From b9391832450e6085de403a9fc1dd1dda05a1e227 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 25 Sep 2022 00:09:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pv7r-v4qc-v4gq.json | 10 ++-- .../GHSA-574v-3xxh-gwh5.json | 4 ++ .../GHSA-q5p3-3mpm-hppr.json | 2 +- .../GHSA-4v97-3733-h7mw.json | 2 +- .../GHSA-9q6c-grq3-7prg.json | 2 +- .../GHSA-25vq-j8q6-c4xv.json | 7 ++- .../GHSA-3xxr-x7rp-pc4x.json | 7 ++- .../GHSA-42g8-62v3-2jg8.json | 7 ++- .../GHSA-659h-rq95-r222.json | 7 ++- .../GHSA-6gph-499x-vm5j.json | 8 ++- .../GHSA-8q2m-9hf9-7qq4.json | 7 ++- .../GHSA-8vw4-xv4w-x2mf.json | 7 ++- .../GHSA-95xc-mm75-h3v2.json | 7 ++- .../GHSA-c8h9-xgqx-fc49.json | 8 ++- .../GHSA-ccc3-9cpj-334h.json | 7 ++- .../GHSA-cgwf-g22v-w6c6.json | 8 ++- .../GHSA-cj6h-3w4g-pcm8.json | 7 ++- .../GHSA-g52j-gcmf-jf6c.json | 7 ++- .../GHSA-g8xw-6mmv-frg4.json | 7 ++- .../GHSA-hmpv-pvg5-4fpq.json | 8 ++- .../GHSA-j677-7992-mrpc.json | 7 ++- .../GHSA-qgmh-w9pv-x25v.json | 7 ++- .../GHSA-r7rr-ghh8-j4p9.json | 7 ++- .../GHSA-v5gp-rv55-crrm.json | 7 ++- .../GHSA-wp7q-xrrh-6rxg.json | 7 ++- .../GHSA-x2gj-m25r-2923.json | 7 ++- .../GHSA-x6fw-fv3x-rwmc.json | 8 ++- .../GHSA-xxpf-vv2v-cfqq.json | 7 ++- .../GHSA-3rm2-w8f7-h7rf.json | 4 ++ .../GHSA-4h78-xq9p-vv4g.json | 4 ++ .../GHSA-5948-4f22-j6wp.json | 8 +++ .../GHSA-g8qv-x989-399f.json | 12 +++++ .../GHSA-h66w-323g-4q62.json | 4 ++ .../GHSA-22jw-r3jv-5f4f.json | 53 +++++++++++++++++++ .../GHSA-239x-qr9g-j39q.json | 53 +++++++++++++++++++ .../GHSA-255p-hfwr-9qm4.json | 33 ++++++++++++ .../GHSA-25qf-mc6x-fm76.json | 37 +++++++++++++ .../GHSA-27m4-83f2-2x77.json | 33 ++++++++++++ .../GHSA-27v6-4m9p-3qq4.json | 11 ++-- .../GHSA-27wf-832r-r7vc.json | 11 ++-- .../GHSA-29pj-cw86-x2fg.json | 53 +++++++++++++++++++ .../GHSA-2h7v-c8c8-vxg7.json | 11 ++-- .../GHSA-2hr4-jcq5-r7fq.json | 11 ++-- .../GHSA-2vq2-xc55-3j5m.json | 4 ++ .../GHSA-2wqp-mx6p-m496.json | 9 ++-- .../GHSA-3229-cmr6-cvgv.json | 37 +++++++++++++ .../GHSA-32c6-653x-x3pm.json | 10 ++-- .../GHSA-33v4-rh3c-mhcg.json | 4 ++ .../GHSA-349w-cgp3-287r.json | 15 ++++-- .../GHSA-3686-mp4v-qv73.json | 37 +++++++++++++ .../GHSA-37cj-9g83-7692.json | 11 ++-- .../GHSA-37g5-jpqm-9jr7.json | 9 ++-- .../GHSA-38q5-v7xx-c8c6.json | 37 +++++++++++++ .../GHSA-3cjx-7cj6-qvq3.json | 33 ++++++++++++ .../GHSA-3mg9-m3f6-v7fq.json | 36 +++++++++++++ .../GHSA-3mgp-qhxh-6rqh.json | 12 +++++ .../GHSA-3qjj-8gwh-qxvc.json | 33 ++++++++++++ .../GHSA-42hx-vrxx-5r6v.json | 33 ++++++++++++ .../GHSA-49c7-gf66-cc93.json | 9 ++-- .../GHSA-4c97-vhfm-xx23.json | 41 ++++++++++++++ .../GHSA-4cf6-725j-v28m.json | 11 ++-- .../GHSA-4jx6-c96p-4mcx.json | 45 ++++++++++++++++ .../GHSA-4m4c-mm78-3pcw.json | 37 +++++++++++++ .../GHSA-4m75-cr73-v7hw.json | 11 ++-- .../GHSA-4rrx-m76x-mwvv.json | 33 ++++++++++++ .../GHSA-4vr4-w499-9g67.json | 33 ++++++++++++ .../GHSA-4vvq-7gfj-3jv6.json | 37 +++++++++++++ .../GHSA-4w54-c3hg-qqrv.json | 33 ++++++++++++ .../GHSA-4xjp-gp7m-jj8v.json | 33 ++++++++++++ .../GHSA-526f-868j-w52f.json | 33 ++++++++++++ .../GHSA-532v-wmjj-rx65.json | 33 ++++++++++++ .../GHSA-54xp-94gx-wj5g.json | 33 ++++++++++++ .../GHSA-55x8-6vhc-2mmm.json | 11 ++-- .../GHSA-57v8-x3g4-p832.json | 9 ++-- .../GHSA-57ww-qgjv-3g3c.json | 33 ++++++++++++ .../GHSA-5c8r-r849-xgpp.json | 33 ++++++++++++ .../GHSA-5fp5-vv6c-j2hj.json | 40 ++++++++++++++ .../GHSA-5g39-p52c-vm53.json | 33 ++++++++++++ .../GHSA-5j86-vmpx-42pc.json | 11 ++-- .../GHSA-5q53-x3g6-993r.json | 11 ++-- .../GHSA-5qv2-q3p3-26r4.json | 45 ++++++++++++++++ .../GHSA-5rj5-5628-7w5m.json | 53 +++++++++++++++++++ .../GHSA-5rp7-42mh-ggj9.json | 37 +++++++++++++ .../GHSA-5rr9-5h6r-5qx9.json | 37 +++++++++++++ .../GHSA-5v5c-3mjh-2c2w.json | 37 +++++++++++++ .../GHSA-5v8v-cp6r-mq7c.json | 45 ++++++++++++++++ .../GHSA-5vfq-rv44-c5ff.json | 15 ++++-- .../GHSA-5wwv-hh2v-ww89.json | 37 +++++++++++++ .../GHSA-5xm4-48v6-7p2f.json | 40 ++++++++++++++ .../GHSA-637r-47cq-j74p.json | 11 ++-- .../GHSA-669q-4gjm-8895.json | 40 ++++++++++++++ .../GHSA-6827-ch9x-qwxf.json | 37 +++++++++++++ .../GHSA-6859-c7gv-hqq5.json | 40 ++++++++++++++ .../GHSA-692h-cj57-w2g9.json | 41 ++++++++++++++ .../GHSA-69cg-p879-7622.json | 4 ++ .../GHSA-6fg9-5q9c-4fp2.json | 53 +++++++++++++++++++ .../GHSA-6grm-385j-c2m8.json | 33 ++++++++++++ .../GHSA-6h2q-3hc7-cvj3.json | 9 ++-- .../GHSA-6h67-m47q-xj4p.json | 33 ++++++++++++ .../GHSA-6jg8-m9ff-fv96.json | 11 ++-- .../GHSA-6jr7-xr67-mgxw.json | 8 +++ .../GHSA-6mqc-jm93-59f3.json | 40 ++++++++++++++ .../GHSA-6mqr-f9rh-mggr.json | 49 +++++++++++++++++ .../GHSA-6r33-cjf7-78gm.json | 37 +++++++++++++ .../GHSA-6v4j-97pm-7wc2.json | 37 +++++++++++++ .../GHSA-6v9f-3xw7-vjj9.json | 37 +++++++++++++ .../GHSA-72hv-vf28-v4jh.json | 33 ++++++++++++ .../GHSA-72rp-xxph-m42m.json | 33 ++++++++++++ .../GHSA-7373-2gf3-53wq.json | 37 +++++++++++++ .../GHSA-738c-cx4m-7gvx.json | 33 ++++++++++++ .../GHSA-74m6-rqc7-wfvx.json | 41 ++++++++++++++ .../GHSA-74v5-x8gw-q8f8.json | 33 ++++++++++++ .../GHSA-75p4-j454-hrjv.json | 33 ++++++++++++ .../GHSA-779j-v68w-458w.json | 33 ++++++++++++ .../GHSA-7853-2h44-89w4.json | 11 ++-- .../GHSA-7873-9v2g-3whm.json | 36 +++++++++++++ .../GHSA-79xc-f76g-hpg4.json | 49 +++++++++++++++++ .../GHSA-7m65-hmvg-rxpc.json | 11 ++-- .../GHSA-7mrh-jrcg-wc76.json | 15 ++++-- .../GHSA-7r3w-wggm-pjwf.json | 15 ++++-- .../GHSA-7rw7-2244-fpqf.json | 33 ++++++++++++ .../GHSA-7vg3-f99h-353x.json | 41 ++++++++++++++ .../GHSA-7wq7-cmgr-8g2v.json | 37 +++++++++++++ .../GHSA-82hg-7wf7-rhvf.json | 37 +++++++++++++ .../GHSA-84fw-3p4m-3vrc.json | 49 +++++++++++++++++ .../GHSA-87wp-c9x7-ppq5.json | 11 ++-- .../GHSA-89gf-mhc4-x76w.json | 33 ++++++++++++ .../GHSA-8cpp-2498-rv3h.json | 33 ++++++++++++ .../GHSA-8hwf-7cch-jr9v.json | 11 ++-- .../GHSA-8jh8-j7rp-79hx.json | 37 +++++++++++++ .../GHSA-8p5p-w63v-mxqh.json | 45 ++++++++++++++++ .../GHSA-8qv5-68g4-248j.json | 37 +++++++++++++ .../GHSA-8r7q-9xwv-2g7p.json | 9 ++-- .../GHSA-8rp5-857c-f5pv.json | 37 +++++++++++++ .../GHSA-8xcf-8ggp-m7gj.json | 36 +++++++++++++ .../GHSA-955x-77q4-5vqw.json | 53 +++++++++++++++++++ .../GHSA-96g3-wc5j-4mh5.json | 37 +++++++++++++ .../GHSA-986h-37wj-r876.json | 33 ++++++++++++ .../GHSA-98r4-4f3j-q239.json | 36 +++++++++++++ .../GHSA-99gj-9798-gpx5.json | 33 ++++++++++++ .../GHSA-9fj7-9qg7-9fgc.json | 53 +++++++++++++++++++ .../GHSA-9h9x-w962-5wpc.json | 33 ++++++++++++ .../GHSA-9m56-6xhm-cg4f.json | 33 ++++++++++++ .../GHSA-9mq2-v988-m7mr.json | 15 ++++-- .../GHSA-9rwx-hp6q-64m8.json | 53 +++++++++++++++++++ .../GHSA-9vv6-62qf-hh55.json | 36 +++++++++++++ .../GHSA-9w7j-q3xw-p9vh.json | 41 ++++++++++++++ .../GHSA-9x4q-463c-8gcm.json | 37 +++++++++++++ .../GHSA-9xw6-hr9q-88xg.json | 33 ++++++++++++ .../GHSA-c2f5-g88r-g7jp.json | 9 ++-- .../GHSA-c38j-ccr2-v3jw.json | 41 ++++++++++++++ .../GHSA-c3cj-4xxg-mg34.json | 33 ++++++++++++ .../GHSA-c429-5p7v-vgjp.json | 37 +++++++++++++ .../GHSA-c5fp-x2h5-vjv7.json | 33 ++++++++++++ .../GHSA-c5x2-5cvx-r2ch.json | 37 +++++++++++++ .../GHSA-c65m-86j4-57vv.json | 9 ++-- .../GHSA-c7hp-7v7r-r7v9.json | 33 ++++++++++++ .../GHSA-c92m-jh9p-prmj.json | 37 +++++++++++++ .../GHSA-c99w-7r7q-cgcx.json | 37 +++++++++++++ .../GHSA-c9wp-mpwg-qr66.json | 41 ++++++++++++++ .../GHSA-cc3x-hwc5-9pfq.json | 9 ++-- .../GHSA-cc8c-93xf-8jgq.json | 37 +++++++++++++ .../GHSA-cfqx-4cch-8hgx.json | 37 +++++++++++++ .../GHSA-cfw9-4m3h-gp62.json | 9 ++-- .../GHSA-cpqw-x96c-hvhh.json | 40 ++++++++++++++ .../GHSA-cqmx-6jcw-hqpm.json | 40 ++++++++++++++ .../GHSA-f399-ff4w-62fm.json | 11 ++-- .../GHSA-f54m-mh6r-hqvj.json | 53 +++++++++++++++++++ .../GHSA-f56r-hm9p-96h7.json | 37 +++++++++++++ .../GHSA-f67v-5x5c-x8vr.json | 11 ++-- .../GHSA-f888-gr94-8gvj.json | 9 ++-- .../GHSA-f8p7-rhpm-pg98.json | 49 +++++++++++++++++ .../GHSA-fhc7-6h7r-f5p6.json | 36 +++++++++++++ .../GHSA-g5xp-5m3c-87v8.json | 37 +++++++++++++ .../GHSA-g83j-rjq4-8487.json | 4 ++ .../GHSA-g993-5jgg-hxg6.json | 33 ++++++++++++ .../GHSA-g9j7-8vx6-5gr7.json | 8 +++ .../GHSA-g9qq-f6m5-gmx2.json | 37 +++++++++++++ .../GHSA-ggg4-hcxv-87v9.json | 9 ++-- .../GHSA-ggv8-q2cf-2vxj.json | 11 ++-- .../GHSA-gj8c-59qc-mfr6.json | 41 ++++++++++++++ .../GHSA-gjh8-h6gp-pqgr.json | 11 ++-- .../GHSA-gm96-5f79-f6q3.json | 40 ++++++++++++++ .../GHSA-gmgf-76vr-x3ch.json | 33 ++++++++++++ .../GHSA-grmw-xj5w-6h62.json | 37 +++++++++++++ .../GHSA-gv26-x27m-rfg3.json | 33 ++++++++++++ .../GHSA-gxrc-qj6f-5vph.json | 33 ++++++++++++ .../GHSA-h3j4-vfr6-r3jp.json | 33 ++++++++++++ .../GHSA-h886-rpm5-x6pr.json | 11 ++-- .../GHSA-h9c4-pjqq-xffc.json | 11 ++-- .../GHSA-hf58-wxpq-9pg5.json | 40 ++++++++++++++ .../GHSA-hh3j-qq6p-7797.json | 40 ++++++++++++++ .../GHSA-hhrc-f68j-f28p.json | 33 ++++++++++++ .../GHSA-hhx4-8rv9-cwrp.json | 41 ++++++++++++++ .../GHSA-hhxh-qphc-v423.json | 33 ++++++++++++ .../GHSA-hj8m-g2fw-34rv.json | 44 +++++++++++++++ .../GHSA-hr3v-8cp3-68rf.json | 40 ++++++++++++++ .../GHSA-hw62-5m9w-9pm8.json | 11 ++-- .../GHSA-j3q4-gmj4-mj95.json | 37 +++++++++++++ .../GHSA-j3qw-g67q-7m64.json | 33 ++++++++++++ .../GHSA-j588-5q9c-p6xm.json | 11 ++-- .../GHSA-j65m-4mmp-29cm.json | 9 ++-- .../GHSA-j6c2-g387-8rqr.json | 37 +++++++++++++ .../GHSA-j78f-66qm-2mcw.json | 40 ++++++++++++++ .../GHSA-j82j-q47h-ph2c.json | 37 +++++++++++++ .../GHSA-j85x-2g6q-qxvf.json | 33 ++++++++++++ .../GHSA-j8gh-qgf7-j54p.json | 33 ++++++++++++ .../GHSA-jcg9-774r-mm8x.json | 36 +++++++++++++ .../GHSA-jjrw-xpw9-v3qh.json | 45 ++++++++++++++++ .../GHSA-jq8c-j47c-vvwm.json | 11 ++-- .../GHSA-jv5x-4hfr-x3p5.json | 33 ++++++++++++ .../GHSA-jvf3-mfxv-jcqr.json | 33 ++++++++++++ .../GHSA-jvpp-mw65-r55x.json | 33 ++++++++++++ .../GHSA-jx87-887q-554q.json | 33 ++++++++++++ .../GHSA-m69r-9g56-7mv8.json | 37 +++++++++++++ .../GHSA-m7rj-3phc-xm3w.json | 33 ++++++++++++ .../GHSA-m7w4-q5vg-5xfp.json | 37 +++++++++++++ .../GHSA-m864-5788-g574.json | 33 ++++++++++++ .../GHSA-mchf-7f36-58fj.json | 37 +++++++++++++ .../GHSA-mcxh-2w23-3cf7.json | 45 ++++++++++++++++ .../GHSA-mhpj-fprx-gcxh.json | 9 ++-- .../GHSA-mmj5-42wx-3r4f.json | 49 +++++++++++++++++ .../GHSA-p235-xqcv-9xrg.json | 41 ++++++++++++++ .../GHSA-p294-p2wv-22g4.json | 44 +++++++++++++++ .../GHSA-p38h-v883-px7v.json | 49 +++++++++++++++++ .../GHSA-p7g7-h68c-47c2.json | 41 ++++++++++++++ .../GHSA-p7m9-fxq8-hp5x.json | 37 +++++++++++++ .../GHSA-p8vh-mwc9-r3jw.json | 49 +++++++++++++++++ .../GHSA-ph7r-3p2x-7pq8.json | 37 +++++++++++++ .../GHSA-pp63-cgj5-h996.json | 53 +++++++++++++++++++ .../GHSA-pqxc-54m5-8r8m.json | 11 ++-- .../GHSA-pv7f-h3w8-w3jh.json | 37 +++++++++++++ .../GHSA-pv83-hp5m-9f24.json | 37 +++++++++++++ .../GHSA-pvw2-9h4r-c5cr.json | 33 ++++++++++++ .../GHSA-pwp2-44q5-vv6j.json | 4 ++ .../GHSA-pwpx-qj2c-fq5c.json | 40 ++++++++++++++ .../GHSA-q3cp-h2hv-r3mf.json | 33 ++++++++++++ .../GHSA-q3f4-9h4p-vgr3.json | 45 ++++++++++++++++ .../GHSA-q472-4r55-2p86.json | 41 ++++++++++++++ .../GHSA-q638-4gfp-67hc.json | 9 ++-- .../GHSA-q63w-g4hg-gvcw.json | 33 ++++++++++++ .../GHSA-q979-9m39-23mq.json | 33 ++++++++++++ .../GHSA-q9pg-4hmx-4cfv.json | 37 +++++++++++++ .../GHSA-qc3c-r429-gpgf.json | 33 ++++++++++++ .../GHSA-qc73-wjpr-m8fj.json | 37 +++++++++++++ .../GHSA-qf6h-wr49-rv76.json | 33 ++++++++++++ .../GHSA-qfmw-4w5x-xhxf.json | 36 +++++++++++++ .../GHSA-qfvq-h39h-4m98.json | 9 ++-- .../GHSA-qhg4-wfwm-7qcr.json | 37 +++++++++++++ .../GHSA-qhg5-w79j-3jj3.json | 9 ++-- .../GHSA-qj68-h3qr-6vgv.json | 37 +++++++++++++ .../GHSA-qj7c-f3xj-jxpv.json | 33 ++++++++++++ .../GHSA-qj9p-jvmw-82rh.json | 33 ++++++++++++ .../GHSA-qrj8-rh2f-3cj9.json | 11 ++-- .../GHSA-qrqm-574x-q7f2.json | 9 ++-- .../GHSA-qv87-xvw7-xfrc.json | 33 ++++++++++++ .../GHSA-r5vg-678j-p7m4.json | 33 ++++++++++++ .../GHSA-rggh-c47v-5wh6.json | 37 +++++++++++++ .../GHSA-rjp4-q5qr-3cqx.json | 53 +++++++++++++++++++ .../GHSA-rm7v-mc66-6r49.json | 4 ++ .../GHSA-rpm3-vf32-w565.json | 37 +++++++++++++ .../GHSA-rq7v-mq45-xcm2.json | 37 +++++++++++++ .../GHSA-rrrr-cw7x-rf7j.json | 40 ++++++++++++++ .../GHSA-rrv6-26r4-h5pj.json | 45 ++++++++++++++++ .../GHSA-rvg5-w7ph-h5wx.json | 33 ++++++++++++ .../GHSA-rvjg-x555-jh28.json | 37 +++++++++++++ .../GHSA-rvpq-xxmq-5x83.json | 9 ++-- .../GHSA-rvxx-h83g-7vgf.json | 11 ++-- .../GHSA-rwg3-p25f-fp5x.json | 37 +++++++++++++ .../GHSA-v2qf-2g23-xmcg.json | 37 +++++++++++++ .../GHSA-v44q-v8rf-3m92.json | 41 ++++++++++++++ .../GHSA-v525-vvmv-fh2m.json | 37 +++++++++++++ .../GHSA-v5mm-c2pr-7qgh.json | 37 +++++++++++++ .../GHSA-v5rw-hwp6-gf94.json | 37 +++++++++++++ .../GHSA-v9wp-86gv-6c8f.json | 33 ++++++++++++ .../GHSA-v9xf-qq9q-332r.json | 33 ++++++++++++ .../GHSA-vc7q-8w3h-jx8q.json | 11 ++-- .../GHSA-vcqh-2q2g-pgc3.json | 33 ++++++++++++ .../GHSA-vhxm-j92c-jf79.json | 40 ++++++++++++++ .../GHSA-vqgp-46r4-f6j8.json | 33 ++++++++++++ .../GHSA-w2rj-3rf3-w34g.json | 33 ++++++++++++ .../GHSA-w397-9p2j-6x23.json | 11 ++-- .../GHSA-w76j-g6q7-46hq.json | 45 ++++++++++++++++ .../GHSA-wff9-xm82-6wp2.json | 41 ++++++++++++++ .../GHSA-wffm-j7m8-93g4.json | 11 ++-- .../GHSA-wgh8-h75r-c4qw.json | 37 +++++++++++++ .../GHSA-wh36-484v-vm65.json | 33 ++++++++++++ .../GHSA-whxv-p57p-v97w.json | 37 +++++++++++++ .../GHSA-wj23-j559-8mf4.json | 37 +++++++++++++ .../GHSA-wj87-2328-6c5m.json | 37 +++++++++++++ .../GHSA-wjvx-p9xx-8cxp.json | 40 ++++++++++++++ .../GHSA-ww8h-58w2-5v3c.json | 9 ++-- .../GHSA-x2rq-mrc8-r79h.json | 44 +++++++++++++++ .../GHSA-x92w-hx54-ffh8.json | 9 ++-- .../GHSA-xc4f-pxh3-qwrq.json | 36 +++++++++++++ .../GHSA-xch5-pwh8-cf69.json | 45 ++++++++++++++++ .../GHSA-xg7c-263c-79vp.json | 37 +++++++++++++ .../GHSA-xhpr-rjf3-gg6p.json | 37 +++++++++++++ .../GHSA-xhq5-7429-4hrv.json | 41 ++++++++++++++ .../GHSA-xmxp-x783-v5rx.json | 36 +++++++++++++ .../GHSA-xrmg-5x28-jv6w.json | 37 +++++++++++++ .../GHSA-xx24-pg44-2jhw.json | 37 +++++++++++++ 302 files changed, 8288 insertions(+), 262 deletions(-) create mode 100644 advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json create mode 100644 advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json create mode 100644 advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json create mode 100644 advisories/unreviewed/2022/09/GHSA-25qf-mc6x-fm76/GHSA-25qf-mc6x-fm76.json create mode 100644 advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json create mode 100644 advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json create mode 100644 advisories/unreviewed/2022/09/GHSA-3229-cmr6-cvgv/GHSA-3229-cmr6-cvgv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-3686-mp4v-qv73/GHSA-3686-mp4v-qv73.json create mode 100644 advisories/unreviewed/2022/09/GHSA-38q5-v7xx-c8c6/GHSA-38q5-v7xx-c8c6.json create mode 100644 advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json create mode 100644 advisories/unreviewed/2022/09/GHSA-3mg9-m3f6-v7fq/GHSA-3mg9-m3f6-v7fq.json create mode 100644 advisories/unreviewed/2022/09/GHSA-3qjj-8gwh-qxvc/GHSA-3qjj-8gwh-qxvc.json create mode 100644 advisories/unreviewed/2022/09/GHSA-42hx-vrxx-5r6v/GHSA-42hx-vrxx-5r6v.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4c97-vhfm-xx23/GHSA-4c97-vhfm-xx23.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4jx6-c96p-4mcx/GHSA-4jx6-c96p-4mcx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4m4c-mm78-3pcw/GHSA-4m4c-mm78-3pcw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4rrx-m76x-mwvv/GHSA-4rrx-m76x-mwvv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4vr4-w499-9g67/GHSA-4vr4-w499-9g67.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4vvq-7gfj-3jv6/GHSA-4vvq-7gfj-3jv6.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4w54-c3hg-qqrv/GHSA-4w54-c3hg-qqrv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-4xjp-gp7m-jj8v/GHSA-4xjp-gp7m-jj8v.json create mode 100644 advisories/unreviewed/2022/09/GHSA-526f-868j-w52f/GHSA-526f-868j-w52f.json create mode 100644 advisories/unreviewed/2022/09/GHSA-532v-wmjj-rx65/GHSA-532v-wmjj-rx65.json create mode 100644 advisories/unreviewed/2022/09/GHSA-54xp-94gx-wj5g/GHSA-54xp-94gx-wj5g.json create mode 100644 advisories/unreviewed/2022/09/GHSA-57ww-qgjv-3g3c/GHSA-57ww-qgjv-3g3c.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5c8r-r849-xgpp/GHSA-5c8r-r849-xgpp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5fp5-vv6c-j2hj/GHSA-5fp5-vv6c-j2hj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5g39-p52c-vm53/GHSA-5g39-p52c-vm53.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5qv2-q3p3-26r4/GHSA-5qv2-q3p3-26r4.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5rj5-5628-7w5m/GHSA-5rj5-5628-7w5m.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5rp7-42mh-ggj9/GHSA-5rp7-42mh-ggj9.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5rr9-5h6r-5qx9/GHSA-5rr9-5h6r-5qx9.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5v5c-3mjh-2c2w/GHSA-5v5c-3mjh-2c2w.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5wwv-hh2v-ww89/GHSA-5wwv-hh2v-ww89.json create mode 100644 advisories/unreviewed/2022/09/GHSA-5xm4-48v6-7p2f/GHSA-5xm4-48v6-7p2f.json create mode 100644 advisories/unreviewed/2022/09/GHSA-669q-4gjm-8895/GHSA-669q-4gjm-8895.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6827-ch9x-qwxf/GHSA-6827-ch9x-qwxf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6859-c7gv-hqq5/GHSA-6859-c7gv-hqq5.json create mode 100644 advisories/unreviewed/2022/09/GHSA-692h-cj57-w2g9/GHSA-692h-cj57-w2g9.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6fg9-5q9c-4fp2/GHSA-6fg9-5q9c-4fp2.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6grm-385j-c2m8/GHSA-6grm-385j-c2m8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6h67-m47q-xj4p/GHSA-6h67-m47q-xj4p.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6mqc-jm93-59f3/GHSA-6mqc-jm93-59f3.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6mqr-f9rh-mggr/GHSA-6mqr-f9rh-mggr.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6r33-cjf7-78gm/GHSA-6r33-cjf7-78gm.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6v4j-97pm-7wc2/GHSA-6v4j-97pm-7wc2.json create mode 100644 advisories/unreviewed/2022/09/GHSA-6v9f-3xw7-vjj9/GHSA-6v9f-3xw7-vjj9.json create mode 100644 advisories/unreviewed/2022/09/GHSA-72hv-vf28-v4jh/GHSA-72hv-vf28-v4jh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-72rp-xxph-m42m/GHSA-72rp-xxph-m42m.json create mode 100644 advisories/unreviewed/2022/09/GHSA-7373-2gf3-53wq/GHSA-7373-2gf3-53wq.json create mode 100644 advisories/unreviewed/2022/09/GHSA-738c-cx4m-7gvx/GHSA-738c-cx4m-7gvx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-74m6-rqc7-wfvx/GHSA-74m6-rqc7-wfvx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-74v5-x8gw-q8f8/GHSA-74v5-x8gw-q8f8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-75p4-j454-hrjv/GHSA-75p4-j454-hrjv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-779j-v68w-458w/GHSA-779j-v68w-458w.json create mode 100644 advisories/unreviewed/2022/09/GHSA-7873-9v2g-3whm/GHSA-7873-9v2g-3whm.json create mode 100644 advisories/unreviewed/2022/09/GHSA-79xc-f76g-hpg4/GHSA-79xc-f76g-hpg4.json create mode 100644 advisories/unreviewed/2022/09/GHSA-7rw7-2244-fpqf/GHSA-7rw7-2244-fpqf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-7vg3-f99h-353x/GHSA-7vg3-f99h-353x.json create mode 100644 advisories/unreviewed/2022/09/GHSA-7wq7-cmgr-8g2v/GHSA-7wq7-cmgr-8g2v.json create mode 100644 advisories/unreviewed/2022/09/GHSA-82hg-7wf7-rhvf/GHSA-82hg-7wf7-rhvf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-84fw-3p4m-3vrc/GHSA-84fw-3p4m-3vrc.json create mode 100644 advisories/unreviewed/2022/09/GHSA-89gf-mhc4-x76w/GHSA-89gf-mhc4-x76w.json create mode 100644 advisories/unreviewed/2022/09/GHSA-8cpp-2498-rv3h/GHSA-8cpp-2498-rv3h.json create mode 100644 advisories/unreviewed/2022/09/GHSA-8jh8-j7rp-79hx/GHSA-8jh8-j7rp-79hx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-8p5p-w63v-mxqh/GHSA-8p5p-w63v-mxqh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-8qv5-68g4-248j/GHSA-8qv5-68g4-248j.json create mode 100644 advisories/unreviewed/2022/09/GHSA-8rp5-857c-f5pv/GHSA-8rp5-857c-f5pv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-8xcf-8ggp-m7gj/GHSA-8xcf-8ggp-m7gj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-955x-77q4-5vqw/GHSA-955x-77q4-5vqw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-96g3-wc5j-4mh5/GHSA-96g3-wc5j-4mh5.json create mode 100644 advisories/unreviewed/2022/09/GHSA-986h-37wj-r876/GHSA-986h-37wj-r876.json create mode 100644 advisories/unreviewed/2022/09/GHSA-98r4-4f3j-q239/GHSA-98r4-4f3j-q239.json create mode 100644 advisories/unreviewed/2022/09/GHSA-99gj-9798-gpx5/GHSA-99gj-9798-gpx5.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9fj7-9qg7-9fgc/GHSA-9fj7-9qg7-9fgc.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9h9x-w962-5wpc/GHSA-9h9x-w962-5wpc.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9m56-6xhm-cg4f/GHSA-9m56-6xhm-cg4f.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9rwx-hp6q-64m8/GHSA-9rwx-hp6q-64m8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9vv6-62qf-hh55/GHSA-9vv6-62qf-hh55.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9w7j-q3xw-p9vh/GHSA-9w7j-q3xw-p9vh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9x4q-463c-8gcm/GHSA-9x4q-463c-8gcm.json create mode 100644 advisories/unreviewed/2022/09/GHSA-9xw6-hr9q-88xg/GHSA-9xw6-hr9q-88xg.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c38j-ccr2-v3jw/GHSA-c38j-ccr2-v3jw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c3cj-4xxg-mg34/GHSA-c3cj-4xxg-mg34.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c429-5p7v-vgjp/GHSA-c429-5p7v-vgjp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c5fp-x2h5-vjv7/GHSA-c5fp-x2h5-vjv7.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c5x2-5cvx-r2ch/GHSA-c5x2-5cvx-r2ch.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c7hp-7v7r-r7v9/GHSA-c7hp-7v7r-r7v9.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c92m-jh9p-prmj/GHSA-c92m-jh9p-prmj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c99w-7r7q-cgcx/GHSA-c99w-7r7q-cgcx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-c9wp-mpwg-qr66/GHSA-c9wp-mpwg-qr66.json create mode 100644 advisories/unreviewed/2022/09/GHSA-cc8c-93xf-8jgq/GHSA-cc8c-93xf-8jgq.json create mode 100644 advisories/unreviewed/2022/09/GHSA-cfqx-4cch-8hgx/GHSA-cfqx-4cch-8hgx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-cpqw-x96c-hvhh/GHSA-cpqw-x96c-hvhh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-cqmx-6jcw-hqpm/GHSA-cqmx-6jcw-hqpm.json create mode 100644 advisories/unreviewed/2022/09/GHSA-f54m-mh6r-hqvj/GHSA-f54m-mh6r-hqvj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-f56r-hm9p-96h7/GHSA-f56r-hm9p-96h7.json create mode 100644 advisories/unreviewed/2022/09/GHSA-f8p7-rhpm-pg98/GHSA-f8p7-rhpm-pg98.json create mode 100644 advisories/unreviewed/2022/09/GHSA-fhc7-6h7r-f5p6/GHSA-fhc7-6h7r-f5p6.json create mode 100644 advisories/unreviewed/2022/09/GHSA-g5xp-5m3c-87v8/GHSA-g5xp-5m3c-87v8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-g993-5jgg-hxg6/GHSA-g993-5jgg-hxg6.json create mode 100644 advisories/unreviewed/2022/09/GHSA-g9qq-f6m5-gmx2/GHSA-g9qq-f6m5-gmx2.json create mode 100644 advisories/unreviewed/2022/09/GHSA-gj8c-59qc-mfr6/GHSA-gj8c-59qc-mfr6.json create mode 100644 advisories/unreviewed/2022/09/GHSA-gm96-5f79-f6q3/GHSA-gm96-5f79-f6q3.json create mode 100644 advisories/unreviewed/2022/09/GHSA-gmgf-76vr-x3ch/GHSA-gmgf-76vr-x3ch.json create mode 100644 advisories/unreviewed/2022/09/GHSA-grmw-xj5w-6h62/GHSA-grmw-xj5w-6h62.json create mode 100644 advisories/unreviewed/2022/09/GHSA-gv26-x27m-rfg3/GHSA-gv26-x27m-rfg3.json create mode 100644 advisories/unreviewed/2022/09/GHSA-gxrc-qj6f-5vph/GHSA-gxrc-qj6f-5vph.json create mode 100644 advisories/unreviewed/2022/09/GHSA-h3j4-vfr6-r3jp/GHSA-h3j4-vfr6-r3jp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hf58-wxpq-9pg5/GHSA-hf58-wxpq-9pg5.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hh3j-qq6p-7797/GHSA-hh3j-qq6p-7797.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hhrc-f68j-f28p/GHSA-hhrc-f68j-f28p.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hhx4-8rv9-cwrp/GHSA-hhx4-8rv9-cwrp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hhxh-qphc-v423/GHSA-hhxh-qphc-v423.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hj8m-g2fw-34rv/GHSA-hj8m-g2fw-34rv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-hr3v-8cp3-68rf/GHSA-hr3v-8cp3-68rf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j3q4-gmj4-mj95/GHSA-j3q4-gmj4-mj95.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j3qw-g67q-7m64/GHSA-j3qw-g67q-7m64.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j6c2-g387-8rqr/GHSA-j6c2-g387-8rqr.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j78f-66qm-2mcw/GHSA-j78f-66qm-2mcw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j82j-q47h-ph2c/GHSA-j82j-q47h-ph2c.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j85x-2g6q-qxvf/GHSA-j85x-2g6q-qxvf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-j8gh-qgf7-j54p/GHSA-j8gh-qgf7-j54p.json create mode 100644 advisories/unreviewed/2022/09/GHSA-jcg9-774r-mm8x/GHSA-jcg9-774r-mm8x.json create mode 100644 advisories/unreviewed/2022/09/GHSA-jjrw-xpw9-v3qh/GHSA-jjrw-xpw9-v3qh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-jv5x-4hfr-x3p5/GHSA-jv5x-4hfr-x3p5.json create mode 100644 advisories/unreviewed/2022/09/GHSA-jvf3-mfxv-jcqr/GHSA-jvf3-mfxv-jcqr.json create mode 100644 advisories/unreviewed/2022/09/GHSA-jvpp-mw65-r55x/GHSA-jvpp-mw65-r55x.json create mode 100644 advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json create mode 100644 advisories/unreviewed/2022/09/GHSA-m69r-9g56-7mv8/GHSA-m69r-9g56-7mv8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-m7rj-3phc-xm3w/GHSA-m7rj-3phc-xm3w.json create mode 100644 advisories/unreviewed/2022/09/GHSA-m7w4-q5vg-5xfp/GHSA-m7w4-q5vg-5xfp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json create mode 100644 advisories/unreviewed/2022/09/GHSA-mchf-7f36-58fj/GHSA-mchf-7f36-58fj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json create mode 100644 advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json create mode 100644 advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json create mode 100644 advisories/unreviewed/2022/09/GHSA-p294-p2wv-22g4/GHSA-p294-p2wv-22g4.json create mode 100644 advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json create mode 100644 advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json create mode 100644 advisories/unreviewed/2022/09/GHSA-p7m9-fxq8-hp5x/GHSA-p7m9-fxq8-hp5x.json create mode 100644 advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-ph7r-3p2x-7pq8/GHSA-ph7r-3p2x-7pq8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-pp63-cgj5-h996/GHSA-pp63-cgj5-h996.json create mode 100644 advisories/unreviewed/2022/09/GHSA-pv7f-h3w8-w3jh/GHSA-pv7f-h3w8-w3jh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-pv83-hp5m-9f24/GHSA-pv83-hp5m-9f24.json create mode 100644 advisories/unreviewed/2022/09/GHSA-pvw2-9h4r-c5cr/GHSA-pvw2-9h4r-c5cr.json create mode 100644 advisories/unreviewed/2022/09/GHSA-pwpx-qj2c-fq5c/GHSA-pwpx-qj2c-fq5c.json create mode 100644 advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-q3f4-9h4p-vgr3/GHSA-q3f4-9h4p-vgr3.json create mode 100644 advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json create mode 100644 advisories/unreviewed/2022/09/GHSA-q63w-g4hg-gvcw/GHSA-q63w-g4hg-gvcw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-q979-9m39-23mq/GHSA-q979-9m39-23mq.json create mode 100644 advisories/unreviewed/2022/09/GHSA-q9pg-4hmx-4cfv/GHSA-q9pg-4hmx-4cfv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qfmw-4w5x-xhxf/GHSA-qfmw-4w5x-xhxf.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qhg4-wfwm-7qcr/GHSA-qhg4-wfwm-7qcr.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qj68-h3qr-6vgv/GHSA-qj68-h3qr-6vgv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qj9p-jvmw-82rh/GHSA-qj9p-jvmw-82rh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json create mode 100644 advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rggh-c47v-5wh6/GHSA-rggh-c47v-5wh6.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rpm3-vf32-w565/GHSA-rpm3-vf32-w565.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rq7v-mq45-xcm2/GHSA-rq7v-mq45-xcm2.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rrrr-cw7x-rf7j/GHSA-rrrr-cw7x-rf7j.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rrv6-26r4-h5pj/GHSA-rrv6-26r4-h5pj.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rvg5-w7ph-h5wx/GHSA-rvg5-w7ph-h5wx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rvjg-x555-jh28/GHSA-rvjg-x555-jh28.json create mode 100644 advisories/unreviewed/2022/09/GHSA-rwg3-p25f-fp5x/GHSA-rwg3-p25f-fp5x.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v2qf-2g23-xmcg/GHSA-v2qf-2g23-xmcg.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v525-vvmv-fh2m/GHSA-v525-vvmv-fh2m.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v5rw-hwp6-gf94/GHSA-v5rw-hwp6-gf94.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json create mode 100644 advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json create mode 100644 advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json create mode 100644 advisories/unreviewed/2022/09/GHSA-vhxm-j92c-jf79/GHSA-vhxm-j92c-jf79.json create mode 100644 advisories/unreviewed/2022/09/GHSA-vqgp-46r4-f6j8/GHSA-vqgp-46r4-f6j8.json create mode 100644 advisories/unreviewed/2022/09/GHSA-w2rj-3rf3-w34g/GHSA-w2rj-3rf3-w34g.json create mode 100644 advisories/unreviewed/2022/09/GHSA-w76j-g6q7-46hq/GHSA-w76j-g6q7-46hq.json create mode 100644 advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json create mode 100644 advisories/unreviewed/2022/09/GHSA-wgh8-h75r-c4qw/GHSA-wgh8-h75r-c4qw.json create mode 100644 advisories/unreviewed/2022/09/GHSA-wh36-484v-vm65/GHSA-wh36-484v-vm65.json create mode 100644 advisories/unreviewed/2022/09/GHSA-whxv-p57p-v97w/GHSA-whxv-p57p-v97w.json create mode 100644 advisories/unreviewed/2022/09/GHSA-wj23-j559-8mf4/GHSA-wj23-j559-8mf4.json create mode 100644 advisories/unreviewed/2022/09/GHSA-wj87-2328-6c5m/GHSA-wj87-2328-6c5m.json create mode 100644 advisories/unreviewed/2022/09/GHSA-wjvx-p9xx-8cxp/GHSA-wjvx-p9xx-8cxp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xc4f-pxh3-qwrq/GHSA-xc4f-pxh3-qwrq.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xch5-pwh8-cf69/GHSA-xch5-pwh8-cf69.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xg7c-263c-79vp/GHSA-xg7c-263c-79vp.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xhpr-rjf3-gg6p/GHSA-xhpr-rjf3-gg6p.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xmxp-x783-v5rx/GHSA-xmxp-x783-v5rx.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xrmg-5x28-jv6w/GHSA-xrmg-5x28-jv6w.json create mode 100644 advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json diff --git a/advisories/unreviewed/2021/12/GHSA-pv7r-v4qc-v4gq/GHSA-pv7r-v4qc-v4gq.json b/advisories/unreviewed/2021/12/GHSA-pv7r-v4qc-v4gq/GHSA-pv7r-v4qc-v4gq.json index 2525ec230da..d897e26e57c 100644 --- a/advisories/unreviewed/2021/12/GHSA-pv7r-v4qc-v4gq/GHSA-pv7r-v4qc-v4gq.json +++ b/advisories/unreviewed/2021/12/GHSA-pv7r-v4qc-v4gq/GHSA-pv7r-v4qc-v4gq.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-pv7r-v4qc-v4gq", - "modified": "2021-12-14T00:01:38Z", + "modified": "2022-09-25T00:00:18Z", "published": "2021-12-09T00:00:53Z", "aliases": [ "CVE-2021-25518" ], "details": "An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false diff --git a/advisories/unreviewed/2022/03/GHSA-574v-3xxh-gwh5/GHSA-574v-3xxh-gwh5.json b/advisories/unreviewed/2022/03/GHSA-574v-3xxh-gwh5/GHSA-574v-3xxh-gwh5.json index 41e42979fbc..d5b82bc523a 100644 --- a/advisories/unreviewed/2022/03/GHSA-574v-3xxh-gwh5/GHSA-574v-3xxh-gwh5.json +++ b/advisories/unreviewed/2022/03/GHSA-574v-3xxh-gwh5/GHSA-574v-3xxh-gwh5.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://www.incibe-cert.es/en/early-warning/security-advisories/tp-link-tapo-c200-remote-code-execution-vulnerability" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/168472/TP-Link-Tapo-c200-1.1.15-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json b/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json index f914066d5cc..9c1c4a33ce9 100644 --- a/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json +++ b/advisories/unreviewed/2022/03/GHSA-q5p3-3mpm-hppr/GHSA-q5p3-3mpm-hppr.json @@ -1,7 +1,7 @@ { "schema_version": "1.3.0", "id": "GHSA-q5p3-3mpm-hppr", - "modified": "2022-04-30T00:01:02Z", + "modified": "2022-09-25T00:00:26Z", "published": "2022-03-26T00:00:29Z", "aliases": [ "CVE-2022-0995" diff --git a/advisories/unreviewed/2022/04/GHSA-4v97-3733-h7mw/GHSA-4v97-3733-h7mw.json b/advisories/unreviewed/2022/04/GHSA-4v97-3733-h7mw/GHSA-4v97-3733-h7mw.json index 87de7af587f..d478338e309 100644 --- a/advisories/unreviewed/2022/04/GHSA-4v97-3733-h7mw/GHSA-4v97-3733-h7mw.json +++ b/advisories/unreviewed/2022/04/GHSA-4v97-3733-h7mw/GHSA-4v97-3733-h7mw.json @@ -101,7 +101,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], "severity": "MODERATE", "github_reviewed": false diff --git a/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json b/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json index a4db33203d9..3c6e37ae810 100644 --- a/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json +++ b/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json @@ -125,7 +125,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false diff --git a/advisories/unreviewed/2022/05/GHSA-25vq-j8q6-c4xv/GHSA-25vq-j8q6-c4xv.json b/advisories/unreviewed/2022/05/GHSA-25vq-j8q6-c4xv/GHSA-25vq-j8q6-c4xv.json index 0f800d23177..7b8ce5bf841 100644 --- a/advisories/unreviewed/2022/05/GHSA-25vq-j8q6-c4xv/GHSA-25vq-j8q6-c4xv.json +++ b/advisories/unreviewed/2022/05/GHSA-25vq-j8q6-c4xv/GHSA-25vq-j8q6-c4xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-25vq-j8q6-c4xv", - "modified": "2022-05-24T19:07:17Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:07:17Z", "aliases": [ "CVE-2021-25426" ], "details": "Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted applications to access Message files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-3xxr-x7rp-pc4x/GHSA-3xxr-x7rp-pc4x.json b/advisories/unreviewed/2022/05/GHSA-3xxr-x7rp-pc4x/GHSA-3xxr-x7rp-pc4x.json index 0929f136835..b9b11fe303e 100644 --- a/advisories/unreviewed/2022/05/GHSA-3xxr-x7rp-pc4x/GHSA-3xxr-x7rp-pc4x.json +++ b/advisories/unreviewed/2022/05/GHSA-3xxr-x7rp-pc4x/GHSA-3xxr-x7rp-pc4x.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-3xxr-x7rp-pc4x", - "modified": "2022-05-24T17:43:41Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T17:43:41Z", "aliases": [ "CVE-2021-25340" ], "details": "Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-42g8-62v3-2jg8/GHSA-42g8-62v3-2jg8.json b/advisories/unreviewed/2022/05/GHSA-42g8-62v3-2jg8/GHSA-42g8-62v3-2jg8.json index 5c671ac3a09..d50eb6eb546 100644 --- a/advisories/unreviewed/2022/05/GHSA-42g8-62v3-2jg8/GHSA-42g8-62v3-2jg8.json +++ b/advisories/unreviewed/2022/05/GHSA-42g8-62v3-2jg8/GHSA-42g8-62v3-2jg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-42g8-62v3-2jg8", - "modified": "2022-05-24T17:46:25Z", + "modified": "2022-09-25T00:00:26Z", "published": "2022-05-24T17:46:25Z", "aliases": [ "CVE-2021-22200" ], "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-659h-rq95-r222/GHSA-659h-rq95-r222.json b/advisories/unreviewed/2022/05/GHSA-659h-rq95-r222/GHSA-659h-rq95-r222.json index 656b4e26c9a..48e1cd32c01 100644 --- a/advisories/unreviewed/2022/05/GHSA-659h-rq95-r222/GHSA-659h-rq95-r222.json +++ b/advisories/unreviewed/2022/05/GHSA-659h-rq95-r222/GHSA-659h-rq95-r222.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-659h-rq95-r222", - "modified": "2022-05-24T19:13:56Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T19:13:56Z", "aliases": [ "CVE-2021-25464" ], "details": "An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6gph-499x-vm5j/GHSA-6gph-499x-vm5j.json b/advisories/unreviewed/2022/05/GHSA-6gph-499x-vm5j/GHSA-6gph-499x-vm5j.json index 9b8521ca2a7..c5494feb4bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-6gph-499x-vm5j/GHSA-6gph-499x-vm5j.json +++ b/advisories/unreviewed/2022/05/GHSA-6gph-499x-vm5j/GHSA-6gph-499x-vm5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-6gph-499x-vm5j", - "modified": "2022-05-24T19:05:10Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:05:10Z", "aliases": [ "CVE-2021-25386" ], "details": "An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-120" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-8q2m-9hf9-7qq4/GHSA-8q2m-9hf9-7qq4.json b/advisories/unreviewed/2022/05/GHSA-8q2m-9hf9-7qq4/GHSA-8q2m-9hf9-7qq4.json index 07462ae1ad0..f05fe23c848 100644 --- a/advisories/unreviewed/2022/05/GHSA-8q2m-9hf9-7qq4/GHSA-8q2m-9hf9-7qq4.json +++ b/advisories/unreviewed/2022/05/GHSA-8q2m-9hf9-7qq4/GHSA-8q2m-9hf9-7qq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-8q2m-9hf9-7qq4", - "modified": "2022-05-24T19:16:44Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T19:16:44Z", "aliases": [ "CVE-2021-25472" ], "details": "An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8vw4-xv4w-x2mf/GHSA-8vw4-xv4w-x2mf.json b/advisories/unreviewed/2022/05/GHSA-8vw4-xv4w-x2mf/GHSA-8vw4-xv4w-x2mf.json index c54ff91c88d..7aabea3f12a 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vw4-xv4w-x2mf/GHSA-8vw4-xv4w-x2mf.json +++ b/advisories/unreviewed/2022/05/GHSA-8vw4-xv4w-x2mf/GHSA-8vw4-xv4w-x2mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-8vw4-xv4w-x2mf", - "modified": "2022-05-24T19:10:57Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-05-24T19:10:57Z", "aliases": [ "CVE-2020-20977" ], "details": "A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-95xc-mm75-h3v2/GHSA-95xc-mm75-h3v2.json b/advisories/unreviewed/2022/05/GHSA-95xc-mm75-h3v2/GHSA-95xc-mm75-h3v2.json index 9a21381872b..7923bfdd0f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-95xc-mm75-h3v2/GHSA-95xc-mm75-h3v2.json +++ b/advisories/unreviewed/2022/05/GHSA-95xc-mm75-h3v2/GHSA-95xc-mm75-h3v2.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-95xc-mm75-h3v2", - "modified": "2022-05-24T17:46:59Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T17:46:59Z", "aliases": [ "CVE-2021-25361" ], "details": "An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-c8h9-xgqx-fc49/GHSA-c8h9-xgqx-fc49.json b/advisories/unreviewed/2022/05/GHSA-c8h9-xgqx-fc49/GHSA-c8h9-xgqx-fc49.json index 2592f5037c4..9d5d61c6eff 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8h9-xgqx-fc49/GHSA-c8h9-xgqx-fc49.json +++ b/advisories/unreviewed/2022/05/GHSA-c8h9-xgqx-fc49/GHSA-c8h9-xgqx-fc49.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-c8h9-xgqx-fc49", - "modified": "2022-05-24T19:05:10Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T19:05:10Z", "aliases": [ "CVE-2021-25385" ], "details": "An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-120" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-ccc3-9cpj-334h/GHSA-ccc3-9cpj-334h.json b/advisories/unreviewed/2022/05/GHSA-ccc3-9cpj-334h/GHSA-ccc3-9cpj-334h.json index 04097b6370d..d40d18c90ad 100644 --- a/advisories/unreviewed/2022/05/GHSA-ccc3-9cpj-334h/GHSA-ccc3-9cpj-334h.json +++ b/advisories/unreviewed/2022/05/GHSA-ccc3-9cpj-334h/GHSA-ccc3-9cpj-334h.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-ccc3-9cpj-334h", - "modified": "2022-05-24T19:10:12Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:10:12Z", "aliases": [ "CVE-2021-25446" ], "details": "Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cgwf-g22v-w6c6/GHSA-cgwf-g22v-w6c6.json b/advisories/unreviewed/2022/05/GHSA-cgwf-g22v-w6c6/GHSA-cgwf-g22v-w6c6.json index d04bdc5a335..b2da3a4d3c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cgwf-g22v-w6c6/GHSA-cgwf-g22v-w6c6.json +++ b/advisories/unreviewed/2022/05/GHSA-cgwf-g22v-w6c6/GHSA-cgwf-g22v-w6c6.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-cgwf-g22v-w6c6", - "modified": "2022-05-24T19:05:10Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T19:05:10Z", "aliases": [ "CVE-2021-25387" ], "details": "An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-cj6h-3w4g-pcm8/GHSA-cj6h-3w4g-pcm8.json b/advisories/unreviewed/2022/05/GHSA-cj6h-3w4g-pcm8/GHSA-cj6h-3w4g-pcm8.json index 8ecd4fa4586..5b371ca2921 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj6h-3w4g-pcm8/GHSA-cj6h-3w4g-pcm8.json +++ b/advisories/unreviewed/2022/05/GHSA-cj6h-3w4g-pcm8/GHSA-cj6h-3w4g-pcm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-cj6h-3w4g-pcm8", - "modified": "2022-05-24T19:13:57Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:13:57Z", "aliases": [ "CVE-2021-25463" ], "details": "Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-g52j-gcmf-jf6c/GHSA-g52j-gcmf-jf6c.json b/advisories/unreviewed/2022/05/GHSA-g52j-gcmf-jf6c/GHSA-g52j-gcmf-jf6c.json index 51121e06537..8e6359549d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-g52j-gcmf-jf6c/GHSA-g52j-gcmf-jf6c.json +++ b/advisories/unreviewed/2022/05/GHSA-g52j-gcmf-jf6c/GHSA-g52j-gcmf-jf6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-g52j-gcmf-jf6c", - "modified": "2022-05-24T19:10:12Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:10:12Z", "aliases": [ "CVE-2021-25447" ], "details": "Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-g8xw-6mmv-frg4/GHSA-g8xw-6mmv-frg4.json b/advisories/unreviewed/2022/05/GHSA-g8xw-6mmv-frg4/GHSA-g8xw-6mmv-frg4.json index 748989bcf04..5600ab246df 100644 --- a/advisories/unreviewed/2022/05/GHSA-g8xw-6mmv-frg4/GHSA-g8xw-6mmv-frg4.json +++ b/advisories/unreviewed/2022/05/GHSA-g8xw-6mmv-frg4/GHSA-g8xw-6mmv-frg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-g8xw-6mmv-frg4", - "modified": "2022-05-24T17:46:59Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T17:46:59Z", "aliases": [ "CVE-2021-25360" ], "details": "An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hmpv-pvg5-4fpq/GHSA-hmpv-pvg5-4fpq.json b/advisories/unreviewed/2022/05/GHSA-hmpv-pvg5-4fpq/GHSA-hmpv-pvg5-4fpq.json index 028eb6bc186..867f14114f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-hmpv-pvg5-4fpq/GHSA-hmpv-pvg5-4fpq.json +++ b/advisories/unreviewed/2022/05/GHSA-hmpv-pvg5-4fpq/GHSA-hmpv-pvg5-4fpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-hmpv-pvg5-4fpq", - "modified": "2022-05-24T19:16:43Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T19:16:43Z", "aliases": [ "CVE-2021-25489" ], "details": "Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-134", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-j677-7992-mrpc/GHSA-j677-7992-mrpc.json b/advisories/unreviewed/2022/05/GHSA-j677-7992-mrpc/GHSA-j677-7992-mrpc.json index b8ff9509db2..44dc0d6e36c 100644 --- a/advisories/unreviewed/2022/05/GHSA-j677-7992-mrpc/GHSA-j677-7992-mrpc.json +++ b/advisories/unreviewed/2022/05/GHSA-j677-7992-mrpc/GHSA-j677-7992-mrpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-j677-7992-mrpc", - "modified": "2022-05-24T17:47:00Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T17:47:00Z", "aliases": [ "CVE-2021-25378" ], "details": "Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qgmh-w9pv-x25v/GHSA-qgmh-w9pv-x25v.json b/advisories/unreviewed/2022/05/GHSA-qgmh-w9pv-x25v/GHSA-qgmh-w9pv-x25v.json index 443fe47e5f2..b1d48ea33d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgmh-w9pv-x25v/GHSA-qgmh-w9pv-x25v.json +++ b/advisories/unreviewed/2022/05/GHSA-qgmh-w9pv-x25v/GHSA-qgmh-w9pv-x25v.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-qgmh-w9pv-x25v", - "modified": "2022-05-24T19:13:57Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:13:57Z", "aliases": [ "CVE-2021-25459" ], "details": "An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-r7rr-ghh8-j4p9/GHSA-r7rr-ghh8-j4p9.json b/advisories/unreviewed/2022/05/GHSA-r7rr-ghh8-j4p9/GHSA-r7rr-ghh8-j4p9.json index b10ded71626..d9d929f13a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7rr-ghh8-j4p9/GHSA-r7rr-ghh8-j4p9.json +++ b/advisories/unreviewed/2022/05/GHSA-r7rr-ghh8-j4p9/GHSA-r7rr-ghh8-j4p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-r7rr-ghh8-j4p9", - "modified": "2022-05-24T17:45:24Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T17:45:24Z", "aliases": [ "CVE-2021-25351" ], "details": "Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v5gp-rv55-crrm/GHSA-v5gp-rv55-crrm.json b/advisories/unreviewed/2022/05/GHSA-v5gp-rv55-crrm/GHSA-v5gp-rv55-crrm.json index 30e1977ea2a..2b8fce32874 100644 --- a/advisories/unreviewed/2022/05/GHSA-v5gp-rv55-crrm/GHSA-v5gp-rv55-crrm.json +++ b/advisories/unreviewed/2022/05/GHSA-v5gp-rv55-crrm/GHSA-v5gp-rv55-crrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-v5gp-rv55-crrm", - "modified": "2022-05-24T19:13:58Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:13:58Z", "aliases": [ "CVE-2021-25453" ], "details": "Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-wp7q-xrrh-6rxg/GHSA-wp7q-xrrh-6rxg.json b/advisories/unreviewed/2022/05/GHSA-wp7q-xrrh-6rxg/GHSA-wp7q-xrrh-6rxg.json index 22290cdfe37..2f03b408a13 100644 --- a/advisories/unreviewed/2022/05/GHSA-wp7q-xrrh-6rxg/GHSA-wp7q-xrrh-6rxg.json +++ b/advisories/unreviewed/2022/05/GHSA-wp7q-xrrh-6rxg/GHSA-wp7q-xrrh-6rxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-wp7q-xrrh-6rxg", - "modified": "2022-05-24T17:45:24Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T17:45:24Z", "aliases": [ "CVE-2021-25366" ], "details": "Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-x2gj-m25r-2923/GHSA-x2gj-m25r-2923.json b/advisories/unreviewed/2022/05/GHSA-x2gj-m25r-2923/GHSA-x2gj-m25r-2923.json index 663d81873c1..77ea76428ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-x2gj-m25r-2923/GHSA-x2gj-m25r-2923.json +++ b/advisories/unreviewed/2022/05/GHSA-x2gj-m25r-2923/GHSA-x2gj-m25r-2923.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-x2gj-m25r-2923", - "modified": "2022-05-24T19:10:12Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:10:12Z", "aliases": [ "CVE-2021-25448" ], "details": "Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-x6fw-fv3x-rwmc/GHSA-x6fw-fv3x-rwmc.json b/advisories/unreviewed/2022/05/GHSA-x6fw-fv3x-rwmc/GHSA-x6fw-fv3x-rwmc.json index 4cf6e5b7491..97ec80a82c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-x6fw-fv3x-rwmc/GHSA-x6fw-fv3x-rwmc.json +++ b/advisories/unreviewed/2022/05/GHSA-x6fw-fv3x-rwmc/GHSA-x6fw-fv3x-rwmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-x6fw-fv3x-rwmc", - "modified": "2022-05-24T19:05:11Z", + "modified": "2022-09-25T00:00:18Z", "published": "2022-05-24T19:05:11Z", "aliases": [ "CVE-2021-25383" ], "details": "An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-120" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-xxpf-vv2v-cfqq/GHSA-xxpf-vv2v-cfqq.json b/advisories/unreviewed/2022/05/GHSA-xxpf-vv2v-cfqq/GHSA-xxpf-vv2v-cfqq.json index aed2c08e7f5..2a0681fa954 100644 --- a/advisories/unreviewed/2022/05/GHSA-xxpf-vv2v-cfqq/GHSA-xxpf-vv2v-cfqq.json +++ b/advisories/unreviewed/2022/05/GHSA-xxpf-vv2v-cfqq/GHSA-xxpf-vv2v-cfqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-xxpf-vv2v-cfqq", - "modified": "2022-05-24T19:13:57Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-05-24T19:13:57Z", "aliases": [ "CVE-2021-25460" ], "details": "An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/08/GHSA-3rm2-w8f7-h7rf/GHSA-3rm2-w8f7-h7rf.json b/advisories/unreviewed/2022/08/GHSA-3rm2-w8f7-h7rf/GHSA-3rm2-w8f7-h7rf.json index 1064f828390..b713cfe3cd7 100644 --- a/advisories/unreviewed/2022/08/GHSA-3rm2-w8f7-h7rf/GHSA-3rm2-w8f7-h7rf.json +++ b/advisories/unreviewed/2022/08/GHSA-3rm2-w8f7-h7rf/GHSA-3rm2-w8f7-h7rf.json @@ -44,6 +44,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2022-0537" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20220923-0003/" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/08/GHSA-4h78-xq9p-vv4g/GHSA-4h78-xq9p-vv4g.json b/advisories/unreviewed/2022/08/GHSA-4h78-xq9p-vv4g/GHSA-4h78-xq9p-vv4g.json index 1513bdcafa7..b6d4decd516 100644 --- a/advisories/unreviewed/2022/08/GHSA-4h78-xq9p-vv4g/GHSA-4h78-xq9p-vv4g.json +++ b/advisories/unreviewed/2022/08/GHSA-4h78-xq9p-vv4g/GHSA-4h78-xq9p-vv4g.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-20824" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20220923-0001/" + }, { "type": "WEB", "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cdp-dos-ce-wWvPucC9" diff --git a/advisories/unreviewed/2022/08/GHSA-5948-4f22-j6wp/GHSA-5948-4f22-j6wp.json b/advisories/unreviewed/2022/08/GHSA-5948-4f22-j6wp/GHSA-5948-4f22-j6wp.json index 46be4f70a90..3d44f9087a6 100644 --- a/advisories/unreviewed/2022/08/GHSA-5948-4f22-j6wp/GHSA-5948-4f22-j6wp.json +++ b/advisories/unreviewed/2022/08/GHSA-5948-4f22-j6wp/GHSA-5948-4f22-j6wp.json @@ -24,6 +24,14 @@ { "type": "WEB", "url": "https://github.com/CrowCpp/Crow/pull/523" + }, + { + "type": "WEB", + "url": "https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md" + }, + { + "type": "WEB", + "url": "https://gynvael.coldwind.pl/?id=752" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/08/GHSA-g8qv-x989-399f/GHSA-g8qv-x989-399f.json b/advisories/unreviewed/2022/08/GHSA-g8qv-x989-399f/GHSA-g8qv-x989-399f.json index 21a6e129086..afaa6458a31 100644 --- a/advisories/unreviewed/2022/08/GHSA-g8qv-x989-399f/GHSA-g8qv-x989-399f.json +++ b/advisories/unreviewed/2022/08/GHSA-g8qv-x989-399f/GHSA-g8qv-x989-399f.json @@ -24,6 +24,18 @@ { "type": "WEB", "url": "https://github.com/CrowCpp/Crow/pull/524" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/372.html" + }, + { + "type": "WEB", + "url": "https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38667.md" + }, + { + "type": "WEB", + "url": "https://gynvael.coldwind.pl/?id=753" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json b/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json index d79624f51ee..b335cad46ac 100644 --- a/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json +++ b/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://gitlab.com/qemu-project/qemu/-/issues/782" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I/" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json b/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json new file mode 100644 index 00000000000..8323e5e545f --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-22jw-r3jv-5f4f/GHSA-22jw-r3jv-5f4f.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-22jw-r3jv-5f4f", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32819" + ], + "details": "A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32819" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json b/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json new file mode 100644 index 00000000000..293e017214f --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-239x-qr9g-j39q/GHSA-239x-qr9g-j39q.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-239x-qr9g-j39q", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32847" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32847" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json b/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json new file mode 100644 index 00000000000..e6805758ff3 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-255p-hfwr-9qm4/GHSA-255p-hfwr-9qm4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-255p-hfwr-9qm4", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32782" + ], + "details": "This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32782" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213257" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-25qf-mc6x-fm76/GHSA-25qf-mc6x-fm76.json b/advisories/unreviewed/2022/09/GHSA-25qf-mc6x-fm76/GHSA-25qf-mc6x-fm76.json new file mode 100644 index 00000000000..07d0bdbc124 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-25qf-mc6x-fm76/GHSA-25qf-mc6x-fm76.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-25qf-mc6x-fm76", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-40115" + ], + "details": "Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40115" + }, + { + "type": "WEB", + "url": "https://github.com/zakee94/online-banking-system/issues/10" + }, + { + "type": "WEB", + "url": "https://github.com/0clickjacking0/BugReport/blob/main/online-banking-system/sql_injection1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json b/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json new file mode 100644 index 00000000000..1de6921d454 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-27m4-83f2-2x77/GHSA-27m4-83f2-2x77.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-27m4-83f2-2x77", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-40103" + ], + "details": "Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40103" + }, + { + "type": "WEB", + "url": "https://github.com/splashsc/IOT_Vulnerability_Discovery/blob/main/Tenda/Tenda_i9/buffer_overflow_formSetAutoPing.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-27v6-4m9p-3qq4/GHSA-27v6-4m9p-3qq4.json b/advisories/unreviewed/2022/09/GHSA-27v6-4m9p-3qq4/GHSA-27v6-4m9p-3qq4.json index d0253e37484..276d23166f9 100644 --- a/advisories/unreviewed/2022/09/GHSA-27v6-4m9p-3qq4/GHSA-27v6-4m9p-3qq4.json +++ b/advisories/unreviewed/2022/09/GHSA-27v6-4m9p-3qq4/GHSA-27v6-4m9p-3qq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-27v6-4m9p-3qq4", - "modified": "2022-09-22T00:00:22Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-22T00:00:22Z", "aliases": [ "CVE-2022-36386" ], "details": "Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-27wf-832r-r7vc/GHSA-27wf-832r-r7vc.json b/advisories/unreviewed/2022/09/GHSA-27wf-832r-r7vc/GHSA-27wf-832r-r7vc.json index 28d82154687..9b642030314 100644 --- a/advisories/unreviewed/2022/09/GHSA-27wf-832r-r7vc/GHSA-27wf-832r-r7vc.json +++ b/advisories/unreviewed/2022/09/GHSA-27wf-832r-r7vc/GHSA-27wf-832r-r7vc.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-27wf-832r-r7vc", - "modified": "2022-09-21T00:00:39Z", + "modified": "2022-09-25T00:00:15Z", "published": "2022-09-21T00:00:39Z", "aliases": [ "CVE-2022-40250" ], "details": "An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json b/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json new file mode 100644 index 00000000000..4cfd3848239 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-29pj-cw86-x2fg/GHSA-29pj-cw86-x2fg.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-29pj-cw86-x2fg", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32823" + ], + "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32823" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-2h7v-c8c8-vxg7/GHSA-2h7v-c8c8-vxg7.json b/advisories/unreviewed/2022/09/GHSA-2h7v-c8c8-vxg7/GHSA-2h7v-c8c8-vxg7.json index 8819b46a8bc..32af549bf89 100644 --- a/advisories/unreviewed/2022/09/GHSA-2h7v-c8c8-vxg7/GHSA-2h7v-c8c8-vxg7.json +++ b/advisories/unreviewed/2022/09/GHSA-2h7v-c8c8-vxg7/GHSA-2h7v-c8c8-vxg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-2h7v-c8c8-vxg7", - "modified": "2022-09-23T00:00:41Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-09-23T00:00:41Z", "aliases": [ "CVE-2022-40446" ], "details": "ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-2hr4-jcq5-r7fq/GHSA-2hr4-jcq5-r7fq.json b/advisories/unreviewed/2022/09/GHSA-2hr4-jcq5-r7fq/GHSA-2hr4-jcq5-r7fq.json index 983ad96d9d3..759213c7168 100644 --- a/advisories/unreviewed/2022/09/GHSA-2hr4-jcq5-r7fq/GHSA-2hr4-jcq5-r7fq.json +++ b/advisories/unreviewed/2022/09/GHSA-2hr4-jcq5-r7fq/GHSA-2hr4-jcq5-r7fq.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-2hr4-jcq5-r7fq", - "modified": "2022-09-22T00:00:32Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-0495" ], "details": "The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json b/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json index 0b4f5c70d31..7a4015c7547 100644 --- a/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json +++ b/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/libexpat/libexpat/pull/640" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5236" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json b/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json index 14f892c5f99..bedbd419900 100644 --- a/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json +++ b/advisories/unreviewed/2022/09/GHSA-2wqp-mx6p-m496/GHSA-2wqp-mx6p-m496.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-2wqp-mx6p-m496", - "modified": "2022-09-23T00:00:31Z", + "modified": "2022-09-25T00:00:27Z", "published": "2022-09-23T00:00:31Z", "aliases": [ "CVE-2022-35024" ], "details": "OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-3229-cmr6-cvgv/GHSA-3229-cmr6-cvgv.json b/advisories/unreviewed/2022/09/GHSA-3229-cmr6-cvgv/GHSA-3229-cmr6-cvgv.json new file mode 100644 index 00000000000..678079b00b1 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-3229-cmr6-cvgv/GHSA-3229-cmr6-cvgv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-3229-cmr6-cvgv", + "modified": "2022-09-25T00:00:18Z", + "published": "2022-09-25T00:00:18Z", + "aliases": [ + "CVE-2022-40132" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to plugin settings change.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40132" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/seriously-simple-podcasting/wordpress-seriously-simple-podcasting-plugin-2-16-0-cross-site-request-forgery-csrf-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/seriously-simple-podcasting/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-32c6-653x-x3pm/GHSA-32c6-653x-x3pm.json b/advisories/unreviewed/2022/09/GHSA-32c6-653x-x3pm/GHSA-32c6-653x-x3pm.json index 57245fe5dcb..adcc2456e8c 100644 --- a/advisories/unreviewed/2022/09/GHSA-32c6-653x-x3pm/GHSA-32c6-653x-x3pm.json +++ b/advisories/unreviewed/2022/09/GHSA-32c6-653x-x3pm/GHSA-32c6-653x-x3pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-32c6-653x-x3pm", - "modified": "2022-09-22T00:00:24Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-09-22T00:00:24Z", "aliases": [ "CVE-2022-3251" ], "details": "Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-311", "CWE-614" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-33v4-rh3c-mhcg/GHSA-33v4-rh3c-mhcg.json b/advisories/unreviewed/2022/09/GHSA-33v4-rh3c-mhcg/GHSA-33v4-rh3c-mhcg.json index 5f7cc5ccf52..e4ee9f13fbe 100644 --- a/advisories/unreviewed/2022/09/GHSA-33v4-rh3c-mhcg/GHSA-33v4-rh3c-mhcg.json +++ b/advisories/unreviewed/2022/09/GHSA-33v4-rh3c-mhcg/GHSA-33v4-rh3c-mhcg.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://cyber-guy.gitbook.io/cyber-guy/pocs/omnia-node-mpx-auth-bypass-via-lfd" }, + { + "type": "WEB", + "url": "https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/bypassing-mpx-node-authentication-firmware-analysis" + }, { "type": "WEB", "url": "https://drive.google.com/drive/folders/1jm9h8JNmezTt7AbHYRY7gPC4lXGDNklL" diff --git a/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json b/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json index 9e10b1ffd96..258082e455c 100644 --- a/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json +++ b/advisories/unreviewed/2022/09/GHSA-349w-cgp3-287r/GHSA-349w-cgp3-287r.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-349w-cgp3-287r", - "modified": "2022-09-22T00:00:32Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-38178" ], "details": "By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -22,6 +25,10 @@ "type": "WEB", "url": "https://kb.isc.org/docs/cve-2022-38178" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5235" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/09/21/3" @@ -29,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-3686-mp4v-qv73/GHSA-3686-mp4v-qv73.json b/advisories/unreviewed/2022/09/GHSA-3686-mp4v-qv73/GHSA-3686-mp4v-qv73.json new file mode 100644 index 00000000000..204ad3498f4 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-3686-mp4v-qv73/GHSA-3686-mp4v-qv73.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-3686-mp4v-qv73", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-38085" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Read more By Adam plugin <= 1.1.8 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38085" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/read-more/wordpress-read-more-by-adam-plugin-1-1-8-cross-site-request-forgery-csrf-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/read-more/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json b/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json index a868c7b0be2..835e2d93715 100644 --- a/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json +++ b/advisories/unreviewed/2022/09/GHSA-37cj-9g83-7692/GHSA-37cj-9g83-7692.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-37cj-9g83-7692", - "modified": "2022-09-22T00:00:23Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-09-22T00:00:23Z", "aliases": [ "CVE-2022-29800" ], "details": "A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-37g5-jpqm-9jr7/GHSA-37g5-jpqm-9jr7.json b/advisories/unreviewed/2022/09/GHSA-37g5-jpqm-9jr7/GHSA-37g5-jpqm-9jr7.json index 58b6902e5f0..9b366b16132 100644 --- a/advisories/unreviewed/2022/09/GHSA-37g5-jpqm-9jr7/GHSA-37g5-jpqm-9jr7.json +++ b/advisories/unreviewed/2022/09/GHSA-37g5-jpqm-9jr7/GHSA-37g5-jpqm-9jr7.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-37g5-jpqm-9jr7", - "modified": "2022-09-22T00:00:22Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-09-22T00:00:22Z", "aliases": [ "CVE-2022-36365" ], "details": "Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.10 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-38q5-v7xx-c8c6/GHSA-38q5-v7xx-c8c6.json b/advisories/unreviewed/2022/09/GHSA-38q5-v7xx-c8c6/GHSA-38q5-v7xx-c8c6.json new file mode 100644 index 00000000000..4b45df56292 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-38q5-v7xx-c8c6/GHSA-38q5-v7xx-c8c6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-38q5-v7xx-c8c6", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-22423" + ], + "details": "IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22423" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/223596" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6695893" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json b/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json new file mode 100644 index 00000000000..183bd80e78e --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-3cjx-7cj6-qvq3/GHSA-3cjx-7cj6-qvq3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-3cjx-7cj6-qvq3", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32220" + ], + "details": "An information disclosure vulnerability exists in Rocket.Chat FUN_0007db78 function with the request /goform/SetNetControlList/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40861" + }, + { + "type": "WEB", + "url": "https://github.com/CPSeek/Router-vuls/blob/main/Tenda/AC18/formSetQosBand.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json b/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json new file mode 100644 index 00000000000..738a667d3e3 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-jx87-887q-554q/GHSA-jx87-887q-554q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-jx87-887q-554q", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32226" + ], + "details": "An improper access control vulnerability exists in Rocket.Chat ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc(). An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2566" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/commit/c953baa084607dd1d84c3bfcce3cf6a87c3e6e05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-mchf-7f36-58fj/GHSA-mchf-7f36-58fj.json b/advisories/unreviewed/2022/09/GHSA-mchf-7f36-58fj/GHSA-mchf-7f36-58fj.json new file mode 100644 index 00000000000..0ae01215133 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-mchf-7f36-58fj/GHSA-mchf-7f36-58fj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-mchf-7f36-58fj", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-40118" + ], + "details": "Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40118" + }, + { + "type": "WEB", + "url": "https://github.com/zakee94/online-banking-system/issues/19" + }, + { + "type": "WEB", + "url": "https://github.com/0clickjacking0/BugReport/blob/main/online-banking-system/sql_injection4.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json b/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json new file mode 100644 index 00000000000..8ef90975682 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-mcxh-2w23-3cf7/GHSA-mcxh-2w23-3cf7.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-mcxh-2w23-3cf7", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32817" + ], + "details": "An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32817" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-mhpj-fprx-gcxh/GHSA-mhpj-fprx-gcxh.json b/advisories/unreviewed/2022/09/GHSA-mhpj-fprx-gcxh/GHSA-mhpj-fprx-gcxh.json index d79507964a4..bb27e6f06ef 100644 --- a/advisories/unreviewed/2022/09/GHSA-mhpj-fprx-gcxh/GHSA-mhpj-fprx-gcxh.json +++ b/advisories/unreviewed/2022/09/GHSA-mhpj-fprx-gcxh/GHSA-mhpj-fprx-gcxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-mhpj-fprx-gcxh", - "modified": "2022-09-23T00:00:31Z", + "modified": "2022-09-25T00:00:27Z", "published": "2022-09-23T00:00:31Z", "aliases": [ "CVE-2022-35022" ], "details": "OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json b/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json new file mode 100644 index 00000000000..6e545367b5e --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-mmj5-42wx-3r4f/GHSA-mmj5-42wx-3r4f.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-mmj5-42wx-3r4f", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32825" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32825" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json b/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json new file mode 100644 index 00000000000..a1f32d98de2 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-p235-xqcv-9xrg/GHSA-p235-xqcv-9xrg.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p235-xqcv-9xrg", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32828" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32828" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-p294-p2wv-22g4/GHSA-p294-p2wv-22g4.json b/advisories/unreviewed/2022/09/GHSA-p294-p2wv-22g4/GHSA-p294-p2wv-22g4.json new file mode 100644 index 00000000000..15358d09c8a --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-p294-p2wv-22g4/GHSA-p294-p2wv-22g4.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p294-p2wv-22g4", + "modified": "2022-09-25T00:00:18Z", + "published": "2022-09-25T00:00:18Z", + "aliases": [ + "CVE-2022-3144" + ], + "details": "The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3144" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2780937%40wordfence&new=2780937%40wordfence&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wordfence/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-3144" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json b/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json new file mode 100644 index 00000000000..4e92e92c5b9 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-p38h-v883-px7v/GHSA-p38h-v883-px7v.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p38h-v883-px7v", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-22637" + ], + "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22637" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213182" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213183" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213186" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213187" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213193" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json b/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json new file mode 100644 index 00000000000..bc8935762ad --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-p7g7-h68c-47c2/GHSA-p7g7-h68c-47c2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p7g7-h68c-47c2", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32800" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32800" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-p7m9-fxq8-hp5x/GHSA-p7m9-fxq8-hp5x.json b/advisories/unreviewed/2022/09/GHSA-p7m9-fxq8-hp5x/GHSA-p7m9-fxq8-hp5x.json new file mode 100644 index 00000000000..af1f9979c56 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-p7m9-fxq8-hp5x/GHSA-p7m9-fxq8-hp5x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p7m9-fxq8-hp5x", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-40628" + ], + "details": "This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40628" + }, + { + "type": "WEB", + "url": "https://tacitine.com/newdownload/CVE-2022-40628.pdf" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2022-0363" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json b/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json new file mode 100644 index 00000000000..d092442bb70 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-p8vh-mwc9-r3jw/GHSA-p8vh-mwc9-r3jw.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-p8vh-mwc9-r3jw", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32792" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32792" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213341" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-ph7r-3p2x-7pq8/GHSA-ph7r-3p2x-7pq8.json b/advisories/unreviewed/2022/09/GHSA-ph7r-3p2x-7pq8/GHSA-ph7r-3p2x-7pq8.json new file mode 100644 index 00000000000..56ba8d1ffad --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-ph7r-3p2x-7pq8/GHSA-ph7r-3p2x-7pq8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-ph7r-3p2x-7pq8", + "modified": "2022-09-25T00:00:26Z", + "published": "2022-09-25T00:00:26Z", + "aliases": [ + "CVE-2022-37330" + ], + "details": "Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37330" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wha-crossword/wordpress-wha-crossword-plugin-1-1-10-authenticated-stored-cross-site-scripting-xss-vulnerability" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wha-crossword/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-pp63-cgj5-h996/GHSA-pp63-cgj5-h996.json b/advisories/unreviewed/2022/09/GHSA-pp63-cgj5-h996/GHSA-pp63-cgj5-h996.json new file mode 100644 index 00000000000..dac9eec3e3f --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-pp63-cgj5-h996/GHSA-pp63-cgj5-h996.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-pp63-cgj5-h996", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-22629" + ], + "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22629" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213182" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213183" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213186" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213187" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213188" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213193" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-pqxc-54m5-8r8m/GHSA-pqxc-54m5-8r8m.json b/advisories/unreviewed/2022/09/GHSA-pqxc-54m5-8r8m/GHSA-pqxc-54m5-8r8m.json index 5df26cc0951..65f854927e1 100644 --- a/advisories/unreviewed/2022/09/GHSA-pqxc-54m5-8r8m/GHSA-pqxc-54m5-8r8m.json +++ b/advisories/unreviewed/2022/09/GHSA-pqxc-54m5-8r8m/GHSA-pqxc-54m5-8r8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-pqxc-54m5-8r8m", - "modified": "2022-09-22T00:00:32Z", + "modified": "2022-09-25T00:00:26Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-2906" ], "details": "An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-pv7f-h3w8-w3jh/GHSA-pv7f-h3w8-w3jh.json b/advisories/unreviewed/2022/09/GHSA-pv7f-h3w8-w3jh/GHSA-pv7f-h3w8-w3jh.json new file mode 100644 index 00000000000..ffcc958eb5b --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-pv7f-h3w8-w3jh/GHSA-pv7f-h3w8-w3jh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-pv7f-h3w8-w3jh", + "modified": "2022-09-25T00:00:20Z", + "published": "2022-09-25T00:00:20Z", + "aliases": [ + "CVE-2021-45035" + ], + "details": "Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45035" + }, + { + "type": "WEB", + "url": "https://velneo.es/publicacion-de-incidencia-de-seguridad-en-cve-cve-2021-45035/" + }, + { + "type": "WEB", + "url": "https://www.incibe-cert.es/en/early-warning/security-advisories/velneo-vclient-improper-authentication" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-pv83-hp5m-9f24/GHSA-pv83-hp5m-9f24.json b/advisories/unreviewed/2022/09/GHSA-pv83-hp5m-9f24/GHSA-pv83-hp5m-9f24.json new file mode 100644 index 00000000000..9ca51447a26 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-pv83-hp5m-9f24/GHSA-pv83-hp5m-9f24.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-pv83-hp5m-9f24", + "modified": "2022-09-25T00:00:26Z", + "published": "2022-09-25T00:00:26Z", + "aliases": [ + "CVE-2022-38095" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38095" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-dynamic-pricing-for-woocommerce/wordpress-advanced-dynamic-pricing-for-woocommerce-plugin-4-1-3-cross-site-request-forgery-csrf-vulnerability" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/advanced-dynamic-pricing-for-woocommerce/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-pvw2-9h4r-c5cr/GHSA-pvw2-9h4r-c5cr.json b/advisories/unreviewed/2022/09/GHSA-pvw2-9h4r-c5cr/GHSA-pvw2-9h4r-c5cr.json new file mode 100644 index 00000000000..3c8d9e9d0d1 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-pvw2-9h4r-c5cr/GHSA-pvw2-9h4r-c5cr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-pvw2-9h4r-c5cr", + "modified": "2022-09-25T00:00:20Z", + "published": "2022-09-25T00:00:20Z", + "aliases": [ + "CVE-2021-3782" + ], + "details": "An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3782" + }, + { + "type": "WEB", + "url": "https://gitlab.freedesktop.org/wayland/wayland/-/issues/224" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json b/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json index a766c4e05eb..32e76f00e93 100644 --- a/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json +++ b/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2941" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/168479/WordPress-WP-UserOnline-2.88.0-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-pwpx-qj2c-fq5c/GHSA-pwpx-qj2c-fq5c.json b/advisories/unreviewed/2022/09/GHSA-pwpx-qj2c-fq5c/GHSA-pwpx-qj2c-fq5c.json new file mode 100644 index 00000000000..d9507f8d736 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-pwpx-qj2c-fq5c/GHSA-pwpx-qj2c-fq5c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-pwpx-qj2c-fq5c", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-40213" + ], + "details": "Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gs-testimonial/wordpress-gs-testimonial-slider-plugin-1-9-6-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/gs-testimonial/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json b/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json new file mode 100644 index 00000000000..b2b4bfc5203 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-q3cp-h2hv-r3mf/GHSA-q3cp-h2hv-r3mf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-q3cp-h2hv-r3mf", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32796" + ], + "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32796" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q3f4-9h4p-vgr3/GHSA-q3f4-9h4p-vgr3.json b/advisories/unreviewed/2022/09/GHSA-q3f4-9h4p-vgr3/GHSA-q3f4-9h4p-vgr3.json new file mode 100644 index 00000000000..c70155aef12 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-q3f4-9h4p-vgr3/GHSA-q3f4-9h4p-vgr3.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-q3f4-9h4p-vgr3", + "modified": "2022-09-25T00:00:15Z", + "published": "2022-09-25T00:00:15Z", + "aliases": [ + "CVE-2022-41340" + ], + "details": "The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41340" + }, + { + "type": "WEB", + "url": "https://github.com/lionello/secp256k1-js/issues/11" + }, + { + "type": "WEB", + "url": "https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e" + }, + { + "type": "WEB", + "url": "https://github.com/lionello/secp256k1-js/compare/1.0.1...1.1.0" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/@lionello/secp256k1-js" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json b/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json new file mode 100644 index 00000000000..b923a87c3a9 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-q472-4r55-2p86/GHSA-q472-4r55-2p86.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-q472-4r55-2p86", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-35893" + ], + "details": "An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35893" + }, + { + "type": "WEB", + "url": "https://binarly.io/advisories/BRLY-2022-026/index.html" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/SA-2022035" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q638-4gfp-67hc/GHSA-q638-4gfp-67hc.json b/advisories/unreviewed/2022/09/GHSA-q638-4gfp-67hc/GHSA-q638-4gfp-67hc.json index 55795173dd9..87a4b22d10b 100644 --- a/advisories/unreviewed/2022/09/GHSA-q638-4gfp-67hc/GHSA-q638-4gfp-67hc.json +++ b/advisories/unreviewed/2022/09/GHSA-q638-4gfp-67hc/GHSA-q638-4gfp-67hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-q638-4gfp-67hc", - "modified": "2022-09-23T00:00:31Z", + "modified": "2022-09-25T00:00:27Z", "published": "2022-09-23T00:00:31Z", "aliases": [ "CVE-2022-35025" ], "details": "OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q63w-g4hg-gvcw/GHSA-q63w-g4hg-gvcw.json b/advisories/unreviewed/2022/09/GHSA-q63w-g4hg-gvcw/GHSA-q63w-g4hg-gvcw.json new file mode 100644 index 00000000000..83f02394d76 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-q63w-g4hg-gvcw/GHSA-q63w-g4hg-gvcw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-q63w-g4hg-gvcw", + "modified": "2022-09-25T00:00:27Z", + "published": "2022-09-25T00:00:27Z", + "aliases": [ + "CVE-2022-41320" + ], + "details": "Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41320" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS21-002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q979-9m39-23mq/GHSA-q979-9m39-23mq.json b/advisories/unreviewed/2022/09/GHSA-q979-9m39-23mq/GHSA-q979-9m39-23mq.json new file mode 100644 index 00000000000..979bdea9ca7 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-q979-9m39-23mq/GHSA-q979-9m39-23mq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-q979-9m39-23mq", + "modified": "2022-09-25T00:00:15Z", + "published": "2022-09-25T00:00:15Z", + "aliases": [ + "CVE-2022-23463" + ], + "details": "Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23463" + }, + { + "type": "ADVISORY", + "url": "https://securitylab.github.com/advisories/GHSL-2022-033_GHSL-2022-034_Discovery/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-917" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-q9pg-4hmx-4cfv/GHSA-q9pg-4hmx-4cfv.json b/advisories/unreviewed/2022/09/GHSA-q9pg-4hmx-4cfv/GHSA-q9pg-4hmx-4cfv.json new file mode 100644 index 00000000000..258afa4eded --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-q9pg-4hmx-4cfv/GHSA-q9pg-4hmx-4cfv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-q9pg-4hmx-4cfv", + "modified": "2022-09-25T00:00:22Z", + "published": "2022-09-25T00:00:22Z", + "aliases": [ + "CVE-2022-40671" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rate-my-post/wordpress-rate-my-post-wp-rating-system-plugin-3-3-4-cross-site-request-forgery-csrf-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/rate-my-post/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json b/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json new file mode 100644 index 00000000000..f0b6a8924d9 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qc3c-r429-gpgf/GHSA-qc3c-r429-gpgf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qc3c-r429-gpgf", + "modified": "2022-09-25T00:00:26Z", + "published": "2022-09-25T00:00:26Z", + "aliases": [ + "CVE-2022-35252" + ], + "details": "When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a\"sister site\" to deny service to all siblings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35252" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1613943" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json b/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json new file mode 100644 index 00000000000..3b5d5f85d72 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qc73-wjpr-m8fj/GHSA-qc73-wjpr-m8fj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qc73-wjpr-m8fj", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32848" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to capture a user’s screen.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32848" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json b/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json new file mode 100644 index 00000000000..7bd5fd4f948 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qf6h-wr49-rv76/GHSA-qf6h-wr49-rv76.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qf6h-wr49-rv76", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32217" + ], + "details": "A cleartext storage of sensitive information exists in Rocket.Chat FUN_0007dd20 with request /goform/SetNetControlList", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40860" + }, + { + "type": "WEB", + "url": "https://github.com/CPSeek/Router-vuls/blob/main/Tenda/AC15/formSetQosBand.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qfvq-h39h-4m98/GHSA-qfvq-h39h-4m98.json b/advisories/unreviewed/2022/09/GHSA-qfvq-h39h-4m98/GHSA-qfvq-h39h-4m98.json index 5fb43a6162f..3a392e0973a 100644 --- a/advisories/unreviewed/2022/09/GHSA-qfvq-h39h-4m98/GHSA-qfvq-h39h-4m98.json +++ b/advisories/unreviewed/2022/09/GHSA-qfvq-h39h-4m98/GHSA-qfvq-h39h-4m98.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-qfvq-h39h-4m98", - "modified": "2022-09-22T00:00:22Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-22T00:00:22Z", "aliases": [ "CVE-2022-36390" ], "details": "Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qhg4-wfwm-7qcr/GHSA-qhg4-wfwm-7qcr.json b/advisories/unreviewed/2022/09/GHSA-qhg4-wfwm-7qcr/GHSA-qhg4-wfwm-7qcr.json new file mode 100644 index 00000000000..af6ba545475 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qhg4-wfwm-7qcr/GHSA-qhg4-wfwm-7qcr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qhg4-wfwm-7qcr", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-38704" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38704" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/seo-redirection/wordpress-seo-redirection-plugin-8-9-cross-site-request-forgery-csrf-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/seo-redirection/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qhg5-w79j-3jj3/GHSA-qhg5-w79j-3jj3.json b/advisories/unreviewed/2022/09/GHSA-qhg5-w79j-3jj3/GHSA-qhg5-w79j-3jj3.json index 3ed0551b470..d4974ee173c 100644 --- a/advisories/unreviewed/2022/09/GHSA-qhg5-w79j-3jj3/GHSA-qhg5-w79j-3jj3.json +++ b/advisories/unreviewed/2022/09/GHSA-qhg5-w79j-3jj3/GHSA-qhg5-w79j-3jj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-qhg5-w79j-3jj3", - "modified": "2022-09-23T00:00:32Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-23T00:00:32Z", "aliases": [ "CVE-2022-35030" ], "details": "OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qj68-h3qr-6vgv/GHSA-qj68-h3qr-6vgv.json b/advisories/unreviewed/2022/09/GHSA-qj68-h3qr-6vgv/GHSA-qj68-h3qr-6vgv.json new file mode 100644 index 00000000000..33f5fdc74d5 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qj68-h3qr-6vgv/GHSA-qj68-h3qr-6vgv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qj68-h3qr-6vgv", + "modified": "2022-09-25T00:00:26Z", + "published": "2022-09-25T00:00:26Z", + "aliases": [ + "CVE-2022-37338" + ], + "details": "Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37338" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/blossom-recipe-maker/wordpress-blossom-recipe-maker-plugin-1-0-7-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/blossom-recipe-maker/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json b/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json new file mode 100644 index 00000000000..1ad6235a878 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qj7c-f3xj-jxpv/GHSA-qj7c-f3xj-jxpv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qj7c-f3xj-jxpv", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-40188" + ], + "details": "Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40188" + }, + { + "type": "WEB", + "url": "https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1343#note_262558" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qj9p-jvmw-82rh/GHSA-qj9p-jvmw-82rh.json b/advisories/unreviewed/2022/09/GHSA-qj9p-jvmw-82rh/GHSA-qj9p-jvmw-82rh.json new file mode 100644 index 00000000000..202df460cbb --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qj9p-jvmw-82rh/GHSA-qj9p-jvmw-82rh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qj9p-jvmw-82rh", + "modified": "2022-09-25T00:00:26Z", + "published": "2022-09-25T00:00:26Z", + "aliases": [ + "CVE-2022-26112" + ], + "details": "In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26112" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/4pb0r12s2b68d78llk04yd8rh3qk5t9h" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qrj8-rh2f-3cj9/GHSA-qrj8-rh2f-3cj9.json b/advisories/unreviewed/2022/09/GHSA-qrj8-rh2f-3cj9/GHSA-qrj8-rh2f-3cj9.json index 21a38b9adfc..7a8fdc908fd 100644 --- a/advisories/unreviewed/2022/09/GHSA-qrj8-rh2f-3cj9/GHSA-qrj8-rh2f-3cj9.json +++ b/advisories/unreviewed/2022/09/GHSA-qrj8-rh2f-3cj9/GHSA-qrj8-rh2f-3cj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-qrj8-rh2f-3cj9", - "modified": "2022-09-23T00:00:32Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-23T00:00:32Z", "aliases": [ "CVE-2022-35035" ], "details": "OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qrqm-574x-q7f2/GHSA-qrqm-574x-q7f2.json b/advisories/unreviewed/2022/09/GHSA-qrqm-574x-q7f2/GHSA-qrqm-574x-q7f2.json index 44412f1ac27..64d6d4695e5 100644 --- a/advisories/unreviewed/2022/09/GHSA-qrqm-574x-q7f2/GHSA-qrqm-574x-q7f2.json +++ b/advisories/unreviewed/2022/09/GHSA-qrqm-574x-q7f2/GHSA-qrqm-574x-q7f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-qrqm-574x-q7f2", - "modified": "2022-09-22T00:00:22Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-22T00:00:22Z", "aliases": [ "CVE-2022-38073" ], "details": "Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json b/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json new file mode 100644 index 00000000000..acd7b848bd6 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-qv87-xvw7-xfrc/GHSA-qv87-xvw7-xfrc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-qv87-xvw7-xfrc", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32798" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.5. An app may be able to gain elevated privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32798" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json b/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json new file mode 100644 index 00000000000..9c1b080b823 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-r5vg-678j-p7m4/GHSA-r5vg-678j-p7m4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-r5vg-678j-p7m4", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-40101" + ], + "details": "Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formWifiMacFilterSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40101" + }, + { + "type": "WEB", + "url": "https://github.com/splashsc/IOT_Vulnerability_Discovery/blob/main/Tenda/Tenda_i9/buffer_overflow_formWifiMacFilterSet.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rggh-c47v-5wh6/GHSA-rggh-c47v-5wh6.json b/advisories/unreviewed/2022/09/GHSA-rggh-c47v-5wh6/GHSA-rggh-c47v-5wh6.json new file mode 100644 index 00000000000..e2598be29d9 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rggh-c47v-5wh6/GHSA-rggh-c47v-5wh6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rggh-c47v-5wh6", + "modified": "2022-09-25T00:00:20Z", + "published": "2022-09-25T00:00:20Z", + "aliases": [ + "CVE-2022-40629" + ], + "details": "This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to insecure design in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to view sensitive information on the targeted device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40629" + }, + { + "type": "WEB", + "url": "https://tacitine.com/newdownload/CVE-2022-40629.pdf" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2022-0363" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json b/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json new file mode 100644 index 00000000000..1e7b2ad1fcc --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rjp4-q5qr-3cqx/GHSA-rjp4-q5qr-3cqx.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rjp4-q5qr-3cqx", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32787" + ], + "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. Processing maliciously crafted web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32787" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json b/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json index fd3823fe7e6..7f60c7120fd 100644 --- a/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json +++ b/advisories/unreviewed/2022/09/GHSA-rm7v-mc66-6r49/GHSA-rm7v-mc66-6r49.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32886" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDV6OLKDTL55NH4LNSMLQ4D6LLSX6JU2/" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213442" diff --git a/advisories/unreviewed/2022/09/GHSA-rpm3-vf32-w565/GHSA-rpm3-vf32-w565.json b/advisories/unreviewed/2022/09/GHSA-rpm3-vf32-w565/GHSA-rpm3-vf32-w565.json new file mode 100644 index 00000000000..50bce2cf2de --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rpm3-vf32-w565/GHSA-rpm3-vf32-w565.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rpm3-vf32-w565", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-38470" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38470" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/customer-reviews-woocommerce/wordpress-customer-reviews-for-woocommerce-plugin-5-3-5-cross-site-request-forgery-csrf-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/customer-reviews-woocommerce/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rq7v-mq45-xcm2/GHSA-rq7v-mq45-xcm2.json b/advisories/unreviewed/2022/09/GHSA-rq7v-mq45-xcm2/GHSA-rq7v-mq45-xcm2.json new file mode 100644 index 00000000000..79a9f51772e --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rq7v-mq45-xcm2/GHSA-rq7v-mq45-xcm2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rq7v-mq45-xcm2", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-40113" + ], + "details": "Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40113" + }, + { + "type": "WEB", + "url": "https://github.com/zakee94/online-banking-system/issues/18" + }, + { + "type": "WEB", + "url": "https://github.com/0clickjacking0/BugReport/blob/main/online-banking-system/sql_injection3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rrrr-cw7x-rf7j/GHSA-rrrr-cw7x-rf7j.json b/advisories/unreviewed/2022/09/GHSA-rrrr-cw7x-rf7j/GHSA-rrrr-cw7x-rf7j.json new file mode 100644 index 00000000000..09e407dc474 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rrrr-cw7x-rf7j/GHSA-rrrr-cw7x-rf7j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rrrr-cw7x-rf7j", + "modified": "2022-09-25T00:00:18Z", + "published": "2022-09-25T00:00:18Z", + "aliases": [ + "CVE-2022-38703" + ], + "details": "Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <= 9.2 at WordPress", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38703" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/maxbuttons/wordpress-wordpress-button-plugin-maxbuttons-plugin-9-2-authenticated-stored-cross-site-scripting-xss-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/maxbuttons/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rrv6-26r4-h5pj/GHSA-rrv6-26r4-h5pj.json b/advisories/unreviewed/2022/09/GHSA-rrv6-26r4-h5pj/GHSA-rrv6-26r4-h5pj.json new file mode 100644 index 00000000000..08a8d10bb27 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rrv6-26r4-h5pj/GHSA-rrv6-26r4-h5pj.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rrv6-26r4-h5pj", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32814" + ], + "details": "A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32814" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213342" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rvg5-w7ph-h5wx/GHSA-rvg5-w7ph-h5wx.json b/advisories/unreviewed/2022/09/GHSA-rvg5-w7ph-h5wx/GHSA-rvg5-w7ph-h5wx.json new file mode 100644 index 00000000000..2f21951b546 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rvg5-w7ph-h5wx/GHSA-rvg5-w7ph-h5wx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rvg5-w7ph-h5wx", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-38742" + ], + "details": "Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the ThinServer process. If successfully exploited, this could expose the server to arbitrary remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38742" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1136847" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rvjg-x555-jh28/GHSA-rvjg-x555-jh28.json b/advisories/unreviewed/2022/09/GHSA-rvjg-x555-jh28/GHSA-rvjg-x555-jh28.json new file mode 100644 index 00000000000..ff6faf76e54 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rvjg-x555-jh28/GHSA-rvjg-x555-jh28.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rvjg-x555-jh28", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-35091" + ], + "details": "SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf/Stream.cc.ow()", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35091" + }, + { + "type": "WEB", + "url": "https://github.com/matthiaskramm/swftools/issues/182" + }, + { + "type": "WEB", + "url": "https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35091.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rvpq-xxmq-5x83/GHSA-rvpq-xxmq-5x83.json b/advisories/unreviewed/2022/09/GHSA-rvpq-xxmq-5x83/GHSA-rvpq-xxmq-5x83.json index 6caff133706..7b52cba1d23 100644 --- a/advisories/unreviewed/2022/09/GHSA-rvpq-xxmq-5x83/GHSA-rvpq-xxmq-5x83.json +++ b/advisories/unreviewed/2022/09/GHSA-rvpq-xxmq-5x83/GHSA-rvpq-xxmq-5x83.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-rvpq-xxmq-5x83", - "modified": "2022-09-23T00:00:32Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-23T00:00:32Z", "aliases": [ "CVE-2022-35032" ], "details": "OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rvxx-h83g-7vgf/GHSA-rvxx-h83g-7vgf.json b/advisories/unreviewed/2022/09/GHSA-rvxx-h83g-7vgf/GHSA-rvxx-h83g-7vgf.json index d38740aec60..e4444bcb90a 100644 --- a/advisories/unreviewed/2022/09/GHSA-rvxx-h83g-7vgf/GHSA-rvxx-h83g-7vgf.json +++ b/advisories/unreviewed/2022/09/GHSA-rvxx-h83g-7vgf/GHSA-rvxx-h83g-7vgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-rvxx-h83g-7vgf", - "modified": "2022-09-23T00:00:41Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-09-23T00:00:41Z", "aliases": [ "CVE-2022-40443" ], "details": "An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-rwg3-p25f-fp5x/GHSA-rwg3-p25f-fp5x.json b/advisories/unreviewed/2022/09/GHSA-rwg3-p25f-fp5x/GHSA-rwg3-p25f-fp5x.json new file mode 100644 index 00000000000..c10f1613c81 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-rwg3-p25f-fp5x/GHSA-rwg3-p25f-fp5x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-rwg3-p25f-fp5x", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-35096" + ], + "details": "SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35096" + }, + { + "type": "WEB", + "url": "https://github.com/matthiaskramm/swftools/issues/182" + }, + { + "type": "WEB", + "url": "https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35096.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v2qf-2g23-xmcg/GHSA-v2qf-2g23-xmcg.json b/advisories/unreviewed/2022/09/GHSA-v2qf-2g23-xmcg/GHSA-v2qf-2g23-xmcg.json new file mode 100644 index 00000000000..16110665a3c --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v2qf-2g23-xmcg/GHSA-v2qf-2g23-xmcg.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v2qf-2g23-xmcg", + "modified": "2022-09-25T00:00:20Z", + "published": "2022-09-25T00:00:20Z", + "aliases": [ + "CVE-2022-40359" + ], + "details": "Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40359" + }, + { + "type": "WEB", + "url": "https://code.google.com/archive/p/kfm/downloads" + }, + { + "type": "WEB", + "url": "https://cxsecurity.com/issue/WLB-2022090057" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json b/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json new file mode 100644 index 00000000000..cbcc48f5c75 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v44q-v8rf-3m92/GHSA-v44q-v8rf-3m92.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v44q-v8rf-3m92", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32831" + ], + "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32831" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v525-vvmv-fh2m/GHSA-v525-vvmv-fh2m.json b/advisories/unreviewed/2022/09/GHSA-v525-vvmv-fh2m/GHSA-v525-vvmv-fh2m.json new file mode 100644 index 00000000000..810ed058c93 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v525-vvmv-fh2m/GHSA-v525-vvmv-fh2m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v525-vvmv-fh2m", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-40117" + ], + "details": "Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40117" + }, + { + "type": "WEB", + "url": "https://github.com/zakee94/online-banking-system/issues/17" + }, + { + "type": "WEB", + "url": "https://github.com/0clickjacking0/BugReport/blob/main/online-banking-system/sql_injection2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json b/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json new file mode 100644 index 00000000000..598382779c9 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v5mm-c2pr-7qgh/GHSA-v5mm-c2pr-7qgh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v5mm-c2pr-7qgh", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32842" + ], + "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. An app may be able to gain elevated privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32842" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v5rw-hwp6-gf94/GHSA-v5rw-hwp6-gf94.json b/advisories/unreviewed/2022/09/GHSA-v5rw-hwp6-gf94/GHSA-v5rw-hwp6-gf94.json new file mode 100644 index 00000000000..6c80630f7da --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v5rw-hwp6-gf94/GHSA-v5rw-hwp6-gf94.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v5rw-hwp6-gf94", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-36417" + ], + "details": "Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <= 3.8 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cardoza-3d-tag-cloud/wordpress-3d-tag-cloud-plugin-3-8-multiple-stored-cross-site-scripting-xss-via-cross-site-request-forgery-csrf-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/cardoza-3d-tag-cloud/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json b/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json new file mode 100644 index 00000000000..024ffe23dbe --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v9wp-86gv-6c8f/GHSA-v9wp-86gv-6c8f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v9wp-86gv-6c8f", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32818" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5. An app may be able to leak sensitive kernel state.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32818" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json b/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json new file mode 100644 index 00000000000..28abd1ede75 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-v9xf-qq9q-332r/GHSA-v9xf-qq9q-332r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-v9xf-qq9q-332r", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32783" + ], + "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32783" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213257" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-vc7q-8w3h-jx8q/GHSA-vc7q-8w3h-jx8q.json b/advisories/unreviewed/2022/09/GHSA-vc7q-8w3h-jx8q/GHSA-vc7q-8w3h-jx8q.json index 1741371b857..fb5af61e9d0 100644 --- a/advisories/unreviewed/2022/09/GHSA-vc7q-8w3h-jx8q/GHSA-vc7q-8w3h-jx8q.json +++ b/advisories/unreviewed/2022/09/GHSA-vc7q-8w3h-jx8q/GHSA-vc7q-8w3h-jx8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-vc7q-8w3h-jx8q", - "modified": "2022-09-23T00:00:32Z", + "modified": "2022-09-25T00:00:28Z", "published": "2022-09-23T00:00:32Z", "aliases": [ "CVE-2022-35036" ], "details": "OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e1fc8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json b/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json new file mode 100644 index 00000000000..b9c7dee347e --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-vcqh-2q2g-pgc3/GHSA-vcqh-2q2g-pgc3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-vcqh-2q2g-pgc3", + "modified": "2022-09-25T00:00:26Z", + "published": "2022-09-25T00:00:26Z", + "aliases": [ + "CVE-2022-30121" + ], + "details": "The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30121" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-for-Ivanti-Endpoint-Manager-Client-CVE-2022-30121?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-vhxm-j92c-jf79/GHSA-vhxm-j92c-jf79.json b/advisories/unreviewed/2022/09/GHSA-vhxm-j92c-jf79/GHSA-vhxm-j92c-jf79.json new file mode 100644 index 00000000000..18e3deb34b9 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-vhxm-j92c-jf79/GHSA-vhxm-j92c-jf79.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-vhxm-j92c-jf79", + "modified": "2022-09-25T00:00:18Z", + "published": "2022-09-25T00:00:18Z", + "aliases": [ + "CVE-2022-40195" + ], + "details": "Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40195" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/address-email-and-phone-validation/wordpress-pca-predict-plugin-1-0-3-authenticated-stored-cross-site-scripting-xss-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/address-email-and-phone-validation/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-vqgp-46r4-f6j8/GHSA-vqgp-46r4-f6j8.json b/advisories/unreviewed/2022/09/GHSA-vqgp-46r4-f6j8/GHSA-vqgp-46r4-f6j8.json new file mode 100644 index 00000000000..9e29f315429 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-vqgp-46r4-f6j8/GHSA-vqgp-46r4-f6j8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-vqgp-46r4-f6j8", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-40102" + ], + "details": "Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDset function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40102" + }, + { + "type": "WEB", + "url": "https://github.com/splashsc/IOT_Vulnerability_Discovery/blob/main/Tenda/Tenda_i9/buffer_overflow_formwrlSSIDset.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-w2rj-3rf3-w34g/GHSA-w2rj-3rf3-w34g.json b/advisories/unreviewed/2022/09/GHSA-w2rj-3rf3-w34g/GHSA-w2rj-3rf3-w34g.json new file mode 100644 index 00000000000..55be3ea19d2 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-w2rj-3rf3-w34g/GHSA-w2rj-3rf3-w34g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-w2rj-3rf3-w34g", + "modified": "2022-09-25T00:00:22Z", + "published": "2022-09-25T00:00:22Z", + "aliases": [ + "CVE-2022-40854" + ], + "details": "Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40854" + }, + { + "type": "WEB", + "url": "https://github.com/CPSeek/Router-vuls/blob/main/Tenda/AC18/form_fast_setting_wifi_set.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-w397-9p2j-6x23/GHSA-w397-9p2j-6x23.json b/advisories/unreviewed/2022/09/GHSA-w397-9p2j-6x23/GHSA-w397-9p2j-6x23.json index 966a3d96599..a79251e4292 100644 --- a/advisories/unreviewed/2022/09/GHSA-w397-9p2j-6x23/GHSA-w397-9p2j-6x23.json +++ b/advisories/unreviewed/2022/09/GHSA-w397-9p2j-6x23/GHSA-w397-9p2j-6x23.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-w397-9p2j-6x23", - "modified": "2022-09-23T00:00:46Z", + "modified": "2022-09-25T00:00:20Z", "published": "2022-09-23T00:00:46Z", "aliases": [ "CVE-2022-28977" ], "details": "HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-w76j-g6q7-46hq/GHSA-w76j-g6q7-46hq.json b/advisories/unreviewed/2022/09/GHSA-w76j-g6q7-46hq/GHSA-w76j-g6q7-46hq.json new file mode 100644 index 00000000000..38c4ebf1ad8 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-w76j-g6q7-46hq/GHSA-w76j-g6q7-46hq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-w76j-g6q7-46hq", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-22624" + ], + "details": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22624" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213182" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213183" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213186" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213187" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json b/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json new file mode 100644 index 00000000000..3e15b94b56a --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-wff9-xm82-6wp2/GHSA-wff9-xm82-6wp2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-wff9-xm82-6wp2", + "modified": "2022-09-25T00:00:17Z", + "published": "2022-09-25T00:00:17Z", + "aliases": [ + "CVE-2022-32845" + ], + "details": "This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32845" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213340" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wffm-j7m8-93g4/GHSA-wffm-j7m8-93g4.json b/advisories/unreviewed/2022/09/GHSA-wffm-j7m8-93g4/GHSA-wffm-j7m8-93g4.json index 1f448869bda..895e2d18650 100644 --- a/advisories/unreviewed/2022/09/GHSA-wffm-j7m8-93g4/GHSA-wffm-j7m8-93g4.json +++ b/advisories/unreviewed/2022/09/GHSA-wffm-j7m8-93g4/GHSA-wffm-j7m8-93g4.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-wffm-j7m8-93g4", - "modified": "2022-09-23T00:00:46Z", + "modified": "2022-09-25T00:00:26Z", "published": "2022-09-23T00:00:46Z", "aliases": [ "CVE-2022-28982" ], "details": "A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wgh8-h75r-c4qw/GHSA-wgh8-h75r-c4qw.json b/advisories/unreviewed/2022/09/GHSA-wgh8-h75r-c4qw/GHSA-wgh8-h75r-c4qw.json new file mode 100644 index 00000000000..1148f4c248c --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-wgh8-h75r-c4qw/GHSA-wgh8-h75r-c4qw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-wgh8-h75r-c4qw", + "modified": "2022-09-25T00:00:22Z", + "published": "2022-09-25T00:00:22Z", + "aliases": [ + "CVE-2022-40310" + ], + "details": "Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40310" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rate-my-post/wordpress-rate-my-post-wp-rating-system-plugin-3-3-4-race-condition-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/rate-my-post/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wh36-484v-vm65/GHSA-wh36-484v-vm65.json b/advisories/unreviewed/2022/09/GHSA-wh36-484v-vm65/GHSA-wh36-484v-vm65.json new file mode 100644 index 00000000000..842ba5313bd --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-wh36-484v-vm65/GHSA-wh36-484v-vm65.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-wh36-484v-vm65", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-30124" + ], + "details": "An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30124" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1126414" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-whxv-p57p-v97w/GHSA-whxv-p57p-v97w.json b/advisories/unreviewed/2022/09/GHSA-whxv-p57p-v97w/GHSA-whxv-p57p-v97w.json new file mode 100644 index 00000000000..6d1878bf77c --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-whxv-p57p-v97w/GHSA-whxv-p57p-v97w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-whxv-p57p-v97w", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-38061" + ], + "details": "Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38061" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/export-post-info/wordpress-export-post-info-plugin-1-2-0-authenticated-csv-injection-vulnerability/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/export-post-info/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wj23-j559-8mf4/GHSA-wj23-j559-8mf4.json b/advisories/unreviewed/2022/09/GHSA-wj23-j559-8mf4/GHSA-wj23-j559-8mf4.json new file mode 100644 index 00000000000..cfb7533fd3b --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-wj23-j559-8mf4/GHSA-wj23-j559-8mf4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-wj23-j559-8mf4", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-40114" + ], + "details": "Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40114" + }, + { + "type": "WEB", + "url": "https://github.com/zakee94/online-banking-system/issues/16" + }, + { + "type": "WEB", + "url": "https://github.com/0clickjacking0/BugReport/blob/main/online-banking-system/sql_injection5.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wj87-2328-6c5m/GHSA-wj87-2328-6c5m.json b/advisories/unreviewed/2022/09/GHSA-wj87-2328-6c5m/GHSA-wj87-2328-6c5m.json new file mode 100644 index 00000000000..68d9dc28807 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-wj87-2328-6c5m/GHSA-wj87-2328-6c5m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-wj87-2328-6c5m", + "modified": "2022-09-25T00:00:21Z", + "published": "2022-09-25T00:00:21Z", + "aliases": [ + "CVE-2022-40215" + ], + "details": "Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40215" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vc-tabs/wordpress-tabs-plugin-3-7-1-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities/_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/vc-tabs/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-wjvx-p9xx-8cxp/GHSA-wjvx-p9xx-8cxp.json b/advisories/unreviewed/2022/09/GHSA-wjvx-p9xx-8cxp/GHSA-wjvx-p9xx-8cxp.json new file mode 100644 index 00000000000..0f18d494a49 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-wjvx-p9xx-8cxp/GHSA-wjvx-p9xx-8cxp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-wjvx-p9xx-8cxp", + "modified": "2022-09-25T00:00:15Z", + "published": "2022-09-25T00:00:15Z", + "aliases": [ + "CVE-2022-38573" + ], + "details": "10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38573" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/168133/10-Strike-Network-Inventory-Explorer-9.3-Buffer-Overflow.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-ww8h-58w2-5v3c/GHSA-ww8h-58w2-5v3c.json b/advisories/unreviewed/2022/09/GHSA-ww8h-58w2-5v3c/GHSA-ww8h-58w2-5v3c.json index fd3e0e19e13..88c8c71e506 100644 --- a/advisories/unreviewed/2022/09/GHSA-ww8h-58w2-5v3c/GHSA-ww8h-58w2-5v3c.json +++ b/advisories/unreviewed/2022/09/GHSA-ww8h-58w2-5v3c/GHSA-ww8h-58w2-5v3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-ww8h-58w2-5v3c", - "modified": "2022-09-23T00:00:32Z", + "modified": "2022-09-25T00:00:27Z", "published": "2022-09-23T00:00:32Z", "aliases": [ "CVE-2022-35029" ], "details": "OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json b/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json new file mode 100644 index 00000000000..b34c8173161 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-x2rq-mrc8-r79h/GHSA-x2rq-mrc8-r79h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-x2rq-mrc8-r79h", + "modified": "2022-09-25T00:00:15Z", + "published": "2022-09-25T00:00:15Z", + "aliases": [ + "CVE-2022-37235" + ], + "details": "Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37235" + }, + { + "type": "WEB", + "url": "https://github.com/Davidteeri/Bug-Report/blob/main/netgear-R7000-0x461bc.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security/" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/support/download/?model=R7000" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json b/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json index 8f27fbee034..ce25dbcfeb9 100644 --- a/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json +++ b/advisories/unreviewed/2022/09/GHSA-x92w-hx54-ffh8/GHSA-x92w-hx54-ffh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.3.0", "id": "GHSA-x92w-hx54-ffh8", - "modified": "2022-09-21T00:00:35Z", + "modified": "2022-09-25T00:00:19Z", "published": "2022-09-21T00:00:35Z", "aliases": [ "CVE-2022-28640" ], "details": "A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xc4f-pxh3-qwrq/GHSA-xc4f-pxh3-qwrq.json b/advisories/unreviewed/2022/09/GHSA-xc4f-pxh3-qwrq/GHSA-xc4f-pxh3-qwrq.json new file mode 100644 index 00000000000..a008070036c --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xc4f-pxh3-qwrq/GHSA-xc4f-pxh3-qwrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xc4f-pxh3-qwrq", + "modified": "2022-09-25T00:00:18Z", + "published": "2022-09-25T00:00:18Z", + "aliases": [ + "CVE-2022-41319" + ], + "details": "A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login page (aka the DLOServer/restore/login.jsp URI). This affects versions before 9.8 (e.g., 9.1 through 9.7).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41319" + }, + { + "type": "WEB", + "url": "https://www.veritas.com/content/support/en_US/security/VTS22-010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xch5-pwh8-cf69/GHSA-xch5-pwh8-cf69.json b/advisories/unreviewed/2022/09/GHSA-xch5-pwh8-cf69/GHSA-xch5-pwh8-cf69.json new file mode 100644 index 00000000000..bf1c0ff1d77 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xch5-pwh8-cf69/GHSA-xch5-pwh8-cf69.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xch5-pwh8-cf69", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32785" + ], + "details": "A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing an image may lead to a denial-of-service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32785" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213346" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xg7c-263c-79vp/GHSA-xg7c-263c-79vp.json b/advisories/unreviewed/2022/09/GHSA-xg7c-263c-79vp/GHSA-xg7c-263c-79vp.json new file mode 100644 index 00000000000..fdc69977c46 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xg7c-263c-79vp/GHSA-xg7c-263c-79vp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xg7c-263c-79vp", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-34348" + ], + "details": "IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 230017.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34348" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230017" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6695927" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xhpr-rjf3-gg6p/GHSA-xhpr-rjf3-gg6p.json b/advisories/unreviewed/2022/09/GHSA-xhpr-rjf3-gg6p/GHSA-xhpr-rjf3-gg6p.json new file mode 100644 index 00000000000..181bcbdb70a --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xhpr-rjf3-gg6p/GHSA-xhpr-rjf3-gg6p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xhpr-rjf3-gg6p", + "modified": "2022-09-25T00:00:27Z", + "published": "2022-09-25T00:00:27Z", + "aliases": [ + "CVE-2022-2785" + ], + "details": "There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2785" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/bpf/bpf/c/86f44fcec22c" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/bpf/20220816205517.682470-1-zhuyifei@google.com/T/#t" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json b/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json new file mode 100644 index 00000000000..2bfc69f979a --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xhq5-7429-4hrv/GHSA-xhq5-7429-4hrv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xhq5-7429-4hrv", + "modified": "2022-09-25T00:00:16Z", + "published": "2022-09-25T00:00:16Z", + "aliases": [ + "CVE-2022-32786" + ], + "details": "An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32786" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213343" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213344" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213345" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xmxp-x783-v5rx/GHSA-xmxp-x783-v5rx.json b/advisories/unreviewed/2022/09/GHSA-xmxp-x783-v5rx/GHSA-xmxp-x783-v5rx.json new file mode 100644 index 00000000000..3c880325e9f --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xmxp-x783-v5rx/GHSA-xmxp-x783-v5rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xmxp-x783-v5rx", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-40093" + ], + "details": "Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40093" + }, + { + "type": "WEB", + "url": "https://github.com/autumnmap/Bug_report/blob/main/vendors/mayuri_k/online-tours-travels-management-system/SQLi-3.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xrmg-5x28-jv6w/GHSA-xrmg-5x28-jv6w.json b/advisories/unreviewed/2022/09/GHSA-xrmg-5x28-jv6w/GHSA-xrmg-5x28-jv6w.json new file mode 100644 index 00000000000..5d71fdb5183 --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xrmg-5x28-jv6w/GHSA-xrmg-5x28-jv6w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xrmg-5x28-jv6w", + "modified": "2022-09-25T00:00:19Z", + "published": "2022-09-25T00:00:19Z", + "aliases": [ + "CVE-2022-35097" + ], + "details": "SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35097" + }, + { + "type": "WEB", + "url": "https://github.com/matthiaskramm/swftools/issues/182" + }, + { + "type": "WEB", + "url": "https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35097.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json b/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json new file mode 100644 index 00000000000..102e1cede4a --- /dev/null +++ b/advisories/unreviewed/2022/09/GHSA-xx24-pg44-2jhw/GHSA-xx24-pg44-2jhw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.3.0", + "id": "GHSA-xx24-pg44-2jhw", + "modified": "2022-09-25T00:00:18Z", + "published": "2022-09-25T00:00:18Z", + "aliases": [ + "CVE-2022-40630" + ], + "details": "This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40630" + }, + { + "type": "WEB", + "url": "https://tacitine.com/newdownload/CVE-2022-40630.pdf" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2022-0363" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false + } +} \ No newline at end of file