diff --git a/advisories/unreviewed/2023/12/GHSA-9h8c-4wj7-59cr/GHSA-9h8c-4wj7-59cr.json b/advisories/unreviewed/2023/12/GHSA-9h8c-4wj7-59cr/GHSA-9h8c-4wj7-59cr.json index ed9e205f11d..0ddb3127230 100644 --- a/advisories/unreviewed/2023/12/GHSA-9h8c-4wj7-59cr/GHSA-9h8c-4wj7-59cr.json +++ b/advisories/unreviewed/2023/12/GHSA-9h8c-4wj7-59cr/GHSA-9h8c-4wj7-59cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9h8c-4wj7-59cr", - "modified": "2023-12-31T03:30:30Z", + "modified": "2024-01-11T18:31:22Z", "published": "2023-12-31T03:30:30Z", "aliases": [ "CVE-2023-52275" ], "details": "Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-31T03:15:46Z" diff --git a/advisories/unreviewed/2024/01/GHSA-237g-fwhr-q8q2/GHSA-237g-fwhr-q8q2.json b/advisories/unreviewed/2024/01/GHSA-237g-fwhr-q8q2/GHSA-237g-fwhr-q8q2.json new file mode 100644 index 00000000000..6798baa7c9c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-237g-fwhr-q8q2/GHSA-237g-fwhr-q8q2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-237g-fwhr-q8q2", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0413" + ], + "details": "A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file public/install.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250433 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0413" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/MarH4fY66BgO" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250433" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250433" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2623-7ghf-34hg/GHSA-2623-7ghf-34hg.json b/advisories/unreviewed/2024/01/GHSA-2623-7ghf-34hg/GHSA-2623-7ghf-34hg.json new file mode 100644 index 00000000000..14cff57359f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2623-7ghf-34hg/GHSA-2623-7ghf-34hg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2623-7ghf-34hg", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0414" + ], + "details": "A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0414" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/xYQMsARg83ui" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250434" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250434" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-353q-7h99-hf4x/GHSA-353q-7h99-hf4x.json b/advisories/unreviewed/2024/01/GHSA-353q-7h99-hf4x/GHSA-353q-7h99-hf4x.json index 31ea364e6ed..bb036b04df5 100644 --- a/advisories/unreviewed/2024/01/GHSA-353q-7h99-hf4x/GHSA-353q-7h99-hf4x.json +++ b/advisories/unreviewed/2024/01/GHSA-353q-7h99-hf4x/GHSA-353q-7h99-hf4x.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7210" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-353q-7h99-hf4x" + }, { "type": "WEB", "url": "https://note.zhaoj.in/share/eRbUygGMiJcp" diff --git a/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json b/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json index 2c0f74a0b27..83d50da1407 100644 --- a/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json +++ b/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qxp-p56x-r4h3", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34322" ], "details": "For migration as well as to work around kernels unaware of L1TF (see\nXSA-273), PV guests may be run in shadow paging mode. Since Xen itself\nneeds to be mapped when PV guests run, Xen and shadowed PV guests run\ndirectly the respective shadow page tables. For 64-bit PV guests this\nmeans running on the shadow of the guest root page table.\n\nIn the course of dealing with shortage of memory in the shadow pool\nassociated with a domain, shadows of page tables may be torn down. This\ntearing down may include the shadow root page table that the CPU in\nquestion is presently running on. While a precaution exists to\nsupposedly prevent the tearing down of the underlying live page table,\nthe time window covered by that precaution isn't large enough.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-273" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json b/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json index dd92e1afdb4..59fe3e308ec 100644 --- a/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json +++ b/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fr6-x37h-wjwr", - "modified": "2024-01-03T21:30:31Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-03T21:30:31Z", "aliases": [ "CVE-2023-5880" ], "details": "When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser. \n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-03T20:15:21Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4mw2-cf3r-fx8j/GHSA-4mw2-cf3r-fx8j.json b/advisories/unreviewed/2024/01/GHSA-4mw2-cf3r-fx8j/GHSA-4mw2-cf3r-fx8j.json new file mode 100644 index 00000000000..3996fa63d12 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4mw2-cf3r-fx8j/GHSA-4mw2-cf3r-fx8j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mw2-cf3r-fx8j", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2023-51989" + ], + "details": "D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51989" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/dir822+/2/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json b/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json index 30126289155..50a0515ff71 100644 --- a/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json +++ b/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rmw-8gh7-w6g3", - "modified": "2024-01-05T18:30:26Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:26Z", "aliases": [ "CVE-2023-46836" ], "details": "The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative\nReturn Stack Overflow) are not IRQ-safe. It was believed that the\nmitigations always operated in contexts with IRQs disabled.\n\nHowever, the original XSA-254 fix for Meltdown (XPTI) deliberately left\ninterrupts enabled on two entry paths; one unconditionally, and one\nconditionally on whether XPTI was active.\n\nAs BTC/SRSO and Meltdown affect different CPU vendors, the mitigations\nare not active together by default. Therefore, there is a race\ncondition whereby a malicious PV guest can bypass BTC/SRSO protections\nand launch a BTC/SRSO attack against Xen.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-55g6-j6ff-jqjg/GHSA-55g6-j6ff-jqjg.json b/advisories/unreviewed/2024/01/GHSA-55g6-j6ff-jqjg/GHSA-55g6-j6ff-jqjg.json new file mode 100644 index 00000000000..aebed1d1a1b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-55g6-j6ff-jqjg/GHSA-55g6-j6ff-jqjg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55g6-j6ff-jqjg", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-23057" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23057" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/5/TOTOlink%20A3300R%20setNtpCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json b/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json index 581e84ff955..915fde3326e 100644 --- a/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json +++ b/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56gq-fgx7-r88g", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-50020" ], "details": "An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T22:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-58qc-w2x7-4rp7/GHSA-58qc-w2x7-4rp7.json b/advisories/unreviewed/2024/01/GHSA-58qc-w2x7-4rp7/GHSA-58qc-w2x7-4rp7.json new file mode 100644 index 00000000000..e16f45f3d85 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-58qc-w2x7-4rp7/GHSA-58qc-w2x7-4rp7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58qc-w2x7-4rp7", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0411" + ], + "details": "A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250431.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0411" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/9G6K6RBjS4M4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250431" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250431" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5fxf-m765-2wf6/GHSA-5fxf-m765-2wf6.json b/advisories/unreviewed/2024/01/GHSA-5fxf-m765-2wf6/GHSA-5fxf-m765-2wf6.json new file mode 100644 index 00000000000..ade874e7b46 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5fxf-m765-2wf6/GHSA-5fxf-m765-2wf6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fxf-m765-2wf6", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-23060" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23060" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/4/TOTOLINK%20A3300R%20setDmzCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json b/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json index 2fbcb1408c0..cd94b2a9060 100644 --- a/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json +++ b/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fx2-c8rv-2w4f", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34327" ], "details": "\n[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nAMD CPUs since ~2014 have extensions to normal x86 debugging functionality.\nXen supports guests using these extensions.\n\nUnfortunately there are errors in Xen's handling of the guest state, leading\nto denials of service.\n\n 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of\n a previous vCPUs debug mask state.\n\n 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.\n This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock\n up the CPU entirely.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-826f-v6w3-63vg/GHSA-826f-v6w3-63vg.json b/advisories/unreviewed/2024/01/GHSA-826f-v6w3-63vg/GHSA-826f-v6w3-63vg.json index cb44329d32f..1957802c707 100644 --- a/advisories/unreviewed/2024/01/GHSA-826f-v6w3-63vg/GHSA-826f-v6w3-63vg.json +++ b/advisories/unreviewed/2024/01/GHSA-826f-v6w3-63vg/GHSA-826f-v6w3-63vg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-427" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json b/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json index 38b7394f57b..ee9af218dcf 100644 --- a/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json +++ b/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-85fq-cwc3-mp4q", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34323" ], "details": "When a transaction is committed, C Xenstored will first check\nthe quota is correct before attempting to commit any nodes. It would\nbe possible that accounting is temporarily negative if a node has\nbeen removed outside of the transaction.\n\nUnfortunately, some versions of C Xenstored are assuming that the\nquota cannot be negative and are using assert() to confirm it. This\nwill lead to C Xenstored crash when tools are built without -DNDEBUG\n(this is the default).\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json b/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json index e813f26dbd4..efeb5945159 100644 --- a/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json +++ b/advisories/unreviewed/2024/01/GHSA-895h-3m6x-8h8x/GHSA-895h-3m6x-8h8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-895h-3m6x-8h8x", - "modified": "2024-01-05T06:30:19Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-05T06:30:19Z", "aliases": [ "CVE-2024-22086" ], "details": "handle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T04:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8c3q-7745-hrhp/GHSA-8c3q-7745-hrhp.json b/advisories/unreviewed/2024/01/GHSA-8c3q-7745-hrhp/GHSA-8c3q-7745-hrhp.json index 84251d4d0f6..f6c19807cde 100644 --- a/advisories/unreviewed/2024/01/GHSA-8c3q-7745-hrhp/GHSA-8c3q-7745-hrhp.json +++ b/advisories/unreviewed/2024/01/GHSA-8c3q-7745-hrhp/GHSA-8c3q-7745-hrhp.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-99g9-3q96-95pw/GHSA-99g9-3q96-95pw.json b/advisories/unreviewed/2024/01/GHSA-99g9-3q96-95pw/GHSA-99g9-3q96-95pw.json new file mode 100644 index 00000000000..8af5bde1b09 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-99g9-3q96-95pw/GHSA-99g9-3q96-95pw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99g9-3q96-95pw", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2024-22942" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22942" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/1/TOTOlink%20A3300R%20setWanCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9hx6-3xpp-hq3q/GHSA-9hx6-3xpp-hq3q.json b/advisories/unreviewed/2024/01/GHSA-9hx6-3xpp-hq3q/GHSA-9hx6-3xpp-hq3q.json new file mode 100644 index 00000000000..06d1674dd89 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9hx6-3xpp-hq3q/GHSA-9hx6-3xpp-hq3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hx6-3xpp-hq3q", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-23058" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23058" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/6/TOTOlink%20A3300R%20setTr069Cfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json b/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json index b750accecca..e73684cb998 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json +++ b/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m9h-jcjj-xjvx", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2023-50019" ], "details": "An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T22:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json b/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json index 0dc8b0c8df5..66d471f683b 100644 --- a/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json +++ b/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2mm-wq7p-rpm8", - "modified": "2024-01-05T18:30:26Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:26Z", "aliases": [ "CVE-2023-46835" ], "details": "The current setup of the quarantine page tables assumes that the\nquarantine domain (dom_io) has been initialized with an address width\nof DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and hence 4 page table levels.\n\nHowever dom_io being a PV domain gets the AMD-Vi IOMMU page tables\nlevels based on the maximum (hot pluggable) RAM address, and hence on\nsystems with no RAM above the 512GB mark only 3 page-table levels are\nconfigured in the IOMMU.\n\nOn systems without RAM above the 512GB boundary\namd_iommu_quarantine_init() will setup page tables for the scratch\npage with 4 levels, while the IOMMU will be configured to use 3 levels\nonly, resulting in the last page table directory (PDE) effectively\nbecoming a page table entry (PTE), and hence a device in quarantine\nmode gaining write access to the page destined to be a PDE.\n\nDue to this page table level mismatch, the sink page the device gets\nread/write access to is no longer cleared between device assignment,\npossibly leading to data leaks.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cmrr-pfc2-p86v/GHSA-cmrr-pfc2-p86v.json b/advisories/unreviewed/2024/01/GHSA-cmrr-pfc2-p86v/GHSA-cmrr-pfc2-p86v.json new file mode 100644 index 00000000000..9e8e07e5a1f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cmrr-pfc2-p86v/GHSA-cmrr-pfc2-p86v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmrr-pfc2-p86v", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0412" + ], + "details": "A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250432.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0412" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/Q56cf5nN9RzF" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250432" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cpjv-h35c-937x/GHSA-cpjv-h35c-937x.json b/advisories/unreviewed/2024/01/GHSA-cpjv-h35c-937x/GHSA-cpjv-h35c-937x.json index c435e304493..705f142f185 100644 --- a/advisories/unreviewed/2024/01/GHSA-cpjv-h35c-937x/GHSA-cpjv-h35c-937x.json +++ b/advisories/unreviewed/2024/01/GHSA-cpjv-h35c-937x/GHSA-cpjv-h35c-937x.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-cvj3-f4x8-hw28/GHSA-cvj3-f4x8-hw28.json b/advisories/unreviewed/2024/01/GHSA-cvj3-f4x8-hw28/GHSA-cvj3-f4x8-hw28.json new file mode 100644 index 00000000000..ffed86356f3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cvj3-f4x8-hw28/GHSA-cvj3-f4x8-hw28.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvj3-f4x8-hw28", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0416" + ], + "details": "A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument file_name leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250436.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0416" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/DxR7FZsCKJQ1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250436" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250436" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cvvm-x945-2wwp/GHSA-cvvm-x945-2wwp.json b/advisories/unreviewed/2024/01/GHSA-cvvm-x945-2wwp/GHSA-cvvm-x945-2wwp.json index d99aec2aa5a..7c75a91a0a6 100644 --- a/advisories/unreviewed/2024/01/GHSA-cvvm-x945-2wwp/GHSA-cvvm-x945-2wwp.json +++ b/advisories/unreviewed/2024/01/GHSA-cvvm-x945-2wwp/GHSA-cvvm-x945-2wwp.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-fjpx-rx54-q5vf/GHSA-fjpx-rx54-q5vf.json b/advisories/unreviewed/2024/01/GHSA-fjpx-rx54-q5vf/GHSA-fjpx-rx54-q5vf.json new file mode 100644 index 00000000000..fd2d99ee948 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fjpx-rx54-q5vf/GHSA-fjpx-rx54-q5vf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjpx-rx54-q5vf", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-23061" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23061" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/3/TOTOLINK%20A3300R%20setScheduleCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json b/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json index a39458664ae..599fb473b57 100644 --- a/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json +++ b/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fm4g-p248-j5wj", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34328" ], "details": "\n[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nAMD CPUs since ~2014 have extensions to normal x86 debugging functionality.\nXen supports guests using these extensions.\n\nUnfortunately there are errors in Xen's handling of the guest state, leading\nto denials of service.\n\n 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of\n a previous vCPUs debug mask state.\n\n 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.\n This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock\n up the CPU entirely.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gpcp-gx8h-767w/GHSA-gpcp-gx8h-767w.json b/advisories/unreviewed/2024/01/GHSA-gpcp-gx8h-767w/GHSA-gpcp-gx8h-767w.json index ab76da7fcf1..8ff21657a4f 100644 --- a/advisories/unreviewed/2024/01/GHSA-gpcp-gx8h-767w/GHSA-gpcp-gx8h-767w.json +++ b/advisories/unreviewed/2024/01/GHSA-gpcp-gx8h-767w/GHSA-gpcp-gx8h-767w.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-gwgh-999f-h6wf/GHSA-gwgh-999f-h6wf.json b/advisories/unreviewed/2024/01/GHSA-gwgh-999f-h6wf/GHSA-gwgh-999f-h6wf.json new file mode 100644 index 00000000000..66e4db4cda8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gwgh-999f-h6wf/GHSA-gwgh-999f-h6wf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwgh-999f-h6wf", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2023-6554" + ], + "details": "When access to the \"admin\" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6554" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-6554/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-6554/" + }, + { + "type": "WEB", + "url": "https://tcexam.org/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json b/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json index 8a53ae9b54f..8703cb71702 100644 --- a/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json +++ b/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwmw-qvr5-88j2", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34325" ], "details": "\n[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nlibfsimage contains parsing code for several filesystems, most of them based on\ngrub-legacy code. libfsimage is used by pygrub to inspect guest disks.\n\nPygrub runs as the same user as the toolstack (root in a priviledged domain).\n\nAt least one issue has been reported to the Xen Security Team that allows an\nattacker to trigger a stack buffer overflow in libfsimage. After further\nanalisys the Xen Security Team is no longer confident in the suitability of\nlibfsimage when run against guest controlled input with super user priviledges.\n\nIn order to not affect current deployments that rely on pygrub patches are\nprovided in the resolution section of the advisory that allow running pygrub in\ndeprivileged mode.\n\nCVE-2023-4949 refers to the original issue in the upstream grub\nproject (\"An attacker with local access to a system (either through a\ndisk or external drive) can present a modified XFS partition to\ngrub-legacy in such a way to exploit a memory corruption in grub’s XFS\nfile system implementation.\") CVE-2023-34325 refers specifically to\nthe vulnerabilities in Xen's copy of libfsimage, which is decended\nfrom a very old version of grub.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json b/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json index 6a3c495c203..b9028d6cb83 100644 --- a/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json +++ b/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gwr5-jm6x-gfh6", - "modified": "2024-01-08T09:30:34Z", + "modified": "2024-01-11T18:31:24Z", "published": "2024-01-08T09:30:34Z", "aliases": [ "CVE-2024-22216" ], "details": "In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-08T07:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json b/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json index 495a84bf150..cd7f3a32ab9 100644 --- a/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json +++ b/advisories/unreviewed/2024/01/GHSA-h25w-qh4w-j2hf/GHSA-h25w-qh4w-j2hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h25w-qh4w-j2hf", - "modified": "2024-01-08T15:30:27Z", + "modified": "2024-01-11T18:31:24Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-7224" ], "details": "OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-94", "CWE-95" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-08T14:15:47Z" diff --git a/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json b/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json index 8349d1e4413..1e8e37441c8 100644 --- a/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json +++ b/advisories/unreviewed/2024/01/GHSA-h93h-6948-g84m/GHSA-h93h-6948-g84m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h93h-6948-g84m", - "modified": "2024-01-05T06:30:19Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-05T06:30:19Z", "aliases": [ "CVE-2023-51277" ], "details": "nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T05:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-hqv4-427w-6698/GHSA-hqv4-427w-6698.json b/advisories/unreviewed/2024/01/GHSA-hqv4-427w-6698/GHSA-hqv4-427w-6698.json new file mode 100644 index 00000000000..b42ca53a111 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hqv4-427w-6698/GHSA-hqv4-427w-6698.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqv4-427w-6698", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2023-5118" + ], + "details": "The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author and text are not adequately sanitized and validated. This allows for the injection of malicious JavaScript code. The vulnerability was identified in the function for adding new annotations while editing document content.\n\nReporters inform that the vulnerability has been removed in software versions above 11.1.x. Previous versions may also be vulnerable, but this has not been confirmed.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5118" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/01/CVE-2023-5118/" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/01/CVE-2023-5118/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jwhp-365f-27vv/GHSA-jwhp-365f-27vv.json b/advisories/unreviewed/2024/01/GHSA-jwhp-365f-27vv/GHSA-jwhp-365f-27vv.json new file mode 100644 index 00000000000..826173bd89f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jwhp-365f-27vv/GHSA-jwhp-365f-27vv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwhp-365f-27vv", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2023-51987" + ], + "details": "D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51987" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/tree/main/dir822%2B/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json b/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json index 014acd2b92d..fdc3befcae6 100644 --- a/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json +++ b/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3fq-v9fh-gg5p", - "modified": "2024-01-05T12:30:25Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-05T12:30:25Z", "aliases": [ "CVE-2022-46839" diff --git a/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json b/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json index ca7479c159e..39fa5d34529 100644 --- a/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json +++ b/advisories/unreviewed/2024/01/GHSA-m892-r7q3-ww6c/GHSA-m892-r7q3-ww6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m892-r7q3-ww6c", - "modified": "2024-01-05T06:30:19Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-05T06:30:19Z", "aliases": [ "CVE-2024-22087" ], "details": "route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T04:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json b/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json index ab6eec2faeb..f6d7103f77e 100644 --- a/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json +++ b/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjvw-frxx-6hm5", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34326" ], "details": "The caching invalidation guidelines from the AMD-Vi specification (48882—Rev\n3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction\n(see stale DMA mappings) if some fields of the DTE are updated but the IOMMU\nTLB is not flushed.\n\nSuch stale DMA mappings can point to memory ranges not owned by the guest, thus\nallowing access to unindented memory regions.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-p5m5-hv26-hw94/GHSA-p5m5-hv26-hw94.json b/advisories/unreviewed/2024/01/GHSA-p5m5-hv26-hw94/GHSA-p5m5-hv26-hw94.json index 17a6b680673..2eccf3a7232 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5m5-hv26-hw94/GHSA-p5m5-hv26-hw94.json +++ b/advisories/unreviewed/2024/01/GHSA-p5m5-hv26-hw94/GHSA-p5m5-hv26-hw94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5m5-hv26-hw94", - "modified": "2024-01-06T06:30:29Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-06T06:30:29Z", "aliases": [ "CVE-2023-46953" ], "details": "SQL Injection vulnerability in ABO.CMS v.5.9.3, allows remote attackers to execute arbitrary code via the d parameter in the Documents module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-06T05:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json b/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json index d80caf9be68..9088e366aa0 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json +++ b/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5q9-hxvv-3rqq", - "modified": "2024-01-05T18:30:25Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:25Z", "aliases": [ "CVE-2023-34321" ], "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-pq9w-q369-w2gf/GHSA-pq9w-q369-w2gf.json b/advisories/unreviewed/2024/01/GHSA-pq9w-q369-w2gf/GHSA-pq9w-q369-w2gf.json new file mode 100644 index 00000000000..335db090698 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pq9w-q369-w2gf/GHSA-pq9w-q369-w2gf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq9w-q369-w2gf", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-23059" + ], + "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23059" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/2/TOTOlink%20A3300R%20setDdnsCfg.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-prqf-cjvf-5788/GHSA-prqf-cjvf-5788.json b/advisories/unreviewed/2024/01/GHSA-prqf-cjvf-5788/GHSA-prqf-cjvf-5788.json new file mode 100644 index 00000000000..11966b6c96f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-prqf-cjvf-5788/GHSA-prqf-cjvf-5788.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prqf-cjvf-5788", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2023-51984" + ], + "details": "D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51984" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/dir822+/1/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pxj4-c79w-7wm3/GHSA-pxj4-c79w-7wm3.json b/advisories/unreviewed/2024/01/GHSA-pxj4-c79w-7wm3/GHSA-pxj4-c79w-7wm3.json new file mode 100644 index 00000000000..47f178521ed --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pxj4-c79w-7wm3/GHSA-pxj4-c79w-7wm3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxj4-c79w-7wm3", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0415" + ], + "details": "A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250435.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0415" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/63LhFitJmKGR" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250435" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250435" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q393-gpq2-prjv/GHSA-q393-gpq2-prjv.json b/advisories/unreviewed/2024/01/GHSA-q393-gpq2-prjv/GHSA-q393-gpq2-prjv.json new file mode 100644 index 00000000000..1fe48cabfa8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q393-gpq2-prjv/GHSA-q393-gpq2-prjv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q393-gpq2-prjv", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0417" + ], + "details": "A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5. This affects an unknown part of the file application/home/controller/MemberAuth.php. The manipulation of the argument member_info leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250437 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0417" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/ZpRTCLblKd7N" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250437" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250437" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json b/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json index 6864e08d055..55944aafb6b 100644 --- a/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json +++ b/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-qjxc-jh7f-mmc9/GHSA-qjxc-jh7f-mmc9.json b/advisories/unreviewed/2024/01/GHSA-qjxc-jh7f-mmc9/GHSA-qjxc-jh7f-mmc9.json new file mode 100644 index 00000000000..165f4bbec76 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qjxc-jh7f-mmc9/GHSA-qjxc-jh7f-mmc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjxc-jh7f-mmc9", + "modified": "2024-01-11T18:31:27Z", + "published": "2024-01-11T18:31:27Z", + "aliases": [ + "CVE-2024-0429" + ], + "details": "A denial service vulnerability has been found on  Hex Workshop affecting version 6.7, an attacker could send a command line file arguments and control the Structured Exception Handler (SEH) records resulting in a service shutdown.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0429" + }, + { + "type": "WEB", + "url": "https://https://www.incibe.es/en/incibe-cert/notices/aviso/buffer-overflow-vulnerability-hex-workshop" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json b/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json index 35e3c02e87a..ceedb8ea0a6 100644 --- a/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json +++ b/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r45q-p466-5ghh", - "modified": "2024-01-05T12:30:25Z", + "modified": "2024-01-11T18:31:22Z", "published": "2024-01-05T12:30:25Z", "aliases": [ "CVE-2023-52121" diff --git a/advisories/unreviewed/2024/01/GHSA-rcqr-8jwm-jxfp/GHSA-rcqr-8jwm-jxfp.json b/advisories/unreviewed/2024/01/GHSA-rcqr-8jwm-jxfp/GHSA-rcqr-8jwm-jxfp.json new file mode 100644 index 00000000000..c8d19c8ff8f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rcqr-8jwm-jxfp/GHSA-rcqr-8jwm-jxfp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcqr-8jwm-jxfp", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2024-0418" + ], + "details": "A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of the component GET Request Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250438 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0418" + }, + { + "type": "WEB", + "url": "https://cxsecurity.com/issue/WLB-2024010023" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.250438" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.250438" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=WK7xK9KHiMU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rw58-qmcf-p57g/GHSA-rw58-qmcf-p57g.json b/advisories/unreviewed/2024/01/GHSA-rw58-qmcf-p57g/GHSA-rw58-qmcf-p57g.json new file mode 100644 index 00000000000..79f5e74e999 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rw58-qmcf-p57g/GHSA-rw58-qmcf-p57g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw58-qmcf-p57g", + "modified": "2024-01-11T18:31:29Z", + "published": "2024-01-11T18:31:29Z", + "aliases": [ + "CVE-2023-50671" + ], + "details": "In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50671" + }, + { + "type": "WEB", + "url": "https://blog.yulun.ac.cn/posts/2023/fuzzing-exiftags/" + }, + { + "type": "WEB", + "url": "https://johnst.org/sw/exiftags/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json b/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json index 5b3a1eb852d..7c6f130cff4 100644 --- a/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json +++ b/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v75r-qqcp-59c7", - "modified": "2024-01-05T18:30:26Z", + "modified": "2024-01-11T18:31:23Z", "published": "2024-01-05T18:30:26Z", "aliases": [ "CVE-2023-46837" ], "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n\nThis undefined behavior was meant to be addressed by XSA-437, but the\napproach was not sufficient.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-05T17:15:11Z" diff --git a/advisories/unreviewed/2024/01/GHSA-vqmp-r4j7-xh29/GHSA-vqmp-r4j7-xh29.json b/advisories/unreviewed/2024/01/GHSA-vqmp-r4j7-xh29/GHSA-vqmp-r4j7-xh29.json index ef911e37802..ebac80eef32 100644 --- a/advisories/unreviewed/2024/01/GHSA-vqmp-r4j7-xh29/GHSA-vqmp-r4j7-xh29.json +++ b/advisories/unreviewed/2024/01/GHSA-vqmp-r4j7-xh29/GHSA-vqmp-r4j7-xh29.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://https://www.ibm.com/support/pages/node/7105094" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7105094" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-vxfg-523g-29hw/GHSA-vxfg-523g-29hw.json b/advisories/unreviewed/2024/01/GHSA-vxfg-523g-29hw/GHSA-vxfg-523g-29hw.json index 0466c8c2836..7847be51fe4 100644 --- a/advisories/unreviewed/2024/01/GHSA-vxfg-523g-29hw/GHSA-vxfg-523g-29hw.json +++ b/advisories/unreviewed/2024/01/GHSA-vxfg-523g-29hw/GHSA-vxfg-523g-29hw.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-291" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json b/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json index 06abd29a5e0..6f1ed50b28f 100644 --- a/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json +++ b/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-532" ], "severity": "HIGH", "github_reviewed": false,