diff --git a/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json b/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json index 8baae454aad..b3b7eccae49 100644 --- a/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json +++ b/advisories/unreviewed/2024/03/GHSA-xcpx-x4rg-25pv/GHSA-xcpx-x4rg-25pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xcpx-x4rg-25pv", - "modified": "2024-03-18T18:32:21Z", + "modified": "2024-12-03T00:31:29Z", "published": "2024-03-18T18:32:21Z", "aliases": [ "CVE-2024-26050" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/05/GHSA-p887-27mf-gvwv/GHSA-p887-27mf-gvwv.json b/advisories/unreviewed/2024/05/GHSA-p887-27mf-gvwv/GHSA-p887-27mf-gvwv.json index d71cc6c944c..af4ede02fdb 100644 --- a/advisories/unreviewed/2024/05/GHSA-p887-27mf-gvwv/GHSA-p887-27mf-gvwv.json +++ b/advisories/unreviewed/2024/05/GHSA-p887-27mf-gvwv/GHSA-p887-27mf-gvwv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pc92-542g-jrp5/GHSA-pc92-542g-jrp5.json b/advisories/unreviewed/2024/05/GHSA-pc92-542g-jrp5/GHSA-pc92-542g-jrp5.json index cfcad914217..185ecf44085 100644 --- a/advisories/unreviewed/2024/05/GHSA-pc92-542g-jrp5/GHSA-pc92-542g-jrp5.json +++ b/advisories/unreviewed/2024/05/GHSA-pc92-542g-jrp5/GHSA-pc92-542g-jrp5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json b/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json index 9d5f2b42456..996ee0a6064 100644 --- a/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json +++ b/advisories/unreviewed/2024/08/GHSA-9m45-g52w-xm9x/GHSA-9m45-g52w-xm9x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json b/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json new file mode 100644 index 00000000000..05fbf9713b9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23mj-f5f2-4h46", + "modified": "2024-12-03T00:31:31Z", + "published": "2024-12-03T00:31:31Z", + "aliases": [ + "CVE-2024-53939" + ], + "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53939" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/CVE-2024-53939.txt" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/RX1800-EN_V1.0.0_r12_110933-CMD-INJ-WIFI-SHELL.gif" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/Victure_RX1800_Security_Report.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json b/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json new file mode 100644 index 00000000000..8c73ef6c9cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6962-78fv-7v2v/GHSA-6962-78fv-7v2v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6962-78fv-7v2v", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9418" + ], + "details": "In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9418" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8ggj-85qv-ffm2/GHSA-8ggj-85qv-ffm2.json b/advisories/unreviewed/2024/12/GHSA-8ggj-85qv-ffm2/GHSA-8ggj-85qv-ffm2.json new file mode 100644 index 00000000000..e6940ac479c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8ggj-85qv-ffm2/GHSA-8ggj-85qv-ffm2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ggj-85qv-ffm2", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9423" + ], + "details": "In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c there is a possible out of bound read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9423" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8wr8-x8hv-fmqv/GHSA-8wr8-x8hv-fmqv.json b/advisories/unreviewed/2024/12/GHSA-8wr8-x8hv-fmqv/GHSA-8wr8-x8hv-fmqv.json new file mode 100644 index 00000000000..870a47e34a5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8wr8-x8hv-fmqv/GHSA-8wr8-x8hv-fmqv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wr8-x8hv-fmqv", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9429" + ], + "details": "In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9429" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json b/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json new file mode 100644 index 00000000000..2bc21e7d597 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rp-8r7p-prmv", + "modified": "2024-12-03T00:31:31Z", + "published": "2024-12-03T00:31:31Z", + "aliases": [ + "CVE-2024-53938" + ], + "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achieve full control over the router remotely without any authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53938" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/CVE-2024-53938.txt" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/Victure_RX1800_Security_Report.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9xgh-98m3-h62h/GHSA-9xgh-98m3-h62h.json b/advisories/unreviewed/2024/12/GHSA-9xgh-98m3-h62h/GHSA-9xgh-98m3-h62h.json new file mode 100644 index 00000000000..453f3d465b5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9xgh-98m3-h62h/GHSA-9xgh-98m3-h62h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xgh-98m3-h62h", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9431" + ], + "details": "In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9431" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json b/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json new file mode 100644 index 00000000000..b63af8e7a5e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chvj-r97v-jv3h", + "modified": "2024-12-03T00:31:32Z", + "published": "2024-12-03T00:31:32Z", + "aliases": [ + "CVE-2024-53937" + ], + "details": "An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with root-level permissions. Device setup does not require this password to be changed during setup in order to utilize the device. (However, the TELNET password is dictated by the current GUI password.)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53937" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/CVE-2024-53937.txt" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/Victure_RX1800_Security_Report.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T23:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json b/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json new file mode 100644 index 00000000000..3a5792be3f9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4c6-r2qh-5wvm", + "modified": "2024-12-03T00:31:31Z", + "published": "2024-12-03T00:31:31Z", + "aliases": [ + "CVE-2024-53941" + ], + "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53941" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/CVE-2024-53941.txt" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/Victure_RX1800_Security_Report.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json b/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json new file mode 100644 index 00000000000..a589d473c08 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhf4-rfw7-w7pj", + "modified": "2024-12-03T00:31:31Z", + "published": "2024-12-03T00:31:31Z", + "aliases": [ + "CVE-2024-53940" + ], + "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the ping utility, enabling arbitrary command execution with root-level permissions on the device.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53940" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Victure/CVE-2024-53940.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p63w-272x-4755/GHSA-p63w-272x-4755.json b/advisories/unreviewed/2024/12/GHSA-p63w-272x-4755/GHSA-p63w-272x-4755.json new file mode 100644 index 00000000000..78901a9101f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p63w-272x-4755/GHSA-p63w-272x-4755.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p63w-272x-4755", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9430" + ], + "details": "In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9430" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pjm2-9jh6-vjw2/GHSA-pjm2-9jh6-vjw2.json b/advisories/unreviewed/2024/12/GHSA-pjm2-9jh6-vjw2/GHSA-pjm2-9jh6-vjw2.json new file mode 100644 index 00000000000..e69e7ef5db4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pjm2-9jh6-vjw2/GHSA-pjm2-9jh6-vjw2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjm2-9jh6-vjw2", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9426" + ], + "details": "In  RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementation could cause weak RSA key pairs being generated. This could lead to crypto vulnerability with no additional execution privileges needed. User interaction is not needed for exploitation. Bulletin Fix: The fix is designed to correctly implement the key generation according to FIPS standard.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9426" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pvf4-gmq6-p9cx/GHSA-pvf4-gmq6-p9cx.json b/advisories/unreviewed/2024/12/GHSA-pvf4-gmq6-p9cx/GHSA-pvf4-gmq6-p9cx.json index 4665779f9b4..c1c4a8f6c40 100644 --- a/advisories/unreviewed/2024/12/GHSA-pvf4-gmq6-p9cx/GHSA-pvf4-gmq6-p9cx.json +++ b/advisories/unreviewed/2024/12/GHSA-pvf4-gmq6-p9cx/GHSA-pvf4-gmq6-p9cx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvf4-gmq6-p9cx", - "modified": "2024-12-02T21:31:19Z", + "modified": "2024-12-03T00:31:30Z", "published": "2024-12-02T21:31:19Z", "aliases": [ "CVE-2018-9381" ], "details": "In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T20:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-r6f7-w899-79q2/GHSA-r6f7-w899-79q2.json b/advisories/unreviewed/2024/12/GHSA-r6f7-w899-79q2/GHSA-r6f7-w899-79q2.json new file mode 100644 index 00000000000..ff68494ac50 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r6f7-w899-79q2/GHSA-r6f7-w899-79q2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6f7-w899-79q2", + "modified": "2024-12-03T00:31:30Z", + "published": "2024-12-03T00:31:30Z", + "aliases": [ + "CVE-2018-9435" + ], + "details": "In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9435" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel/2018-08-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json b/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json new file mode 100644 index 00000000000..fe919a4f73a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx8m-vcrx-w4p5", + "modified": "2024-12-03T00:31:31Z", + "published": "2024-12-03T00:31:31Z", + "aliases": [ + "CVE-2024-53375" + ], + "details": "Authenticated remote code execution (RCE) vulnerabilities affect TP-Link Archer, Deco, and Tapo series routers. A vulnerability exists in the \"tmp_get_sites\" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the installation or activation of the HomeShield functionality.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53375" + }, + { + "type": "WEB", + "url": "https://github.com/ThottySploity/CVE-2024-53375" + }, + { + "type": "WEB", + "url": "https://thottysploity.github.io/posts/cve-2024-53375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xm64-rgmg-cp62/GHSA-xm64-rgmg-cp62.json b/advisories/unreviewed/2024/12/GHSA-xm64-rgmg-cp62/GHSA-xm64-rgmg-cp62.json index 2f29f5dcc85..6433fc091ef 100644 --- a/advisories/unreviewed/2024/12/GHSA-xm64-rgmg-cp62/GHSA-xm64-rgmg-cp62.json +++ b/advisories/unreviewed/2024/12/GHSA-xm64-rgmg-cp62/GHSA-xm64-rgmg-cp62.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xm64-rgmg-cp62", - "modified": "2024-12-02T21:31:19Z", + "modified": "2024-12-03T00:31:30Z", "published": "2024-12-02T21:31:19Z", "aliases": [ "CVE-2018-9380" ], "details": "In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T20:15:04Z"