diff --git a/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json b/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json index 219fa4c0a3c..46041890680 100644 --- a/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json +++ b/advisories/unreviewed/2024/01/GHSA-6j62-7qgg-9gww/GHSA-6j62-7qgg-9gww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6j62-7qgg-9gww", - "modified": "2024-01-29T18:31:53Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-01-29T18:31:53Z", "aliases": [ "CVE-2023-40551" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40551" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1835" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40551" diff --git a/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json b/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json index adb6527c291..7097f38e3d0 100644 --- a/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json +++ b/advisories/unreviewed/2024/01/GHSA-7cf2-63mg-hv4j/GHSA-7cf2-63mg-hv4j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cf2-63mg-hv4j", - "modified": "2024-01-29T15:30:29Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-40548" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40548" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1835" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40548" diff --git a/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json b/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json index 561f8c8bea2..68ecd161a14 100644 --- a/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json +++ b/advisories/unreviewed/2024/01/GHSA-86pm-fpxw-jjjc/GHSA-86pm-fpxw-jjjc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86pm-fpxw-jjjc", - "modified": "2024-01-29T18:31:50Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-01-29T18:31:50Z", "aliases": [ "CVE-2023-40549" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40549" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1835" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40549" diff --git a/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json b/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json index 24adb59076f..958f82e5ea4 100644 --- a/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json +++ b/advisories/unreviewed/2024/01/GHSA-9fh5-955w-9jfh/GHSA-9fh5-955w-9jfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fh5-955w-9jfh", - "modified": "2024-01-29T18:31:50Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-01-29T18:31:50Z", "aliases": [ "CVE-2023-40546" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40546" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1835" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40546" diff --git a/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json b/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json index e8c3621d5db..c2a10f11c77 100644 --- a/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json +++ b/advisories/unreviewed/2024/01/GHSA-grx2-83w4-8647/GHSA-grx2-83w4-8647.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grx2-83w4-8647", - "modified": "2024-01-29T18:31:53Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-01-29T18:31:53Z", "aliases": [ "CVE-2023-40550" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40550" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1835" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40550" diff --git a/advisories/unreviewed/2024/01/GHSA-gwqg-xwh5-rjmm/GHSA-gwqg-xwh5-rjmm.json b/advisories/unreviewed/2024/01/GHSA-gwqg-xwh5-rjmm/GHSA-gwqg-xwh5-rjmm.json index 2ac14e5febd..038c2404c2e 100644 --- a/advisories/unreviewed/2024/01/GHSA-gwqg-xwh5-rjmm/GHSA-gwqg-xwh5-rjmm.json +++ b/advisories/unreviewed/2024/01/GHSA-gwqg-xwh5-rjmm/GHSA-gwqg-xwh5-rjmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gwqg-xwh5-rjmm", - "modified": "2024-01-27T00:31:23Z", + "modified": "2024-04-16T18:31:33Z", "published": "2024-01-27T00:31:23Z", "aliases": [ "CVE-2024-0948" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.252191" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.270218" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-qjqj-4cq6-6f2f/GHSA-qjqj-4cq6-6f2f.json b/advisories/unreviewed/2024/01/GHSA-qjqj-4cq6-6f2f/GHSA-qjqj-4cq6-6f2f.json index 1629e2e7cf4..24dd3df56e5 100644 --- a/advisories/unreviewed/2024/01/GHSA-qjqj-4cq6-6f2f/GHSA-qjqj-4cq6-6f2f.json +++ b/advisories/unreviewed/2024/01/GHSA-qjqj-4cq6-6f2f/GHSA-qjqj-4cq6-6f2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjqj-4cq6-6f2f", - "modified": "2024-01-25T18:30:50Z", + "modified": "2024-04-16T18:31:33Z", "published": "2024-01-25T18:30:50Z", "aliases": [ "CVE-2023-40547" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40547" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1834" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1835" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-40547" diff --git a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json index ff51fd4bff3..cb37ada22a6 100644 --- a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json +++ b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xr62-xhf5-qw2c", - "modified": "2024-03-19T12:30:41Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2609" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-12" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json new file mode 100644 index 00000000000..bc598079d5d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vhm-v3w9-8mr8", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3863" + ], + "details": "The executable file warning was not presented when downloading .xrm-ms files. \n*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3863" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1885855" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4g4r-f763-vv8x/GHSA-4g4r-f763-vv8x.json b/advisories/unreviewed/2024/04/GHSA-4g4r-f763-vv8x/GHSA-4g4r-f763-vv8x.json new file mode 100644 index 00000000000..c670789aadd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4g4r-f763-vv8x/GHSA-4g4r-f763-vv8x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g4r-f763-vv8x", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3865" + ], + "details": "Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3865" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1881076%2C1884887%2C1885359%2C1889049" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json b/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json new file mode 100644 index 00000000000..c6d230bd3a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g37-8p7x-w23g", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-32256" + ], + "details": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32256" + }, + { + "type": "WEB", + "url": "https://github.com/jinhaochan/CVE-POC/blob/main/tms/POC.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json b/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json new file mode 100644 index 00000000000..970a4321753 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62v2-fqcx-rj9f", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3875" + ], + "details": "A vulnerability was found in Tenda F1202 1.2.0.20(408). It has been rated as critical. This issue affects the function fromNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260909 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3875" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromNatlimit.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260909" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260909" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312817" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json new file mode 100644 index 00000000000..a7b135a9c9a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f82-r7wj-8fxf", + "modified": "2024-04-16T18:31:35Z", + "published": "2024-04-16T18:31:35Z", + "aliases": [ + "CVE-2024-3859" + ], + "details": "On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3859" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1874489" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-746x-qpfv-r44f/GHSA-746x-qpfv-r44f.json b/advisories/unreviewed/2024/04/GHSA-746x-qpfv-r44f/GHSA-746x-qpfv-r44f.json new file mode 100644 index 00000000000..b847bc9f1a1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-746x-qpfv-r44f/GHSA-746x-qpfv-r44f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-746x-qpfv-r44f", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3874" + ], + "details": "A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of the argument remoteIP leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260908. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3874" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/W20E/formSetRemoteWebManage.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312816" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json new file mode 100644 index 00000000000..0e5e21b32c7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8564-m639-jh8r", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3857" + ], + "details": "The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3857" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1886683" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8hmx-3p38-h5rw/GHSA-8hmx-3p38-h5rw.json b/advisories/unreviewed/2024/04/GHSA-8hmx-3p38-h5rw/GHSA-8hmx-3p38-h5rw.json new file mode 100644 index 00000000000..e384690ed09 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8hmx-3p38-h5rw/GHSA-8hmx-3p38-h5rw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hmx-3p38-h5rw", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2023-45000" + ], + "details": "Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n/a through 5.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-5-7-unauthenticated-broken-access-control-on-api-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json b/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json new file mode 100644 index 00000000000..9cb01a8bafb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92q3-88m7-gfwx", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3876" + ], + "details": "A vulnerability classified as critical has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260910 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3876" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/F/F1202/fromVirtualSer.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260910" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260910" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312818" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json b/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json new file mode 100644 index 00000000000..b4034cfe403 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f985-cwrv-f4qp/GHSA-f985-cwrv-f4qp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f985-cwrv-f4qp", + "modified": "2024-04-16T18:31:35Z", + "published": "2024-04-16T18:31:35Z", + "aliases": [ + "CVE-2024-3860" + ], + "details": "An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3860" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1881417" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fvp6-8p9w-vffq/GHSA-fvp6-8p9w-vffq.json b/advisories/unreviewed/2024/04/GHSA-fvp6-8p9w-vffq/GHSA-fvp6-8p9w-vffq.json new file mode 100644 index 00000000000..781b540f17d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fvp6-8p9w-vffq/GHSA-fvp6-8p9w-vffq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvp6-8p9w-vffq", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2023-40000" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/litespeed-cache/wordpress-litespeed-cache-plugin-5-7-unauthenticated-site-wide-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json b/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json new file mode 100644 index 00000000000..20f993ac088 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fvvm-pp96-j72m/GHSA-fvvm-pp96-j72m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvvm-pp96-j72m", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3862" + ], + "details": "The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3862" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1884457" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hf5c-hjgx-rmrw/GHSA-hf5c-hjgx-rmrw.json b/advisories/unreviewed/2024/04/GHSA-hf5c-hjgx-rmrw/GHSA-hf5c-hjgx-rmrw.json new file mode 100644 index 00000000000..487be439431 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hf5c-hjgx-rmrw/GHSA-hf5c-hjgx-rmrw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf5c-hjgx-rmrw", + "modified": "2024-04-16T18:31:35Z", + "published": "2024-04-16T18:31:35Z", + "aliases": [ + "CVE-2024-3858" + ], + "details": "It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3858" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1888892" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hgxh-g8gm-w483/GHSA-hgxh-g8gm-w483.json b/advisories/unreviewed/2024/04/GHSA-hgxh-g8gm-w483/GHSA-hgxh-g8gm-w483.json new file mode 100644 index 00000000000..c62ced66ee5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hgxh-g8gm-w483/GHSA-hgxh-g8gm-w483.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgxh-g8gm-w483", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-32086" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AitThemes Citadela Listing.This issue affects Citadela Listing: from n/a through 5.18.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32086" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/citadela-directory/wordpress-citadela-listing-plugin-5-18-1-unauthenticated-sensitive-data-users-posts-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json b/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json new file mode 100644 index 00000000000..aba6d60fe8c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjxq-w2ww-jfj3", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3856" + ], + "details": "A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3856" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1885829" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json new file mode 100644 index 00000000000..c336556c3dc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvc5-vcrh-v937", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3861" + ], + "details": "If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3861" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1883158" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json b/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json index 56a5a03da09..c541453fa55 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json +++ b/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5h3-wwqf-f5rv", - "modified": "2024-04-12T15:37:21Z", + "modified": "2024-04-16T18:31:34Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-21598" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L" }, + { + "type": "WEB", + "url": "http://supportportal.juniper.net/JSA75739" + }, { "type": "WEB", "url": "http://supportportal.juniper.netJSA75739" diff --git a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json new file mode 100644 index 00000000000..ba3f4a9f1fd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6gp-c388-p4cr", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3302" + ], + "details": "There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3302" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1881183" + }, + { + "type": "WEB", + "url": "https://kb.cert.org/vuls/id/421644" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json b/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json new file mode 100644 index 00000000000..bd63457c6d8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6j5-jrmm-j3w6", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3853" + ], + "details": "A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3853" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1884427" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json new file mode 100644 index 00000000000..847c5eeb341 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc7c-2483-8558", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3852" + ], + "details": "GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3852" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1883542" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json new file mode 100644 index 00000000000..1a78fdcff12 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qj2m-h9cr-4gv7/GHSA-qj2m-h9cr-4gv7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj2m-h9cr-4gv7", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2023-50872" + ], + "details": "The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions \"Vendor says that it's not a security issue.\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50872" + }, + { + "type": "WEB", + "url": "https://excellium-services.com/cert-xlm-advisory/CVE-2023-50872" + }, + { + "type": "WEB", + "url": "https://help.accredible.com/accredible-product-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vv26-p739-hhr7/GHSA-vv26-p739-hhr7.json b/advisories/unreviewed/2024/04/GHSA-vv26-p739-hhr7/GHSA-vv26-p739-hhr7.json new file mode 100644 index 00000000000..a8e62f2525d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vv26-p739-hhr7/GHSA-vv26-p739-hhr7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv26-p739-hhr7", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3873" + ], + "details": "A vulnerability was found in SMI SMI-EX-5414W up to 1.0.03. It has been classified as problematic. This affects an unknown part of the component Web Interface. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260907.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3873" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1ekMbzI-lv6M02HttjFoQHWG8nZOIwPbf/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.260907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.260907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.312623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json b/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json new file mode 100644 index 00000000000..75c5c7f25fa --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w74w-xq97-pg62", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-3864" + ], + "details": "Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3864" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1888333" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json b/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json new file mode 100644 index 00000000000..1d773de9d0e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wpgg-qfwq-fwj4/GHSA-wpgg-qfwq-fwj4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpgg-qfwq-fwj4", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-32254" + ], + "details": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32254" + }, + { + "type": "WEB", + "url": "https://github.com/jinhaochan/CVE-POC/blob/main/tms/POC.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json new file mode 100644 index 00000000000..9c73f968b63 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc66-q4x2-cwqx", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3854" + ], + "details": "In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3854" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1884552" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json b/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json new file mode 100644 index 00000000000..a0deef2dfe4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc8j-mr73-m6wv", + "modified": "2024-04-16T18:31:34Z", + "published": "2024-04-16T18:31:34Z", + "aliases": [ + "CVE-2024-3855" + ], + "details": "In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3855" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1885828" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-18" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xv6g-cccv-mjvg/GHSA-xv6g-cccv-mjvg.json b/advisories/unreviewed/2024/04/GHSA-xv6g-cccv-mjvg/GHSA-xv6g-cccv-mjvg.json new file mode 100644 index 00000000000..511ae973bf6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xv6g-cccv-mjvg/GHSA-xv6g-cccv-mjvg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv6g-cccv-mjvg", + "modified": "2024-04-16T18:31:36Z", + "published": "2024-04-16T18:31:36Z", + "aliases": [ + "CVE-2024-21676" + ], + "details": "This High severity Injection vulnerability was introduced in versions 7.3.0 of Confluence Data Center. \n\nThis Injection vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. \n\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: \t\t \t\t\n\nConfluence Data Center 8.5: Upgrade to a release greater than or equal to 8.5.8 \n\nSee the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center from the download center (https://www.atlassian.com/software/confluence/download-archives). \n\nThis vulnerability was discovered by l3yx and reported via our Bug Bounty program", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21676" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/rest/api/2/issue/2005000" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-16T17:15:10Z" + } +} \ No newline at end of file