Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-02-13 18:40:06 +00:00
parent e0f215a32e
commit b818c367a1
180 changed files with 3391 additions and 227 deletions
@@ -37,7 +37,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -53,7 +53,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-824"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88qv-6q9j-fhvv",
"modified": "2022-04-29T02:57:11Z",
"modified": "2024-02-13T18:38:20Z",
"published": "2022-04-29T02:57:11Z",
"aliases": [
"CVE-2004-0121"
@@ -32,7 +32,7 @@
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843"
"url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:843"
},
{
"type": "WEB",
@@ -61,7 +61,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9h96-28m7-7h3g",
"modified": "2022-04-29T01:27:11Z",
"modified": "2024-02-13T18:38:20Z",
"published": "2022-04-29T01:27:11Z",
"aliases": [
"CVE-2003-0907"
@@ -28,11 +28,11 @@
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000"
"url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:1000"
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904"
"url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:904"
},
{
"type": "WEB",
@@ -65,7 +65,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvr6-jvr3-rqhf",
"modified": "2022-04-30T18:21:41Z",
"modified": "2024-02-13T18:38:20Z",
"published": "2022-04-30T18:21:41Z",
"aliases": [
"CVE-2002-1696"
],
"details": "Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when \"Automatically decrypt/verify when opening messages\" option is checked, \"Always use Secure Viewer when decrypting\" option is not checked, and the user replies to an encrypted message.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": "LOW",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f465-339w-2vhm",
"modified": "2022-04-30T18:18:14Z",
"modified": "2024-02-13T18:38:20Z",
"published": "2022-04-30T18:18:14Z",
"aliases": [
"CVE-2001-1537"
],
"details": "The default \"basic\" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -41,7 +41,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5h4-cjwm-9g2f",
"modified": "2022-04-30T18:18:08Z",
"modified": "2024-02-13T18:38:18Z",
"published": "2022-04-30T18:18:08Z",
"aliases": [
"CVE-2001-1481"
],
"details": "Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -37,7 +37,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -33,7 +33,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qm29-mf5j-82rg",
"modified": "2022-04-29T03:01:22Z",
"modified": "2024-02-13T18:38:20Z",
"published": "2022-04-29T03:01:22Z",
"aliases": [
"CVE-2004-2397"
],
"details": "The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -41,7 +44,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -25,7 +25,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rgp9-mx7h-rwqv",
"modified": "2022-04-29T02:57:41Z",
"modified": "2024-02-13T18:38:20Z",
"published": "2022-04-29T02:57:41Z",
"aliases": [
"CVE-2004-0411"
@@ -24,7 +24,7 @@
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A954"
"url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:954"
},
{
"type": "WEB",
@@ -89,7 +89,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-88"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -37,7 +37,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -29,7 +29,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-278x-6vg6-6g42",
"modified": "2022-05-01T23:49:30Z",
"modified": "2024-02-13T18:38:21Z",
"published": "2022-05-01T23:49:30Z",
"aliases": [
"CVE-2008-2374"
@@ -20,7 +20,7 @@
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9973"
"url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:9973"
},
{
"type": "WEB",
@@ -64,11 +64,11 @@
},
{
"type": "WEB",
"url": "http://sourceforge.net/mailarchive/message.php?msg_name=b32d44000806161327u680c290au54fd21f2fef1d58e%40mail.gmail.com"
"url": "http://sourceforge.net/mailarchive/message.php?msg_name=b32d44000806161327u680c290au54fd21f2fef1d58e@mail.gmail.com"
},
{
"type": "WEB",
"url": "http://www.bluez.org/bluez-334/"
"url": "http://www.bluez.org/bluez-334"
},
{
"type": "WEB",
@@ -93,6 +93,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1284",
"CWE-20"
],
"severity": "HIGH",
@@ -57,6 +57,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-88",
"CWE-94"
],
"severity": "LOW",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2r7g-mf5h-9gcw",
"modified": "2022-05-01T23:40:08Z",
"modified": "2024-02-13T18:38:21Z",
"published": "2022-05-01T23:40:08Z",
"aliases": [
"CVE-2008-1440"
@@ -24,7 +24,7 @@
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5473"
"url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:5473"
},
{
"type": "WEB",
@@ -49,6 +49,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1284",
"CWE-20"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43rr-prv9-867f",
"modified": "2022-05-01T23:37:17Z",
"modified": "2024-02-13T18:38:21Z",
"published": "2022-05-01T23:37:17Z",
"aliases": [
"CVE-2008-1160"
],
"details": "ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -36,7 +39,7 @@
},
{
"type": "WEB",
"url": "http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-(default-pass)-remote-root-vulnerability-2008032143791/"
"url": "http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-(default-pass)-remote-root-vulnerability-2008032143791"
},
{
"type": "WEB",
@@ -49,7 +52,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": "HIGH",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More