From be9e46e9ffa428d7b9d8889396fa7396a77c213d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Nov 2023 00:35:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-m93q-8wxv-xgc5.json | 11 ++++- .../GHSA-h76g-vp43-8cw5.json | 5 ++ .../GHSA-4j35-7cr4-3mc8.json | 10 ++-- .../GHSA-5gxv-52gp-vmhp.json | 8 +++- .../GHSA-8x3h-4f64-v6v6.json | 10 ++-- .../GHSA-9pqg-44mx-r5gr.json | 10 ++-- .../GHSA-r6j2-4r52-mpg7.json | 10 ++-- .../GHSA-vr26-5f5w-r829.json | 10 ++-- .../GHSA-wg7x-fvjp-r3fx.json | 10 ++-- .../GHSA-xfrf-5cgw-f964.json | 10 ++-- .../GHSA-8mwf-hvfp-6xfg.json | 8 +++- .../GHSA-79jx-q243-6wc7.json | 2 +- .../GHSA-pcqh-qfj4-8h2g.json | 13 ++++-- .../GHSA-q385-6v59-7vxv.json | 11 +++-- .../GHSA-2974-5gjv-486c.json | 38 +++++++++++++++ .../GHSA-2gcw-vfw4-7268.json | 38 +++++++++++++++ .../GHSA-2pxc-8fhw-2cw4.json | 38 +++++++++++++++ .../GHSA-3cwq-cmm2-67gg.json | 38 +++++++++++++++ .../GHSA-3f7x-wmqw-jp3f.json | 11 +++-- .../GHSA-4439-7p27-rx63.json | 38 +++++++++++++++ .../GHSA-4c68-prv2-7cp2.json | 11 +++-- .../GHSA-5gxq-f8fx-9847.json | 13 ++++-- .../GHSA-66rr-phv8-5jpp.json | 38 +++++++++++++++ .../GHSA-69g5-4rhf-w2gx.json | 38 +++++++++++++++ .../GHSA-6mhg-89x7-jmrg.json | 38 +++++++++++++++ .../GHSA-74j8-4v49-qf74.json | 38 +++++++++++++++ .../GHSA-75fp-j7f7-j7j8.json | 38 +++++++++++++++ .../GHSA-77h7-f57j-cjv2.json | 38 +++++++++++++++ .../GHSA-7gq7-rh5h-8vq2.json | 11 +++-- .../GHSA-7hgj-2cr9-625f.json | 38 +++++++++++++++ .../GHSA-7j49-vjx9-cwp7.json | 46 +++++++++++++++++++ .../GHSA-7j74-mjgh-q8hf.json | 2 +- .../GHSA-853g-q2x9-h9rr.json | 13 ++++-- .../GHSA-89r9-jhrv-559c.json | 38 +++++++++++++++ .../GHSA-8fj8-2mjg-p38q.json | 38 +++++++++++++++ .../GHSA-8w36-q6qv-jw4f.json | 38 +++++++++++++++ .../GHSA-9vrm-5j5h-x98j.json | 2 +- .../GHSA-c368-3rx3-26ww.json | 2 +- .../GHSA-cjpq-3xp9-4722.json | 38 +++++++++++++++ .../GHSA-fmxw-c4w5-cjwc.json | 38 +++++++++++++++ .../GHSA-g7x3-4v2w-9vxw.json | 2 +- .../GHSA-gq8h-r2cw-gp26.json | 11 +++-- .../GHSA-gw3g-x57p-x5x3.json | 38 +++++++++++++++ .../GHSA-hf79-fwx9-q3gm.json | 38 +++++++++++++++ .../GHSA-hwp3-3266-mxg2.json | 11 +++-- .../GHSA-j2q6-cc54-gcmf.json | 38 +++++++++++++++ .../GHSA-j97j-w85x-cvvq.json | 35 ++++++++++++++ .../GHSA-jgm2-w45w-592c.json | 38 +++++++++++++++ .../GHSA-mh77-wx4j-rgjj.json | 11 +++-- .../GHSA-mv8w-vmwf-98gq.json | 38 +++++++++++++++ .../GHSA-mxq5-hwfr-q6p8.json | 38 +++++++++++++++ .../GHSA-q6v3-24wc-vg36.json | 13 ++++-- .../GHSA-qxv7-837m-ggxx.json | 13 ++++-- .../GHSA-r23r-h529-fcxw.json | 2 +- .../GHSA-rhhg-49v7-xmqc.json | 2 +- .../GHSA-rvf5-fhrh-vc2m.json | 39 ++++++++++++++++ .../GHSA-rwr4-c9v9-crcw.json | 38 +++++++++++++++ .../GHSA-vq49-7r44-hh7p.json | 2 +- .../GHSA-w3vg-2x3w-fq35.json | 38 +++++++++++++++ .../GHSA-w5f9-f469-qpc7.json | 13 ++++-- .../GHSA-wq49-7ccq-37c5.json | 38 +++++++++++++++ .../GHSA-x4x4-4mj9-h7v7.json | 38 +++++++++++++++ .../GHSA-xjf7-7f5m-qhq8.json | 38 +++++++++++++++ .../GHSA-xqfg-p7f2-6w5f.json | 38 +++++++++++++++ .../GHSA-xr7w-c4xp-gqc3.json | 38 +++++++++++++++ .../GHSA-xw58-crph-crhm.json | 38 +++++++++++++++ .../GHSA-xwr9-j862-6mj9.json | 38 +++++++++++++++ 67 files changed, 1517 insertions(+), 92 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-2974-5gjv-486c/GHSA-2974-5gjv-486c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2gcw-vfw4-7268/GHSA-2gcw-vfw4-7268.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2pxc-8fhw-2cw4/GHSA-2pxc-8fhw-2cw4.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3cwq-cmm2-67gg/GHSA-3cwq-cmm2-67gg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4439-7p27-rx63/GHSA-4439-7p27-rx63.json create mode 100644 advisories/unreviewed/2023/11/GHSA-66rr-phv8-5jpp/GHSA-66rr-phv8-5jpp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-69g5-4rhf-w2gx/GHSA-69g5-4rhf-w2gx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6mhg-89x7-jmrg/GHSA-6mhg-89x7-jmrg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-74j8-4v49-qf74/GHSA-74j8-4v49-qf74.json create mode 100644 advisories/unreviewed/2023/11/GHSA-75fp-j7f7-j7j8/GHSA-75fp-j7f7-j7j8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7hgj-2cr9-625f/GHSA-7hgj-2cr9-625f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-89r9-jhrv-559c/GHSA-89r9-jhrv-559c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8fj8-2mjg-p38q/GHSA-8fj8-2mjg-p38q.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8w36-q6qv-jw4f/GHSA-8w36-q6qv-jw4f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fmxw-c4w5-cjwc/GHSA-fmxw-c4w5-cjwc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gw3g-x57p-x5x3/GHSA-gw3g-x57p-x5x3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hf79-fwx9-q3gm/GHSA-hf79-fwx9-q3gm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-j2q6-cc54-gcmf/GHSA-j2q6-cc54-gcmf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jgm2-w45w-592c/GHSA-jgm2-w45w-592c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mv8w-vmwf-98gq/GHSA-mv8w-vmwf-98gq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mxq5-hwfr-q6p8/GHSA-mxq5-hwfr-q6p8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rwr4-c9v9-crcw/GHSA-rwr4-c9v9-crcw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w3vg-2x3w-fq35/GHSA-w3vg-2x3w-fq35.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wq49-7ccq-37c5/GHSA-wq49-7ccq-37c5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x4x4-4mj9-h7v7/GHSA-x4x4-4mj9-h7v7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xjf7-7f5m-qhq8/GHSA-xjf7-7f5m-qhq8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xqfg-p7f2-6w5f/GHSA-xqfg-p7f2-6w5f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xr7w-c4xp-gqc3/GHSA-xr7w-c4xp-gqc3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xw58-crph-crhm/GHSA-xw58-crph-crhm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xwr9-j862-6mj9/GHSA-xwr9-j862-6mj9.json diff --git a/advisories/unreviewed/2022/02/GHSA-m93q-8wxv-xgc5/GHSA-m93q-8wxv-xgc5.json b/advisories/unreviewed/2022/02/GHSA-m93q-8wxv-xgc5/GHSA-m93q-8wxv-xgc5.json index 8f4c0c151c5..2874991db9c 100644 --- a/advisories/unreviewed/2022/02/GHSA-m93q-8wxv-xgc5/GHSA-m93q-8wxv-xgc5.json +++ b/advisories/unreviewed/2022/02/GHSA-m93q-8wxv-xgc5/GHSA-m93q-8wxv-xgc5.json @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25643" }, + { + "type": "WEB", + "url": "https://github.com/kennylevinsen/seatd/commit/10658dc5439db429af0088295a051c53925a4416" + }, + { + "type": "WEB", + "url": "https://github.com/kennylevinsen/seatd/commit/7cffe0797fdb17a9c08922339465b1b187394335" + }, { "type": "WEB", "url": "https://github.com/kennylevinsen/seatd/compare/0.6.3...0.6.4" @@ -36,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-668" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-h76g-vp43-8cw5/GHSA-h76g-vp43-8cw5.json b/advisories/unreviewed/2022/05/GHSA-h76g-vp43-8cw5/GHSA-h76g-vp43-8cw5.json index 11ed9679b7c..d24e71035b1 100644 --- a/advisories/unreviewed/2022/05/GHSA-h76g-vp43-8cw5/GHSA-h76g-vp43-8cw5.json +++ b/advisories/unreviewed/2022/05/GHSA-h76g-vp43-8cw5/GHSA-h76g-vp43-8cw5.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31855" }, + { + "type": "WEB", + "url": "https://github.com/KDE/messagelib/commit/3b5b171e91ce78b966c98b1292a1bcbc8d984799" + }, { "type": "WEB", "url": "https://kde.org/info/security/advisory-20210429-1.txt" @@ -28,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-319" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/04/GHSA-4j35-7cr4-3mc8/GHSA-4j35-7cr4-3mc8.json b/advisories/unreviewed/2023/04/GHSA-4j35-7cr4-3mc8/GHSA-4j35-7cr4-3mc8.json index b080ebfef8a..41c26a9d428 100644 --- a/advisories/unreviewed/2023/04/GHSA-4j35-7cr4-3mc8/GHSA-4j35-7cr4-3mc8.json +++ b/advisories/unreviewed/2023/04/GHSA-4j35-7cr4-3mc8/GHSA-4j35-7cr4-3mc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4j35-7cr4-3mc8", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21930" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:13Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-5gxv-52gp-vmhp/GHSA-5gxv-52gp-vmhp.json b/advisories/unreviewed/2023/04/GHSA-5gxv-52gp-vmhp/GHSA-5gxv-52gp-vmhp.json index 4db90c8717d..5358b4f1937 100644 --- a/advisories/unreviewed/2023/04/GHSA-5gxv-52gp-vmhp/GHSA-5gxv-52gp-vmhp.json +++ b/advisories/unreviewed/2023/04/GHSA-5gxv-52gp-vmhp/GHSA-5gxv-52gp-vmhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gxv-52gp-vmhp", - "modified": "2023-04-18T15:30:18Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-14T21:30:24Z", "aliases": [ "CVE-2023-2033" @@ -57,6 +57,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202309-17" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5390" @@ -66,7 +70,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-14T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8x3h-4f64-v6v6/GHSA-8x3h-4f64-v6v6.json b/advisories/unreviewed/2023/04/GHSA-8x3h-4f64-v6v6/GHSA-8x3h-4f64-v6v6.json index ee652a7dbb2..edf3b585558 100644 --- a/advisories/unreviewed/2023/04/GHSA-8x3h-4f64-v6v6/GHSA-8x3h-4f64-v6v6.json +++ b/advisories/unreviewed/2023/04/GHSA-8x3h-4f64-v6v6/GHSA-8x3h-4f64-v6v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x3h-4f64-v6v6", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21954" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:15Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-9pqg-44mx-r5gr/GHSA-9pqg-44mx-r5gr.json b/advisories/unreviewed/2023/04/GHSA-9pqg-44mx-r5gr/GHSA-9pqg-44mx-r5gr.json index 517f82e7a62..f87191d605e 100644 --- a/advisories/unreviewed/2023/04/GHSA-9pqg-44mx-r5gr/GHSA-9pqg-44mx-r5gr.json +++ b/advisories/unreviewed/2023/04/GHSA-9pqg-44mx-r5gr/GHSA-9pqg-44mx-r5gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pqg-44mx-r5gr", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21938" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:14Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-r6j2-4r52-mpg7/GHSA-r6j2-4r52-mpg7.json b/advisories/unreviewed/2023/04/GHSA-r6j2-4r52-mpg7/GHSA-r6j2-4r52-mpg7.json index 063ca9c6fb4..40c5b899f2b 100644 --- a/advisories/unreviewed/2023/04/GHSA-r6j2-4r52-mpg7/GHSA-r6j2-4r52-mpg7.json +++ b/advisories/unreviewed/2023/04/GHSA-r6j2-4r52-mpg7/GHSA-r6j2-4r52-mpg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6j2-4r52-mpg7", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21968" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:16Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-vr26-5f5w-r829/GHSA-vr26-5f5w-r829.json b/advisories/unreviewed/2023/04/GHSA-vr26-5f5w-r829/GHSA-vr26-5f5w-r829.json index 476d062d775..f322efe3807 100644 --- a/advisories/unreviewed/2023/04/GHSA-vr26-5f5w-r829/GHSA-vr26-5f5w-r829.json +++ b/advisories/unreviewed/2023/04/GHSA-vr26-5f5w-r829/GHSA-vr26-5f5w-r829.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vr26-5f5w-r829", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21937" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:14Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-wg7x-fvjp-r3fx/GHSA-wg7x-fvjp-r3fx.json b/advisories/unreviewed/2023/04/GHSA-wg7x-fvjp-r3fx/GHSA-wg7x-fvjp-r3fx.json index ebdadcf241d..23b40b9d582 100644 --- a/advisories/unreviewed/2023/04/GHSA-wg7x-fvjp-r3fx/GHSA-wg7x-fvjp-r3fx.json +++ b/advisories/unreviewed/2023/04/GHSA-wg7x-fvjp-r3fx/GHSA-wg7x-fvjp-r3fx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wg7x-fvjp-r3fx", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21967" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:16Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-xfrf-5cgw-f964/GHSA-xfrf-5cgw-f964.json b/advisories/unreviewed/2023/04/GHSA-xfrf-5cgw-f964/GHSA-xfrf-5cgw-f964.json index 58c6f568942..6c86399065e 100644 --- a/advisories/unreviewed/2023/04/GHSA-xfrf-5cgw-f964/GHSA-xfrf-5cgw-f964.json +++ b/advisories/unreviewed/2023/04/GHSA-xfrf-5cgw-f964/GHSA-xfrf-5cgw-f964.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfrf-5cgw-f964", - "modified": "2023-04-18T21:30:29Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-04-18T21:30:29Z", "aliases": [ "CVE-2023-21939" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0008/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5430" @@ -46,9 +50,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-04-18T20:15:14Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-8mwf-hvfp-6xfg/GHSA-8mwf-hvfp-6xfg.json b/advisories/unreviewed/2023/06/GHSA-8mwf-hvfp-6xfg/GHSA-8mwf-hvfp-6xfg.json index 266b4e52e33..feae0958769 100644 --- a/advisories/unreviewed/2023/06/GHSA-8mwf-hvfp-6xfg/GHSA-8mwf-hvfp-6xfg.json +++ b/advisories/unreviewed/2023/06/GHSA-8mwf-hvfp-6xfg/GHSA-8mwf-hvfp-6xfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mwf-hvfp-6xfg", - "modified": "2023-06-12T18:30:17Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-06-06T00:30:19Z", "aliases": [ "CVE-2023-3079" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4OXTNIZY4JYHJT7CVLPAJQILI6BISVM/" }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5420" @@ -46,7 +50,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-05T22:15:12Z" diff --git a/advisories/unreviewed/2023/10/GHSA-79jx-q243-6wc7/GHSA-79jx-q243-6wc7.json b/advisories/unreviewed/2023/10/GHSA-79jx-q243-6wc7/GHSA-79jx-q243-6wc7.json index 60740229159..67989f15f14 100644 --- a/advisories/unreviewed/2023/10/GHSA-79jx-q243-6wc7/GHSA-79jx-q243-6wc7.json +++ b/advisories/unreviewed/2023/10/GHSA-79jx-q243-6wc7/GHSA-79jx-q243-6wc7.json @@ -41,6 +41,6 @@ "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T12:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pcqh-qfj4-8h2g/GHSA-pcqh-qfj4-8h2g.json b/advisories/unreviewed/2023/10/GHSA-pcqh-qfj4-8h2g/GHSA-pcqh-qfj4-8h2g.json index 598ce9e4556..e8627c5f26a 100644 --- a/advisories/unreviewed/2023/10/GHSA-pcqh-qfj4-8h2g/GHSA-pcqh-qfj4-8h2g.json +++ b/advisories/unreviewed/2023/10/GHSA-pcqh-qfj4-8h2g/GHSA-pcqh-qfj4-8h2g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcqh-qfj4-8h2g", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-42425" ], "details": "An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-q385-6v59-7vxv/GHSA-q385-6v59-7vxv.json b/advisories/unreviewed/2023/10/GHSA-q385-6v59-7vxv/GHSA-q385-6v59-7vxv.json index 9eb9c0390f3..276e65af963 100644 --- a/advisories/unreviewed/2023/10/GHSA-q385-6v59-7vxv/GHSA-q385-6v59-7vxv.json +++ b/advisories/unreviewed/2023/10/GHSA-q385-6v59-7vxv/GHSA-q385-6v59-7vxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q385-6v59-7vxv", - "modified": "2023-10-31T15:30:22Z", + "modified": "2023-11-09T00:33:54Z", "published": "2023-10-31T15:30:22Z", "aliases": [ "CVE-2016-1203" ], "details": "Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,9 +34,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T13:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2974-5gjv-486c/GHSA-2974-5gjv-486c.json b/advisories/unreviewed/2023/11/GHSA-2974-5gjv-486c/GHSA-2974-5gjv-486c.json new file mode 100644 index 00000000000..fa4c66fff38 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2974-5gjv-486c/GHSA-2974-5gjv-486c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2974-5gjv-486c", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43570" + ], + "details": "\nA potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43570" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2gcw-vfw4-7268/GHSA-2gcw-vfw4-7268.json b/advisories/unreviewed/2023/11/GHSA-2gcw-vfw4-7268/GHSA-2gcw-vfw4-7268.json new file mode 100644 index 00000000000..9771fdcbba9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2gcw-vfw4-7268/GHSA-2gcw-vfw4-7268.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gcw-vfw4-7268", + "modified": "2023-11-09T00:33:55Z", + "published": "2023-11-09T00:33:55Z", + "aliases": [ + "CVE-2023-43567" + ], + "details": "A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43567" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2pxc-8fhw-2cw4/GHSA-2pxc-8fhw-2cw4.json b/advisories/unreviewed/2023/11/GHSA-2pxc-8fhw-2cw4/GHSA-2pxc-8fhw-2cw4.json new file mode 100644 index 00000000000..4408878e554 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2pxc-8fhw-2cw4/GHSA-2pxc-8fhw-2cw4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pxc-8fhw-2cw4", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-5075" + ], + "details": "A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5075" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3cwq-cmm2-67gg/GHSA-3cwq-cmm2-67gg.json b/advisories/unreviewed/2023/11/GHSA-3cwq-cmm2-67gg/GHSA-3cwq-cmm2-67gg.json new file mode 100644 index 00000000000..471c8d241e2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3cwq-cmm2-67gg/GHSA-3cwq-cmm2-67gg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cwq-cmm2-67gg", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43574" + ], + "details": "A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges\n\nto disclose sensitive information.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43574" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3f7x-wmqw-jp3f/GHSA-3f7x-wmqw-jp3f.json b/advisories/unreviewed/2023/11/GHSA-3f7x-wmqw-jp3f/GHSA-3f7x-wmqw-jp3f.json index 631cfad9d8c..da366eea306 100644 --- a/advisories/unreviewed/2023/11/GHSA-3f7x-wmqw-jp3f/GHSA-3f7x-wmqw-jp3f.json +++ b/advisories/unreviewed/2023/11/GHSA-3f7x-wmqw-jp3f/GHSA-3f7x-wmqw-jp3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f7x-wmqw-jp3f", - "modified": "2023-11-06T06:30:26Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-06T06:30:26Z", "aliases": [ "CVE-2023-32838" ], "details": "In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T04:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-4439-7p27-rx63/GHSA-4439-7p27-rx63.json b/advisories/unreviewed/2023/11/GHSA-4439-7p27-rx63/GHSA-4439-7p27-rx63.json new file mode 100644 index 00000000000..639a11d3777 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4439-7p27-rx63/GHSA-4439-7p27-rx63.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4439-7p27-rx63", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-4891" + ], + "details": "\nA potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4891" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-135344" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4c68-prv2-7cp2/GHSA-4c68-prv2-7cp2.json b/advisories/unreviewed/2023/11/GHSA-4c68-prv2-7cp2/GHSA-4c68-prv2-7cp2.json index 7ba06d60439..310d21182b9 100644 --- a/advisories/unreviewed/2023/11/GHSA-4c68-prv2-7cp2/GHSA-4c68-prv2-7cp2.json +++ b/advisories/unreviewed/2023/11/GHSA-4c68-prv2-7cp2/GHSA-4c68-prv2-7cp2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4c68-prv2-7cp2", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42647" ], "details": "In Ifaa service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5gxq-f8fx-9847/GHSA-5gxq-f8fx-9847.json b/advisories/unreviewed/2023/11/GHSA-5gxq-f8fx-9847/GHSA-5gxq-f8fx-9847.json index 3fe7928962b..53c424eb2c6 100644 --- a/advisories/unreviewed/2023/11/GHSA-5gxq-f8fx-9847/GHSA-5gxq-f8fx-9847.json +++ b/advisories/unreviewed/2023/11/GHSA-5gxq-f8fx-9847/GHSA-5gxq-f8fx-9847.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gxq-f8fx-9847", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42653" ], "details": "In faceid service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-66rr-phv8-5jpp/GHSA-66rr-phv8-5jpp.json b/advisories/unreviewed/2023/11/GHSA-66rr-phv8-5jpp/GHSA-66rr-phv8-5jpp.json new file mode 100644 index 00000000000..ae291cb6043 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-66rr-phv8-5jpp/GHSA-66rr-phv8-5jpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66rr-phv8-5jpp", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-43755" + ], + "details": "Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,\n CB6231, B8520, B8220, and CD321 \n\nIP Cameras \n\nwith firmware version M2.1.6.05 are \nvulnerable to multiple instances of stack-based overflows. During the \nprocessing and parsing of certain fields in XML elements from incoming \nnetwork requests, the product does not sufficiently check or validate \nallocated buffer size. This may lead to remote code execution.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43755" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-69g5-4rhf-w2gx/GHSA-69g5-4rhf-w2gx.json b/advisories/unreviewed/2023/11/GHSA-69g5-4rhf-w2gx/GHSA-69g5-4rhf-w2gx.json new file mode 100644 index 00000000000..a708157542b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-69g5-4rhf-w2gx/GHSA-69g5-4rhf-w2gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69g5-4rhf-w2gx", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-5079" + ], + "details": "Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in information disclosure.\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5079" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/418253?" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6mhg-89x7-jmrg/GHSA-6mhg-89x7-jmrg.json b/advisories/unreviewed/2023/11/GHSA-6mhg-89x7-jmrg/GHSA-6mhg-89x7-jmrg.json new file mode 100644 index 00000000000..69f1f70c523 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6mhg-89x7-jmrg/GHSA-6mhg-89x7-jmrg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mhg-89x7-jmrg", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43568" + ], + "details": "A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43568" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-74j8-4v49-qf74/GHSA-74j8-4v49-qf74.json b/advisories/unreviewed/2023/11/GHSA-74j8-4v49-qf74/GHSA-74j8-4v49-qf74.json new file mode 100644 index 00000000000..6d37d8abb4f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-74j8-4v49-qf74/GHSA-74j8-4v49-qf74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74j8-4v49-qf74", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-43581" + ], + "details": "A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43581" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-75fp-j7f7-j7j8/GHSA-75fp-j7f7-j7j8.json b/advisories/unreviewed/2023/11/GHSA-75fp-j7f7-j7j8/GHSA-75fp-j7f7-j7j8.json new file mode 100644 index 00000000000..9fdab5aa45d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-75fp-j7f7-j7j8/GHSA-75fp-j7f7-j7j8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75fp-j7f7-j7j8", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-39435" + ], + "details": "Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,\n CB6231, B8520, B8220, and CD321 IP Cameras \n\nwith firmware version M2.1.6.05 are \nvulnerable to stack-based overflows. During the process of updating \ncertain settings sent from incoming network requests, the product does \nnot sufficiently check or validate allocated buffer size. This may lead \nto remote code execution.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39435" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json b/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json new file mode 100644 index 00000000000..4c8fbe48f71 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-77h7-f57j-cjv2/GHSA-77h7-f57j-cjv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77h7-f57j-cjv2", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-37533" + ], + "details": "HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which contains the malicious script code. This may allow the attacker to steal cookie-based authentication credentials and comprise a user's account then launch other attacks.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37533" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108434" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7gq7-rh5h-8vq2/GHSA-7gq7-rh5h-8vq2.json b/advisories/unreviewed/2023/11/GHSA-7gq7-rh5h-8vq2/GHSA-7gq7-rh5h-8vq2.json index d091ba22d11..6d7435624df 100644 --- a/advisories/unreviewed/2023/11/GHSA-7gq7-rh5h-8vq2/GHSA-7gq7-rh5h-8vq2.json +++ b/advisories/unreviewed/2023/11/GHSA-7gq7-rh5h-8vq2/GHSA-7gq7-rh5h-8vq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7gq7-rh5h-8vq2", - "modified": "2023-11-06T06:30:26Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-06T06:30:26Z", "aliases": [ "CVE-2023-32836" ], "details": "In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08126725; Issue ID: ALPS08126725.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T04:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-7hgj-2cr9-625f/GHSA-7hgj-2cr9-625f.json b/advisories/unreviewed/2023/11/GHSA-7hgj-2cr9-625f/GHSA-7hgj-2cr9-625f.json new file mode 100644 index 00000000000..911db9b05ac --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7hgj-2cr9-625f/GHSA-7hgj-2cr9-625f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hgj-2cr9-625f", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-5078" + ], + "details": "A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5078" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json b/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json new file mode 100644 index 00000000000..726c32ba6a9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7j49-vjx9-cwp7/GHSA-7j49-vjx9-cwp7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j49-vjx9-cwp7", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2021-43609" + ], + "details": "An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43609" + }, + { + "type": "WEB", + "url": "https://community.spiceworks.com/blogs/help-desk-server-release-notes/3610-1-3-2-1-3-3" + }, + { + "type": "WEB", + "url": "https://github.com/d5sec/CVE-2021-43609-POC" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/cve-2021-43609-write-up-division5-security-4lgwe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7j74-mjgh-q8hf/GHSA-7j74-mjgh-q8hf.json b/advisories/unreviewed/2023/11/GHSA-7j74-mjgh-q8hf/GHSA-7j74-mjgh-q8hf.json index c30b458d03e..c699d54a9f8 100644 --- a/advisories/unreviewed/2023/11/GHSA-7j74-mjgh-q8hf/GHSA-7j74-mjgh-q8hf.json +++ b/advisories/unreviewed/2023/11/GHSA-7j74-mjgh-q8hf/GHSA-7j74-mjgh-q8hf.json @@ -37,6 +37,6 @@ "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-853g-q2x9-h9rr/GHSA-853g-q2x9-h9rr.json b/advisories/unreviewed/2023/11/GHSA-853g-q2x9-h9rr/GHSA-853g-q2x9-h9rr.json index b4f0d6f046c..d71218536c7 100644 --- a/advisories/unreviewed/2023/11/GHSA-853g-q2x9-h9rr/GHSA-853g-q2x9-h9rr.json +++ b/advisories/unreviewed/2023/11/GHSA-853g-q2x9-h9rr/GHSA-853g-q2x9-h9rr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-853g-q2x9-h9rr", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42750" ], "details": "In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-89r9-jhrv-559c/GHSA-89r9-jhrv-559c.json b/advisories/unreviewed/2023/11/GHSA-89r9-jhrv-559c/GHSA-89r9-jhrv-559c.json new file mode 100644 index 00000000000..c96927c6155 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-89r9-jhrv-559c/GHSA-89r9-jhrv-559c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89r9-jhrv-559c", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-45078" + ], + "details": "A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45078" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8fj8-2mjg-p38q/GHSA-8fj8-2mjg-p38q.json b/advisories/unreviewed/2023/11/GHSA-8fj8-2mjg-p38q/GHSA-8fj8-2mjg-p38q.json new file mode 100644 index 00000000000..9c63d3eb473 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8fj8-2mjg-p38q/GHSA-8fj8-2mjg-p38q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fj8-2mjg-p38q", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43569" + ], + "details": "A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43569" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8w36-q6qv-jw4f/GHSA-8w36-q6qv-jw4f.json b/advisories/unreviewed/2023/11/GHSA-8w36-q6qv-jw4f/GHSA-8w36-q6qv-jw4f.json new file mode 100644 index 00000000000..080546ce3ad --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8w36-q6qv-jw4f/GHSA-8w36-q6qv-jw4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w36-q6qv-jw4f", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-43580" + ], + "details": "A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43580" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9vrm-5j5h-x98j/GHSA-9vrm-5j5h-x98j.json b/advisories/unreviewed/2023/11/GHSA-9vrm-5j5h-x98j/GHSA-9vrm-5j5h-x98j.json index c8c23b590f2..0eb4f3dd31a 100644 --- a/advisories/unreviewed/2023/11/GHSA-9vrm-5j5h-x98j/GHSA-9vrm-5j5h-x98j.json +++ b/advisories/unreviewed/2023/11/GHSA-9vrm-5j5h-x98j/GHSA-9vrm-5j5h-x98j.json @@ -37,6 +37,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c368-3rx3-26ww/GHSA-c368-3rx3-26ww.json b/advisories/unreviewed/2023/11/GHSA-c368-3rx3-26ww/GHSA-c368-3rx3-26ww.json index 5d1c5632f20..91b557343d2 100644 --- a/advisories/unreviewed/2023/11/GHSA-c368-3rx3-26ww/GHSA-c368-3rx3-26ww.json +++ b/advisories/unreviewed/2023/11/GHSA-c368-3rx3-26ww/GHSA-c368-3rx3-26ww.json @@ -37,6 +37,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json b/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json new file mode 100644 index 00000000000..1a2945943e9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cjpq-3xp9-4722/GHSA-cjpq-3xp9-4722.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjpq-3xp9-4722", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-45075" + ], + "details": "A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45075" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fmxw-c4w5-cjwc/GHSA-fmxw-c4w5-cjwc.json b/advisories/unreviewed/2023/11/GHSA-fmxw-c4w5-cjwc/GHSA-fmxw-c4w5-cjwc.json new file mode 100644 index 00000000000..07c4bc808f0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fmxw-c4w5-cjwc/GHSA-fmxw-c4w5-cjwc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmxw-c4w5-cjwc", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-4706" + ], + "details": "\nA privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4706" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-127385" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g7x3-4v2w-9vxw/GHSA-g7x3-4v2w-9vxw.json b/advisories/unreviewed/2023/11/GHSA-g7x3-4v2w-9vxw/GHSA-g7x3-4v2w-9vxw.json index bdec4c40e0e..532e2b26629 100644 --- a/advisories/unreviewed/2023/11/GHSA-g7x3-4v2w-9vxw/GHSA-g7x3-4v2w-9vxw.json +++ b/advisories/unreviewed/2023/11/GHSA-g7x3-4v2w-9vxw/GHSA-g7x3-4v2w-9vxw.json @@ -37,6 +37,6 @@ "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gq8h-r2cw-gp26/GHSA-gq8h-r2cw-gp26.json b/advisories/unreviewed/2023/11/GHSA-gq8h-r2cw-gp26/GHSA-gq8h-r2cw-gp26.json index 697381f90f6..e05370b5805 100644 --- a/advisories/unreviewed/2023/11/GHSA-gq8h-r2cw-gp26/GHSA-gq8h-r2cw-gp26.json +++ b/advisories/unreviewed/2023/11/GHSA-gq8h-r2cw-gp26/GHSA-gq8h-r2cw-gp26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq8h-r2cw-gp26", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42645" ], "details": "In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gw3g-x57p-x5x3/GHSA-gw3g-x57p-x5x3.json b/advisories/unreviewed/2023/11/GHSA-gw3g-x57p-x5x3/GHSA-gw3g-x57p-x5x3.json new file mode 100644 index 00000000000..8b7e84cfe28 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gw3g-x57p-x5x3/GHSA-gw3g-x57p-x5x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw3g-x57p-x5x3", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43573" + ], + "details": "A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43573" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hf79-fwx9-q3gm/GHSA-hf79-fwx9-q3gm.json b/advisories/unreviewed/2023/11/GHSA-hf79-fwx9-q3gm/GHSA-hf79-fwx9-q3gm.json new file mode 100644 index 00000000000..6d73f574b1e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hf79-fwx9-q3gm/GHSA-hf79-fwx9-q3gm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf79-fwx9-q3gm", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-4249" + ], + "details": "Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,\n CB6231, B8520, B8220, and CD321 \n\nIP Cameras \n\nwith firmware version M2.1.6.05 has a \ncommand injection vulnerability in their implementation of their \nbinaries and handling of network requests.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4249" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hwp3-3266-mxg2/GHSA-hwp3-3266-mxg2.json b/advisories/unreviewed/2023/11/GHSA-hwp3-3266-mxg2/GHSA-hwp3-3266-mxg2.json index e6bb337b86b..601851a3fe4 100644 --- a/advisories/unreviewed/2023/11/GHSA-hwp3-3266-mxg2/GHSA-hwp3-3266-mxg2.json +++ b/advisories/unreviewed/2023/11/GHSA-hwp3-3266-mxg2/GHSA-hwp3-3266-mxg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwp3-3266-mxg2", - "modified": "2023-11-06T06:30:26Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-06T06:30:26Z", "aliases": [ "CVE-2023-32839" ], "details": "In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262576; Issue ID: ALPS07262576.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T04:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-j2q6-cc54-gcmf/GHSA-j2q6-cc54-gcmf.json b/advisories/unreviewed/2023/11/GHSA-j2q6-cc54-gcmf/GHSA-j2q6-cc54-gcmf.json new file mode 100644 index 00000000000..e7fc8325f46 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j2q6-cc54-gcmf/GHSA-j2q6-cc54-gcmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2q6-cc54-gcmf", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-43579" + ], + "details": "A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43579" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json b/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json new file mode 100644 index 00000000000..6943ef1240f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j97j-w85x-cvvq/GHSA-j97j-w85x-cvvq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j97j-w85x-cvvq", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-37790" + ], + "details": "Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37790" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/173508/Clarity-PPM-14.3.0.298-Cross-Site-Scripting.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jgm2-w45w-592c/GHSA-jgm2-w45w-592c.json b/advisories/unreviewed/2023/11/GHSA-jgm2-w45w-592c/GHSA-jgm2-w45w-592c.json new file mode 100644 index 00000000000..a98cad773da --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jgm2-w45w-592c/GHSA-jgm2-w45w-592c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgm2-w45w-592c", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43572" + ], + "details": "A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43572" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json b/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json index c4bb52a4ede..8e51fca47db 100644 --- a/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json +++ b/advisories/unreviewed/2023/11/GHSA-mh77-wx4j-rgjj/GHSA-mh77-wx4j-rgjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh77-wx4j-rgjj", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42655" ], "details": "In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mv8w-vmwf-98gq/GHSA-mv8w-vmwf-98gq.json b/advisories/unreviewed/2023/11/GHSA-mv8w-vmwf-98gq/GHSA-mv8w-vmwf-98gq.json new file mode 100644 index 00000000000..7113868b830 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mv8w-vmwf-98gq/GHSA-mv8w-vmwf-98gq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv8w-vmwf-98gq", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43575" + ], + "details": "A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43575" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mxq5-hwfr-q6p8/GHSA-mxq5-hwfr-q6p8.json b/advisories/unreviewed/2023/11/GHSA-mxq5-hwfr-q6p8/GHSA-mxq5-hwfr-q6p8.json new file mode 100644 index 00000000000..639db192c4f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mxq5-hwfr-q6p8/GHSA-mxq5-hwfr-q6p8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxq5-hwfr-q6p8", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43571" + ], + "details": "A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43571" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q6v3-24wc-vg36/GHSA-q6v3-24wc-vg36.json b/advisories/unreviewed/2023/11/GHSA-q6v3-24wc-vg36/GHSA-q6v3-24wc-vg36.json index ec84db6b4e5..e1890993da9 100644 --- a/advisories/unreviewed/2023/11/GHSA-q6v3-24wc-vg36/GHSA-q6v3-24wc-vg36.json +++ b/advisories/unreviewed/2023/11/GHSA-q6v3-24wc-vg36/GHSA-q6v3-24wc-vg36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q6v3-24wc-vg36", - "modified": "2023-11-01T00:30:48Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T00:30:48Z", "aliases": [ "CVE-2023-37833" ], "details": "Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T23:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qxv7-837m-ggxx/GHSA-qxv7-837m-ggxx.json b/advisories/unreviewed/2023/11/GHSA-qxv7-837m-ggxx/GHSA-qxv7-837m-ggxx.json index b2136055410..411c7b7c78b 100644 --- a/advisories/unreviewed/2023/11/GHSA-qxv7-837m-ggxx/GHSA-qxv7-837m-ggxx.json +++ b/advisories/unreviewed/2023/11/GHSA-qxv7-837m-ggxx/GHSA-qxv7-837m-ggxx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxv7-837m-ggxx", - "modified": "2023-11-01T00:30:49Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T00:30:49Z", "aliases": [ "CVE-2023-46378" ], "details": "Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T23:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r23r-h529-fcxw/GHSA-r23r-h529-fcxw.json b/advisories/unreviewed/2023/11/GHSA-r23r-h529-fcxw/GHSA-r23r-h529-fcxw.json index 8373d2878db..2c0150bf99f 100644 --- a/advisories/unreviewed/2023/11/GHSA-r23r-h529-fcxw/GHSA-r23r-h529-fcxw.json +++ b/advisories/unreviewed/2023/11/GHSA-r23r-h529-fcxw/GHSA-r23r-h529-fcxw.json @@ -37,6 +37,6 @@ "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rhhg-49v7-xmqc/GHSA-rhhg-49v7-xmqc.json b/advisories/unreviewed/2023/11/GHSA-rhhg-49v7-xmqc/GHSA-rhhg-49v7-xmqc.json index fd963e8a3ee..824ec738434 100644 --- a/advisories/unreviewed/2023/11/GHSA-rhhg-49v7-xmqc/GHSA-rhhg-49v7-xmqc.json +++ b/advisories/unreviewed/2023/11/GHSA-rhhg-49v7-xmqc/GHSA-rhhg-49v7-xmqc.json @@ -37,6 +37,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json b/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json new file mode 100644 index 00000000000..51f1e8937c5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rvf5-fhrh-vc2m/GHSA-rvf5-fhrh-vc2m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvf5-fhrh-vc2m", + "modified": "2023-11-09T00:33:55Z", + "published": "2023-11-09T00:33:55Z", + "aliases": [ + "CVE-2023-36667" + ], + "details": "Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36667" + }, + { + "type": "WEB", + "url": "https://docs.couchbase.com/server/current/release-notes/relnotes.html" + }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rwr4-c9v9-crcw/GHSA-rwr4-c9v9-crcw.json b/advisories/unreviewed/2023/11/GHSA-rwr4-c9v9-crcw/GHSA-rwr4-c9v9-crcw.json new file mode 100644 index 00000000000..a5b55f40621 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rwr4-c9v9-crcw/GHSA-rwr4-c9v9-crcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwr4-c9v9-crcw", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43576" + ], + "details": "A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43576" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vq49-7r44-hh7p/GHSA-vq49-7r44-hh7p.json b/advisories/unreviewed/2023/11/GHSA-vq49-7r44-hh7p/GHSA-vq49-7r44-hh7p.json index 179e18c5370..813de11136c 100644 --- a/advisories/unreviewed/2023/11/GHSA-vq49-7r44-hh7p/GHSA-vq49-7r44-hh7p.json +++ b/advisories/unreviewed/2023/11/GHSA-vq49-7r44-hh7p/GHSA-vq49-7r44-hh7p.json @@ -45,6 +45,6 @@ "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-02T00:15:23Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w3vg-2x3w-fq35/GHSA-w3vg-2x3w-fq35.json b/advisories/unreviewed/2023/11/GHSA-w3vg-2x3w-fq35/GHSA-w3vg-2x3w-fq35.json new file mode 100644 index 00000000000..d189640e4b0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w3vg-2x3w-fq35/GHSA-w3vg-2x3w-fq35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3vg-2x3w-fq35", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-45077" + ], + "details": "A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45077" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w5f9-f469-qpc7/GHSA-w5f9-f469-qpc7.json b/advisories/unreviewed/2023/11/GHSA-w5f9-f469-qpc7/GHSA-w5f9-f469-qpc7.json index 58b767130c2..00c1beab04d 100644 --- a/advisories/unreviewed/2023/11/GHSA-w5f9-f469-qpc7/GHSA-w5f9-f469-qpc7.json +++ b/advisories/unreviewed/2023/11/GHSA-w5f9-f469-qpc7/GHSA-w5f9-f469-qpc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5f9-f469-qpc7", - "modified": "2023-11-01T00:30:49Z", + "modified": "2023-11-09T00:33:55Z", "published": "2023-11-01T00:30:49Z", "aliases": [ "CVE-2023-46278" ], "details": "Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated attacker to consume huge storage space or cause significantly delayed communication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T00:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wq49-7ccq-37c5/GHSA-wq49-7ccq-37c5.json b/advisories/unreviewed/2023/11/GHSA-wq49-7ccq-37c5/GHSA-wq49-7ccq-37c5.json new file mode 100644 index 00000000000..c71f8088aa7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wq49-7ccq-37c5/GHSA-wq49-7ccq-37c5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq49-7ccq-37c5", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-43578" + ], + "details": "A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43578" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x4x4-4mj9-h7v7/GHSA-x4x4-4mj9-h7v7.json b/advisories/unreviewed/2023/11/GHSA-x4x4-4mj9-h7v7/GHSA-x4x4-4mj9-h7v7.json new file mode 100644 index 00000000000..71402d0822a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x4x4-4mj9-h7v7/GHSA-x4x4-4mj9-h7v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4x4-4mj9-h7v7", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-45225" + ], + "details": "Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,\n CB6231, B8520, B8220, and CD321 \n\nIP Cameras  with firmware version M2.1.6.05 are \nvulnerable to multiple instances of stack-based overflows. While parsing\n certain XML elements from incoming network requests, the product does \nnot sufficiently check or validate allocated buffer size. This may lead \nto remote code execution.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45225" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xjf7-7f5m-qhq8/GHSA-xjf7-7f5m-qhq8.json b/advisories/unreviewed/2023/11/GHSA-xjf7-7f5m-qhq8/GHSA-xjf7-7f5m-qhq8.json new file mode 100644 index 00000000000..ba4e57a1ce7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xjf7-7f5m-qhq8/GHSA-xjf7-7f5m-qhq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjf7-7f5m-qhq8", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-43577" + ], + "details": "A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43577" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xqfg-p7f2-6w5f/GHSA-xqfg-p7f2-6w5f.json b/advisories/unreviewed/2023/11/GHSA-xqfg-p7f2-6w5f/GHSA-xqfg-p7f2-6w5f.json new file mode 100644 index 00000000000..3a33d8bc3bc --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xqfg-p7f2-6w5f/GHSA-xqfg-p7f2-6w5f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqfg-p7f2-6w5f", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-4632" + ], + "details": "An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4632" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-135367" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xr7w-c4xp-gqc3/GHSA-xr7w-c4xp-gqc3.json b/advisories/unreviewed/2023/11/GHSA-xr7w-c4xp-gqc3/GHSA-xr7w-c4xp-gqc3.json new file mode 100644 index 00000000000..5000258ffb5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xr7w-c4xp-gqc3/GHSA-xr7w-c4xp-gqc3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr7w-c4xp-gqc3", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-45079" + ], + "details": "A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45079" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xw58-crph-crhm/GHSA-xw58-crph-crhm.json b/advisories/unreviewed/2023/11/GHSA-xw58-crph-crhm/GHSA-xw58-crph-crhm.json new file mode 100644 index 00000000000..3a2ec42104b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xw58-crph-crhm/GHSA-xw58-crph-crhm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw58-crph-crhm", + "modified": "2023-11-09T00:33:56Z", + "published": "2023-11-09T00:33:56Z", + "aliases": [ + "CVE-2023-3959" + ], + "details": "Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,\n CB6231, B8520, B8220, and CD321 \n\nIP Cameras\n\nwith firmware version M2.1.6.05 are \nvulnerable to multiple instances of stack-based overflows. While \nprocessing XML elements from incoming network requests, the product does\n not sufficiently check or validate allocated buffer size. This may lead\n to remote code execution.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3959" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xwr9-j862-6mj9/GHSA-xwr9-j862-6mj9.json b/advisories/unreviewed/2023/11/GHSA-xwr9-j862-6mj9/GHSA-xwr9-j862-6mj9.json new file mode 100644 index 00000000000..4a1f7880b0c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xwr9-j862-6mj9/GHSA-xwr9-j862-6mj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwr9-j862-6mj9", + "modified": "2023-11-09T00:33:57Z", + "published": "2023-11-09T00:33:57Z", + "aliases": [ + "CVE-2023-45076" + ], + "details": "A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45076" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-141775" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T23:15:11Z" + } +} \ No newline at end of file