Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-11 21:33:09 +00:00
parent 5a5a48d49e
commit af83453708
25 changed files with 966 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-974p-hhmc-6h46",
"modified": "2024-09-13T21:31:22Z",
"modified": "2024-11-11T21:31:47Z",
"published": "2024-09-13T18:31:48Z",
"aliases": [
"CVE-2024-39924"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0"
},
{
"type": "WEB",
"url": "https://www.mgm-sp.com/cve/missing-authentication-check-for-emergency-access"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r89w-9fr4-c7c9",
"modified": "2024-09-13T21:31:22Z",
"modified": "2024-11-11T21:31:47Z",
"published": "2024-09-13T18:31:48Z",
"aliases": [
"CVE-2024-39925"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0"
},
{
"type": "WEB",
"url": "https://www.mgm-sp.com/cve/missing-rotation-of-the-organization-key"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfwm-h968-g65h",
"modified": "2024-09-13T21:31:22Z",
"modified": "2024-11-11T21:31:47Z",
"published": "2024-09-13T18:31:48Z",
"aliases": [
"CVE-2024-39926"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0"
},
{
"type": "WEB",
"url": "https://www.mgm-sp.com/cve/html-injection-in-vaultwarden"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37r8-854r-595c",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-52530"
],
"details": "GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\\0' characters at the end of header names are ignored, i.e., a \"Transfer-Encoding\\0: chunked\" header is treated the same as a \"Transfer-Encoding: chunked\" header.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52530"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libsoup/-/issues/377"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/402"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:20Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5jpp-jp5m-8w78",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-46963"
],
"details": "The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46963"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.superfast.video.downloader/blob/main/CVE-2024-46963"
},
{
"type": "WEB",
"url": "https://play.google.com/store/apps/details?id=com.superfast.video.downloader"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T21:15:06Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mc3-gwcr-mgc3",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-52531"
],
"details": "GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. Input received over the network cannot trigger this.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52531"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:20Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62gp-cqpw-rgh4",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-10315"
],
"details": "In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10315"
},
{
"type": "WEB",
"url": "https://portal.perforce.com/s/detail/a91PA000001SZVJYA4"
}
],
"database_specific": {
"cwe_ids": [
"CWE-942"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:17Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62pq-m3vv-gfjj",
"modified": "2024-11-11T21:31:47Z",
"published": "2024-11-11T21:31:47Z",
"aliases": [
"CVE-2024-11077"
],
"details": "A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11077"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://github.com/UnrealdDei/cve/blob/main/sql3.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.283872"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.283872"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.441184"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T19:15:03Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r2c-554q-5q54",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-51186"
],
"details": "D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51186"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/D-Link/DIR-820L/CI_ping_addr/README.md"
},
{
"type": "WEB",
"url": "https://legacy.us.dlink.com/pages/product.aspx?id=00c2150966b046b58ba95d8ae3a8f73d"
},
{
"type": "WEB",
"url": "https://www.dlink.com/en"
},
{
"type": "WEB",
"url": "https://www.dlink.com/en/security-bulletin"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:17Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-742m-mjf5-8f66",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-11078"
],
"details": "A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11078"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://github.com/UnrealdDei/cve/blob/main/xss.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.283873"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.283873"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.441187"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:17Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pj5-4fw9-jfjq",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-46965"
],
"details": "The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46965"
},
{
"type": "WEB",
"url": "https://github.com/actuator/allvideo.downloader.browser/blob/main/CVE-2024-46965"
},
{
"type": "WEB",
"url": "https://play.google.com/store/apps/details?id=allvideo.downloader.browser"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:17Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x5h-hfqw-552w",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-51190"
],
"details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51190"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Special_AP/README.md"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:18Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92m5-rpfj-8332",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-44546"
],
"details": "Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44546"
},
{
"type": "WEB",
"url": "https://gist.github.com/jwx0539/5151f53ec497474cab6af4fa8ee6b6f7"
},
{
"type": "WEB",
"url": "https://github.com/PowerJob/PowerJob"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T21:15:06Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c6xg-p6mw-qxxr",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-46962"
],
"details": "The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46962"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.downloader.video.fast/blob/main/CVE-2024-46962"
},
{
"type": "WEB",
"url": "https://play.google.com/store/apps/details?id=com.downloader.video.fast"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T21:15:06Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj5q-856p-33fg",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-51189"
],
"details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51189"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Filter/README.md"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:18Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cx99-h4rf-2j49",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-50667"
],
"details": "The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50667"
},
{
"type": "WEB",
"url": "https://github.com/ixout/iotVuls/blob/main/Trendnet/TEW_820/report.md"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/support/support-detail.asp?prod=100_TEW-820AP"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T19:15:03Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6qg-rg6j-cxgf",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-52532"
],
"details": "GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52532"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libsoup/-/issues/391"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/410"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:20Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g6gg-3vqf-rfrx",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-48322"
],
"details": "UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48322"
},
{
"type": "WEB",
"url": "https://github.com/runcodes-icmc/server/issues/12"
},
{
"type": "WEB",
"url": "https://github.com/runcodes-icmc/server"
},
{
"type": "WEB",
"url": "https://github.com/runcodes-icmc/server/releases/tag/v1.5.3"
},
{
"type": "WEB",
"url": "https://github.com/trqt/CVE-2024-48322"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:17Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gf2c-phc6-4g3w",
"modified": "2024-11-11T21:31:48Z",
"published": "2024-11-11T21:31:48Z",
"aliases": [
"CVE-2024-51188"
],
"details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51188"
},
{
"type": "WEB",
"url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Virtual_Server/README.md"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP"
},
{
"type": "WEB",
"url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T20:15:18Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2xv-hq2x-rvxq",
"modified": "2024-11-11T21:31:49Z",
"published": "2024-11-11T21:31:49Z",
"aliases": [
"CVE-2024-51026"
],
"details": "The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51026"
},
{
"type": "WEB",
"url": "https://github.com/BrotherOfJhonny/CVE-2024-51026_Overview"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-11T21:15:06Z"
}
}

Some files were not shown because too many files have changed in this diff Show More