From b5671dd936e6b1b69b4ec169bae047415f576a20 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Oct 2024 18:32:44 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7823-23gq-8g79.json | 2 +- .../GHSA-hwhw-f642-jhqq.json | 2 +- .../GHSA-jm25-87xp-4h76.json | 2 +- .../GHSA-4g5h-7prv-mvj5.json | 2 +- .../GHSA-pm38-4f58-28pj.json | 2 +- .../GHSA-3rw3-pfv7-m7r7.json | 11 ++-- .../GHSA-4f4g-mjgj-wqjc.json | 3 +- .../GHSA-4mm4-rvx3-h58h.json | 11 ++-- .../GHSA-65xf-588v-56fv.json | 11 ++-- .../GHSA-76f2-qj4m-vmqr.json | 11 ++-- .../GHSA-97x9-7h6v-3jx9.json | 10 +++- .../GHSA-cv8x-m68j-4834.json | 11 ++-- .../GHSA-gfhp-57f6-m54h.json | 11 ++-- .../GHSA-gfx6-fv9x-fgpc.json | 11 ++-- .../GHSA-pwxr-xm9v-qfvh.json | 9 ++- .../GHSA-rp89-9jxh-73fw.json | 11 ++-- .../GHSA-vx7x-qwmp-h33c.json | 9 ++- .../GHSA-x8x2-w2mg-gx8m.json | 11 ++-- .../GHSA-xgc6-jf52-wphf.json | 9 ++- .../GHSA-3qpq-hc75-5535.json | 51 ++++++++++++++++ .../GHSA-482v-6rp2-p55w.json | 35 +++++++++++ .../GHSA-667m-43f5-gwwr.json | 51 ++++++++++++++++ .../GHSA-734x-qgf3-3vh7.json | 6 +- .../GHSA-94mm-6r76-6pgh.json | 43 ++++++++++++++ .../GHSA-99rj-hj9g-wrcv.json | 51 ++++++++++++++++ .../GHSA-fc27-6qvc-xq94.json | 55 +++++++++++++++++ .../GHSA-g76c-5vhc-hqmg.json | 51 ++++++++++++++++ .../GHSA-hc6r-wpfc-q7m8.json | 59 +++++++++++++++++++ .../GHSA-p5hw-4fxj-g4x6.json | 39 ++++++++++++ .../GHSA-qph8-rvxf-5936.json | 55 +++++++++++++++++ .../GHSA-r28p-rpv4-w54r.json | 51 ++++++++++++++++ .../GHSA-rggh-rm3v-8xqj.json | 55 +++++++++++++++++ .../GHSA-v2j8-2q45-8jcq.json | 39 ++++++++++++ .../GHSA-vpgc-chc4-fq2j.json | 51 ++++++++++++++++ .../GHSA-wh5g-cw5m-22mw.json | 11 ++-- .../GHSA-www5-6jrx-9mwq.json | 11 ++-- .../GHSA-xxc2-5537-pj53.json | 35 +++++++++++ 37 files changed, 837 insertions(+), 61 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json create mode 100644 advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p5hw-4fxj-g4x6/GHSA-p5hw-4fxj-g4x6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v2j8-2q45-8jcq/GHSA-v2j8-2q45-8jcq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vpgc-chc4-fq2j/GHSA-vpgc-chc4-fq2j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json diff --git a/advisories/unreviewed/2023/05/GHSA-7823-23gq-8g79/GHSA-7823-23gq-8g79.json b/advisories/unreviewed/2023/05/GHSA-7823-23gq-8g79/GHSA-7823-23gq-8g79.json index fdf7ac89a55..db42b4cc1ec 100644 --- a/advisories/unreviewed/2023/05/GHSA-7823-23gq-8g79/GHSA-7823-23gq-8g79.json +++ b/advisories/unreviewed/2023/05/GHSA-7823-23gq-8g79/GHSA-7823-23gq-8g79.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-hwhw-f642-jhqq/GHSA-hwhw-f642-jhqq.json b/advisories/unreviewed/2023/07/GHSA-hwhw-f642-jhqq/GHSA-hwhw-f642-jhqq.json index 57533341a8c..fc9b017e8f0 100644 --- a/advisories/unreviewed/2023/07/GHSA-hwhw-f642-jhqq/GHSA-hwhw-f642-jhqq.json +++ b/advisories/unreviewed/2023/07/GHSA-hwhw-f642-jhqq/GHSA-hwhw-f642-jhqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwhw-f642-jhqq", - "modified": "2023-07-31T18:30:19Z", + "modified": "2024-10-01T18:31:15Z", "published": "2023-07-19T00:31:16Z", "aliases": [ "CVE-2023-22506" diff --git a/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json b/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json index 7f655855b27..babdebe02db 100644 --- a/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json +++ b/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm25-87xp-4h76", - "modified": "2024-04-04T05:32:22Z", + "modified": "2024-10-01T18:31:15Z", "published": "2023-07-06T19:24:08Z", "aliases": [ "CVE-2023-22501" diff --git a/advisories/unreviewed/2023/09/GHSA-4g5h-7prv-mvj5/GHSA-4g5h-7prv-mvj5.json b/advisories/unreviewed/2023/09/GHSA-4g5h-7prv-mvj5/GHSA-4g5h-7prv-mvj5.json index 6f7d077a389..bf056aab5b0 100644 --- a/advisories/unreviewed/2023/09/GHSA-4g5h-7prv-mvj5/GHSA-4g5h-7prv-mvj5.json +++ b/advisories/unreviewed/2023/09/GHSA-4g5h-7prv-mvj5/GHSA-4g5h-7prv-mvj5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-pm38-4f58-28pj/GHSA-pm38-4f58-28pj.json b/advisories/unreviewed/2023/09/GHSA-pm38-4f58-28pj/GHSA-pm38-4f58-28pj.json index c819afcec8e..07c534b534c 100644 --- a/advisories/unreviewed/2023/09/GHSA-pm38-4f58-28pj/GHSA-pm38-4f58-28pj.json +++ b/advisories/unreviewed/2023/09/GHSA-pm38-4f58-28pj/GHSA-pm38-4f58-28pj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-3rw3-pfv7-m7r7/GHSA-3rw3-pfv7-m7r7.json b/advisories/unreviewed/2024/09/GHSA-3rw3-pfv7-m7r7/GHSA-3rw3-pfv7-m7r7.json index f748052cf11..50e8ebfaae0 100644 --- a/advisories/unreviewed/2024/09/GHSA-3rw3-pfv7-m7r7/GHSA-3rw3-pfv7-m7r7.json +++ b/advisories/unreviewed/2024/09/GHSA-3rw3-pfv7-m7r7/GHSA-3rw3-pfv7-m7r7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rw3-pfv7-m7r7", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46857" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix bridge mode operations when there are no VFs\n\nCurrently, trying to set the bridge mode attribute when numvfs=0 leads to a\ncrash:\n\nbridge link set dev eth2 hwmode vepa\n\n[ 168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030\n[...]\n[ 168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core]\n[...]\n[ 168.976037] Call Trace:\n[ 168.976188] \n[ 168.978620] _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core]\n[ 168.979074] mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core]\n[ 168.979471] rtnl_bridge_setlink+0xe9/0x1f0\n[ 168.979714] rtnetlink_rcv_msg+0x159/0x400\n[ 168.980451] netlink_rcv_skb+0x54/0x100\n[ 168.980675] netlink_unicast+0x241/0x360\n[ 168.980918] netlink_sendmsg+0x1f6/0x430\n[ 168.981162] ____sys_sendmsg+0x3bb/0x3f0\n[ 168.982155] ___sys_sendmsg+0x88/0xd0\n[ 168.985036] __sys_sendmsg+0x59/0xa0\n[ 168.985477] do_syscall_64+0x79/0x150\n[ 168.987273] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 168.987773] RIP: 0033:0x7f8f7950f917\n\n(esw->fdb_table.legacy.vepa_fdb is null)\n\nThe bridge mode is only relevant when there are multiple functions per\nport. Therefore, prevent setting and getting this setting when there are no\nVFs.\n\nNote that after this change, there are no settings to change on the PF\ninterface using `bridge link` when there are no VFs, so the interface no\nlonger appears in the `bridge link` output.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json b/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json index fd78be32d85..004ced2e9d0 100644 --- a/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json +++ b/advisories/unreviewed/2024/09/GHSA-4f4g-mjgj-wqjc/GHSA-4f4g-mjgj-wqjc.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json b/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json index c62e276289d..5d6fe2d0240 100644 --- a/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json +++ b/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mm4-rvx3-h58h", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46858" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: Fix uaf in __timer_delete_sync\n\nThere are two paths to access mptcp_pm_del_add_timer, result in a race\ncondition:\n\n CPU1\t\t\t\tCPU2\n ==== ====\n net_rx_action\n napi_poll netlink_sendmsg\n __napi_poll netlink_unicast\n process_backlog netlink_unicast_kernel\n __netif_receive_skb genl_rcv\n __netif_receive_skb_one_core netlink_rcv_skb\n NF_HOOK genl_rcv_msg\n ip_local_deliver_finish genl_family_rcv_msg\n ip_protocol_deliver_rcu genl_family_rcv_msg_doit\n tcp_v4_rcv mptcp_pm_nl_flush_addrs_doit\n tcp_v4_do_rcv mptcp_nl_remove_addrs_list\n tcp_rcv_established mptcp_pm_remove_addrs_and_subflows\n tcp_data_queue remove_anno_list_by_saddr\n mptcp_incoming_options mptcp_pm_del_add_timer\n mptcp_pm_del_add_timer kfree(entry)\n\nIn remove_anno_list_by_saddr(running on CPU2), after leaving the critical\nzone protected by \"pm.lock\", the entry will be released, which leads to the\noccurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1).\n\nKeeping a reference to add_timer inside the lock, and calling\nsk_stop_timer_sync() with this reference, instead of \"entry->add_timer\".\n\nMove list_del(&entry->list) to mptcp_pm_del_add_timer and inside the pm lock,\ndo not directly access any members of the entry outside the pm lock, which\ncan avoid similar \"entry->x\" uaf.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json b/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json index 8c81ed195e5..02462ef1467 100644 --- a/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json +++ b/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65xf-588v-56fv", - "modified": "2024-09-30T21:31:07Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-30T21:31:07Z", "aliases": [ "CVE-2024-46503" ], "details": "An issue in the _readFileSync function of Simple-Spellchecker v1.0.2 allows attackers to read arbitrary files via a directory traversal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T21:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-76f2-qj4m-vmqr/GHSA-76f2-qj4m-vmqr.json b/advisories/unreviewed/2024/09/GHSA-76f2-qj4m-vmqr/GHSA-76f2-qj4m-vmqr.json index 36b757df234..e5eccc81da8 100644 --- a/advisories/unreviewed/2024/09/GHSA-76f2-qj4m-vmqr/GHSA-76f2-qj4m-vmqr.json +++ b/advisories/unreviewed/2024/09/GHSA-76f2-qj4m-vmqr/GHSA-76f2-qj4m-vmqr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76f2-qj4m-vmqr", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46868" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire()\n\nIf the __qcuefi pointer is not set, then in the original code, we would\nhold onto the lock. That means that if we tried to set it later, then\nit would cause a deadlock. Drop the lock on the error path. That's\nwhat all the callers are expecting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:18Z" diff --git a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json index c85cc3f080c..63ec7f18f26 100644 --- a/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json +++ b/advisories/unreviewed/2024/09/GHSA-97x9-7h6v-3jx9/GHSA-97x9-7h6v-3jx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97x9-7h6v-3jx9", - "modified": "2024-10-01T15:32:03Z", + "modified": "2024-10-01T18:31:16Z", "published": "2024-09-17T21:30:32Z", "aliases": [ "CVE-2024-8900" @@ -28,6 +28,14 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-33" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-cv8x-m68j-4834/GHSA-cv8x-m68j-4834.json b/advisories/unreviewed/2024/09/GHSA-cv8x-m68j-4834/GHSA-cv8x-m68j-4834.json index 20d301eed54..3f90d7d1397 100644 --- a/advisories/unreviewed/2024/09/GHSA-cv8x-m68j-4834/GHSA-cv8x-m68j-4834.json +++ b/advisories/unreviewed/2024/09/GHSA-cv8x-m68j-4834/GHSA-cv8x-m68j-4834.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv8x-m68j-4834", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46856" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: dp83822: Fix NULL pointer dereference on DP83825 devices\n\nThe probe() function is only used for DP83822 and DP83826 PHY,\nleaving the private data pointer uninitialized for the DP83825 models\nwhich causes a NULL pointer dereference in the recently introduced/changed\nfunctions dp8382x_config_init() and dp83822_set_wol().\n\nAdd the dp8382x_probe() function, so all PHY models will have a valid\nprivate data pointer to fix this issue and also prevent similar issues\nin the future.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gfhp-57f6-m54h/GHSA-gfhp-57f6-m54h.json b/advisories/unreviewed/2024/09/GHSA-gfhp-57f6-m54h/GHSA-gfhp-57f6-m54h.json index f45bfe6df2e..a40b29cdfe8 100644 --- a/advisories/unreviewed/2024/09/GHSA-gfhp-57f6-m54h/GHSA-gfhp-57f6-m54h.json +++ b/advisories/unreviewed/2024/09/GHSA-gfhp-57f6-m54h/GHSA-gfhp-57f6-m54h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gfhp-57f6-m54h", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46866" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: add missing bo locking in show_meminfo()\n\nbo_meminfo() wants to inspect bo state like tt and the ttm resource,\nhowever this state can change at any point leading to stuff like NPD and\nUAF, if the bo lock is not held. Grab the bo lock when calling\nbo_meminfo(), ensuring we drop any spinlocks first. In the case of\nobject_idr we now also need to hold a ref.\n\nv2 (MattB)\n - Also add xe_bo_assert_held()\n\n(cherry picked from commit 4f63d712fa104c3ebefcb289d1e733e86d8698c7)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json b/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json index ab5b3cb0ea6..b9b9a14c0fa 100644 --- a/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json +++ b/advisories/unreviewed/2024/09/GHSA-gfx6-fv9x-fgpc/GHSA-gfx6-fv9x-fgpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gfx6-fv9x-fgpc", - "modified": "2024-09-18T15:30:52Z", + "modified": "2024-10-01T18:31:16Z", "published": "2024-09-18T15:30:52Z", "aliases": [ "CVE-2024-39081" ], "details": "An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-294" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T14:15:19Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json b/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json index 4df044b89ab..11f87e9e657 100644 --- a/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json +++ b/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwxr-xm9v-qfvh", - "modified": "2024-09-30T06:33:37Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-30T06:33:37Z", "aliases": [ "CVE-2024-8536" ], "details": "The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T06:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rp89-9jxh-73fw/GHSA-rp89-9jxh-73fw.json b/advisories/unreviewed/2024/09/GHSA-rp89-9jxh-73fw/GHSA-rp89-9jxh-73fw.json index bbb75817c87..26ec84afa91 100644 --- a/advisories/unreviewed/2024/09/GHSA-rp89-9jxh-73fw/GHSA-rp89-9jxh-73fw.json +++ b/advisories/unreviewed/2024/09/GHSA-rp89-9jxh-73fw/GHSA-rp89-9jxh-73fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rp89-9jxh-73fw", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46867" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/client: fix deadlock in show_meminfo()\n\nThere is a real deadlock as well as sleeping in atomic() bug in here, if\nthe bo put happens to be the last ref, since bo destruction wants to\ngrab the same spinlock and sleeping locks. Fix that by dropping the ref\nusing xe_bo_put_deferred(), and moving the final commit outside of the\nlock. Dropping the lock around the put is tricky since the bo can go\nout of scope and delete itself from the list, making it difficult to\nnavigate to the next list entry.\n\n(cherry picked from commit 0083b8e6f11d7662283a267d4ce7c966812ffd8a)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json b/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json index 6915aed275b..993c9209324 100644 --- a/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json +++ b/advisories/unreviewed/2024/09/GHSA-vx7x-qwmp-h33c/GHSA-vx7x-qwmp-h33c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vx7x-qwmp-h33c", - "modified": "2024-09-25T15:31:12Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-25T15:31:12Z", "aliases": [ "CVE-2024-6512" ], "details": "Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T14:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json b/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json index 1978fac36c2..9935d1773c3 100644 --- a/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json +++ b/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8x2-w2mg-gx8m", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46865" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: fix initialization of grc\n\nThe grc must be initialize first. There can be a condition where if\nfou is NULL, goto out will be executed and grc would be used\nuninitialized.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json b/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json index 43300758def..9e4d841c0a0 100644 --- a/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json +++ b/advisories/unreviewed/2024/09/GHSA-xgc6-jf52-wphf/GHSA-xgc6-jf52-wphf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xgc6-jf52-wphf", - "modified": "2024-09-30T06:33:37Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-09-30T06:33:37Z", "aliases": [ "CVE-2024-8379" ], "details": "The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-30T06:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json b/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json new file mode 100644 index 00000000000..6710db1ec54 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3qpq-hc75-5535/GHSA-3qpq-hc75-5535.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qpq-hc75-5535", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9398" + ], + "details": "By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9398" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1881037" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json b/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json new file mode 100644 index 00000000000..b2b1b85d836 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-482v-6rp2-p55w/GHSA-482v-6rp2-p55w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-482v-6rp2-p55w", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-25660" + ], + "details": "The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25660" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25660" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json b/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json new file mode 100644 index 00000000000..d166bc3941e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-667m-43f5-gwwr/GHSA-667m-43f5-gwwr.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-667m-43f5-gwwr", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9396" + ], + "details": "It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9396" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1912471" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-734x-qgf3-3vh7/GHSA-734x-qgf3-3vh7.json b/advisories/unreviewed/2024/10/GHSA-734x-qgf3-3vh7/GHSA-734x-qgf3-3vh7.json index d97b29f9230..1fd9ec4d9df 100644 --- a/advisories/unreviewed/2024/10/GHSA-734x-qgf3-3vh7/GHSA-734x-qgf3-3vh7.json +++ b/advisories/unreviewed/2024/10/GHSA-734x-qgf3-3vh7/GHSA-734x-qgf3-3vh7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-734x-qgf3-3vh7", - "modified": "2024-10-01T00:33:41Z", + "modified": "2024-10-01T18:31:17Z", "published": "2024-10-01T00:33:41Z", "aliases": [ "CVE-2024-9194" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before 2024.2.9482, from 2024.3.0 before 2024.3.12766.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json b/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json new file mode 100644 index 00000000000..5520f7709e3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94mm-6r76-6pgh", + "modified": "2024-10-01T18:31:19Z", + "published": "2024-10-01T18:31:19Z", + "aliases": [ + "CVE-2024-9403" + ], + "details": "Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9403" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1917807" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json b/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json new file mode 100644 index 00000000000..8bc21c27fda --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-99rj-hj9g-wrcv/GHSA-99rj-hj9g-wrcv.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rj-hj9g-wrcv", + "modified": "2024-10-01T18:31:19Z", + "published": "2024-10-01T18:31:19Z", + "aliases": [ + "CVE-2024-9400" + ], + "details": "A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9400" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1915249" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json b/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json new file mode 100644 index 00000000000..ce37d86410a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fc27-6qvc-xq94/GHSA-fc27-6qvc-xq94.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc27-6qvc-xq94", + "modified": "2024-10-01T18:31:19Z", + "published": "2024-10-01T18:31:19Z", + "aliases": [ + "CVE-2024-9401" + ], + "details": "Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9401" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1872744%2C1897792%2C1911317%2C1916476" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-48" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json b/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json new file mode 100644 index 00000000000..dbd555db4aa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g76c-5vhc-hqmg", + "modified": "2024-10-01T18:31:19Z", + "published": "2024-10-01T18:31:19Z", + "aliases": [ + "CVE-2024-9399" + ], + "details": "A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9399" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1907726" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json b/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json new file mode 100644 index 00000000000..6b43e2a9ad7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hc6r-wpfc-q7m8/GHSA-hc6r-wpfc-q7m8.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc6r-wpfc-q7m8", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9392" + ], + "details": "A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9392" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1899154" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1905843" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-48" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p5hw-4fxj-g4x6/GHSA-p5hw-4fxj-g4x6.json b/advisories/unreviewed/2024/10/GHSA-p5hw-4fxj-g4x6/GHSA-p5hw-4fxj-g4x6.json new file mode 100644 index 00000000000..4647cb19b67 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p5hw-4fxj-g4x6/GHSA-p5hw-4fxj-g4x6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5hw-4fxj-g4x6", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9391" + ], + "details": "A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible.\n*This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9391" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1892407" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json b/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json new file mode 100644 index 00000000000..28386262abc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qph8-rvxf-5936/GHSA-qph8-rvxf-5936.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qph8-rvxf-5936", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9394" + ], + "details": "An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to \"same site\" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9394" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1918874" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-48" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json b/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json new file mode 100644 index 00000000000..45ff3d47dc8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r28p-rpv4-w54r/GHSA-r28p-rpv4-w54r.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r28p-rpv4-w54r", + "modified": "2024-10-01T18:31:19Z", + "published": "2024-10-01T18:31:19Z", + "aliases": [ + "CVE-2024-9402" + ], + "details": "Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9402" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1872744%2C1897792%2C1911317%2C1913445%2C1914106%2C1914475%2C1914963%2C1915008%2C1916476" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json b/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json new file mode 100644 index 00000000000..f20785facdf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rggh-rm3v-8xqj/GHSA-rggh-rm3v-8xqj.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rggh-rm3v-8xqj", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9393" + ], + "details": "An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to \"same site\" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9393" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1918301" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-48" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v2j8-2q45-8jcq/GHSA-v2j8-2q45-8jcq.json b/advisories/unreviewed/2024/10/GHSA-v2j8-2q45-8jcq/GHSA-v2j8-2q45-8jcq.json new file mode 100644 index 00000000000..d04c1f668b3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v2j8-2q45-8jcq/GHSA-v2j8-2q45-8jcq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2j8-2q45-8jcq", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9395" + ], + "details": "A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog.\n*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9395" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1906024" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vpgc-chc4-fq2j/GHSA-vpgc-chc4-fq2j.json b/advisories/unreviewed/2024/10/GHSA-vpgc-chc4-fq2j/GHSA-vpgc-chc4-fq2j.json new file mode 100644 index 00000000000..4c4ce5d2bd6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vpgc-chc4-fq2j/GHSA-vpgc-chc4-fq2j.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpgc-chc4-fq2j", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-9397" + ], + "details": "A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9397" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1916659" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-46" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-47" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-49" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json b/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json index be8ae2ae24a..79f62dd0fe9 100644 --- a/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json +++ b/advisories/unreviewed/2024/10/GHSA-wh5g-cw5m-22mw/GHSA-wh5g-cw5m-22mw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wh5g-cw5m-22mw", - "modified": "2024-10-01T15:32:08Z", + "modified": "2024-10-01T18:31:18Z", "published": "2024-10-01T15:32:08Z", "aliases": [ "CVE-2024-25661" ], "details": "In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T15:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json b/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json index ec039fde6e6..28024be41bd 100644 --- a/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json +++ b/advisories/unreviewed/2024/10/GHSA-www5-6jrx-9mwq/GHSA-www5-6jrx-9mwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-www5-6jrx-9mwq", - "modified": "2024-10-01T15:32:05Z", + "modified": "2024-10-01T18:31:18Z", "published": "2024-10-01T15:32:05Z", "aliases": [ "CVE-2024-41276" ], "details": "A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T14:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json b/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json new file mode 100644 index 00000000000..d2ce0b41c84 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xxc2-5537-pj53/GHSA-xxc2-5537-pj53.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxc2-5537-pj53", + "modified": "2024-10-01T18:31:18Z", + "published": "2024-10-01T18:31:18Z", + "aliases": [ + "CVE-2024-25659" + ], + "details": "In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25659" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25659" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-01T16:15:09Z" + } +} \ No newline at end of file