From bfd544fd3ec8debe8a2a1ea2aad9098406a6b384 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 4 Nov 2024 12:34:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-xgqc-3vhw-cphp.json | 6 ++- .../GHSA-28pg-93m7-9jmx.json | 10 ++++- .../GHSA-5cmh-766g-p8jx.json | 14 ++++++- .../GHSA-v8h5-cghp-q3c4.json | 10 ++++- .../GHSA-2w43-52vj-94gx.json | 38 +++++++++++++++++++ .../GHSA-34x9-x6hh-cvvw.json | 9 +++-- .../GHSA-3925-h58h-pr2m.json | 38 +++++++++++++++++++ .../GHSA-3qgc-vrvv-mv2r.json | 38 +++++++++++++++++++ .../GHSA-3r6h-pxfq-6cr9.json | 38 +++++++++++++++++++ .../GHSA-49j5-25jj-6293.json | 38 +++++++++++++++++++ .../GHSA-4g7x-pvhw-3mph.json | 9 +++-- .../GHSA-4qm8-phhf-q2q2.json | 38 +++++++++++++++++++ .../GHSA-4r9r-m8vg-chxf.json | 9 +++-- .../GHSA-5jgq-h327-whqc.json | 38 +++++++++++++++++++ .../GHSA-6cwr-j8fg-5c5x.json | 38 +++++++++++++++++++ .../GHSA-72ch-892x-fp25.json | 38 +++++++++++++++++++ .../GHSA-752q-72qc-rc66.json | 35 +++++++++++++++++ .../GHSA-79m4-m83j-wqr4.json | 9 +++-- .../GHSA-7h5w-r4x3-245g.json | 38 +++++++++++++++++++ .../GHSA-98cj-759m-rr93.json | 38 +++++++++++++++++++ .../GHSA-9c8g-4qx4-v74x.json | 9 +++-- .../GHSA-9w8c-9425-p69g.json | 9 +++-- .../GHSA-cc49-h52c-hm2r.json | 9 +++-- .../GHSA-f3jh-3x43-rfcx.json | 9 +++-- .../GHSA-fm3h-xpw5-j8xh.json | 38 +++++++++++++++++++ .../GHSA-fr3q-8g9r-hvpv.json | 38 +++++++++++++++++++ .../GHSA-g7rx-xjjw-j9xq.json | 38 +++++++++++++++++++ .../GHSA-gwr8-j573-qw62.json | 38 +++++++++++++++++++ .../GHSA-hhm7-rcc5-4hjc.json | 38 +++++++++++++++++++ .../GHSA-hmcg-rc8j-cqqx.json | 38 +++++++++++++++++++ .../GHSA-jg3v-6rvm-6p3v.json | 38 +++++++++++++++++++ .../GHSA-m62c-rp67-pw2c.json | 9 +++-- .../GHSA-mgx7-9xcp-cmj3.json | 9 +++-- .../GHSA-mppp-8v9v-595f.json | 38 +++++++++++++++++++ .../GHSA-ph42-jmfw-fmpf.json | 9 +++-- .../GHSA-q3rp-vvm7-j8jg.json | 38 +++++++++++++++++++ .../GHSA-q97v-2cp6-jv6p.json | 38 +++++++++++++++++++ .../GHSA-qjg4-p6j3-36x6.json | 38 +++++++++++++++++++ .../GHSA-rhh2-f22c-xh7f.json | 38 +++++++++++++++++++ .../GHSA-v45x-45vv-7hm9.json | 9 +++-- .../GHSA-vg89-xvr7-m96m.json | 9 +++-- .../GHSA-vqfr-ww83-fm63.json | 38 +++++++++++++++++++ .../GHSA-w36j-hqcc-jvpp.json | 38 +++++++++++++++++++ .../GHSA-w9p5-xqxf-xvx7.json | 9 +++-- .../GHSA-wjq7-92jr-r24h.json | 9 +++-- .../GHSA-wqm7-xh9j-c3ff.json | 38 +++++++++++++++++++ .../GHSA-x6g6-7cr3-c8p4.json | 9 +++-- .../GHSA-xch5-v6mf-cvxj.json | 38 +++++++++++++++++++ .../GHSA-xp7h-ghc6-47w2.json | 38 +++++++++++++++++++ 49 files changed, 1231 insertions(+), 52 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3qgc-vrvv-mv2r/GHSA-3qgc-vrvv-mv2r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6cwr-j8fg-5c5x/GHSA-6cwr-j8fg-5c5x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json create mode 100644 advisories/unreviewed/2024/11/GHSA-752q-72qc-rc66/GHSA-752q-72qc-rc66.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fm3h-xpw5-j8xh/GHSA-fm3h-xpw5-j8xh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mppp-8v9v-595f/GHSA-mppp-8v9v-595f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q3rp-vvm7-j8jg/GHSA-q3rp-vvm7-j8jg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qjg4-p6j3-36x6/GHSA-qjg4-p6j3-36x6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rhh2-f22c-xh7f/GHSA-rhh2-f22c-xh7f.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vqfr-ww83-fm63/GHSA-vqfr-ww83-fm63.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wqm7-xh9j-c3ff/GHSA-wqm7-xh9j-c3ff.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json diff --git a/advisories/unreviewed/2024/06/GHSA-xgqc-3vhw-cphp/GHSA-xgqc-3vhw-cphp.json b/advisories/unreviewed/2024/06/GHSA-xgqc-3vhw-cphp/GHSA-xgqc-3vhw-cphp.json index 5bd3b455dd3..60fbf592798 100644 --- a/advisories/unreviewed/2024/06/GHSA-xgqc-3vhw-cphp/GHSA-xgqc-3vhw-cphp.json +++ b/advisories/unreviewed/2024/06/GHSA-xgqc-3vhw-cphp/GHSA-xgqc-3vhw-cphp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xgqc-3vhw-cphp", - "modified": "2024-06-06T21:30:37Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-06-06T21:30:37Z", "aliases": [ "CVE-2024-5124" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5124" }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/e46ec4ecd896bc3c88eb9a2f44e8593f3c6761b4" + }, { "type": "WEB", "url": "https://huntr.com/bounties/e85ec077-930a-4597-975f-9341d2805641" diff --git a/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json b/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json index 971b9563ded..94c29e0e3ff 100644 --- a/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json +++ b/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28pg-93m7-9jmx", - "modified": "2024-10-29T18:30:35Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-10-28T03:30:39Z", "aliases": [ "CVE-2024-50067" @@ -24,6 +24,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/373b9338c9722a368925d83bc622c596896b328e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/537ad4a431f6dddbf15d40d19f24bb9ee12b55cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e5f93788c9dd4309e75a56860a1ac44a8e117b9" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-5cmh-766g-p8jx/GHSA-5cmh-766g-p8jx.json b/advisories/unreviewed/2024/10/GHSA-5cmh-766g-p8jx/GHSA-5cmh-766g-p8jx.json index a67f374c395..139c5b431cc 100644 --- a/advisories/unreviewed/2024/10/GHSA-5cmh-766g-p8jx/GHSA-5cmh-766g-p8jx.json +++ b/advisories/unreviewed/2024/10/GHSA-5cmh-766g-p8jx/GHSA-5cmh-766g-p8jx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cmh-766g-p8jx", - "modified": "2024-10-21T21:30:49Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-10-21T21:30:49Z", "aliases": [ "CVE-2024-50010" @@ -18,10 +18,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50010" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bdf77be2330062b3a64f2bec39f62ab874a6796" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d16f53c91111cec914f0811fcc526a2ba77b20d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/0d196e7589cefe207d5d41f37a0a28a1fdeeb7c6" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b723f96407a0a078cf75970e4dbf16b46d286a61" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/d62ba2a5536df83473a2ac15ab302258e3845251" diff --git a/advisories/unreviewed/2024/10/GHSA-v8h5-cghp-q3c4/GHSA-v8h5-cghp-q3c4.json b/advisories/unreviewed/2024/10/GHSA-v8h5-cghp-q3c4/GHSA-v8h5-cghp-q3c4.json index ff3d5ab03eb..66f298128e0 100644 --- a/advisories/unreviewed/2024/10/GHSA-v8h5-cghp-q3c4/GHSA-v8h5-cghp-q3c4.json +++ b/advisories/unreviewed/2024/10/GHSA-v8h5-cghp-q3c4/GHSA-v8h5-cghp-q3c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8h5-cghp-q3c4", - "modified": "2024-10-24T06:30:29Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50058" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50058" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/399927f0f875b93f3d5a0336d382ba48b8671eb2" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/602babaa84d627923713acaf5f7e9a4369e77473" @@ -29,6 +33,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/76ed24a34223bb2c6b6162e1d8389ec4e602a290" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7b5876a6e74cdf8468a478be6b23f2f5464ac7a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/e418d91195d29d5f9c9685ff309b92b04b41dc40" diff --git a/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json b/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json new file mode 100644 index 00000000000..13f9c984954 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2w43-52vj-94gx/GHSA-2w43-52vj-94gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w43-52vj-94gx", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38410" + ], + "details": "Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38410" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json b/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json index 8ee52efca1e..3482c486990 100644 --- a/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json +++ b/advisories/unreviewed/2024/11/GHSA-34x9-x6hh-cvvw/GHSA-34x9-x6hh-cvvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34x9-x6hh-cvvw", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:56Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20120" ], "details": "In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1575.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json b/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json new file mode 100644 index 00000000000..7c2c556e9d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3925-h58h-pr2m/GHSA-3925-h58h-pr2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3925-h58h-pr2m", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-33029" + ], + "details": "Memory corruption while handling the PDR in driver for getting the remote heap maps.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33029" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3qgc-vrvv-mv2r/GHSA-3qgc-vrvv-mv2r.json b/advisories/unreviewed/2024/11/GHSA-3qgc-vrvv-mv2r/GHSA-3qgc-vrvv-mv2r.json new file mode 100644 index 00000000000..8aafab97b7a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3qgc-vrvv-mv2r/GHSA-3qgc-vrvv-mv2r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qgc-vrvv-mv2r", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38422" + ], + "details": "Memory corruption while processing voice packet with arbitrary data received from ADSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38422" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-680" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json b/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json new file mode 100644 index 00000000000..edb5deb56ad --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3r6h-pxfq-6cr9/GHSA-3r6h-pxfq-6cr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r6h-pxfq-6cr9", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38424" + ], + "details": "Memory corruption during GNSS HAL process initialization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38424" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json b/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json new file mode 100644 index 00000000000..f49e5f329b4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-49j5-25jj-6293/GHSA-49j5-25jj-6293.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49j5-25jj-6293", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38403" + ], + "details": "Transient DOS while parsing BTM ML IE when per STA profile is not included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38403" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json b/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json index b7f9a8665a5..425c36c703a 100644 --- a/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json +++ b/advisories/unreviewed/2024/11/GHSA-4g7x-pvhw-3mph/GHSA-4g7x-pvhw-3mph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g7x-pvhw-3mph", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20112" ], "details": "In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json b/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json new file mode 100644 index 00000000000..153d73fb903 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4qm8-phhf-q2q2/GHSA-4qm8-phhf-q2q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qm8-phhf-q2q2", + "modified": "2024-11-04T12:32:57Z", + "published": "2024-11-04T12:32:57Z", + "aliases": [ + "CVE-2024-48878" + ], + "details": "Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48878" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json b/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json index 91464a8c318..b21d1d8e478 100644 --- a/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json +++ b/advisories/unreviewed/2024/11/GHSA-4r9r-m8vg-chxf/GHSA-4r9r-m8vg-chxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4r9r-m8vg-chxf", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20117" ], "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1681.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json b/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json new file mode 100644 index 00000000000..70be772c884 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5jgq-h327-whqc/GHSA-5jgq-h327-whqc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jgq-h327-whqc", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38415" + ], + "details": "Memory corruption while handling session errors from firmware.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38415" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6cwr-j8fg-5c5x/GHSA-6cwr-j8fg-5c5x.json b/advisories/unreviewed/2024/11/GHSA-6cwr-j8fg-5c5x/GHSA-6cwr-j8fg-5c5x.json new file mode 100644 index 00000000000..f76b37fc107 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6cwr-j8fg-5c5x/GHSA-6cwr-j8fg-5c5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cwr-j8fg-5c5x", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-23377" + ], + "details": "Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23377" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json b/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json new file mode 100644 index 00000000000..aed9c4307d5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-72ch-892x-fp25/GHSA-72ch-892x-fp25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72ch-892x-fp25", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38406" + ], + "details": "Memory corruption while handling IOCTL calls in JPEG Encoder driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38406" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-752q-72qc-rc66/GHSA-752q-72qc-rc66.json b/advisories/unreviewed/2024/11/GHSA-752q-72qc-rc66/GHSA-752q-72qc-rc66.json new file mode 100644 index 00000000000..88059a187a0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-752q-72qc-rc66/GHSA-752q-72qc-rc66.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-752q-72qc-rc66", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-23590" + ], + "details": "Session Fixation vulnerability in Apache Kylin.\n\nThis issue affects Apache Kylin: from 2.0.0 through 4.x.\n\nUsers are recommended to upgrade to version 5.0.0 or above, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23590" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/7161154h0k6zygr9917qq0g95p39szml" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json b/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json index bcf79b84233..855fd54bfca 100644 --- a/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json +++ b/advisories/unreviewed/2024/11/GHSA-79m4-m83j-wqr4/GHSA-79m4-m83j-wqr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79m4-m83j-wqr4", - "modified": "2024-11-04T03:30:39Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:39Z", "aliases": [ "CVE-2024-20104" ], "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:15Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json b/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json new file mode 100644 index 00000000000..1571a5a9c2f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7h5w-r4x3-245g/GHSA-7h5w-r4x3-245g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h5w-r4x3-245g", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-33068" + ], + "details": "Transient DOS while parsing fragments of MBSSID IE from beacon frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33068" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json b/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json new file mode 100644 index 00000000000..afa3e799bff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-98cj-759m-rr93/GHSA-98cj-759m-rr93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98cj-759m-rr93", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38407" + ], + "details": "Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38407" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json b/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json index b8026e96795..34be243d8ca 100644 --- a/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json +++ b/advisories/unreviewed/2024/11/GHSA-9c8g-4qx4-v74x/GHSA-9c8g-4qx4-v74x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9c8g-4qx4-v74x", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20109" ], "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065928; Issue ID: MSV-1763.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json b/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json index 4fa669862be..35ae8127db3 100644 --- a/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json +++ b/advisories/unreviewed/2024/11/GHSA-9w8c-9425-p69g/GHSA-9w8c-9425-p69g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w8c-9425-p69g", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:56Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20121" ], "details": "In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1574.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json b/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json index 62e5ac375f9..f353bd3e737 100644 --- a/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json +++ b/advisories/unreviewed/2024/11/GHSA-cc49-h52c-hm2r/GHSA-cc49-h52c-hm2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cc49-h52c-hm2r", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:56Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20119" ], "details": "In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062301; Issue ID: MSV-1620.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-123" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json b/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json index ec4c20fc537..30c082c2c1b 100644 --- a/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json +++ b/advisories/unreviewed/2024/11/GHSA-f3jh-3x43-rfcx/GHSA-f3jh-3x43-rfcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3jh-3x43-rfcx", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20113" ], "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036814; Issue ID: MSV-1715.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fm3h-xpw5-j8xh/GHSA-fm3h-xpw5-j8xh.json b/advisories/unreviewed/2024/11/GHSA-fm3h-xpw5-j8xh/GHSA-fm3h-xpw5-j8xh.json new file mode 100644 index 00000000000..f784b2ba7f0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fm3h-xpw5-j8xh/GHSA-fm3h-xpw5-j8xh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm3h-xpw5-j8xh", + "modified": "2024-11-04T12:32:57Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-51661" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51661" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/media-library-assistant/wordpress-media-library-assistant-plugin-3-19-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json b/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json new file mode 100644 index 00000000000..bb8f8558ee5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fr3q-8g9r-hvpv/GHSA-fr3q-8g9r-hvpv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr3q-8g9r-hvpv", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38423" + ], + "details": "Memory corruption while processing GPU page table switch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38423" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json b/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json new file mode 100644 index 00000000000..213abb6e90b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g7rx-xjjw-j9xq/GHSA-g7rx-xjjw-j9xq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7rx-xjjw-j9xq", + "modified": "2024-11-04T12:32:57Z", + "published": "2024-11-04T12:32:57Z", + "aliases": [ + "CVE-2024-36485" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions 8121 and prior are vulnerable to SQL Injection in Technician reports option.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36485" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2024-36485.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T12:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json b/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json new file mode 100644 index 00000000000..04d7600512b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gwr8-j573-qw62/GHSA-gwr8-j573-qw62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwr8-j573-qw62", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38421" + ], + "details": "Memory corruption while processing GPU commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38421" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json b/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json new file mode 100644 index 00000000000..a24940faec0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hhm7-rcc5-4hjc/GHSA-hhm7-rcc5-4hjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhm7-rcc5-4hjc", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-33033" + ], + "details": "Memory corruption while processing IOCTL calls to unmap the buffers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33033" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json b/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json new file mode 100644 index 00000000000..0080e052460 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hmcg-rc8j-cqqx/GHSA-hmcg-rc8j-cqqx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmcg-rc8j-cqqx", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38409" + ], + "details": "Memory corruption while station LL statistic handling.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38409" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json b/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json new file mode 100644 index 00000000000..29aefe85f5f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jg3v-6rvm-6p3v/GHSA-jg3v-6rvm-6p3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg3v-6rvm-6p3v", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-33032" + ], + "details": "Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33032" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json b/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json index 722c7ce2166..5fda7118e2e 100644 --- a/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json +++ b/advisories/unreviewed/2024/11/GHSA-m62c-rp67-pw2c/GHSA-m62c-rp67-pw2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m62c-rp67-pw2c", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20107" ], "details": "In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json b/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json index 498fe8dc000..d23c5b858de 100644 --- a/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json +++ b/advisories/unreviewed/2024/11/GHSA-mgx7-9xcp-cmj3/GHSA-mgx7-9xcp-cmj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgx7-9xcp-cmj3", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20108" ], "details": "In atci, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09082988; Issue ID: MSV-1774.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mppp-8v9v-595f/GHSA-mppp-8v9v-595f.json b/advisories/unreviewed/2024/11/GHSA-mppp-8v9v-595f/GHSA-mppp-8v9v-595f.json new file mode 100644 index 00000000000..7f795713487 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mppp-8v9v-595f/GHSA-mppp-8v9v-595f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mppp-8v9v-595f", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-23386" + ], + "details": "memory corruption when WiFi display APIs are invoked with large random inputs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23386" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json b/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json index b81529ca81d..988c0329824 100644 --- a/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json +++ b/advisories/unreviewed/2024/11/GHSA-ph42-jmfw-fmpf/GHSA-ph42-jmfw-fmpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ph42-jmfw-fmpf", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20110" ], "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065887; Issue ID: MSV-1762.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q3rp-vvm7-j8jg/GHSA-q3rp-vvm7-j8jg.json b/advisories/unreviewed/2024/11/GHSA-q3rp-vvm7-j8jg/GHSA-q3rp-vvm7-j8jg.json new file mode 100644 index 00000000000..55365ac3218 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q3rp-vvm7-j8jg/GHSA-q3rp-vvm7-j8jg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3rp-vvm7-j8jg", + "modified": "2024-11-04T12:32:57Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-10389" + ], + "details": "There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10389" + }, + { + "type": "WEB", + "url": "https://github.com/google/safearchive/commit/f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T11:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json b/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json new file mode 100644 index 00000000000..3e3e3a93b3c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q97v-2cp6-jv6p/GHSA-q97v-2cp6-jv6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q97v-2cp6-jv6p", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-23385" + ], + "details": "Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23385" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qjg4-p6j3-36x6/GHSA-qjg4-p6j3-36x6.json b/advisories/unreviewed/2024/11/GHSA-qjg4-p6j3-36x6/GHSA-qjg4-p6j3-36x6.json new file mode 100644 index 00000000000..8d835738f87 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qjg4-p6j3-36x6/GHSA-qjg4-p6j3-36x6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjg4-p6j3-36x6", + "modified": "2024-11-04T12:32:57Z", + "published": "2024-11-04T12:32:57Z", + "aliases": [ + "CVE-2024-10035" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection.This issue affects CoslatV3: through 3.1069. \n\n\n\nNOTE: The vendor was contacted and it was learned that the product is not supported.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10035" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T12:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rhh2-f22c-xh7f/GHSA-rhh2-f22c-xh7f.json b/advisories/unreviewed/2024/11/GHSA-rhh2-f22c-xh7f/GHSA-rhh2-f22c-xh7f.json new file mode 100644 index 00000000000..fad5aadb149 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rhh2-f22c-xh7f/GHSA-rhh2-f22c-xh7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhh2-f22c-xh7f", + "modified": "2024-11-04T12:32:57Z", + "published": "2024-11-04T12:32:57Z", + "aliases": [ + "CVE-2024-10523" + ], + "details": "This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10523" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0331" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T12:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json b/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json index 071611f0fd5..b7efa67d645 100644 --- a/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json +++ b/advisories/unreviewed/2024/11/GHSA-v45x-45vv-7hm9/GHSA-v45x-45vv-7hm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v45x-45vv-7hm9", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20115" ], "details": "In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036695; Issue ID: MSV-1713.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json b/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json index 84f9b7f2122..dd0173c94a8 100644 --- a/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json +++ b/advisories/unreviewed/2024/11/GHSA-vg89-xvr7-m96m/GHSA-vg89-xvr7-m96m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vg89-xvr7-m96m", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:55Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20106" ], "details": "In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08960505; Issue ID: MSV-1590.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vqfr-ww83-fm63/GHSA-vqfr-ww83-fm63.json b/advisories/unreviewed/2024/11/GHSA-vqfr-ww83-fm63/GHSA-vqfr-ww83-fm63.json new file mode 100644 index 00000000000..c1a0d49af29 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vqfr-ww83-fm63/GHSA-vqfr-ww83-fm63.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqfr-ww83-fm63", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-33031" + ], + "details": "Memory corruption while processing the update SIM PB records request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33031" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json b/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json new file mode 100644 index 00000000000..f7086363701 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w36j-hqcc-jvpp/GHSA-w36j-hqcc-jvpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w36j-hqcc-jvpp", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38405" + ], + "details": "Transient DOS while processing the CU information from RNR IE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38405" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json b/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json index eb89f72933e..e5310bdd547 100644 --- a/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json +++ b/advisories/unreviewed/2024/11/GHSA-w9p5-xqxf-xvx7/GHSA-w9p5-xqxf-xvx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9p5-xqxf-xvx7", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:56Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20118" ], "details": "In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062392; Issue ID: MSV-1621.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-123" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json b/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json index 1d5680f787d..606cbc2e8ef 100644 --- a/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json +++ b/advisories/unreviewed/2024/11/GHSA-wjq7-92jr-r24h/GHSA-wjq7-92jr-r24h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjq7-92jr-r24h", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:56Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20123" ], "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1569.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wqm7-xh9j-c3ff/GHSA-wqm7-xh9j-c3ff.json b/advisories/unreviewed/2024/11/GHSA-wqm7-xh9j-c3ff/GHSA-wqm7-xh9j-c3ff.json new file mode 100644 index 00000000000..a1d0fbbc5a5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wqm7-xh9j-c3ff/GHSA-wqm7-xh9j-c3ff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqm7-xh9j-c3ff", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38408" + ], + "details": "Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38408" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json b/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json index 171010bef61..cc9e5b8dc3a 100644 --- a/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json +++ b/advisories/unreviewed/2024/11/GHSA-x6g6-7cr3-c8p4/GHSA-x6g6-7cr3-c8p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6g6-7cr3-c8p4", - "modified": "2024-11-04T03:30:40Z", + "modified": "2024-11-04T12:32:56Z", "published": "2024-11-04T03:30:40Z", "aliases": [ "CVE-2024-20124" ], "details": "In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1568.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T02:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json b/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json new file mode 100644 index 00000000000..ed710ae6b8a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xch5-v6mf-cvxj/GHSA-xch5-v6mf-cvxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xch5-v6mf-cvxj", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-38419" + ], + "details": "Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38419" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json b/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json new file mode 100644 index 00000000000..a527f326b98 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xp7h-ghc6-47w2/GHSA-xp7h-ghc6-47w2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp7h-ghc6-47w2", + "modified": "2024-11-04T12:32:56Z", + "published": "2024-11-04T12:32:56Z", + "aliases": [ + "CVE-2024-33030" + ], + "details": "Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33030" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-04T10:15:05Z" + } +} \ No newline at end of file