From b0054ff2d98be1c90bb74629597317d71a0f51e7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 27 Aug 2024 21:32:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-f4cj-v28g-9hh9.json | 2 +- .../GHSA-ph9g-g7m5-2pg5.json | 2 +- .../GHSA-wxv8-6x37-53r6.json | 2 +- .../GHSA-67f2-j5vg-639w.json | 2 +- .../GHSA-2p37-96m9-9qq9.json | 4 +- .../GHSA-g9fc-wq66-mpcr.json | 2 +- .../GHSA-hrfw-pwjg-7prc.json | 5 +- .../GHSA-3m2w-jxjv-4wfv.json | 11 ++-- .../GHSA-53fp-rvgh-5wr6.json | 11 ++-- .../GHSA-599j-qj67-hr6x.json | 11 ++-- .../GHSA-5g9g-vh54-q73c.json | 11 ++-- .../GHSA-9426-vxhj-rxm5.json | 11 ++-- .../GHSA-c2cc-r8fq-338p.json | 11 ++-- .../GHSA-hhg5-qh7h-f99g.json | 11 ++-- .../GHSA-j39f-fqh7-4887.json | 2 +- .../GHSA-jxr4-5qvc-pqfm.json | 11 ++-- .../GHSA-qjr7-7f86-j28r.json | 11 ++-- .../GHSA-r2cr-gm62-vm8v.json | 11 ++-- .../GHSA-rjx3-xwwm-jhj5.json | 11 ++-- .../GHSA-vqx4-jcwp-8g92.json | 11 ++-- .../GHSA-275x-9ffh-fhq2.json | 11 ++-- .../GHSA-3rwc-8hqh-2vxh.json | 11 ++-- .../GHSA-45mc-5wq7-gwvh.json | 11 ++-- .../GHSA-4fwq-rwj5-pm2v.json | 9 ++- .../GHSA-4qv4-vh73-q92w.json | 11 ++-- .../GHSA-5v3g-553g-mcmp.json | 11 ++-- .../GHSA-669w-wwp7-2p8m.json | 11 ++-- .../GHSA-6frx-mq4h-6r95.json | 11 ++-- .../GHSA-6q5p-rp5c-wmph.json | 11 ++-- .../GHSA-6r3q-8mcr-xqjw.json | 11 ++-- .../GHSA-6vj5-v9m4-vvmg.json | 11 ++-- .../GHSA-6wfg-rr5q-wg74.json | 11 ++-- .../GHSA-7vrj-g8g5-m532.json | 11 ++-- .../GHSA-88v9-rfqm-4wj5.json | 11 ++-- .../GHSA-c2c4-4544-w949.json | 11 ++-- .../GHSA-cm37-53wc-mx6g.json | 9 ++- .../GHSA-fpcv-v65p-wv5w.json | 11 ++-- .../GHSA-gmh5-hrww-qvc2.json | 11 ++-- .../GHSA-hc48-625f-hwjq.json | 11 ++-- .../GHSA-hp9q-xmc4-g3pr.json | 11 ++-- .../GHSA-j4wq-m2h7-q8qx.json | 11 ++-- .../GHSA-mwm3-q3pf-fp7v.json | 9 ++- .../GHSA-p53h-fpw3-ffwh.json | 11 ++-- .../GHSA-q699-2648-qrc2.json | 11 ++-- .../GHSA-qpg5-fc22-gh5w.json | 9 ++- .../GHSA-rggc-4jrg-r8g6.json | 11 ++-- .../GHSA-rjwj-693g-mq28.json | 9 ++- .../GHSA-rx25-q489-m9cc.json | 11 ++-- .../GHSA-vj6h-9583-2qx2.json | 11 ++-- .../GHSA-vpp6-9fcm-rv58.json | 11 ++-- .../GHSA-wxwf-h485-h4x8.json | 11 ++-- .../GHSA-29r2-4vgj-7729.json | 11 ++-- .../GHSA-5h4m-75jp-hg7m.json | 11 ++-- .../GHSA-5qgx-xxph-rwjx.json | 11 ++-- .../GHSA-9wj5-w226-r39m.json | 2 +- .../GHSA-rmv2-vqg4-6ggj.json | 11 ++-- .../GHSA-2hgc-w527-6cxw.json | 11 ++-- .../GHSA-3q8r-mh7f-v4r2.json | 11 ++-- .../GHSA-9hg8-83gp-55g2.json | 11 ++-- .../GHSA-c8cc-57pq-936r.json | 11 ++-- .../GHSA-ffpm-gq7j-8x7r.json | 11 ++-- .../GHSA-gwmp-87px-jxrx.json | 9 ++- .../GHSA-hmgj-4596-mmpr.json | 11 ++-- .../GHSA-mhr3-x4xm-6j7c.json | 11 ++-- .../GHSA-qwxv-c47r-2c92.json | 9 ++- .../GHSA-r3vw-m8qr-8f9r.json | 11 ++-- .../GHSA-v4gm-xx5v-3j7m.json | 11 ++-- .../GHSA-w738-qp3q-hrfg.json | 11 ++-- .../GHSA-vjgx-4h24-68wp.json | 11 ++-- .../GHSA-2hph-w7cx-74wr.json | 62 +++++++++++++++++++ .../GHSA-364c-g6gq-6jw3.json | 11 ++-- .../GHSA-3qv5-2hqj-p2wq.json | 11 ++-- .../GHSA-6frw-26pf-8hp9.json | 58 +++++++++++++++++ .../GHSA-6q99-8h4h-jqfw.json | 11 ++-- .../GHSA-8cr7-x5g8-m3f3.json | 38 ++++++++++++ .../GHSA-98g8-h992-mhww.json | 11 ++-- .../GHSA-c7vp-757h-879w.json | 62 +++++++++++++++++++ .../GHSA-gp65-r3h2-m7mh.json | 39 ++++++++++++ .../GHSA-grjj-54gm-q5vf.json | 38 ++++++++++++ .../GHSA-hchh-wrf4-gc5c.json | 62 +++++++++++++++++++ .../GHSA-hqgg-5wv8-wwxg.json | 11 ++-- .../GHSA-jwjf-h4v6-qrpp.json | 38 ++++++++++++ .../GHSA-p6m4-jqc8-546h.json | 11 ++-- .../GHSA-pqpf-8gv5-j9mf.json | 50 +++++++++++++++ .../GHSA-r7vw-6xhh-5gwh.json | 58 +++++++++++++++++ .../GHSA-rrg9-cmw9-3pwx.json | 38 ++++++++++++ .../GHSA-vcw3-hwj8-8j82.json | 11 ++-- .../GHSA-vwcr-cpgw-p977.json | 62 +++++++++++++++++++ .../GHSA-wwqr-qf45-7869.json | 11 ++-- .../GHSA-x72g-3j3q-w4wf.json | 11 ++-- .../GHSA-xv9x-vwxf-xx9x.json | 62 +++++++++++++++++++ 91 files changed, 1155 insertions(+), 280 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-2hph-w7cx-74wr/GHSA-2hph-w7cx-74wr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6frw-26pf-8hp9/GHSA-6frw-26pf-8hp9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8cr7-x5g8-m3f3/GHSA-8cr7-x5g8-m3f3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gp65-r3h2-m7mh/GHSA-gp65-r3h2-m7mh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-grjj-54gm-q5vf/GHSA-grjj-54gm-q5vf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jwjf-h4v6-qrpp/GHSA-jwjf-h4v6-qrpp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pqpf-8gv5-j9mf/GHSA-pqpf-8gv5-j9mf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r7vw-6xhh-5gwh/GHSA-r7vw-6xhh-5gwh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rrg9-cmw9-3pwx/GHSA-rrg9-cmw9-3pwx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json diff --git a/advisories/unreviewed/2023/07/GHSA-f4cj-v28g-9hh9/GHSA-f4cj-v28g-9hh9.json b/advisories/unreviewed/2023/07/GHSA-f4cj-v28g-9hh9/GHSA-f4cj-v28g-9hh9.json index 7c0680fd45f..216e512f62c 100644 --- a/advisories/unreviewed/2023/07/GHSA-f4cj-v28g-9hh9/GHSA-f4cj-v28g-9hh9.json +++ b/advisories/unreviewed/2023/07/GHSA-f4cj-v28g-9hh9/GHSA-f4cj-v28g-9hh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4cj-v28g-9hh9", - "modified": "2023-11-17T21:30:26Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-07-18T00:31:08Z", "aliases": [ "CVE-2023-38427" diff --git a/advisories/unreviewed/2023/07/GHSA-ph9g-g7m5-2pg5/GHSA-ph9g-g7m5-2pg5.json b/advisories/unreviewed/2023/07/GHSA-ph9g-g7m5-2pg5/GHSA-ph9g-g7m5-2pg5.json index 3e70d8cdc4b..a5f2c8a56cc 100644 --- a/advisories/unreviewed/2023/07/GHSA-ph9g-g7m5-2pg5/GHSA-ph9g-g7m5-2pg5.json +++ b/advisories/unreviewed/2023/07/GHSA-ph9g-g7m5-2pg5/GHSA-ph9g-g7m5-2pg5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph9g-g7m5-2pg5", - "modified": "2023-12-04T15:31:54Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-07-24T18:30:43Z", "aliases": [ "CVE-2023-32247" diff --git a/advisories/unreviewed/2023/07/GHSA-wxv8-6x37-53r6/GHSA-wxv8-6x37-53r6.json b/advisories/unreviewed/2023/07/GHSA-wxv8-6x37-53r6/GHSA-wxv8-6x37-53r6.json index 60ffc914d77..4d650638a62 100644 --- a/advisories/unreviewed/2023/07/GHSA-wxv8-6x37-53r6/GHSA-wxv8-6x37-53r6.json +++ b/advisories/unreviewed/2023/07/GHSA-wxv8-6x37-53r6/GHSA-wxv8-6x37-53r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxv8-6x37-53r6", - "modified": "2023-11-24T09:30:27Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-07-24T18:30:43Z", "aliases": [ "CVE-2023-32252" diff --git a/advisories/unreviewed/2023/10/GHSA-67f2-j5vg-639w/GHSA-67f2-j5vg-639w.json b/advisories/unreviewed/2023/10/GHSA-67f2-j5vg-639w/GHSA-67f2-j5vg-639w.json index 9b939b060ff..6de69b216c0 100644 --- a/advisories/unreviewed/2023/10/GHSA-67f2-j5vg-639w/GHSA-67f2-j5vg-639w.json +++ b/advisories/unreviewed/2023/10/GHSA-67f2-j5vg-639w/GHSA-67f2-j5vg-639w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67f2-j5vg-639w", - "modified": "2023-11-10T18:30:19Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-10-15T03:30:30Z", "aliases": [ "CVE-2023-45871" diff --git a/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json b/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json index d341a71403f..e4ef0e370a2 100644 --- a/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json +++ b/advisories/unreviewed/2023/12/GHSA-2p37-96m9-9qq9/GHSA-2p37-96m9-9qq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2p37-96m9-9qq9", - "modified": "2023-12-27T21:31:00Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-12-22T21:30:23Z", "aliases": [ "CVE-2023-51015" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-g9fc-wq66-mpcr/GHSA-g9fc-wq66-mpcr.json b/advisories/unreviewed/2023/12/GHSA-g9fc-wq66-mpcr/GHSA-g9fc-wq66-mpcr.json index 7bb3e4101f9..1e02a7a7d02 100644 --- a/advisories/unreviewed/2023/12/GHSA-g9fc-wq66-mpcr/GHSA-g9fc-wq66-mpcr.json +++ b/advisories/unreviewed/2023/12/GHSA-g9fc-wq66-mpcr/GHSA-g9fc-wq66-mpcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9fc-wq66-mpcr", - "modified": "2023-12-22T12:31:46Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-12-19T15:30:30Z", "aliases": [ "CVE-2023-6866" diff --git a/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json b/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json index f20a7bcb504..7cb4be02673 100644 --- a/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json +++ b/advisories/unreviewed/2023/12/GHSA-hrfw-pwjg-7prc/GHSA-hrfw-pwjg-7prc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrfw-pwjg-7prc", - "modified": "2024-01-05T00:30:28Z", + "modified": "2024-08-27T21:31:10Z", "published": "2023-12-29T06:30:29Z", "aliases": [ "CVE-2023-31296" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1236" + "CWE-1236", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3m2w-jxjv-4wfv/GHSA-3m2w-jxjv-4wfv.json b/advisories/unreviewed/2024/02/GHSA-3m2w-jxjv-4wfv/GHSA-3m2w-jxjv-4wfv.json index d3d18d26829..f990d32ccc9 100644 --- a/advisories/unreviewed/2024/02/GHSA-3m2w-jxjv-4wfv/GHSA-3m2w-jxjv-4wfv.json +++ b/advisories/unreviewed/2024/02/GHSA-3m2w-jxjv-4wfv/GHSA-3m2w-jxjv-4wfv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3m2w-jxjv-4wfv", - "modified": "2024-02-15T00:30:33Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-15T00:30:33Z", "aliases": [ "CVE-2024-24301" ], "details": "Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-53fp-rvgh-5wr6/GHSA-53fp-rvgh-5wr6.json b/advisories/unreviewed/2024/02/GHSA-53fp-rvgh-5wr6/GHSA-53fp-rvgh-5wr6.json index 6e87a6b0d03..2aef10e7430 100644 --- a/advisories/unreviewed/2024/02/GHSA-53fp-rvgh-5wr6/GHSA-53fp-rvgh-5wr6.json +++ b/advisories/unreviewed/2024/02/GHSA-53fp-rvgh-5wr6/GHSA-53fp-rvgh-5wr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53fp-rvgh-5wr6", - "modified": "2024-02-29T00:30:23Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-29T00:30:23Z", "aliases": [ "CVE-2024-25868" ], "details": "A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T22:15:26Z" diff --git a/advisories/unreviewed/2024/02/GHSA-599j-qj67-hr6x/GHSA-599j-qj67-hr6x.json b/advisories/unreviewed/2024/02/GHSA-599j-qj67-hr6x/GHSA-599j-qj67-hr6x.json index 372cf399435..cf5c1d7201c 100644 --- a/advisories/unreviewed/2024/02/GHSA-599j-qj67-hr6x/GHSA-599j-qj67-hr6x.json +++ b/advisories/unreviewed/2024/02/GHSA-599j-qj67-hr6x/GHSA-599j-qj67-hr6x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-599j-qj67-hr6x", - "modified": "2024-02-27T00:32:04Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-27T00:32:04Z", "aliases": [ "CVE-2024-25751" ], "details": "A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T22:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json b/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json index b84c63efe29..eb3fb13d156 100644 --- a/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json +++ b/advisories/unreviewed/2024/02/GHSA-5g9g-vh54-q73c/GHSA-5g9g-vh54-q73c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5g9g-vh54-q73c", - "modified": "2024-02-24T00:30:20Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-24T00:30:20Z", "aliases": [ "CVE-2024-25469" ], "details": "SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-23T23:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9426-vxhj-rxm5/GHSA-9426-vxhj-rxm5.json b/advisories/unreviewed/2024/02/GHSA-9426-vxhj-rxm5/GHSA-9426-vxhj-rxm5.json index f9b7845d011..25daaea0216 100644 --- a/advisories/unreviewed/2024/02/GHSA-9426-vxhj-rxm5/GHSA-9426-vxhj-rxm5.json +++ b/advisories/unreviewed/2024/02/GHSA-9426-vxhj-rxm5/GHSA-9426-vxhj-rxm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9426-vxhj-rxm5", - "modified": "2024-02-29T03:33:09Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-29T03:33:09Z", "aliases": [ "CVE-2022-34269" ], "details": "An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:35:13Z" diff --git a/advisories/unreviewed/2024/02/GHSA-c2cc-r8fq-338p/GHSA-c2cc-r8fq-338p.json b/advisories/unreviewed/2024/02/GHSA-c2cc-r8fq-338p/GHSA-c2cc-r8fq-338p.json index 8bdf738d46d..5334e86148b 100644 --- a/advisories/unreviewed/2024/02/GHSA-c2cc-r8fq-338p/GHSA-c2cc-r8fq-338p.json +++ b/advisories/unreviewed/2024/02/GHSA-c2cc-r8fq-338p/GHSA-c2cc-r8fq-338p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2cc-r8fq-338p", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40106" ], "details": "In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hhg5-qh7h-f99g/GHSA-hhg5-qh7h-f99g.json b/advisories/unreviewed/2024/02/GHSA-hhg5-qh7h-f99g/GHSA-hhg5-qh7h-f99g.json index ebc1aae9904..8a68a404ecc 100644 --- a/advisories/unreviewed/2024/02/GHSA-hhg5-qh7h-f99g/GHSA-hhg5-qh7h-f99g.json +++ b/advisories/unreviewed/2024/02/GHSA-hhg5-qh7h-f99g/GHSA-hhg5-qh7h-f99g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hhg5-qh7h-f99g", - "modified": "2024-02-22T00:31:01Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-22T00:31:00Z", "aliases": [ "CVE-2023-51828" ], "details": "A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T22:15:48Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j39f-fqh7-4887/GHSA-j39f-fqh7-4887.json b/advisories/unreviewed/2024/02/GHSA-j39f-fqh7-4887/GHSA-j39f-fqh7-4887.json index 61a51278d43..65c19d28653 100644 --- a/advisories/unreviewed/2024/02/GHSA-j39f-fqh7-4887/GHSA-j39f-fqh7-4887.json +++ b/advisories/unreviewed/2024/02/GHSA-j39f-fqh7-4887/GHSA-j39f-fqh7-4887.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-jxr4-5qvc-pqfm/GHSA-jxr4-5qvc-pqfm.json b/advisories/unreviewed/2024/02/GHSA-jxr4-5qvc-pqfm/GHSA-jxr4-5qvc-pqfm.json index 23795c247c3..1aee41c856a 100644 --- a/advisories/unreviewed/2024/02/GHSA-jxr4-5qvc-pqfm/GHSA-jxr4-5qvc-pqfm.json +++ b/advisories/unreviewed/2024/02/GHSA-jxr4-5qvc-pqfm/GHSA-jxr4-5qvc-pqfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxr4-5qvc-pqfm", - "modified": "2024-02-27T03:31:02Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-27T03:31:02Z", "aliases": [ "CVE-2023-41506" ], "details": "An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T02:15:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qjr7-7f86-j28r/GHSA-qjr7-7f86-j28r.json b/advisories/unreviewed/2024/02/GHSA-qjr7-7f86-j28r/GHSA-qjr7-7f86-j28r.json index 15e304897aa..d9efc2d83e9 100644 --- a/advisories/unreviewed/2024/02/GHSA-qjr7-7f86-j28r/GHSA-qjr7-7f86-j28r.json +++ b/advisories/unreviewed/2024/02/GHSA-qjr7-7f86-j28r/GHSA-qjr7-7f86-j28r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qjr7-7f86-j28r", - "modified": "2024-02-29T03:33:18Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-26471" ], "details": "A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:18Z" diff --git a/advisories/unreviewed/2024/02/GHSA-r2cr-gm62-vm8v/GHSA-r2cr-gm62-vm8v.json b/advisories/unreviewed/2024/02/GHSA-r2cr-gm62-vm8v/GHSA-r2cr-gm62-vm8v.json index 383dc89a6d3..39bba992629 100644 --- a/advisories/unreviewed/2024/02/GHSA-r2cr-gm62-vm8v/GHSA-r2cr-gm62-vm8v.json +++ b/advisories/unreviewed/2024/02/GHSA-r2cr-gm62-vm8v/GHSA-r2cr-gm62-vm8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2cr-gm62-vm8v", - "modified": "2024-02-29T03:33:17Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-23052" ], "details": "An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json b/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json index 70612afa810..731c117eada 100644 --- a/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json +++ b/advisories/unreviewed/2024/02/GHSA-rjx3-xwwm-jhj5/GHSA-rjx3-xwwm-jhj5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rjx3-xwwm-jhj5", - "modified": "2024-05-01T21:30:30Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-25081" ], "details": "Splinefont in FontForge through 20230101 allows command injection via crafted filenames.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:27:58Z" diff --git a/advisories/unreviewed/2024/02/GHSA-vqx4-jcwp-8g92/GHSA-vqx4-jcwp-8g92.json b/advisories/unreviewed/2024/02/GHSA-vqx4-jcwp-8g92/GHSA-vqx4-jcwp-8g92.json index 90c407dfc08..72c9845bee6 100644 --- a/advisories/unreviewed/2024/02/GHSA-vqx4-jcwp-8g92/GHSA-vqx4-jcwp-8g92.json +++ b/advisories/unreviewed/2024/02/GHSA-vqx4-jcwp-8g92/GHSA-vqx4-jcwp-8g92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqx4-jcwp-8g92", - "modified": "2024-02-29T03:33:17Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-22939" ], "details": "Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-275x-9ffh-fhq2/GHSA-275x-9ffh-fhq2.json b/advisories/unreviewed/2024/03/GHSA-275x-9ffh-fhq2/GHSA-275x-9ffh-fhq2.json index b8a2c8f6054..4c1d2df4aa9 100644 --- a/advisories/unreviewed/2024/03/GHSA-275x-9ffh-fhq2/GHSA-275x-9ffh-fhq2.json +++ b/advisories/unreviewed/2024/03/GHSA-275x-9ffh-fhq2/GHSA-275x-9ffh-fhq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-275x-9ffh-fhq2", - "modified": "2024-03-25T15:30:39Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-25T15:30:39Z", "aliases": [ "CVE-2024-28393" ], "details": "SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T14:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json b/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json index 0a5730aa99e..36e8880b120 100644 --- a/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json +++ b/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rwc-8hqh-2vxh", - "modified": "2024-03-28T15:30:33Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-30587" ], "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T14:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json b/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json index 8363ba4b20f..fdd361019a4 100644 --- a/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json +++ b/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45mc-5wq7-gwvh", - "modified": "2024-03-28T15:30:33Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-30600" ], "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T15:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json b/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json index 0fd6f44541a..16bc4cbd103 100644 --- a/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json +++ b/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fwq-rwj5-pm2v", - "modified": "2024-03-28T03:30:59Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-28012" ], "details": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4qv4-vh73-q92w/GHSA-4qv4-vh73-q92w.json b/advisories/unreviewed/2024/03/GHSA-4qv4-vh73-q92w/GHSA-4qv4-vh73-q92w.json index 794aca29893..e5221a2200e 100644 --- a/advisories/unreviewed/2024/03/GHSA-4qv4-vh73-q92w/GHSA-4qv4-vh73-q92w.json +++ b/advisories/unreviewed/2024/03/GHSA-4qv4-vh73-q92w/GHSA-4qv4-vh73-q92w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qv4-vh73-q92w", - "modified": "2024-03-22T00:31:14Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-22T00:31:14Z", "aliases": [ "CVE-2023-42954" ], "details": "A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-250" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T23:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json b/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json index 6c5b3a364ad..7a0b89cc3c0 100644 --- a/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json +++ b/advisories/unreviewed/2024/03/GHSA-5v3g-553g-mcmp/GHSA-5v3g-553g-mcmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5v3g-553g-mcmp", - "modified": "2024-03-29T15:30:31Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-29T15:30:31Z", "aliases": [ "CVE-2024-30630" ], "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json b/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json index ec263733f81..bc3945d7b16 100644 --- a/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json +++ b/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-669w-wwp7-2p8m", - "modified": "2024-03-28T15:30:33Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-30606" ], "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T14:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6frx-mq4h-6r95/GHSA-6frx-mq4h-6r95.json b/advisories/unreviewed/2024/03/GHSA-6frx-mq4h-6r95/GHSA-6frx-mq4h-6r95.json index 3b1643332d4..99190930c94 100644 --- a/advisories/unreviewed/2024/03/GHSA-6frx-mq4h-6r95/GHSA-6frx-mq4h-6r95.json +++ b/advisories/unreviewed/2024/03/GHSA-6frx-mq4h-6r95/GHSA-6frx-mq4h-6r95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6frx-mq4h-6r95", - "modified": "2024-03-15T09:30:37Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-15T09:30:37Z", "aliases": [ "CVE-2024-28353" ], "details": "There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T08:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json b/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json index a2fb05225bd..6c483b088a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json +++ b/advisories/unreviewed/2024/03/GHSA-6q5p-rp5c-wmph/GHSA-6q5p-rp5c-wmph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q5p-rp5c-wmph", - "modified": "2024-04-19T03:31:02Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2024-22857" ], "details": "zlog 1.2.16 has a heap-based buffer overflow in struct zlog_rule_s while creating a new rule that is already defined in the provided configuration file. A regular user can achieve arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T01:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json b/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json index dee9e17eb37..460d2205e4b 100644 --- a/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json +++ b/advisories/unreviewed/2024/03/GHSA-6r3q-8mcr-xqjw/GHSA-6r3q-8mcr-xqjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6r3q-8mcr-xqjw", - "modified": "2024-03-29T15:30:30Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-29T15:30:30Z", "aliases": [ "CVE-2024-30626" ], "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:16Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6vj5-v9m4-vvmg/GHSA-6vj5-v9m4-vvmg.json b/advisories/unreviewed/2024/03/GHSA-6vj5-v9m4-vvmg/GHSA-6vj5-v9m4-vvmg.json index 44b8fa33b2d..03356747c40 100644 --- a/advisories/unreviewed/2024/03/GHSA-6vj5-v9m4-vvmg/GHSA-6vj5-v9m4-vvmg.json +++ b/advisories/unreviewed/2024/03/GHSA-6vj5-v9m4-vvmg/GHSA-6vj5-v9m4-vvmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6vj5-v9m4-vvmg", - "modified": "2024-03-05T09:31:19Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-05T09:31:19Z", "aliases": [ "CVE-2024-26333" ], "details": "swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T08:15:39Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6wfg-rr5q-wg74/GHSA-6wfg-rr5q-wg74.json b/advisories/unreviewed/2024/03/GHSA-6wfg-rr5q-wg74/GHSA-6wfg-rr5q-wg74.json index c439cb6f876..01bb9896c8e 100644 --- a/advisories/unreviewed/2024/03/GHSA-6wfg-rr5q-wg74/GHSA-6wfg-rr5q-wg74.json +++ b/advisories/unreviewed/2024/03/GHSA-6wfg-rr5q-wg74/GHSA-6wfg-rr5q-wg74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6wfg-rr5q-wg74", - "modified": "2024-03-24T00:30:32Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-24T00:30:32Z", "aliases": [ "CVE-2024-24725" ], "details": "Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-23T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7vrj-g8g5-m532/GHSA-7vrj-g8g5-m532.json b/advisories/unreviewed/2024/03/GHSA-7vrj-g8g5-m532/GHSA-7vrj-g8g5-m532.json index a75199204b4..bf7e5142995 100644 --- a/advisories/unreviewed/2024/03/GHSA-7vrj-g8g5-m532/GHSA-7vrj-g8g5-m532.json +++ b/advisories/unreviewed/2024/03/GHSA-7vrj-g8g5-m532/GHSA-7vrj-g8g5-m532.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vrj-g8g5-m532", - "modified": "2024-03-08T03:31:25Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-25845" ], "details": "In the module \"CD Custom Fields 4 Orders\" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-88v9-rfqm-4wj5/GHSA-88v9-rfqm-4wj5.json b/advisories/unreviewed/2024/03/GHSA-88v9-rfqm-4wj5/GHSA-88v9-rfqm-4wj5.json index 628d940d28d..35ffa7d79b0 100644 --- a/advisories/unreviewed/2024/03/GHSA-88v9-rfqm-4wj5/GHSA-88v9-rfqm-4wj5.json +++ b/advisories/unreviewed/2024/03/GHSA-88v9-rfqm-4wj5/GHSA-88v9-rfqm-4wj5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-88v9-rfqm-4wj5", - "modified": "2024-03-28T21:30:31Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T21:30:31Z", "aliases": [ "CVE-2024-27719" ], "details": "A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c2c4-4544-w949/GHSA-c2c4-4544-w949.json b/advisories/unreviewed/2024/03/GHSA-c2c4-4544-w949/GHSA-c2c4-4544-w949.json index ac31eff2fcc..0a5d3b40e2a 100644 --- a/advisories/unreviewed/2024/03/GHSA-c2c4-4544-w949/GHSA-c2c4-4544-w949.json +++ b/advisories/unreviewed/2024/03/GHSA-c2c4-4544-w949/GHSA-c2c4-4544-w949.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2c4-4544-w949", - "modified": "2024-03-15T03:30:52Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-15T03:30:52Z", "aliases": [ "CVE-2024-26540" ], "details": "A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg::_load_analyze.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T01:15:58Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cm37-53wc-mx6g/GHSA-cm37-53wc-mx6g.json b/advisories/unreviewed/2024/03/GHSA-cm37-53wc-mx6g/GHSA-cm37-53wc-mx6g.json index 6335737831b..1b6adc31525 100644 --- a/advisories/unreviewed/2024/03/GHSA-cm37-53wc-mx6g/GHSA-cm37-53wc-mx6g.json +++ b/advisories/unreviewed/2024/03/GHSA-cm37-53wc-mx6g/GHSA-cm37-53wc-mx6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cm37-53wc-mx6g", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-22T15:31:06Z", "aliases": [ "CVE-2024-29944" ], "details": "An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T13:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json b/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json index b1493ad797d..6239e63b65e 100644 --- a/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json +++ b/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpcv-v65p-wv5w", - "modified": "2024-03-25T21:31:08Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-25T21:31:08Z", "aliases": [ "CVE-2024-29666" ], "details": "Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1393" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T19:15:59Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gmh5-hrww-qvc2/GHSA-gmh5-hrww-qvc2.json b/advisories/unreviewed/2024/03/GHSA-gmh5-hrww-qvc2/GHSA-gmh5-hrww-qvc2.json index efb19c30cd7..72d1ab010e1 100644 --- a/advisories/unreviewed/2024/03/GHSA-gmh5-hrww-qvc2/GHSA-gmh5-hrww-qvc2.json +++ b/advisories/unreviewed/2024/03/GHSA-gmh5-hrww-qvc2/GHSA-gmh5-hrww-qvc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmh5-hrww-qvc2", - "modified": "2024-03-28T21:30:31Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T21:30:31Z", "aliases": [ "CVE-2024-28713" ], "details": "An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json b/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json index 115a12c7abd..03c31723a5a 100644 --- a/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json +++ b/advisories/unreviewed/2024/03/GHSA-hc48-625f-hwjq/GHSA-hc48-625f-hwjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hc48-625f-hwjq", - "modified": "2024-03-11T18:31:07Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-11T18:31:07Z", "aliases": [ "CVE-2024-0045" ], "details": "In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T17:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hp9q-xmc4-g3pr/GHSA-hp9q-xmc4-g3pr.json b/advisories/unreviewed/2024/03/GHSA-hp9q-xmc4-g3pr/GHSA-hp9q-xmc4-g3pr.json index 4d9515365af..92e95fb98ec 100644 --- a/advisories/unreviewed/2024/03/GHSA-hp9q-xmc4-g3pr/GHSA-hp9q-xmc4-g3pr.json +++ b/advisories/unreviewed/2024/03/GHSA-hp9q-xmc4-g3pr/GHSA-hp9q-xmc4-g3pr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hp9q-xmc4-g3pr", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-13T21:31:02Z", "aliases": [ "CVE-2024-25250" ], "details": "SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T21:15:58Z" diff --git a/advisories/unreviewed/2024/03/GHSA-j4wq-m2h7-q8qx/GHSA-j4wq-m2h7-q8qx.json b/advisories/unreviewed/2024/03/GHSA-j4wq-m2h7-q8qx/GHSA-j4wq-m2h7-q8qx.json index 05d9df1e955..e1500bc8eb6 100644 --- a/advisories/unreviewed/2024/03/GHSA-j4wq-m2h7-q8qx/GHSA-j4wq-m2h7-q8qx.json +++ b/advisories/unreviewed/2024/03/GHSA-j4wq-m2h7-q8qx/GHSA-j4wq-m2h7-q8qx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4wq-m2h7-q8qx", - "modified": "2024-03-05T00:31:14Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-05T00:31:14Z", "aliases": [ "CVE-2024-27718" ], "details": "SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T00:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json b/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json index d3269ec10a9..83997efd38f 100644 --- a/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json +++ b/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwm3-q3pf-fp7v", - "modified": "2024-03-14T00:31:04Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-0258" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-p53h-fpw3-ffwh/GHSA-p53h-fpw3-ffwh.json b/advisories/unreviewed/2024/03/GHSA-p53h-fpw3-ffwh/GHSA-p53h-fpw3-ffwh.json index c49a51ec678..2a0cf784fab 100644 --- a/advisories/unreviewed/2024/03/GHSA-p53h-fpw3-ffwh/GHSA-p53h-fpw3-ffwh.json +++ b/advisories/unreviewed/2024/03/GHSA-p53h-fpw3-ffwh/GHSA-p53h-fpw3-ffwh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p53h-fpw3-ffwh", - "modified": "2024-03-05T18:31:13Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-05T18:31:13Z", "aliases": [ "CVE-2024-27561" ], "details": "A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T17:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q699-2648-qrc2/GHSA-q699-2648-qrc2.json b/advisories/unreviewed/2024/03/GHSA-q699-2648-qrc2/GHSA-q699-2648-qrc2.json index 90843712097..fb731db1de3 100644 --- a/advisories/unreviewed/2024/03/GHSA-q699-2648-qrc2/GHSA-q699-2648-qrc2.json +++ b/advisories/unreviewed/2024/03/GHSA-q699-2648-qrc2/GHSA-q699-2648-qrc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q699-2648-qrc2", - "modified": "2024-03-12T00:30:36Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-12T00:30:35Z", "aliases": [ "CVE-2024-25854" ], "details": "Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting a support ticket.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T22:15:55Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json b/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json index 7f34ba4d301..68409bd65ff 100644 --- a/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json +++ b/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpg5-fc22-gh5w", - "modified": "2024-03-09T09:30:42Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-09T09:30:42Z", "aliases": [ "CVE-2024-25501" ], "details": "An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-09T08:15:05Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rggc-4jrg-r8g6/GHSA-rggc-4jrg-r8g6.json b/advisories/unreviewed/2024/03/GHSA-rggc-4jrg-r8g6/GHSA-rggc-4jrg-r8g6.json index b043a4c5bd9..dfb45977742 100644 --- a/advisories/unreviewed/2024/03/GHSA-rggc-4jrg-r8g6/GHSA-rggc-4jrg-r8g6.json +++ b/advisories/unreviewed/2024/03/GHSA-rggc-4jrg-r8g6/GHSA-rggc-4jrg-r8g6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rggc-4jrg-r8g6", - "modified": "2024-03-28T21:30:32Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T21:30:31Z", "aliases": [ "CVE-2024-23727" ], "details": "The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T21:16:01Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json b/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json index 8806ecf44e7..f78155965c0 100644 --- a/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json +++ b/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rjwj-693g-mq28", - "modified": "2024-03-29T00:30:34Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-29T00:30:34Z", "aliases": [ "CVE-2023-50969" ], "details": "Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T23:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json b/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json index 55bb9c33695..5132dd34ccb 100644 --- a/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json +++ b/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rx25-q489-m9cc", - "modified": "2024-03-28T15:30:33Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-30604" ], "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T15:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vj6h-9583-2qx2/GHSA-vj6h-9583-2qx2.json b/advisories/unreviewed/2024/03/GHSA-vj6h-9583-2qx2/GHSA-vj6h-9583-2qx2.json index c67304c395e..55c6438b52f 100644 --- a/advisories/unreviewed/2024/03/GHSA-vj6h-9583-2qx2/GHSA-vj6h-9583-2qx2.json +++ b/advisories/unreviewed/2024/03/GHSA-vj6h-9583-2qx2/GHSA-vj6h-9583-2qx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj6h-9583-2qx2", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-14T00:31:05Z", "aliases": [ "CVE-2024-27703" ], "details": "Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T22:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json b/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json index a35a5fb5f86..fee9d27c6c9 100644 --- a/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json +++ b/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpp6-9fcm-rv58", - "modified": "2024-04-05T18:30:33Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-03-29T18:30:42Z", "aliases": [ "CVE-2023-49231" ], "details": "An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-288" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wxwf-h485-h4x8/GHSA-wxwf-h485-h4x8.json b/advisories/unreviewed/2024/03/GHSA-wxwf-h485-h4x8/GHSA-wxwf-h485-h4x8.json index dff64eaaf79..f92c20ee996 100644 --- a/advisories/unreviewed/2024/03/GHSA-wxwf-h485-h4x8/GHSA-wxwf-h485-h4x8.json +++ b/advisories/unreviewed/2024/03/GHSA-wxwf-h485-h4x8/GHSA-wxwf-h485-h4x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxwf-h485-h4x8", - "modified": "2024-03-14T03:31:15Z", + "modified": "2024-08-27T21:31:10Z", "published": "2024-03-14T03:31:15Z", "aliases": [ "CVE-2024-25649" ], "details": "In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-316" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-29r2-4vgj-7729/GHSA-29r2-4vgj-7729.json b/advisories/unreviewed/2024/04/GHSA-29r2-4vgj-7729/GHSA-29r2-4vgj-7729.json index eb04ad57374..610fe65c35b 100644 --- a/advisories/unreviewed/2024/04/GHSA-29r2-4vgj-7729/GHSA-29r2-4vgj-7729.json +++ b/advisories/unreviewed/2024/04/GHSA-29r2-4vgj-7729/GHSA-29r2-4vgj-7729.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29r2-4vgj-7729", - "modified": "2024-04-10T21:30:33Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-04-10T21:30:33Z", "aliases": [ "CVE-2024-29269" ], "details": "An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json b/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json index 0167083d7ac..b4f3ee75d6c 100644 --- a/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json +++ b/advisories/unreviewed/2024/04/GHSA-5h4m-75jp-hg7m/GHSA-5h4m-75jp-hg7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h4m-75jp-hg7m", - "modified": "2024-04-05T00:31:28Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-04-05T00:31:28Z", "aliases": [ "CVE-2024-31498" ], "details": "ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T23:15:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5qgx-xxph-rwjx/GHSA-5qgx-xxph-rwjx.json b/advisories/unreviewed/2024/04/GHSA-5qgx-xxph-rwjx/GHSA-5qgx-xxph-rwjx.json index c2c2a2fba3d..594874c9f8f 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qgx-xxph-rwjx/GHSA-5qgx-xxph-rwjx.json +++ b/advisories/unreviewed/2024/04/GHSA-5qgx-xxph-rwjx/GHSA-5qgx-xxph-rwjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qgx-xxph-rwjx", - "modified": "2024-04-04T00:33:11Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-04-04T00:33:11Z", "aliases": [ "CVE-2024-29413" ], "details": "Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant messenger field in the Contact info function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T22:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json b/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json index e736b3e4b72..05c64ca69b0 100644 --- a/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json +++ b/advisories/unreviewed/2024/04/GHSA-9wj5-w226-r39m/GHSA-9wj5-w226-r39m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-rmv2-vqg4-6ggj/GHSA-rmv2-vqg4-6ggj.json b/advisories/unreviewed/2024/04/GHSA-rmv2-vqg4-6ggj/GHSA-rmv2-vqg4-6ggj.json index e9e882e09b2..709e1a04b16 100644 --- a/advisories/unreviewed/2024/04/GHSA-rmv2-vqg4-6ggj/GHSA-rmv2-vqg4-6ggj.json +++ b/advisories/unreviewed/2024/04/GHSA-rmv2-vqg4-6ggj/GHSA-rmv2-vqg4-6ggj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmv2-vqg4-6ggj", - "modified": "2024-04-02T18:31:16Z", + "modified": "2024-08-27T21:31:11Z", "published": "2024-04-02T18:31:16Z", "aliases": [ "CVE-2024-28287" ], "details": "A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T17:15:46Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2hgc-w527-6cxw/GHSA-2hgc-w527-6cxw.json b/advisories/unreviewed/2024/06/GHSA-2hgc-w527-6cxw/GHSA-2hgc-w527-6cxw.json index b3968ef987f..f1e2aacef72 100644 --- a/advisories/unreviewed/2024/06/GHSA-2hgc-w527-6cxw/GHSA-2hgc-w527-6cxw.json +++ b/advisories/unreviewed/2024/06/GHSA-2hgc-w527-6cxw/GHSA-2hgc-w527-6cxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hgc-w527-6cxw", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38553" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fec: remove .ndo_poll_controller to avoid deadlocks\n\nThere is a deadlock issue found in sungem driver, please refer to the\ncommit ac0a230f719b (\"eth: sungem: remove .ndo_poll_controller to avoid\ndeadlocks\"). The root cause of the issue is that netpoll is in atomic\ncontext and disable_irq() is called by .ndo_poll_controller interface\nof sungem driver, however, disable_irq() might sleep. After analyzing\nthe implementation of fec_poll_controller(), the fec driver should have\nthe same issue. Due to the fec driver uses NAPI for TX completions, the\n.ndo_poll_controller is unnecessary to be implemented in the fec driver,\nso fec_poll_controller() can be safely removed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3q8r-mh7f-v4r2/GHSA-3q8r-mh7f-v4r2.json b/advisories/unreviewed/2024/06/GHSA-3q8r-mh7f-v4r2/GHSA-3q8r-mh7f-v4r2.json index f50da226f2b..0c02a362845 100644 --- a/advisories/unreviewed/2024/06/GHSA-3q8r-mh7f-v4r2/GHSA-3q8r-mh7f-v4r2.json +++ b/advisories/unreviewed/2024/06/GHSA-3q8r-mh7f-v4r2/GHSA-3q8r-mh7f-v4r2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q8r-mh7f-v4r2", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38555" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Discard command completions in internal error\n\nFix use after free when FW completion arrives while device is in\ninternal error state. Avoid calling completion handler in this case,\nsince the device will flush the command interface and trigger all\ncompletions manually.\n\nKernel log:\n------------[ cut here ]------------\nrefcount_t: underflow; use-after-free.\n...\nRIP: 0010:refcount_warn_saturate+0xd8/0xe0\n...\nCall Trace:\n\n? __warn+0x79/0x120\n? refcount_warn_saturate+0xd8/0xe0\n? report_bug+0x17c/0x190\n? handle_bug+0x3c/0x60\n? exc_invalid_op+0x14/0x70\n? asm_exc_invalid_op+0x16/0x20\n? refcount_warn_saturate+0xd8/0xe0\ncmd_ent_put+0x13b/0x160 [mlx5_core]\nmlx5_cmd_comp_handler+0x5f9/0x670 [mlx5_core]\ncmd_comp_notifier+0x1f/0x30 [mlx5_core]\nnotifier_call_chain+0x35/0xb0\natomic_notifier_call_chain+0x16/0x20\nmlx5_eq_async_int+0xf6/0x290 [mlx5_core]\nnotifier_call_chain+0x35/0xb0\natomic_notifier_call_chain+0x16/0x20\nirq_int_handler+0x19/0x30 [mlx5_core]\n__handle_irq_event_percpu+0x4b/0x160\nhandle_irq_event+0x2e/0x80\nhandle_edge_irq+0x98/0x230\n__common_interrupt+0x3b/0xa0\ncommon_interrupt+0x7b/0xa0\n\n\nasm_common_interrupt+0x22/0x40", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-9hg8-83gp-55g2/GHSA-9hg8-83gp-55g2.json b/advisories/unreviewed/2024/06/GHSA-9hg8-83gp-55g2/GHSA-9hg8-83gp-55g2.json index c98ccae5187..33fe22a1f35 100644 --- a/advisories/unreviewed/2024/06/GHSA-9hg8-83gp-55g2/GHSA-9hg8-83gp-55g2.json +++ b/advisories/unreviewed/2024/06/GHSA-9hg8-83gp-55g2/GHSA-9hg8-83gp-55g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hg8-83gp-55g2", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38546" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: vc4: Fix possible null pointer dereference\n\nIn vc4_hdmi_audio_init() of_get_address() may return\nNULL which is later dereferenced. Fix this bug by adding NULL check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c8cc-57pq-936r/GHSA-c8cc-57pq-936r.json b/advisories/unreviewed/2024/06/GHSA-c8cc-57pq-936r/GHSA-c8cc-57pq-936r.json index 99a1dd07a20..e2e0424e7e3 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8cc-57pq-936r/GHSA-c8cc-57pq-936r.json +++ b/advisories/unreviewed/2024/06/GHSA-c8cc-57pq-936r/GHSA-c8cc-57pq-936r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8cc-57pq-936r", - "modified": "2024-06-27T12:30:47Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38598" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: fix resync softlockup when bitmap size is less than array size\n\nIs is reported that for dm-raid10, lvextend + lvchange --syncaction will\ntrigger following softlockup:\n\nkernel:watchdog: BUG: soft lockup - CPU#3 stuck for 26s! [mdX_resync:6976]\nCPU: 7 PID: 3588 Comm: mdX_resync Kdump: loaded Not tainted 6.9.0-rc4-next-20240419 #1\nRIP: 0010:_raw_spin_unlock_irq+0x13/0x30\nCall Trace:\n \n md_bitmap_start_sync+0x6b/0xf0\n raid10_sync_request+0x25c/0x1b40 [raid10]\n md_do_sync+0x64b/0x1020\n md_thread+0xa7/0x170\n kthread+0xcf/0x100\n ret_from_fork+0x30/0x50\n ret_from_fork_asm+0x1a/0x30\n\nAnd the detailed process is as follows:\n\nmd_do_sync\n j = mddev->resync_min\n while (j < max_sectors)\n sectors = raid10_sync_request(mddev, j, &skipped)\n if (!md_bitmap_start_sync(..., &sync_blocks))\n // md_bitmap_start_sync set sync_blocks to 0\n return sync_blocks + sectors_skippe;\n // sectors = 0;\n j += sectors;\n // j never change\n\nRoot cause is that commit 301867b1c168 (\"md/raid10: check\nslab-out-of-bounds in md_bitmap_get_counter\") return early from\nmd_bitmap_get_counter(), without setting returned blocks.\n\nFix this problem by always set returned blocks from\nmd_bitmap_get_counter\"(), as it used to be.\n\nNoted that this patch just fix the softlockup problem in kernel, the\ncase that bitmap size doesn't match array size still need to be fixed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:19Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ffpm-gq7j-8x7r/GHSA-ffpm-gq7j-8x7r.json b/advisories/unreviewed/2024/06/GHSA-ffpm-gq7j-8x7r/GHSA-ffpm-gq7j-8x7r.json index 60c77611566..0759e915b5b 100644 --- a/advisories/unreviewed/2024/06/GHSA-ffpm-gq7j-8x7r/GHSA-ffpm-gq7j-8x7r.json +++ b/advisories/unreviewed/2024/06/GHSA-ffpm-gq7j-8x7r/GHSA-ffpm-gq7j-8x7r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffpm-gq7j-8x7r", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38547" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: atomisp: ssh_css: Fix a null-pointer dereference in load_video_binaries\n\nThe allocation failure of mycs->yuv_scaler_binary in load_video_binaries()\nis followed with a dereference of mycs->yuv_scaler_binary after the\nfollowing call chain:\n\nsh_css_pipe_load_binaries()\n |-> load_video_binaries(mycs->yuv_scaler_binary == NULL)\n |\n |-> sh_css_pipe_unload_binaries()\n |-> unload_video_binaries()\n\nIn unload_video_binaries(), it calls to ia_css_binary_unload with argument\n&pipe->pipe_settings.video.yuv_scaler_binary[i], which refers to the\nsame memory slot as mycs->yuv_scaler_binary. Thus, a null-pointer\ndereference is triggered.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gwmp-87px-jxrx/GHSA-gwmp-87px-jxrx.json b/advisories/unreviewed/2024/06/GHSA-gwmp-87px-jxrx/GHSA-gwmp-87px-jxrx.json index 5037d79fa5a..42958fc3f42 100644 --- a/advisories/unreviewed/2024/06/GHSA-gwmp-87px-jxrx/GHSA-gwmp-87px-jxrx.json +++ b/advisories/unreviewed/2024/06/GHSA-gwmp-87px-jxrx/GHSA-gwmp-87px-jxrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwmp-87px-jxrx", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38554" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Fix reference count leak issue of net_device\n\nThere is a reference count leak issue of the object \"net_device\" in\nax25_dev_device_down(). When the ax25 device is shutting down, the\nax25_dev_device_down() drops the reference count of net_device one\nor zero times depending on if we goto unlock_put or not, which will\ncause memory leak.\n\nIn order to solve the above issue, decrease the reference count of\nnet_device after dev->ax25_ptr is set to null.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hmgj-4596-mmpr/GHSA-hmgj-4596-mmpr.json b/advisories/unreviewed/2024/06/GHSA-hmgj-4596-mmpr/GHSA-hmgj-4596-mmpr.json index 826b728b1c7..57411333dfb 100644 --- a/advisories/unreviewed/2024/06/GHSA-hmgj-4596-mmpr/GHSA-hmgj-4596-mmpr.json +++ b/advisories/unreviewed/2024/06/GHSA-hmgj-4596-mmpr/GHSA-hmgj-4596-mmpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmgj-4596-mmpr", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38597" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: sungem: remove .ndo_poll_controller to avoid deadlocks\n\nErhard reports netpoll warnings from sungem:\n\n netpoll_send_skb_on_dev(): eth0 enabled interrupts in poll (gem_start_xmit+0x0/0x398)\n WARNING: CPU: 1 PID: 1 at net/core/netpoll.c:370 netpoll_send_skb+0x1fc/0x20c\n\ngem_poll_controller() disables interrupts, which may sleep.\nWe can't sleep in netpoll, it has interrupts disabled completely.\nStrangely, gem_poll_controller() doesn't even poll the completions,\nand instead acts as if an interrupt has fired so it just schedules\nNAPI and exits. None of this has been necessary for years, since\nnetpoll invokes NAPI directly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:19Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mhr3-x4xm-6j7c/GHSA-mhr3-x4xm-6j7c.json b/advisories/unreviewed/2024/06/GHSA-mhr3-x4xm-6j7c/GHSA-mhr3-x4xm-6j7c.json index 76fc1ab2d17..4943c5faa12 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhr3-x4xm-6j7c/GHSA-mhr3-x4xm-6j7c.json +++ b/advisories/unreviewed/2024/06/GHSA-mhr3-x4xm-6j7c/GHSA-mhr3-x4xm-6j7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhr3-x4xm-6j7c", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38591" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix deadlock on SRQ async events.\n\nxa_lock for SRQ table may be required in AEQ. Use xa_store_irq()/\nxa_erase_irq() to avoid deadlock.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:19Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qwxv-c47r-2c92/GHSA-qwxv-c47r-2c92.json b/advisories/unreviewed/2024/06/GHSA-qwxv-c47r-2c92/GHSA-qwxv-c47r-2c92.json index ddcadc9a6b0..b8241397cd5 100644 --- a/advisories/unreviewed/2024/06/GHSA-qwxv-c47r-2c92/GHSA-qwxv-c47r-2c92.json +++ b/advisories/unreviewed/2024/06/GHSA-qwxv-c47r-2c92/GHSA-qwxv-c47r-2c92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwxv-c47r-2c92", - "modified": "2024-06-27T15:30:39Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38549" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Add 0 size check to mtk_drm_gem_obj\n\nAdd a check to mtk_drm_gem_init if we attempt to allocate a GEM object\nof 0 bytes. Currently, no such check exists and the kernel will panic if\na userspace application attempts to allocate a 0x0 GBM buffer.\n\nTested by attempting to allocate a 0x0 GBM buffer on an MT8188 and\nverifying that we now return EINVAL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r3vw-m8qr-8f9r/GHSA-r3vw-m8qr-8f9r.json b/advisories/unreviewed/2024/06/GHSA-r3vw-m8qr-8f9r/GHSA-r3vw-m8qr-8f9r.json index c01c7901a51..d2d5942a747 100644 --- a/advisories/unreviewed/2024/06/GHSA-r3vw-m8qr-8f9r/GHSA-r3vw-m8qr-8f9r.json +++ b/advisories/unreviewed/2024/06/GHSA-r3vw-m8qr-8f9r/GHSA-r3vw-m8qr-8f9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3vw-m8qr-8f9r", - "modified": "2024-06-27T15:30:39Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38552" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix potential index out of bounds in color transformation function\n\nFixes index out of bounds issue in the color transformation function.\nThe issue could occur when the index 'i' exceeds the number of transfer\nfunction points (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds, an error message is\nlogged and the function returns false to indicate an error.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:405 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:406 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:407 cm_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v4gm-xx5v-3j7m/GHSA-v4gm-xx5v-3j7m.json b/advisories/unreviewed/2024/06/GHSA-v4gm-xx5v-3j7m/GHSA-v4gm-xx5v-3j7m.json index 6e64c58e9cd..6fafb84f0e4 100644 --- a/advisories/unreviewed/2024/06/GHSA-v4gm-xx5v-3j7m/GHSA-v4gm-xx5v-3j7m.json +++ b/advisories/unreviewed/2024/06/GHSA-v4gm-xx5v-3j7m/GHSA-v4gm-xx5v-3j7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4gm-xx5v-3j7m", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38551" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: Assign dummy when codec not specified for a DAI link\n\nMediaTek sound card drivers are checking whether a DAI link is present\nand used on a board to assign the correct parameters and this is done\nby checking the codec DAI names at probe time.\n\nIf no real codec is present, assign the dummy codec to the DAI link\nto avoid NULL pointer during string comparison.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:15Z" diff --git a/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json b/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json index f291ba5077e..fbc34653cec 100644 --- a/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json +++ b/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w738-qp3q-hrfg", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-08-27T21:31:12Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38545" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix UAF for cq async event\n\nThe refcount of CQ is not protected by locks. When CQ asynchronous\nevents and CQ destruction are concurrent, CQ may have been released,\nwhich will cause UAF.\n\nUse the xa_lock() to protect the CQ refcount.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vjgx-4h24-68wp/GHSA-vjgx-4h24-68wp.json b/advisories/unreviewed/2024/07/GHSA-vjgx-4h24-68wp/GHSA-vjgx-4h24-68wp.json index 31ff558083d..133ca609ab2 100644 --- a/advisories/unreviewed/2024/07/GHSA-vjgx-4h24-68wp/GHSA-vjgx-4h24-68wp.json +++ b/advisories/unreviewed/2024/07/GHSA-vjgx-4h24-68wp/GHSA-vjgx-4h24-68wp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjgx-4h24-68wp", - "modified": "2024-07-24T21:31:30Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-07-24T21:31:30Z", "aliases": [ "CVE-2024-36534" ], "details": "Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-24T20:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2hph-w7cx-74wr/GHSA-2hph-w7cx-74wr.json b/advisories/unreviewed/2024/08/GHSA-2hph-w7cx-74wr/GHSA-2hph-w7cx-74wr.json new file mode 100644 index 00000000000..643ffb0009c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2hph-w7cx-74wr/GHSA-2hph-w7cx-74wr.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hph-w7cx-74wr", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-8212" + ], + "details": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been rated as critical. This issue affects the function cgi_FMT_R12R5_2nd_DiskMGR of the file /cgi-bin/hd_config.cgi. The manipulation of the argument f_source_dev leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8212" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_FMT_R12R5_2nd_DiskMGR.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397276" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json b/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json index ccf9c114480..c50f022505f 100644 --- a/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json +++ b/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-364c-g6gq-6jw3", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-44340" ], "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json b/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json index ede67436833..be674685f73 100644 --- a/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json +++ b/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qv5-2hqj-p2wq", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-44341" ], "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6frw-26pf-8hp9/GHSA-6frw-26pf-8hp9.json b/advisories/unreviewed/2024/08/GHSA-6frw-26pf-8hp9/GHSA-6frw-26pf-8hp9.json new file mode 100644 index 00000000000..0cf57e4bc4d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6frw-26pf-8hp9/GHSA-6frw-26pf-8hp9.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6frw-26pf-8hp9", + "modified": "2024-08-27T21:31:15Z", + "published": "2024-08-27T21:31:15Z", + "aliases": [ + "CVE-2024-8218" + ], + "details": "A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument loginid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8218" + }, + { + "type": "WEB", + "url": "https://github.com/t4rrega/cve/issues/7" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.398204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json b/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json index eea2fb52e6c..1d134fbc7eb 100644 --- a/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json +++ b/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q99-8h4h-jqfw", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2022-39996" ], "details": "Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T18:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8cr7-x5g8-m3f3/GHSA-8cr7-x5g8-m3f3.json b/advisories/unreviewed/2024/08/GHSA-8cr7-x5g8-m3f3/GHSA-8cr7-x5g8-m3f3.json new file mode 100644 index 00000000000..8d0cdb649c5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8cr7-x5g8-m3f3/GHSA-8cr7-x5g8-m3f3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cr7-x5g8-m3f3", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-5814" + ], + "details": "A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:M/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5814" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssl/blob/master/ChangeLog.md#add_later" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json b/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json index 214ffcc02e7..7d9291da7d5 100644 --- a/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json +++ b/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-98g8-h992-mhww", - "modified": "2024-08-27T18:31:38Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-36068" ], "details": "An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T18:15:14Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json b/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json new file mode 100644 index 00000000000..4c629487ee5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7vp-757h-879w/GHSA-c7vp-757h-879w.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7vp-757h-879w", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-8213" + ], + "details": "A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected is the function cgi_FMT_R12R5_1st_DiskMGR of the file /cgi-bin/hd_config.cgi. The manipulation of the argument f_source_dev leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8213" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_FMT_R12R5_1st_DiskMGR.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275922" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397277" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gp65-r3h2-m7mh/GHSA-gp65-r3h2-m7mh.json b/advisories/unreviewed/2024/08/GHSA-gp65-r3h2-m7mh/GHSA-gp65-r3h2-m7mh.json new file mode 100644 index 00000000000..6d4beee7bf9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gp65-r3h2-m7mh/GHSA-gp65-r3h2-m7mh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp65-r3h2-m7mh", + "modified": "2024-08-27T21:31:13Z", + "published": "2024-08-27T21:31:13Z", + "aliases": [ + "CVE-2022-39997" + ], + "details": "A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39997" + }, + { + "type": "WEB", + "url": "https://github.com/uyhacked/Teldat-s-Router/blob/main/Teldat" + }, + { + "type": "WEB", + "url": "https://github.com/uyhacked/Teldat-s-Router/blob/main/Teldat%27s%20Router%20Vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-grjj-54gm-q5vf/GHSA-grjj-54gm-q5vf.json b/advisories/unreviewed/2024/08/GHSA-grjj-54gm-q5vf/GHSA-grjj-54gm-q5vf.json new file mode 100644 index 00000000000..c0454c7ffbe --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-grjj-54gm-q5vf/GHSA-grjj-54gm-q5vf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grjj-54gm-q5vf", + "modified": "2024-08-27T21:31:13Z", + "published": "2024-08-27T21:31:13Z", + "aliases": [ + "CVE-2024-1544" + ], + "details": "Generating the ECDSA nonce k samples a random number r and then \ntruncates this randomness with a modular reduction mod n where n is the \norder of the elliptic curve. Meaning k = r mod n. The division used \nduring the reduction estimates a factor q_e by dividing the upper two \ndigits (a digit having e.g. a size of 8 byte) of r by the upper digit of \nn and then decrements q_e in a loop until it has the correct size. \nObserving the number of times q_e is decremented through a control-flow \nrevealing side-channel reveals a bias in the most significant bits of \nk. Depending on the curve this is either a negligible bias or a \nsignificant bias large enough to reconstruct k with lattice reduction \nmethods. For SECP160R1, e.g., we find a bias of 15 bits.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1544" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssl/releases/tag/v5.7.2-stable" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json b/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json new file mode 100644 index 00000000000..6a1fbd9140a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hchh-wrf4-gc5c/GHSA-hchh-wrf4-gc5c.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hchh-wrf4-gc5c", + "modified": "2024-08-27T21:31:15Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-8214" + ], + "details": "A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected by this vulnerability is the function cgi_FMT_Std2R5_2nd_DiskMGR of the file /cgi-bin/hd_config.cgi. The manipulation of the argument f_source_dev leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8214" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_FMT_Std2R5_2nd_DiskMGR.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275923" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397278" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json b/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json index 6e55c78814a..eab530c7bc3 100644 --- a/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json +++ b/advisories/unreviewed/2024/08/GHSA-hqgg-5wv8-wwxg/GHSA-hqgg-5wv8-wwxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hqgg-5wv8-wwxg", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-42789" ], "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in \"/music/controller.php?page=test\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the \"page\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T15:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jwjf-h4v6-qrpp/GHSA-jwjf-h4v6-qrpp.json b/advisories/unreviewed/2024/08/GHSA-jwjf-h4v6-qrpp/GHSA-jwjf-h4v6-qrpp.json new file mode 100644 index 00000000000..9c1d8e364ea --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jwjf-h4v6-qrpp/GHSA-jwjf-h4v6-qrpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwjf-h4v6-qrpp", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-5991" + ], + "details": "In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be NULL terminated. If a caller was attempting to do a name check on a non-NULL terminated buffer, the code would read beyond the bounds of the input array until it found a NULL terminator.This issue affects wolfSSL: through 5.7.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5991" + }, + { + "type": "WEB", + "url": "https://https://github.com/wolfSSL/wolfssl/pull/7604" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json b/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json index 7d6bfee1b4e..c35eb5e2510 100644 --- a/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json +++ b/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6m4-jqc8-546h", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-41622" ], "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pqpf-8gv5-j9mf/GHSA-pqpf-8gv5-j9mf.json b/advisories/unreviewed/2024/08/GHSA-pqpf-8gv5-j9mf/GHSA-pqpf-8gv5-j9mf.json new file mode 100644 index 00000000000..0932417094a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pqpf-8gv5-j9mf/GHSA-pqpf-8gv5-j9mf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqpf-8gv5-j9mf", + "modified": "2024-08-27T21:31:15Z", + "published": "2024-08-27T21:31:15Z", + "aliases": [ + "CVE-2024-8216" + ], + "details": "A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file editPayment.php of the component Payment Handler. The manipulation of the argument recipt_no leads to improper access controls. The attack may be launched remotely. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8216" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r7vw-6xhh-5gwh/GHSA-r7vw-6xhh-5gwh.json b/advisories/unreviewed/2024/08/GHSA-r7vw-6xhh-5gwh/GHSA-r7vw-6xhh-5gwh.json new file mode 100644 index 00000000000..7ddcd897d2b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r7vw-6xhh-5gwh/GHSA-r7vw-6xhh-5gwh.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7vw-6xhh-5gwh", + "modified": "2024-08-27T21:31:15Z", + "published": "2024-08-27T21:31:15Z", + "aliases": [ + "CVE-2024-8217" + ], + "details": "A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8217" + }, + { + "type": "WEB", + "url": "https://github.com/gurudattch/CVEs/blob/main/Sourcecodester-Online-Art-Gallary-Management-System-onlinadvisory-sqli.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.398157" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rrg9-cmw9-3pwx/GHSA-rrg9-cmw9-3pwx.json b/advisories/unreviewed/2024/08/GHSA-rrg9-cmw9-3pwx/GHSA-rrg9-cmw9-3pwx.json new file mode 100644 index 00000000000..51466a5b892 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rrg9-cmw9-3pwx/GHSA-rrg9-cmw9-3pwx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrg9-cmw9-3pwx", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-5288" + ], + "details": "An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys,\n\nsuch as in server-side TLS connections, the connection is halted if any fault occurs. The success rate in a certain amount of connection requests can be processed via an advanced technique for ECDSA key recovery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5288" + }, + { + "type": "WEB", + "url": "https://github.com/wolfSSL/wolfssl/releases/tag/v5.7.2-stable" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json b/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json index ff93adc46b9..43e88053eac 100644 --- a/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json +++ b/advisories/unreviewed/2024/08/GHSA-vcw3-hwj8-8j82/GHSA-vcw3-hwj8-8j82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcw3-hwj8-8j82", - "modified": "2024-08-23T18:33:02Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-23T18:33:02Z", "aliases": [ "CVE-2024-33854" ], "details": "A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T17:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json b/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json new file mode 100644 index 00000000000..62ccca2c88e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vwcr-cpgw-p977/GHSA-vwcr-cpgw-p977.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwcr-cpgw-p977", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-8210" + ], + "details": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been classified as critical. This affects the function sprintf of the file /cgi-bin/hd_config.cgi. The manipulation of the argument f_mount leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8210" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_FMT_R12R5_3rd_DiskMGR.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275919" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397274" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json b/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json index 7d75470b841..879f74080d5 100644 --- a/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json +++ b/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwqr-qf45-7869", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-44342" ], "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json b/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json index 21911869e43..29527f01612 100644 --- a/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json +++ b/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x72g-3j3q-w4wf", - "modified": "2024-08-27T18:31:38Z", + "modified": "2024-08-27T21:31:13Z", "published": "2024-08-27T18:31:38Z", "aliases": [ "CVE-2024-42851" ], "details": "Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T18:15:14Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json b/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json new file mode 100644 index 00000000000..12b3cfc157a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xv9x-vwxf-xx9x/GHSA-xv9x-vwxf-xx9x.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv9x-vwxf-xx9x", + "modified": "2024-08-27T21:31:14Z", + "published": "2024-08-27T21:31:14Z", + "aliases": [ + "CVE-2024-8211" + ], + "details": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been declared as critical. This vulnerability affects the function cgi_FMT_Std2R1_DiskMGR of the file /cgi-bin/hd_config.cgi. The manipulation of the argument f_newly_dev leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8211" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_FMT_Std2R1_DiskMGR.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275920" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397275" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T19:15:18Z" + } +} \ No newline at end of file