Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-11-09 00:35:14 +00:00
parent 3a8cfa41fe
commit be9e46e9ff
67 changed files with 1517 additions and 92 deletions
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25643"
},
{
"type": "WEB",
"url": "https://github.com/kennylevinsen/seatd/commit/10658dc5439db429af0088295a051c53925a4416"
},
{
"type": "WEB",
"url": "https://github.com/kennylevinsen/seatd/commit/7cffe0797fdb17a9c08922339465b1b187394335"
},
{
"type": "WEB",
"url": "https://github.com/kennylevinsen/seatd/compare/0.6.3...0.6.4"
@@ -36,7 +44,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-668"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31855"
},
{
"type": "WEB",
"url": "https://github.com/KDE/messagelib/commit/3b5b171e91ce78b966c98b1292a1bcbc8d984799"
},
{
"type": "WEB",
"url": "https://kde.org/info/security/advisory-20210429-1.txt"
@@ -28,6 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312",
"CWE-319"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j35-7cr4-3mc8",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21930"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:13Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gxv-52gp-vmhp",
"modified": "2023-04-18T15:30:18Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-14T21:30:24Z",
"aliases": [
"CVE-2023-2033"
@@ -57,6 +57,10 @@
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202309-17"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5390"
@@ -66,7 +70,7 @@
"cwe_ids": [
"CWE-843"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-14T19:15:00Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x3h-4f64-v6v6",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21954"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:15Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pqg-44mx-r5gr",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21938"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:14Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6j2-4r52-mpg7",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21968"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:16Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vr26-5f5w-r829",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21937"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:14Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wg7x-fvjp-r3fx",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21967"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:16Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfrf-5cgw-f964",
"modified": "2023-04-18T21:30:29Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-04-18T21:30:29Z",
"aliases": [
"CVE-2023-21939"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0008/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5430"
@@ -46,9 +50,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-04-18T20:15:14Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mwf-hvfp-6xfg",
"modified": "2023-06-12T18:30:17Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-06-06T00:30:19Z",
"aliases": [
"CVE-2023-3079"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4OXTNIZY4JYHJT7CVLPAJQILI6BISVM/"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5420"
@@ -46,7 +50,7 @@
"cwe_ids": [
"CWE-843"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-05T22:15:12Z"
@@ -41,6 +41,6 @@
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T12:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcqh-qfj4-8h2g",
"modified": "2023-10-31T15:30:24Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-10-31T15:30:24Z",
"aliases": [
"CVE-2023-42425"
],
"details": "An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,11 +32,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T15:15:09Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q385-6v59-7vxv",
"modified": "2023-10-31T15:30:22Z",
"modified": "2023-11-09T00:33:54Z",
"published": "2023-10-31T15:30:22Z",
"aliases": [
"CVE-2016-1203"
],
"details": "Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,9 +34,9 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
"nvd_published_at": "2023-10-31T13:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2974-5gjv-486c",
"modified": "2023-11-09T00:33:56Z",
"published": "2023-11-09T00:33:56Z",
"aliases": [
"CVE-2023-43570"
],
"details": "\nA potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code. \n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43570"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-141775"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T22:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2gcw-vfw4-7268",
"modified": "2023-11-09T00:33:55Z",
"published": "2023-11-09T00:33:55Z",
"aliases": [
"CVE-2023-43567"
],
"details": "A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43567"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-141775"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T22:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pxc-8fhw-2cw4",
"modified": "2023-11-09T00:33:56Z",
"published": "2023-11-09T00:33:56Z",
"aliases": [
"CVE-2023-5075"
],
"details": "A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5075"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-141775"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T22:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3cwq-cmm2-67gg",
"modified": "2023-11-09T00:33:56Z",
"published": "2023-11-09T00:33:56Z",
"aliases": [
"CVE-2023-43574"
],
"details": "A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges\n\nto disclose sensitive information.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43574"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-141775"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T23:15:09Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f7x-wmqw-jp3f",
"modified": "2023-11-06T06:30:26Z",
"modified": "2023-11-09T00:33:55Z",
"published": "2023-11-06T06:30:26Z",
"aliases": [
"CVE-2023-32838"
],
"details": "In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-06T04:15:08Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4439-7p27-rx63",
"modified": "2023-11-09T00:33:56Z",
"published": "2023-11-09T00:33:56Z",
"aliases": [
"CVE-2023-4891"
],
"details": "\nA potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. \n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4891"
},
{
"type": "WEB",
"url": "https://support.lenovo.com/us/en/product_security/LEN-135344"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-11-08T22:15:11Z"
}
}

Some files were not shown because too many files have changed in this diff Show More