Publish Advisories

GHSA-3f54-fhj6-g7ff
GHSA-3g68-hg24-4xxq
GHSA-3q9p-f48q-wjcp
GHSA-5qcf-4cgw-f76m
GHSA-g6j7-vgxw-qg28
GHSA-mx27-jhrp-2gfm
GHSA-w978-mmpv-hphg
This commit is contained in:
advisory-database[bot]
2024-02-28 01:13:29 +00:00
parent f614c53ed8
commit b4a8102e16
7 changed files with 49 additions and 28 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f54-fhj6-g7ff",
"modified": "2022-04-21T01:57:47Z",
"modified": "2024-02-28T01:10:55Z",
"published": "2022-04-21T01:57:47Z",
"aliases": [
"CVE-2010-3665"
],
"details": "TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-04T22:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g68-hg24-4xxq",
"modified": "2022-04-21T01:57:46Z",
"modified": "2024-02-28T01:10:53Z",
"published": "2022-04-21T01:57:46Z",
"aliases": [
"CVE-2010-2783"
],
"details": "IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-10-31T21:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q9p-f48q-wjcp",
"modified": "2022-04-21T01:57:51Z",
"modified": "2024-02-28T01:12:11Z",
"published": "2022-04-21T01:57:51Z",
"aliases": [
"CVE-2010-4177"
],
"details": "mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-319"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-12T23:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qcf-4cgw-f76m",
"modified": "2022-04-21T01:57:48Z",
"modified": "2024-02-28T01:12:04Z",
"published": "2022-04-21T01:57:48Z",
"aliases": [
"CVE-2010-2446"
],
"details": "Rbot Reaction plugin allows command execution",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-06T17:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g6j7-vgxw-qg28",
"modified": "2022-04-21T01:57:52Z",
"modified": "2024-02-28T01:12:53Z",
"published": "2022-04-21T01:57:52Z",
"aliases": [
"CVE-2010-4817"
],
"details": "pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-13T22:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx27-jhrp-2gfm",
"modified": "2022-04-21T01:57:51Z",
"modified": "2024-02-28T01:12:20Z",
"published": "2022-04-21T01:57:51Z",
"aliases": [
"CVE-2010-4657"
],
"details": "PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-772"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-13T21:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w978-mmpv-hphg",
"modified": "2022-04-21T01:57:46Z",
"modified": "2024-02-28T01:10:51Z",
"published": "2022-04-21T01:57:46Z",
"aliases": [
"CVE-2010-2548"
],
"details": "IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-10-31T21:15:00Z"