 100644 index 00000000000..6728848a095 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-m7gx-pf5v-mw6f/GHSA-m7gx-pf5v-mw6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7gx-pf5v-mw6f", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20865" + ], + "details": "Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20865" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mr2f-mm92-fppw/GHSA-mr2f-mm92-fppw.json b/advisories/unreviewed/2024/05/GHSA-mr2f-mm92-fppw/GHSA-mr2f-mm92-fppw.json new file mode 100644 index 00000000000..5a997551c7f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mr2f-mm92-fppw/GHSA-mr2f-mm92-fppw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr2f-mm92-fppw", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-4186" + ], + "details": "The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This can only be exploited if the 'Email Verification' setting is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4186" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/edwiser-bridge/tags/3.0.4/includes/class-eb-user-manager.php#L1571" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3081961/edwiser-bridge#file1" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6969d281-f280-4714-9859-38ac66e9cc60?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json b/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json new file mode 100644 index 00000000000..dcf55321c0e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p5j5-mxj7-f5fg/GHSA-p5j5-mxj7-f5fg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5j5-mxj7-f5fg", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-3628" + ], + "details": "The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3628" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/171af8eb-ceeb-403a-abc2-969d9535a4c9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q4m7-vjrr-h6rj/GHSA-q4m7-vjrr-h6rj.json b/advisories/unreviewed/2024/05/GHSA-q4m7-vjrr-h6rj/GHSA-q4m7-vjrr-h6rj.json new file mode 100644 index 00000000000..c45d0fa7311 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q4m7-vjrr-h6rj/GHSA-q4m7-vjrr-h6rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4m7-vjrr-h6rj", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20857" + ], + "details": "Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20857" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qrx8-7p7c-vc5w/GHSA-qrx8-7p7c-vc5w.json b/advisories/unreviewed/2024/05/GHSA-qrx8-7p7c-vc5w/GHSA-qrx8-7p7c-vc5w.json new file mode 100644 index 00000000000..3056ad57c8f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qrx8-7p7c-vc5w/GHSA-qrx8-7p7c-vc5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrx8-7p7c-vc5w", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20872" + ], + "details": "Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20872" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rmxp-h7fr-q442/GHSA-rmxp-h7fr-q442.json b/advisories/unreviewed/2024/05/GHSA-rmxp-h7fr-q442/GHSA-rmxp-h7fr-q442.json new file mode 100644 index 00000000000..d089ec2f342 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rmxp-h7fr-q442/GHSA-rmxp-h7fr-q442.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmxp-h7fr-q442", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20870" + ], + "details": "Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20870" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rqph-fqcj-v36g/GHSA-rqph-fqcj-v36g.json b/advisories/unreviewed/2024/05/GHSA-rqph-fqcj-v36g/GHSA-rqph-fqcj-v36g.json new file mode 100644 index 00000000000..4ff5e1b029a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rqph-fqcj-v36g/GHSA-rqph-fqcj-v36g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqph-fqcj-v36g", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20860" + ], + "details": "Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20860" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json b/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json new file mode 100644 index 00000000000..eb711d7d5c5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9v3-78qq-v64f", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20861" + ], + "details": "Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20861" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vp5x-rmv6-9wmp/GHSA-vp5x-rmv6-9wmp.json b/advisories/unreviewed/2024/05/GHSA-vp5x-rmv6-9wmp/GHSA-vp5x-rmv6-9wmp.json new file mode 100644 index 00000000000..bb9821b526f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vp5x-rmv6-9wmp/GHSA-vp5x-rmv6-9wmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp5x-rmv6-9wmp", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20858" + ], + "details": "Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20858" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wvp9-fc5q-j3q4/GHSA-wvp9-fc5q-j3q4.json b/advisories/unreviewed/2024/05/GHSA-wvp9-fc5q-j3q4/GHSA-wvp9-fc5q-j3q4.json new file mode 100644 index 00000000000..d6675035930 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wvp9-fc5q-j3q4/GHSA-wvp9-fc5q-j3q4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvp9-fc5q-j3q4", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20821" + ], + "details": "A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode, which disables security features. This attack needs additional privilege to control TEE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20821" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x67c-fh4p-7v8m/GHSA-x67c-fh4p-7v8m.json b/advisories/unreviewed/2024/05/GHSA-x67c-fh4p-7v8m/GHSA-x67c-fh4p-7v8m.json new file mode 100644 index 00000000000..49bbf599cee --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x67c-fh4p-7v8m/GHSA-x67c-fh4p-7v8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x67c-fh4p-7v8m", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20856" + ], + "details": "Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20856" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json b/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json new file mode 100644 index 00000000000..967358b65c0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6px-gcfp-pfxj", + "modified": "2024-05-07T06:30:36Z", + "published": "2024-05-07T06:30:36Z", + "aliases": [ + "CVE-2024-20863" + ], + "details": "Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20863" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T05:15:50Z" + } +} \ No newline at end of file