From b35bef6eb06375c8a54552d373991e2e7a68793e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 30 Oct 2024 18:32:24 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-586p-749j-fhwp.json | 6 ++- .../GHSA-jrp6-94m7-j7gw.json | 2 +- .../GHSA-34g8-74vq-q8mf.json | 2 +- .../GHSA-mq9m-4hg9-c34x.json | 9 ++-- .../GHSA-ww69-c6p5-r54m.json | 9 ++-- .../GHSA-xhcj-9vv5-9686.json | 11 +++-- .../GHSA-4jfc-fmx7-w96j.json | 11 +++-- .../GHSA-7h53-ghp8-m96v.json | 9 ++-- .../GHSA-89x5-5cm6-8f6q.json | 11 +++-- .../GHSA-9c8r-v4r8-9v3x.json | 11 +++-- .../GHSA-ggqq-32pw-pm22.json | 9 ++-- .../GHSA-w584-w92p-hx8h.json | 9 ++-- .../GHSA-556r-646r-vxjp.json | 9 ++-- .../GHSA-5jv6-7953-598p.json | 9 ++-- .../GHSA-chc5-gj7v-7hf9.json | 2 +- .../GHSA-m2qg-6h4j-p422.json | 11 +++-- .../GHSA-26jw-cv8r-w4pr.json | 9 ++-- .../GHSA-783m-7jjf-pmgr.json | 4 +- .../GHSA-f975-vjfw-7f99.json | 9 ++-- .../GHSA-v7qr-4h7w-77cm.json | 9 ++-- .../GHSA-xwqp-6c5w-h6q9.json | 9 ++-- .../GHSA-6f83-xgr8-j9pf.json | 11 +++-- .../GHSA-6mp9-hrx8-6ffg.json | 2 +- .../GHSA-c4xw-jcqw-fwfx.json | 2 +- .../GHSA-hmj9-jcgj-cqxx.json | 2 +- .../GHSA-wx36-wgp2-fwpq.json | 2 +- .../GHSA-mg4j-48vm-fxmg.json | 9 ++-- .../GHSA-r3h8-2v74-r6qj.json | 2 +- .../GHSA-wcrf-58c6-27cg.json | 11 +++-- .../GHSA-794f-5gfq-xmmq.json | 2 +- .../GHSA-97x9-7h6v-3jx9.json | 2 +- .../GHSA-hrqj-68hr-6cvc.json | 11 +++-- .../GHSA-j755-mmjr-g7rh.json | 2 +- .../GHSA-p34f-6xg6-mcrp.json | 1 + .../GHSA-ph32-hgpc-r5j4.json | 2 +- .../GHSA-2387-p29v-hcc7.json | 2 +- .../GHSA-28h3-55jv-gc4g.json | 2 +- .../GHSA-2jwm-qv7q-9cc7.json | 11 +++-- .../GHSA-3vrp-8p8h-29r9.json | 11 +++-- .../GHSA-3x5w-67jh-3785.json | 35 +++++++++++++++ .../GHSA-3xpf-325v-j848.json | 9 ++-- .../GHSA-46c8-p74g-hqqh.json | 43 +++++++++++++++++++ .../GHSA-4f8q-56wq-r4gw.json | 11 +++-- .../GHSA-4mgj-f599-w3j8.json | 9 ++-- .../GHSA-5744-494c-924x.json | 9 ++-- .../GHSA-57cp-r273-mcmf.json | 9 ++-- .../GHSA-58q9-jhx4-mj9p.json | 9 ++-- .../GHSA-5fx2-6ffx-qmvv.json | 11 +++-- .../GHSA-5qq3-3hpq-crq9.json | 2 +- .../GHSA-64xw-25gj-x6w6.json | 11 +++-- .../GHSA-6c6m-6wj2-c9h3.json | 35 +++++++++++++++ .../GHSA-78fm-rcjq-jr27.json | 38 ++++++++++++++++ .../GHSA-7x3v-348q-cc5h.json | 9 ++-- .../GHSA-822w-7669-q3g6.json | 11 +++-- .../GHSA-8545-3w77-w6gm.json | 9 ++-- .../GHSA-8798-5c83-39gj.json | 2 +- .../GHSA-8h4j-cm33-q84h.json | 2 +- .../GHSA-8hp8-42cx-5q42.json | 11 +++-- .../GHSA-8pmx-rxgv-j8j9.json | 6 ++- .../GHSA-8xq2-3cqg-9xfj.json | 35 +++++++++++++++ .../GHSA-93c2-6235-vfvp.json | 9 ++-- .../GHSA-94jr-5hwp-8492.json | 1 + .../GHSA-95v3-2xxf-g2hg.json | 35 +++++++++++++++ .../GHSA-9f2m-2wcx-2f6m.json | 38 ++++++++++++++++ .../GHSA-9v5x-r4g7-gqw3.json | 11 +++-- .../GHSA-c45f-33wq-x2qc.json | 2 +- .../GHSA-c83g-cgfm-hc33.json | 2 +- .../GHSA-c8r4-qw78-4r3m.json | 11 +++-- .../GHSA-cvm9-cv4j-fhwp.json | 35 +++++++++++++++ .../GHSA-cwg2-qmg3-3f6x.json | 11 +++-- .../GHSA-fh9m-mpjc-38hg.json | 9 ++-- .../GHSA-g56g-9mxr-9pgw.json | 35 +++++++++++++++ .../GHSA-g6j9-66rq-g4jr.json | 11 +++-- .../GHSA-grqq-hcc7-crmr.json | 6 ++- .../GHSA-hxrv-64jf-fgmr.json | 35 +++++++++++++++ .../GHSA-jg9m-4m4c-v7c8.json | 35 +++++++++++++++ .../GHSA-jpwg-q62q-pwpw.json | 11 +++-- .../GHSA-m2wj-x8qh-wqcv.json | 11 +++-- .../GHSA-m499-vjfj-6h36.json | 2 +- .../GHSA-m4vf-r3xm-3qhj.json | 11 +++-- .../GHSA-mcg7-2pf9-m48g.json | 11 +++-- .../GHSA-mrqw-j759-rwwq.json | 9 ++-- .../GHSA-p7rr-c68v-256j.json | 12 ++++-- .../GHSA-p8vr-968q-whxq.json | 35 +++++++++++++++ .../GHSA-p94g-pv57-gw9x.json | 11 +++-- .../GHSA-pjg9-qwh6-g7w9.json | 11 +++-- .../GHSA-pvm4-q7m8-9wqx.json | 3 +- .../GHSA-pxj5-97f9-grjr.json | 11 +++-- .../GHSA-q2q9-q8mv-pv59.json | 11 +++-- .../GHSA-qc9f-6x66-h8c3.json | 11 +++-- .../GHSA-qvrv-r8xg-hh75.json | 9 ++-- .../GHSA-r2q9-52vc-q982.json | 42 ++++++++++++++++++ .../GHSA-r5h8-q4jm-864x.json | 11 +++-- .../GHSA-r922-52fr-4x9g.json | 3 +- .../GHSA-rggh-rm3v-8xqj.json | 2 +- .../GHSA-v39q-v2cw-g4fp.json | 11 +++-- .../GHSA-v4pp-cm3w-w8gh.json | 35 +++++++++++++++ .../GHSA-vgwf-5fwc-xx64.json | 11 +++-- .../GHSA-vhv3-639r-j6rp.json | 9 ++-- .../GHSA-w688-vpw2-mqfg.json | 11 +++-- .../GHSA-wg5p-9v6g-ch4x.json | 9 ++-- .../GHSA-wpcr-qwq5-j6w2.json | 11 +++-- .../GHSA-wrjh-x85j-vvg8.json | 35 +++++++++++++++ .../GHSA-wvfr-r5jg-p8ff.json | 9 ++-- .../GHSA-wvj9-mrxw-ww9p.json | 35 +++++++++++++++ .../GHSA-wx35-29xj-r29q.json | 9 ++-- .../GHSA-xf88-x6f5-fvg8.json | 9 ++-- .../GHSA-xvhx-jwjw-g589.json | 11 +++-- 108 files changed, 1039 insertions(+), 252 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json create mode 100644 advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-78fm-rcjq-jr27/GHSA-78fm-rcjq-jr27.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-95v3-2xxf-g2hg/GHSA-95v3-2xxf-g2hg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9f2m-2wcx-2f6m/GHSA-9f2m-2wcx-2f6m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r2q9-52vc-q982/GHSA-r2q9-52vc-q982.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v4pp-cm3w-w8gh/GHSA-v4pp-cm3w-w8gh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wrjh-x85j-vvg8/GHSA-wrjh-x85j-vvg8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json diff --git a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json index e677910edc2..291be4fbb04 100644 --- a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json +++ b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-586p-749j-fhwp", - "modified": "2024-10-30T09:30:46Z", + "modified": "2024-10-30T18:30:46Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-9675" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8563" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8675" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9675" diff --git a/advisories/unreviewed/2023/07/GHSA-jrp6-94m7-j7gw/GHSA-jrp6-94m7-j7gw.json b/advisories/unreviewed/2023/07/GHSA-jrp6-94m7-j7gw/GHSA-jrp6-94m7-j7gw.json index 0cbc981d1ce..a3386bfffb6 100644 --- a/advisories/unreviewed/2023/07/GHSA-jrp6-94m7-j7gw/GHSA-jrp6-94m7-j7gw.json +++ b/advisories/unreviewed/2023/07/GHSA-jrp6-94m7-j7gw/GHSA-jrp6-94m7-j7gw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-34g8-74vq-q8mf/GHSA-34g8-74vq-q8mf.json b/advisories/unreviewed/2024/03/GHSA-34g8-74vq-q8mf/GHSA-34g8-74vq-q8mf.json index f0e08d79739..bf4c344caa4 100644 --- a/advisories/unreviewed/2024/03/GHSA-34g8-74vq-q8mf/GHSA-34g8-74vq-q8mf.json +++ b/advisories/unreviewed/2024/03/GHSA-34g8-74vq-q8mf/GHSA-34g8-74vq-q8mf.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json b/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json index f26dc12aec5..9318623c156 100644 --- a/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json +++ b/advisories/unreviewed/2024/03/GHSA-mq9m-4hg9-c34x/GHSA-mq9m-4hg9-c34x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq9m-4hg9-c34x", - "modified": "2024-03-25T18:30:57Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2610" ], "details": "Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T12:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json b/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json index 7f90d266f75..0b89797339f 100644 --- a/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json +++ b/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ww69-c6p5-r54m", - "modified": "2024-03-19T12:30:41Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2606" ], "details": "Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T12:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xhcj-9vv5-9686/GHSA-xhcj-9vv5-9686.json b/advisories/unreviewed/2024/03/GHSA-xhcj-9vv5-9686/GHSA-xhcj-9vv5-9686.json index 0da87e424c8..d8b2af3311e 100644 --- a/advisories/unreviewed/2024/03/GHSA-xhcj-9vv5-9686/GHSA-xhcj-9vv5-9686.json +++ b/advisories/unreviewed/2024/03/GHSA-xhcj-9vv5-9686/GHSA-xhcj-9vv5-9686.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhcj-9vv5-9686", - "modified": "2024-03-28T21:30:31Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-03-28T21:30:31Z", "aliases": [ "CVE-2024-31064" ], "details": "Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T19:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4jfc-fmx7-w96j/GHSA-4jfc-fmx7-w96j.json b/advisories/unreviewed/2024/04/GHSA-4jfc-fmx7-w96j/GHSA-4jfc-fmx7-w96j.json index bf0ac23a6d8..680e6289387 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jfc-fmx7-w96j/GHSA-4jfc-fmx7-w96j.json +++ b/advisories/unreviewed/2024/04/GHSA-4jfc-fmx7-w96j/GHSA-4jfc-fmx7-w96j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jfc-fmx7-w96j", - "modified": "2024-04-25T18:30:39Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-04-25T18:30:39Z", "aliases": [ "CVE-2024-31574" ], "details": "Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-25T17:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7h53-ghp8-m96v/GHSA-7h53-ghp8-m96v.json b/advisories/unreviewed/2024/04/GHSA-7h53-ghp8-m96v/GHSA-7h53-ghp8-m96v.json index a86c5697a2c..edec264ad43 100644 --- a/advisories/unreviewed/2024/04/GHSA-7h53-ghp8-m96v/GHSA-7h53-ghp8-m96v.json +++ b/advisories/unreviewed/2024/04/GHSA-7h53-ghp8-m96v/GHSA-7h53-ghp8-m96v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h53-ghp8-m96v", - "modified": "2024-04-28T15:30:29Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48634" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gma500: Fix BUG: sleeping function called from invalid context errors\n\ngma_crtc_page_flip() was holding the event_lock spinlock while calling\ncrtc_funcs->mode_set_base() which takes ww_mutex.\n\nThe only reason to hold event_lock is to clear gma_crtc->page_flip_event\non mode_set_base() errors.\n\nInstead unlock it after setting gma_crtc->page_flip_event and on\nerrors re-take the lock and clear gma_crtc->page_flip_event it\nit is still set.\n\nThis fixes the following WARN/stacktrace:\n\n[ 512.122953] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:870\n[ 512.123004] in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 1253, name: gnome-shell\n[ 512.123031] preempt_count: 1, expected: 0\n[ 512.123048] RCU nest depth: 0, expected: 0\n[ 512.123066] INFO: lockdep is turned off.\n[ 512.123080] irq event stamp: 0\n[ 512.123094] hardirqs last enabled at (0): [<0000000000000000>] 0x0\n[ 512.123134] hardirqs last disabled at (0): [] copy_process+0x9fc/0x1de0\n[ 512.123176] softirqs last enabled at (0): [] copy_process+0x9fc/0x1de0\n[ 512.123207] softirqs last disabled at (0): [<0000000000000000>] 0x0\n[ 512.123233] Preemption disabled at:\n[ 512.123241] [<0000000000000000>] 0x0\n[ 512.123275] CPU: 3 PID: 1253 Comm: gnome-shell Tainted: G W 5.19.0+ #1\n[ 512.123304] Hardware name: Packard Bell dot s/SJE01_CT, BIOS V1.10 07/23/2013\n[ 512.123323] Call Trace:\n[ 512.123346] \n[ 512.123370] dump_stack_lvl+0x5b/0x77\n[ 512.123412] __might_resched.cold+0xff/0x13a\n[ 512.123458] ww_mutex_lock+0x1e/0xa0\n[ 512.123495] psb_gem_pin+0x2c/0x150 [gma500_gfx]\n[ 512.123601] gma_pipe_set_base+0x76/0x240 [gma500_gfx]\n[ 512.123708] gma_crtc_page_flip+0x95/0x130 [gma500_gfx]\n[ 512.123808] drm_mode_page_flip_ioctl+0x57d/0x5d0\n[ 512.123897] ? drm_mode_cursor2_ioctl+0x10/0x10\n[ 512.123936] drm_ioctl_kernel+0xa1/0x150\n[ 512.123984] drm_ioctl+0x21f/0x420\n[ 512.124025] ? drm_mode_cursor2_ioctl+0x10/0x10\n[ 512.124070] ? rcu_read_lock_bh_held+0xb/0x60\n[ 512.124104] ? lock_release+0x1ef/0x2d0\n[ 512.124161] __x64_sys_ioctl+0x8d/0xd0\n[ 512.124203] do_syscall_64+0x58/0x80\n[ 512.124239] ? do_syscall_64+0x67/0x80\n[ 512.124267] ? trace_hardirqs_on_prepare+0x55/0xe0\n[ 512.124300] ? do_syscall_64+0x67/0x80\n[ 512.124340] ? rcu_read_lock_sched_held+0x10/0x80\n[ 512.124377] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 512.124411] RIP: 0033:0x7fcc4a70740f\n[ 512.124442] Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00\n[ 512.124470] RSP: 002b:00007ffda73f5390 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n[ 512.124503] RAX: ffffffffffffffda RBX: 000055cc9e474500 RCX: 00007fcc4a70740f\n[ 512.124524] RDX: 00007ffda73f5420 RSI: 00000000c01864b0 RDI: 0000000000000009\n[ 512.124544] RBP: 00007ffda73f5420 R08: 000055cc9c0b0cb0 R09: 0000000000000034\n[ 512.124564] R10: 0000000000000000 R11: 0000000000000246 R12: 00000000c01864b0\n[ 512.124584] R13: 0000000000000009 R14: 000055cc9df484d0 R15: 000055cc9af5d0c0\n[ 512.124647] ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-89x5-5cm6-8f6q/GHSA-89x5-5cm6-8f6q.json b/advisories/unreviewed/2024/04/GHSA-89x5-5cm6-8f6q/GHSA-89x5-5cm6-8f6q.json index 923a3f3744f..3a4f3b2e59c 100644 --- a/advisories/unreviewed/2024/04/GHSA-89x5-5cm6-8f6q/GHSA-89x5-5cm6-8f6q.json +++ b/advisories/unreviewed/2024/04/GHSA-89x5-5cm6-8f6q/GHSA-89x5-5cm6-8f6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89x5-5cm6-8f6q", - "modified": "2024-04-16T06:30:27Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-04-16T06:30:27Z", "aliases": [ "CVE-2024-31634" ], "details": "Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog \\XunRuiCMS\\dayrui\\Fcms\\Library.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T04:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9c8r-v4r8-9v3x/GHSA-9c8r-v4r8-9v3x.json b/advisories/unreviewed/2024/04/GHSA-9c8r-v4r8-9v3x/GHSA-9c8r-v4r8-9v3x.json index 70ebcfb67a6..7038302e58a 100644 --- a/advisories/unreviewed/2024/04/GHSA-9c8r-v4r8-9v3x/GHSA-9c8r-v4r8-9v3x.json +++ b/advisories/unreviewed/2024/04/GHSA-9c8r-v4r8-9v3x/GHSA-9c8r-v4r8-9v3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9c8r-v4r8-9v3x", - "modified": "2024-04-15T21:30:47Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-04-15T21:30:47Z", "aliases": [ "CVE-2024-31652" ], "details": "A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-ggqq-32pw-pm22/GHSA-ggqq-32pw-pm22.json b/advisories/unreviewed/2024/04/GHSA-ggqq-32pw-pm22/GHSA-ggqq-32pw-pm22.json index 3956aaa8ee6..8718b1fab06 100644 --- a/advisories/unreviewed/2024/04/GHSA-ggqq-32pw-pm22/GHSA-ggqq-32pw-pm22.json +++ b/advisories/unreviewed/2024/04/GHSA-ggqq-32pw-pm22/GHSA-ggqq-32pw-pm22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggqq-32pw-pm22", - "modified": "2024-04-28T15:30:29Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48638" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: cgroup_get_from_id() must check the looked-up kn is a directory\n\ncgroup has to be one kernfs dir, otherwise kernel panic is caused,\nespecially cgroup id is provide from userspace.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w584-w92p-hx8h/GHSA-w584-w92p-hx8h.json b/advisories/unreviewed/2024/04/GHSA-w584-w92p-hx8h/GHSA-w584-w92p-hx8h.json index b3b9aaab6a8..9ab4efba40d 100644 --- a/advisories/unreviewed/2024/04/GHSA-w584-w92p-hx8h/GHSA-w584-w92p-hx8h.json +++ b/advisories/unreviewed/2024/04/GHSA-w584-w92p-hx8h/GHSA-w584-w92p-hx8h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w584-w92p-hx8h", - "modified": "2024-04-03T18:30:40Z", + "modified": "2024-10-30T18:30:44Z", "published": "2024-04-03T18:30:40Z", "aliases": [ "CVE-2024-31392" ], "details": "If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T16:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json b/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json index 0cb05ad2030..60aa90ecf37 100644 --- a/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json +++ b/advisories/unreviewed/2024/05/GHSA-556r-646r-vxjp/GHSA-556r-646r-vxjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-556r-646r-vxjp", - "modified": "2024-05-03T18:30:36Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-05-03T18:30:36Z", "aliases": [ "CVE-2022-48697" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix a use-after-free\n\nFix the following use-after-free complaint triggered by blktests nvme/004:\n\nBUG: KASAN: user-memory-access in blk_mq_complete_request_remote+0xac/0x350\nRead of size 4 at addr 0000607bd1835943 by task kworker/13:1/460\nWorkqueue: nvmet-wq nvme_loop_execute_work [nvme_loop]\nCall Trace:\n show_stack+0x52/0x58\n dump_stack_lvl+0x49/0x5e\n print_report.cold+0x36/0x1e2\n kasan_report+0xb9/0xf0\n __asan_load4+0x6b/0x80\n blk_mq_complete_request_remote+0xac/0x350\n nvme_loop_queue_response+0x1df/0x275 [nvme_loop]\n __nvmet_req_complete+0x132/0x4f0 [nvmet]\n nvmet_req_complete+0x15/0x40 [nvmet]\n nvmet_execute_io_connect+0x18a/0x1f0 [nvmet]\n nvme_loop_execute_work+0x20/0x30 [nvme_loop]\n process_one_work+0x56e/0xa70\n worker_thread+0x2d1/0x640\n kthread+0x183/0x1c0\n ret_from_fork+0x1f/0x30", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json b/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json index a3bcfd848db..48c98482ce9 100644 --- a/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json +++ b/advisories/unreviewed/2024/05/GHSA-5jv6-7953-598p/GHSA-5jv6-7953-598p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jv6-7953-598p", - "modified": "2024-05-03T18:30:36Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-05-03T18:30:36Z", "aliases": [ "CVE-2022-48698" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix memory leak when using debugfs_lookup()\n\nWhen calling debugfs_lookup() the result must have dput() called on it,\notherwise the memory will leak over time. Fix this up by properly\ncalling dput().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-chc5-gj7v-7hf9/GHSA-chc5-gj7v-7hf9.json b/advisories/unreviewed/2024/05/GHSA-chc5-gj7v-7hf9/GHSA-chc5-gj7v-7hf9.json index bea26053770..d15fc23081c 100644 --- a/advisories/unreviewed/2024/05/GHSA-chc5-gj7v-7hf9/GHSA-chc5-gj7v-7hf9.json +++ b/advisories/unreviewed/2024/05/GHSA-chc5-gj7v-7hf9/GHSA-chc5-gj7v-7hf9.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-m2qg-6h4j-p422/GHSA-m2qg-6h4j-p422.json b/advisories/unreviewed/2024/05/GHSA-m2qg-6h4j-p422/GHSA-m2qg-6h4j-p422.json index 7d269db2e2c..535acd5e7c5 100644 --- a/advisories/unreviewed/2024/05/GHSA-m2qg-6h4j-p422/GHSA-m2qg-6h4j-p422.json +++ b/advisories/unreviewed/2024/05/GHSA-m2qg-6h4j-p422/GHSA-m2qg-6h4j-p422.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2qg-6h4j-p422", - "modified": "2024-05-06T06:30:45Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-05-06T06:30:45Z", "aliases": [ "CVE-2024-3752" ], "details": "The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T06:15:07Z" diff --git a/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json b/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json index 24fae6cda6a..90d85f386c4 100644 --- a/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json +++ b/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26jw-cv8r-w4pr", - "modified": "2024-06-20T12:31:22Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-06-20T12:31:22Z", "aliases": [ "CVE-2022-48767" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: properly put ceph_string reference after async create attempt\n\nThe reference acquired by try_prep_async_create is currently leaked.\nEnsure we put it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json b/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json index d630f7f883f..6497de5b644 100644 --- a/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json +++ b/advisories/unreviewed/2024/06/GHSA-783m-7jjf-pmgr/GHSA-783m-7jjf-pmgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-783m-7jjf-pmgr", - "modified": "2024-06-25T18:31:22Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-06-25T18:31:22Z", "aliases": [ "CVE-2024-6238" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json b/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json index 06cbbc7699c..c9f5b9f7050 100644 --- a/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json +++ b/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f975-vjfw-7f99", - "modified": "2024-06-20T12:31:22Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-06-20T12:31:22Z", "aliases": [ "CVE-2022-48761" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci-plat: fix crash when suspend if remote wake enable\n\nCrashed at i.mx8qm platform when suspend if enable remote wakeup\n\nInternal error: synchronous external abort: 96000210 [#1] PREEMPT SMP\nModules linked in:\nCPU: 2 PID: 244 Comm: kworker/u12:6 Not tainted 5.15.5-dirty #12\nHardware name: Freescale i.MX8QM MEK (DT)\nWorkqueue: events_unbound async_run_entry_fn\npstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : xhci_disable_hub_port_wake.isra.62+0x60/0xf8\nlr : xhci_disable_hub_port_wake.isra.62+0x34/0xf8\nsp : ffff80001394bbf0\nx29: ffff80001394bbf0 x28: 0000000000000000 x27: ffff00081193b578\nx26: ffff00081193b570 x25: 0000000000000000 x24: 0000000000000000\nx23: ffff00081193a29c x22: 0000000000020001 x21: 0000000000000001\nx20: 0000000000000000 x19: ffff800014e90490 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\nx14: 0000000000000000 x13: 0000000000000002 x12: 0000000000000000\nx11: 0000000000000000 x10: 0000000000000960 x9 : ffff80001394baa0\nx8 : ffff0008145d1780 x7 : ffff0008f95b8e80 x6 : 000000001853b453\nx5 : 0000000000000496 x4 : 0000000000000000 x3 : ffff00081193a29c\nx2 : 0000000000000001 x1 : 0000000000000000 x0 : ffff000814591620\nCall trace:\n xhci_disable_hub_port_wake.isra.62+0x60/0xf8\n xhci_suspend+0x58/0x510\n xhci_plat_suspend+0x50/0x78\n platform_pm_suspend+0x2c/0x78\n dpm_run_callback.isra.25+0x50/0xe8\n __device_suspend+0x108/0x3c0\n\nThe basic flow:\n\t1. run time suspend call xhci_suspend, xhci parent devices gate the clock.\n 2. echo mem >/sys/power/state, system _device_suspend call xhci_suspend\n 3. xhci_suspend call xhci_disable_hub_port_wake, which access register,\n\t but clock already gated by run time suspend.\n\nThis problem was hidden by power domain driver, which call run time resume before it.\n\nBut the below commit remove it and make this issue happen.\n\tcommit c1df456d0f06e (\"PM: domains: Don't runtime resume devices at genpd_prepare()\")\n\nThis patch call run time resume before suspend to make sure clock is on\nbefore access register.\n\nTesteb-by: Abel Vesa ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json b/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json index 662ece77b7d..9ab255d4156 100644 --- a/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json +++ b/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7qr-4h7w-77cm", - "modified": "2024-06-20T12:31:22Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-06-20T12:31:22Z", "aliases": [ "CVE-2022-48764" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Free kvm_cpuid_entry2 array on post-KVM_RUN KVM_SET_CPUID{,2}\n\nFree the \"struct kvm_cpuid_entry2\" array on successful post-KVM_RUN\nKVM_SET_CPUID{,2} to fix a memory leak, the callers of kvm_set_cpuid()\nfree the array only on failure.\n\n BUG: memory leak\n unreferenced object 0xffff88810963a800 (size 2048):\n comm \"syz-executor025\", pid 3610, jiffies 4294944928 (age 8.080s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 0d 00 00 00 ................\n 47 65 6e 75 6e 74 65 6c 69 6e 65 49 00 00 00 00 GenuntelineI....\n backtrace:\n [] kmalloc_node include/linux/slab.h:604 [inline]\n [] kvmalloc_node+0x3e/0x100 mm/util.c:580\n [] kvmalloc include/linux/slab.h:732 [inline]\n [] vmemdup_user+0x22/0x100 mm/util.c:199\n [] kvm_vcpu_ioctl_set_cpuid2+0x8f/0xf0 arch/x86/kvm/cpuid.c:423\n [] kvm_arch_vcpu_ioctl+0xb99/0x1e60 arch/x86/kvm/x86.c:5251\n [] kvm_vcpu_ioctl+0x4ad/0x950 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4066\n [] vfs_ioctl fs/ioctl.c:51 [inline]\n [] __do_sys_ioctl fs/ioctl.c:874 [inline]\n [] __se_sys_ioctl fs/ioctl.c:860 [inline]\n [] __x64_sys_ioctl+0xfc/0x140 fs/ioctl.c:860\n [] do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n [] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n [] entry_SYSCALL_64_after_hwframe+0x44/0xae", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json b/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json index d5eec257e1c..87033b8309a 100644 --- a/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json +++ b/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwqp-6c5w-h6q9", - "modified": "2024-06-20T12:31:20Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-06-20T12:31:20Z", "aliases": [ "CVE-2022-48711" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: improve size validations for received domain records\n\nThe function tipc_mon_rcv() allows a node to receive and process\ndomain_record structs from peer nodes to track their views of the\nnetwork topology.\n\nThis patch verifies that the number of members in a received domain\nrecord does not exceed the limit defined by MAX_MON_DOMAIN, something\nthat may otherwise lead to a stack overflow.\n\ntipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where\nwe are reading a 32 bit message data length field into a uint16. To\navert any risk of bit overflow, we add an extra sanity check for this in\nthat function. We cannot see that happen with the current code, but\nfuture designers being unaware of this risk, may introduce it by\nallowing delivery of very large (> 64k) sk buffers from the bearer\nlayer. This potential problem was identified by Eric Dumazet.\n\nThis fixes CVE-2022-0435", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T11:15:54Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6f83-xgr8-j9pf/GHSA-6f83-xgr8-j9pf.json b/advisories/unreviewed/2024/07/GHSA-6f83-xgr8-j9pf/GHSA-6f83-xgr8-j9pf.json index 1d2d9f075e4..6c71fca00f4 100644 --- a/advisories/unreviewed/2024/07/GHSA-6f83-xgr8-j9pf/GHSA-6f83-xgr8-j9pf.json +++ b/advisories/unreviewed/2024/07/GHSA-6f83-xgr8-j9pf/GHSA-6f83-xgr8-j9pf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f83-xgr8-j9pf", - "modified": "2024-07-15T21:31:06Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-07-15T21:31:06Z", "aliases": [ "CVE-2024-31946" ], "details": "An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the template preview. The following versions fix this: 3.7.42, 3.11.30, 4.3.25, and 4.7.5.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T19:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json b/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json index ce049386d23..01920391166 100644 --- a/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json +++ b/advisories/unreviewed/2024/07/GHSA-6mp9-hrx8-6ffg/GHSA-6mp9-hrx8-6ffg.json @@ -84,7 +84,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json b/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json index e149632cd45..3814c5db0d0 100644 --- a/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json +++ b/advisories/unreviewed/2024/07/GHSA-c4xw-jcqw-fwfx/GHSA-c4xw-jcqw-fwfx.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-hmj9-jcgj-cqxx/GHSA-hmj9-jcgj-cqxx.json b/advisories/unreviewed/2024/07/GHSA-hmj9-jcgj-cqxx/GHSA-hmj9-jcgj-cqxx.json index b94295edb20..16389da4ca2 100644 --- a/advisories/unreviewed/2024/07/GHSA-hmj9-jcgj-cqxx/GHSA-hmj9-jcgj-cqxx.json +++ b/advisories/unreviewed/2024/07/GHSA-hmj9-jcgj-cqxx/GHSA-hmj9-jcgj-cqxx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json b/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json index 24977f378d2..74106666815 100644 --- a/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json +++ b/advisories/unreviewed/2024/07/GHSA-wx36-wgp2-fwpq/GHSA-wx36-wgp2-fwpq.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json b/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json index 504b3c04ae1..fc5ca2234ee 100644 --- a/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json +++ b/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mg4j-48vm-fxmg", - "modified": "2024-08-20T18:31:26Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-08-20T18:31:26Z", "aliases": [ "CVE-2024-40743" ], "details": "The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T16:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json b/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json index d4a2a786098..e6a72ebe1b1 100644 --- a/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json +++ b/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json b/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json index c870392aa68..8caff792f89 100644 --- a/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json +++ b/advisories/unreviewed/2024/08/GHSA-wcrf-58c6-27cg/GHSA-wcrf-58c6-27cg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wcrf-58c6-27cg", - "modified": "2024-08-16T18:30:57Z", + "modified": "2024-10-30T18:30:45Z", "published": "2024-08-16T18:30:57Z", "aliases": [ "CVE-2024-25837" ], "details": "A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T18:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json b/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json index 558187384e3..9bfb26e3bf4 100644 --- a/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json +++ b/advisories/unreviewed/2024/09/GHSA-794f-5gfq-xmmq/GHSA-794f-5gfq-xmmq.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1188" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json index 63ec7f18f26..c5b5d1d5dc9 100644 --- a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json +++ b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json b/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json index 9a1dc4b33c4..047ceb6c5a6 100644 --- a/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json +++ b/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrqj-68hr-6cvc", - "modified": "2024-09-30T18:31:36Z", + "modified": "2024-10-30T18:30:46Z", "published": "2024-09-30T18:31:36Z", "aliases": [ "CVE-2024-35495" ], "details": "An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json b/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json index 72ed25d331e..a93d66dc1f6 100644 --- a/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json +++ b/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json b/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json index 8030e2f9b7b..cad4259a998 100644 --- a/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json +++ b/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-290", "CWE-601" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json b/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json index 41df11d124e..3efaa4ffa34 100644 --- a/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json +++ b/advisories/unreviewed/2024/09/GHSA-ph32-hgpc-r5j4/GHSA-ph32-hgpc-r5j4.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-273" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2387-p29v-hcc7/GHSA-2387-p29v-hcc7.json b/advisories/unreviewed/2024/10/GHSA-2387-p29v-hcc7/GHSA-2387-p29v-hcc7.json index 46568447b20..b76713f8100 100644 --- a/advisories/unreviewed/2024/10/GHSA-2387-p29v-hcc7/GHSA-2387-p29v-hcc7.json +++ b/advisories/unreviewed/2024/10/GHSA-2387-p29v-hcc7/GHSA-2387-p29v-hcc7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-28h3-55jv-gc4g/GHSA-28h3-55jv-gc4g.json b/advisories/unreviewed/2024/10/GHSA-28h3-55jv-gc4g/GHSA-28h3-55jv-gc4g.json index 25065bb10df..33038f7fc5d 100644 --- a/advisories/unreviewed/2024/10/GHSA-28h3-55jv-gc4g/GHSA-28h3-55jv-gc4g.json +++ b/advisories/unreviewed/2024/10/GHSA-28h3-55jv-gc4g/GHSA-28h3-55jv-gc4g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2jwm-qv7q-9cc7/GHSA-2jwm-qv7q-9cc7.json b/advisories/unreviewed/2024/10/GHSA-2jwm-qv7q-9cc7/GHSA-2jwm-qv7q-9cc7.json index b5bcfc644db..a260e54d645 100644 --- a/advisories/unreviewed/2024/10/GHSA-2jwm-qv7q-9cc7/GHSA-2jwm-qv7q-9cc7.json +++ b/advisories/unreviewed/2024/10/GHSA-2jwm-qv7q-9cc7/GHSA-2jwm-qv7q-9cc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jwm-qv7q-9cc7", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44239" ], "details": "An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. An app may be able to leak sensitive kernel state.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3vrp-8p8h-29r9/GHSA-3vrp-8p8h-29r9.json b/advisories/unreviewed/2024/10/GHSA-3vrp-8p8h-29r9/GHSA-3vrp-8p8h-29r9.json index dfcc2404005..02b34245a35 100644 --- a/advisories/unreviewed/2024/10/GHSA-3vrp-8p8h-29r9/GHSA-3vrp-8p8h-29r9.json +++ b/advisories/unreviewed/2024/10/GHSA-3vrp-8p8h-29r9/GHSA-3vrp-8p8h-29r9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vrp-8p8h-29r9", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44270" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A sandboxed process may be able to circumvent sandbox restrictions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json b/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json new file mode 100644 index 00000000000..0b064f436ee --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x5w-67jh-3785", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-31975" + ], + "details": "EnGenius ESR580 devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31975" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-31975" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3xpf-325v-j848/GHSA-3xpf-325v-j848.json b/advisories/unreviewed/2024/10/GHSA-3xpf-325v-j848/GHSA-3xpf-325v-j848.json index 4a4fd6ad497..e41eb57c12d 100644 --- a/advisories/unreviewed/2024/10/GHSA-3xpf-325v-j848/GHSA-3xpf-325v-j848.json +++ b/advisories/unreviewed/2024/10/GHSA-3xpf-325v-j848/GHSA-3xpf-325v-j848.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3xpf-325v-j848", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44194" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json b/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json new file mode 100644 index 00000000000..06251159709 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46c8-p74g-hqqh", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-48241" + ], + "details": "An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48241" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/issues/23317" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/pull/23318" + }, + { + "type": "WEB", + "url": "https://github.com/St-Andrews-Bug-Busters/Vuln_info/blob/main/radare2/CVE-2024-48241.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4f8q-56wq-r4gw/GHSA-4f8q-56wq-r4gw.json b/advisories/unreviewed/2024/10/GHSA-4f8q-56wq-r4gw/GHSA-4f8q-56wq-r4gw.json index 2eae74683a0..c41eec539f0 100644 --- a/advisories/unreviewed/2024/10/GHSA-4f8q-56wq-r4gw/GHSA-4f8q-56wq-r4gw.json +++ b/advisories/unreviewed/2024/10/GHSA-4f8q-56wq-r4gw/GHSA-4f8q-56wq-r4gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f8q-56wq-r4gw", - "modified": "2024-10-30T00:31:04Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-30T00:31:04Z", "aliases": [ "CVE-2024-48573" ], "details": "A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the \"Reset password\" feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T22:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4mgj-f599-w3j8/GHSA-4mgj-f599-w3j8.json b/advisories/unreviewed/2024/10/GHSA-4mgj-f599-w3j8/GHSA-4mgj-f599-w3j8.json index 10d0d7ba01b..4149ee37177 100644 --- a/advisories/unreviewed/2024/10/GHSA-4mgj-f599-w3j8/GHSA-4mgj-f599-w3j8.json +++ b/advisories/unreviewed/2024/10/GHSA-4mgj-f599-w3j8/GHSA-4mgj-f599-w3j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mgj-f599-w3j8", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50080" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk: don't allow user copy for unprivileged device\n\nUBLK_F_USER_COPY requires userspace to call write() on ublk char\ndevice for filling request buffer, and unprivileged device can't\nbe trusted.\n\nSo don't allow user copy for unprivileged device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json b/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json index 0246f6101c9..e795bfdc6ac 100644 --- a/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json +++ b/advisories/unreviewed/2024/10/GHSA-5744-494c-924x/GHSA-5744-494c-924x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5744-494c-924x", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44213" ], "details": "An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An attacker in a privileged network position may be able to leak sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-57cp-r273-mcmf/GHSA-57cp-r273-mcmf.json b/advisories/unreviewed/2024/10/GHSA-57cp-r273-mcmf/GHSA-57cp-r273-mcmf.json index 55f29b3c570..da3ef98ce8e 100644 --- a/advisories/unreviewed/2024/10/GHSA-57cp-r273-mcmf/GHSA-57cp-r273-mcmf.json +++ b/advisories/unreviewed/2024/10/GHSA-57cp-r273-mcmf/GHSA-57cp-r273-mcmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57cp-r273-mcmf", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44251" ], "details": "This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-58q9-jhx4-mj9p/GHSA-58q9-jhx4-mj9p.json b/advisories/unreviewed/2024/10/GHSA-58q9-jhx4-mj9p/GHSA-58q9-jhx4-mj9p.json index ad2da431d1c..d93754a015c 100644 --- a/advisories/unreviewed/2024/10/GHSA-58q9-jhx4-mj9p/GHSA-58q9-jhx4-mj9p.json +++ b/advisories/unreviewed/2024/10/GHSA-58q9-jhx4-mj9p/GHSA-58q9-jhx4-mj9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58q9-jhx4-mj9p", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50082" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race\n\nWe're seeing crashes from rq_qos_wake_function that look like this:\n\n BUG: unable to handle page fault for address: ffffafe180a40084\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x0002) - not-present page\n PGD 100000067 P4D 100000067 PUD 10027c067 PMD 10115d067 PTE 0\n Oops: Oops: 0002 [#1] PREEMPT SMP PTI\n CPU: 17 UID: 0 PID: 0 Comm: swapper/17 Not tainted 6.12.0-rc3-00013-geca631b8fe80 #11\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n RIP: 0010:_raw_spin_lock_irqsave+0x1d/0x40\n Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 9c 41 5c fa 65 ff 05 62 97 30 4c 31 c0 ba 01 00 00 00 0f b1 17 75 0a 4c 89 e0 41 5c c3 cc cc cc cc 89 c6 e8 2c 0b 00\n RSP: 0018:ffffafe180580ca0 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: ffffafe180a3f7a8 RCX: 0000000000000011\n RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffffafe180a40084\n RBP: 0000000000000000 R08: 00000000001e7240 R09: 0000000000000011\n R10: 0000000000000028 R11: 0000000000000888 R12: 0000000000000002\n R13: ffffafe180a40084 R14: 0000000000000000 R15: 0000000000000003\n FS: 0000000000000000(0000) GS:ffff9aaf1f280000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: ffffafe180a40084 CR3: 000000010e428002 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n try_to_wake_up+0x5a/0x6a0\n rq_qos_wake_function+0x71/0x80\n __wake_up_common+0x75/0xa0\n __wake_up+0x36/0x60\n scale_up.part.0+0x50/0x110\n wb_timer_fn+0x227/0x450\n ...\n\nSo rq_qos_wake_function() calls wake_up_process(data->task), which calls\ntry_to_wake_up(), which faults in raw_spin_lock_irqsave(&p->pi_lock).\n\np comes from data->task, and data comes from the waitqueue entry, which\nis stored on the waiter's stack in rq_qos_wait(). Analyzing the core\ndump with drgn, I found that the waiter had already woken up and moved\non to a completely unrelated code path, clobbering what was previously\ndata->task. Meanwhile, the waker was passing the clobbered garbage in\ndata->task to wake_up_process(), leading to the crash.\n\nWhat's happening is that in between rq_qos_wake_function() deleting the\nwaitqueue entry and calling wake_up_process(), rq_qos_wait() is finding\nthat it already got a token and returning. The race looks like this:\n\nrq_qos_wait() rq_qos_wake_function()\n==============================================================\nprepare_to_wait_exclusive()\n data->got_token = true;\n list_del_init(&curr->entry);\nif (data.got_token)\n break;\nfinish_wait(&rqw->wait, &data.wq);\n ^- returns immediately because\n list_empty_careful(&wq_entry->entry)\n is true\n... return, go do something else ...\n wake_up_process(data->task)\n (NO LONGER VALID!)-^\n\nNormally, finish_wait() is supposed to synchronize against the waker.\nBut, as noted above, it is returning immediately because the waitqueue\nentry has already been removed from the waitqueue.\n\nThe bug is that rq_qos_wake_function() is accessing the waitqueue entry\nAFTER deleting it. Note that autoremove_wake_function() wakes the waiter\nand THEN deletes the waitqueue entry, which is the proper order.\n\nFix it by swapping the order. We also need to use\nlist_del_init_careful() to match the list_empty_careful() in\nfinish_wait().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5fx2-6ffx-qmvv/GHSA-5fx2-6ffx-qmvv.json b/advisories/unreviewed/2024/10/GHSA-5fx2-6ffx-qmvv/GHSA-5fx2-6ffx-qmvv.json index dd5f9af06ed..3513ef9c789 100644 --- a/advisories/unreviewed/2024/10/GHSA-5fx2-6ffx-qmvv/GHSA-5fx2-6ffx-qmvv.json +++ b/advisories/unreviewed/2024/10/GHSA-5fx2-6ffx-qmvv/GHSA-5fx2-6ffx-qmvv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5fx2-6ffx-qmvv", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44255" ], "details": "A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious app may be able to run arbitrary shortcuts without user consent.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5qq3-3hpq-crq9/GHSA-5qq3-3hpq-crq9.json b/advisories/unreviewed/2024/10/GHSA-5qq3-3hpq-crq9/GHSA-5qq3-3hpq-crq9.json index d777d922ef3..2660f3a3b09 100644 --- a/advisories/unreviewed/2024/10/GHSA-5qq3-3hpq-crq9/GHSA-5qq3-3hpq-crq9.json +++ b/advisories/unreviewed/2024/10/GHSA-5qq3-3hpq-crq9/GHSA-5qq3-3hpq-crq9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json b/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json index 107801154a3..8dc3abd77b8 100644 --- a/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json +++ b/advisories/unreviewed/2024/10/GHSA-64xw-25gj-x6w6/GHSA-64xw-25gj-x6w6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64xw-25gj-x6w6", - "modified": "2024-10-30T15:30:47Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-30T15:30:47Z", "aliases": [ "CVE-2024-51257" ], "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T14:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json b/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json new file mode 100644 index 00000000000..44f605bf568 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c6m-6wj2-c9h3", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-42041" + ], + "details": "The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42041" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.videodownload.browser.videodownloader/blob/main/CVE-2024-42041" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-78fm-rcjq-jr27/GHSA-78fm-rcjq-jr27.json b/advisories/unreviewed/2024/10/GHSA-78fm-rcjq-jr27/GHSA-78fm-rcjq-jr27.json new file mode 100644 index 00000000000..5cb90b4e7a7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-78fm-rcjq-jr27/GHSA-78fm-rcjq-jr27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78fm-rcjq-jr27", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-9419" + ], + "details": "Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Execution and/or Elevation of Privilege. A client using the HP Smart Universal Printing Driver that sends a print job comprised of a malicious XPS file could potentially lead to Remote Code Execution and/or Elevation of Privilege on the PC.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9419" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11505949-11505972-16" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7x3v-348q-cc5h/GHSA-7x3v-348q-cc5h.json b/advisories/unreviewed/2024/10/GHSA-7x3v-348q-cc5h/GHSA-7x3v-348q-cc5h.json index ad8fed4b308..63d22bd7385 100644 --- a/advisories/unreviewed/2024/10/GHSA-7x3v-348q-cc5h/GHSA-7x3v-348q-cc5h.json +++ b/advisories/unreviewed/2024/10/GHSA-7x3v-348q-cc5h/GHSA-7x3v-348q-cc5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7x3v-348q-cc5h", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50081" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: setup queue ->tag_set before initializing hctx\n\nCommit 7b815817aa58 (\"blk-mq: add helper for checking if one CPU is mapped to specified hctx\")\nneeds to check queue mapping via tag set in hctx's cpuhp handler.\n\nHowever, q->tag_set may not be setup yet when the cpuhp handler is\nenabled, then kernel oops is triggered.\n\nFix the issue by setup queue tag_set before initializing hctx.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-822w-7669-q3g6/GHSA-822w-7669-q3g6.json b/advisories/unreviewed/2024/10/GHSA-822w-7669-q3g6/GHSA-822w-7669-q3g6.json index 9b361bb7ab4..41fc40f8802 100644 --- a/advisories/unreviewed/2024/10/GHSA-822w-7669-q3g6/GHSA-822w-7669-q3g6.json +++ b/advisories/unreviewed/2024/10/GHSA-822w-7669-q3g6/GHSA-822w-7669-q3g6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-822w-7669-q3g6", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50068" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/tests/sysfs-kunit.h: fix memory leak in damon_sysfs_test_add_targets()\n\nThe sysfs_target->regions allocated in damon_sysfs_regions_alloc() is not\nfreed in damon_sysfs_test_add_targets(), which cause the following memory\nleak, free it to fix it.\n\n\tunreferenced object 0xffffff80c2a8db80 (size 96):\n\t comm \"kunit_try_catch\", pid 187, jiffies 4294894363\n\t hex dump (first 32 bytes):\n\t 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n\t 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n\t backtrace (crc 0):\n\t [<0000000001e3714d>] kmemleak_alloc+0x34/0x40\n\t [<000000008e6835c1>] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [<000000001286d9f8>] damon_sysfs_test_add_targets+0x1cc/0x738\n\t [<0000000032ef8f77>] kunit_try_run_case+0x13c/0x3ac\n\t [<00000000f3edea23>] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [<00000000adf936cf>] kthread+0x2e8/0x374\n\t [<0000000041bb1628>] ret_from_fork+0x10/0x20", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8545-3w77-w6gm/GHSA-8545-3w77-w6gm.json b/advisories/unreviewed/2024/10/GHSA-8545-3w77-w6gm/GHSA-8545-3w77-w6gm.json index b2a739cd2f4..8f077ad5071 100644 --- a/advisories/unreviewed/2024/10/GHSA-8545-3w77-w6gm/GHSA-8545-3w77-w6gm.json +++ b/advisories/unreviewed/2024/10/GHSA-8545-3w77-w6gm/GHSA-8545-3w77-w6gm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8545-3w77-w6gm", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44215" ], "details": "This issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. Processing an image may result in disclosure of process memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8798-5c83-39gj/GHSA-8798-5c83-39gj.json b/advisories/unreviewed/2024/10/GHSA-8798-5c83-39gj/GHSA-8798-5c83-39gj.json index d4f0d6de51f..23c036e7590 100644 --- a/advisories/unreviewed/2024/10/GHSA-8798-5c83-39gj/GHSA-8798-5c83-39gj.json +++ b/advisories/unreviewed/2024/10/GHSA-8798-5c83-39gj/GHSA-8798-5c83-39gj.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json b/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json index e806b70a892..901730b5be0 100644 --- a/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json +++ b/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8hp8-42cx-5q42/GHSA-8hp8-42cx-5q42.json b/advisories/unreviewed/2024/10/GHSA-8hp8-42cx-5q42/GHSA-8hp8-42cx-5q42.json index 3002f5dee55..ca45e408e7b 100644 --- a/advisories/unreviewed/2024/10/GHSA-8hp8-42cx-5q42/GHSA-8hp8-42cx-5q42.json +++ b/advisories/unreviewed/2024/10/GHSA-8hp8-42cx-5q42/GHSA-8hp8-42cx-5q42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hp8-42cx-5q42", - "modified": "2024-10-30T00:31:04Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-30T00:31:04Z", "aliases": [ "CVE-2024-48138" ], "details": "A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8pmx-rxgv-j8j9/GHSA-8pmx-rxgv-j8j9.json b/advisories/unreviewed/2024/10/GHSA-8pmx-rxgv-j8j9/GHSA-8pmx-rxgv-j8j9.json index 1011a7b0cfd..cac8f2c9a6f 100644 --- a/advisories/unreviewed/2024/10/GHSA-8pmx-rxgv-j8j9/GHSA-8pmx-rxgv-j8j9.json +++ b/advisories/unreviewed/2024/10/GHSA-8pmx-rxgv-j8j9/GHSA-8pmx-rxgv-j8j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pmx-rxgv-j8j9", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-30T18:30:46Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2024-8036" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:I/V:D/RE:H/U:Amber" } ], "affected": [ diff --git a/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json b/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json new file mode 100644 index 00000000000..727bfa760f8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8xq2-3cqg-9xfj/GHSA-8xq2-3cqg-9xfj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xq2-3cqg-9xfj", + "modified": "2024-10-30T18:30:48Z", + "published": "2024-10-30T18:30:48Z", + "aliases": [ + "CVE-2024-51258" + ], + "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51258" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-93c2-6235-vfvp/GHSA-93c2-6235-vfvp.json b/advisories/unreviewed/2024/10/GHSA-93c2-6235-vfvp/GHSA-93c2-6235-vfvp.json index 4caf64c2e72..fca98f4a8df 100644 --- a/advisories/unreviewed/2024/10/GHSA-93c2-6235-vfvp/GHSA-93c2-6235-vfvp.json +++ b/advisories/unreviewed/2024/10/GHSA-93c2-6235-vfvp/GHSA-93c2-6235-vfvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93c2-6235-vfvp", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44280" ], "details": "A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-94jr-5hwp-8492/GHSA-94jr-5hwp-8492.json b/advisories/unreviewed/2024/10/GHSA-94jr-5hwp-8492/GHSA-94jr-5hwp-8492.json index 233703bf54b..42222976dc5 100644 --- a/advisories/unreviewed/2024/10/GHSA-94jr-5hwp-8492/GHSA-94jr-5hwp-8492.json +++ b/advisories/unreviewed/2024/10/GHSA-94jr-5hwp-8492/GHSA-94jr-5hwp-8492.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-95v3-2xxf-g2hg/GHSA-95v3-2xxf-g2hg.json b/advisories/unreviewed/2024/10/GHSA-95v3-2xxf-g2hg/GHSA-95v3-2xxf-g2hg.json new file mode 100644 index 00000000000..25783e0b068 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-95v3-2xxf-g2hg/GHSA-95v3-2xxf-g2hg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95v3-2xxf-g2hg", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-48646" + ], + "details": "An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48646" + }, + { + "type": "WEB", + "url": "https://github.com/hx381/Sage-1000-v7.0.0-Exploit/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9f2m-2wcx-2f6m/GHSA-9f2m-2wcx-2f6m.json b/advisories/unreviewed/2024/10/GHSA-9f2m-2wcx-2f6m/GHSA-9f2m-2wcx-2f6m.json new file mode 100644 index 00000000000..867b4fd1c69 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9f2m-2wcx-2f6m/GHSA-9f2m-2wcx-2f6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f2m-2wcx-2f6m", + "modified": "2024-10-30T18:30:48Z", + "published": "2024-10-30T18:30:48Z", + "aliases": [ + "CVE-2024-9110" + ], + "details": "A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9110" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/trust-center/security-advisories/bt24-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9v5x-r4g7-gqw3/GHSA-9v5x-r4g7-gqw3.json b/advisories/unreviewed/2024/10/GHSA-9v5x-r4g7-gqw3/GHSA-9v5x-r4g7-gqw3.json index 3876f58daed..b92f4d26c32 100644 --- a/advisories/unreviewed/2024/10/GHSA-9v5x-r4g7-gqw3/GHSA-9v5x-r4g7-gqw3.json +++ b/advisories/unreviewed/2024/10/GHSA-9v5x-r4g7-gqw3/GHSA-9v5x-r4g7-gqw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v5x-r4g7-gqw3", - "modified": "2024-10-29T21:30:52Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T21:30:52Z", "aliases": [ "CVE-2024-48063" ], "details": "In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json b/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json index 4aeda399e2f..3aa0925ce8d 100644 --- a/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json +++ b/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json b/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json index ec8796c7e37..e0d0c8271fc 100644 --- a/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json +++ b/advisories/unreviewed/2024/10/GHSA-c83g-cgfm-hc33/GHSA-c83g-cgfm-hc33.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-c8r4-qw78-4r3m/GHSA-c8r4-qw78-4r3m.json b/advisories/unreviewed/2024/10/GHSA-c8r4-qw78-4r3m/GHSA-c8r4-qw78-4r3m.json index 0ee5c416925..b4bd0e7cce4 100644 --- a/advisories/unreviewed/2024/10/GHSA-c8r4-qw78-4r3m/GHSA-c8r4-qw78-4r3m.json +++ b/advisories/unreviewed/2024/10/GHSA-c8r4-qw78-4r3m/GHSA-c8r4-qw78-4r3m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8r4-qw78-4r3m", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T18:30:46Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-48357" ], "details": "LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json b/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json new file mode 100644 index 00000000000..2f43476b6e1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvm9-cv4j-fhwp", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-48648" + ], + "details": "A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48648" + }, + { + "type": "WEB", + "url": "https://github.com/hx381/Sage-1000-v7.0.0-Exploit/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json b/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json index 7a44ad952a6..90ce8572f3c 100644 --- a/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json +++ b/advisories/unreviewed/2024/10/GHSA-cwg2-qmg3-3f6x/GHSA-cwg2-qmg3-3f6x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwg2-qmg3-3f6x", - "modified": "2024-10-29T18:30:37Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T18:30:36Z", "aliases": [ "CVE-2019-25219" ], "details": "Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1188" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T17:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json b/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json index 6cd2c0da2be..ae9b16aaf50 100644 --- a/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json +++ b/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh9m-mpjc-38hg", - "modified": "2024-10-30T15:30:47Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-30T15:30:47Z", "aliases": [ "CVE-2024-51298" ], "details": "In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T14:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json b/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json new file mode 100644 index 00000000000..4da1ac146a7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g56g-9mxr-9pgw", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-31973" + ], + "details": "Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31973" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-31973" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json b/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json index cdc3f23f13e..34dec2ffb3e 100644 --- a/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json +++ b/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6j9-66rq-g4jr", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50070" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: stm32: check devm_kasprintf() returned value\n\ndevm_kasprintf() can return a NULL pointer on failure but this returned\nvalue is not checked. Fix this lack and check the returned value.\n\nFound by code review.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-grqq-hcc7-crmr/GHSA-grqq-hcc7-crmr.json b/advisories/unreviewed/2024/10/GHSA-grqq-hcc7-crmr/GHSA-grqq-hcc7-crmr.json index c8b1dbb33c6..27665ae1411 100644 --- a/advisories/unreviewed/2024/10/GHSA-grqq-hcc7-crmr/GHSA-grqq-hcc7-crmr.json +++ b/advisories/unreviewed/2024/10/GHSA-grqq-hcc7-crmr/GHSA-grqq-hcc7-crmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grqq-hcc7-crmr", - "modified": "2024-10-22T18:32:12Z", + "modified": "2024-10-30T18:30:46Z", "published": "2024-10-22T18:32:12Z", "aliases": [ "CVE-2024-9287" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/pull/124712" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/e52095a0c1005a87eed2276af7a1f2f66e2b6483" + }, { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL" diff --git a/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json b/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json new file mode 100644 index 00000000000..72559f4f9c1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxrv-64jf-fgmr", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-31972" + ], + "details": "EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulnerable fields this way are executed immediately when a user logs into the admin page. This affects /admin/wifi/wlan1 and /admin/wifi/wlan_guest.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31972" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-31972" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json b/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json new file mode 100644 index 00000000000..bc033351a50 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg9m-4m4c-v7c8", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-48214" + ], + "details": "KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48214" + }, + { + "type": "WEB", + "url": "https://medium.com/%40shenhavmor/exploiting-a-chinese-camera-for-fun-cve-2024-48214-2d56848870c2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jpwg-q62q-pwpw/GHSA-jpwg-q62q-pwpw.json b/advisories/unreviewed/2024/10/GHSA-jpwg-q62q-pwpw/GHSA-jpwg-q62q-pwpw.json index 85bcbbbce4f..ff90a56ff4c 100644 --- a/advisories/unreviewed/2024/10/GHSA-jpwg-q62q-pwpw/GHSA-jpwg-q62q-pwpw.json +++ b/advisories/unreviewed/2024/10/GHSA-jpwg-q62q-pwpw/GHSA-jpwg-q62q-pwpw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jpwg-q62q-pwpw", - "modified": "2024-10-30T00:31:04Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44244" ], "details": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1, visionOS 2.1, tvOS 18.1. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m2wj-x8qh-wqcv/GHSA-m2wj-x8qh-wqcv.json b/advisories/unreviewed/2024/10/GHSA-m2wj-x8qh-wqcv/GHSA-m2wj-x8qh-wqcv.json index 7ff4a4f0907..bbe397aa0c7 100644 --- a/advisories/unreviewed/2024/10/GHSA-m2wj-x8qh-wqcv/GHSA-m2wj-x8qh-wqcv.json +++ b/advisories/unreviewed/2024/10/GHSA-m2wj-x8qh-wqcv/GHSA-m2wj-x8qh-wqcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2wj-x8qh-wqcv", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50071" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func()\n\n'new_map' is allocated using devm_* which takes care of freeing the\nallocated data on device removal, call to\n\n\t.dt_free_map = pinconf_generic_dt_free_map\n\ndouble frees the map as pinconf_generic_dt_free_map() calls\npinctrl_utils_free_map().\n\nFix this by using kcalloc() instead of auto-managed devm_kcalloc().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json b/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json index c0c9750897e..c91479d2286 100644 --- a/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json +++ b/advisories/unreviewed/2024/10/GHSA-m499-vjfj-6h36/GHSA-m499-vjfj-6h36.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-m4vf-r3xm-3qhj/GHSA-m4vf-r3xm-3qhj.json b/advisories/unreviewed/2024/10/GHSA-m4vf-r3xm-3qhj/GHSA-m4vf-r3xm-3qhj.json index d72769c0500..74c7eac2e6e 100644 --- a/advisories/unreviewed/2024/10/GHSA-m4vf-r3xm-3qhj/GHSA-m4vf-r3xm-3qhj.json +++ b/advisories/unreviewed/2024/10/GHSA-m4vf-r3xm-3qhj/GHSA-m4vf-r3xm-3qhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m4vf-r3xm-3qhj", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50069" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: apple: check devm_kasprintf() returned value\n\ndevm_kasprintf() can return a NULL pointer on failure but this returned\nvalue is not checked. Fix this lack and check the returned value.\n\nFound by code review.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json b/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json index fa358cd5c53..a46bb971d3c 100644 --- a/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json +++ b/advisories/unreviewed/2024/10/GHSA-mcg7-2pf9-m48g/GHSA-mcg7-2pf9-m48g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcg7-2pf9-m48g", - "modified": "2024-10-29T18:30:37Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T18:30:37Z", "aliases": [ "CVE-2024-48955" ], "details": "In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another device, granting unauthorized access. This type of attack is commonly referred to as session hijacking.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-384" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mrqw-j759-rwwq/GHSA-mrqw-j759-rwwq.json b/advisories/unreviewed/2024/10/GHSA-mrqw-j759-rwwq/GHSA-mrqw-j759-rwwq.json index ebc5aab4d2c..f44ac8bc7bb 100644 --- a/advisories/unreviewed/2024/10/GHSA-mrqw-j759-rwwq/GHSA-mrqw-j759-rwwq.json +++ b/advisories/unreviewed/2024/10/GHSA-mrqw-j759-rwwq/GHSA-mrqw-j759-rwwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrqw-j759-rwwq", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50079" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work\n\nWhen the sqpoll is exiting and cancels pending work items, it may need\nto run task_work. If this happens from within io_uring_cancel_generic(),\nthen it may be under waiting for the io_uring_task waitqueue. This\nresults in the below splat from the scheduler, as the ring mutex may be\nattempted grabbed while in a TASK_INTERRUPTIBLE state.\n\nEnsure that the task state is set appropriately for that, just like what\nis done for the other cases in io_run_task_work().\n\ndo not call blocking ops when !TASK_RUNNING; state=1 set at [<0000000029387fd2>] prepare_to_wait+0x88/0x2fc\nWARNING: CPU: 6 PID: 59939 at kernel/sched/core.c:8561 __might_sleep+0xf4/0x140\nModules linked in:\nCPU: 6 UID: 0 PID: 59939 Comm: iou-sqp-59938 Not tainted 6.12.0-rc3-00113-g8d020023b155 #7456\nHardware name: linux,dummy-virt (DT)\npstate: 61400005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\npc : __might_sleep+0xf4/0x140\nlr : __might_sleep+0xf4/0x140\nsp : ffff80008c5e7830\nx29: ffff80008c5e7830 x28: ffff0000d93088c0 x27: ffff60001c2d7230\nx26: dfff800000000000 x25: ffff0000e16b9180 x24: ffff80008c5e7a50\nx23: 1ffff000118bcf4a x22: ffff0000e16b9180 x21: ffff0000e16b9180\nx20: 000000000000011b x19: ffff80008310fac0 x18: 1ffff000118bcd90\nx17: 30303c5b20746120 x16: 74657320313d6574 x15: 0720072007200720\nx14: 0720072007200720 x13: 0720072007200720 x12: ffff600036c64f0b\nx11: 1fffe00036c64f0a x10: ffff600036c64f0a x9 : dfff800000000000\nx8 : 00009fffc939b0f6 x7 : ffff0001b6327853 x6 : 0000000000000001\nx5 : ffff0001b6327850 x4 : ffff600036c64f0b x3 : ffff8000803c35bc\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000e16b9180\nCall trace:\n __might_sleep+0xf4/0x140\n mutex_lock+0x84/0x124\n io_handle_tw_list+0xf4/0x260\n tctx_task_work_run+0x94/0x340\n io_run_task_work+0x1ec/0x3c0\n io_uring_cancel_generic+0x364/0x524\n io_sq_thread+0x820/0x124c\n ret_from_fork+0x10/0x20", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-p7rr-c68v-256j/GHSA-p7rr-c68v-256j.json b/advisories/unreviewed/2024/10/GHSA-p7rr-c68v-256j/GHSA-p7rr-c68v-256j.json index 71d7f0b6da7..d42750e3868 100644 --- a/advisories/unreviewed/2024/10/GHSA-p7rr-c68v-256j/GHSA-p7rr-c68v-256j.json +++ b/advisories/unreviewed/2024/10/GHSA-p7rr-c68v-256j/GHSA-p7rr-c68v-256j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p7rr-c68v-256j", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44175" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59", + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json b/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json new file mode 100644 index 00000000000..799f2df155b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8vr-968q-whxq", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-37573" + ], + "details": "The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.talkatone.vedroid.ui.launcher.OutgoingCallInterceptor component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37573" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.talkatone.android/blob/main/CVE-2024-37573" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p94g-pv57-gw9x/GHSA-p94g-pv57-gw9x.json b/advisories/unreviewed/2024/10/GHSA-p94g-pv57-gw9x/GHSA-p94g-pv57-gw9x.json index 980c5a94cc5..b2dbd633f6c 100644 --- a/advisories/unreviewed/2024/10/GHSA-p94g-pv57-gw9x/GHSA-p94g-pv57-gw9x.json +++ b/advisories/unreviewed/2024/10/GHSA-p94g-pv57-gw9x/GHSA-p94g-pv57-gw9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p94g-pv57-gw9x", - "modified": "2024-10-28T21:30:36Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-28T21:30:36Z", "aliases": [ "CVE-2024-48356" ], "details": "LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pjg9-qwh6-g7w9/GHSA-pjg9-qwh6-g7w9.json b/advisories/unreviewed/2024/10/GHSA-pjg9-qwh6-g7w9/GHSA-pjg9-qwh6-g7w9.json index 0618523eb9c..dbc7a1ae433 100644 --- a/advisories/unreviewed/2024/10/GHSA-pjg9-qwh6-g7w9/GHSA-pjg9-qwh6-g7w9.json +++ b/advisories/unreviewed/2024/10/GHSA-pjg9-qwh6-g7w9/GHSA-pjg9-qwh6-g7w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjg9-qwh6-g7w9", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44247" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pvm4-q7m8-9wqx/GHSA-pvm4-q7m8-9wqx.json b/advisories/unreviewed/2024/10/GHSA-pvm4-q7m8-9wqx/GHSA-pvm4-q7m8-9wqx.json index 15fda61cc26..a00dc74d523 100644 --- a/advisories/unreviewed/2024/10/GHSA-pvm4-q7m8-9wqx/GHSA-pvm4-q7m8-9wqx.json +++ b/advisories/unreviewed/2024/10/GHSA-pvm4-q7m8-9wqx/GHSA-pvm4-q7m8-9wqx.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-pxj5-97f9-grjr/GHSA-pxj5-97f9-grjr.json b/advisories/unreviewed/2024/10/GHSA-pxj5-97f9-grjr/GHSA-pxj5-97f9-grjr.json index 05293b8681d..72cb5d28170 100644 --- a/advisories/unreviewed/2024/10/GHSA-pxj5-97f9-grjr/GHSA-pxj5-97f9-grjr.json +++ b/advisories/unreviewed/2024/10/GHSA-pxj5-97f9-grjr/GHSA-pxj5-97f9-grjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxj5-97f9-grjr", - "modified": "2024-10-29T21:30:53Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-29T21:30:53Z", "aliases": [ "CVE-2024-48206" ], "details": "A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q2q9-q8mv-pv59/GHSA-q2q9-q8mv-pv59.json b/advisories/unreviewed/2024/10/GHSA-q2q9-q8mv-pv59/GHSA-q2q9-q8mv-pv59.json index b75bec8d3c5..b305ebf203c 100644 --- a/advisories/unreviewed/2024/10/GHSA-q2q9-q8mv-pv59/GHSA-q2q9-q8mv-pv59.json +++ b/advisories/unreviewed/2024/10/GHSA-q2q9-q8mv-pv59/GHSA-q2q9-q8mv-pv59.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2q9-q8mv-pv59", - "modified": "2024-10-28T21:30:36Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-28T21:30:36Z", "aliases": [ "CVE-2024-48107" ], "details": "SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qc9f-6x66-h8c3/GHSA-qc9f-6x66-h8c3.json b/advisories/unreviewed/2024/10/GHSA-qc9f-6x66-h8c3/GHSA-qc9f-6x66-h8c3.json index fbdf839ed75..d90d1d518a4 100644 --- a/advisories/unreviewed/2024/10/GHSA-qc9f-6x66-h8c3/GHSA-qc9f-6x66-h8c3.json +++ b/advisories/unreviewed/2024/10/GHSA-qc9f-6x66-h8c3/GHSA-qc9f-6x66-h8c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc9f-6x66-h8c3", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44279" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. Parsing a file may lead to disclosure of user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qvrv-r8xg-hh75/GHSA-qvrv-r8xg-hh75.json b/advisories/unreviewed/2024/10/GHSA-qvrv-r8xg-hh75/GHSA-qvrv-r8xg-hh75.json index 7ae6ea154a4..a2f8abe2dbd 100644 --- a/advisories/unreviewed/2024/10/GHSA-qvrv-r8xg-hh75/GHSA-qvrv-r8xg-hh75.json +++ b/advisories/unreviewed/2024/10/GHSA-qvrv-r8xg-hh75/GHSA-qvrv-r8xg-hh75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvrv-r8xg-hh75", - "modified": "2024-10-28T21:30:36Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:36Z", "aliases": [ "CVE-2024-44302" ], "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. Processing a maliciously crafted font may result in the disclosure of process memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r2q9-52vc-q982/GHSA-r2q9-52vc-q982.json b/advisories/unreviewed/2024/10/GHSA-r2q9-52vc-q982/GHSA-r2q9-52vc-q982.json new file mode 100644 index 00000000000..bf887e5bc64 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r2q9-52vc-q982/GHSA-r2q9-52vc-q982.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2q9-52vc-q982", + "modified": "2024-10-30T18:30:48Z", + "published": "2024-10-30T18:30:48Z", + "aliases": [ + "CVE-2024-10456" + ], + "details": "Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10456" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-303-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r5h8-q4jm-864x/GHSA-r5h8-q4jm-864x.json b/advisories/unreviewed/2024/10/GHSA-r5h8-q4jm-864x/GHSA-r5h8-q4jm-864x.json index 5dd36a22d0b..c1641670bef 100644 --- a/advisories/unreviewed/2024/10/GHSA-r5h8-q4jm-864x/GHSA-r5h8-q4jm-864x.json +++ b/advisories/unreviewed/2024/10/GHSA-r5h8-q4jm-864x/GHSA-r5h8-q4jm-864x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r5h8-q4jm-864x", - "modified": "2024-10-28T21:30:34Z", + "modified": "2024-10-30T18:30:46Z", "published": "2024-10-28T21:30:34Z", "aliases": [ "CVE-2024-27849" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to read sensitive location information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json b/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json index 3710e21d622..43731c02189 100644 --- a/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json +++ b/advisories/unreviewed/2024/10/GHSA-r922-52fr-4x9g/GHSA-r922-52fr-4x9g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-754" + "CWE-754", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json b/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json index eca2bcddf56..beb95582966 100644 --- a/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json +++ b/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-v39q-v2cw-g4fp/GHSA-v39q-v2cw-g4fp.json b/advisories/unreviewed/2024/10/GHSA-v39q-v2cw-g4fp/GHSA-v39q-v2cw-g4fp.json index b37685537fb..783d6d4fb5f 100644 --- a/advisories/unreviewed/2024/10/GHSA-v39q-v2cw-g4fp/GHSA-v39q-v2cw-g4fp.json +++ b/advisories/unreviewed/2024/10/GHSA-v39q-v2cw-g4fp/GHSA-v39q-v2cw-g4fp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v39q-v2cw-g4fp", - "modified": "2024-10-28T21:30:36Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-28T21:30:36Z", "aliases": [ "CVE-2024-48594" ], "details": "File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v4pp-cm3w-w8gh/GHSA-v4pp-cm3w-w8gh.json b/advisories/unreviewed/2024/10/GHSA-v4pp-cm3w-w8gh/GHSA-v4pp-cm3w-w8gh.json new file mode 100644 index 00000000000..a688af78450 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v4pp-cm3w-w8gh/GHSA-v4pp-cm3w-w8gh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4pp-cm3w-w8gh", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-48569" + ], + "details": "Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48569" + }, + { + "type": "WEB", + "url": "https://github.com/MarioTesoro/CVE-2024-48569" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vgwf-5fwc-xx64/GHSA-vgwf-5fwc-xx64.json b/advisories/unreviewed/2024/10/GHSA-vgwf-5fwc-xx64/GHSA-vgwf-5fwc-xx64.json index f8e1ab62904..99ee34d630e 100644 --- a/advisories/unreviewed/2024/10/GHSA-vgwf-5fwc-xx64/GHSA-vgwf-5fwc-xx64.json +++ b/advisories/unreviewed/2024/10/GHSA-vgwf-5fwc-xx64/GHSA-vgwf-5fwc-xx64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgwf-5fwc-xx64", - "modified": "2024-10-30T00:31:04Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-30T00:31:04Z", "aliases": [ "CVE-2024-44080" ], "details": "In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vhv3-639r-j6rp/GHSA-vhv3-639r-j6rp.json b/advisories/unreviewed/2024/10/GHSA-vhv3-639r-j6rp/GHSA-vhv3-639r-j6rp.json index b235a30641d..6749095f0f1 100644 --- a/advisories/unreviewed/2024/10/GHSA-vhv3-639r-j6rp/GHSA-vhv3-639r-j6rp.json +++ b/advisories/unreviewed/2024/10/GHSA-vhv3-639r-j6rp/GHSA-vhv3-639r-j6rp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhv3-639r-j6rp", - "modified": "2024-10-30T00:31:04Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44296" ], "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, watchOS 11.1, visionOS 2.1. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w688-vpw2-mqfg/GHSA-w688-vpw2-mqfg.json b/advisories/unreviewed/2024/10/GHSA-w688-vpw2-mqfg/GHSA-w688-vpw2-mqfg.json index ed2bb04ac43..d4cecbd2ace 100644 --- a/advisories/unreviewed/2024/10/GHSA-w688-vpw2-mqfg/GHSA-w688-vpw2-mqfg.json +++ b/advisories/unreviewed/2024/10/GHSA-w688-vpw2-mqfg/GHSA-w688-vpw2-mqfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w688-vpw2-mqfg", - "modified": "2024-10-28T21:30:36Z", + "modified": "2024-10-30T18:30:48Z", "published": "2024-10-28T21:30:36Z", "aliases": [ "CVE-2024-48177" ], "details": "MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wg5p-9v6g-ch4x/GHSA-wg5p-9v6g-ch4x.json b/advisories/unreviewed/2024/10/GHSA-wg5p-9v6g-ch4x/GHSA-wg5p-9v6g-ch4x.json index 3027225fb9d..98f92909b77 100644 --- a/advisories/unreviewed/2024/10/GHSA-wg5p-9v6g-ch4x/GHSA-wg5p-9v6g-ch4x.json +++ b/advisories/unreviewed/2024/10/GHSA-wg5p-9v6g-ch4x/GHSA-wg5p-9v6g-ch4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg5p-9v6g-ch4x", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44254" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 11.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, iOS 18.1 and iPadOS 18.1. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wpcr-qwq5-j6w2/GHSA-wpcr-qwq5-j6w2.json b/advisories/unreviewed/2024/10/GHSA-wpcr-qwq5-j6w2/GHSA-wpcr-qwq5-j6w2.json index e7fb0bbded5..defd1e1fc93 100644 --- a/advisories/unreviewed/2024/10/GHSA-wpcr-qwq5-j6w2/GHSA-wpcr-qwq5-j6w2.json +++ b/advisories/unreviewed/2024/10/GHSA-wpcr-qwq5-j6w2/GHSA-wpcr-qwq5-j6w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpcr-qwq5-j6w2", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44258" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wrjh-x85j-vvg8/GHSA-wrjh-x85j-vvg8.json b/advisories/unreviewed/2024/10/GHSA-wrjh-x85j-vvg8/GHSA-wrjh-x85j-vvg8.json new file mode 100644 index 00000000000..70072f27f5e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wrjh-x85j-vvg8/GHSA-wrjh-x85j-vvg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrjh-x85j-vvg8", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-48647" + ], + "details": "A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive information, including configuration files that may contain credentials and system settings, which could lead to further compromise of the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48647" + }, + { + "type": "WEB", + "url": "https://github.com/hx381/Sage-1000-v7.0.0-Exploit/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wvfr-r5jg-p8ff/GHSA-wvfr-r5jg-p8ff.json b/advisories/unreviewed/2024/10/GHSA-wvfr-r5jg-p8ff/GHSA-wvfr-r5jg-p8ff.json index 0f5af53c86a..cedae724be5 100644 --- a/advisories/unreviewed/2024/10/GHSA-wvfr-r5jg-p8ff/GHSA-wvfr-r5jg-p8ff.json +++ b/advisories/unreviewed/2024/10/GHSA-wvfr-r5jg-p8ff/GHSA-wvfr-r5jg-p8ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvfr-r5jg-p8ff", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44252" ], "details": "A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json b/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json new file mode 100644 index 00000000000..020bbd88cd3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvj9-mrxw-ww9p", + "modified": "2024-10-30T18:30:49Z", + "published": "2024-10-30T18:30:49Z", + "aliases": [ + "CVE-2024-36060" + ], + "details": "EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36060" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-36060" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-30T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json b/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json index 1001165bca7..e09014bf3ae 100644 --- a/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json +++ b/advisories/unreviewed/2024/10/GHSA-wx35-29xj-r29q/GHSA-wx35-29xj-r29q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx35-29xj-r29q", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44253" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xf88-x6f5-fvg8/GHSA-xf88-x6f5-fvg8.json b/advisories/unreviewed/2024/10/GHSA-xf88-x6f5-fvg8/GHSA-xf88-x6f5-fvg8.json index e6245d969ad..21eb8a156a0 100644 --- a/advisories/unreviewed/2024/10/GHSA-xf88-x6f5-fvg8/GHSA-xf88-x6f5-fvg8.json +++ b/advisories/unreviewed/2024/10/GHSA-xf88-x6f5-fvg8/GHSA-xf88-x6f5-fvg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf88-x6f5-fvg8", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44267" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious application may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xvhx-jwjw-g589/GHSA-xvhx-jwjw-g589.json b/advisories/unreviewed/2024/10/GHSA-xvhx-jwjw-g589/GHSA-xvhx-jwjw-g589.json index b2b37468fe5..e748009c77e 100644 --- a/advisories/unreviewed/2024/10/GHSA-xvhx-jwjw-g589/GHSA-xvhx-jwjw-g589.json +++ b/advisories/unreviewed/2024/10/GHSA-xvhx-jwjw-g589/GHSA-xvhx-jwjw-g589.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xvhx-jwjw-g589", - "modified": "2024-10-28T21:30:35Z", + "modified": "2024-10-30T18:30:47Z", "published": "2024-10-28T21:30:35Z", "aliases": [ "CVE-2024-44196" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T21:15:05Z"