From b7bcac9d33c4ec85b4a922d20e8b4ac54c28b9fc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Dec 2024 18:32:48 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jpxc-vmjf-9fcj.json | 6 ++- .../GHSA-32p4-gm2c-wmch.json | 6 ++- .../GHSA-66jj-h4cx-53pq.json | 11 ++++-- .../GHSA-h3cg-9jm8-7468.json | 8 +--- .../GHSA-pq5h-mphr-9wrg.json | 17 ++++----- .../GHSA-pvgw-2qh3-cj63.json | 15 ++++++-- .../GHSA-qwff-3j78-f8jm.json | 4 +- .../GHSA-f5pr-p2jr-pvpx.json | 6 +-- .../GHSA-vxx9-qwhq-hgf4.json | 15 ++++---- .../GHSA-3jpw-p5mr-c3q9.json | 4 +- .../GHSA-5g37-8p7x-w23g.json | 15 ++++++-- .../GHSA-63p3-gmh7-933m.json | 4 +- .../GHSA-734v-mgwp-5gmw.json | 4 +- .../GHSA-g77x-hh5w-qpw7.json | 4 +- .../GHSA-wr7f-w7qw-m8x2.json | 15 ++++---- .../GHSA-x49r-f7f3-ghcf.json | 4 +- .../GHSA-3r68-84rw-29ww.json | 15 ++++++-- .../GHSA-92vx-8h67-43cg.json | 15 ++++++-- .../GHSA-mjm5-gj95-f347.json | 15 ++++++-- .../GHSA-27rm-pvpp-228f.json | 10 +++-- .../GHSA-5554-3cr8-7rwc.json | 11 ++++-- .../GHSA-g6wf-h667-5899.json | 2 +- .../GHSA-h64c-rqqh-q3fp.json | 6 ++- .../GHSA-mw9q-g6cf-hfc4.json | 4 +- .../GHSA-cj3p-4jrq-mg7x.json | 7 ++-- .../GHSA-mwrq-qv64-xgq7.json | 10 +++-- .../GHSA-wvvr-rxq8-c379.json | 10 +++-- .../GHSA-28fq-q3c7-php2.json | 3 +- .../GHSA-2jfw-8cwj-3579.json | 15 ++++++-- .../GHSA-34f4-hghj-ww8r.json | 3 +- .../GHSA-34wf-7h8g-xjhv.json | 15 ++++---- .../GHSA-38x5-mx6x-v39w.json | 6 +-- .../GHSA-5pwf-rq3f-8vg9.json | 15 ++++++-- .../GHSA-79vx-5hp8-mg9f.json | 3 +- .../GHSA-7q82-fxvh-gf2x.json | 15 ++++---- .../GHSA-8fm9-fr2m-7q98.json | 15 ++++---- .../GHSA-93fw-3pcm-8m72.json | 3 +- .../GHSA-9fr3-g426-jq79.json | 15 ++++++-- .../GHSA-9rg9-5x45-8r53.json | 15 ++++---- .../GHSA-9vh2-j2vg-h96g.json | 3 +- .../GHSA-c5xq-qh58-5jg9.json | 3 +- .../GHSA-f924-xqm3-3544.json | 3 +- .../GHSA-g4f9-hf22-85j8.json | 15 ++++---- .../GHSA-h8qc-rfpw-g45j.json | 15 ++++---- .../GHSA-hj2g-qp5m-cjqg.json | 3 +- .../GHSA-j33p-727h-4cv5.json | 15 ++++++-- .../GHSA-j8fr-cp65-m9m7.json | 15 ++++---- .../GHSA-mcpp-gh22-hwjw.json | 15 ++++++-- .../GHSA-mfqc-rm3c-48wj.json | 3 +- .../GHSA-qf6r-242x-wpg6.json | 15 ++++---- .../GHSA-qr6c-gp8p-xcwh.json | 15 ++++---- .../GHSA-x578-xmfm-9w46.json | 3 +- .../GHSA-259p-qfg9-jr98.json | 36 ++++++++++++++++++ .../GHSA-2qph-2p52-g49j.json | 4 +- .../GHSA-34fq-364c-3w2g.json | 36 ++++++++++++++++++ .../GHSA-3769-fj8m-crfp.json | 15 ++++++-- .../GHSA-6962-78fv-7v2v.json | 15 ++++++-- .../GHSA-6c9h-x2w3-3j4c.json | 36 ++++++++++++++++++ .../GHSA-6cmq-jm4v-8r35.json | 37 +++++++++++++++++++ .../GHSA-837j-xr3g-c46p.json | 36 ++++++++++++++++++ .../GHSA-8x6f-x28r-pfq4.json | 36 ++++++++++++++++++ .../GHSA-8x98-cpj8-mjx8.json | 36 ++++++++++++++++++ .../GHSA-f7fg-rvhw-9328.json | 36 ++++++++++++++++++ .../GHSA-fp87-jfrm-4f3f.json | 36 ++++++++++++++++++ .../GHSA-g42v-q2pr-gwfv.json | 36 ++++++++++++++++++ .../GHSA-g998-4r58-rr8q.json | 36 ++++++++++++++++++ .../GHSA-gjcw-vmfm-pc8c.json | 36 ++++++++++++++++++ .../GHSA-h852-6q42-cm59.json | 36 ++++++++++++++++++ .../GHSA-hwhh-rxm7-pxhq.json | 36 ++++++++++++++++++ .../GHSA-mjgg-cggm-7j9f.json | 36 ++++++++++++++++++ .../GHSA-pcg3-64vv-w6jf.json | 15 ++++++-- .../GHSA-pr78-f476-ghvf.json | 15 ++++++-- .../GHSA-qf6v-j5x7-cg97.json | 36 ++++++++++++++++++ .../GHSA-rmpf-7vcg-2m3m.json | 25 +++++++++++++ .../GHSA-v437-r985-w9w5.json | 3 +- .../GHSA-w2mr-h878-6344.json | 36 ++++++++++++++++++ 76 files changed, 990 insertions(+), 204 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-259p-qfg9-jr98/GHSA-259p-qfg9-jr98.json create mode 100644 advisories/unreviewed/2024/12/GHSA-34fq-364c-3w2g/GHSA-34fq-364c-3w2g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6c9h-x2w3-3j4c/GHSA-6c9h-x2w3-3j4c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json create mode 100644 advisories/unreviewed/2024/12/GHSA-837j-xr3g-c46p/GHSA-837j-xr3g-c46p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8x6f-x28r-pfq4/GHSA-8x6f-x28r-pfq4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8x98-cpj8-mjx8/GHSA-8x98-cpj8-mjx8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f7fg-rvhw-9328/GHSA-f7fg-rvhw-9328.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fp87-jfrm-4f3f/GHSA-fp87-jfrm-4f3f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g42v-q2pr-gwfv/GHSA-g42v-q2pr-gwfv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h852-6q42-cm59/GHSA-h852-6q42-cm59.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hwhh-rxm7-pxhq/GHSA-hwhh-rxm7-pxhq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rmpf-7vcg-2m3m/GHSA-rmpf-7vcg-2m3m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w2mr-h878-6344/GHSA-w2mr-h878-6344.json diff --git a/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json b/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json index 5f2a0f5d435..17a233f0a34 100644 --- a/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json +++ b/advisories/github-reviewed/2024/09/GHSA-jpxc-vmjf-9fcj/GHSA-jpxc-vmjf-9fcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jpxc-vmjf-9fcj", - "modified": "2024-11-21T21:33:31Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-09-16T14:37:26Z", "aliases": [ "CVE-2024-8775" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8775" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10762" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8969" diff --git a/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json b/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json index af05661b361..17b1d742b86 100644 --- a/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json +++ b/advisories/github-reviewed/2024/11/GHSA-32p4-gm2c-wmch/GHSA-32p4-gm2c-wmch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32p4-gm2c-wmch", - "modified": "2024-11-25T00:31:54Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-06T12:31:32Z", "aliases": [ "CVE-2024-9902" @@ -140,6 +140,10 @@ "type": "WEB", "url": "https://github.com/ansible/ansible/commit/f7be90626da3035c697623dcf9c90b7a0bc91c92" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10762" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8969" diff --git a/advisories/unreviewed/2024/02/GHSA-66jj-h4cx-53pq/GHSA-66jj-h4cx-53pq.json b/advisories/unreviewed/2024/02/GHSA-66jj-h4cx-53pq/GHSA-66jj-h4cx-53pq.json index 91d27a02759..5539b7004a8 100644 --- a/advisories/unreviewed/2024/02/GHSA-66jj-h4cx-53pq/GHSA-66jj-h4cx-53pq.json +++ b/advisories/unreviewed/2024/02/GHSA-66jj-h4cx-53pq/GHSA-66jj-h4cx-53pq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-66jj-h4cx-53pq", - "modified": "2024-02-15T21:31:27Z", + "modified": "2024-12-03T18:30:59Z", "published": "2024-02-15T21:31:27Z", "aliases": [ "CVE-2024-21728" ], "details": "An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a base64 malicious URL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T21:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json b/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json index a146efc8595..14654a61248 100644 --- a/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json +++ b/advisories/unreviewed/2024/02/GHSA-h3cg-9jm8-7468/GHSA-h3cg-9jm8-7468.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +33,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-pq5h-mphr-9wrg/GHSA-pq5h-mphr-9wrg.json b/advisories/unreviewed/2024/02/GHSA-pq5h-mphr-9wrg/GHSA-pq5h-mphr-9wrg.json index 8d50c2f93ea..ab085cd8942 100644 --- a/advisories/unreviewed/2024/02/GHSA-pq5h-mphr-9wrg/GHSA-pq5h-mphr-9wrg.json +++ b/advisories/unreviewed/2024/02/GHSA-pq5h-mphr-9wrg/GHSA-pq5h-mphr-9wrg.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-pq5h-mphr-9wrg", - "modified": "2024-02-17T06:30:34Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-02-17T06:30:34Z", "aliases": [ "CVE-2024-22727" ], "details": "Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability via Ethernet LAN or USB.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,10 +25,8 @@ } ], "database_specific": { - "cwe_ids": [ - - ], - "severity": null, + "cwe_ids": [], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-17T04:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pvgw-2qh3-cj63/GHSA-pvgw-2qh3-cj63.json b/advisories/unreviewed/2024/02/GHSA-pvgw-2qh3-cj63/GHSA-pvgw-2qh3-cj63.json index b6e0aae6b7d..51df31d63fb 100644 --- a/advisories/unreviewed/2024/02/GHSA-pvgw-2qh3-cj63/GHSA-pvgw-2qh3-cj63.json +++ b/advisories/unreviewed/2024/02/GHSA-pvgw-2qh3-cj63/GHSA-pvgw-2qh3-cj63.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvgw-2qh3-cj63", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42878" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:50Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qwff-3j78-f8jm/GHSA-qwff-3j78-f8jm.json b/advisories/unreviewed/2024/02/GHSA-qwff-3j78-f8jm/GHSA-qwff-3j78-f8jm.json index 331aedb5a9f..674b1c2be01 100644 --- a/advisories/unreviewed/2024/02/GHSA-qwff-3j78-f8jm/GHSA-qwff-3j78-f8jm.json +++ b/advisories/unreviewed/2024/02/GHSA-qwff-3j78-f8jm/GHSA-qwff-3j78-f8jm.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json b/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json index 2b956de1b51..bf458a2784d 100644 --- a/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json +++ b/advisories/unreviewed/2024/03/GHSA-f5pr-p2jr-pvpx/GHSA-f5pr-p2jr-pvpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5pr-p2jr-pvpx", - "modified": "2024-03-18T18:32:21Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-03-18T18:32:21Z", "aliases": [ "CVE-2024-26051" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/03/GHSA-vxx9-qwhq-hgf4/GHSA-vxx9-qwhq-hgf4.json b/advisories/unreviewed/2024/03/GHSA-vxx9-qwhq-hgf4/GHSA-vxx9-qwhq-hgf4.json index 9f6f5ae89ae..8dabbd6772e 100644 --- a/advisories/unreviewed/2024/03/GHSA-vxx9-qwhq-hgf4/GHSA-vxx9-qwhq-hgf4.json +++ b/advisories/unreviewed/2024/03/GHSA-vxx9-qwhq-hgf4/GHSA-vxx9-qwhq-hgf4.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-vxx9-qwhq-hgf4", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-03-25T15:30:43Z", "aliases": [ "CVE-2024-30205" ], "details": "In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -45,9 +46,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-494" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json b/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json index 8cb98c163e5..e70bc20225b 100644 --- a/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json +++ b/advisories/unreviewed/2024/04/GHSA-3jpw-p5mr-c3q9/GHSA-3jpw-p5mr-c3q9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json b/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json index bd97ea6e814..918e6fc7921 100644 --- a/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json +++ b/advisories/unreviewed/2024/04/GHSA-5g37-8p7x-w23g/GHSA-5g37-8p7x-w23g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5g37-8p7x-w23g", - "modified": "2024-04-16T18:31:36Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-32256" ], "details": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T17:15:11Z" diff --git a/advisories/unreviewed/2024/04/GHSA-63p3-gmh7-933m/GHSA-63p3-gmh7-933m.json b/advisories/unreviewed/2024/04/GHSA-63p3-gmh7-933m/GHSA-63p3-gmh7-933m.json index 49c1eb0ea26..301fc053d37 100644 --- a/advisories/unreviewed/2024/04/GHSA-63p3-gmh7-933m/GHSA-63p3-gmh7-933m.json +++ b/advisories/unreviewed/2024/04/GHSA-63p3-gmh7-933m/GHSA-63p3-gmh7-933m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-734v-mgwp-5gmw/GHSA-734v-mgwp-5gmw.json b/advisories/unreviewed/2024/04/GHSA-734v-mgwp-5gmw/GHSA-734v-mgwp-5gmw.json index 1c6f9c4ce37..7dbc475c96d 100644 --- a/advisories/unreviewed/2024/04/GHSA-734v-mgwp-5gmw/GHSA-734v-mgwp-5gmw.json +++ b/advisories/unreviewed/2024/04/GHSA-734v-mgwp-5gmw/GHSA-734v-mgwp-5gmw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json b/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json index 88ac531c5c3..5c24bd408ad 100644 --- a/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json +++ b/advisories/unreviewed/2024/04/GHSA-g77x-hh5w-qpw7/GHSA-g77x-hh5w-qpw7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wr7f-w7qw-m8x2/GHSA-wr7f-w7qw-m8x2.json b/advisories/unreviewed/2024/04/GHSA-wr7f-w7qw-m8x2/GHSA-wr7f-w7qw-m8x2.json index 97848abe6b6..769c6d28673 100644 --- a/advisories/unreviewed/2024/04/GHSA-wr7f-w7qw-m8x2/GHSA-wr7f-w7qw-m8x2.json +++ b/advisories/unreviewed/2024/04/GHSA-wr7f-w7qw-m8x2/GHSA-wr7f-w7qw-m8x2.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-wr7f-w7qw-m8x2", - "modified": "2024-04-12T06:33:24Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-04-12T06:33:24Z", "aliases": [ "CVE-2023-44854" ], "details": "Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the c_set_rslog_decode function in the acu_web file.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -25,9 +26,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T04:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x49r-f7f3-ghcf/GHSA-x49r-f7f3-ghcf.json b/advisories/unreviewed/2024/04/GHSA-x49r-f7f3-ghcf/GHSA-x49r-f7f3-ghcf.json index 0adbeedf23f..4f04e3ac7fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-x49r-f7f3-ghcf/GHSA-x49r-f7f3-ghcf.json +++ b/advisories/unreviewed/2024/04/GHSA-x49r-f7f3-ghcf/GHSA-x49r-f7f3-ghcf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3r68-84rw-29ww/GHSA-3r68-84rw-29ww.json b/advisories/unreviewed/2024/05/GHSA-3r68-84rw-29ww/GHSA-3r68-84rw-29ww.json index 172e6a2cc21..cb21e2322a2 100644 --- a/advisories/unreviewed/2024/05/GHSA-3r68-84rw-29ww/GHSA-3r68-84rw-29ww.json +++ b/advisories/unreviewed/2024/05/GHSA-3r68-84rw-29ww/GHSA-3r68-84rw-29ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3r68-84rw-29ww", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32610" ], "details": "HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-92vx-8h67-43cg/GHSA-92vx-8h67-43cg.json b/advisories/unreviewed/2024/05/GHSA-92vx-8h67-43cg/GHSA-92vx-8h67-43cg.json index 91b5caa6ffe..67da8130b90 100644 --- a/advisories/unreviewed/2024/05/GHSA-92vx-8h67-43cg/GHSA-92vx-8h67-43cg.json +++ b/advisories/unreviewed/2024/05/GHSA-92vx-8h67-43cg/GHSA-92vx-8h67-43cg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92vx-8h67-43cg", - "modified": "2024-05-23T18:30:55Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-05-23T18:30:55Z", "aliases": [ "CVE-2024-34931" ], "details": "A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T17:15:29Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json b/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json index 75bbdf9ad13..9237efec6be 100644 --- a/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json +++ b/advisories/unreviewed/2024/07/GHSA-mjm5-gj95-f347/GHSA-mjm5-gj95-f347.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mjm5-gj95-f347", - "modified": "2024-07-03T21:39:43Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-07-03T21:39:43Z", "aliases": [ "CVE-2024-29507" ], "details": "Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T19:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json b/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json index 3135cbe6494..d07d4a007b2 100644 --- a/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json +++ b/advisories/unreviewed/2024/08/GHSA-27rm-pvpp-228f/GHSA-27rm-pvpp-228f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27rm-pvpp-228f", - "modified": "2024-09-12T21:32:00Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-37392" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -24,6 +22,10 @@ { "type": "WEB", "url": "https://www.smseagle.eu/2024/08/21/resolved-xss-in-smseagle-software-cve-2024-37392" + }, + { + "type": "WEB", + "url": "https://www.smseagle.eu/security-advisory/resolved-xss-in-smseagle-software-cve-2024-37392" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json b/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json index 94e4a400000..72b4265f9b1 100644 --- a/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json +++ b/advisories/unreviewed/2024/08/GHSA-5554-3cr8-7rwc/GHSA-5554-3cr8-7rwc.json @@ -1,21 +1,23 @@ { "schema_version": "1.4.0", "id": "GHSA-5554-3cr8-7rwc", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-38859" ], "details": "XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by other users.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json b/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json index f78d8dec23a..456c174b7aa 100644 --- a/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json +++ b/advisories/unreviewed/2024/08/GHSA-g6wf-h667-5899/GHSA-g6wf-h667-5899.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g6wf-h667-5899", - "modified": "2024-08-14T03:31:07Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2023-31366" diff --git a/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json b/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json index 3098bb664ec..121ffe4cf5a 100644 --- a/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json +++ b/advisories/unreviewed/2024/08/GHSA-h64c-rqqh-q3fp/GHSA-h64c-rqqh-q3fp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h64c-rqqh-q3fp", - "modified": "2024-08-20T12:30:27Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-08-20T12:30:27Z", "aliases": [ "CVE-2024-28829" ], "details": "Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json b/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json index 5411743c6f1..fcff230210a 100644 --- a/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json +++ b/advisories/unreviewed/2024/08/GHSA-mw9q-g6cf-hfc4/GHSA-mw9q-g6cf-hfc4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-129" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json b/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json index dd2fe3f83a8..964ea7b8581 100644 --- a/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json +++ b/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cj3p-4jrq-mg7x", - "modified": "2024-10-17T15:31:09Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-10-17T15:31:09Z", "aliases": [ "CVE-2024-9683" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -32,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-305" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-mwrq-qv64-xgq7/GHSA-mwrq-qv64-xgq7.json b/advisories/unreviewed/2024/10/GHSA-mwrq-qv64-xgq7/GHSA-mwrq-qv64-xgq7.json index 5477e4d1fcf..5a2dc8824cd 100644 --- a/advisories/unreviewed/2024/10/GHSA-mwrq-qv64-xgq7/GHSA-mwrq-qv64-xgq7.json +++ b/advisories/unreviewed/2024/10/GHSA-mwrq-qv64-xgq7/GHSA-mwrq-qv64-xgq7.json @@ -1,21 +1,23 @@ { "schema_version": "1.4.0", "id": "GHSA-mwrq-qv64-xgq7", - "modified": "2024-10-14T09:30:53Z", + "modified": "2024-12-03T18:31:01Z", "published": "2024-10-14T09:30:53Z", "aliases": [ "CVE-2024-38862" ], "details": "Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to administrators.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/10/GHSA-wvvr-rxq8-c379/GHSA-wvvr-rxq8-c379.json b/advisories/unreviewed/2024/10/GHSA-wvvr-rxq8-c379/GHSA-wvvr-rxq8-c379.json index 893b701af38..73614bddec8 100644 --- a/advisories/unreviewed/2024/10/GHSA-wvvr-rxq8-c379/GHSA-wvvr-rxq8-c379.json +++ b/advisories/unreviewed/2024/10/GHSA-wvvr-rxq8-c379/GHSA-wvvr-rxq8-c379.json @@ -1,21 +1,23 @@ { "schema_version": "1.4.0", "id": "GHSA-wvvr-rxq8-c379", - "modified": "2024-10-14T09:30:53Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-10-14T09:30:53Z", "aliases": [ "CVE-2024-38863" ], "details": "Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json b/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json index 1e672d50830..17575a42e40 100644 --- a/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json +++ b/advisories/unreviewed/2024/11/GHSA-28fq-q3c7-php2/GHSA-28fq-q3c7-php2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-2jfw-8cwj-3579/GHSA-2jfw-8cwj-3579.json b/advisories/unreviewed/2024/11/GHSA-2jfw-8cwj-3579/GHSA-2jfw-8cwj-3579.json index 70872b71234..2c2e1c809fd 100644 --- a/advisories/unreviewed/2024/11/GHSA-2jfw-8cwj-3579/GHSA-2jfw-8cwj-3579.json +++ b/advisories/unreviewed/2024/11/GHSA-2jfw-8cwj-3579/GHSA-2jfw-8cwj-3579.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2jfw-8cwj-3579", - "modified": "2024-11-29T18:34:03Z", + "modified": "2024-12-03T18:31:03Z", "published": "2024-11-29T18:34:03Z", "aliases": [ "CVE-2024-36622" ], "details": "In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T18:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json b/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json index d5f75344a68..3095ef9081c 100644 --- a/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json +++ b/advisories/unreviewed/2024/11/GHSA-34f4-hghj-ww8r/GHSA-34f4-hghj-ww8r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-34wf-7h8g-xjhv/GHSA-34wf-7h8g-xjhv.json b/advisories/unreviewed/2024/11/GHSA-34wf-7h8g-xjhv/GHSA-34wf-7h8g-xjhv.json index 5f73b0f1600..9c8893a6c84 100644 --- a/advisories/unreviewed/2024/11/GHSA-34wf-7h8g-xjhv/GHSA-34wf-7h8g-xjhv.json +++ b/advisories/unreviewed/2024/11/GHSA-34wf-7h8g-xjhv/GHSA-34wf-7h8g-xjhv.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-34wf-7h8g-xjhv", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-44759" ], "details": "An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json b/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json index f7da2a6a196..2176eb59b7e 100644 --- a/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json +++ b/advisories/unreviewed/2024/11/GHSA-38x5-mx6x-v39w/GHSA-38x5-mx6x-v39w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38x5-mx6x-v39w", - "modified": "2024-11-25T00:31:54Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-25T00:31:54Z", "aliases": [ "CVE-2024-11666" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json b/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json index 5701eb38867..22b424fc6c0 100644 --- a/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json +++ b/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5pwf-rq3f-8vg9", - "modified": "2024-11-20T21:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-48533" ], "details": "A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json b/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json index b7e20193b31..3ca246253cd 100644 --- a/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json +++ b/advisories/unreviewed/2024/11/GHSA-79vx-5hp8-mg9f/GHSA-79vx-5hp8-mg9f.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json b/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json index b4b81591ed1..0bbbae3dcc1 100644 --- a/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json +++ b/advisories/unreviewed/2024/11/GHSA-7q82-fxvh-gf2x/GHSA-7q82-fxvh-gf2x.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-7q82-fxvh-gf2x", - "modified": "2024-11-15T18:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-51164" ], "details": "Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T16:15:37Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8fm9-fr2m-7q98/GHSA-8fm9-fr2m-7q98.json b/advisories/unreviewed/2024/11/GHSA-8fm9-fr2m-7q98/GHSA-8fm9-fr2m-7q98.json index d0a9b1f548b..5c404ce8bbb 100644 --- a/advisories/unreviewed/2024/11/GHSA-8fm9-fr2m-7q98/GHSA-8fm9-fr2m-7q98.json +++ b/advisories/unreviewed/2024/11/GHSA-8fm9-fr2m-7q98/GHSA-8fm9-fr2m-7q98.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-8fm9-fr2m-7q98", - "modified": "2024-11-15T21:30:46Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T21:30:46Z", "aliases": [ "CVE-2024-24431" ], "details": "A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json b/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json index f815328edf6..c0dc4158393 100644 --- a/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json +++ b/advisories/unreviewed/2024/11/GHSA-93fw-3pcm-8m72/GHSA-93fw-3pcm-8m72.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json b/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json index 9df67bcbe93..c3b81616569 100644 --- a/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json +++ b/advisories/unreviewed/2024/11/GHSA-9fr3-g426-jq79/GHSA-9fr3-g426-jq79.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fr3-g426-jq79", - "modified": "2024-11-29T21:31:03Z", + "modified": "2024-12-03T18:31:03Z", "published": "2024-11-29T21:31:03Z", "aliases": [ "CVE-2024-36615" ], "details": "FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T19:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json b/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json index d04b1dc5928..c35b6b136b2 100644 --- a/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json +++ b/advisories/unreviewed/2024/11/GHSA-9rg9-5x45-8r53/GHSA-9rg9-5x45-8r53.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-9rg9-5x45-8r53", - "modified": "2024-11-15T18:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-50649" ], "details": "The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T16:15:36Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json b/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json index 95208e318a4..63d1ccf2b5f 100644 --- a/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json +++ b/advisories/unreviewed/2024/11/GHSA-9vh2-j2vg-h96g/GHSA-9vh2-j2vg-h96g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json b/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json index 06121298370..e53458edae6 100644 --- a/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json +++ b/advisories/unreviewed/2024/11/GHSA-c5xq-qh58-5jg9/GHSA-c5xq-qh58-5jg9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json b/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json index 937b58d10b7..aad3631ffea 100644 --- a/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json +++ b/advisories/unreviewed/2024/11/GHSA-f924-xqm3-3544/GHSA-f924-xqm3-3544.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json b/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json index 988939e9527..35e60604b9b 100644 --- a/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json +++ b/advisories/unreviewed/2024/11/GHSA-g4f9-hf22-85j8/GHSA-g4f9-hf22-85j8.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-g4f9-hf22-85j8", - "modified": "2024-11-15T18:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-50648" ], "details": "yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T16:15:36Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json b/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json index 75f5eb053cb..e11a088bc2c 100644 --- a/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json +++ b/advisories/unreviewed/2024/11/GHSA-h8qc-rfpw-g45j/GHSA-h8qc-rfpw-g45j.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-h8qc-rfpw-g45j", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-50724" ], "details": "KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -25,9 +26,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T16:15:36Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json b/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json index 48eb11e58ed..dde5cc76cde 100644 --- a/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json +++ b/advisories/unreviewed/2024/11/GHSA-hj2g-qp5m-cjqg/GHSA-hj2g-qp5m-cjqg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json b/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json index cafe7157cb9..0466b7acc73 100644 --- a/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json +++ b/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j33p-727h-4cv5", - "modified": "2024-11-20T21:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-48536" ], "details": "Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j8fr-cp65-m9m7/GHSA-j8fr-cp65-m9m7.json b/advisories/unreviewed/2024/11/GHSA-j8fr-cp65-m9m7/GHSA-j8fr-cp65-m9m7.json index 7a232f7baa9..6f7bdc419c4 100644 --- a/advisories/unreviewed/2024/11/GHSA-j8fr-cp65-m9m7/GHSA-j8fr-cp65-m9m7.json +++ b/advisories/unreviewed/2024/11/GHSA-j8fr-cp65-m9m7/GHSA-j8fr-cp65-m9m7.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-j8fr-cp65-m9m7", - "modified": "2024-11-15T00:31:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T00:31:50Z", "aliases": [ "CVE-2024-31695" ], "details": "A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -25,9 +26,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T22:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json b/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json index 840665438f7..c03411cf189 100644 --- a/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json +++ b/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mcpp-gh22-hwjw", - "modified": "2024-11-20T21:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-48530" ], "details": "An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json b/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json index c3f30ff66c7..eb31959e1cd 100644 --- a/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json +++ b/advisories/unreviewed/2024/11/GHSA-mfqc-rm3c-48wj/GHSA-mfqc-rm3c-48wj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json b/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json index 10409692d1a..650514e570c 100644 --- a/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json +++ b/advisories/unreviewed/2024/11/GHSA-qf6r-242x-wpg6/GHSA-qf6r-242x-wpg6.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-qf6r-242x-wpg6", - "modified": "2024-11-15T18:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-50650" ], "details": "python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T16:15:36Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json b/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json index cbbc1105882..38b1fbeb47c 100644 --- a/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json +++ b/advisories/unreviewed/2024/11/GHSA-qr6c-gp8p-xcwh/GHSA-qr6c-gp8p-xcwh.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-qr6c-gp8p-xcwh", - "modified": "2024-11-15T18:30:50Z", + "modified": "2024-12-03T18:31:02Z", "published": "2024-11-15T18:30:50Z", "aliases": [ "CVE-2024-50647" ], "details": "The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user information beyond authorization.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T16:15:36Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json b/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json index 75f96b5839c..3ec66bf8140 100644 --- a/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json +++ b/advisories/unreviewed/2024/11/GHSA-x578-xmfm-9w46/GHSA-x578-xmfm-9w46.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-259p-qfg9-jr98/GHSA-259p-qfg9-jr98.json b/advisories/unreviewed/2024/12/GHSA-259p-qfg9-jr98/GHSA-259p-qfg9-jr98.json new file mode 100644 index 00000000000..17fdd848be2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-259p-qfg9-jr98/GHSA-259p-qfg9-jr98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-259p-qfg9-jr98", + "modified": "2024-12-03T18:31:03Z", + "published": "2024-12-03T18:31:03Z", + "aliases": [ + "CVE-2024-25036" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\n\n\n\n\ncould allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fields.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25036" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2qph-2p52-g49j/GHSA-2qph-2p52-g49j.json b/advisories/unreviewed/2024/12/GHSA-2qph-2p52-g49j/GHSA-2qph-2p52-g49j.json index a15d7f3f7de..ce3eb302b04 100644 --- a/advisories/unreviewed/2024/12/GHSA-2qph-2p52-g49j/GHSA-2qph-2p52-g49j.json +++ b/advisories/unreviewed/2024/12/GHSA-2qph-2p52-g49j/GHSA-2qph-2p52-g49j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-34fq-364c-3w2g/GHSA-34fq-364c-3w2g.json b/advisories/unreviewed/2024/12/GHSA-34fq-364c-3w2g/GHSA-34fq-364c-3w2g.json new file mode 100644 index 00000000000..2ef63c21930 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-34fq-364c-3w2g/GHSA-34fq-364c-3w2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34fq-364c-3w2g", + "modified": "2024-12-03T18:31:02Z", + "published": "2024-12-03T18:31:02Z", + "aliases": [ + "CVE-2024-53429" + ], + "details": "Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53429" + }, + { + "type": "WEB", + "url": "https://github.com/open62541/open62541/issues/6825" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json b/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json index ee6382d1e83..57904fd6d1c 100644 --- a/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json +++ b/advisories/unreviewed/2024/12/GHSA-3769-fj8m-crfp/GHSA-3769-fj8m-crfp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3769-fj8m-crfp", - "modified": "2024-12-02T15:31:41Z", + "modified": "2024-12-03T18:31:03Z", "published": "2024-12-02T15:31:41Z", "aliases": [ "CVE-2024-52732" ], "details": "Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T15:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json b/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json index 8c73ef6c9cd..c6653ba40e8 100644 --- a/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json +++ b/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6962-78fv-7v2v", - "modified": "2024-12-03T00:31:30Z", + "modified": "2024-12-03T18:31:03Z", "published": "2024-12-03T00:31:30Z", "aliases": [ "CVE-2018-9418" ], "details": "In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T22:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6c9h-x2w3-3j4c/GHSA-6c9h-x2w3-3j4c.json b/advisories/unreviewed/2024/12/GHSA-6c9h-x2w3-3j4c/GHSA-6c9h-x2w3-3j4c.json new file mode 100644 index 00000000000..9a6fe7f9ebe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6c9h-x2w3-3j4c/GHSA-6c9h-x2w3-3j4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c9h-x2w3-3j4c", + "modified": "2024-12-03T18:31:03Z", + "published": "2024-12-03T18:31:03Z", + "aliases": [ + "CVE-2024-25019" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\ncould be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25019" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json b/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json new file mode 100644 index 00000000000..535913b6a90 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cmq-jm4v-8r35", + "modified": "2024-12-03T18:31:03Z", + "published": "2024-12-03T18:31:03Z", + "aliases": [ + "CVE-2024-29404" + ], + "details": "An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29404" + }, + { + "type": "WEB", + "url": "https://github.com/mansk1es/CVE-2024-29404_Razer" + }, + { + "type": "WEB", + "url": "https://www.razer.com/synapse-3" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-837j-xr3g-c46p/GHSA-837j-xr3g-c46p.json b/advisories/unreviewed/2024/12/GHSA-837j-xr3g-c46p/GHSA-837j-xr3g-c46p.json new file mode 100644 index 00000000000..532a55d2fc8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-837j-xr3g-c46p/GHSA-837j-xr3g-c46p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-837j-xr3g-c46p", + "modified": "2024-12-03T18:31:03Z", + "published": "2024-12-03T18:31:03Z", + "aliases": [ + "CVE-2021-29892" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-29892" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8x6f-x28r-pfq4/GHSA-8x6f-x28r-pfq4.json b/advisories/unreviewed/2024/12/GHSA-8x6f-x28r-pfq4/GHSA-8x6f-x28r-pfq4.json new file mode 100644 index 00000000000..834b62cb67d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8x6f-x28r-pfq4/GHSA-8x6f-x28r-pfq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x6f-x28r-pfq4", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-40691" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\ncould be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40691" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8x98-cpj8-mjx8/GHSA-8x98-cpj8-mjx8.json b/advisories/unreviewed/2024/12/GHSA-8x98-cpj8-mjx8/GHSA-8x98-cpj8-mjx8.json new file mode 100644 index 00000000000..5b62c847329 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8x98-cpj8-mjx8/GHSA-8x98-cpj8-mjx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x98-cpj8-mjx8", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-41776" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\n\n\n\n\n\n\n\n\n\n\nis vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41776" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f7fg-rvhw-9328/GHSA-f7fg-rvhw-9328.json b/advisories/unreviewed/2024/12/GHSA-f7fg-rvhw-9328/GHSA-f7fg-rvhw-9328.json new file mode 100644 index 00000000000..06b56fd136b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f7fg-rvhw-9328/GHSA-f7fg-rvhw-9328.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7fg-rvhw-9328", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-25020" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\n\n\n\n\n\n\n\n\n\n\n\n\nis vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can make use of this weakness and upload malicious executable files into the system and can be sent to victims for performing further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25020" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fp87-jfrm-4f3f/GHSA-fp87-jfrm-4f3f.json b/advisories/unreviewed/2024/12/GHSA-fp87-jfrm-4f3f/GHSA-fp87-jfrm-4f3f.json new file mode 100644 index 00000000000..6477f8798b9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fp87-jfrm-4f3f/GHSA-fp87-jfrm-4f3f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp87-jfrm-4f3f", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-52548" + ], + "details": "An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52548" + }, + { + "type": "WEB", + "url": "https://github.com/sfewer-r7/LorexExploit" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g42v-q2pr-gwfv/GHSA-g42v-q2pr-gwfv.json b/advisories/unreviewed/2024/12/GHSA-g42v-q2pr-gwfv/GHSA-g42v-q2pr-gwfv.json new file mode 100644 index 00000000000..9cba0382961 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g42v-q2pr-gwfv/GHSA-g42v-q2pr-gwfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g42v-q2pr-gwfv", + "modified": "2024-12-03T18:31:03Z", + "published": "2024-12-03T18:31:03Z", + "aliases": [ + "CVE-2024-25035" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\n\n\nexposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25035" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json b/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json new file mode 100644 index 00000000000..dd7cd60ad5b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g998-4r58-rr8q", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-52545" + ], + "details": "An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52545" + }, + { + "type": "WEB", + "url": "https://github.com/sfewer-r7/LorexExploit" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json b/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json new file mode 100644 index 00000000000..c2a351e6c7c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjcw-vmfm-pc8c", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-52546" + ], + "details": "An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52546" + }, + { + "type": "WEB", + "url": "https://github.com/sfewer-r7/LorexExploit" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h852-6q42-cm59/GHSA-h852-6q42-cm59.json b/advisories/unreviewed/2024/12/GHSA-h852-6q42-cm59/GHSA-h852-6q42-cm59.json new file mode 100644 index 00000000000..ef12a8c705c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h852-6q42-cm59/GHSA-h852-6q42-cm59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h852-6q42-cm59", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-41777" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\n\n\n\n\n\n\n\n\ncontains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41777" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwhh-rxm7-pxhq/GHSA-hwhh-rxm7-pxhq.json b/advisories/unreviewed/2024/12/GHSA-hwhh-rxm7-pxhq/GHSA-hwhh-rxm7-pxhq.json new file mode 100644 index 00000000000..45a60cb9da4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwhh-rxm7-pxhq/GHSA-hwhh-rxm7-pxhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhh-rxm7-pxhq", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-45676" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 \n\n\n\n\n\n\n\ncould allow an authenticated user to upload insecure files, due to insufficient file type distinction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45676" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-351" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json b/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json new file mode 100644 index 00000000000..6f478c4fe46 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjgg-cggm-7j9f", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-52544" + ], + "details": "An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52544" + }, + { + "type": "WEB", + "url": "https://github.com/sfewer-r7/LorexExploit" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json b/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json index 809217e6bd5..536bfe368a9 100644 --- a/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json +++ b/advisories/unreviewed/2024/12/GHSA-pcg3-64vv-w6jf/GHSA-pcg3-64vv-w6jf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pcg3-64vv-w6jf", - "modified": "2024-12-02T15:31:41Z", + "modified": "2024-12-03T18:31:03Z", "published": "2024-12-02T15:31:41Z", "aliases": [ "CVE-2024-31669" ], "details": "rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T15:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pr78-f476-ghvf/GHSA-pr78-f476-ghvf.json b/advisories/unreviewed/2024/12/GHSA-pr78-f476-ghvf/GHSA-pr78-f476-ghvf.json index b805f604f1a..57f6d5cdc26 100644 --- a/advisories/unreviewed/2024/12/GHSA-pr78-f476-ghvf/GHSA-pr78-f476-ghvf.json +++ b/advisories/unreviewed/2024/12/GHSA-pr78-f476-ghvf/GHSA-pr78-f476-ghvf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pr78-f476-ghvf", - "modified": "2024-12-02T21:31:20Z", + "modified": "2024-12-03T18:31:03Z", "published": "2024-12-02T21:31:20Z", "aliases": [ "CVE-2018-9414" ], "details": "In gattServerSendResponseNative of com_android_bluetooth_gatt.cpp, there is a possible out of bounds stack write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json b/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json new file mode 100644 index 00000000000..482ec4419e8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf6v-j5x7-cg97", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-52547" + ], + "details": "An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52547" + }, + { + "type": "WEB", + "url": "https://github.com/sfewer-r7/LorexExploit" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rmpf-7vcg-2m3m/GHSA-rmpf-7vcg-2m3m.json b/advisories/unreviewed/2024/12/GHSA-rmpf-7vcg-2m3m/GHSA-rmpf-7vcg-2m3m.json new file mode 100644 index 00000000000..aed1bf82e8f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rmpf-7vcg-2m3m/GHSA-rmpf-7vcg-2m3m.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmpf-7vcg-2m3m", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2023-7255" + ], + "details": "Rejected reason: Assigned as duplicate and no longer used.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7255" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v437-r985-w9w5/GHSA-v437-r985-w9w5.json b/advisories/unreviewed/2024/12/GHSA-v437-r985-w9w5/GHSA-v437-r985-w9w5.json index 36868a87778..892d1eaf4aa 100644 --- a/advisories/unreviewed/2024/12/GHSA-v437-r985-w9w5/GHSA-v437-r985-w9w5.json +++ b/advisories/unreviewed/2024/12/GHSA-v437-r985-w9w5/GHSA-v437-r985-w9w5.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-798" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-w2mr-h878-6344/GHSA-w2mr-h878-6344.json b/advisories/unreviewed/2024/12/GHSA-w2mr-h878-6344/GHSA-w2mr-h878-6344.json new file mode 100644 index 00000000000..1a55da30084 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w2mr-h878-6344/GHSA-w2mr-h878-6344.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2mr-h878-6344", + "modified": "2024-12-03T18:31:04Z", + "published": "2024-12-03T18:31:04Z", + "aliases": [ + "CVE-2024-41775" + ], + "details": "IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41775" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T18:15:13Z" + } +} \ No newline at end of file