diff --git a/advisories/unreviewed/2024/03/GHSA-68h2-qgq2-26fg/GHSA-68h2-qgq2-26fg.json b/advisories/unreviewed/2024/03/GHSA-68h2-qgq2-26fg/GHSA-68h2-qgq2-26fg.json new file mode 100644 index 00000000000..5b951755c39 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-68h2-qgq2-26fg/GHSA-68h2-qgq2-26fg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68h2-qgq2-26fg", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-0686" + ], + "details": "Rejected reason: Incorrect assignment", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0686" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json b/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json new file mode 100644 index 00000000000..2ec388079e3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fq2-mvcq-gw26", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-27680" + ], + "details": "Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the \"Contact form.\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27680" + }, + { + "type": "WEB", + "url": "https://github.com/xiaolanjing0/cms/blob/main/4.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6jqg-q6mq-24mg/GHSA-6jqg-q6mq-24mg.json b/advisories/unreviewed/2024/03/GHSA-6jqg-q6mq-24mg/GHSA-6jqg-q6mq-24mg.json new file mode 100644 index 00000000000..66ee4f27025 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6jqg-q6mq-24mg/GHSA-6jqg-q6mq-24mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jqg-q6mq-24mg", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-24901" + ], + "details": "Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24901" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000222691/dsa-2024-062-security-update-for-dell-powerscale-onefs-for-proprietary-code-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-778" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7639-4x37-qfj8/GHSA-7639-4x37-qfj8.json b/advisories/unreviewed/2024/03/GHSA-7639-4x37-qfj8/GHSA-7639-4x37-qfj8.json new file mode 100644 index 00000000000..0837fa63164 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7639-4x37-qfj8/GHSA-7639-4x37-qfj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7639-4x37-qfj8", + "modified": "2024-03-04T15:31:06Z", + "published": "2024-03-04T15:31:06Z", + "aliases": [ + "CVE-2024-0155" + ], + "details": "Dell Digital Delivery, versions prior to 5.0.86.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to an application crash or execution of arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0155" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000222292/dsa-2024-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json b/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json new file mode 100644 index 00000000000..59f60757744 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8f8j-wj6q-42wj/GHSA-8f8j-wj6q-42wj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f8j-wj6q-42wj", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-27684" + ], + "details": "A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27684" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1qu4iBQGeAwolTXjVOTXsAAusSHo2ie-Y/view" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-955p-rhm2-9c6j/GHSA-955p-rhm2-9c6j.json b/advisories/unreviewed/2024/03/GHSA-955p-rhm2-9c6j/GHSA-955p-rhm2-9c6j.json new file mode 100644 index 00000000000..31395f8d460 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-955p-rhm2-9c6j/GHSA-955p-rhm2-9c6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-955p-rhm2-9c6j", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-22452" + ], + "details": "Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability by modifying files in the installation folder to execute arbitrary code, leading to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22452" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000221414/dsa-2024-056" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json b/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json new file mode 100644 index 00000000000..7af6c32d94e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfqh-m928-7c6m", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-27668" + ], + "details": "Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27668" + }, + { + "type": "WEB", + "url": "https://github.com/LY102483/cms/blob/main/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p6cr-4f2h-m98v/GHSA-p6cr-4f2h-m98v.json b/advisories/unreviewed/2024/03/GHSA-p6cr-4f2h-m98v/GHSA-p6cr-4f2h-m98v.json new file mode 100644 index 00000000000..f2f8c978bca --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p6cr-4f2h-m98v/GHSA-p6cr-4f2h-m98v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6cr-4f2h-m98v", + "modified": "2024-03-04T15:31:06Z", + "published": "2024-03-04T15:31:06Z", + "aliases": [ + "CVE-2023-6241" + ], + "details": "Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r11p0 through r25p0; Valhall GPU Kernel Driver: from r19p0 through r25p0, from r29p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6241" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json b/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json new file mode 100644 index 00000000000..0b86dfe3ae4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r345-j492-57q4", + "modified": "2024-03-04T15:31:06Z", + "published": "2024-03-04T15:31:06Z", + "aliases": [ + "CVE-2024-0156" + ], + "details": "\nDell Digital Delivery, versions prior to 5.0.86.0, contain a Buffer Overflow vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0156" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000222536/dsa-2024-032-security-update-for-dell-digital-delivery-for-a-buffer-overflow-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xphf-mrgr-jm6p/GHSA-xphf-mrgr-jm6p.json b/advisories/unreviewed/2024/03/GHSA-xphf-mrgr-jm6p/GHSA-xphf-mrgr-jm6p.json new file mode 100644 index 00000000000..37056028139 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xphf-mrgr-jm6p/GHSA-xphf-mrgr-jm6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xphf-mrgr-jm6p", + "modified": "2024-03-04T15:31:07Z", + "published": "2024-03-04T15:31:07Z", + "aliases": [ + "CVE-2024-22463" + ], + "details": "Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to compromise of confidentiality and integrity of sensitive information", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22463" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000222691/dsa-2024-062-security-update-for-dell-powerscale-onefs-for-proprietary-code-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T14:15:41Z" + } +} \ No newline at end of file