Publish Advisories

GHSA-2vf8-hmhp-gw9x
GHSA-7j2j-w9w6-4cg9
GHSA-ggwq-65m4-2gf3
GHSA-x7v5-rxwv-mpjw
GHSA-58mp-9hhc-gwv9
GHSA-h2wx-vrp7-wvmw
GHSA-x6vg-gvf6-hmp9
GHSA-wvw3-cj3j-fc6w
GHSA-9gw4-m84r-cgxj
GHSA-9xjq-9p64-px3q
GHSA-fr6r-4pjc-5pwj
GHSA-qmc7-2p7g-4x4p
This commit is contained in:
advisory-database[bot]
2024-10-27 15:31:41 +00:00
parent 1032bb01d4
commit ac0a445bc8
12 changed files with 278 additions and 25 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vf8-hmhp-gw9x",
"modified": "2024-03-14T00:31:05Z",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-03-08T03:31:25Z",
"aliases": [
"CVE-2024-23293"
],
"details": "This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"
}
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7j2j-w9w6-4cg9",
"modified": "2024-03-14T00:31:05Z",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-03-08T03:31:25Z",
"aliases": [
"CVE-2024-23283"
],
"details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access user-sensitive data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -51,7 +54,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:49Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ggwq-65m4-2gf3",
"modified": "2024-03-14T00:31:05Z",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-03-08T03:31:25Z",
"aliases": [
"CVE-2024-23297"
],
"details": "The issue was addressed with improved checks. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4. A malicious application may be able to access private information.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7v5-rxwv-mpjw",
"modified": "2024-03-14T00:31:05Z",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-03-08T03:31:25Z",
"aliases": [
"CVE-2024-23295"
],
"details": "A permissions issue was addressed to help ensure Personas are always protected This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58mp-9hhc-gwv9",
"modified": "2024-04-08T03:30:53Z",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-04-08T03:30:53Z",
"aliases": [
"CVE-2024-23658"
],
"details": "In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-08T03:15:09Z"
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-367"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9gw4-m84r-cgxj",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-10-27T15:30:43Z",
"aliases": [
"CVE-2024-10418"
],
"details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /file/infoAdd.php. The manipulation of the argument bg leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10418"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/25a103a1fe84c4db4530e68d2f998d11"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281959"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281959"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.431782"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-27T14:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xjq-9p64-px3q",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-10-27T15:30:43Z",
"aliases": [
"CVE-2024-10417"
],
"details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /file/delete.php. The manipulation of the argument bid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10417"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/bf0cf963ec56cfe0dcaba2956352bafd"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281958"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281958"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.431781"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-27T13:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr6r-4pjc-5pwj",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-10-27T15:30:43Z",
"aliases": [
"CVE-2024-10416"
],
"details": "A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /file/cancel.php. The manipulation of the argument reqid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10416"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/18cf04067697c8ceb2cba68980139dcc"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281957"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281957"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.431686"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-27T13:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmc7-2p7g-4x4p",
"modified": "2024-10-27T15:30:43Z",
"published": "2024-10-27T15:30:43Z",
"aliases": [
"CVE-2024-10419"
],
"details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bloodrequest.php. The manipulation of the argument msg leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10419"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/62ad5208270c67834d02818d6ba44126"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281960"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281960"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.431784"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-27T15:15:02Z"
}
}