diff --git a/advisories/unreviewed/2022/05/GHSA-6c6v-jhrm-ff4w/GHSA-6c6v-jhrm-ff4w.json b/advisories/unreviewed/2022/05/GHSA-6c6v-jhrm-ff4w/GHSA-6c6v-jhrm-ff4w.json index bde9856492b..f158bbe9f07 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c6v-jhrm-ff4w/GHSA-6c6v-jhrm-ff4w.json +++ b/advisories/unreviewed/2022/05/GHSA-6c6v-jhrm-ff4w/GHSA-6c6v-jhrm-ff4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6c6v-jhrm-ff4w", - "modified": "2022-05-17T04:56:00Z", + "modified": "2024-03-28T15:30:32Z", "published": "2022-05-17T04:56:00Z", "aliases": [ "CVE-2013-4558" @@ -18,6 +18,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-4558" }, + { + "type": "WEB", + "url": "https://github.com/apache/subversion/commit/2c77c43e4255555f3b79f761f0d141393a3856cc" + }, + { + "type": "WEB", + "url": "https://github.com/apache/subversion/commit/647e3f8365a74831bb915f63793b63e31fae062d" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1033431" diff --git a/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json b/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json index 2ad530a26aa..e79c6b0daf7 100644 --- a/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json +++ b/advisories/unreviewed/2023/12/GHSA-96fh-9q43-rmjh/GHSA-96fh-9q43-rmjh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-96fh-9q43-rmjh", - "modified": "2023-12-30T00:30:23Z", + "modified": "2024-03-28T15:30:32Z", "published": "2023-12-30T00:30:23Z", "aliases": [ "CVE-2023-47038" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNEEWAACXQCEEAKSG7XX2D5YDRWLCIZJ" + }, + { + "type": "WEB", + "url": "https://perldoc.perl.org/perl5382delta#CVE-2023-47038-Write-past-buffer-end-via-illegal-user-defined-Unicode-property" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json b/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json index 2b7fed586ce..75b4d0160f1 100644 --- a/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json +++ b/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-44qm-928x-6p3g", - "modified": "2024-02-08T12:30:48Z", + "modified": "2024-03-28T15:30:32Z", "published": "2024-01-02T06:30:31Z", "aliases": [ "CVE-2023-47039" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249525" }, + { + "type": "WEB", + "url": "https://perldoc.perl.org/perl5382delta#CVE-2023-47039-Perl-for-Windows-binary-hijacking-vulnerability" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240208-0005" diff --git a/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json b/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json new file mode 100644 index 00000000000..cd622334201 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2fjx-8hxj-4456/GHSA-2fjx-8hxj-4456.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fjx-8hxj-4456", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31136" + ], + "details": "In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31136" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json b/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json new file mode 100644 index 00000000000..1da09226958 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33r2-8g93-5hm2", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2023-45715" + ], + "details": "The console may experience a service interruption when processing file names with invalid characters.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45715" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0111972" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json b/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json new file mode 100644 index 00000000000..6a52df3fc32 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-38mw-3mfv-34fc/GHSA-38mw-3mfv-34fc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38mw-3mfv-34fc", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2023-45706" + ], + "details": "An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45706" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0111972" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json b/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json new file mode 100644 index 00000000000..0a5730aa99e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3rwc-8hqh-2vxh/GHSA-3rwc-8hqh-2vxh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rwc-8hqh-2vxh", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30587" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30587" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/saveParentControlInfo_urls.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json new file mode 100644 index 00000000000..aacd8b1d9be --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3h-fcc9-p4px", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2023-45705" + ], + "details": "An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45705" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0111972" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json b/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json new file mode 100644 index 00000000000..8363ba4b20f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-45mc-5wq7-gwvh/GHSA-45mc-5wq7-gwvh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45mc-5wq7-gwvh", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30600" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30600" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/setSchedWifi_end.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json b/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json new file mode 100644 index 00000000000..fd7090b5da5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q5q-v9v4-9c33", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-0259" + ], + "details": "Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0259" + }, + { + "type": "WEB", + "url": "https://hstechdocs.helpsystems.com/releasenotes/Content/_ProductPages/Robot/RobotScheduleEnterprise.htm" + }, + { + "type": "WEB", + "url": "https://www.fortra.com/security/advisory/fi-2024-005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json b/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json new file mode 100644 index 00000000000..6ce3d294da0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5gww-24v3-qcfw/GHSA-5gww-24v3-qcfw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gww-24v3-qcfw", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31134" + ], + "details": "In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31134" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json b/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json new file mode 100644 index 00000000000..ec263733f81 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-669w-wwp7-2p8m/GHSA-669w-wwp7-2p8m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-669w-wwp7-2p8m", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30606" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30606" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/fromDhcpListClient_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6hfg-gc6j-4f52/GHSA-6hfg-gc6j-4f52.json b/advisories/unreviewed/2024/03/GHSA-6hfg-gc6j-4f52/GHSA-6hfg-gc6j-4f52.json new file mode 100644 index 00000000000..c30f68e3a31 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6hfg-gc6j-4f52/GHSA-6hfg-gc6j-4f52.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hfg-gc6j-4f52", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30590" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30590" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/setSchedWifi_end.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json b/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json new file mode 100644 index 00000000000..bda25099e2d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rfv-m2fm-w83c", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-30612" + ], + "details": "Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30612" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC10U/v1.V15.03.06.48/more/formSetClientState.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7rm2-x86r-ghpx/GHSA-7rm2-x86r-ghpx.json b/advisories/unreviewed/2024/03/GHSA-7rm2-x86r-ghpx/GHSA-7rm2-x86r-ghpx.json new file mode 100644 index 00000000000..e6fc10e89f8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7rm2-x86r-ghpx/GHSA-7rm2-x86r-ghpx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rm2-x86r-ghpx", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30584" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30584" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/formWifiBasicSet_security.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json b/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json new file mode 100644 index 00000000000..d20fad939f9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w53-4qwf-wfw9", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30588" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30588" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/setSchedWifi_start.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-83hv-pm62-wx33/GHSA-83hv-pm62-wx33.json b/advisories/unreviewed/2024/03/GHSA-83hv-pm62-wx33/GHSA-83hv-pm62-wx33.json new file mode 100644 index 00000000000..bc3aff0ff44 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-83hv-pm62-wx33/GHSA-83hv-pm62-wx33.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83hv-pm62-wx33", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30599" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30599" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/addWifiMacFilter_deviceMac.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json b/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json new file mode 100644 index 00000000000..304f2a50b5d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8h97-3wj9-m4mh/GHSA-8h97-3wj9-m4mh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h97-3wj9-m4mh", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31137" + ], + "details": "In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31137" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8hpx-7pm4-9fx9/GHSA-8hpx-7pm4-9fx9.json b/advisories/unreviewed/2024/03/GHSA-8hpx-7pm4-9fx9/GHSA-8hpx-7pm4-9fx9.json new file mode 100644 index 00000000000..847fb1a705f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8hpx-7pm4-9fx9/GHSA-8hpx-7pm4-9fx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hpx-7pm4-9fx9", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-27775" + ], + "details": "\nSysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27775" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8qf9-7xmg-5frx/GHSA-8qf9-7xmg-5frx.json b/advisories/unreviewed/2024/03/GHSA-8qf9-7xmg-5frx/GHSA-8qf9-7xmg-5frx.json new file mode 100644 index 00000000000..088672861eb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8qf9-7xmg-5frx/GHSA-8qf9-7xmg-5frx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qf9-7xmg-5frx", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30598" + ], + "details": "Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30598" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/formWifiBasicSet_security_5g.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9crc-c2p4-5rqm/GHSA-9crc-c2p4-5rqm.json b/advisories/unreviewed/2024/03/GHSA-9crc-c2p4-5rqm/GHSA-9crc-c2p4-5rqm.json new file mode 100644 index 00000000000..85a5dd7d80e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9crc-c2p4-5rqm/GHSA-9crc-c2p4-5rqm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9crc-c2p4-5rqm", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30602" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30602" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/setSchedWifi_start.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9q6m-mw2x-4prg/GHSA-9q6m-mw2x-4prg.json b/advisories/unreviewed/2024/03/GHSA-9q6m-mw2x-4prg/GHSA-9q6m-mw2x-4prg.json new file mode 100644 index 00000000000..ba5043358c7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9q6m-mw2x-4prg/GHSA-9q6m-mw2x-4prg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q6m-mw2x-4prg", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30603" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30603" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/saveParentControlInfo_urls.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9qj2-fmrm-53wv/GHSA-9qj2-fmrm-53wv.json b/advisories/unreviewed/2024/03/GHSA-9qj2-fmrm-53wv/GHSA-9qj2-fmrm-53wv.json new file mode 100644 index 00000000000..60290f1705a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9qj2-fmrm-53wv/GHSA-9qj2-fmrm-53wv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qj2-fmrm-53wv", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30596" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30596" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/formSetDeviceName_deviceId.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c4j7-fj85-r93w/GHSA-c4j7-fj85-r93w.json b/advisories/unreviewed/2024/03/GHSA-c4j7-fj85-r93w/GHSA-c4j7-fj85-r93w.json new file mode 100644 index 00000000000..bd93b5773a8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c4j7-fj85-r93w/GHSA-c4j7-fj85-r93w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4j7-fj85-r93w", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30592" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30592" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/fromAddressNat_page.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f8fg-9v3c-g666/GHSA-f8fg-9v3c-g666.json b/advisories/unreviewed/2024/03/GHSA-f8fg-9v3c-g666/GHSA-f8fg-9v3c-g666.json new file mode 100644 index 00000000000..7e8f79a5a80 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f8fg-9v3c-g666/GHSA-f8fg-9v3c-g666.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8fg-9v3c-g666", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30583" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30583" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/fromAddressNat_mitInterface.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json b/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json new file mode 100644 index 00000000000..cefd05652c0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fm4v-hxhr-prfx/GHSA-fm4v-hxhr-prfx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm4v-hxhr-prfx", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-3041" + ], + "details": "A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258430 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3041" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-listloginfo.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258430" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258430" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.302342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fv5c-qfh5-jjpg/GHSA-fv5c-qfh5-jjpg.json b/advisories/unreviewed/2024/03/GHSA-fv5c-qfh5-jjpg/GHSA-fv5c-qfh5-jjpg.json new file mode 100644 index 00000000000..bd6dff24cca --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fv5c-qfh5-jjpg/GHSA-fv5c-qfh5-jjpg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv5c-qfh5-jjpg", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30591" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30591" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/saveParentControlInfo_time.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json b/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json new file mode 100644 index 00000000000..42d17845ce8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g8xv-jmgw-wfcj/GHSA-g8xv-jmgw-wfcj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8xv-jmgw-wfcj", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30589" + ], + "details": "Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30589" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/fromAddressNat_entrys.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json b/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json new file mode 100644 index 00000000000..a767a61d4c3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hh25-cvgx-xhwx/GHSA-hh25-cvgx-xhwx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh25-cvgx-xhwx", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-3042" + ], + "details": "A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258431.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3042" + }, + { + "type": "WEB", + "url": "https://github.com/maxmvp666/planCve/blob/main/Simple%20Subscription%20Website%20with%20Admin%20System%20manage_user.php%20has%20Sqlinjection.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258431" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258431" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.306119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json b/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json new file mode 100644 index 00000000000..84ad96d59b5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jgcq-59jx-w43v/GHSA-jgcq-59jx-w43v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgcq-59jx-w43v", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31140" + ], + "details": "In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31140" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mv26-57j8-pqhr/GHSA-mv26-57j8-pqhr.json b/advisories/unreviewed/2024/03/GHSA-mv26-57j8-pqhr/GHSA-mv26-57j8-pqhr.json new file mode 100644 index 00000000000..0558ae70e62 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mv26-57j8-pqhr/GHSA-mv26-57j8-pqhr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv26-57j8-pqhr", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30597" + ], + "details": "Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30597" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/formWifiBasicSet_security.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json b/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json new file mode 100644 index 00000000000..c9cb49898e1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5w7-h2h4-299j", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30594" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30594" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/addWifiMacFilter_deviceMac.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json b/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json new file mode 100644 index 00000000000..514f5f0aea3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p65p-h8xw-f45x/GHSA-p65p-h8xw-f45x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p65p-h8xw-f45x", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31139" + ], + "details": "In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31139" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p958-gp8v-57pc/GHSA-p958-gp8v-57pc.json b/advisories/unreviewed/2024/03/GHSA-p958-gp8v-57pc/GHSA-p958-gp8v-57pc.json new file mode 100644 index 00000000000..878bfd1eb5f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p958-gp8v-57pc/GHSA-p958-gp8v-57pc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p958-gp8v-57pc", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30585" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30585" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/saveParentControlInfo_deviceId.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json b/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json new file mode 100644 index 00000000000..0089328dfa9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pp7c-r283-qv76/GHSA-pp7c-r283-qv76.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp7c-r283-qv76", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-3039" + ], + "details": "A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the component API. The manipulation with the input updatexml(1,concat(0x3f,md5(123456),0x3f),1)=1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3039" + }, + { + "type": "WEB", + "url": "https://spoofer.cn/bladex_sqli" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258426" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258426" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.301469" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json b/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json new file mode 100644 index 00000000000..41f5f5a4391 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q3f6-347p-3qc9/GHSA-q3f6-347p-3qc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3f6-347p-3qc9", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2023-6437" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Turk Telekom TP-Link allows OS Command Injection.This issue affects TP-Link: through 2024.03.28.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6437" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q54h-5hxr-8v5q/GHSA-q54h-5hxr-8v5q.json b/advisories/unreviewed/2024/03/GHSA-q54h-5hxr-8v5q/GHSA-q54h-5hxr-8v5q.json new file mode 100644 index 00000000000..f1b0a978943 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q54h-5hxr-8v5q/GHSA-q54h-5hxr-8v5q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q54h-5hxr-8v5q", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30607" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30607" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/saveParentControlInfo_deviceId.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json b/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json new file mode 100644 index 00000000000..9e3f8303a9f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw5g-qccp-wchw", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30586" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30586" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/formWifiBasicSet_security_5g.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json b/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json new file mode 100644 index 00000000000..b22bea03926 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r2c4-w9mv-hxcf/GHSA-r2c4-w9mv-hxcf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2c4-w9mv-hxcf", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31135" + ], + "details": "In JetBrains TeamCity before 2024.03 open redirect was possible on the login page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31135" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json b/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json new file mode 100644 index 00000000000..f4c6452106d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rpvr-xch8-v9v3/GHSA-rpvr-xch8-v9v3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpvr-xch8-v9v3", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-3040" + ], + "details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. The manipulation of the argument CRLId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258429 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3040" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-list_crl_conf.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258429" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258429" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.302340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json b/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json new file mode 100644 index 00000000000..55bb9c33695 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rx25-q489-m9cc/GHSA-rx25-q489-m9cc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx25-q489-m9cc", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30604" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30604" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/fromDhcpListClient_list1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json b/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json new file mode 100644 index 00000000000..722d903a8f5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rxxr-85xg-h73w/GHSA-rxxr-85xg-h73w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxxr-85xg-h73w", + "modified": "2024-03-28T15:30:34Z", + "published": "2024-03-28T15:30:34Z", + "aliases": [ + "CVE-2024-31138" + ], + "details": "In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31138" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vpq8-9rj2-88fw/GHSA-vpq8-9rj2-88fw.json b/advisories/unreviewed/2024/03/GHSA-vpq8-9rj2-88fw/GHSA-vpq8-9rj2-88fw.json new file mode 100644 index 00000000000..8c81a229a88 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vpq8-9rj2-88fw/GHSA-vpq8-9rj2-88fw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpq8-9rj2-88fw", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2023-35121" + ], + "details": "Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35121" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00988.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wfp8-rg23-hm62/GHSA-wfp8-rg23-hm62.json b/advisories/unreviewed/2024/03/GHSA-wfp8-rg23-hm62/GHSA-wfp8-rg23-hm62.json new file mode 100644 index 00000000000..aea6da8cf67 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wfp8-rg23-hm62/GHSA-wfp8-rg23-hm62.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfp8-rg23-hm62", + "modified": "2024-03-28T15:30:33Z", + "published": "2024-03-28T15:30:33Z", + "aliases": [ + "CVE-2024-30601" + ], + "details": "Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30601" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1203/saveParentControlInfo_time.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xv7j-v722-h5vx/GHSA-xv7j-v722-h5vx.json b/advisories/unreviewed/2024/03/GHSA-xv7j-v722-h5vx/GHSA-xv7j-v722-h5vx.json new file mode 100644 index 00000000000..3c9274d6311 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xv7j-v722-h5vx/GHSA-xv7j-v722-h5vx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv7j-v722-h5vx", + "modified": "2024-03-28T15:30:32Z", + "published": "2024-03-28T15:30:32Z", + "aliases": [ + "CVE-2024-30593" + ], + "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30593" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/FH/FH1202/formSetDeviceName_devName.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T13:15:47Z" + } +} \ No newline at end of file