diff --git a/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json b/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json index 6e3228a2347..d2cad17a1a1 100644 --- a/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json +++ b/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77jm-r76q-g5ph", - "modified": "2024-01-19T21:30:34Z", + "modified": "2024-09-04T03:30:44Z", "published": "2024-01-16T12:30:26Z", "aliases": [ "CVE-2023-52106" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://consumer.huawei.com/en/support/bulletin/2024/1" }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + }, { "type": "WEB", "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" diff --git a/advisories/unreviewed/2024/09/GHSA-2cfc-579m-w2fj/GHSA-2cfc-579m-w2fj.json b/advisories/unreviewed/2024/09/GHSA-2cfc-579m-w2fj/GHSA-2cfc-579m-w2fj.json new file mode 100644 index 00000000000..a057e372e05 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2cfc-579m-w2fj/GHSA-2cfc-579m-w2fj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cfc-579m-w2fj", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-45450" + ], + "details": "Permission control vulnerability in the software update module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45450" + }, + { + "type": "WEB", + "url": "https://https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T02:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-325c-wxfw-8v2c/GHSA-325c-wxfw-8v2c.json b/advisories/unreviewed/2024/09/GHSA-325c-wxfw-8v2c/GHSA-325c-wxfw-8v2c.json new file mode 100644 index 00000000000..476dbedda60 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-325c-wxfw-8v2c/GHSA-325c-wxfw-8v2c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-325c-wxfw-8v2c", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-45444" + ], + "details": "Access permission verification vulnerability in the WMS module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45444" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5rgc-q76g-34wh/GHSA-5rgc-q76g-34wh.json b/advisories/unreviewed/2024/09/GHSA-5rgc-q76g-34wh/GHSA-5rgc-q76g-34wh.json new file mode 100644 index 00000000000..d819fc93581 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5rgc-q76g-34wh/GHSA-5rgc-q76g-34wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rgc-q76g-34wh", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-45446" + ], + "details": "Access permission verification vulnerability in the camera driver module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45446" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7c3r-4j4x-4rjj/GHSA-7c3r-4j4x-4rjj.json b/advisories/unreviewed/2024/09/GHSA-7c3r-4j4x-4rjj/GHSA-7c3r-4j4x-4rjj.json new file mode 100644 index 00000000000..cf27b9f06f0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7c3r-4j4x-4rjj/GHSA-7c3r-4j4x-4rjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c3r-4j4x-4rjj", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-45445" + ], + "details": "Vulnerability of resources not being closed or released in the keystore module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45445" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-82c2-gvr4-jj72/GHSA-82c2-gvr4-jj72.json b/advisories/unreviewed/2024/09/GHSA-82c2-gvr4-jj72/GHSA-82c2-gvr4-jj72.json new file mode 100644 index 00000000000..30d8c2bcb68 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-82c2-gvr4-jj72/GHSA-82c2-gvr4-jj72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82c2-gvr4-jj72", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-45449" + ], + "details": "Access permission verification vulnerability in the ringtone setting module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45449" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c5j5-cf8h-96p6/GHSA-c5j5-cf8h-96p6.json b/advisories/unreviewed/2024/09/GHSA-c5j5-cf8h-96p6/GHSA-c5j5-cf8h-96p6.json new file mode 100644 index 00000000000..3d186d09657 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c5j5-cf8h-96p6/GHSA-c5j5-cf8h-96p6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5j5-cf8h-96p6", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-39921" + ], + "details": "Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can obtain the contents of the communication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39921" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN29238389" + }, + { + "type": "WEB", + "url": "https://www.fujitsu.com/jp/products/network/support/2024/ipcom-04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fv25-93g9-xjjv/GHSA-fv25-93g9-xjjv.json b/advisories/unreviewed/2024/09/GHSA-fv25-93g9-xjjv/GHSA-fv25-93g9-xjjv.json new file mode 100644 index 00000000000..3e6b0b68895 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fv25-93g9-xjjv/GHSA-fv25-93g9-xjjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv25-93g9-xjjv", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-45448" + ], + "details": "Page table protection configuration vulnerability in the trusted firmware module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45448" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gx34-4qhf-jgr6/GHSA-gx34-4qhf-jgr6.json b/advisories/unreviewed/2024/09/GHSA-gx34-4qhf-jgr6/GHSA-gx34-4qhf-jgr6.json new file mode 100644 index 00000000000..0eeb0fc88ea --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gx34-4qhf-jgr6/GHSA-gx34-4qhf-jgr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx34-4qhf-jgr6", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-45447" + ], + "details": "Access control vulnerability in the camera framework module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45447" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mp2j-278w-pv83/GHSA-mp2j-278w-pv83.json b/advisories/unreviewed/2024/09/GHSA-mp2j-278w-pv83/GHSA-mp2j-278w-pv83.json new file mode 100644 index 00000000000..6f69b91febe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mp2j-278w-pv83/GHSA-mp2j-278w-pv83.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp2j-278w-pv83", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-45443" + ], + "details": "Directory traversal vulnerability in the cust module\nImpact: Successful exploitation of this vulnerability will affect availability and confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45443" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mww4-7pfq-38g6/GHSA-mww4-7pfq-38g6.json b/advisories/unreviewed/2024/09/GHSA-mww4-7pfq-38g6/GHSA-mww4-7pfq-38g6.json new file mode 100644 index 00000000000..611abac9154 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mww4-7pfq-38g6/GHSA-mww4-7pfq-38g6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mww4-7pfq-38g6", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-45441" + ], + "details": "Input verification vulnerability in the system service module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45441" + }, + { + "type": "WEB", + "url": "https://https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T02:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pf98-xx8j-74qh/GHSA-pf98-xx8j-74qh.json b/advisories/unreviewed/2024/09/GHSA-pf98-xx8j-74qh/GHSA-pf98-xx8j-74qh.json new file mode 100644 index 00000000000..4cebaf4fb00 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pf98-xx8j-74qh/GHSA-pf98-xx8j-74qh.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf98-xx8j-74qh", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-7950" + ], + "details": "The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the 'checkFormRequest' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. Attackers can also update arbitrary settings and create user accounts even when registration is disabled, leading to user creation with a default role of Administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7950" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.1.5/includes/formhandler.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.1.5/includes/includer.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.1.5/includes/wpjobportal-hooks.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.1.5/modules/configuration/controller.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.1.5/modules/user/controller.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.1.5/modules/user/tmpl/views/frontend/form-field.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3138675" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1d5275-3398-47a7-889b-4050ebe635ee?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json b/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json new file mode 100644 index 00000000000..89a593ab95c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pq2c-46q4-qwg3/GHSA-pq2c-46q4-qwg3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq2c-46q4-qwg3", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-41716" + ], + "details": "Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able to manipulate and/or suspend the PLC and Operator Interfaces by accessing or hijacking them.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41716" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN08342147" + }, + { + "type": "WEB", + "url": "https://us.idec.com/media/24-RD-0219-EN.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q4gj-2fgv-hpxf/GHSA-q4gj-2fgv-hpxf.json b/advisories/unreviewed/2024/09/GHSA-q4gj-2fgv-hpxf/GHSA-q4gj-2fgv-hpxf.json new file mode 100644 index 00000000000..3f26d1cc069 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q4gj-2fgv-hpxf/GHSA-q4gj-2fgv-hpxf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4gj-2fgv-hpxf", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-41927" + ], + "details": "Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41927" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU96959731" + }, + { + "type": "WEB", + "url": "https://us.idec.com/media/24-RD-0256-EN.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json b/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json new file mode 100644 index 00000000000..901c2bde959 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5h4-2jhc-x7wp", + "modified": "2024-09-04T03:30:45Z", + "published": "2024-09-04T03:30:45Z", + "aliases": [ + "CVE-2024-8298" + ], + "details": "Memory request vulnerability in the memory management module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8298" + }, + { + "type": "WEB", + "url": "https://https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T03:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r6x2-5fqg-2qj5/GHSA-r6x2-5fqg-2qj5.json b/advisories/unreviewed/2024/09/GHSA-r6x2-5fqg-2qj5/GHSA-r6x2-5fqg-2qj5.json new file mode 100644 index 00000000000..c18f218cf56 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r6x2-5fqg-2qj5/GHSA-r6x2-5fqg-2qj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6x2-5fqg-2qj5", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-45442" + ], + "details": "Vulnerability of permission verification for APIs in the DownloadProviderMain module\nImpact: Successful exploitation of this vulnerability will affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45442" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T02:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-w73v-v2m6-g85c/GHSA-w73v-v2m6-g85c.json b/advisories/unreviewed/2024/09/GHSA-w73v-v2m6-g85c/GHSA-w73v-v2m6-g85c.json new file mode 100644 index 00000000000..cff22b69b1f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-w73v-v2m6-g85c/GHSA-w73v-v2m6-g85c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w73v-v2m6-g85c", + "modified": "2024-09-04T03:30:44Z", + "published": "2024-09-04T03:30:44Z", + "aliases": [ + "CVE-2024-42039" + ], + "details": "Access control vulnerability in the SystemUI module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42039" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T02:15:03Z" + } +} \ No newline at end of file