diff --git a/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json b/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json new file mode 100644 index 00000000000..fbe665f4697 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-25rm-72cp-x5mm/GHSA-25rm-72cp-x5mm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25rm-72cp-x5mm", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33113" + ], + "details": "Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33113" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json b/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json new file mode 100644 index 00000000000..fd158212d4d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44qm-928x-6p3g", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-47039" + ], + "details": "A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe` within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to place`cmd.exe` in locations with weak permissions, such as `C:\\ProgramData`. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47039" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-47039" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056746" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249525" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json b/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json new file mode 100644 index 00000000000..558e3655d47 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q33-wj3r-p79q", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-43512" + ], + "details": "Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43512" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json b/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json new file mode 100644 index 00000000000..0e78b8c24bd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w3j-4m96-c92x", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-28583" + ], + "details": "Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28583" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5rxp-9658-h93v/GHSA-5rxp-9658-h93v.json b/advisories/unreviewed/2024/01/GHSA-5rxp-9658-h93v/GHSA-5rxp-9658-h93v.json new file mode 100644 index 00000000000..b34f3eb6b22 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5rxp-9658-h93v/GHSA-5rxp-9658-h93v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rxp-9658-h93v", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-26157" + ], + "details": "Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26157" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/issues/850" + }, + { + "type": "WEB", + "url": "https://github.com/LibreDWG/libredwg/commit/c8cf03ce4c2315b146caf582ea061c0460193bcc" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-UNMANAGED-LIBREDWG-6070730" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json b/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json new file mode 100644 index 00000000000..7fae7f5f9cf --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w5c-6hmq-mgpr", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-43511" + ], + "details": "Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43511" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-864j-6gwg-g82x/GHSA-864j-6gwg-g82x.json b/advisories/unreviewed/2024/01/GHSA-864j-6gwg-g82x/GHSA-864j-6gwg-g82x.json new file mode 100644 index 00000000000..a346a542e2a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-864j-6gwg-g82x/GHSA-864j-6gwg-g82x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-864j-6gwg-g82x", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33094" + ], + "details": "Memory corruption while running VK synchronization with KASAN enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33094" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8p2w-c42w-3mfv/GHSA-8p2w-c42w-3mfv.json b/advisories/unreviewed/2024/01/GHSA-8p2w-c42w-3mfv/GHSA-8p2w-c42w-3mfv.json new file mode 100644 index 00000000000..1aff16bce14 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8p2w-c42w-3mfv/GHSA-8p2w-c42w-3mfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p2w-c42w-3mfv", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33108" + ], + "details": "Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33108" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json b/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json new file mode 100644 index 00000000000..ae4502329ee --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9fw6-m2v2-f3rp/GHSA-9fw6-m2v2-f3rp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fw6-m2v2-f3rp", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33038" + ], + "details": "Memory corruption while receiving a message in Bus Socket Transport Server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33038" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9gv7-j9wm-9q6p/GHSA-9gv7-j9wm-9q6p.json b/advisories/unreviewed/2024/01/GHSA-9gv7-j9wm-9q6p/GHSA-9gv7-j9wm-9q6p.json new file mode 100644 index 00000000000..91715f7df76 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9gv7-j9wm-9q6p/GHSA-9gv7-j9wm-9q6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gv7-j9wm-9q6p", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33109" + ], + "details": "Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33109" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json b/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json new file mode 100644 index 00000000000..8667be67de2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c44g-2jv9-3436/GHSA-c44g-2jv9-3436.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c44g-2jv9-3436", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33112" + ], + "details": "Transient DOS when WLAN firmware receives \"reassoc response\" frame including RIC_DATA element.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33112" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json b/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json new file mode 100644 index 00000000000..da356c26e71 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c543-q7r3-jw94", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33014" + ], + "details": "Information disclosure in Core services while processing a Diag command.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33014" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c8p2-9jx9-h338/GHSA-c8p2-9jx9-h338.json b/advisories/unreviewed/2024/01/GHSA-c8p2-9jx9-h338/GHSA-c8p2-9jx9-h338.json new file mode 100644 index 00000000000..fdf6d9bf7ba --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c8p2-9jx9-h338/GHSA-c8p2-9jx9-h338.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8p2-9jx9-h338", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33114" + ], + "details": "Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33114" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json b/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json new file mode 100644 index 00000000000..f68b3558390 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv8x-5cww-p4pf", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33116" + ], + "details": "Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33116" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cvq4-g535-rh5v/GHSA-cvq4-g535-rh5v.json b/advisories/unreviewed/2024/01/GHSA-cvq4-g535-rh5v/GHSA-cvq4-g535-rh5v.json new file mode 100644 index 00000000000..0e4eb9b317f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cvq4-g535-rh5v/GHSA-cvq4-g535-rh5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvq4-g535-rh5v", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33085" + ], + "details": "Memory corruption in wearables while processing data from AON.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33085" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json b/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json new file mode 100644 index 00000000000..8bb8de3b20f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cxcm-vgv2-mq4g/GHSA-cxcm-vgv2-mq4g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxcm-vgv2-mq4g", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33062" + ], + "details": "Transient DOS in WLAN Firmware while parsing a BTM request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33062" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fffh-vg75-287f/GHSA-fffh-vg75-287f.json b/advisories/unreviewed/2024/01/GHSA-fffh-vg75-287f/GHSA-fffh-vg75-287f.json new file mode 100644 index 00000000000..9c4f6f5d79b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fffh-vg75-287f/GHSA-fffh-vg75-287f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fffh-vg75-287f", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33037" + ], + "details": "Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33037" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json b/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json new file mode 100644 index 00000000000..a0d853d665e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf8x-c888-36h7", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33117" + ], + "details": "Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33117" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gxgx-xpgc-8hmf/GHSA-gxgx-xpgc-8hmf.json b/advisories/unreviewed/2024/01/GHSA-gxgx-xpgc-8hmf/GHSA-gxgx-xpgc-8hmf.json new file mode 100644 index 00000000000..757d4087c04 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gxgx-xpgc-8hmf/GHSA-gxgx-xpgc-8hmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxgx-xpgc-8hmf", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33025" + ], + "details": "Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33025" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jchw-25xp-jwwc/GHSA-jchw-25xp-jwwc.json b/advisories/unreviewed/2024/01/GHSA-jchw-25xp-jwwc/GHSA-jchw-25xp-jwwc.json new file mode 100644 index 00000000000..55665fe1446 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jchw-25xp-jwwc/GHSA-jchw-25xp-jwwc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jchw-25xp-jwwc", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-26159" + ], + "details": "Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26159" + }, + { + "type": "WEB", + "url": "https://github.com/follow-redirects/follow-redirects/issues/235" + }, + { + "type": "WEB", + "url": "https://github.com/follow-redirects/follow-redirects/pull/236" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mcqw-jc72-xrwr/GHSA-mcqw-jc72-xrwr.json b/advisories/unreviewed/2024/01/GHSA-mcqw-jc72-xrwr/GHSA-mcqw-jc72-xrwr.json new file mode 100644 index 00000000000..ab392956dca --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mcqw-jc72-xrwr/GHSA-mcqw-jc72-xrwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcqw-jc72-xrwr", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33120" + ], + "details": "Memory corruption in Audio when memory map command is executed consecutively in ADSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33120" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json b/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json new file mode 100644 index 00000000000..7accf2a6ab3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9h6-c2ff-prcp", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33032" + ], + "details": "Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33032" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json b/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json new file mode 100644 index 00000000000..b6195fa8c2f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwm2-x6hp-6h68", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33118" + ], + "details": "Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33118" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json b/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json new file mode 100644 index 00000000000..b8a4ff14bc9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rh7v-fmqc-c7rj/GHSA-rh7v-fmqc-c7rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh7v-fmqc-c7rj", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33030" + ], + "details": "Memory corruption in HLOS while running playready use-case.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33030" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json b/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json new file mode 100644 index 00000000000..322c3e92b87 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmpv-5qmj-3fgc", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-43514" + ], + "details": "Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43514" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v3cw-88qx-cf5c/GHSA-v3cw-88qx-cf5c.json b/advisories/unreviewed/2024/01/GHSA-v3cw-88qx-cf5c/GHSA-v3cw-88qx-cf5c.json new file mode 100644 index 00000000000..1979f87d605 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v3cw-88qx-cf5c/GHSA-v3cw-88qx-cf5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3cw-88qx-cf5c", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33036" + ], + "details": "Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33036" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json b/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json new file mode 100644 index 00000000000..aa716ac35bb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vgh7-9mhq-v768/GHSA-vgh7-9mhq-v768.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgh7-9mhq-v768", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33040" + ], + "details": "Transient DOS in Data Modem during DTLS handshake.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33040" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json b/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json new file mode 100644 index 00000000000..a4b888a092f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vw9c-c8qf-hw7g/GHSA-vw9c-c8qf-hw7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw9c-c8qf-hw7g", + "modified": "2024-01-02T06:30:31Z", + "published": "2024-01-02T06:30:31Z", + "aliases": [ + "CVE-2023-33110" + ], + "details": "The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33110" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json b/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json new file mode 100644 index 00000000000..77a2a92133e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxqg-47fv-wf96", + "modified": "2024-01-02T06:30:30Z", + "published": "2024-01-02T06:30:30Z", + "aliases": [ + "CVE-2023-33033" + ], + "details": "Memory corruption in Audio during playback with speaker protection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33033" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/january-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T06:15:09Z" + } +} \ No newline at end of file