diff --git a/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json b/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json new file mode 100644 index 00000000000..8c81ed195e5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-65xf-588v-56fv/GHSA-65xf-588v-56fv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65xf-588v-56fv", + "modified": "2024-09-30T21:31:07Z", + "published": "2024-09-30T21:31:07Z", + "aliases": [ + "CVE-2024-46503" + ], + "details": "An issue in the _readFileSync function of Simple-Spellchecker v1.0.2 allows attackers to read arbitrary files via a directory traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46503" + }, + { + "type": "WEB", + "url": "https://gist.github.com/guilherme-goncalves793/30d62c12fffd18d4058f4aebe188f462" + }, + { + "type": "WEB", + "url": "https://gist.github.com/guilherme-goncalves793/9c3125c6c8e33e0d9216847118137c63" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6p4r-rcv8-5x44/GHSA-6p4r-rcv8-5x44.json b/advisories/unreviewed/2024/09/GHSA-6p4r-rcv8-5x44/GHSA-6p4r-rcv8-5x44.json new file mode 100644 index 00000000000..96ea30921a3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6p4r-rcv8-5x44/GHSA-6p4r-rcv8-5x44.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p4r-rcv8-5x44", + "modified": "2024-09-30T21:31:06Z", + "published": "2024-09-30T21:31:06Z", + "aliases": [ + "CVE-2024-28807" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28807" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28807" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json b/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json new file mode 100644 index 00000000000..1f7c7f03767 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-73w6-p42r-w4jh/GHSA-73w6-p42r-w4jh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73w6-p42r-w4jh", + "modified": "2024-09-30T21:31:06Z", + "published": "2024-09-30T21:31:06Z", + "aliases": [ + "CVE-2024-28808" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28808" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28808" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json b/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json new file mode 100644 index 00000000000..6eb7afb137b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7cv4-mxxr-4vxg/GHSA-7cv4-mxxr-4vxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cv4-mxxr-4vxg", + "modified": "2024-09-30T21:31:07Z", + "published": "2024-09-30T21:31:07Z", + "aliases": [ + "CVE-2024-7671" + ], + "details": "A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7671" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json b/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json new file mode 100644 index 00000000000..824669eefaa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h5x9-4j34-4q7p/GHSA-h5x9-4j34-4q7p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5x9-4j34-4q7p", + "modified": "2024-09-30T21:31:08Z", + "published": "2024-09-30T21:31:08Z", + "aliases": [ + "CVE-2024-7675" + ], + "details": "A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7675" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json b/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json new file mode 100644 index 00000000000..6895cd2d62e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m785-2mqm-9r6g/GHSA-m785-2mqm-9r6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m785-2mqm-9r6g", + "modified": "2024-09-30T21:31:08Z", + "published": "2024-09-30T21:31:08Z", + "aliases": [ + "CVE-2024-7672" + ], + "details": "A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Navisworks, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7672" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json b/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json new file mode 100644 index 00000000000..0cd937d9e80 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q9cq-m6qx-6497/GHSA-q9cq-m6qx-6497.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9cq-m6qx-6497", + "modified": "2024-09-30T21:31:07Z", + "published": "2024-09-30T21:31:07Z", + "aliases": [ + "CVE-2024-7670" + ], + "details": "A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7670" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json b/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json new file mode 100644 index 00000000000..de7c483f221 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrv4-mmpj-7phv", + "modified": "2024-09-30T21:31:08Z", + "published": "2024-09-30T21:31:08Z", + "aliases": [ + "CVE-2024-7673" + ], + "details": "A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7673" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json b/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json new file mode 100644 index 00000000000..09280b12a9b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq4q-895p-v538", + "modified": "2024-09-30T21:31:08Z", + "published": "2024-09-30T21:31:08Z", + "aliases": [ + "CVE-2024-7674" + ], + "details": "A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7674" + }, + { + "type": "WEB", + "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T21:15:04Z" + } +} \ No newline at end of file