diff --git a/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json b/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json index a97e745a069..0fc7217ac7e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json +++ b/advisories/unreviewed/2022/05/GHSA-2g47-r68w-wq9w/GHSA-2g47-r68w-wq9w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g47-r68w-wq9w", - "modified": "2022-05-24T19:17:39Z", + "modified": "2024-09-10T18:30:41Z", "published": "2022-05-24T19:17:39Z", "aliases": [ "CVE-2018-16061" ], "details": "Mitsubishi Electric SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json b/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json index f7668c912e8..8409af0d443 100644 --- a/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json +++ b/advisories/unreviewed/2022/05/GHSA-rw74-237r-47cj/GHSA-rw74-237r-47cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rw74-237r-47cj", - "modified": "2022-05-24T19:17:39Z", + "modified": "2024-09-10T18:30:41Z", "published": "2022-05-24T19:17:39Z", "aliases": [ "CVE-2018-16060" ], "details": "Mitsubishi Electric SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json b/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json index a5c3c56e146..74380edf492 100644 --- a/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json +++ b/advisories/unreviewed/2022/05/GHSA-xp5g-v8fx-97mv/GHSA-xp5g-v8fx-97mv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xp5g-v8fx-97mv", - "modified": "2022-05-24T16:59:57Z", + "modified": "2024-09-10T18:30:40Z", "published": "2022-05-24T16:59:57Z", "aliases": [ "CVE-2019-14927" ], "details": "An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json b/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json index 5c35beea53c..be5b1519b12 100644 --- a/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json +++ b/advisories/unreviewed/2023/09/GHSA-453j-gwgw-838r/GHSA-453j-gwgw-838r.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-359" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json b/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json index 44c8518d374..21d1b7e2f20 100644 --- a/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json +++ b/advisories/unreviewed/2023/09/GHSA-pjp5-qqc6-2qcq/GHSA-pjp5-qqc6-2qcq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-466r-fx46-xrp4/GHSA-466r-fx46-xrp4.json b/advisories/unreviewed/2023/10/GHSA-466r-fx46-xrp4/GHSA-466r-fx46-xrp4.json index af70d7d7454..78b99223cac 100644 --- a/advisories/unreviewed/2023/10/GHSA-466r-fx46-xrp4/GHSA-466r-fx46-xrp4.json +++ b/advisories/unreviewed/2023/10/GHSA-466r-fx46-xrp4/GHSA-466r-fx46-xrp4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json b/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json index b87ec0f053b..511d1f71e2f 100644 --- a/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json +++ b/advisories/unreviewed/2023/10/GHSA-9vfc-9j87-j2p2/GHSA-9vfc-9j87-j2p2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-359" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json b/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json index da1f6084786..77635a65c85 100644 --- a/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json +++ b/advisories/unreviewed/2023/10/GHSA-pxm4-75xf-9fq8/GHSA-pxm4-75xf-9fq8.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json b/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json index 2ccdf69fc81..774ba027ffa 100644 --- a/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json +++ b/advisories/unreviewed/2023/10/GHSA-r6j8-w974-w846/GHSA-r6j8-w974-w846.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-96" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json index b1c320c8186..e8d51be6c63 100644 --- a/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json +++ b/advisories/unreviewed/2023/10/GHSA-xr44-9893-8w63/GHSA-xr44-9893-8w63.json @@ -60,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json b/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json index 742bee36e25..8071d5c933a 100644 --- a/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json +++ b/advisories/unreviewed/2024/02/GHSA-mmcc-f5rv-h6pc/GHSA-mmcc-f5rv-h6pc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-359" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json b/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json index 6107f7d6f46..1f269fe4c44 100644 --- a/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json +++ b/advisories/unreviewed/2024/07/GHSA-2ff5-8rvr-hgx3/GHSA-2ff5-8rvr-hgx3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2ff5-8rvr-hgx3", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: cancel all works upon hci_unregister_dev()\n\nsyzbot is reporting that calling hci_release_dev() from hci_error_reset()\ndue to hci_dev_put() from hci_error_reset() can cause deadlock at\ndestroy_workqueue(), for hci_error_reset() is called from\nhdev->req_workqueue which destroy_workqueue() needs to flush.\n\nWe need to make sure that hdev->{rx_work,cmd_work,tx_work} which are\nqueued into hdev->workqueue and hdev->{power_on,error_reset} which are\nqueued into hdev->req_workqueue are no longer running by the moment\n\n destroy_workqueue(hdev->workqueue);\n destroy_workqueue(hdev->req_workqueue);\n\nare called from hci_release_dev().\n\nCall cancel_work_sync() on these work items from hci_unregister_dev()\nas soon as hdev->list is removed from hci_dev_list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json b/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json index f7aab9a5c2f..dcab17c3c7d 100644 --- a/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json +++ b/advisories/unreviewed/2024/07/GHSA-683c-6fpf-jr2w/GHSA-683c-6fpf-jr2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-683c-6fpf-jr2w", - "modified": "2024-07-29T15:30:41Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:41Z", "aliases": [ "CVE-2024-41036" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ks8851: Fix deadlock with the SPI chip variant\n\nWhen SMP is enabled and spinlocks are actually functional then there is\na deadlock with the 'statelock' spinlock between ks8851_start_xmit_spi\nand ks8851_irq:\n\n watchdog: BUG: soft lockup - CPU#0 stuck for 27s!\n call trace:\n queued_spin_lock_slowpath+0x100/0x284\n do_raw_spin_lock+0x34/0x44\n ks8851_start_xmit_spi+0x30/0xb8\n ks8851_start_xmit+0x14/0x20\n netdev_start_xmit+0x40/0x6c\n dev_hard_start_xmit+0x6c/0xbc\n sch_direct_xmit+0xa4/0x22c\n __qdisc_run+0x138/0x3fc\n qdisc_run+0x24/0x3c\n net_tx_action+0xf8/0x130\n handle_softirqs+0x1ac/0x1f0\n __do_softirq+0x14/0x20\n ____do_softirq+0x10/0x1c\n call_on_irq_stack+0x3c/0x58\n do_softirq_own_stack+0x1c/0x28\n __irq_exit_rcu+0x54/0x9c\n irq_exit_rcu+0x10/0x1c\n el1_interrupt+0x38/0x50\n el1h_64_irq_handler+0x18/0x24\n el1h_64_irq+0x64/0x68\n __netif_schedule+0x6c/0x80\n netif_tx_wake_queue+0x38/0x48\n ks8851_irq+0xb8/0x2c8\n irq_thread_fn+0x2c/0x74\n irq_thread+0x10c/0x1b0\n kthread+0xc8/0xd8\n ret_from_fork+0x10/0x20\n\nThis issue has not been identified earlier because tests were done on\na device with SMP disabled and so spinlocks were actually NOPs.\n\nNow use spin_(un)lock_bh for TX queue related locking to avoid execution\nof softirq work synchronously that would lead to a deadlock.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json b/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json index ed6c15cc1eb..83360913b24 100644 --- a/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json +++ b/advisories/unreviewed/2024/07/GHSA-fxx9-w28j-5rc5/GHSA-fxx9-w28j-5rc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxx9-w28j-5rc5", - "modified": "2024-07-29T15:30:41Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:41Z", "aliases": [ "CVE-2024-41039" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Fix overflow checking of wmfw header\n\nFix the checking that firmware file buffer is large enough for the\nwmfw header, to prevent overrunning the buffer.\n\nThe original code tested that the firmware data buffer contained\nenough bytes for the sums of the size of the structs\n\n\twmfw_header + wmfw_adsp1_sizes + wmfw_footer\n\nBut wmfw_adsp1_sizes is only used on ADSP1 firmware. For ADSP2 and\nHalo Core the equivalent struct is wmfw_adsp2_sizes, which is\n4 bytes longer. So the length check didn't guarantee that there\nare enough bytes in the firmware buffer for a header with\nwmfw_adsp2_sizes.\n\nThis patch splits the length check into three separate parts. Each\nof the wmfw_header, wmfw_adsp?_sizes and wmfw_footer are checked\nseparately before they are used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json b/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json index b5aa4c0da43..3344af2f3c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json +++ b/advisories/unreviewed/2024/07/GHSA-g37m-wg3j-xw8v/GHSA-g37m-wg3j-xw8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g37m-wg3j-xw8v", - "modified": "2024-07-29T15:30:41Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:41Z", "aliases": [ "CVE-2024-41040" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: Fix UAF when resolving a clash\n\nKASAN reports the following UAF:\n\n BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]\n Read of size 1 at addr ffff888c07603600 by task handler130/6469\n\n Call Trace:\n \n dump_stack_lvl+0x48/0x70\n print_address_description.constprop.0+0x33/0x3d0\n print_report+0xc0/0x2b0\n kasan_report+0xd0/0x120\n __asan_load1+0x6c/0x80\n tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]\n tcf_ct_act+0x886/0x1350 [act_ct]\n tcf_action_exec+0xf8/0x1f0\n fl_classify+0x355/0x360 [cls_flower]\n __tcf_classify+0x1fd/0x330\n tcf_classify+0x21c/0x3c0\n sch_handle_ingress.constprop.0+0x2c5/0x500\n __netif_receive_skb_core.constprop.0+0xb25/0x1510\n __netif_receive_skb_list_core+0x220/0x4c0\n netif_receive_skb_list_internal+0x446/0x620\n napi_complete_done+0x157/0x3d0\n gro_cell_poll+0xcf/0x100\n __napi_poll+0x65/0x310\n net_rx_action+0x30c/0x5c0\n __do_softirq+0x14f/0x491\n __irq_exit_rcu+0x82/0xc0\n irq_exit_rcu+0xe/0x20\n common_interrupt+0xa1/0xb0\n \n \n asm_common_interrupt+0x27/0x40\n\n Allocated by task 6469:\n kasan_save_stack+0x38/0x70\n kasan_set_track+0x25/0x40\n kasan_save_alloc_info+0x1e/0x40\n __kasan_krealloc+0x133/0x190\n krealloc+0xaa/0x130\n nf_ct_ext_add+0xed/0x230 [nf_conntrack]\n tcf_ct_act+0x1095/0x1350 [act_ct]\n tcf_action_exec+0xf8/0x1f0\n fl_classify+0x355/0x360 [cls_flower]\n __tcf_classify+0x1fd/0x330\n tcf_classify+0x21c/0x3c0\n sch_handle_ingress.constprop.0+0x2c5/0x500\n __netif_receive_skb_core.constprop.0+0xb25/0x1510\n __netif_receive_skb_list_core+0x220/0x4c0\n netif_receive_skb_list_internal+0x446/0x620\n napi_complete_done+0x157/0x3d0\n gro_cell_poll+0xcf/0x100\n __napi_poll+0x65/0x310\n net_rx_action+0x30c/0x5c0\n __do_softirq+0x14f/0x491\n\n Freed by task 6469:\n kasan_save_stack+0x38/0x70\n kasan_set_track+0x25/0x40\n kasan_save_free_info+0x2b/0x60\n ____kasan_slab_free+0x180/0x1f0\n __kasan_slab_free+0x12/0x30\n slab_free_freelist_hook+0xd2/0x1a0\n __kmem_cache_free+0x1a2/0x2f0\n kfree+0x78/0x120\n nf_conntrack_free+0x74/0x130 [nf_conntrack]\n nf_ct_destroy+0xb2/0x140 [nf_conntrack]\n __nf_ct_resolve_clash+0x529/0x5d0 [nf_conntrack]\n nf_ct_resolve_clash+0xf6/0x490 [nf_conntrack]\n __nf_conntrack_confirm+0x2c6/0x770 [nf_conntrack]\n tcf_ct_act+0x12ad/0x1350 [act_ct]\n tcf_action_exec+0xf8/0x1f0\n fl_classify+0x355/0x360 [cls_flower]\n __tcf_classify+0x1fd/0x330\n tcf_classify+0x21c/0x3c0\n sch_handle_ingress.constprop.0+0x2c5/0x500\n __netif_receive_skb_core.constprop.0+0xb25/0x1510\n __netif_receive_skb_list_core+0x220/0x4c0\n netif_receive_skb_list_internal+0x446/0x620\n napi_complete_done+0x157/0x3d0\n gro_cell_poll+0xcf/0x100\n __napi_poll+0x65/0x310\n net_rx_action+0x30c/0x5c0\n __do_softirq+0x14f/0x491\n\nThe ct may be dropped if a clash has been resolved but is still passed to\nthe tcf_ct_flow_table_process_conn function for further usage. This issue\ncan be fixed by retrieving ct from skb again after confirming conntrack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json b/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json index 73f03ff8e1e..5c7eb2cd84a 100644 --- a/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json +++ b/advisories/unreviewed/2024/07/GHSA-gg37-jm4h-hhxg/GHSA-gg37-jm4h-hhxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gg37-jm4h-hhxg", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41059" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix uninit-value in copy_name\n\n[syzbot reported]\nBUG: KMSAN: uninit-value in sized_strscpy+0xc4/0x160\n sized_strscpy+0xc4/0x160\n copy_name+0x2af/0x320 fs/hfsplus/xattr.c:411\n hfsplus_listxattr+0x11e9/0x1a50 fs/hfsplus/xattr.c:750\n vfs_listxattr fs/xattr.c:493 [inline]\n listxattr+0x1f3/0x6b0 fs/xattr.c:840\n path_listxattr fs/xattr.c:864 [inline]\n __do_sys_listxattr fs/xattr.c:876 [inline]\n __se_sys_listxattr fs/xattr.c:873 [inline]\n __x64_sys_listxattr+0x16b/0x2f0 fs/xattr.c:873\n x64_sys_call+0x2ba0/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:195\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3877 [inline]\n slab_alloc_node mm/slub.c:3918 [inline]\n kmalloc_trace+0x57b/0xbe0 mm/slub.c:4065\n kmalloc include/linux/slab.h:628 [inline]\n hfsplus_listxattr+0x4cc/0x1a50 fs/hfsplus/xattr.c:699\n vfs_listxattr fs/xattr.c:493 [inline]\n listxattr+0x1f3/0x6b0 fs/xattr.c:840\n path_listxattr fs/xattr.c:864 [inline]\n __do_sys_listxattr fs/xattr.c:876 [inline]\n __se_sys_listxattr fs/xattr.c:873 [inline]\n __x64_sys_listxattr+0x16b/0x2f0 fs/xattr.c:873\n x64_sys_call+0x2ba0/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:195\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[Fix]\nWhen allocating memory to strbuf, initialize memory to 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json b/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json index a94745669f4..8484d1afc4e 100644 --- a/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json +++ b/advisories/unreviewed/2024/07/GHSA-hfhw-chjg-j547/GHSA-hfhw-chjg-j547.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfhw-chjg-j547", - "modified": "2024-07-13T00:31:12Z", + "modified": "2024-09-10T18:30:41Z", "published": "2024-07-13T00:31:12Z", "aliases": [ "CVE-2024-31947" ], "details": "StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-12T23:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json b/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json index e0ae5348aad..a11fd25d262 100644 --- a/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json +++ b/advisories/unreviewed/2024/07/GHSA-j7w3-jhcq-frvr/GHSA-j7w3-jhcq-frvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7w3-jhcq-frvr", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Add tx check to prevent skb leak\n\nBelow is a summary of how the driver stores a reference to an skb during\ntransmit:\n tx_buff[free_map[consumer_index]]->skb = new_skb;\n free_map[consumer_index] = IBMVNIC_INVALID_MAP;\n consumer_index ++;\nWhere variable data looks like this:\n free_map == [4, IBMVNIC_INVALID_MAP, IBMVNIC_INVALID_MAP, 0, 3]\n \tconsumer_index^\n tx_buff == [skb=null, skb=, skb=, skb=null, skb=null]\n\nThe driver has checks to ensure that free_map[consumer_index] pointed to\na valid index but there was no check to ensure that this index pointed\nto an unused/null skb address. So, if, by some chance, our free_map and\ntx_buff lists become out of sync then we were previously risking an\nskb memory leak. This could then cause tcp congestion control to stop\nsending packets, eventually leading to ETIMEDOUT.\n\nTherefore, add a conditional to ensure that the skb address is null. If\nnot then warn the user (because this is still a bug that should be\npatched) and free the old pointer to prevent memleak/tcp problems.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json b/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json index d31a7ca282c..908e69cbb42 100644 --- a/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json +++ b/advisories/unreviewed/2024/07/GHSA-j8wv-5g58-r5vh/GHSA-j8wv-5g58-r5vh.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8wv-5g58-r5vh", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2024-6325" ], "details": "The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html  by implementing CIP security and did not update to the versions of the software CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html  and CVE-2022-1161. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-jm8h-r9wg-2qjw/GHSA-jm8h-r9wg-2qjw.json b/advisories/unreviewed/2024/07/GHSA-jm8h-r9wg-2qjw/GHSA-jm8h-r9wg-2qjw.json index 455f0790ef1..074783b0c5b 100644 --- a/advisories/unreviewed/2024/07/GHSA-jm8h-r9wg-2qjw/GHSA-jm8h-r9wg-2qjw.json +++ b/advisories/unreviewed/2024/07/GHSA-jm8h-r9wg-2qjw/GHSA-jm8h-r9wg-2qjw.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jm8h-r9wg-2qjw", - "modified": "2024-07-15T15:31:00Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-15T15:31:00Z", "aliases": [ "CVE-2024-38493" ], "details": "A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json b/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json index 2c69cba74c7..94d07e4b491 100644 --- a/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json +++ b/advisories/unreviewed/2024/07/GHSA-jp57-4w2p-w9x6/GHSA-jp57-4w2p-w9x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jp57-4w2p-w9x6", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41060" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: check bo_va->bo is non-NULL before using it\n\nThe call to radeon_vm_clear_freed might clear bo_va->bo, so\nwe have to check it before dereferencing it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json b/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json index cae1dffd424..851a5d9e217 100644 --- a/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json +++ b/advisories/unreviewed/2024/07/GHSA-rwrj-7c92-9hmp/GHSA-rwrj-7c92-9hmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwrj-7c92-9hmp", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2019-16638" ], "details": "An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T17:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5xmq-m54x-chjm/GHSA-5xmq-m54x-chjm.json b/advisories/unreviewed/2024/08/GHSA-5xmq-m54x-chjm/GHSA-5xmq-m54x-chjm.json index d50a50aa34a..d72c54720ce 100644 --- a/advisories/unreviewed/2024/08/GHSA-5xmq-m54x-chjm/GHSA-5xmq-m54x-chjm.json +++ b/advisories/unreviewed/2024/08/GHSA-5xmq-m54x-chjm/GHSA-5xmq-m54x-chjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5xmq-m54x-chjm", - "modified": "2024-08-26T12:31:19Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-08-26T12:31:19Z", "aliases": [ "CVE-2024-43894" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/client: fix null pointer dereference in drm_client_modeset_probe\n\nIn drm_client_modeset_probe(), the return value of drm_mode_duplicate() is\nassigned to modeset->mode, which will lead to a possible NULL pointer\ndereference on failure of drm_mode_duplicate(). Add a check to avoid npd.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json b/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json index 69d1f22c135..382f277a909 100644 --- a/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json +++ b/advisories/unreviewed/2024/08/GHSA-fgc5-qhj8-xm5g/GHSA-fgc5-qhj8-xm5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fgc5-qhj8-xm5g", - "modified": "2024-08-28T09:30:34Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-08-28T09:30:34Z", "aliases": [ "CVE-2024-44943" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: gup: stop abusing try_grab_folio\n\nA kernel warning was reported when pinning folio in CMA memory when\nlaunching SEV virtual machine. The splat looks like:\n\n[ 464.325306] WARNING: CPU: 13 PID: 6734 at mm/gup.c:1313 __get_user_pages+0x423/0x520\n[ 464.325464] CPU: 13 PID: 6734 Comm: qemu-kvm Kdump: loaded Not tainted 6.6.33+ #6\n[ 464.325477] RIP: 0010:__get_user_pages+0x423/0x520\n[ 464.325515] Call Trace:\n[ 464.325520] \n[ 464.325523] ? __get_user_pages+0x423/0x520\n[ 464.325528] ? __warn+0x81/0x130\n[ 464.325536] ? __get_user_pages+0x423/0x520\n[ 464.325541] ? report_bug+0x171/0x1a0\n[ 464.325549] ? handle_bug+0x3c/0x70\n[ 464.325554] ? exc_invalid_op+0x17/0x70\n[ 464.325558] ? asm_exc_invalid_op+0x1a/0x20\n[ 464.325567] ? __get_user_pages+0x423/0x520\n[ 464.325575] __gup_longterm_locked+0x212/0x7a0\n[ 464.325583] internal_get_user_pages_fast+0xfb/0x190\n[ 464.325590] pin_user_pages_fast+0x47/0x60\n[ 464.325598] sev_pin_memory+0xca/0x170 [kvm_amd]\n[ 464.325616] sev_mem_enc_register_region+0x81/0x130 [kvm_amd]\n\nPer the analysis done by yangge, when starting the SEV virtual machine, it\nwill call pin_user_pages_fast(..., FOLL_LONGTERM, ...) to pin the memory. \nBut the page is in CMA area, so fast GUP will fail then fallback to the\nslow path due to the longterm pinnalbe check in try_grab_folio().\n\nThe slow path will try to pin the pages then migrate them out of CMA area.\nBut the slow path also uses try_grab_folio() to pin the page, it will\nalso fail due to the same check then the above warning is triggered.\n\nIn addition, the try_grab_folio() is supposed to be used in fast path and\nit elevates folio refcount by using add ref unless zero. We are guaranteed\nto have at least one stable reference in slow path, so the simple atomic add\ncould be used. The performance difference should be trivial, but the\nmisuse may be confusing and misleading.\n\nRedefined try_grab_folio() to try_grab_folio_fast(), and try_grab_page()\nto try_grab_folio(), and use them in the proper paths. This solves both\nthe abuse and the kernel warning.\n\nThe proper naming makes their usecase more clear and should prevent from\nabusing in the future.\n\npeterx said:\n\n: The user will see the pin fails, for gpu-slow it further triggers the WARN\n: right below that failure (as in the original report):\n: \n: folio = try_grab_folio(page, page_increm - 1,\n: foll_flags);\n: if (WARN_ON_ONCE(!folio)) { <------------------------ here\n: /*\n: * Release the 1st page ref if the\n: * folio is problematic, fail hard.\n: */\n: gup_put_folio(page_folio(page), 1,\n: foll_flags);\n: ret = -EFAULT;\n: goto out;\n: }\n\n[1] https://lore.kernel.org/linux-mm/1719478388-31917-1-git-send-email-yangge1116@126.com/\n\n[shy828301@gmail.com: fix implicit declaration of function try_grab_folio_fast]\n Link: https://lkml.kernel.org/r/CAHbLzkowMSso-4Nufc9hcMehQsK9PNz3OSu-+eniU-2Mm-xjhA@mail.gmail.com", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-28T08:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fmj3-3r47-vh2g/GHSA-fmj3-3r47-vh2g.json b/advisories/unreviewed/2024/08/GHSA-fmj3-3r47-vh2g/GHSA-fmj3-3r47-vh2g.json index 4d9983f7c97..b4fbcbbd4c2 100644 --- a/advisories/unreviewed/2024/08/GHSA-fmj3-3r47-vh2g/GHSA-fmj3-3r47-vh2g.json +++ b/advisories/unreviewed/2024/08/GHSA-fmj3-3r47-vh2g/GHSA-fmj3-3r47-vh2g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fmj3-3r47-vh2g", - "modified": "2024-08-26T12:31:19Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-08-26T12:31:19Z", "aliases": [ "CVE-2024-43895" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip Recompute DSC Params if no Stream on Link\n\n[why]\nEncounter NULL pointer dereference uner mst + dsc setup.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 4 PID: 917 Comm: sway Not tainted 6.3.9-arch1-1 #1 124dc55df4f5272ccb409f39ef4872fc2b3376a2\n Hardware name: LENOVO 20NKS01Y00/20NKS01Y00, BIOS R12ET61W(1.31 ) 07/28/2022\n RIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\n Code: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\n RSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\n RAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\n RDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\n RBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\n R10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\n R13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\n FS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000008 CR3: 000000010ddc6000 CR4: 00000000003506e0\n Call Trace:\n\n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? plist_add+0xbe/0x100\n ? exc_page_fault+0x7c/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n ? drm_dp_atomic_find_time_slots+0x28/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n compute_mst_dsc_configs_for_link+0x2ff/0xa40 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n ? fill_plane_buffer_attributes+0x419/0x510 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n compute_mst_dsc_configs_for_state+0x1e1/0x250 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n amdgpu_dm_atomic_check+0xecd/0x1190 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n drm_atomic_check_only+0x5c5/0xa40\n drm_mode_atomic_ioctl+0x76e/0xbc0\n\n[how]\ndsc recompute should be skipped if no mode change detected on the new\nrequest. If detected, keep checking whether the stream is already on\ncurrent state or not.\n\n(cherry picked from commit 8151a6c13111b465dbabe07c19f572f7cbd16fef)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json index e855134e8cb..57eaef7862a 100644 --- a/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json +++ b/advisories/unreviewed/2024/08/GHSA-pwxm-h2xg-rwv6/GHSA-pwxm-h2xg-rwv6.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-78" + "CWE-78", + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json b/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json index 214a7740f9f..ecc7f6c772e 100644 --- a/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json +++ b/advisories/unreviewed/2024/08/GHSA-v66h-w7q8-587v/GHSA-v66h-w7q8-587v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v66h-w7q8-587v", - "modified": "2024-08-26T12:31:19Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-08-26T12:31:19Z", "aliases": [ "CVE-2024-43893" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: check uartclk for zero to avoid divide by zero\n\nCalling ioctl TIOCSSERIAL with an invalid baud_base can\nresult in uartclk being zero, which will result in a\ndivide by zero error in uart_get_divisor(). The check for\nuartclk being zero in uart_set_info() needs to be done\nbefore other settings are made as subsequent calls to\nioctl TIOCSSERIAL for the same port would be impacted if\nthe uartclk check was done where uartclk gets set.\n\nOops: divide error: 0000 PREEMPT SMP KASAN PTI\nRIP: 0010:uart_get_divisor (drivers/tty/serial/serial_core.c:580)\nCall Trace:\n \nserial8250_get_divisor (drivers/tty/serial/8250/8250_port.c:2576\n drivers/tty/serial/8250/8250_port.c:2589)\nserial8250_do_set_termios (drivers/tty/serial/8250/8250_port.c:502\n drivers/tty/serial/8250/8250_port.c:2741)\nserial8250_set_termios (drivers/tty/serial/8250/8250_port.c:2862)\nuart_change_line_settings (./include/linux/spinlock.h:376\n ./include/linux/serial_core.h:608 drivers/tty/serial/serial_core.c:222)\nuart_port_startup (drivers/tty/serial/serial_core.c:342)\nuart_startup (drivers/tty/serial/serial_core.c:368)\nuart_set_info (drivers/tty/serial/serial_core.c:1034)\nuart_set_info_user (drivers/tty/serial/serial_core.c:1059)\ntty_set_serial (drivers/tty/tty_io.c:2637)\ntty_ioctl (drivers/tty/tty_io.c:2647 drivers/tty/tty_io.c:2791)\n__x64_sys_ioctl (fs/ioctl.c:52 fs/ioctl.c:907\n fs/ioctl.c:893 fs/ioctl.c:893)\ndo_syscall_64 (arch/x86/entry/common.c:52\n (discriminator 1) arch/x86/entry/common.c:83 (discriminator 1))\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nRule: add", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-296q-fx3q-6h3p/GHSA-296q-fx3q-6h3p.json b/advisories/unreviewed/2024/09/GHSA-296q-fx3q-6h3p/GHSA-296q-fx3q-6h3p.json new file mode 100644 index 00000000000..c788b897b28 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-296q-fx3q-6h3p/GHSA-296q-fx3q-6h3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-296q-fx3q-6h3p", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38232" + ], + "details": "Windows Networking Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38232" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json b/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json index da786b5d45d..562e1efa812 100644 --- a/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json +++ b/advisories/unreviewed/2024/09/GHSA-2h5m-ffc8-9ffr/GHSA-2h5m-ffc8-9ffr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2h5m-ffc8-9ffr", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:44Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2024-37728" ], "details": "Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the \"Pic/Indexes\" interface", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json b/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json index 2716a70f816..7b05285edd8 100644 --- a/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json +++ b/advisories/unreviewed/2024/09/GHSA-2pmm-55vx-qrxv/GHSA-2pmm-55vx-qrxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pmm-55vx-qrxv", - "modified": "2024-09-10T00:30:49Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-09-06T21:32:28Z", "aliases": [ "CVE-2024-44845" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44845" }, + { + "type": "WEB", + "url": "https://github.com/3okfc/IOT-VUL-WP/blob/main/DaryTek/vigor3900_2.md" + }, { "type": "WEB", "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/DaryTek/vigor3900_2.md" diff --git a/advisories/unreviewed/2024/09/GHSA-2q4v-rwhp-9rxj/GHSA-2q4v-rwhp-9rxj.json b/advisories/unreviewed/2024/09/GHSA-2q4v-rwhp-9rxj/GHSA-2q4v-rwhp-9rxj.json new file mode 100644 index 00000000000..3c7069cd990 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2q4v-rwhp-9rxj/GHSA-2q4v-rwhp-9rxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q4v-rwhp-9rxj", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43464" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43464" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43464" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2wg5-pqfg-hvj9/GHSA-2wg5-pqfg-hvj9.json b/advisories/unreviewed/2024/09/GHSA-2wg5-pqfg-hvj9/GHSA-2wg5-pqfg-hvj9.json new file mode 100644 index 00000000000..587d1701172 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2wg5-pqfg-hvj9/GHSA-2wg5-pqfg-hvj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wg5-pqfg-hvj9", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43482" + ], + "details": "Microsoft Outlook for iOS Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43482" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43482" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-33jw-2jpq-625x/GHSA-33jw-2jpq-625x.json b/advisories/unreviewed/2024/09/GHSA-33jw-2jpq-625x/GHSA-33jw-2jpq-625x.json new file mode 100644 index 00000000000..34e97abbf44 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-33jw-2jpq-625x/GHSA-33jw-2jpq-625x.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33jw-2jpq-625x", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2023-37233" + ], + "details": "Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37233" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + }, + { + "type": "WEB", + "url": "https://docs.loftware.com/spectrum-releasenotes/Content/Hotfix/4.6_HF14.htm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json b/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json new file mode 100644 index 00000000000..43e26c0e377 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-38rg-8rfh-j366/GHSA-38rg-8rfh-j366.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38rg-8rfh-j366", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-44677" + ], + "details": "eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44677" + }, + { + "type": "WEB", + "url": "https://github.com/elunez/eladmin" + }, + { + "type": "WEB", + "url": "https://github.com/jcxj/jcxj/blob/master/source/_posts/eladmin-%E5%A4%8D%E7%8E%B0.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json b/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json new file mode 100644 index 00000000000..019079bacfc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3g3h-v46v-fqhf/GHSA-3g3h-v46v-fqhf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g3h-v46v-fqhf", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37965" + ], + "details": "Microsoft SQL Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37965" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37965" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json b/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json index 150202421c9..dd86f155e09 100644 --- a/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json +++ b/advisories/unreviewed/2024/09/GHSA-3g3x-qrhw-j5jj/GHSA-3g3x-qrhw-j5jj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g3x-qrhw-j5jj", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:44Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2023-37230" ], "details": "Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3j25-9c38-888w/GHSA-3j25-9c38-888w.json b/advisories/unreviewed/2024/09/GHSA-3j25-9c38-888w/GHSA-3j25-9c38-888w.json new file mode 100644 index 00000000000..4e992a4281d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3j25-9c38-888w/GHSA-3j25-9c38-888w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j25-9c38-888w", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38236" + ], + "details": "DHCP Server Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38236" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38236" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3m4m-vgvw-3q25/GHSA-3m4m-vgvw-3q25.json b/advisories/unreviewed/2024/09/GHSA-3m4m-vgvw-3q25/GHSA-3m4m-vgvw-3q25.json new file mode 100644 index 00000000000..1444106e8aa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3m4m-vgvw-3q25/GHSA-3m4m-vgvw-3q25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m4m-vgvw-3q25", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38227" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38227" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json b/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json new file mode 100644 index 00000000000..afff552a742 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3r5x-g9r7-3w5m/GHSA-3r5x-g9r7-3w5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r5x-g9r7-3w5m", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-37335" + ], + "details": "Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37335" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37335" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3w85-rr8r-762j/GHSA-3w85-rr8r-762j.json b/advisories/unreviewed/2024/09/GHSA-3w85-rr8r-762j/GHSA-3w85-rr8r-762j.json new file mode 100644 index 00000000000..d948aeb2d2e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3w85-rr8r-762j/GHSA-3w85-rr8r-762j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w85-rr8r-762j", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38216" + ], + "details": "Azure Stack Hub Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38216" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3x9f-3c9h-x7gj/GHSA-3x9f-3c9h-x7gj.json b/advisories/unreviewed/2024/09/GHSA-3x9f-3c9h-x7gj/GHSA-3x9f-3c9h-x7gj.json new file mode 100644 index 00000000000..691bbf443cb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3x9f-3c9h-x7gj/GHSA-3x9f-3c9h-x7gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x9f-3c9h-x7gj", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38247" + ], + "details": "Windows Graphics Component Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38247" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38247" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-474v-px9m-xcjx/GHSA-474v-px9m-xcjx.json b/advisories/unreviewed/2024/09/GHSA-474v-px9m-xcjx/GHSA-474v-px9m-xcjx.json new file mode 100644 index 00000000000..465b140efa2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-474v-px9m-xcjx/GHSA-474v-px9m-xcjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-474v-px9m-xcjx", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38240" + ], + "details": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38240" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38240" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-49px-m4gc-wgg2/GHSA-49px-m4gc-wgg2.json b/advisories/unreviewed/2024/09/GHSA-49px-m4gc-wgg2/GHSA-49px-m4gc-wgg2.json new file mode 100644 index 00000000000..8ab39ed4806 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-49px-m4gc-wgg2/GHSA-49px-m4gc-wgg2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49px-m4gc-wgg2", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38257" + ], + "details": "Microsoft AllJoyn API Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38257" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38257" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4c22-xgpq-qfxw/GHSA-4c22-xgpq-qfxw.json b/advisories/unreviewed/2024/09/GHSA-4c22-xgpq-qfxw/GHSA-4c22-xgpq-qfxw.json new file mode 100644 index 00000000000..a12fb16fb72 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4c22-xgpq-qfxw/GHSA-4c22-xgpq-qfxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c22-xgpq-qfxw", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38233" + ], + "details": "Windows Networking Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38233" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4c2x-v4q9-wm44/GHSA-4c2x-v4q9-wm44.json b/advisories/unreviewed/2024/09/GHSA-4c2x-v4q9-wm44/GHSA-4c2x-v4q9-wm44.json new file mode 100644 index 00000000000..0d2d8d811d4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4c2x-v4q9-wm44/GHSA-4c2x-v4q9-wm44.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c2x-v4q9-wm44", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38235" + ], + "details": "Windows Hyper-V Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38235" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38235" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json b/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json index a635312cdc4..c33a30947bb 100644 --- a/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json +++ b/advisories/unreviewed/2024/09/GHSA-4gh9-53jc-3mcr/GHSA-4gh9-53jc-3mcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gh9-53jc-3mcr", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44983" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: validate vlan header\n\nEnsure there is sufficient room to access the protocol field of the\nVLAN header, validate it once before the flowtable lookup.\n\n=====================================================\nBUG: KMSAN: uninit-value in nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_flow_offload_inet_hook+0x45a/0x5f0 net/netfilter/nf_flow_table_inet.c:32\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_ingress include/linux/netfilter_netdev.h:34 [inline]\n nf_ingress net/core/dev.c:5440 [inline]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-534f-hj89-3j8f/GHSA-534f-hj89-3j8f.json b/advisories/unreviewed/2024/09/GHSA-534f-hj89-3j8f/GHSA-534f-hj89-3j8f.json new file mode 100644 index 00000000000..de4bda87bb2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-534f-hj89-3j8f/GHSA-534f-hj89-3j8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-534f-hj89-3j8f", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38220" + ], + "details": "Azure Stack Hub Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38220" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-53qj-7827-7xqp/GHSA-53qj-7827-7xqp.json b/advisories/unreviewed/2024/09/GHSA-53qj-7827-7xqp/GHSA-53qj-7827-7xqp.json new file mode 100644 index 00000000000..c3329288315 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-53qj-7827-7xqp/GHSA-53qj-7827-7xqp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53qj-7827-7xqp", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38256" + ], + "details": "Windows Kernel-Mode Driver Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38256" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38256" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json b/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json index c67917a8f33..d7ad223767b 100644 --- a/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json +++ b/advisories/unreviewed/2024/09/GHSA-54cp-27ww-4fm3/GHSA-54cp-27ww-4fm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54cp-27ww-4fm3", - "modified": "2024-09-09T21:31:23Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-09T21:31:23Z", "aliases": [ "CVE-2024-44085" ], "details": "ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T20:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5536-r29g-pv75/GHSA-5536-r29g-pv75.json b/advisories/unreviewed/2024/09/GHSA-5536-r29g-pv75/GHSA-5536-r29g-pv75.json new file mode 100644 index 00000000000..0391cfd591a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5536-r29g-pv75/GHSA-5536-r29g-pv75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5536-r29g-pv75", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38250" + ], + "details": "Windows Graphics Component Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38250" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-587h-34w2-xgxr/GHSA-587h-34w2-xgxr.json b/advisories/unreviewed/2024/09/GHSA-587h-34w2-xgxr/GHSA-587h-34w2-xgxr.json new file mode 100644 index 00000000000..11921379c59 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-587h-34w2-xgxr/GHSA-587h-34w2-xgxr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-587h-34w2-xgxr", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38242" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38242" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38242" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json b/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json new file mode 100644 index 00000000000..b355e0912b9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5999-prhj-w7r5/GHSA-5999-prhj-w7r5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5999-prhj-w7r5", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37339" + ], + "details": "Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37339" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37339" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5gvh-cqjm-hff8/GHSA-5gvh-cqjm-hff8.json b/advisories/unreviewed/2024/09/GHSA-5gvh-cqjm-hff8/GHSA-5gvh-cqjm-hff8.json new file mode 100644 index 00000000000..d2155c3faae --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5gvh-cqjm-hff8/GHSA-5gvh-cqjm-hff8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gvh-cqjm-hff8", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43495" + ], + "details": "Windows libarchive Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43495" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43495" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-65qm-2w7w-w7h5/GHSA-65qm-2w7w-w7h5.json b/advisories/unreviewed/2024/09/GHSA-65qm-2w7w-w7h5/GHSA-65qm-2w7w-w7h5.json new file mode 100644 index 00000000000..e04617e1eac --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-65qm-2w7w-w7h5/GHSA-65qm-2w7w-w7h5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65qm-2w7w-w7h5", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43479" + ], + "details": "Microsoft Power Automate Desktop Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43479" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6jf8-wh8p-q53m/GHSA-6jf8-wh8p-q53m.json b/advisories/unreviewed/2024/09/GHSA-6jf8-wh8p-q53m/GHSA-6jf8-wh8p-q53m.json new file mode 100644 index 00000000000..7a179dd0733 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6jf8-wh8p-q53m/GHSA-6jf8-wh8p-q53m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jf8-wh8p-q53m", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-26191" + ], + "details": "Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26191" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json b/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json new file mode 100644 index 00000000000..dcab9ce3208 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-78v4-hxhf-xqqv/GHSA-78v4-hxhf-xqqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78v4-hxhf-xqqv", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38217" + ], + "details": "Windows Mark of the Web Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38217" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7c27-jcxr-97cm/GHSA-7c27-jcxr-97cm.json b/advisories/unreviewed/2024/09/GHSA-7c27-jcxr-97cm/GHSA-7c27-jcxr-97cm.json new file mode 100644 index 00000000000..f4930b66fd3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7c27-jcxr-97cm/GHSA-7c27-jcxr-97cm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c27-jcxr-97cm", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38248" + ], + "details": "Windows Storage Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38248" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38248" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7q6v-68mf-6678/GHSA-7q6v-68mf-6678.json b/advisories/unreviewed/2024/09/GHSA-7q6v-68mf-6678/GHSA-7q6v-68mf-6678.json new file mode 100644 index 00000000000..ae7dbb6fe83 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7q6v-68mf-6678/GHSA-7q6v-68mf-6678.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q6v-68mf-6678", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43461" + ], + "details": "Windows MSHTML Platform Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43461" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43461" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json b/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json index 7e0bd104be0..6e72afa9eef 100644 --- a/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json +++ b/advisories/unreviewed/2024/09/GHSA-82mg-vc5c-pcm3/GHSA-82mg-vc5c-pcm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82mg-vc5c-pcm3", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:44Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2023-37229" ], "details": "Loftware Spectrum before 5.1 allows SSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json b/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json index a6e56fe8ce5..6ab08e35b92 100644 --- a/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json +++ b/advisories/unreviewed/2024/09/GHSA-8635-cr25-p8xq/GHSA-8635-cr25-p8xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8635-cr25-p8xq", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2023-37226" ], "details": "Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8722-vchq-6p72/GHSA-8722-vchq-6p72.json b/advisories/unreviewed/2024/09/GHSA-8722-vchq-6p72/GHSA-8722-vchq-6p72.json new file mode 100644 index 00000000000..f707515f512 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8722-vchq-6p72/GHSA-8722-vchq-6p72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8722-vchq-6p72", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43474" + ], + "details": "Microsoft SQL Server Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43474" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-170" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json b/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json index b032c3b82b2..882d2257a88 100644 --- a/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json +++ b/advisories/unreviewed/2024/09/GHSA-8g86-p27w-cfrf/GHSA-8g86-p27w-cfrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g86-p27w-cfrf", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-5561" ], "details": "The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T06:15:01Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8jqv-r4vx-8fp4/GHSA-8jqv-r4vx-8fp4.json b/advisories/unreviewed/2024/09/GHSA-8jqv-r4vx-8fp4/GHSA-8jqv-r4vx-8fp4.json new file mode 100644 index 00000000000..eea1eb03ed1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8jqv-r4vx-8fp4/GHSA-8jqv-r4vx-8fp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jqv-r4vx-8fp4", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43463" + ], + "details": "Microsoft Office Visio Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43463" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43463" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8mc9-3vv7-xwf3/GHSA-8mc9-3vv7-xwf3.json b/advisories/unreviewed/2024/09/GHSA-8mc9-3vv7-xwf3/GHSA-8mc9-3vv7-xwf3.json new file mode 100644 index 00000000000..9bf70dc4d3e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8mc9-3vv7-xwf3/GHSA-8mc9-3vv7-xwf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mc9-3vv7-xwf3", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38253" + ], + "details": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38253" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38253" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json b/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json new file mode 100644 index 00000000000..6851c2a9a19 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8vw5-3vcf-59wh/GHSA-8vw5-3vcf-59wh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vw5-3vcf-59wh", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-44676" + ], + "details": "eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44676" + }, + { + "type": "WEB", + "url": "https://github.com/elunez/eladmin" + }, + { + "type": "WEB", + "url": "https://github.com/jcxj/jcxj/blob/master/source/_posts/eladmin-%E5%A4%8D%E7%8E%B0.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9qjv-xm65-gq4f/GHSA-9qjv-xm65-gq4f.json b/advisories/unreviewed/2024/09/GHSA-9qjv-xm65-gq4f/GHSA-9qjv-xm65-gq4f.json new file mode 100644 index 00000000000..851468796ba --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9qjv-xm65-gq4f/GHSA-9qjv-xm65-gq4f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qjv-xm65-gq4f", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-6876" + ], + "details": "Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6876" + }, + { + "type": "WEB", + "url": "https://certvde.com/en/advisories/VDE-2024-046" + }, + { + "type": "WEB", + "url": "https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=18601&token=27389a52e058d95ff70b17a2370fedf07e073034&download=" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9rp7-83cj-89pw/GHSA-9rp7-83cj-89pw.json b/advisories/unreviewed/2024/09/GHSA-9rp7-83cj-89pw/GHSA-9rp7-83cj-89pw.json new file mode 100644 index 00000000000..46982521c90 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9rp7-83cj-89pw/GHSA-9rp7-83cj-89pw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rp7-83cj-89pw", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38245" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38245" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9wg2-mhm9-jgvc/GHSA-9wg2-mhm9-jgvc.json b/advisories/unreviewed/2024/09/GHSA-9wg2-mhm9-jgvc/GHSA-9wg2-mhm9-jgvc.json new file mode 100644 index 00000000000..fe880a19beb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9wg2-mhm9-jgvc/GHSA-9wg2-mhm9-jgvc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wg2-mhm9-jgvc", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38260" + ], + "details": "Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38260" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38260" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c5m2-6p7h-vxqm/GHSA-c5m2-6p7h-vxqm.json b/advisories/unreviewed/2024/09/GHSA-c5m2-6p7h-vxqm/GHSA-c5m2-6p7h-vxqm.json new file mode 100644 index 00000000000..c687e457c19 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c5m2-6p7h-vxqm/GHSA-c5m2-6p7h-vxqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5m2-6p7h-vxqm", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37341" + ], + "details": "Microsoft SQL Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37341" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37341" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c665-2rvm-477f/GHSA-c665-2rvm-477f.json b/advisories/unreviewed/2024/09/GHSA-c665-2rvm-477f/GHSA-c665-2rvm-477f.json new file mode 100644 index 00000000000..66812e82154 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c665-2rvm-477f/GHSA-c665-2rvm-477f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c665-2rvm-477f", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43492" + ], + "details": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43492" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43492" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json index 23c31370495..112ab7ff1ff 100644 --- a/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json +++ b/advisories/unreviewed/2024/09/GHSA-c6f5-vg46-h8r2/GHSA-c6f5-vg46-h8r2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6f5-vg46-h8r2", - "modified": "2024-09-09T21:31:23Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-09T21:31:23Z", "aliases": [ "CVE-2024-44410" ], "details": "D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T21:15:11Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json b/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json index d75395f02a2..e7626f8813e 100644 --- a/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json +++ b/advisories/unreviewed/2024/09/GHSA-cgp2-rgv5-7hcp/GHSA-cgp2-rgv5-7hcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgp2-rgv5-7hcp", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2023-37227" ], "details": "Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json b/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json index b76826cf383..4540f52a899 100644 --- a/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json +++ b/advisories/unreviewed/2024/09/GHSA-cqpj-cqf7-q68j/GHSA-cqpj-cqf7-q68j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqpj-cqf7-q68j", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:44Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2024-44867" ], "details": "phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-crg8-qm9j-p9f5/GHSA-crg8-qm9j-p9f5.json b/advisories/unreviewed/2024/09/GHSA-crg8-qm9j-p9f5/GHSA-crg8-qm9j-p9f5.json new file mode 100644 index 00000000000..0128ef63c25 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-crg8-qm9j-p9f5/GHSA-crg8-qm9j-p9f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crg8-qm9j-p9f5", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43465" + ], + "details": "Microsoft Excel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43465" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43465" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2w3-qvqc-x7rq/GHSA-f2w3-qvqc-x7rq.json b/advisories/unreviewed/2024/09/GHSA-f2w3-qvqc-x7rq/GHSA-f2w3-qvqc-x7rq.json new file mode 100644 index 00000000000..7c2a9d76f14 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f2w3-qvqc-x7rq/GHSA-f2w3-qvqc-x7rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2w3-qvqc-x7rq", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43475" + ], + "details": "Microsoft Windows Admin Center Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43475" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json b/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json new file mode 100644 index 00000000000..407e37ffc3e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f3fq-wr7m-7vrp/GHSA-f3fq-wr7m-7vrp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3fq-wr7m-7vrp", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-44872" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44872" + }, + { + "type": "WEB", + "url": "https://github.com/moziloDasEinsteigerCMS/mozilo3.0" + }, + { + "type": "WEB", + "url": "https://github.com/sec-fortress/Exploits/tree/main/CVE-2024-44872" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fj4c-4j79-r43g/GHSA-fj4c-4j79-r43g.json b/advisories/unreviewed/2024/09/GHSA-fj4c-4j79-r43g/GHSA-fj4c-4j79-r43g.json new file mode 100644 index 00000000000..c47b9e81217 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fj4c-4j79-r43g/GHSA-fj4c-4j79-r43g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj4c-4j79-r43g", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38249" + ], + "details": "Windows Graphics Component Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38249" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38249" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fv7g-cg7m-qjrp/GHSA-fv7g-cg7m-qjrp.json b/advisories/unreviewed/2024/09/GHSA-fv7g-cg7m-qjrp/GHSA-fv7g-cg7m-qjrp.json new file mode 100644 index 00000000000..3859d06418f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fv7g-cg7m-qjrp/GHSA-fv7g-cg7m-qjrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv7g-cg7m-qjrp", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-43454" + ], + "details": "Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43454" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43454" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json b/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json new file mode 100644 index 00000000000..600a6123882 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g3j3-68hm-8gfm/GHSA-g3j3-68hm-8gfm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3j3-68hm-8gfm", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-44871" + ], + "details": "An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44871" + }, + { + "type": "WEB", + "url": "https://github.com/moziloDasEinsteigerCMS/mozilo3.0" + }, + { + "type": "WEB", + "url": "https://github.com/sec-fortress/Exploits/tree/main/CVE-2024-44871" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json b/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json new file mode 100644 index 00000000000..28001dc2974 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g5f6-rx9g-xrpv/GHSA-g5f6-rx9g-xrpv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5f6-rx9g-xrpv", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38018" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38018" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g5r8-9p9v-pqjx/GHSA-g5r8-9p9v-pqjx.json b/advisories/unreviewed/2024/09/GHSA-g5r8-9p9v-pqjx/GHSA-g5r8-9p9v-pqjx.json new file mode 100644 index 00000000000..841745bde47 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g5r8-9p9v-pqjx/GHSA-g5r8-9p9v-pqjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5r8-9p9v-pqjx", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43467" + ], + "details": "Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43467" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43467" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gvc4-cjm6-v27m/GHSA-gvc4-cjm6-v27m.json b/advisories/unreviewed/2024/09/GHSA-gvc4-cjm6-v27m/GHSA-gvc4-cjm6-v27m.json new file mode 100644 index 00000000000..273342fad61 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gvc4-cjm6-v27m/GHSA-gvc4-cjm6-v27m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvc4-cjm6-v27m", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43476" + ], + "details": "Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43476" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43476" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gwj7-4qx3-h44c/GHSA-gwj7-4qx3-h44c.json b/advisories/unreviewed/2024/09/GHSA-gwj7-4qx3-h44c/GHSA-gwj7-4qx3-h44c.json new file mode 100644 index 00000000000..793afa231a8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gwj7-4qx3-h44c/GHSA-gwj7-4qx3-h44c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwj7-4qx3-h44c", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38237" + ], + "details": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38237" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38237" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h59m-8f5f-h863/GHSA-h59m-8f5f-h863.json b/advisories/unreviewed/2024/09/GHSA-h59m-8f5f-h863/GHSA-h59m-8f5f-h863.json new file mode 100644 index 00000000000..a62756093a4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h59m-8f5f-h863/GHSA-h59m-8f5f-h863.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h59m-8f5f-h863", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-43457" + ], + "details": "Windows Setup and Deployment Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43457" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43457" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json b/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json new file mode 100644 index 00000000000..e66b0b48a11 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hp6q-6g58-99wm/GHSA-hp6q-6g58-99wm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp6q-6g58-99wm", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-31960" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31960" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31960" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j5j6-f7rx-wf55/GHSA-j5j6-f7rx-wf55.json b/advisories/unreviewed/2024/09/GHSA-j5j6-f7rx-wf55/GHSA-j5j6-f7rx-wf55.json new file mode 100644 index 00000000000..68c0d3596e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j5j6-f7rx-wf55/GHSA-j5j6-f7rx-wf55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5j6-f7rx-wf55", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43487" + ], + "details": "Windows Mark of the Web Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43487" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43487" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j7fx-rmf6-crmw/GHSA-j7fx-rmf6-crmw.json b/advisories/unreviewed/2024/09/GHSA-j7fx-rmf6-crmw/GHSA-j7fx-rmf6-crmw.json new file mode 100644 index 00000000000..abe14204c64 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j7fx-rmf6-crmw/GHSA-j7fx-rmf6-crmw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7fx-rmf6-crmw", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38239" + ], + "details": "Windows Kerberos Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38239" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jhm7-8qm3-8x49/GHSA-jhm7-8qm3-8x49.json b/advisories/unreviewed/2024/09/GHSA-jhm7-8qm3-8x49/GHSA-jhm7-8qm3-8x49.json new file mode 100644 index 00000000000..e9627aad8c9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jhm7-8qm3-8x49/GHSA-jhm7-8qm3-8x49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhm7-8qm3-8x49", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38259" + ], + "details": "Microsoft Management Console Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38259" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38259" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jq6v-vmmh-49wr/GHSA-jq6v-vmmh-49wr.json b/advisories/unreviewed/2024/09/GHSA-jq6v-vmmh-49wr/GHSA-jq6v-vmmh-49wr.json new file mode 100644 index 00000000000..c47889207e1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jq6v-vmmh-49wr/GHSA-jq6v-vmmh-49wr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq6v-vmmh-49wr", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38258" + ], + "details": "Windows Remote Desktop Licensing Service Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38258" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38258" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json b/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json index 87e16ef07e6..9d4c8f1c7d3 100644 --- a/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json +++ b/advisories/unreviewed/2024/09/GHSA-jvc3-9vpf-mx93/GHSA-jvc3-9vpf-mx93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvc3-9vpf-mx93", - "modified": "2024-09-10T15:31:04Z", + "modified": "2024-09-10T18:30:44Z", "published": "2024-09-10T15:31:04Z", "aliases": [ "CVE-2023-37231" ], "details": "Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-259" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T14:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jww9-vwpc-6qmf/GHSA-jww9-vwpc-6qmf.json b/advisories/unreviewed/2024/09/GHSA-jww9-vwpc-6qmf/GHSA-jww9-vwpc-6qmf.json new file mode 100644 index 00000000000..5da1e9ae040 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jww9-vwpc-6qmf/GHSA-jww9-vwpc-6qmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jww9-vwpc-6qmf", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38238" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38238" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38238" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m4jv-p2cx-9g8r/GHSA-m4jv-p2cx-9g8r.json b/advisories/unreviewed/2024/09/GHSA-m4jv-p2cx-9g8r/GHSA-m4jv-p2cx-9g8r.json new file mode 100644 index 00000000000..af042f89cd1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m4jv-p2cx-9g8r/GHSA-m4jv-p2cx-9g8r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4jv-p2cx-9g8r", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38244" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38244" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m65g-rcvq-qjj5/GHSA-m65g-rcvq-qjj5.json b/advisories/unreviewed/2024/09/GHSA-m65g-rcvq-qjj5/GHSA-m65g-rcvq-qjj5.json new file mode 100644 index 00000000000..bccc01c2810 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m65g-rcvq-qjj5/GHSA-m65g-rcvq-qjj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m65g-rcvq-qjj5", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-37337" + ], + "details": "Microsoft SQL Server Native Scoring Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37337" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-197" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m882-rgxp-c7jh/GHSA-m882-rgxp-c7jh.json b/advisories/unreviewed/2024/09/GHSA-m882-rgxp-c7jh/GHSA-m882-rgxp-c7jh.json new file mode 100644 index 00000000000..f4c3e8f03f0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m882-rgxp-c7jh/GHSA-m882-rgxp-c7jh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m882-rgxp-c7jh", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43491" + ], + "details": "Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability.\nThis servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order.\nNote: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43491" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43491" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mhc8-f455-fqc9/GHSA-mhc8-f455-fqc9.json b/advisories/unreviewed/2024/09/GHSA-mhc8-f455-fqc9/GHSA-mhc8-f455-fqc9.json new file mode 100644 index 00000000000..5c660c3ee2b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mhc8-f455-fqc9/GHSA-mhc8-f455-fqc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhc8-f455-fqc9", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37340" + ], + "details": "Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37340" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json b/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json new file mode 100644 index 00000000000..51ea94dd0f3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mm7m-mg28-rj6q/GHSA-mm7m-mg28-rj6q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm7m-mg28-rj6q", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2023-37232" + ], + "details": "Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37232" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mp72-mr55-299x/GHSA-mp72-mr55-299x.json b/advisories/unreviewed/2024/09/GHSA-mp72-mr55-299x/GHSA-mp72-mr55-299x.json new file mode 100644 index 00000000000..d2533e6bd19 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mp72-mr55-299x/GHSA-mp72-mr55-299x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp72-mr55-299x", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38045" + ], + "details": "Windows TCP/IP Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38045" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38045" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mp7m-vrr7-g6gw/GHSA-mp7m-vrr7-g6gw.json b/advisories/unreviewed/2024/09/GHSA-mp7m-vrr7-g6gw/GHSA-mp7m-vrr7-g6gw.json new file mode 100644 index 00000000000..81559ea1030 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mp7m-vrr7-g6gw/GHSA-mp7m-vrr7-g6gw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp7m-vrr7-g6gw", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38228" + ], + "details": "Microsoft SharePoint Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38228" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38228" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mphg-33v9-x9g5/GHSA-mphg-33v9-x9g5.json b/advisories/unreviewed/2024/09/GHSA-mphg-33v9-x9g5/GHSA-mphg-33v9-x9g5.json new file mode 100644 index 00000000000..d13da6ae405 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mphg-33v9-x9g5/GHSA-mphg-33v9-x9g5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mphg-33v9-x9g5", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38241" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38241" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38241" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mvjr-3jgq-45rj/GHSA-mvjr-3jgq-45rj.json b/advisories/unreviewed/2024/09/GHSA-mvjr-3jgq-45rj/GHSA-mvjr-3jgq-45rj.json new file mode 100644 index 00000000000..ed7627611a6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mvjr-3jgq-45rj/GHSA-mvjr-3jgq-45rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvjr-3jgq-45rj", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38119" + ], + "details": "Windows Network Address Translation (NAT) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38119" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json b/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json new file mode 100644 index 00000000000..29a8c71d316 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mvx5-3q3c-pr6w/GHSA-mvx5-3q3c-pr6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvx5-3q3c-pr6w", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38014" + ], + "details": "Windows Installer Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38014" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p5j4-6jm5-6fj9/GHSA-p5j4-6jm5-6fj9.json b/advisories/unreviewed/2024/09/GHSA-p5j4-6jm5-6fj9/GHSA-p5j4-6jm5-6fj9.json new file mode 100644 index 00000000000..af5e15728ba --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p5j4-6jm5-6fj9/GHSA-p5j4-6jm5-6fj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5j4-6jm5-6fj9", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37966" + ], + "details": "Microsoft SQL Server Native Scoring Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37966" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37966" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json b/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json index 8cca93c3a3e..67bb3f47e7f 100644 --- a/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json +++ b/advisories/unreviewed/2024/09/GHSA-p6wm-338f-gmjm/GHSA-p6wm-338f-gmjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6wm-338f-gmjm", - "modified": "2024-09-10T06:30:49Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-10T06:30:49Z", "aliases": [ "CVE-2024-7955" ], "details": "The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-10T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p77f-9283-wx93/GHSA-p77f-9283-wx93.json b/advisories/unreviewed/2024/09/GHSA-p77f-9283-wx93/GHSA-p77f-9283-wx93.json new file mode 100644 index 00000000000..50e82bdc496 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p77f-9283-wx93/GHSA-p77f-9283-wx93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p77f-9283-wx93", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43466" + ], + "details": "Microsoft SharePoint Server Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43466" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43466" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pg6q-2w5f-8pw9/GHSA-pg6q-2w5f-8pw9.json b/advisories/unreviewed/2024/09/GHSA-pg6q-2w5f-8pw9/GHSA-pg6q-2w5f-8pw9.json new file mode 100644 index 00000000000..b53d21e9885 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pg6q-2w5f-8pw9/GHSA-pg6q-2w5f-8pw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg6q-2w5f-8pw9", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38225" + ], + "details": "Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38225" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pgxx-gq7v-fg8m/GHSA-pgxx-gq7v-fg8m.json b/advisories/unreviewed/2024/09/GHSA-pgxx-gq7v-fg8m/GHSA-pgxx-gq7v-fg8m.json new file mode 100644 index 00000000000..bd3f9a2e2bc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pgxx-gq7v-fg8m/GHSA-pgxx-gq7v-fg8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgxx-gq7v-fg8m", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37342" + ], + "details": "Microsoft SQL Server Native Scoring Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37342" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json b/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json new file mode 100644 index 00000000000..ad047f05950 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-phx5-vwwh-9gm8/GHSA-phx5-vwwh-9gm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phx5-vwwh-9gm8", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-37980" + ], + "details": "Microsoft SQL Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37980" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37980" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pm59-739h-g5cv/GHSA-pm59-739h-g5cv.json b/advisories/unreviewed/2024/09/GHSA-pm59-739h-g5cv/GHSA-pm59-739h-g5cv.json new file mode 100644 index 00000000000..d226168a40b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pm59-739h-g5cv/GHSA-pm59-739h-g5cv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm59-739h-g5cv", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43470" + ], + "details": "Azure Network Watcher VM Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43470" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43470" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json b/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json new file mode 100644 index 00000000000..d36f017dacf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pmc5-pcm8-42pf/GHSA-pmc5-pcm8-42pf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmc5-pcm8-42pf", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2023-36103" + ], + "details": "Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36103" + }, + { + "type": "WEB", + "url": "https://github.com/t0hka1/Tenda-AC15-Exp/blob/master/Tenda%20AC15%20V15.03.05.20%20Exp.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pmhg-5fq2-cxqq/GHSA-pmhg-5fq2-cxqq.json b/advisories/unreviewed/2024/09/GHSA-pmhg-5fq2-cxqq/GHSA-pmhg-5fq2-cxqq.json new file mode 100644 index 00000000000..f2ba97260b9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pmhg-5fq2-cxqq/GHSA-pmhg-5fq2-cxqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmhg-5fq2-cxqq", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38231" + ], + "details": "Windows Remote Desktop Licensing Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38231" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pr5w-3qqg-c6mc/GHSA-pr5w-3qqg-c6mc.json b/advisories/unreviewed/2024/09/GHSA-pr5w-3qqg-c6mc/GHSA-pr5w-3qqg-c6mc.json new file mode 100644 index 00000000000..e81bd5c8a2d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pr5w-3qqg-c6mc/GHSA-pr5w-3qqg-c6mc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr5w-3qqg-c6mc", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38230" + ], + "details": "Windows Standards-Based Storage Management Service Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38230" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38230" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json b/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json index 43ffff5c83a..785304cbd6a 100644 --- a/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json +++ b/advisories/unreviewed/2024/09/GHSA-pvxf-38x8-qcmc/GHSA-pvxf-38x8-qcmc.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pw5m-22q6-976f/GHSA-pw5m-22q6-976f.json b/advisories/unreviewed/2024/09/GHSA-pw5m-22q6-976f/GHSA-pw5m-22q6-976f.json new file mode 100644 index 00000000000..085c646633a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pw5m-22q6-976f/GHSA-pw5m-22q6-976f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw5m-22q6-976f", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-43455" + ], + "details": "Windows Remote Desktop Licensing Service Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43455" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43455" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-px24-vp7g-w3gw/GHSA-px24-vp7g-w3gw.json b/advisories/unreviewed/2024/09/GHSA-px24-vp7g-w3gw/GHSA-px24-vp7g-w3gw.json new file mode 100644 index 00000000000..57a15e4ef80 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-px24-vp7g-w3gw/GHSA-px24-vp7g-w3gw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px24-vp7g-w3gw", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-43458" + ], + "details": "Windows Networking Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43458" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pxwm-r9vq-x573/GHSA-pxwm-r9vq-x573.json b/advisories/unreviewed/2024/09/GHSA-pxwm-r9vq-x573/GHSA-pxwm-r9vq-x573.json new file mode 100644 index 00000000000..212127f6208 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pxwm-r9vq-x573/GHSA-pxwm-r9vq-x573.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxwm-r9vq-x573", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38263" + ], + "details": "Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38263" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-591" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json b/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json index 4f47418d464..7625749f8ad 100644 --- a/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json +++ b/advisories/unreviewed/2024/09/GHSA-qmgp-8gjw-93v8/GHSA-qmgp-8gjw-93v8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmgp-8gjw-93v8", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44978" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Free job before xe_exec_queue_put\n\nFree job depends on job->vm being valid, the last xe_exec_queue_put can\ndestroy the VM. Prevent UAF by freeing job before xe_exec_queue_put.\n\n(cherry picked from commit 32a42c93b74c8ca6d0915ea3eba21bceff53042f)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-r3q3-7r4r-xv74/GHSA-r3q3-7r4r-xv74.json b/advisories/unreviewed/2024/09/GHSA-r3q3-7r4r-xv74/GHSA-r3q3-7r4r-xv74.json new file mode 100644 index 00000000000..3d6cb6ba26b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r3q3-7r4r-xv74/GHSA-r3q3-7r4r-xv74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3q3-7r4r-xv74", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-37338" + ], + "details": "Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37338" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-37338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json b/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json new file mode 100644 index 00000000000..65e1ff8831d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r95v-7x7v-phw8/GHSA-r95v-7x7v-phw8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r95v-7x7v-phw8", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-44667" + ], + "details": "Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44667" + }, + { + "type": "WEB", + "url": "https://medium.com/%40sengkyaut/unauthenticated-factory-mode-reset-and-at-command-injection-in-jboneos-or-jbonecloud-firmware-1dec156b7ddd" + }, + { + "type": "WEB", + "url": "http://shenzhen.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rc6w-v672-99cv/GHSA-rc6w-v672-99cv.json b/advisories/unreviewed/2024/09/GHSA-rc6w-v672-99cv/GHSA-rc6w-v672-99cv.json new file mode 100644 index 00000000000..e271ba190c8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rc6w-v672-99cv/GHSA-rc6w-v672-99cv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc6w-v672-99cv", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38194" + ], + "details": "An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38194" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38194" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json b/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json index bd0dbf5f32d..ec26fc92a8d 100644 --- a/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json +++ b/advisories/unreviewed/2024/09/GHSA-rcqr-8g6q-fmc3/GHSA-rcqr-8g6q-fmc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcqr-8g6q-fmc3", - "modified": "2024-09-09T21:31:22Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-09T21:31:22Z", "aliases": [ "CVE-2023-50883" ], "details": "ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T20:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rf2v-qj9w-x393/GHSA-rf2v-qj9w-x393.json b/advisories/unreviewed/2024/09/GHSA-rf2v-qj9w-x393/GHSA-rf2v-qj9w-x393.json new file mode 100644 index 00000000000..3327612f739 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rf2v-qj9w-x393/GHSA-rf2v-qj9w-x393.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf2v-qj9w-x393", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38226" + ], + "details": "Microsoft Publisher Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38226" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rhxj-v9fc-vpm2/GHSA-rhxj-v9fc-vpm2.json b/advisories/unreviewed/2024/09/GHSA-rhxj-v9fc-vpm2/GHSA-rhxj-v9fc-vpm2.json new file mode 100644 index 00000000000..2ecfa0c7575 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rhxj-v9fc-vpm2/GHSA-rhxj-v9fc-vpm2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhxj-v9fc-vpm2", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-44815" + ], + "details": "An issue in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain sensitive information via SPI flash Firmware W25Q64JV", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44815" + }, + { + "type": "WEB", + "url": "https://github.com/nitinronge91/Extracting-User-credentials-For-Web-portal-and-WiFi-AP-For-Hathway-Router-CVE-2024-44815-" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rjw7-qg6g-6c2j/GHSA-rjw7-qg6g-6c2j.json b/advisories/unreviewed/2024/09/GHSA-rjw7-qg6g-6c2j/GHSA-rjw7-qg6g-6c2j.json new file mode 100644 index 00000000000..438a0bf8789 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rjw7-qg6g-6c2j/GHSA-rjw7-qg6g-6c2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjw7-qg6g-6c2j", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38252" + ], + "details": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38252" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rm77-w39m-fpfm/GHSA-rm77-w39m-fpfm.json b/advisories/unreviewed/2024/09/GHSA-rm77-w39m-fpfm/GHSA-rm77-w39m-fpfm.json new file mode 100644 index 00000000000..ed371d7dbb9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rm77-w39m-fpfm/GHSA-rm77-w39m-fpfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm77-w39m-fpfm", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-21416" + ], + "details": "Windows TCP/IP Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21416" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json b/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json index d0e616e9002..4a15758bad8 100644 --- a/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json +++ b/advisories/unreviewed/2024/09/GHSA-rpfq-qgpp-7qm9/GHSA-rpfq-qgpp-7qm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rpfq-qgpp-7qm9", - "modified": "2024-09-06T09:32:31Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-09-06T09:32:31Z", "aliases": [ "CVE-2023-52915" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer\n\nIn af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf\nis null and msg[i].len is zero, former checks on msg[i].buf would be\npassed. Malicious data finally reach af9035_i2c_master_xfer. If accessing\nmsg[i].buf[0] without sanity check, null ptr deref would happen.\nWe add check on msg[i].len to prevent crash.\n\nSimilar commit:\ncommit 0ed554fd769a\n(\"media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()\")", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T09:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rqjr-fpm9-pwx5/GHSA-rqjr-fpm9-pwx5.json b/advisories/unreviewed/2024/09/GHSA-rqjr-fpm9-pwx5/GHSA-rqjr-fpm9-pwx5.json new file mode 100644 index 00000000000..0ea3e01fb04 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rqjr-fpm9-pwx5/GHSA-rqjr-fpm9-pwx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqjr-fpm9-pwx5", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38046" + ], + "details": "PowerShell Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38046" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v6rj-vqvp-pjw9/GHSA-v6rj-vqvp-pjw9.json b/advisories/unreviewed/2024/09/GHSA-v6rj-vqvp-pjw9/GHSA-v6rj-vqvp-pjw9.json new file mode 100644 index 00000000000..f53b16988b8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v6rj-vqvp-pjw9/GHSA-v6rj-vqvp-pjw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6rj-vqvp-pjw9", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-43469" + ], + "details": "Azure CycleCloud Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43469" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43469" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json b/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json index 1252127bc6c..54ac4f19ed3 100644 --- a/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json +++ b/advisories/unreviewed/2024/09/GHSA-vw78-5596-vx6r/GHSA-vw78-5596-vx6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vw78-5596-vx6r", - "modified": "2024-09-09T21:31:22Z", + "modified": "2024-09-10T18:30:43Z", "published": "2024-09-09T21:31:22Z", "aliases": [ "CVE-2024-42759" ], "details": "An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T19:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json b/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json index 9df360c0963..9a95e2cb7b7 100644 --- a/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json +++ b/advisories/unreviewed/2024/09/GHSA-w66f-4c3w-wm2w/GHSA-w66f-4c3w-wm2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w66f-4c3w-wm2w", - "modified": "2024-09-10T00:30:49Z", + "modified": "2024-09-10T18:30:42Z", "published": "2024-09-06T21:32:28Z", "aliases": [ "CVE-2024-44844" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44844" }, + { + "type": "WEB", + "url": "https://github.com/3okfc/IOT-VUL-WP/blob/main/DaryTek/vigor3900_1.md" + }, { "type": "WEB", "url": "https://github.com/glkfc/IoT-Vulnerability/blob/main/DaryTek/vigor3900_1.md" diff --git a/advisories/unreviewed/2024/09/GHSA-w97f-w3hq-36g2/GHSA-w97f-w3hq-36g2.json b/advisories/unreviewed/2024/09/GHSA-w97f-w3hq-36g2/GHSA-w97f-w3hq-36g2.json new file mode 100644 index 00000000000..d0810318d66 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w97f-w3hq-36g2/GHSA-w97f-w3hq-36g2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w97f-w3hq-36g2", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2023-6841" + ], + "details": "A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6841" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-6841" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254714" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-231" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wggm-rx98-f2mr/GHSA-wggm-rx98-f2mr.json b/advisories/unreviewed/2024/09/GHSA-wggm-rx98-f2mr/GHSA-wggm-rx98-f2mr.json new file mode 100644 index 00000000000..6e9d270af8d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wggm-rx98-f2mr/GHSA-wggm-rx98-f2mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wggm-rx98-f2mr", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38243" + ], + "details": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38243" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38243" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json b/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json new file mode 100644 index 00000000000..174dd0fab68 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wpwg-4rvh-5q27/GHSA-wpwg-4rvh-5q27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpwg-4rvh-5q27", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-44893" + ], + "details": "An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44893" + }, + { + "type": "WEB", + "url": "https://github.com/jeecgboot/JimuReport/issues/2904" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json b/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json new file mode 100644 index 00000000000..65a919df0bf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x996-vwrq-5c5f/GHSA-x996-vwrq-5c5f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x996-vwrq-5c5f", + "modified": "2024-09-10T18:30:47Z", + "published": "2024-09-10T18:30:47Z", + "aliases": [ + "CVE-2024-34831" + ], + "details": "cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34831" + }, + { + "type": "WEB", + "url": "https://github.com/enzored/CVE-2024-34831" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T18:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x9x8-4xvf-mwjp/GHSA-x9x8-4xvf-mwjp.json b/advisories/unreviewed/2024/09/GHSA-x9x8-4xvf-mwjp/GHSA-x9x8-4xvf-mwjp.json new file mode 100644 index 00000000000..435aa681846 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x9x8-4xvf-mwjp/GHSA-x9x8-4xvf-mwjp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9x8-4xvf-mwjp", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38246" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38246" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38246" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json b/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json new file mode 100644 index 00000000000..68b1dd012c4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xghp-74wc-wjg3/GHSA-xghp-74wc-wjg3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xghp-74wc-wjg3", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-30073" + ], + "details": "Windows Security Zone Mapping Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30073" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30073" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xgjv-9929-vw26/GHSA-xgjv-9929-vw26.json b/advisories/unreviewed/2024/09/GHSA-xgjv-9929-vw26/GHSA-xgjv-9929-vw26.json new file mode 100644 index 00000000000..4dda2d20e14 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xgjv-9929-vw26/GHSA-xgjv-9929-vw26.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgjv-9929-vw26", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2023-37234" + ], + "details": "Loftware Spectrum through 4.6 has unprotected JMX Registry.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37234" + }, + { + "type": "WEB", + "url": "https://code-white.com" + }, + { + "type": "WEB", + "url": "https://code-white.com/public-vulnerability-list" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xmv4-684g-76jm/GHSA-xmv4-684g-76jm.json b/advisories/unreviewed/2024/09/GHSA-xmv4-684g-76jm/GHSA-xmv4-684g-76jm.json new file mode 100644 index 00000000000..1a910de86c3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xmv4-684g-76jm/GHSA-xmv4-684g-76jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmv4-684g-76jm", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38234" + ], + "details": "Windows Networking Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38234" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38234" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json b/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json new file mode 100644 index 00000000000..c16e86e63f4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xr4h-93hj-62q2/GHSA-xr4h-93hj-62q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr4h-93hj-62q2", + "modified": "2024-09-10T18:30:44Z", + "published": "2024-09-10T18:30:44Z", + "aliases": [ + "CVE-2024-26186" + ], + "details": "Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26186" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xvc5-jg6r-264j/GHSA-xvc5-jg6r-264j.json b/advisories/unreviewed/2024/09/GHSA-xvc5-jg6r-264j/GHSA-xvc5-jg6r-264j.json new file mode 100644 index 00000000000..aed95504473 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xvc5-jg6r-264j/GHSA-xvc5-jg6r-264j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvc5-jg6r-264j", + "modified": "2024-09-10T18:30:45Z", + "published": "2024-09-10T18:30:45Z", + "aliases": [ + "CVE-2024-38188" + ], + "details": "Azure Network Watcher VM Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38188" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xxq4-9c68-6533/GHSA-xxq4-9c68-6533.json b/advisories/unreviewed/2024/09/GHSA-xxq4-9c68-6533/GHSA-xxq4-9c68-6533.json new file mode 100644 index 00000000000..58b5f0ec473 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xxq4-9c68-6533/GHSA-xxq4-9c68-6533.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxq4-9c68-6533", + "modified": "2024-09-10T18:30:46Z", + "published": "2024-09-10T18:30:46Z", + "aliases": [ + "CVE-2024-38254" + ], + "details": "Windows Authentication Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38254" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T17:15:31Z" + } +} \ No newline at end of file