diff --git a/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json b/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json index 27ec93616d7..883a167cb05 100644 --- a/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json +++ b/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json b/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json index 7614775eede..be889489c32 100644 --- a/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json +++ b/advisories/unreviewed/2022/04/GHSA-4jjr-44rf-xh3q/GHSA-4jjr-44rf-xh3q.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json b/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json index 7aa63bfa902..d080fb6be64 100644 --- a/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json +++ b/advisories/unreviewed/2022/04/GHSA-4q24-rv9c-m9wm/GHSA-4q24-rv9c-m9wm.json @@ -53,7 +53,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-824" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json b/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json index 71e1489bdac..1375dd3d7e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json +++ b/advisories/unreviewed/2022/04/GHSA-88qv-6q9j-fhvv/GHSA-88qv-6q9j-fhvv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88qv-6q9j-fhvv", - "modified": "2022-04-29T02:57:11Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-04-29T02:57:11Z", "aliases": [ "CVE-2004-0121" @@ -32,7 +32,7 @@ }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:843" }, { "type": "WEB", @@ -61,7 +61,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json b/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json index 83d174405f5..829cbff66e4 100644 --- a/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json +++ b/advisories/unreviewed/2022/04/GHSA-9h96-28m7-7h3g/GHSA-9h96-28m7-7h3g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h96-28m7-7h3g", - "modified": "2022-04-29T01:27:11Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-04-29T01:27:11Z", "aliases": [ "CVE-2003-0907" @@ -28,11 +28,11 @@ }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:1000" }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:904" }, { "type": "WEB", @@ -65,7 +65,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-cvr6-jvr3-rqhf/GHSA-cvr6-jvr3-rqhf.json b/advisories/unreviewed/2022/04/GHSA-cvr6-jvr3-rqhf/GHSA-cvr6-jvr3-rqhf.json index d9a5686a0c4..004e1bb1a4a 100644 --- a/advisories/unreviewed/2022/04/GHSA-cvr6-jvr3-rqhf/GHSA-cvr6-jvr3-rqhf.json +++ b/advisories/unreviewed/2022/04/GHSA-cvr6-jvr3-rqhf/GHSA-cvr6-jvr3-rqhf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvr6-jvr3-rqhf", - "modified": "2022-04-30T18:21:41Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-04-30T18:21:41Z", "aliases": [ "CVE-2002-1696" ], "details": "Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when \"Automatically decrypt/verify when opening messages\" option is checked, \"Always use Secure Viewer when decrypting\" option is not checked, and the user replies to an encrypted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json b/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json index 50d637fc8a4..259c5aab084 100644 --- a/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json +++ b/advisories/unreviewed/2022/04/GHSA-f465-339w-2vhm/GHSA-f465-339w-2vhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f465-339w-2vhm", - "modified": "2022-04-30T18:18:14Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-04-30T18:18:14Z", "aliases": [ "CVE-2001-1537" ], "details": "The default \"basic\" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json b/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json index 36938674984..9e490e9578c 100644 --- a/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json +++ b/advisories/unreviewed/2022/04/GHSA-gv89-cmj2-j2r6/GHSA-gv89-cmj2-j2r6.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json b/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json index 7aa754b2919..9318e49aadc 100644 --- a/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json +++ b/advisories/unreviewed/2022/04/GHSA-h5h4-cjwm-9g2f/GHSA-h5h4-cjwm-9g2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5h4-cjwm-9g2f", - "modified": "2022-04-30T18:18:08Z", + "modified": "2024-02-13T18:38:18Z", "published": "2022-04-30T18:18:08Z", "aliases": [ "CVE-2001-1481" ], "details": "Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json b/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json index c247f7edd08..d38d9657deb 100644 --- a/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json +++ b/advisories/unreviewed/2022/04/GHSA-j2g6-hqhg-776g/GHSA-j2g6-hqhg-776g.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json b/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json index aa718761a2c..2e10c4900d7 100644 --- a/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json +++ b/advisories/unreviewed/2022/04/GHSA-q495-4rmw-2q38/GHSA-q495-4rmw-2q38.json @@ -33,7 +33,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json b/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json index 3f224e522d4..c6c68872aca 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json +++ b/advisories/unreviewed/2022/04/GHSA-qm29-mf5j-82rg/GHSA-qm29-mf5j-82rg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qm29-mf5j-82rg", - "modified": "2022-04-29T03:01:22Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-04-29T03:01:22Z", "aliases": [ "CVE-2004-2397" ], "details": "The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json b/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json index 7928b134994..e6564fb1195 100644 --- a/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json +++ b/advisories/unreviewed/2022/04/GHSA-r496-h5j2-r5vw/GHSA-r496-h5j2-r5vw.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json b/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json index 42dc9db5749..c5ff15a2d5c 100644 --- a/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json +++ b/advisories/unreviewed/2022/04/GHSA-rgp9-mx7h-rwqv/GHSA-rgp9-mx7h-rwqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgp9-mx7h-rwqv", - "modified": "2022-04-29T02:57:41Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-04-29T02:57:41Z", "aliases": [ "CVE-2004-0411" @@ -24,7 +24,7 @@ }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A954" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:954" }, { "type": "WEB", @@ -89,7 +89,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-88" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json b/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json index ad585f6ec12..4ddb2c019cb 100644 --- a/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json +++ b/advisories/unreviewed/2022/04/GHSA-w99v-7jp5-46gc/GHSA-w99v-7jp5-46gc.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json b/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json index 9c613a0011c..401dfef67ab 100644 --- a/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json +++ b/advisories/unreviewed/2022/04/GHSA-wf6v-m5v4-phr8/GHSA-wf6v-m5v4-phr8.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json b/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json index bb0d1de1cb7..67a1fb807c5 100644 --- a/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json +++ b/advisories/unreviewed/2022/05/GHSA-278x-6vg6-6g42/GHSA-278x-6vg6-6g42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-278x-6vg6-6g42", - "modified": "2022-05-01T23:49:30Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T23:49:30Z", "aliases": [ "CVE-2008-2374" @@ -20,7 +20,7 @@ }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9973" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:9973" }, { "type": "WEB", @@ -64,11 +64,11 @@ }, { "type": "WEB", - "url": "http://sourceforge.net/mailarchive/message.php?msg_name=b32d44000806161327u680c290au54fd21f2fef1d58e%40mail.gmail.com" + "url": "http://sourceforge.net/mailarchive/message.php?msg_name=b32d44000806161327u680c290au54fd21f2fef1d58e@mail.gmail.com" }, { "type": "WEB", - "url": "http://www.bluez.org/bluez-334/" + "url": "http://www.bluez.org/bluez-334" }, { "type": "WEB", @@ -93,6 +93,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json b/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json index b0c757d3488..7ff06cd2609 100644 --- a/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json +++ b/advisories/unreviewed/2022/05/GHSA-2mcc-mpmm-5889/GHSA-2mcc-mpmm-5889.json @@ -57,6 +57,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-88", "CWE-94" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json b/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json index 551d915751d..74685d59069 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json +++ b/advisories/unreviewed/2022/05/GHSA-2r7g-mf5h-9gcw/GHSA-2r7g-mf5h-9gcw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r7g-mf5h-9gcw", - "modified": "2022-05-01T23:40:08Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T23:40:08Z", "aliases": [ "CVE-2008-1440" @@ -24,7 +24,7 @@ }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5473" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:5473" }, { "type": "WEB", @@ -49,6 +49,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json b/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json index 26ab3c68805..027a71cfe4f 100644 --- a/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json +++ b/advisories/unreviewed/2022/05/GHSA-43rr-prv9-867f/GHSA-43rr-prv9-867f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-43rr-prv9-867f", - "modified": "2022-05-01T23:37:17Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T23:37:17Z", "aliases": [ "CVE-2008-1160" ], "details": "ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -36,7 +39,7 @@ }, { "type": "WEB", - "url": "http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-(default-pass)-remote-root-vulnerability-2008032143791/" + "url": "http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-(default-pass)-remote-root-vulnerability-2008032143791" }, { "type": "WEB", @@ -49,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4g56-8mc7-hpjq/GHSA-4g56-8mc7-hpjq.json b/advisories/unreviewed/2022/05/GHSA-4g56-8mc7-hpjq/GHSA-4g56-8mc7-hpjq.json index 6ec2d626f74..0358d16db5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4g56-8mc7-hpjq/GHSA-4g56-8mc7-hpjq.json +++ b/advisories/unreviewed/2022/05/GHSA-4g56-8mc7-hpjq/GHSA-4g56-8mc7-hpjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g56-8mc7-hpjq", - "modified": "2022-07-13T00:00:42Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-24T17:08:27Z", "aliases": [ "CVE-2020-0688" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.zerodayinitiative.com/advisories/ZDI-20-258/" + "url": "https://www.zerodayinitiative.com/advisories/ZDI-20-258" }, { "type": "WEB", @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-502", "CWE-798" ], diff --git a/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json b/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json index 0360dfa26f4..cf3b759577a 100644 --- a/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json +++ b/advisories/unreviewed/2022/05/GHSA-53xg-795p-rwf7/GHSA-53xg-795p-rwf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53xg-795p-rwf7", - "modified": "2022-05-01T23:49:30Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T23:49:30Z", "aliases": [ "CVE-2008-2369" ], "details": "manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the server and obtain sensitive information about user accounts and entitlements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json b/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json index 70f4e18d381..a1de82f1b09 100644 --- a/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json +++ b/advisories/unreviewed/2022/05/GHSA-59g7-r33p-jwx9/GHSA-59g7-r33p-jwx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59g7-r33p-jwx9", - "modified": "2022-05-01T02:20:28Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-05-01T02:20:28Z", "aliases": [ "CVE-2005-3716" ], "details": "The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json b/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json index 2756283e48f..79447afb9f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json +++ b/advisories/unreviewed/2022/05/GHSA-5hp5-x426-cxjg/GHSA-5hp5-x426-cxjg.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json b/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json index 897ec065133..6b61058ad0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json +++ b/advisories/unreviewed/2022/05/GHSA-5wfx-x267-4p7r/GHSA-5wfx-x267-4p7r.json @@ -53,6 +53,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-88", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json b/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json index 65be50bc72b..51ec6a2318b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json +++ b/advisories/unreviewed/2022/05/GHSA-5xv2-q475-rwrh/GHSA-5xv2-q475-rwrh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5xv2-q475-rwrh", - "modified": "2022-05-17T05:13:13Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-17T05:13:13Z", "aliases": [ "CVE-2012-3503" ], "details": "The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json b/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json index b0285fa67f2..f2e292f5d5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json +++ b/advisories/unreviewed/2022/05/GHSA-6c5q-h46j-p8gq/GHSA-6c5q-h46j-p8gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6c5q-h46j-p8gq", - "modified": "2022-05-02T03:33:30Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:33:30Z", "aliases": [ "CVE-2009-2272" ], "details": "The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP headers, and possibly by using unspecified other vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json b/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json index a7fdf7eaf82..ff6f0b5967e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json +++ b/advisories/unreviewed/2022/05/GHSA-6jvj-39c6-mh4m/GHSA-6jvj-39c6-mh4m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6jvj-39c6-mh4m", - "modified": "2022-05-02T03:43:02Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:43:02Z", "aliases": [ "CVE-2009-3232" @@ -24,7 +24,7 @@ }, { "type": "WEB", - "url": "https://usn.ubuntu.com/828-1/" + "url": "https://usn.ubuntu.com/828-1" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json b/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json index 0eafd3cd5ad..af755f5b6cb 100644 --- a/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json +++ b/advisories/unreviewed/2022/05/GHSA-73fw-3gw7-gp67/GHSA-73fw-3gw7-gp67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73fw-3gw7-gp67", - "modified": "2022-05-01T07:45:12Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T07:45:12Z", "aliases": [ "CVE-2006-7142" ], "details": "The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration files and decrypt the disk drive.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json b/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json index a7feac14c27..8811f4991fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json +++ b/advisories/unreviewed/2022/05/GHSA-79qx-5345-766q/GHSA-79qx-5345-766q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79qx-5345-766q", - "modified": "2022-05-14T02:45:21Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-14T02:45:21Z", "aliases": [ "CVE-2010-1573" ], "details": "Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json b/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json index c8c8c6ce402..23a3674e8b9 100644 --- a/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json +++ b/advisories/unreviewed/2022/05/GHSA-9cg4-j3w9-fwph/GHSA-9cg4-j3w9-fwph.json @@ -61,6 +61,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-88", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json b/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json index 9f50a56c736..39df1adb1fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json +++ b/advisories/unreviewed/2022/05/GHSA-9x4q-26cx-fr52/GHSA-9x4q-26cx-fr52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9x4q-26cx-fr52", - "modified": "2022-05-02T03:45:05Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:45:05Z", "aliases": [ "CVE-2009-3421" ], "details": "login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json b/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json index bda263f585e..930d6eeaa77 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json +++ b/advisories/unreviewed/2022/05/GHSA-ch4v-vxvm-66qf/GHSA-ch4v-vxvm-66qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch4v-vxvm-66qf", - "modified": "2022-05-01T07:21:11Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T07:21:11Z", "aliases": [ "CVE-2006-4692" @@ -24,7 +24,7 @@ }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A496" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:496" }, { "type": "WEB", @@ -32,7 +32,7 @@ }, { "type": "WEB", - "url": "http://secunia.com/secunia_research/2006-54/advisory/" + "url": "http://secunia.com/secunia_research/2006-54/advisory" }, { "type": "WEB", @@ -69,6 +69,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-88", "CWE-94" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-cv78-f6r2-g223/GHSA-cv78-f6r2-g223.json b/advisories/unreviewed/2022/05/GHSA-cv78-f6r2-g223/GHSA-cv78-f6r2-g223.json index c91bb324d95..d288373af60 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv78-f6r2-g223/GHSA-cv78-f6r2-g223.json +++ b/advisories/unreviewed/2022/05/GHSA-cv78-f6r2-g223/GHSA-cv78-f6r2-g223.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv78-f6r2-g223", - "modified": "2022-05-01T02:06:04Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-05-01T02:06:04Z", "aliases": [ "CVE-2005-2209" ], "details": "Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json b/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json index c0df391a8a9..5aa6ac31e69 100644 --- a/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json +++ b/advisories/unreviewed/2022/05/GHSA-fc3j-3f83-7fhr/GHSA-fc3j-3f83-7fhr.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json b/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json index 3bfd89bceee..118088fd3d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json +++ b/advisories/unreviewed/2022/05/GHSA-g2w2-352j-xq39/GHSA-g2w2-352j-xq39.json @@ -33,7 +33,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-gcrr-725q-f8jw/GHSA-gcrr-725q-f8jw.json b/advisories/unreviewed/2022/05/GHSA-gcrr-725q-f8jw/GHSA-gcrr-725q-f8jw.json index 822f39a57b6..6aa0de77c5d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gcrr-725q-f8jw/GHSA-gcrr-725q-f8jw.json +++ b/advisories/unreviewed/2022/05/GHSA-gcrr-725q-f8jw/GHSA-gcrr-725q-f8jw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcrr-725q-f8jw", - "modified": "2022-07-13T00:01:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-05-24T19:07:48Z", "aliases": [ "CVE-2021-34523" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-822/" + "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-822" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json b/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json index a73f4ffa57a..b45630c0682 100644 --- a/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json +++ b/advisories/unreviewed/2022/05/GHSA-grxh-vgg4-3pff/GHSA-grxh-vgg4-3pff.json @@ -45,7 +45,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json b/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json index 53dc23e49ef..e7f5889275d 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json +++ b/advisories/unreviewed/2022/05/GHSA-h2hc-3hmw-fmq5/GHSA-h2hc-3hmw-fmq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2hc-3hmw-fmq5", - "modified": "2022-05-02T03:32:33Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:32:33Z", "aliases": [ "CVE-2009-2168" ], "details": "cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json b/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json index e59332d28e0..44acf15a303 100644 --- a/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json +++ b/advisories/unreviewed/2022/05/GHSA-h5m2-8pmw-gmg7/GHSA-h5m2-8pmw-gmg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5m2-8pmw-gmg7", - "modified": "2022-05-02T03:26:40Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:26:40Z", "aliases": [ "CVE-2009-1596" ], "details": "Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json b/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json index c7d8d1775f5..ff2af0b81ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json +++ b/advisories/unreviewed/2022/05/GHSA-hvhv-mf3j-r564/GHSA-hvhv-mf3j-r564.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvhv-mf3j-r564", - "modified": "2022-05-01T23:35:08Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T23:35:08Z", "aliases": [ "CVE-2008-0961" ], "details": "EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json b/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json index 4b7fd930259..0f9dbdb2214 100644 --- a/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json +++ b/advisories/unreviewed/2022/05/GHSA-j2v6-c8rw-m58j/GHSA-j2v6-c8rw-m58j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2v6-c8rw-m58j", - "modified": "2022-05-02T03:34:36Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:34:36Z", "aliases": [ "CVE-2009-2382" ], "details": "admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json b/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json index f77b997b4d5..23af45e16d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json +++ b/advisories/unreviewed/2022/05/GHSA-jj26-78h6-475h/GHSA-jj26-78h6-475h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jj26-78h6-475h", - "modified": "2022-05-02T03:21:12Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:21:12Z", "aliases": [ "CVE-2009-1048" ], "details": "The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-290" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json b/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json index 2aa22d32cde..236e341b43e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json +++ b/advisories/unreviewed/2022/05/GHSA-jwxq-72jg-xr6j/GHSA-jwxq-72jg-xr6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwxq-72jg-xr6j", - "modified": "2022-05-17T02:07:37Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-17T02:07:37Z", "aliases": [ "CVE-2010-2073" ], "details": "auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote attackers to read arbitrary files from the FTP server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json b/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json index 56832bd0eb5..7660b46e4ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json +++ b/advisories/unreviewed/2022/05/GHSA-mjp9-35c3-rjjh/GHSA-mjp9-35c3-rjjh.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json b/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json index ba174152455..6790fb18906 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json +++ b/advisories/unreviewed/2022/05/GHSA-mrwj-9mpp-w94q/GHSA-mrwj-9mpp-w94q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrwj-9mpp-w94q", - "modified": "2022-05-02T03:13:53Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-02T03:13:53Z", "aliases": [ "CVE-2009-0265" ], "details": "Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-252", "CWE-287" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json b/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json index 2dd27566c2c..e740d8433c1 100644 --- a/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json +++ b/advisories/unreviewed/2022/05/GHSA-pxf7-7jp8-6443/GHSA-pxf7-7jp8-6443.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json b/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json index a9d835367fb..4a01c14bd35 100644 --- a/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json +++ b/advisories/unreviewed/2022/05/GHSA-q89m-g397-f55p/GHSA-q89m-g397-f55p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q89m-g397-f55p", - "modified": "2022-05-17T02:06:16Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-17T02:06:16Z", "aliases": [ "CVE-2010-2772" ], "details": "Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -36,7 +39,7 @@ }, { "type": "WEB", - "url": "http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/" + "url": "http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw" }, { "type": "WEB", @@ -72,12 +75,12 @@ }, { "type": "WEB", - "url": "http://www.wired.com/threatlevel/2010/07/siemens-scada/" + "url": "http://www.wired.com/threatlevel/2010/07/siemens-scada" } ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json b/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json index 388822b2b24..b1d796b7167 100644 --- a/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json +++ b/advisories/unreviewed/2022/05/GHSA-qc6x-g3h2-596q/GHSA-qc6x-g3h2-596q.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json b/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json index e0a9c7f3dc8..de7201f3306 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json +++ b/advisories/unreviewed/2022/05/GHSA-qmhp-32vc-r662/GHSA-qmhp-32vc-r662.json @@ -45,7 +45,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-r9cj-q2hj-hfq9/GHSA-r9cj-q2hj-hfq9.json b/advisories/unreviewed/2022/05/GHSA-r9cj-q2hj-hfq9/GHSA-r9cj-q2hj-hfq9.json index 4c942dfd6bc..76302da20be 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9cj-q2hj-hfq9/GHSA-r9cj-q2hj-hfq9.json +++ b/advisories/unreviewed/2022/05/GHSA-r9cj-q2hj-hfq9/GHSA-r9cj-q2hj-hfq9.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-178", "CWE-287" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-rc36-f2pm-xcjg/GHSA-rc36-f2pm-xcjg.json b/advisories/unreviewed/2022/05/GHSA-rc36-f2pm-xcjg/GHSA-rc36-f2pm-xcjg.json index ce98ba8dc45..7f0f70eb13b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc36-f2pm-xcjg/GHSA-rc36-f2pm-xcjg.json +++ b/advisories/unreviewed/2022/05/GHSA-rc36-f2pm-xcjg/GHSA-rc36-f2pm-xcjg.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json b/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json index 3a68744d315..47318618eb2 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json +++ b/advisories/unreviewed/2022/05/GHSA-vfj7-xg8w-82vp/GHSA-vfj7-xg8w-82vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfj7-xg8w-82vp", - "modified": "2022-05-01T02:21:23Z", + "modified": "2024-02-13T18:38:21Z", "published": "2022-05-01T02:21:23Z", "aliases": [ "CVE-2005-3803" ], "details": "Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded (\"fixed\") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -24,7 +27,7 @@ }, { "type": "WEB", - "url": "http://secunia.com/advisories/17604/" + "url": "http://secunia.com/advisories/17604" }, { "type": "WEB", @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vw62-wvm7-jfww/GHSA-vw62-wvm7-jfww.json b/advisories/unreviewed/2022/05/GHSA-vw62-wvm7-jfww/GHSA-vw62-wvm7-jfww.json index ca1a47526f3..fa5fc1fa0fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-vw62-wvm7-jfww/GHSA-vw62-wvm7-jfww.json +++ b/advisories/unreviewed/2022/05/GHSA-vw62-wvm7-jfww/GHSA-vw62-wvm7-jfww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vw62-wvm7-jfww", - "modified": "2022-05-01T02:05:37Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-05-01T02:05:37Z", "aliases": [ "CVE-2005-2160" ], "details": "IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json b/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json index 17b17da9d6d..6f29a43b288 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json +++ b/advisories/unreviewed/2022/05/GHSA-w4w3-5rjf-gvqh/GHSA-w4w3-5rjf-gvqh.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json b/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json index 8fc8b4e659a..ac118e0b367 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json +++ b/advisories/unreviewed/2022/05/GHSA-wrmg-46pv-747h/GHSA-wrmg-46pv-747h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrmg-46pv-747h", - "modified": "2022-05-01T01:49:47Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-05-01T01:49:47Z", "aliases": [ "CVE-2005-0496" ], "details": "Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -28,7 +31,7 @@ }, { "type": "WEB", - "url": "http://metasploit.com/research/arkeia_agent/" + "url": "http://metasploit.com/research/arkeia_agent" }, { "type": "WEB", @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-x7hf-rfv2-7qqq/GHSA-x7hf-rfv2-7qqq.json b/advisories/unreviewed/2022/05/GHSA-x7hf-rfv2-7qqq/GHSA-x7hf-rfv2-7qqq.json index 1790abdb1ae..757524abd4e 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7hf-rfv2-7qqq/GHSA-x7hf-rfv2-7qqq.json +++ b/advisories/unreviewed/2022/05/GHSA-x7hf-rfv2-7qqq/GHSA-x7hf-rfv2-7qqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7hf-rfv2-7qqq", - "modified": "2022-05-01T02:02:22Z", + "modified": "2024-02-13T18:38:20Z", "published": "2022-05-01T02:02:22Z", "aliases": [ "CVE-2005-1828" ], "details": "D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-4g4w-x2j6-rp8q/GHSA-4g4w-x2j6-rp8q.json b/advisories/unreviewed/2022/07/GHSA-4g4w-x2j6-rp8q/GHSA-4g4w-x2j6-rp8q.json index d15b89eaaec..4dfc5489ced 100644 --- a/advisories/unreviewed/2022/07/GHSA-4g4w-x2j6-rp8q/GHSA-4g4w-x2j6-rp8q.json +++ b/advisories/unreviewed/2022/07/GHSA-4g4w-x2j6-rp8q/GHSA-4g4w-x2j6-rp8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4w-x2j6-rp8q", - "modified": "2022-08-06T00:00:33Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-29T00:00:24Z", "aliases": [ "CVE-2022-30314" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json b/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json index 3375b307d2f..07f9779339f 100644 --- a/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json +++ b/advisories/unreviewed/2022/07/GHSA-59rw-g46v-6c42/GHSA-59rw-g46v-6c42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59rw-g46v-6c42", - "modified": "2022-08-03T00:00:54Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-27T00:00:30Z", "aliases": [ "CVE-2022-30271" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json b/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json index faacdd5c376..71235c05179 100644 --- a/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json +++ b/advisories/unreviewed/2022/07/GHSA-8w2f-5qfq-prwh/GHSA-8w2f-5qfq-prwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8w2f-5qfq-prwh", - "modified": "2022-08-05T00:00:28Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-27T00:00:32Z", "aliases": [ "CVE-2022-29964" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json b/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json index 0c1198875b7..59196920fac 100644 --- a/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json +++ b/advisories/unreviewed/2022/07/GHSA-q25f-hc6j-2jpw/GHSA-q25f-hc6j-2jpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q25f-hc6j-2jpw", - "modified": "2022-08-03T00:00:53Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-27T00:00:32Z", "aliases": [ "CVE-2022-29953" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json b/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json index 511b3261269..9982eb5823c 100644 --- a/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json +++ b/advisories/unreviewed/2022/07/GHSA-qf39-vcfc-vp3j/GHSA-qf39-vcfc-vp3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf39-vcfc-vp3j", - "modified": "2022-08-10T00:00:24Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-27T00:00:30Z", "aliases": [ "CVE-2022-30276" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-qr79-94p4-h8hm/GHSA-qr79-94p4-h8hm.json b/advisories/unreviewed/2022/07/GHSA-qr79-94p4-h8hm/GHSA-qr79-94p4-h8hm.json index 07a51aafb92..f7d6084c5ee 100644 --- a/advisories/unreviewed/2022/07/GHSA-qr79-94p4-h8hm/GHSA-qr79-94p4-h8hm.json +++ b/advisories/unreviewed/2022/07/GHSA-qr79-94p4-h8hm/GHSA-qr79-94p4-h8hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr79-94p4-h8hm", - "modified": "2022-08-06T00:00:34Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-29T00:00:23Z", "aliases": [ "CVE-2022-30313" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json b/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json index 78e477969f8..105a614ea12 100644 --- a/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json +++ b/advisories/unreviewed/2022/07/GHSA-w6v8-54jm-g2j3/GHSA-w6v8-54jm-g2j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6v8-54jm-g2j3", - "modified": "2022-08-04T00:00:23Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-07-27T00:00:32Z", "aliases": [ "CVE-2022-29960" @@ -31,12 +31,13 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { "cwe_ids": [ - "CWE-327" + "CWE-327", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json b/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json index 6ce4fda1e07..650d00bff6c 100644 --- a/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json +++ b/advisories/unreviewed/2022/08/GHSA-r8mv-jqpq-mx92/GHSA-r8mv-jqpq-mx92.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8mv-jqpq-mx92", - "modified": "2022-08-18T00:00:16Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-08-17T00:00:30Z", "aliases": [ "CVE-2022-29959" @@ -27,12 +27,13 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { "cwe_ids": [ - "CWE-327" + "CWE-327", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-p77h-46hr-84ff/GHSA-p77h-46hr-84ff.json b/advisories/unreviewed/2022/09/GHSA-p77h-46hr-84ff/GHSA-p77h-46hr-84ff.json index 2e705cc9d21..735c2086f50 100644 --- a/advisories/unreviewed/2022/09/GHSA-p77h-46hr-84ff/GHSA-p77h-46hr-84ff.json +++ b/advisories/unreviewed/2022/09/GHSA-p77h-46hr-84ff/GHSA-p77h-46hr-84ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p77h-46hr-84ff", - "modified": "2022-09-10T00:00:33Z", + "modified": "2024-02-13T18:38:22Z", "published": "2022-09-01T00:00:23Z", "aliases": [ "CVE-2022-30317" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://www.forescout.com/blog/" + "url": "https://www.forescout.com/blog" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json b/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json index 169541bde1d..af35c706126 100644 --- a/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json +++ b/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2r6-mg39-w7jm", - "modified": "2023-06-27T15:30:28Z", + "modified": "2024-02-13T18:38:22Z", "published": "2023-06-27T15:30:28Z", "aliases": [ "CVE-2023-2580" ], "details": "The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-27T14:15:10Z" diff --git a/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json b/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json index 6b93f92cda8..28d590f61af 100644 --- a/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json +++ b/advisories/unreviewed/2024/02/GHSA-293v-32vx-9g86/GHSA-293v-32vx-9g86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-293v-32vx-9g86", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T18:38:23Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2024-22852" ], "details": "D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -24,14 +27,14 @@ }, { "type": "WEB", - "url": "https://www.dlink.com/en/security-bulletin/" + "url": "https://www.dlink.com/en/security-bulletin" } ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T02:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-2crq-h5c4-gg2p/GHSA-2crq-h5c4-gg2p.json b/advisories/unreviewed/2024/02/GHSA-2crq-h5c4-gg2p/GHSA-2crq-h5c4-gg2p.json new file mode 100644 index 00000000000..c47f5eadab8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2crq-h5c4-gg2p/GHSA-2crq-h5c4-gg2p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2crq-h5c4-gg2p", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21345" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21345" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-2hmc-fq7v-3hqv/GHSA-2hmc-fq7v-3hqv.json b/advisories/unreviewed/2024/02/GHSA-2hmc-fq7v-3hqv/GHSA-2hmc-fq7v-3hqv.json new file mode 100644 index 00000000000..b091cbee320 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2hmc-fq7v-3hqv/GHSA-2hmc-fq7v-3hqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hmc-fq7v-3hqv", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21343" + ], + "details": "Windows Network Address Translation (NAT) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21343" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21343" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json b/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json new file mode 100644 index 00000000000..340b5b8de29 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2mmw-g99r-5x3v/GHSA-2mmw-g99r-5x3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mmw-g99r-5x3v", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21412" + ], + "details": "Internet Shortcut Files Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21412" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-2wff-jj2f-98c4/GHSA-2wff-jj2f-98c4.json b/advisories/unreviewed/2024/02/GHSA-2wff-jj2f-98c4/GHSA-2wff-jj2f-98c4.json index 90bc2a14d41..2f48173fab5 100644 --- a/advisories/unreviewed/2024/02/GHSA-2wff-jj2f-98c4/GHSA-2wff-jj2f-98c4.json +++ b/advisories/unreviewed/2024/02/GHSA-2wff-jj2f-98c4/GHSA-2wff-jj2f-98c4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-208" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-32q7-gv7f-4cg5/GHSA-32q7-gv7f-4cg5.json b/advisories/unreviewed/2024/02/GHSA-32q7-gv7f-4cg5/GHSA-32q7-gv7f-4cg5.json new file mode 100644 index 00000000000..8a316661ce1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-32q7-gv7f-4cg5/GHSA-32q7-gv7f-4cg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32q7-gv7f-4cg5", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21386" + ], + "details": ".NET Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21386" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21386" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json b/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json index 308b50b06f2..55140228b02 100644 --- a/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json +++ b/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34rx-mprw-whv5", - "modified": "2024-02-05T18:31:37Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-05T18:31:37Z", "aliases": [ "CVE-2024-23054" ], "details": "An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-05T16:15:55Z" diff --git a/advisories/unreviewed/2024/02/GHSA-37rh-9c3h-22jm/GHSA-37rh-9c3h-22jm.json b/advisories/unreviewed/2024/02/GHSA-37rh-9c3h-22jm/GHSA-37rh-9c3h-22jm.json new file mode 100644 index 00000000000..e31ef182f1c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-37rh-9c3h-22jm/GHSA-37rh-9c3h-22jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37rh-9c3h-22jm", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21344" + ], + "details": "Windows Network Address Translation (NAT) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21344" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21344" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3vmx-4pjf-8pwv/GHSA-3vmx-4pjf-8pwv.json b/advisories/unreviewed/2024/02/GHSA-3vmx-4pjf-8pwv/GHSA-3vmx-4pjf-8pwv.json new file mode 100644 index 00000000000..b2bbb51792a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3vmx-4pjf-8pwv/GHSA-3vmx-4pjf-8pwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vmx-4pjf-8pwv", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21329" + ], + "details": "Azure Connected Machine Agent Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21329" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21329" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3x8m-mcw2-vhx7/GHSA-3x8m-mcw2-vhx7.json b/advisories/unreviewed/2024/02/GHSA-3x8m-mcw2-vhx7/GHSA-3x8m-mcw2-vhx7.json new file mode 100644 index 00000000000..9792ff3f3fb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3x8m-mcw2-vhx7/GHSA-3x8m-mcw2-vhx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x8m-mcw2-vhx7", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21354" + ], + "details": "Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21354" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21354" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-44vv-2mpg-8hv5/GHSA-44vv-2mpg-8hv5.json b/advisories/unreviewed/2024/02/GHSA-44vv-2mpg-8hv5/GHSA-44vv-2mpg-8hv5.json new file mode 100644 index 00000000000..0b59c15e357 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-44vv-2mpg-8hv5/GHSA-44vv-2mpg-8hv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44vv-2mpg-8hv5", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21384" + ], + "details": "Microsoft Office OneNote Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21384" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21384" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-45x9-627r-26hh/GHSA-45x9-627r-26hh.json b/advisories/unreviewed/2024/02/GHSA-45x9-627r-26hh/GHSA-45x9-627r-26hh.json index a81cb5c3e10..d09b3d9fafc 100644 --- a/advisories/unreviewed/2024/02/GHSA-45x9-627r-26hh/GHSA-45x9-627r-26hh.json +++ b/advisories/unreviewed/2024/02/GHSA-45x9-627r-26hh/GHSA-45x9-627r-26hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45x9-627r-26hh", - "modified": "2024-02-06T00:30:26Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2023-7014" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3019084/" + "url": "https://plugins.trac.wordpress.org/changeset/3019084" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-47q6-36gc-6phg/GHSA-47q6-36gc-6phg.json b/advisories/unreviewed/2024/02/GHSA-47q6-36gc-6phg/GHSA-47q6-36gc-6phg.json index 1ab6fad3caf..ff00b6703c0 100644 --- a/advisories/unreviewed/2024/02/GHSA-47q6-36gc-6phg/GHSA-47q6-36gc-6phg.json +++ b/advisories/unreviewed/2024/02/GHSA-47q6-36gc-6phg/GHSA-47q6-36gc-6phg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47q6-36gc-6phg", - "modified": "2024-02-06T00:30:26Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2023-6985" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4974-qrr5-pm93/GHSA-4974-qrr5-pm93.json b/advisories/unreviewed/2024/02/GHSA-4974-qrr5-pm93/GHSA-4974-qrr5-pm93.json index 0245baf3714..13fb54d2ea2 100644 --- a/advisories/unreviewed/2024/02/GHSA-4974-qrr5-pm93/GHSA-4974-qrr5-pm93.json +++ b/advisories/unreviewed/2024/02/GHSA-4974-qrr5-pm93/GHSA-4974-qrr5-pm93.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4974-qrr5-pm93", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0761" @@ -23,11 +23,11 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3023403/wp-file-manager/trunk/file_folder_manager.php?old=2984933&old_path=wp-file-manager%2Ftrunk%2Ffile_folder_manager.php" + "url": "https://plugins.trac.wordpress.org/changeset/3023403/wp-file-manager/trunk/file_folder_manager.php?old=2984933&old_path=wp-file-manager/trunk/file_folder_manager.php" }, { "type": "WEB", - "url": "https://wordpress.org/plugins/wp-file-manager/" + "url": "https://wordpress.org/plugins/wp-file-manager" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-330" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4f6r-f3wr-x5fw/GHSA-4f6r-f3wr-x5fw.json b/advisories/unreviewed/2024/02/GHSA-4f6r-f3wr-x5fw/GHSA-4f6r-f3wr-x5fw.json index c5b62985bd1..07f673d7569 100644 --- a/advisories/unreviewed/2024/02/GHSA-4f6r-f3wr-x5fw/GHSA-4f6r-f3wr-x5fw.json +++ b/advisories/unreviewed/2024/02/GHSA-4f6r-f3wr-x5fw/GHSA-4f6r-f3wr-x5fw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4f6r-f3wr-x5fw", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0659" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json b/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json new file mode 100644 index 00000000000..f3939876598 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4hpc-jmfv-gf3c/GHSA-4hpc-jmfv-gf3c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hpc-jmfv-gf3c", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2023-45206" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45206" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4j4p-q978-922r/GHSA-4j4p-q978-922r.json b/advisories/unreviewed/2024/02/GHSA-4j4p-q978-922r/GHSA-4j4p-q978-922r.json index b6b7c434bba..1b117a805a1 100644 --- a/advisories/unreviewed/2024/02/GHSA-4j4p-q978-922r/GHSA-4j4p-q978-922r.json +++ b/advisories/unreviewed/2024/02/GHSA-4j4p-q978-922r/GHSA-4j4p-q978-922r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j4p-q978-922r", - "modified": "2024-02-06T00:30:28Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:28Z", "aliases": [ "CVE-2023-47354" ], "details": "An issue in the PowerOffWidgetReceiver function of Super Reboot (Root) Recovery v1.0.3 allows attackers to arbitrarily reset or power off the device via a crafted intent", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T00:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json b/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json new file mode 100644 index 00000000000..85be1d00b7a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p3v-h475-6j2m", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2023-50808" + ], + "details": "Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50808" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P38" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5274-vpj4-w5jf/GHSA-5274-vpj4-w5jf.json b/advisories/unreviewed/2024/02/GHSA-5274-vpj4-w5jf/GHSA-5274-vpj4-w5jf.json new file mode 100644 index 00000000000..83b4f05da91 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5274-vpj4-w5jf/GHSA-5274-vpj4-w5jf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5274-vpj4-w5jf", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21358" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21358" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21358" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5g3c-xpc6-569g/GHSA-5g3c-xpc6-569g.json b/advisories/unreviewed/2024/02/GHSA-5g3c-xpc6-569g/GHSA-5g3c-xpc6-569g.json new file mode 100644 index 00000000000..6431420c7e7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5g3c-xpc6-569g/GHSA-5g3c-xpc6-569g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g3c-xpc6-569g", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21371" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21371" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21371" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5q8j-7rff-2fw6/GHSA-5q8j-7rff-2fw6.json b/advisories/unreviewed/2024/02/GHSA-5q8j-7rff-2fw6/GHSA-5q8j-7rff-2fw6.json index faecc16f8b9..07cdb466b2b 100644 --- a/advisories/unreviewed/2024/02/GHSA-5q8j-7rff-2fw6/GHSA-5q8j-7rff-2fw6.json +++ b/advisories/unreviewed/2024/02/GHSA-5q8j-7rff-2fw6/GHSA-5q8j-7rff-2fw6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-656r-f454-6wgf/GHSA-656r-f454-6wgf.json b/advisories/unreviewed/2024/02/GHSA-656r-f454-6wgf/GHSA-656r-f454-6wgf.json new file mode 100644 index 00000000000..d8f4c50fa5f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-656r-f454-6wgf/GHSA-656r-f454-6wgf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-656r-f454-6wgf", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21420" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21420" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21420" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json b/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json index d4d40187b80..5dfa9f57fb9 100644 --- a/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json +++ b/advisories/unreviewed/2024/02/GHSA-68r4-mq9j-2rrq/GHSA-68r4-mq9j-2rrq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-6x2q-4wwr-j5p2/GHSA-6x2q-4wwr-j5p2.json b/advisories/unreviewed/2024/02/GHSA-6x2q-4wwr-j5p2/GHSA-6x2q-4wwr-j5p2.json new file mode 100644 index 00000000000..a2d5d137357 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6x2q-4wwr-j5p2/GHSA-6x2q-4wwr-j5p2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x2q-4wwr-j5p2", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21353" + ], + "details": "Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21353" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21353" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-76w3-qpqm-hj57/GHSA-76w3-qpqm-hj57.json b/advisories/unreviewed/2024/02/GHSA-76w3-qpqm-hj57/GHSA-76w3-qpqm-hj57.json new file mode 100644 index 00000000000..4be41dc2e61 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-76w3-qpqm-hj57/GHSA-76w3-qpqm-hj57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76w3-qpqm-hj57", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21396" + ], + "details": "Dynamics 365 Sales Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21396" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21396" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-778x-f39r-xr3j/GHSA-778x-f39r-xr3j.json b/advisories/unreviewed/2024/02/GHSA-778x-f39r-xr3j/GHSA-778x-f39r-xr3j.json new file mode 100644 index 00000000000..7757dced5a6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-778x-f39r-xr3j/GHSA-778x-f39r-xr3j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-778x-f39r-xr3j", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21366" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21366" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21366" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-77fr-m2wv-vvvh/GHSA-77fr-m2wv-vvvh.json b/advisories/unreviewed/2024/02/GHSA-77fr-m2wv-vvvh/GHSA-77fr-m2wv-vvvh.json new file mode 100644 index 00000000000..66ab1246be1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-77fr-m2wv-vvvh/GHSA-77fr-m2wv-vvvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77fr-m2wv-vvvh", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21327" + ], + "details": "Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21327" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21327" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-77qj-g9f7-xqj9/GHSA-77qj-g9f7-xqj9.json b/advisories/unreviewed/2024/02/GHSA-77qj-g9f7-xqj9/GHSA-77qj-g9f7-xqj9.json new file mode 100644 index 00000000000..8de7e169cff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-77qj-g9f7-xqj9/GHSA-77qj-g9f7-xqj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77qj-g9f7-xqj9", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21397" + ], + "details": "Microsoft Azure File Sync Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21397" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21397" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7ffr-7c74-8mp9/GHSA-7ffr-7c74-8mp9.json b/advisories/unreviewed/2024/02/GHSA-7ffr-7c74-8mp9/GHSA-7ffr-7c74-8mp9.json new file mode 100644 index 00000000000..cba6bd97fc7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7ffr-7c74-8mp9/GHSA-7ffr-7c74-8mp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ffr-7c74-8mp9", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21380" + ], + "details": "Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21380" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21380" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7ggc-w2g9-j9rm/GHSA-7ggc-w2g9-j9rm.json b/advisories/unreviewed/2024/02/GHSA-7ggc-w2g9-j9rm/GHSA-7ggc-w2g9-j9rm.json new file mode 100644 index 00000000000..03fe1b1700b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7ggc-w2g9-j9rm/GHSA-7ggc-w2g9-j9rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ggc-w2g9-j9rm", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21369" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21369" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21369" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7j2m-h9v4-jfx3/GHSA-7j2m-h9v4-jfx3.json b/advisories/unreviewed/2024/02/GHSA-7j2m-h9v4-jfx3/GHSA-7j2m-h9v4-jfx3.json new file mode 100644 index 00000000000..8ae6afcec2f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7j2m-h9v4-jfx3/GHSA-7j2m-h9v4-jfx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j2m-h9v4-jfx3", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21357" + ], + "details": "Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21357" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21357" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7m74-4w6g-p6gf/GHSA-7m74-4w6g-p6gf.json b/advisories/unreviewed/2024/02/GHSA-7m74-4w6g-p6gf/GHSA-7m74-4w6g-p6gf.json index 979f1f010da..97872aae450 100644 --- a/advisories/unreviewed/2024/02/GHSA-7m74-4w6g-p6gf/GHSA-7m74-4w6g-p6gf.json +++ b/advisories/unreviewed/2024/02/GHSA-7m74-4w6g-p6gf/GHSA-7m74-4w6g-p6gf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-7wwp-jj6f-3856/GHSA-7wwp-jj6f-3856.json b/advisories/unreviewed/2024/02/GHSA-7wwp-jj6f-3856/GHSA-7wwp-jj6f-3856.json new file mode 100644 index 00000000000..4051b57df64 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7wwp-jj6f-3856/GHSA-7wwp-jj6f-3856.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wwp-jj6f-3856", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-20695" + ], + "details": "Skype for Business Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20695" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20695" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7x7v-w2rw-mcq4/GHSA-7x7v-w2rw-mcq4.json b/advisories/unreviewed/2024/02/GHSA-7x7v-w2rw-mcq4/GHSA-7x7v-w2rw-mcq4.json new file mode 100644 index 00000000000..afd91d29376 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7x7v-w2rw-mcq4/GHSA-7x7v-w2rw-mcq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x7v-w2rw-mcq4", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21370" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21370" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21370" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7xmr-w6vf-6jjf/GHSA-7xmr-w6vf-6jjf.json b/advisories/unreviewed/2024/02/GHSA-7xmr-w6vf-6jjf/GHSA-7xmr-w6vf-6jjf.json index c35fa8ea401..62ce8795608 100644 --- a/advisories/unreviewed/2024/02/GHSA-7xmr-w6vf-6jjf/GHSA-7xmr-w6vf-6jjf.json +++ b/advisories/unreviewed/2024/02/GHSA-7xmr-w6vf-6jjf/GHSA-7xmr-w6vf-6jjf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-82hw-q3r9-q2hc/GHSA-82hw-q3r9-q2hc.json b/advisories/unreviewed/2024/02/GHSA-82hw-q3r9-q2hc/GHSA-82hw-q3r9-q2hc.json new file mode 100644 index 00000000000..b09bf7a1a11 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-82hw-q3r9-q2hc/GHSA-82hw-q3r9-q2hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82hw-q3r9-q2hc", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21362" + ], + "details": "Windows Kernel Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21362" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21362" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-88fq-wp8p-xcg5/GHSA-88fq-wp8p-xcg5.json b/advisories/unreviewed/2024/02/GHSA-88fq-wp8p-xcg5/GHSA-88fq-wp8p-xcg5.json new file mode 100644 index 00000000000..6d0f2fd3f5f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-88fq-wp8p-xcg5/GHSA-88fq-wp8p-xcg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88fq-wp8p-xcg5", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21403" + ], + "details": "Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21403" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21403" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8c3h-v556-h76p/GHSA-8c3h-v556-h76p.json b/advisories/unreviewed/2024/02/GHSA-8c3h-v556-h76p/GHSA-8c3h-v556-h76p.json new file mode 100644 index 00000000000..2818fb5ef80 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8c3h-v556-h76p/GHSA-8c3h-v556-h76p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c3h-v556-h76p", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21376" + ], + "details": "Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21376" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21376" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json b/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json index 6dde1a12bce..33d5483c084 100644 --- a/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json +++ b/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mxm-4gjm-vrc7", - "modified": "2024-02-13T15:31:12Z", + "modified": "2024-02-13T18:38:23Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-6516" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-6516" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-8pmf-5vv3-gw7f/GHSA-8pmf-5vv3-gw7f.json b/advisories/unreviewed/2024/02/GHSA-8pmf-5vv3-gw7f/GHSA-8pmf-5vv3-gw7f.json new file mode 100644 index 00000000000..7f219c1c0f0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8pmf-5vv3-gw7f/GHSA-8pmf-5vv3-gw7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pmf-5vv3-gw7f", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21348" + ], + "details": "Internet Connection Sharing (ICS) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21348" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21348" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8v72-m9q9-xpwf/GHSA-8v72-m9q9-xpwf.json b/advisories/unreviewed/2024/02/GHSA-8v72-m9q9-xpwf/GHSA-8v72-m9q9-xpwf.json new file mode 100644 index 00000000000..81be41973d2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8v72-m9q9-xpwf/GHSA-8v72-m9q9-xpwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v72-m9q9-xpwf", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21352" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21352" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21352" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-95rw-m3jj-r8jm/GHSA-95rw-m3jj-r8jm.json b/advisories/unreviewed/2024/02/GHSA-95rw-m3jj-r8jm/GHSA-95rw-m3jj-r8jm.json new file mode 100644 index 00000000000..e4e8b314d14 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-95rw-m3jj-r8jm/GHSA-95rw-m3jj-r8jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95rw-m3jj-r8jm", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21342" + ], + "details": "Windows DNS Client Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21342" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21342" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-99h4-3x4g-cr3g/GHSA-99h4-3x4g-cr3g.json b/advisories/unreviewed/2024/02/GHSA-99h4-3x4g-cr3g/GHSA-99h4-3x4g-cr3g.json new file mode 100644 index 00000000000..747d9e49ab0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-99h4-3x4g-cr3g/GHSA-99h4-3x4g-cr3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99h4-3x4g-cr3g", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21363" + ], + "details": "Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21363" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21363" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-99xv-j5qx-85qp/GHSA-99xv-j5qx-85qp.json b/advisories/unreviewed/2024/02/GHSA-99xv-j5qx-85qp/GHSA-99xv-j5qx-85qp.json new file mode 100644 index 00000000000..dbcf7129eff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-99xv-j5qx-85qp/GHSA-99xv-j5qx-85qp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99xv-j5qx-85qp", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21355" + ], + "details": "Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21355" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21355" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json b/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json new file mode 100644 index 00000000000..14d38b17adb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9mp4-h7q5-2rgq/GHSA-9mp4-h7q5-2rgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mp4-h7q5-2rgq", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21413" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21413" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9mw3-pvx5-q297/GHSA-9mw3-pvx5-q297.json b/advisories/unreviewed/2024/02/GHSA-9mw3-pvx5-q297/GHSA-9mw3-pvx5-q297.json new file mode 100644 index 00000000000..8db92f43fb4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9mw3-pvx5-q297/GHSA-9mw3-pvx5-q297.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mw3-pvx5-q297", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21405" + ], + "details": "Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21405" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json b/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json new file mode 100644 index 00000000000..36ed36095e1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9qcp-fr5g-q6j7/GHSA-9qcp-fr5g-q6j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qcp-fr5g-q6j7", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21304" + ], + "details": "Trusted Compute Base Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21304" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21304" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9wcf-3gfm-37qh/GHSA-9wcf-3gfm-37qh.json b/advisories/unreviewed/2024/02/GHSA-9wcf-3gfm-37qh/GHSA-9wcf-3gfm-37qh.json new file mode 100644 index 00000000000..373f8dc382f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9wcf-3gfm-37qh/GHSA-9wcf-3gfm-37qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wcf-3gfm-37qh", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21394" + ], + "details": "Dynamics 365 Field Service Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21394" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21394" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9xhj-3vxp-mxvr/GHSA-9xhj-3vxp-mxvr.json b/advisories/unreviewed/2024/02/GHSA-9xhj-3vxp-mxvr/GHSA-9xhj-3vxp-mxvr.json new file mode 100644 index 00000000000..564ec1712ab --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9xhj-3vxp-mxvr/GHSA-9xhj-3vxp-mxvr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xhj-3vxp-mxvr", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-22923" + ], + "details": "SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22923" + }, + { + "type": "WEB", + "url": "https://gist.github.com/whiteman007" + }, + { + "type": "WEB", + "url": "http://advradius.com/demo" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c3f4-9jqh-m7h6/GHSA-c3f4-9jqh-m7h6.json b/advisories/unreviewed/2024/02/GHSA-c3f4-9jqh-m7h6/GHSA-c3f4-9jqh-m7h6.json new file mode 100644 index 00000000000..c9774c18f88 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c3f4-9jqh-m7h6/GHSA-c3f4-9jqh-m7h6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3f4-9jqh-m7h6", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21375" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21375" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21375" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json b/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json index bdc012d81a9..4f264e5fc23 100644 --- a/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json +++ b/advisories/unreviewed/2024/02/GHSA-c5g4-g3x7-x8rm/GHSA-c5g4-g3x7-x8rm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5g4-g3x7-x8rm", - "modified": "2024-02-06T03:32:59Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T03:32:59Z", "aliases": [ "CVE-2023-47353" ], "details": "An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-494" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T01:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json b/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json index 274f6e20111..a9d52113c24 100644 --- a/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json +++ b/advisories/unreviewed/2024/02/GHSA-c6f2-5665-5p8p/GHSA-c6f2-5665-5p8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6f2-5665-5p8p", - "modified": "2024-02-06T03:33:00Z", + "modified": "2024-02-13T18:38:23Z", "published": "2024-02-06T03:33:00Z", "aliases": [ "CVE-2024-22773" ], "details": "Intelbras Roteador ACtion RF 1200 1.2.2 esposes the Password in Cookie resulting in Login Bypass.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -20,7 +23,7 @@ }, { "type": "WEB", - "url": "https://medium.com/%40wagneralves_87750/poc-cve-2024-22773-febf0d3a5433" + "url": "https://medium.com/@wagneralves_87750/poc-cve-2024-22773-febf0d3a5433" }, { "type": "WEB", @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T01:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-cf6q-mwq5-j3p8/GHSA-cf6q-mwq5-j3p8.json b/advisories/unreviewed/2024/02/GHSA-cf6q-mwq5-j3p8/GHSA-cf6q-mwq5-j3p8.json index d6480ec93ae..6892c3a4c3c 100644 --- a/advisories/unreviewed/2024/02/GHSA-cf6q-mwq5-j3p8/GHSA-cf6q-mwq5-j3p8.json +++ b/advisories/unreviewed/2024/02/GHSA-cf6q-mwq5-j3p8/GHSA-cf6q-mwq5-j3p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf6q-mwq5-j3p8", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0709" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3024040%40cryptocurrency-price-ticker-widget&new=3024040%40cryptocurrency-price-ticker-widget&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3024040@cryptocurrency-price-ticker-widget&new=3024040@cryptocurrency-price-ticker-widget&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-cqc2-xcqm-6c3r/GHSA-cqc2-xcqm-6c3r.json b/advisories/unreviewed/2024/02/GHSA-cqc2-xcqm-6c3r/GHSA-cqc2-xcqm-6c3r.json new file mode 100644 index 00000000000..9fb0198b6f3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cqc2-xcqm-6c3r/GHSA-cqc2-xcqm-6c3r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqc2-xcqm-6c3r", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2023-26562" + ], + "details": "In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26562" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cqc3-wp4c-vrcw/GHSA-cqc3-wp4c-vrcw.json b/advisories/unreviewed/2024/02/GHSA-cqc3-wp4c-vrcw/GHSA-cqc3-wp4c-vrcw.json new file mode 100644 index 00000000000..0ca5e78356d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cqc3-wp4c-vrcw/GHSA-cqc3-wp4c-vrcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqc3-wp4c-vrcw", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21360" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21360" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21360" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json b/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json new file mode 100644 index 00000000000..c6ff4501673 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvwm-qh2r-q68h", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2023-20570" + ], + "details": "Insufficient verification of data authenticity in\nthe configuration state machine may allow a local attacker to potentially load\narbitrary bitstreams.\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20570" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cx6w-8xmj-8g7f/GHSA-cx6w-8xmj-8g7f.json b/advisories/unreviewed/2024/02/GHSA-cx6w-8xmj-8g7f/GHSA-cx6w-8xmj-8g7f.json new file mode 100644 index 00000000000..af751b7d4e0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cx6w-8xmj-8g7f/GHSA-cx6w-8xmj-8g7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx6w-8xmj-8g7f", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-20679" + ], + "details": "Azure Stack Hub Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20679" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20679" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-f36v-g487-9gfr/GHSA-f36v-g487-9gfr.json b/advisories/unreviewed/2024/02/GHSA-f36v-g487-9gfr/GHSA-f36v-g487-9gfr.json new file mode 100644 index 00000000000..6734a992fec --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-f36v-g487-9gfr/GHSA-f36v-g487-9gfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f36v-g487-9gfr", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21350" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21350" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21350" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fpcm-3c3x-8cpj/GHSA-fpcm-3c3x-8cpj.json b/advisories/unreviewed/2024/02/GHSA-fpcm-3c3x-8cpj/GHSA-fpcm-3c3x-8cpj.json new file mode 100644 index 00000000000..eba388f8134 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fpcm-3c3x-8cpj/GHSA-fpcm-3c3x-8cpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpcm-3c3x-8cpj", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21391" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21391" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21391" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json b/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json new file mode 100644 index 00000000000..547825873e0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fv4p-ghwr-3g9x/GHSA-fv4p-ghwr-3g9x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv4p-ghwr-3g9x", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21389" + ], + "details": "Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21389" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21389" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fvvm-3cr2-6qx2/GHSA-fvvm-3cr2-6qx2.json b/advisories/unreviewed/2024/02/GHSA-fvvm-3cr2-6qx2/GHSA-fvvm-3cr2-6qx2.json index 10239adc2f0..2ab27861248 100644 --- a/advisories/unreviewed/2024/02/GHSA-fvvm-3cr2-6qx2/GHSA-fvvm-3cr2-6qx2.json +++ b/advisories/unreviewed/2024/02/GHSA-fvvm-3cr2-6qx2/GHSA-fvvm-3cr2-6qx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fvvm-3cr2-6qx2", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0668" @@ -31,7 +31,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3025980/" + "url": "https://plugins.trac.wordpress.org/changeset/3025980" }, { "type": "WEB", @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-fvwf-g95f-ccmf/GHSA-fvwf-g95f-ccmf.json b/advisories/unreviewed/2024/02/GHSA-fvwf-g95f-ccmf/GHSA-fvwf-g95f-ccmf.json new file mode 100644 index 00000000000..41bf2107347 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fvwf-g95f-ccmf/GHSA-fvwf-g95f-ccmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvwf-g95f-ccmf", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21368" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21368" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21368" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fx4r-wq66-f4g2/GHSA-fx4r-wq66-f4g2.json b/advisories/unreviewed/2024/02/GHSA-fx4r-wq66-f4g2/GHSA-fx4r-wq66-f4g2.json new file mode 100644 index 00000000000..0570e326879 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fx4r-wq66-f4g2/GHSA-fx4r-wq66-f4g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx4r-wq66-f4g2", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21346" + ], + "details": "Win32k Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21346" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g7rx-4mww-c3pc/GHSA-g7rx-4mww-c3pc.json b/advisories/unreviewed/2024/02/GHSA-g7rx-4mww-c3pc/GHSA-g7rx-4mww-c3pc.json index 0f713eee7dd..4569b7633a1 100644 --- a/advisories/unreviewed/2024/02/GHSA-g7rx-4mww-c3pc/GHSA-g7rx-4mww-c3pc.json +++ b/advisories/unreviewed/2024/02/GHSA-g7rx-4mww-c3pc/GHSA-g7rx-4mww-c3pc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7rx-4mww-c3pc", - "modified": "2024-02-06T00:30:26Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2023-6996" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3021133%40shortcode-to-display-post-and-user-data&new=3021133%40shortcode-to-display-post-and-user-data&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3021133@shortcode-to-display-post-and-user-data&new=3021133@shortcode-to-display-post-and-user-data&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json b/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json new file mode 100644 index 00000000000..56d276f8533 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc2m-7496-w444", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2023-45207" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browser, the stored XSS payload is executed. (This has been mitigated by sanitising the JavaScript code present in a PDF document.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45207" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gcw7-pj2v-4p7m/GHSA-gcw7-pj2v-4p7m.json b/advisories/unreviewed/2024/02/GHSA-gcw7-pj2v-4p7m/GHSA-gcw7-pj2v-4p7m.json new file mode 100644 index 00000000000..ab358b03b51 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gcw7-pj2v-4p7m/GHSA-gcw7-pj2v-4p7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcw7-pj2v-4p7m", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21372" + ], + "details": "Windows OLE Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21372" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21372" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gf24-7549-v36h/GHSA-gf24-7549-v36h.json b/advisories/unreviewed/2024/02/GHSA-gf24-7549-v36h/GHSA-gf24-7549-v36h.json index af1c343b6e9..dbc0756ffd2 100644 --- a/advisories/unreviewed/2024/02/GHSA-gf24-7549-v36h/GHSA-gf24-7549-v36h.json +++ b/advisories/unreviewed/2024/02/GHSA-gf24-7549-v36h/GHSA-gf24-7549-v36h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf24-7549-v36h", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0509" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-gg34-hfvm-v359/GHSA-gg34-hfvm-v359.json b/advisories/unreviewed/2024/02/GHSA-gg34-hfvm-v359/GHSA-gg34-hfvm-v359.json new file mode 100644 index 00000000000..cee510872c6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gg34-hfvm-v359/GHSA-gg34-hfvm-v359.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg34-hfvm-v359", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-20684" + ], + "details": "Windows Hyper-V Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20684" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20684" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-ghm8-g3hr-5g26/GHSA-ghm8-g3hr-5g26.json b/advisories/unreviewed/2024/02/GHSA-ghm8-g3hr-5g26/GHSA-ghm8-g3hr-5g26.json new file mode 100644 index 00000000000..cea1880e692 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-ghm8-g3hr-5g26/GHSA-ghm8-g3hr-5g26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghm8-g3hr-5g26", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21402" + ], + "details": "Microsoft Outlook Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21402" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21402" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h3h7-g394-rv9x/GHSA-h3h7-g394-rv9x.json b/advisories/unreviewed/2024/02/GHSA-h3h7-g394-rv9x/GHSA-h3h7-g394-rv9x.json new file mode 100644 index 00000000000..933a940a7ee --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h3h7-g394-rv9x/GHSA-h3h7-g394-rv9x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3h7-g394-rv9x", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21377" + ], + "details": "Windows DNS Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21377" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21377" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h5mw-2rhw-phqc/GHSA-h5mw-2rhw-phqc.json b/advisories/unreviewed/2024/02/GHSA-h5mw-2rhw-phqc/GHSA-h5mw-2rhw-phqc.json new file mode 100644 index 00000000000..f866063410a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h5mw-2rhw-phqc/GHSA-h5mw-2rhw-phqc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5mw-2rhw-phqc", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21340" + ], + "details": "Windows Kernel Information Disclosure Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21340" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21340" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h5xg-83p6-j59j/GHSA-h5xg-83p6-j59j.json b/advisories/unreviewed/2024/02/GHSA-h5xg-83p6-j59j/GHSA-h5xg-83p6-j59j.json new file mode 100644 index 00000000000..9d4d6bd9764 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h5xg-83p6-j59j/GHSA-h5xg-83p6-j59j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5xg-83p6-j59j", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21367" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21367" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21367" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json b/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json new file mode 100644 index 00000000000..89feb0f9126 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hrqx-cgrg-w5g9/GHSA-hrqx-cgrg-w5g9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrqx-cgrg-w5g9", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21395" + ], + "details": "Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21395" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21395" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json b/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json index d38942305d5..1774facd6d5 100644 --- a/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json +++ b/advisories/unreviewed/2024/02/GHSA-hxw7-jqv7-6h7r/GHSA-hxw7-jqv7-6h7r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxw7-jqv7-6h7r", - "modified": "2024-02-06T03:32:59Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T03:32:59Z", "aliases": [ "CVE-2023-47889" ], "details": "The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device to send unauthorized broadcasts, leading to unintended consequences. The vulnerability is particularly concerning because these actions include powering off, system reboot & entering recovery mode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T01:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j7vw-8r54-mfcg/GHSA-j7vw-8r54-mfcg.json b/advisories/unreviewed/2024/02/GHSA-j7vw-8r54-mfcg/GHSA-j7vw-8r54-mfcg.json new file mode 100644 index 00000000000..6a70b874fca --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j7vw-8r54-mfcg/GHSA-j7vw-8r54-mfcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7vw-8r54-mfcg", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21315" + ], + "details": "Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21315" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21315" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jfg2-j67c-965p/GHSA-jfg2-j67c-965p.json b/advisories/unreviewed/2024/02/GHSA-jfg2-j67c-965p/GHSA-jfg2-j67c-965p.json new file mode 100644 index 00000000000..79fc9838408 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jfg2-j67c-965p/GHSA-jfg2-j67c-965p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfg2-j67c-965p", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21401" + ], + "details": "Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21401" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21401" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jm96-wx9p-8wm4/GHSA-jm96-wx9p-8wm4.json b/advisories/unreviewed/2024/02/GHSA-jm96-wx9p-8wm4/GHSA-jm96-wx9p-8wm4.json new file mode 100644 index 00000000000..4abf5fa2a53 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jm96-wx9p-8wm4/GHSA-jm96-wx9p-8wm4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm96-wx9p-8wm4", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21406" + ], + "details": "Windows Printing Service Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21406" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21406" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json b/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json new file mode 100644 index 00000000000..3c528c47b48 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqrq-gqwg-r8r5", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21338" + ], + "details": "Windows Kernel Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21338" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json b/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json index 01431c7dad8..dc6a436eefa 100644 --- a/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json +++ b/advisories/unreviewed/2024/02/GHSA-m6p7-jxxh-vc8c/GHSA-m6p7-jxxh-vc8c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-m8j5-w72j-565q/GHSA-m8j5-w72j-565q.json b/advisories/unreviewed/2024/02/GHSA-m8j5-w72j-565q/GHSA-m8j5-w72j-565q.json new file mode 100644 index 00000000000..c10485fa8db --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m8j5-w72j-565q/GHSA-m8j5-w72j-565q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8j5-w72j-565q", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21341" + ], + "details": "Windows Kernel Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21341" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21341" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json b/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json index e1684d4388c..f38f6216e17 100644 --- a/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json +++ b/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf92-wvmg-38g9", - "modified": "2024-02-05T18:31:37Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-05T18:31:37Z", "aliases": [ "CVE-2023-47355" ], "details": "The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-05T16:15:54Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json b/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json index 8dde54626b6..d48059905fd 100644 --- a/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json +++ b/advisories/unreviewed/2024/02/GHSA-mf94-378q-xvc3/GHSA-mf94-378q-xvc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf94-378q-xvc3", - "modified": "2024-02-06T03:32:59Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T03:32:59Z", "aliases": [ "CVE-2023-47022" ], "details": "An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the payload parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T01:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mgrh-9mx5-cjmf/GHSA-mgrh-9mx5-cjmf.json b/advisories/unreviewed/2024/02/GHSA-mgrh-9mx5-cjmf/GHSA-mgrh-9mx5-cjmf.json index 059b8ddb52b..4d6d34ce25d 100644 --- a/advisories/unreviewed/2024/02/GHSA-mgrh-9mx5-cjmf/GHSA-mgrh-9mx5-cjmf.json +++ b/advisories/unreviewed/2024/02/GHSA-mgrh-9mx5-cjmf/GHSA-mgrh-9mx5-cjmf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-mm8h-v6fv-cf89/GHSA-mm8h-v6fv-cf89.json b/advisories/unreviewed/2024/02/GHSA-mm8h-v6fv-cf89/GHSA-mm8h-v6fv-cf89.json new file mode 100644 index 00000000000..812c97421a4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mm8h-v6fv-cf89/GHSA-mm8h-v6fv-cf89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm8h-v6fv-cf89", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21347" + ], + "details": "Microsoft ODBC Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21347" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21347" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mv5v-r4x4-qmxw/GHSA-mv5v-r4x4-qmxw.json b/advisories/unreviewed/2024/02/GHSA-mv5v-r4x4-qmxw/GHSA-mv5v-r4x4-qmxw.json new file mode 100644 index 00000000000..1e819eb881e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mv5v-r4x4-qmxw/GHSA-mv5v-r4x4-qmxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv5v-r4x4-qmxw", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21410" + ], + "details": "Microsoft Exchange Server Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21410" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json b/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json index bab7f665d43..702ce729c53 100644 --- a/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json +++ b/advisories/unreviewed/2024/02/GHSA-p3gm-xxh4-xjmg/GHSA-p3gm-xxh4-xjmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3gm-xxh4-xjmg", - "modified": "2024-02-06T03:32:59Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T03:32:59Z", "aliases": [ "CVE-2023-46359" ], "details": "An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -20,7 +23,7 @@ }, { "type": "WEB", - "url": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360/" + "url": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360" }, { "type": "WEB", @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T01:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-q4pm-3jvq-rm3m/GHSA-q4pm-3jvq-rm3m.json b/advisories/unreviewed/2024/02/GHSA-q4pm-3jvq-rm3m/GHSA-q4pm-3jvq-rm3m.json new file mode 100644 index 00000000000..eec94fb1466 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q4pm-3jvq-rm3m/GHSA-q4pm-3jvq-rm3m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4pm-3jvq-rm3m", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21359" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21359" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21359" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q5x8-3vm4-xrh9/GHSA-q5x8-3vm4-xrh9.json b/advisories/unreviewed/2024/02/GHSA-q5x8-3vm4-xrh9/GHSA-q5x8-3vm4-xrh9.json new file mode 100644 index 00000000000..07361e9007f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q5x8-3vm4-xrh9/GHSA-q5x8-3vm4-xrh9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5x8-3vm4-xrh9", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21404" + ], + "details": ".NET Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21404" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21404" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q658-fh2m-cgvf/GHSA-q658-fh2m-cgvf.json b/advisories/unreviewed/2024/02/GHSA-q658-fh2m-cgvf/GHSA-q658-fh2m-cgvf.json index 5fdd0ae605a..9d8a8d19c15 100644 --- a/advisories/unreviewed/2024/02/GHSA-q658-fh2m-cgvf/GHSA-q658-fh2m-cgvf.json +++ b/advisories/unreviewed/2024/02/GHSA-q658-fh2m-cgvf/GHSA-q658-fh2m-cgvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q658-fh2m-cgvf", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0366" @@ -27,7 +27,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3028775/starbox/trunk?contextall=1&old=3000701&old_path=%2Fstarbox%2Ftrunk" + "url": "https://plugins.trac.wordpress.org/changeset/3028775/starbox/trunk?contextall=1&old=3000701&old_path=/starbox/trunk" }, { "type": "WEB", @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-qc5h-6jxv-459g/GHSA-qc5h-6jxv-459g.json b/advisories/unreviewed/2024/02/GHSA-qc5h-6jxv-459g/GHSA-qc5h-6jxv-459g.json new file mode 100644 index 00000000000..794265669c8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qc5h-6jxv-459g/GHSA-qc5h-6jxv-459g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc5h-6jxv-459g", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21339" + ], + "details": "Windows USB Generic Parent Driver Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21339" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21339" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qm4q-xhjm-67jr/GHSA-qm4q-xhjm-67jr.json b/advisories/unreviewed/2024/02/GHSA-qm4q-xhjm-67jr/GHSA-qm4q-xhjm-67jr.json new file mode 100644 index 00000000000..2a970cfb506 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qm4q-xhjm-67jr/GHSA-qm4q-xhjm-67jr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm4q-xhjm-67jr", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21378" + ], + "details": "Microsoft Outlook Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21378" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21378" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qvh3-fxm2-mgw9/GHSA-qvh3-fxm2-mgw9.json b/advisories/unreviewed/2024/02/GHSA-qvh3-fxm2-mgw9/GHSA-qvh3-fxm2-mgw9.json new file mode 100644 index 00000000000..8d24f29d08c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qvh3-fxm2-mgw9/GHSA-qvh3-fxm2-mgw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvh3-fxm2-mgw9", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-20667" + ], + "details": "Azure DevOps Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20667" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20667" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r5m6-pgh6-qg26/GHSA-r5m6-pgh6-qg26.json b/advisories/unreviewed/2024/02/GHSA-r5m6-pgh6-qg26/GHSA-r5m6-pgh6-qg26.json index ba694d93838..9fd5044d635 100644 --- a/advisories/unreviewed/2024/02/GHSA-r5m6-pgh6-qg26/GHSA-r5m6-pgh6-qg26.json +++ b/advisories/unreviewed/2024/02/GHSA-r5m6-pgh6-qg26/GHSA-r5m6-pgh6-qg26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r5m6-pgh6-qg26", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0508" @@ -31,7 +31,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset/3021959/" + "url": "https://plugins.trac.wordpress.org/changeset/3021959" }, { "type": "WEB", @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-r7jr-h86x-vvx4/GHSA-r7jr-h86x-vvx4.json b/advisories/unreviewed/2024/02/GHSA-r7jr-h86x-vvx4/GHSA-r7jr-h86x-vvx4.json new file mode 100644 index 00000000000..913bcf2d724 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r7jr-h86x-vvx4/GHSA-r7jr-h86x-vvx4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7jr-h86x-vvx4", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21374" + ], + "details": "Microsoft Teams for Android Information Disclosure", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21374" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21374" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rmw7-92wx-897r/GHSA-rmw7-92wx-897r.json b/advisories/unreviewed/2024/02/GHSA-rmw7-92wx-897r/GHSA-rmw7-92wx-897r.json index eec56253465..104eb469471 100644 --- a/advisories/unreviewed/2024/02/GHSA-rmw7-92wx-897r/GHSA-rmw7-92wx-897r.json +++ b/advisories/unreviewed/2024/02/GHSA-rmw7-92wx-897r/GHSA-rmw7-92wx-897r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rmw7-92wx-897r", - "modified": "2024-02-06T00:30:27Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0448" @@ -31,7 +31,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3026261%40addons-for-elementor%2Ftrunk&old=3022220%40addons-for-elementor%2Ftrunk&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3026261@addons-for-elementor/trunk&old=3022220@addons-for-elementor/trunk&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-v22x-x62x-q5qj/GHSA-v22x-x62x-q5qj.json b/advisories/unreviewed/2024/02/GHSA-v22x-x62x-q5qj/GHSA-v22x-x62x-q5qj.json new file mode 100644 index 00000000000..fcbe6836192 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v22x-x62x-q5qj/GHSA-v22x-x62x-q5qj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v22x-x62x-q5qj", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21356" + ], + "details": "Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21356" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21356" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json index 334b038c7ac..352992110c6 100644 --- a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json +++ b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5qp-mx94-j49v", - "modified": "2024-02-13T15:31:12Z", + "modified": "2024-02-13T18:38:23Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5679" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-5679" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-v87j-jxhf-9vq2/GHSA-v87j-jxhf-9vq2.json b/advisories/unreviewed/2024/02/GHSA-v87j-jxhf-9vq2/GHSA-v87j-jxhf-9vq2.json new file mode 100644 index 00000000000..0f6cd9cdaba --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v87j-jxhf-9vq2/GHSA-v87j-jxhf-9vq2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v87j-jxhf-9vq2", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21381" + ], + "details": "Microsoft Azure Active Directory B2C Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21381" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21381" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v92p-76ff-mghv/GHSA-v92p-76ff-mghv.json b/advisories/unreviewed/2024/02/GHSA-v92p-76ff-mghv/GHSA-v92p-76ff-mghv.json index 284ce1fbf80..82425ba74b1 100644 --- a/advisories/unreviewed/2024/02/GHSA-v92p-76ff-mghv/GHSA-v92p-76ff-mghv.json +++ b/advisories/unreviewed/2024/02/GHSA-v92p-76ff-mghv/GHSA-v92p-76ff-mghv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v92p-76ff-mghv", - "modified": "2024-02-06T00:30:26Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2023-6983" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3021133%40shortcode-to-display-post-and-user-data&new=3021133%40shortcode-to-display-post-and-user-data&sfp_email=&sfph_mail=" + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3021133@shortcode-to-display-post-and-user-data&new=3021133@shortcode-to-display-post-and-user-data&sfp_email=&sfph_mail=" }, { "type": "WEB", @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-vr63-2xjh-w46r/GHSA-vr63-2xjh-w46r.json b/advisories/unreviewed/2024/02/GHSA-vr63-2xjh-w46r/GHSA-vr63-2xjh-w46r.json new file mode 100644 index 00000000000..0015b29a73c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vr63-2xjh-w46r/GHSA-vr63-2xjh-w46r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr63-2xjh-w46r", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21361" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21361" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21361" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w457-v52w-2vrw/GHSA-w457-v52w-2vrw.json b/advisories/unreviewed/2024/02/GHSA-w457-v52w-2vrw/GHSA-w457-v52w-2vrw.json new file mode 100644 index 00000000000..f2352431792 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w457-v52w-2vrw/GHSA-w457-v52w-2vrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w457-v52w-2vrw", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21349" + ], + "details": "Microsoft ActiveX Data Objects Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21349" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21349" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json b/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json new file mode 100644 index 00000000000..71b4af49ce3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w4vx-2pcg-383r/GHSA-w4vx-2pcg-383r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4vx-2pcg-383r", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21351" + ], + "details": "Windows SmartScreen Security Feature Bypass Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21351" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21351" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wc83-vppr-rx5r/GHSA-wc83-vppr-rx5r.json b/advisories/unreviewed/2024/02/GHSA-wc83-vppr-rx5r/GHSA-wc83-vppr-rx5r.json new file mode 100644 index 00000000000..c130018369a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wc83-vppr-rx5r/GHSA-wc83-vppr-rx5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc83-vppr-rx5r", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21364" + ], + "details": "Microsoft Azure Site Recovery Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21364" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21364" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wg47-w2rm-c8gx/GHSA-wg47-w2rm-c8gx.json b/advisories/unreviewed/2024/02/GHSA-wg47-w2rm-c8gx/GHSA-wg47-w2rm-c8gx.json new file mode 100644 index 00000000000..2d53397c5d3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wg47-w2rm-c8gx/GHSA-wg47-w2rm-c8gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg47-w2rm-c8gx", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21365" + ], + "details": "Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21365" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21365" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wg5g-2465-7f45/GHSA-wg5g-2465-7f45.json b/advisories/unreviewed/2024/02/GHSA-wg5g-2465-7f45/GHSA-wg5g-2465-7f45.json new file mode 100644 index 00000000000..b261115b408 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wg5g-2465-7f45/GHSA-wg5g-2465-7f45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg5g-2465-7f45", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-21328" + ], + "details": "Dynamics 365 Sales Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21328" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21328" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json b/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json new file mode 100644 index 00000000000..99f35135b57 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wrwv-3pqq-rr32/GHSA-wrwv-3pqq-rr32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrwv-3pqq-rr32", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21393" + ], + "details": "Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21393" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21393" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json b/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json new file mode 100644 index 00000000000..e7ef6aada2f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wwqr-wgwc-gj85/GHSA-wwqr-wgwc-gj85.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwqr-wgwc-gj85", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2024-20673" + ], + "details": "Microsoft Office Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20673" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20673" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json b/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json index 28c3a2be44f..6b619205bb7 100644 --- a/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json +++ b/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x547-pm2q-2cr6", - "modified": "2024-02-06T03:32:59Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-06T03:32:59Z", "aliases": [ "CVE-2023-46360" ], "details": "Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -20,7 +23,7 @@ }, { "type": "WEB", - "url": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360/" + "url": "https://www.offensity.com/en/blog/os-command-injection-in-cph2-charging-station-200-cve-2023-46359-and-cve-2023-46360" }, { "type": "WEB", @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-06T01:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x57c-56xp-xrph/GHSA-x57c-56xp-xrph.json b/advisories/unreviewed/2024/02/GHSA-x57c-56xp-xrph/GHSA-x57c-56xp-xrph.json new file mode 100644 index 00000000000..715ad08a0f3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x57c-56xp-xrph/GHSA-x57c-56xp-xrph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x57c-56xp-xrph", + "modified": "2024-02-13T18:38:24Z", + "published": "2024-02-13T18:38:24Z", + "aliases": [ + "CVE-2024-21379" + ], + "details": "Microsoft Word Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21379" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21379" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json index 23557114d5d..f5204239c69 100644 --- a/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json +++ b/advisories/unreviewed/2024/02/GHSA-x57x-3c65-5f3j/GHSA-x57x-3c65-5f3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x57x-3c65-5f3j", - "modified": "2024-02-13T15:31:12Z", + "modified": "2024-02-13T18:38:22Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-4408" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-4408" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json index 62b662e2ca3..3bbe24c20eb 100644 --- a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json +++ b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcvq-77qq-2wpx", - "modified": "2024-02-13T15:31:12Z", + "modified": "2024-02-13T18:38:23Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2023-5517" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://kb.isc.org/docs/cve-2023-5517" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/13/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-xrq6-qp2x-fh89/GHSA-xrq6-qp2x-fh89.json b/advisories/unreviewed/2024/02/GHSA-xrq6-qp2x-fh89/GHSA-xrq6-qp2x-fh89.json index 5199b46d9ba..c5909334172 100644 --- a/advisories/unreviewed/2024/02/GHSA-xrq6-qp2x-fh89/GHSA-xrq6-qp2x-fh89.json +++ b/advisories/unreviewed/2024/02/GHSA-xrq6-qp2x-fh89/GHSA-xrq6-qp2x-fh89.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json b/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json new file mode 100644 index 00000000000..71d7ca998bc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvvw-m6mf-m9hw", + "modified": "2024-02-13T18:38:23Z", + "published": "2024-02-13T18:38:23Z", + "aliases": [ + "CVE-2023-48432" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48432" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-13T16:15:08Z" + } +} \ No newline at end of file