diff --git a/advisories/unreviewed/2022/05/GHSA-q92f-7cwj-w4w5/GHSA-q92f-7cwj-w4w5.json b/advisories/unreviewed/2022/05/GHSA-q92f-7cwj-w4w5/GHSA-q92f-7cwj-w4w5.json index 7616ad08368..b7b522ea516 100644 --- a/advisories/unreviewed/2022/05/GHSA-q92f-7cwj-w4w5/GHSA-q92f-7cwj-w4w5.json +++ b/advisories/unreviewed/2022/05/GHSA-q92f-7cwj-w4w5/GHSA-q92f-7cwj-w4w5.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/02/msg00017.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html" + }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202101-38" diff --git a/advisories/unreviewed/2022/08/GHSA-297v-qp46-84h5/GHSA-297v-qp46-84h5.json b/advisories/unreviewed/2022/08/GHSA-297v-qp46-84h5/GHSA-297v-qp46-84h5.json index 61f73972e9a..0e2abd255c8 100644 --- a/advisories/unreviewed/2022/08/GHSA-297v-qp46-84h5/GHSA-297v-qp46-84h5.json +++ b/advisories/unreviewed/2022/08/GHSA-297v-qp46-84h5/GHSA-297v-qp46-84h5.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30698" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5L3ZFWZZFPBIL654BG75RWXUMPFQJ5EC/" diff --git a/advisories/unreviewed/2022/08/GHSA-fjfh-84xh-5hv3/GHSA-fjfh-84xh-5hv3.json b/advisories/unreviewed/2022/08/GHSA-fjfh-84xh-5hv3/GHSA-fjfh-84xh-5hv3.json index eb67944317e..b452285feef 100644 --- a/advisories/unreviewed/2022/08/GHSA-fjfh-84xh-5hv3/GHSA-fjfh-84xh-5hv3.json +++ b/advisories/unreviewed/2022/08/GHSA-fjfh-84xh-5hv3/GHSA-fjfh-84xh-5hv3.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30699" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5L3ZFWZZFPBIL654BG75RWXUMPFQJ5EC/" diff --git a/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json b/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json index 6e418ae5e25..dea2b438196 100644 --- a/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json +++ b/advisories/unreviewed/2022/09/GHSA-7mc5-x7xh-682h/GHSA-7mc5-x7xh-682h.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3204" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/35QGS5FBQTG3DBSK7QV67PA64P24ABHY/" diff --git a/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json b/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json index 95a4f71404d..58f8648a072 100644 --- a/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json +++ b/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28pv-xxcq-fr89", - "modified": "2023-03-24T21:30:48Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T21:30:48Z", "aliases": [ "CVE-2021-3674" ], "details": "A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-3h88-j436-w3r5/GHSA-3h88-j436-w3r5.json b/advisories/unreviewed/2023/03/GHSA-3h88-j436-w3r5/GHSA-3h88-j436-w3r5.json index 64ed9c26d4c..d39af5090d7 100644 --- a/advisories/unreviewed/2023/03/GHSA-3h88-j436-w3r5/GHSA-3h88-j436-w3r5.json +++ b/advisories/unreviewed/2023/03/GHSA-3h88-j436-w3r5/GHSA-3h88-j436-w3r5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h88-j436-w3r5", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20996" ], "details": "In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246749764", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-48j5-grh5-3f4f/GHSA-48j5-grh5-3f4f.json b/advisories/unreviewed/2023/03/GHSA-48j5-grh5-3f4f/GHSA-48j5-grh5-3f4f.json new file mode 100644 index 00000000000..b809b1ee9f5 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-48j5-grh5-3f4f/GHSA-48j5-grh5-3f4f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48j5-grh5-3f4f", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2023-1663" + ], + "details": "Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1663" + }, + { + "type": "WEB", + "url": "https://community.synopsys.com/s/article/Mitigation-for-Coverity-Platforms-Exposure-to-CVE-2023-1663" + }, + { + "type": "WEB", + "url": "https://community.synopsys.com/s/article/SIG-Product-Security-Advisory-CVE-2023-1663-Affecting-Coverity-Platform" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4jhx-8mmm-hp3c/GHSA-4jhx-8mmm-hp3c.json b/advisories/unreviewed/2023/03/GHSA-4jhx-8mmm-hp3c/GHSA-4jhx-8mmm-hp3c.json new file mode 100644 index 00000000000..8f32737f5e1 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4jhx-8mmm-hp3c/GHSA-4jhx-8mmm-hp3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jhx-8mmm-hp3c", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2022-48433" + ], + "details": "In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48433" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-599f-hxxf-hgx8/GHSA-599f-hxxf-hgx8.json b/advisories/unreviewed/2023/03/GHSA-599f-hxxf-hgx8/GHSA-599f-hxxf-hgx8.json index 12f1fb6d354..689d0687ec2 100644 --- a/advisories/unreviewed/2023/03/GHSA-599f-hxxf-hgx8/GHSA-599f-hxxf-hgx8.json +++ b/advisories/unreviewed/2023/03/GHSA-599f-hxxf-hgx8/GHSA-599f-hxxf-hgx8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-599f-hxxf-hgx8", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:16Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-21002" ], "details": "In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261193935", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json b/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json index c6964c2ce6c..e400ec74eb7 100644 --- a/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json +++ b/advisories/unreviewed/2023/03/GHSA-5c5q-xj8p-hrg3/GHSA-5c5q-xj8p-hrg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5c5q-xj8p-hrg3", - "modified": "2023-03-24T18:30:21Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T18:30:21Z", "aliases": [ "CVE-2023-28152" ], "details": "An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-611" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T16:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-5j77-g9mw-c64c/GHSA-5j77-g9mw-c64c.json b/advisories/unreviewed/2023/03/GHSA-5j77-g9mw-c64c/GHSA-5j77-g9mw-c64c.json index cdeaa33c4cf..1740f9b6210 100644 --- a/advisories/unreviewed/2023/03/GHSA-5j77-g9mw-c64c/GHSA-5j77-g9mw-c64c.json +++ b/advisories/unreviewed/2023/03/GHSA-5j77-g9mw-c64c/GHSA-5j77-g9mw-c64c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5j77-g9mw-c64c", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:16Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-21000" ], "details": "In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194783918", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-65qf-g3jj-7644/GHSA-65qf-g3jj-7644.json b/advisories/unreviewed/2023/03/GHSA-65qf-g3jj-7644/GHSA-65qf-g3jj-7644.json index 4a15a96eb6f..82efcf1b2fd 100644 --- a/advisories/unreviewed/2023/03/GHSA-65qf-g3jj-7644/GHSA-65qf-g3jj-7644.json +++ b/advisories/unreviewed/2023/03/GHSA-65qf-g3jj-7644/GHSA-65qf-g3jj-7644.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65qf-g3jj-7644", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20991" ], "details": "In btm_ble_process_periodic_adv_sync_lost_evt of ble_scanner_hci_interface.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-255305114", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-65vc-vq9x-469r/GHSA-65vc-vq9x-469r.json b/advisories/unreviewed/2023/03/GHSA-65vc-vq9x-469r/GHSA-65vc-vq9x-469r.json new file mode 100644 index 00000000000..ba1600f7a41 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-65vc-vq9x-469r/GHSA-65vc-vq9x-469r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65vc-vq9x-469r", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2022-48430" + ], + "details": "In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48430" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-742m-jhx7-4749/GHSA-742m-jhx7-4749.json b/advisories/unreviewed/2023/03/GHSA-742m-jhx7-4749/GHSA-742m-jhx7-4749.json index 084ce84b621..a17777a656a 100644 --- a/advisories/unreviewed/2023/03/GHSA-742m-jhx7-4749/GHSA-742m-jhx7-4749.json +++ b/advisories/unreviewed/2023/03/GHSA-742m-jhx7-4749/GHSA-742m-jhx7-4749.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-742m-jhx7-4749", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21058" ], "details": "In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-246169606References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-7vmw-w575-cvm8/GHSA-7vmw-w575-cvm8.json b/advisories/unreviewed/2023/03/GHSA-7vmw-w575-cvm8/GHSA-7vmw-w575-cvm8.json index 2d27d26d9c9..594d18e5f24 100644 --- a/advisories/unreviewed/2023/03/GHSA-7vmw-w575-cvm8/GHSA-7vmw-w575-cvm8.json +++ b/advisories/unreviewed/2023/03/GHSA-7vmw-w575-cvm8/GHSA-7vmw-w575-cvm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vmw-w575-cvm8", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2023-20926" ], "details": "In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-253043058", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-8499-278q-xrph/GHSA-8499-278q-xrph.json b/advisories/unreviewed/2023/03/GHSA-8499-278q-xrph/GHSA-8499-278q-xrph.json index 7529d446199..03099d9723b 100644 --- a/advisories/unreviewed/2023/03/GHSA-8499-278q-xrph/GHSA-8499-278q-xrph.json +++ b/advisories/unreviewed/2023/03/GHSA-8499-278q-xrph/GHSA-8499-278q-xrph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8499-278q-xrph", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2023-20910" ], "details": "In addNetworkSuggestions of WifiManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-245299920", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-8j8f-cx8f-89mc/GHSA-8j8f-cx8f-89mc.json b/advisories/unreviewed/2023/03/GHSA-8j8f-cx8f-89mc/GHSA-8j8f-cx8f-89mc.json new file mode 100644 index 00000000000..a7304d6ba09 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-8j8f-cx8f-89mc/GHSA-8j8f-cx8f-89mc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j8f-cx8f-89mc", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2022-47433" + ], + "details": "Unauth. Reflected Cross-Site Scripting vulnerability in Daniel Powney Multi Rating plugin <= 5.0.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multi-rating/wordpress-multi-rating-plugin-5-0-5-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-99fr-5jwf-5mf5/GHSA-99fr-5jwf-5mf5.json b/advisories/unreviewed/2023/03/GHSA-99fr-5jwf-5mf5/GHSA-99fr-5jwf-5mf5.json index 14daa356b14..ff34b42eee2 100644 --- a/advisories/unreviewed/2023/03/GHSA-99fr-5jwf-5mf5/GHSA-99fr-5jwf-5mf5.json +++ b/advisories/unreviewed/2023/03/GHSA-99fr-5jwf-5mf5/GHSA-99fr-5jwf-5mf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99fr-5jwf-5mf5", - "modified": "2023-03-24T15:30:20Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T15:30:20Z", "aliases": [ "CVE-2023-24625" ], "details": "Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T15:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-9j9q-9x39-w892/GHSA-9j9q-9x39-w892.json b/advisories/unreviewed/2023/03/GHSA-9j9q-9x39-w892/GHSA-9j9q-9x39-w892.json index 7044022be8b..2acab260422 100644 --- a/advisories/unreviewed/2023/03/GHSA-9j9q-9x39-w892/GHSA-9j9q-9x39-w892.json +++ b/advisories/unreviewed/2023/03/GHSA-9j9q-9x39-w892/GHSA-9j9q-9x39-w892.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9j9q-9x39-w892", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-22812" ], "details": "SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json b/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json index 7a4054466fb..8626728993f 100644 --- a/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json +++ b/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4q4-j9gc-fpq4", - "modified": "2023-03-24T21:30:52Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T21:30:52Z", "aliases": [ "CVE-2023-21036" ], "details": "In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-cgm5-p2xv-fjc2/GHSA-cgm5-p2xv-fjc2.json b/advisories/unreviewed/2023/03/GHSA-cgm5-p2xv-fjc2/GHSA-cgm5-p2xv-fjc2.json index 6ad5093926f..914dd661c65 100644 --- a/advisories/unreviewed/2023/03/GHSA-cgm5-p2xv-fjc2/GHSA-cgm5-p2xv-fjc2.json +++ b/advisories/unreviewed/2023/03/GHSA-cgm5-p2xv-fjc2/GHSA-cgm5-p2xv-fjc2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cgm5-p2xv-fjc2", - "modified": "2023-03-22T06:30:22Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-22T06:30:22Z", "aliases": [ "CVE-2022-37940" ], "details": "Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61 or later.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T06:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json b/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json index 9ebbd95bdbc..f685ca6e7af 100644 --- a/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json +++ b/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cw6j-2v5x-f5m2", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-21061" ], "details": "Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json b/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json index fba92eef23f..fa6c06c9056 100644 --- a/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json +++ b/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxcv-gvhj-5xxg", - "modified": "2023-03-24T21:30:53Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:53Z", "aliases": [ "CVE-2023-21067" ], "details": "Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f4j7-9jj6-pqqx/GHSA-f4j7-9jj6-pqqx.json b/advisories/unreviewed/2023/03/GHSA-f4j7-9jj6-pqqx/GHSA-f4j7-9jj6-pqqx.json index de87c61aefa..4f174e0a4cc 100644 --- a/advisories/unreviewed/2023/03/GHSA-f4j7-9jj6-pqqx/GHSA-f4j7-9jj6-pqqx.json +++ b/advisories/unreviewed/2023/03/GHSA-f4j7-9jj6-pqqx/GHSA-f4j7-9jj6-pqqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f4j7-9jj6-pqqx", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20993" ], "details": "In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261588851", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://source.android.com/security/bulletin/pixel/2023-03-01" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/cve/CVE-2023-20993" } ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-f62q-42c7-p38c/GHSA-f62q-42c7-p38c.json b/advisories/unreviewed/2023/03/GHSA-f62q-42c7-p38c/GHSA-f62q-42c7-p38c.json new file mode 100644 index 00000000000..5a34bf20a1e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f62q-42c7-p38c/GHSA-f62q-42c7-p38c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f62q-42c7-p38c", + "modified": "2023-03-29T15:30:16Z", + "published": "2023-03-29T15:30:16Z", + "aliases": [ + "CVE-2023-26982" + ], + "details": "Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26982" + }, + { + "type": "WEB", + "url": "https://github.com/bypazs/CVE-2023-26982" + }, + { + "type": "WEB", + "url": "https://github.com/polonel/trudesk/releases/tag/v1.2.6" + }, + { + "type": "WEB", + "url": "https://trudesk.io/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g7m6-859q-xfqp/GHSA-g7m6-859q-xfqp.json b/advisories/unreviewed/2023/03/GHSA-g7m6-859q-xfqp/GHSA-g7m6-859q-xfqp.json new file mode 100644 index 00000000000..16023510b6a --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-g7m6-859q-xfqp/GHSA-g7m6-859q-xfqp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7m6-859q-xfqp", + "modified": "2023-03-29T15:30:16Z", + "published": "2023-03-29T15:30:16Z", + "aliases": [ + "CVE-2023-1680" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1680" + }, + { + "type": "WEB", + "url": "https://github.com/2714925725/CMS-bug/blob/main/Informationdisclosure-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224237" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224237" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-g8w9-22g6-mj88/GHSA-g8w9-22g6-mj88.json b/advisories/unreviewed/2023/03/GHSA-g8w9-22g6-mj88/GHSA-g8w9-22g6-mj88.json index 85a1db67854..56607a0188f 100644 --- a/advisories/unreviewed/2023/03/GHSA-g8w9-22g6-mj88/GHSA-g8w9-22g6-mj88.json +++ b/advisories/unreviewed/2023/03/GHSA-g8w9-22g6-mj88/GHSA-g8w9-22g6-mj88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8w9-22g6-mj88", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20994" ], "details": "In _ufdt_output_property_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259062118", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-gq78-wj8w-8f75/GHSA-gq78-wj8w-8f75.json b/advisories/unreviewed/2023/03/GHSA-gq78-wj8w-8f75/GHSA-gq78-wj8w-8f75.json index 4f51be5b414..3b11e99f6f7 100644 --- a/advisories/unreviewed/2023/03/GHSA-gq78-wj8w-8f75/GHSA-gq78-wj8w-8f75.json +++ b/advisories/unreviewed/2023/03/GHSA-gq78-wj8w-8f75/GHSA-gq78-wj8w-8f75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq78-wj8w-8f75", - "modified": "2023-03-23T21:30:20Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-23T21:30:20Z", "aliases": [ "CVE-2023-1610" ], "details": "A vulnerability, which was classified as critical, has been found in Rebuild up to 3.2.3. Affected by this issue is some unknown functionality of the file /project/tasks/list. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223742 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-hq22-5ff9-mv6w/GHSA-hq22-5ff9-mv6w.json b/advisories/unreviewed/2023/03/GHSA-hq22-5ff9-mv6w/GHSA-hq22-5ff9-mv6w.json new file mode 100644 index 00000000000..d86f3a5932f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-hq22-5ff9-mv6w/GHSA-hq22-5ff9-mv6w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq22-5ff9-mv6w", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2022-48432" + ], + "details": "In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48432" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-j9vg-wh3v-f932/GHSA-j9vg-wh3v-f932.json b/advisories/unreviewed/2023/03/GHSA-j9vg-wh3v-f932/GHSA-j9vg-wh3v-f932.json new file mode 100644 index 00000000000..22d6728e399 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j9vg-wh3v-f932/GHSA-j9vg-wh3v-f932.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9vg-wh3v-f932", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2023-23861" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin <= 1.5.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23861" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gmace/wordpress-gmace-plugin-1-5-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-m5p2-59ff-782g/GHSA-m5p2-59ff-782g.json b/advisories/unreviewed/2023/03/GHSA-m5p2-59ff-782g/GHSA-m5p2-59ff-782g.json index e186af4a9df..752f1e99c17 100644 --- a/advisories/unreviewed/2023/03/GHSA-m5p2-59ff-782g/GHSA-m5p2-59ff-782g.json +++ b/advisories/unreviewed/2023/03/GHSA-m5p2-59ff-782g/GHSA-m5p2-59ff-782g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5p2-59ff-782g", - "modified": "2023-03-24T18:30:21Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T18:30:21Z", "aliases": [ "CVE-2020-36691" ], "details": "An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a denial of service (unbounded recursion) via a nested Netlink policy with a back reference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-674" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T17:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-mwjj-vghx-7m99/GHSA-mwjj-vghx-7m99.json b/advisories/unreviewed/2023/03/GHSA-mwjj-vghx-7m99/GHSA-mwjj-vghx-7m99.json index a63eb0738d0..5d4da426513 100644 --- a/advisories/unreviewed/2023/03/GHSA-mwjj-vghx-7m99/GHSA-mwjj-vghx-7m99.json +++ b/advisories/unreviewed/2023/03/GHSA-mwjj-vghx-7m99/GHSA-mwjj-vghx-7m99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwjj-vghx-7m99", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20931" ], "details": "In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242535997", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-pr5c-7q57-fp6g/GHSA-pr5c-7q57-fp6g.json b/advisories/unreviewed/2023/03/GHSA-pr5c-7q57-fp6g/GHSA-pr5c-7q57-fp6g.json index 7f67f07ad53..6d34e25ca46 100644 --- a/advisories/unreviewed/2023/03/GHSA-pr5c-7q57-fp6g/GHSA-pr5c-7q57-fp6g.json +++ b/advisories/unreviewed/2023/03/GHSA-pr5c-7q57-fp6g/GHSA-pr5c-7q57-fp6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pr5c-7q57-fp6g", - "modified": "2023-03-22T03:30:15Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-22T03:30:15Z", "aliases": [ "CVE-2023-27857" ], "details": "In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T02:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-pv2h-vpmg-pjp2/GHSA-pv2h-vpmg-pjp2.json b/advisories/unreviewed/2023/03/GHSA-pv2h-vpmg-pjp2/GHSA-pv2h-vpmg-pjp2.json new file mode 100644 index 00000000000..d9e6838ba22 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-pv2h-vpmg-pjp2/GHSA-pv2h-vpmg-pjp2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv2h-vpmg-pjp2", + "modified": "2023-03-29T15:30:18Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2022-47438" + ], + "details": "Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pv8j-m68f-f56q/GHSA-pv8j-m68f-f56q.json b/advisories/unreviewed/2023/03/GHSA-pv8j-m68f-f56q/GHSA-pv8j-m68f-f56q.json index bbfaa72faca..d4eaf3b1324 100644 --- a/advisories/unreviewed/2023/03/GHSA-pv8j-m68f-f56q/GHSA-pv8j-m68f-f56q.json +++ b/advisories/unreviewed/2023/03/GHSA-pv8j-m68f-f56q/GHSA-pv8j-m68f-f56q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pv8j-m68f-f56q", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:16Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-21001" ], "details": "In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-237672190", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-qf34-f43r-gv9p/GHSA-qf34-f43r-gv9p.json b/advisories/unreviewed/2023/03/GHSA-qf34-f43r-gv9p/GHSA-qf34-f43r-gv9p.json new file mode 100644 index 00000000000..3ef6f728830 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-qf34-f43r-gv9p/GHSA-qf34-f43r-gv9p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf34-f43r-gv9p", + "modified": "2023-03-29T15:30:17Z", + "published": "2023-03-29T15:30:17Z", + "aliases": [ + "CVE-2023-28158" + ], + "details": "Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28158" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/8pm6d5y9cptznm0bdny3n8voovmm0dtt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json b/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json index 92b6d87d91b..f216c0c771b 100644 --- a/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json +++ b/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwv6-2vxv-h2vg", - "modified": "2023-03-22T06:30:22Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-22T06:30:21Z", "aliases": [ "CVE-2023-1168" ], "details": "An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-22T06:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-r64v-g53c-27h7/GHSA-r64v-g53c-27h7.json b/advisories/unreviewed/2023/03/GHSA-r64v-g53c-27h7/GHSA-r64v-g53c-27h7.json index 6bbf324d5cc..034fd98b5dc 100644 --- a/advisories/unreviewed/2023/03/GHSA-r64v-g53c-27h7/GHSA-r64v-g53c-27h7.json +++ b/advisories/unreviewed/2023/03/GHSA-r64v-g53c-27h7/GHSA-r64v-g53c-27h7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r64v-g53c-27h7", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:18Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20992" ], "details": "In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260568750", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json b/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json index ea13432e559..25ab2fe1550 100644 --- a/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json +++ b/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wccw-c3q8-hgg2", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20995" ], "details": "In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241910279", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-wv9f-rwrw-wqj3/GHSA-wv9f-rwrw-wqj3.json b/advisories/unreviewed/2023/03/GHSA-wv9f-rwrw-wqj3/GHSA-wv9f-rwrw-wqj3.json index 2b34888199e..642dc7e8ee8 100644 --- a/advisories/unreviewed/2023/03/GHSA-wv9f-rwrw-wqj3/GHSA-wv9f-rwrw-wqj3.json +++ b/advisories/unreviewed/2023/03/GHSA-wv9f-rwrw-wqj3/GHSA-wv9f-rwrw-wqj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv9f-rwrw-wqj3", - "modified": "2023-03-24T21:30:51Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:51Z", "aliases": [ "CVE-2023-20998" ], "details": "In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246749936", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-wvg5-mm8h-8gwp/GHSA-wvg5-mm8h-8gwp.json b/advisories/unreviewed/2023/03/GHSA-wvg5-mm8h-8gwp/GHSA-wvg5-mm8h-8gwp.json index 23ee72ae18d..86c7e62905b 100644 --- a/advisories/unreviewed/2023/03/GHSA-wvg5-mm8h-8gwp/GHSA-wvg5-mm8h-8gwp.json +++ b/advisories/unreviewed/2023/03/GHSA-wvg5-mm8h-8gwp/GHSA-wvg5-mm8h-8gwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvg5-mm8h-8gwp", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20954" ], "details": "In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261867748", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-xfgj-mmw9-2x4f/GHSA-xfgj-mmw9-2x4f.json b/advisories/unreviewed/2023/03/GHSA-xfgj-mmw9-2x4f/GHSA-xfgj-mmw9-2x4f.json index e512f668601..5c7d4485160 100644 --- a/advisories/unreviewed/2023/03/GHSA-xfgj-mmw9-2x4f/GHSA-xfgj-mmw9-2x4f.json +++ b/advisories/unreviewed/2023/03/GHSA-xfgj-mmw9-2x4f/GHSA-xfgj-mmw9-2x4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfgj-mmw9-2x4f", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-29T15:30:17Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2023-20911" ], "details": "In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242537498", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-xj4g-47qc-vhww/GHSA-xj4g-47qc-vhww.json b/advisories/unreviewed/2023/03/GHSA-xj4g-47qc-vhww/GHSA-xj4g-47qc-vhww.json new file mode 100644 index 00000000000..c346fd2919d --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xj4g-47qc-vhww/GHSA-xj4g-47qc-vhww.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj4g-47qc-vhww", + "modified": "2023-03-29T15:30:16Z", + "published": "2023-03-29T15:30:16Z", + "aliases": [ + "CVE-2023-1575" + ], + "details": "The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1575" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/mega-main-menu-wordpress-menu-plugin/6135125" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a44ce6a3-0a9d-4bce-9251-f3a38b000645?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-xx2r-f4xg-6rg7/GHSA-xx2r-f4xg-6rg7.json b/advisories/unreviewed/2023/03/GHSA-xx2r-f4xg-6rg7/GHSA-xx2r-f4xg-6rg7.json new file mode 100644 index 00000000000..366637c3f1e --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-xx2r-f4xg-6rg7/GHSA-xx2r-f4xg-6rg7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx2r-f4xg-6rg7", + "modified": "2023-03-29T15:30:16Z", + "published": "2023-03-29T15:30:16Z", + "aliases": [ + "CVE-2023-28892" + ], + "details": "Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\\AdwCleaner\\Logs\\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28892" + }, + { + "type": "WEB", + "url": "https://malwarebytes.com" + }, + { + "type": "WEB", + "url": "https://www.malwarebytes.com/secure/cves/cve-2023-28892" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T15:15:00Z" + } +} \ No newline at end of file