Publish Advisories

GHSA-84cf-cm69-mj8w
GHSA-8rfc-c9wp-w4x6
GHSA-373g-hg3v-qf78
GHSA-3v8g-fm64-g4mc
GHSA-563c-g7mm-g4xp
GHSA-69x6-6jqx-q847
GHSA-7369-x5q2-rh2m
GHSA-7j5g-jfh2-w58c
GHSA-7jrj-xq8x-h553
GHSA-9wvx-3hw8-4ghf
GHSA-9x8m-8qxp-gj73
GHSA-cr94-c6j4-q6g5
GHSA-gqq7-89cw-236x
GHSA-gvhm-xpqg-38jw
GHSA-gx25-vx95-m52w
GHSA-hf5v-h65q-2g27
GHSA-jgv7-f85p-m95j
GHSA-mcjx-2c4v-mvg9
GHSA-vhmm-vh3j-5vww
This commit is contained in:
advisory-database[bot]
2024-08-07 00:32:21 +00:00
parent 736cc117c0
commit bb52b5781e
19 changed files with 206 additions and 38 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84cf-cm69-mj8w",
"modified": "2024-04-29T18:30:46Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-04-29T18:30:46Z",
"aliases": [
"CVE-2023-51254"
],
"details": "Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T18:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rfc-c9wp-w4x6",
"modified": "2024-04-26T15:30:34Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-04-26T15:30:34Z",
"aliases": [
"CVE-2024-33258"
],
"details": "Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-26T15:15:49Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-373g-hg3v-qf78",
"modified": "2024-08-06T21:30:48Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T21:30:48Z",
"aliases": [
"CVE-2024-7534"
],
"details": "Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-122"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T21:16:04Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3v8g-fm64-g4mc",
"modified": "2024-08-06T18:30:57Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T18:30:57Z",
"aliases": [
"CVE-2024-6991"
],
"details": "Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T16:15:50Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-563c-g7mm-g4xp",
"modified": "2024-08-06T15:30:53Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7521"
@@ -36,6 +36,14 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-69x6-6jqx-q847",
"modified": "2024-08-06T18:30:56Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7527"
@@ -36,6 +36,14 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7369-x5q2-rh2m",
"modified": "2024-08-06T15:30:53Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7525"
],
"details": "It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
@@ -33,13 +36,21 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T13:15:57Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7j5g-jfh2-w58c",
"modified": "2024-08-06T18:30:56Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7520"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jrj-xq8x-h553",
"modified": "2024-08-06T15:30:53Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7522"
@@ -33,6 +33,14 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9wvx-3hw8-4ghf",
"modified": "2024-08-06T15:30:53Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7519"
@@ -33,6 +33,14 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x8m-8qxp-gj73",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-07T00:30:47Z",
"aliases": [
"CVE-2024-38166"
],
"details": "An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38166"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38166"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T22:15:54Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr94-c6j4-q6g5",
"modified": "2024-08-06T15:30:54Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:54Z",
"aliases": [
"CVE-2024-7529"
@@ -36,6 +36,14 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqq7-89cw-236x",
"modified": "2024-08-06T21:30:48Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T21:30:48Z",
"aliases": [
"CVE-2024-7536"
],
"details": "Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T21:16:04Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gvhm-xpqg-38jw",
"modified": "2024-08-06T21:30:47Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T21:30:47Z",
"aliases": [
"CVE-2024-28739"
],
"details": "An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T19:15:56Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gx25-vx95-m52w",
"modified": "2024-08-06T15:30:54Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:54Z",
"aliases": [
"CVE-2024-7528"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf5v-h65q-2g27",
"modified": "2024-08-06T15:30:53Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7526"
@@ -33,6 +33,14 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-38"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgv7-f85p-m95j",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-07T00:30:47Z",
"aliases": [
"CVE-2024-38206"
],
"details": "An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38206"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38206"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-06T22:15:54Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcjx-2c4v-mvg9",
"modified": "2024-08-06T15:30:53Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-06T15:30:53Z",
"aliases": [
"CVE-2024-7518"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-35"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2024-37"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhmm-vh3j-5vww",
"modified": "2024-08-02T18:31:12Z",
"modified": "2024-08-07T00:30:47Z",
"published": "2024-08-02T18:31:12Z",
"aliases": [
"CVE-2024-38886"
],
"details": "An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-940"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T18:16:19Z"