Publish Advisories

GHSA-69g2-mv93-2xq7
GHSA-6fc3-8g79-3f39
GHSA-6pww-pf77-29vx
GHSA-cqfh-c4c5-c2hg
GHSA-j697-hfvp-rhxg
GHSA-pc95-3wgm-x28p
GHSA-q8g7-2p5j-49jv
GHSA-vjqq-2qj5-4qr7
GHSA-vrcc-m4x7-8j47
GHSA-g8hw-gxg5-v62g
GHSA-pwfh-2pj9-f3rc
GHSA-rj29-jj8r-f77v
GHSA-3vvg-gmfw-pmm4
GHSA-4j37-x4vf-9p6c
GHSA-fp9x-9r68-jr5q
GHSA-gp65-r3h2-m7mh
GHSA-px8f-pf56-946w
GHSA-q632-7v8j-586g
GHSA-q98g-hxg3-268c
GHSA-wm5r-jw2j-wfcp
GHSA-xmm6-6gqm-6vjq
This commit is contained in:
advisory-database[bot]
2024-08-28 15:32:42 +00:00
parent bc263058c9
commit b900f1d965
21 changed files with 186 additions and 47 deletions
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fc3-8g79-3f39",
"modified": "2024-03-25T06:30:24Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-1962"
],
"details": "The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T05:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pww-pf77-29vx",
"modified": "2024-03-14T00:31:04Z",
"modified": "2024-08-28T15:31:12Z",
"published": "2024-03-08T03:31:24Z",
"aliases": [
"CVE-2024-23216"
],
"details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to overwrite arbitrary files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -45,9 +48,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-08T02:15:47Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqfh-c4c5-c2hg",
"modified": "2024-03-28T00:31:40Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-03-28T00:31:40Z",
"aliases": [
"CVE-2024-25354"
],
"details": "RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-27T22:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j697-hfvp-rhxg",
"modified": "2024-03-13T18:31:34Z",
"modified": "2024-08-28T15:31:12Z",
"published": "2024-03-13T18:31:34Z",
"aliases": [
"CVE-2024-28669"
],
"details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_edit.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-13T16:15:30Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc95-3wgm-x28p",
"modified": "2024-03-22T06:30:23Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-03-22T06:30:23Z",
"aliases": [
"CVE-2024-29271"
],
"details": "Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-22T04:15:11Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8g7-2p5j-49jv",
"modified": "2024-03-09T06:30:41Z",
"modified": "2024-08-28T15:31:12Z",
"published": "2024-03-09T06:30:41Z",
"aliases": [
"CVE-2023-46427"
],
"details": "An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in media_tools/dash_client.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-09T06:15:50Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjqq-2qj5-4qr7",
"modified": "2024-03-13T18:31:35Z",
"modified": "2024-08-28T15:31:12Z",
"published": "2024-03-13T18:31:35Z",
"aliases": [
"CVE-2024-28682"
],
"details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/sys_cache_up.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-13T16:15:30Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vrcc-m4x7-8j47",
"modified": "2024-03-12T18:31:14Z",
"modified": "2024-08-28T15:31:12Z",
"published": "2024-03-12T18:31:14Z",
"aliases": [
"CVE-2024-28339"
],
"details": "An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-12T17:15:59Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8hw-gxg5-v62g",
"modified": "2024-08-23T18:32:57Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-06-13T18:31:58Z",
"aliases": [
"CVE-2024-35325"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://github.com/idhyt/pocs/blob/main/libyaml/CVE-2024-35325.c"
},
{
"type": "WEB",
"url": "https://github.com/idhyt/pocs/tree/main/libyaml"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwfh-2pj9-f3rc",
"modified": "2024-07-19T15:31:46Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-06-13T18:31:58Z",
"aliases": [
"CVE-2024-35328"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://github.com/idhyt/pocs/blob/main/libyaml/CVE-2024-35328.c"
},
{
"type": "WEB",
"url": "https://github.com/idhyt/pocs/tree/main/libyaml"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rj29-jj8r-f77v",
"modified": "2024-08-06T18:30:50Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-06-13T18:31:58Z",
"aliases": [
"CVE-2024-35326"
@@ -21,9 +21,21 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35326"
},
{
"type": "WEB",
"url": "https://github.com/yaml/libyaml/issues/298"
},
{
"type": "WEB",
"url": "https://github.com/yaml/libyaml/issues/302"
},
{
"type": "WEB",
"url": "https://github.com/idhyt/pocs/blob/main/libyaml/CVE-2024-35326.c"
},
{
"type": "WEB",
"url": "https://github.com/idhyt/pocs/tree/main/libyaml"
}
],
"database_specific": {
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vvg-gmfw-pmm4",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-08-28T15:31:13Z",
"aliases": [
"CVE-2024-8195"
],
"details": "The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to extract sensitive data including password, title, and content of password-protected posts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8195"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.4.4/includes/core/permalink-manager-debug.php#L70"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3142479"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aadf1d59-60ba-4da2-adbb-4e84d587a34d?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-28T14:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j37-x4vf-9p6c",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-08-28T15:31:13Z",
"aliases": [
"CVE-2024-34198"
],
"details": "TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying an excessively long value for the wlan_ssid field, leading to a stack overflow. This can be further exploited to execute arbitrary commands or launch denial-of-service attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34198"
},
{
"type": "WEB",
"url": "https://gist.github.com/Swind1er/02f6cb414e440c34878f20fef756e286"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-28T15:15:16Z"
}
}
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gp65-r3h2-m7mh",
"modified": "2024-08-27T21:31:13Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-08-27T21:31:13Z",
"aliases": [
"CVE-2022-39997"
],
"details": "A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-521"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T19:15:15Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-px8f-pf56-946w",
"modified": "2024-08-27T18:31:38Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-08-27T18:31:38Z",
"aliases": [
"CVE-2024-7720"
],
"details": "HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-27T18:15:15Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q632-7v8j-586g",
"modified": "2024-08-19T18:32:07Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-08-19T06:30:54Z",
"aliases": [
"CVE-2024-44083"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44083"
},
{
"type": "WEB",
"url": "https://github.com/Azvanzed/CVE-2024-44083"
},
{
"type": "WEB",
"url": "https://github.com/Azvanzed/IdaMeme"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q98g-hxg3-268c",
"modified": "2024-08-23T18:33:00Z",
"modified": "2024-08-28T15:31:13Z",
"published": "2024-08-22T21:31:29Z",
"aliases": [
"CVE-2024-8088"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://github.com/python/cpython/issues/122905"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/issues/123270"
},
{
"type": "WEB",
"url": "https://github.com/python/cpython/pull/122906"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More