Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-04-16 18:33:24 +00:00
parent 1c46cd4049
commit b05d58edf3
35 changed files with 1151 additions and 9 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6j62-7qgg-9gww",
"modified": "2024-01-29T18:31:53Z",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-01-29T18:31:53Z",
"aliases": [
"CVE-2023-40551"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40551"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1834"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1835"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40551"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cf2-63mg-hv4j",
"modified": "2024-01-29T15:30:29Z",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-01-29T15:30:29Z",
"aliases": [
"CVE-2023-40548"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40548"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1834"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1835"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40548"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86pm-fpxw-jjjc",
"modified": "2024-01-29T18:31:50Z",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-01-29T18:31:50Z",
"aliases": [
"CVE-2023-40549"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40549"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1834"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1835"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40549"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fh5-955w-9jfh",
"modified": "2024-01-29T18:31:50Z",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-01-29T18:31:50Z",
"aliases": [
"CVE-2023-40546"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40546"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1834"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1835"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40546"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grx2-83w4-8647",
"modified": "2024-01-29T18:31:53Z",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-01-29T18:31:53Z",
"aliases": [
"CVE-2023-40550"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40550"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1834"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1835"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40550"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gwqg-xwh5-rjmm",
"modified": "2024-01-27T00:31:23Z",
"modified": "2024-04-16T18:31:33Z",
"published": "2024-01-27T00:31:23Z",
"aliases": [
"CVE-2024-0948"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?id.252191"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.270218"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjqj-4cq6-6f2f",
"modified": "2024-01-25T18:30:50Z",
"modified": "2024-04-16T18:31:33Z",
"published": "2024-01-25T18:30:50Z",
"aliases": [
"CVE-2023-40547"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40547"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1834"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1835"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-40547"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xr62-xhf5-qw2c",
"modified": "2024-03-19T12:30:41Z",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-03-19T12:30:41Z",
"aliases": [
"CVE-2024-2609"
@@ -25,6 +25,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-12"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vhm-v3w9-8mr8",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3863"
],
"details": "The executable file warning was not presented when downloading .xrm-ms files. \n*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3863"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1885855"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-18"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g4r-f763-vv8x",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3865"
],
"details": "Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3865"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1881076%2C1884887%2C1885359%2C1889049"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-18"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g37-8p7x-w23g",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-32256"
],
"details": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32256"
},
{
"type": "WEB",
"url": "https://github.com/jinhaochan/CVE-POC/blob/main/tms/POC.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T17:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62v2-fqcx-rj9f",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3875"
],
"details": "A vulnerability was found in Tenda F1202 1.2.0.20(408). It has been rated as critical. This issue affects the function fromNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260909 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3875"
},
{
"type": "WEB",
"url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromNatlimit.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.260909"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.260909"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.312817"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T18:15:14Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6f82-r7wj-8fxf",
"modified": "2024-04-16T18:31:35Z",
"published": "2024-04-16T18:31:35Z",
"aliases": [
"CVE-2024-3859"
],
"details": "On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3859"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874489"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-18"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-746x-qpfv-r44f",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3874"
],
"details": "A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of the argument remoteIP leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260908. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3874"
},
{
"type": "WEB",
"url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/W20E/formSetRemoteWebManage.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.260908"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.260908"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.312816"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:09Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8564-m639-jh8r",
"modified": "2024-04-16T18:31:34Z",
"published": "2024-04-16T18:31:34Z",
"aliases": [
"CVE-2024-3857"
],
"details": "The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3857"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1886683"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-18"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-19"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8hmx-3p38-h5rw",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2023-45000"
],
"details": "Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45000"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-5-7-unauthenticated-broken-access-control-on-api-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T18:15:10Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92q3-88m7-gfwx",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3876"
],
"details": "A vulnerability classified as critical has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260910 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3876"
},
{
"type": "WEB",
"url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromVirtualSer.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.260910"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.260910"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.312818"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T18:15:14Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f985-cwrv-f4qp",
"modified": "2024-04-16T18:31:35Z",
"published": "2024-04-16T18:31:35Z",
"aliases": [
"CVE-2024-3860"
],
"details": "An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3860"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1881417"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-18"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvp6-8p9w-vffq",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2023-40000"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40000"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-5-7-unauthenticated-site-wide-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T18:15:10Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvvm-pp96-j72m",
"modified": "2024-04-16T18:31:36Z",
"published": "2024-04-16T18:31:36Z",
"aliases": [
"CVE-2024-3862"
],
"details": "The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3862"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1884457"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-18"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-16T16:15:08Z"
}
}

Some files were not shown because too many files have changed in this diff Show More