From c24d6a0bae8b3778879d196e98e88342d70508a5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Dec 2024 18:32:24 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pwp2-83mh-qj49.json | 4 +- .../GHSA-48g5-4ph9-jjmf.json | 2 +- .../GHSA-372x-c6rw-v8f9.json | 15 +++-- .../GHSA-2948-3mj2-4gw2.json | 15 +++-- .../GHSA-64qm-44w9-r4fm.json | 15 +++-- .../GHSA-69w7-5x2m-p8cp.json | 15 +++-- .../GHSA-79q8-cx3j-4wrg.json | 11 +++- .../GHSA-7p9v-9x3x-2f79.json | 15 +++-- .../GHSA-g6q3-47r5-q8fc.json | 15 +++-- .../GHSA-p64f-v3w3-f3gw.json | 15 +++-- .../GHSA-w3px-8qw9-wj6x.json | 15 +++-- .../GHSA-wpx2-5m9q-j3g7.json | 15 +++-- .../GHSA-cq55-h3qw-j4hc.json | 6 +- .../GHSA-6gwg-w9p5-2c42.json | 3 +- .../GHSA-7w94-mp6m-pfq8.json | 3 +- .../GHSA-jmff-vhcc-w887.json | 3 +- .../GHSA-rh49-w6rx-xcxg.json | 4 +- .../GHSA-3q23-2j2r-mmw3.json | 36 ++++++++++++ .../GHSA-3v69-2vx2-cxcc.json | 15 +++-- .../GHSA-3vmr-3jv9-76jr.json | 15 +++-- .../GHSA-4m2v-5c2p-cp8g.json | 40 +++++++++++++ .../GHSA-529c-hjgw-g8wj.json | 36 ++++++++++++ .../GHSA-52wq-8j3g-pvxx.json | 36 ++++++++++++ .../GHSA-5c75-q5qv-27px.json | 36 ++++++++++++ .../GHSA-5f45-h685-7ww2.json | 3 +- .../GHSA-5xh8-mfhp-x7wc.json | 33 +++++++++++ .../GHSA-6599-24wh-q2vp.json | 36 ++++++++++++ .../GHSA-65fr-wr9w-9m6v.json | 4 +- .../GHSA-6c5q-fg3g-qhhv.json | 15 +++-- .../GHSA-6v27-62rg-jwq2.json | 57 +++++++++++++++++++ .../GHSA-9696-g44j-7f38.json | 15 +++-- .../GHSA-99f4-87g4-qw2h.json | 36 ++++++++++++ .../GHSA-9m9r-rw59-qh84.json | 11 +++- .../GHSA-c93m-w54c-8g9x.json | 36 ++++++++++++ .../GHSA-f2r4-3q83-4c5x.json | 36 ++++++++++++ .../GHSA-f7jp-grr4-2429.json | 40 +++++++++++++ .../GHSA-fcx8-3xwg-jjq7.json | 36 ++++++++++++ .../GHSA-fj3q-j3q4-v62v.json | 40 +++++++++++++ .../GHSA-fppg-2vjw-7hf6.json | 15 +++-- .../GHSA-hmrx-44gm-wjp8.json | 40 +++++++++++++ .../GHSA-hwfm-86r3-467v.json | 33 +++++++++++ .../GHSA-j3vp-3p2j-8q53.json | 11 +++- .../GHSA-jr5v-q344-7hjg.json | 57 +++++++++++++++++++ .../GHSA-mw8h-4567-xqvj.json | 37 ++++++++++++ .../GHSA-p55v-8989-68v9.json | 15 +++-- .../GHSA-pfrv-7m84-m2v2.json | 34 +++++++++++ .../GHSA-pgg8-7hhg-9qjh.json | 15 +++-- .../GHSA-qp49-g67r-vh5q.json | 36 ++++++++++++ .../GHSA-w6c8-g6h2-vv5g.json | 3 +- .../GHSA-wc68-rh2f-56m4.json | 11 +++- 50 files changed, 1004 insertions(+), 86 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-3q23-2j2r-mmw3/GHSA-3q23-2j2r-mmw3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4m2v-5c2p-cp8g/GHSA-4m2v-5c2p-cp8g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-529c-hjgw-g8wj/GHSA-529c-hjgw-g8wj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-52wq-8j3g-pvxx/GHSA-52wq-8j3g-pvxx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5c75-q5qv-27px/GHSA-5c75-q5qv-27px.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6599-24wh-q2vp/GHSA-6599-24wh-q2vp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6v27-62rg-jwq2/GHSA-6v27-62rg-jwq2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-99f4-87g4-qw2h/GHSA-99f4-87g4-qw2h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c93m-w54c-8g9x/GHSA-c93m-w54c-8g9x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f2r4-3q83-4c5x/GHSA-f2r4-3q83-4c5x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f7jp-grr4-2429/GHSA-f7jp-grr4-2429.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fcx8-3xwg-jjq7/GHSA-fcx8-3xwg-jjq7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fj3q-j3q4-v62v/GHSA-fj3q-j3q4-v62v.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hmrx-44gm-wjp8/GHSA-hmrx-44gm-wjp8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jr5v-q344-7hjg/GHSA-jr5v-q344-7hjg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pfrv-7m84-m2v2/GHSA-pfrv-7m84-m2v2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json diff --git a/advisories/unreviewed/2023/06/GHSA-pwp2-83mh-qj49/GHSA-pwp2-83mh-qj49.json b/advisories/unreviewed/2023/06/GHSA-pwp2-83mh-qj49/GHSA-pwp2-83mh-qj49.json index 1f2e07a5810..baa19a898d9 100644 --- a/advisories/unreviewed/2023/06/GHSA-pwp2-83mh-qj49/GHSA-pwp2-83mh-qj49.json +++ b/advisories/unreviewed/2023/06/GHSA-pwp2-83mh-qj49/GHSA-pwp2-83mh-qj49.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-552" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-48g5-4ph9-jjmf/GHSA-48g5-4ph9-jjmf.json b/advisories/unreviewed/2023/07/GHSA-48g5-4ph9-jjmf/GHSA-48g5-4ph9-jjmf.json index 9723b7f78d5..d532f18a69e 100644 --- a/advisories/unreviewed/2023/07/GHSA-48g5-4ph9-jjmf/GHSA-48g5-4ph9-jjmf.json +++ b/advisories/unreviewed/2023/07/GHSA-48g5-4ph9-jjmf/GHSA-48g5-4ph9-jjmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48g5-4ph9-jjmf", - "modified": "2024-01-09T03:30:21Z", + "modified": "2024-12-10T18:31:06Z", "published": "2023-07-31T18:30:22Z", "aliases": [ "CVE-2023-3997" diff --git a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json index fc8ed595b45..30f3b32a6b6 100644 --- a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json +++ b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-372x-c6rw-v8f9", - "modified": "2024-03-04T09:30:29Z", + "modified": "2024-12-10T18:31:05Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1552" ], "details": "Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. *Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-681" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2948-3mj2-4gw2/GHSA-2948-3mj2-4gw2.json b/advisories/unreviewed/2024/03/GHSA-2948-3mj2-4gw2/GHSA-2948-3mj2-4gw2.json index 6e8a629e299..8cb28fc35c6 100644 --- a/advisories/unreviewed/2024/03/GHSA-2948-3mj2-4gw2/GHSA-2948-3mj2-4gw2.json +++ b/advisories/unreviewed/2024/03/GHSA-2948-3mj2-4gw2/GHSA-2948-3mj2-4gw2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2948-3mj2-4gw2", - "modified": "2024-03-01T00:30:28Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47062" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Use online_vcpus, not created_vcpus, to iterate over vCPUs\n\nUse the kvm_for_each_vcpu() helper to iterate over vCPUs when encrypting\nVMSAs for SEV, which effectively switches to use online_vcpus instead of\ncreated_vcpus. This fixes a possible null-pointer dereference as\ncreated_vcpus does not guarantee a vCPU exists, since it is updated at\nthe very beginning of KVM_CREATE_VCPU. created_vcpus exists to allow the\nbulk of vCPU creation to run in parallel, while still correctly\nrestricting the max number of max vCPUs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-64qm-44w9-r4fm/GHSA-64qm-44w9-r4fm.json b/advisories/unreviewed/2024/03/GHSA-64qm-44w9-r4fm/GHSA-64qm-44w9-r4fm.json index c9072c6558b..2af63ef4216 100644 --- a/advisories/unreviewed/2024/03/GHSA-64qm-44w9-r4fm/GHSA-64qm-44w9-r4fm.json +++ b/advisories/unreviewed/2024/03/GHSA-64qm-44w9-r4fm/GHSA-64qm-44w9-r4fm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-64qm-44w9-r4fm", - "modified": "2024-03-01T00:30:28Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47059" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - fix result memory leak on error path\n\nThis patch fixes a memory leak on an error path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-69w7-5x2m-p8cp/GHSA-69w7-5x2m-p8cp.json b/advisories/unreviewed/2024/03/GHSA-69w7-5x2m-p8cp/GHSA-69w7-5x2m-p8cp.json index 9f96dd778d9..8209de98333 100644 --- a/advisories/unreviewed/2024/03/GHSA-69w7-5x2m-p8cp/GHSA-69w7-5x2m-p8cp.json +++ b/advisories/unreviewed/2024/03/GHSA-69w7-5x2m-p8cp/GHSA-69w7-5x2m-p8cp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69w7-5x2m-p8cp", - "modified": "2024-03-01T00:30:28Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47058" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: set debugfs_name to NULL after it is freed\n\nThere is a upstream commit cffa4b2122f5(\"regmap:debugfs:\nFix a memory leak when calling regmap_attach_dev\") that\nadds a if condition when create name for debugfs_name.\nWith below function invoking logical, debugfs_name is\nfreed in regmap_debugfs_exit(), but it is not created again\nbecause of the if condition introduced by above commit.\nregmap_reinit_cache()\n\tregmap_debugfs_exit()\n\t...\n\tregmap_debugfs_init()\nSo, set debugfs_name to NULL after it is freed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-79q8-cx3j-4wrg/GHSA-79q8-cx3j-4wrg.json b/advisories/unreviewed/2024/03/GHSA-79q8-cx3j-4wrg/GHSA-79q8-cx3j-4wrg.json index 451623ad268..5c87586e7ff 100644 --- a/advisories/unreviewed/2024/03/GHSA-79q8-cx3j-4wrg/GHSA-79q8-cx3j-4wrg.json +++ b/advisories/unreviewed/2024/03/GHSA-79q8-cx3j-4wrg/GHSA-79q8-cx3j-4wrg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79q8-cx3j-4wrg", - "modified": "2024-03-01T00:30:27Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:27Z", "aliases": [ "CVE-2021-47054" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: qcom: Put child node before return\n\nPut child node before return to fix potential reference count leak.\nGenerally, the reference count of child is incremented and decremented\nautomatically in the macro for_each_available_child_of_node() and should\nbe decremented manually if the loop is broken in loop body.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7p9v-9x3x-2f79/GHSA-7p9v-9x3x-2f79.json b/advisories/unreviewed/2024/03/GHSA-7p9v-9x3x-2f79/GHSA-7p9v-9x3x-2f79.json index 3c339d342e4..1e6a2780aef 100644 --- a/advisories/unreviewed/2024/03/GHSA-7p9v-9x3x-2f79/GHSA-7p9v-9x3x-2f79.json +++ b/advisories/unreviewed/2024/03/GHSA-7p9v-9x3x-2f79/GHSA-7p9v-9x3x-2f79.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7p9v-9x3x-2f79", - "modified": "2024-03-01T00:30:28Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47065" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtw88: Fix array overrun in rtw_get_tx_power_params()\n\nUsing a kernel with the Undefined Behaviour Sanity Checker (UBSAN) enabled, the\nfollowing array overrun is logged:\n\n================================================================================\nUBSAN: array-index-out-of-bounds in /home/finger/wireless-drivers-next/drivers/net/wireless/realtek/rtw88/phy.c:1789:34\nindex 5 is out of range for type 'u8 [5]'\nCPU: 2 PID: 84 Comm: kworker/u16:3 Tainted: G O 5.12.0-rc5-00086-gd88bba47038e-dirty #651\nHardware name: TOSHIBA TECRA A50-A/TECRA A50-A, BIOS Version 4.50 09/29/2014\nWorkqueue: phy0 ieee80211_scan_work [mac80211]\nCall Trace:\n dump_stack+0x64/0x7c\n ubsan_epilogue+0x5/0x40\n __ubsan_handle_out_of_bounds.cold+0x43/0x48\n rtw_get_tx_power_params+0x83a/drivers/net/wireless/realtek/rtw88/0xad0 [rtw_core]\n ? rtw_pci_read16+0x20/0x20 [rtw_pci]\n ? check_hw_ready+0x50/0x90 [rtw_core]\n rtw_phy_get_tx_power_index+0x4d/0xd0 [rtw_core]\n rtw_phy_set_tx_power_level+0xee/0x1b0 [rtw_core]\n rtw_set_channel+0xab/0x110 [rtw_core]\n rtw_ops_config+0x87/0xc0 [rtw_core]\n ieee80211_hw_config+0x9d/0x130 [mac80211]\n ieee80211_scan_state_set_channel+0x81/0x170 [mac80211]\n ieee80211_scan_work+0x19f/0x2a0 [mac80211]\n process_one_work+0x1dd/0x3a0\n worker_thread+0x49/0x330\n ? rescuer_thread+0x3a0/0x3a0\n kthread+0x134/0x150\n ? kthread_create_worker_on_cpu+0x70/0x70\n ret_from_fork+0x22/0x30\n================================================================================\n\nThe statement where an array is being overrun is shown in the following snippet:\n\n\tif (rate <= DESC_RATE11M)\n\t\ttx_power = pwr_idx_2g->cck_base[group];\n\telse\n====>\t\ttx_power = pwr_idx_2g->bw40_base[group];\n\nThe associated arrays are defined in main.h as follows:\n\nstruct rtw_2g_txpwr_idx {\n\tu8 cck_base[6];\n\tu8 bw40_base[5];\n\tstruct rtw_2g_1s_pwr_idx_diff ht_1s_diff;\n\tstruct rtw_2g_ns_pwr_idx_diff ht_2s_diff;\n\tstruct rtw_2g_ns_pwr_idx_diff ht_3s_diff;\n\tstruct rtw_2g_ns_pwr_idx_diff ht_4s_diff;\n};\n\nThe problem arises because the value of group is 5 for channel 14. The trivial\nincrease in the dimension of bw40_base fails as this struct must match the layout of\nefuse. The fix is to add the rate as an argument to rtw_get_channel_group() and set\nthe group for channel 14 to 4 if rate <= DESC_RATE11M.\n\nThis patch fixes commit fa6dfe6bff24 (\"rtw88: resolve order of tx power setting routines\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g6q3-47r5-q8fc/GHSA-g6q3-47r5-q8fc.json b/advisories/unreviewed/2024/03/GHSA-g6q3-47r5-q8fc/GHSA-g6q3-47r5-q8fc.json index 1e7be6727aa..7b63f30bb7a 100644 --- a/advisories/unreviewed/2024/03/GHSA-g6q3-47r5-q8fc/GHSA-g6q3-47r5-q8fc.json +++ b/advisories/unreviewed/2024/03/GHSA-g6q3-47r5-q8fc/GHSA-g6q3-47r5-q8fc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g6q3-47r5-q8fc", - "modified": "2024-03-01T00:30:28Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: bridge/panel: Cleanup connector on bridge detach\n\nIf we don't call drm_connector_cleanup() manually in\npanel_bridge_detach(), the connector will be cleaned up with the other\nDRM objects in the call to drm_mode_config_cleanup(). However, since our\ndrm_connector is devm-allocated, by the time drm_mode_config_cleanup()\nwill be called, our connector will be long gone. Therefore, the\nconnector must be cleaned up when the bridge is detached to avoid\nuse-after-free conditions.\n\nv2: Cleanup connector only if it was created\n\nv3: Add FIXME\n\nv4: (Use connector->dev) directly in if() block", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-p64f-v3w3-f3gw/GHSA-p64f-v3w3-f3gw.json b/advisories/unreviewed/2024/03/GHSA-p64f-v3w3-f3gw/GHSA-p64f-v3w3-f3gw.json index 2771d633614..47833a00a0e 100644 --- a/advisories/unreviewed/2024/03/GHSA-p64f-v3w3-f3gw/GHSA-p64f-v3w3-f3gw.json +++ b/advisories/unreviewed/2024/03/GHSA-p64f-v3w3-f3gw/GHSA-p64f-v3w3-f3gw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p64f-v3w3-f3gw", - "modified": "2024-03-01T00:30:26Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:26Z", "aliases": [ "CVE-2021-46959" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: Fix use-after-free with devm_spi_alloc_*\n\nWe can't rely on the contents of the devres list during\nspi_unregister_controller(), as the list is already torn down at the\ntime we perform devres_find() for devm_spi_release_controller. This\ncauses devices registered with devm_spi_alloc_{master,slave}() to be\nmistakenly identified as legacy, non-devm managed devices and have their\nreference counters decremented below 0.\n\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 660 at lib/refcount.c:28 refcount_warn_saturate+0x108/0x174\n[] (refcount_warn_saturate) from [] (kobject_put+0x90/0x98)\n[] (kobject_put) from [] (put_device+0x20/0x24)\n r4:b6700140\n[] (put_device) from [] (devm_spi_release_controller+0x3c/0x40)\n[] (devm_spi_release_controller) from [] (release_nodes+0x84/0xc4)\n r5:b6700180 r4:b6700100\n[] (release_nodes) from [] (devres_release_all+0x5c/0x60)\n r8:b1638c54 r7:b117ad94 r6:b1638c10 r5:b117ad94 r4:b163dc10\n[] (devres_release_all) from [] (__device_release_driver+0x144/0x1ec)\n r5:b117ad94 r4:b163dc10\n[] (__device_release_driver) from [] (device_driver_detach+0x84/0xa0)\n r9:00000000 r8:00000000 r7:b117ad94 r6:b163dc54 r5:b1638c10 r4:b163dc10\n[] (device_driver_detach) from [] (unbind_store+0xe4/0xf8)\n\nInstead, determine the devm allocation state as a flag on the\ncontroller which is guaranteed to be stable during cleanup.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w3px-8qw9-wj6x/GHSA-w3px-8qw9-wj6x.json b/advisories/unreviewed/2024/03/GHSA-w3px-8qw9-wj6x/GHSA-w3px-8qw9-wj6x.json index 7f4e0224b23..3701a18d74b 100644 --- a/advisories/unreviewed/2024/03/GHSA-w3px-8qw9-wj6x/GHSA-w3px-8qw9-wj6x.json +++ b/advisories/unreviewed/2024/03/GHSA-w3px-8qw9-wj6x/GHSA-w3px-8qw9-wj6x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3px-8qw9-wj6x", - "modified": "2024-03-01T00:30:27Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:27Z", "aliases": [ "CVE-2021-47020" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoundwire: stream: fix memory leak in stream config error path\n\nWhen stream config is failed, master runtime will release all\nslave runtime in the slave_rt_list, but slave runtime is not\nadded to the list at this time. This patch frees slave runtime\nin the config error path to fix the memory leak.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wpx2-5m9q-j3g7/GHSA-wpx2-5m9q-j3g7.json b/advisories/unreviewed/2024/03/GHSA-wpx2-5m9q-j3g7/GHSA-wpx2-5m9q-j3g7.json index ed911dc9a98..a6e89fd6b42 100644 --- a/advisories/unreviewed/2024/03/GHSA-wpx2-5m9q-j3g7/GHSA-wpx2-5m9q-j3g7.json +++ b/advisories/unreviewed/2024/03/GHSA-wpx2-5m9q-j3g7/GHSA-wpx2-5m9q-j3g7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wpx2-5m9q-j3g7", - "modified": "2024-03-01T00:30:28Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47061" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU\n\nIf allocating a new instance of an I/O bus fails when unregistering a\ndevice, wait to destroy the device until after all readers are guaranteed\nto see the new null bus. Destroying devices before the bus is nullified\ncould lead to use-after-free since readers expect the devices on their\nreference of the bus to remain valid.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json b/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json index a2a5e64665e..fca71c9f1c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json +++ b/advisories/unreviewed/2024/04/GHSA-cq55-h3qw-j4hc/GHSA-cq55-h3qw-j4hc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cq55-h3qw-j4hc", - "modified": "2024-09-06T21:32:27Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-04-26T21:31:11Z", "aliases": [ "CVE-2022-48611" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48611" }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/103001" + }, { "type": "WEB", "url": "https://support.claris.com/s/answerview?anum=000041674&language=en_US" diff --git a/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json b/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json index d005fd25b9c..9e7e9266d9e 100644 --- a/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json +++ b/advisories/unreviewed/2024/05/GHSA-6gwg-w9p5-2c42/GHSA-6gwg-w9p5-2c42.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-257" + "CWE-257", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json b/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json index bf13a4383d3..6be941b0534 100644 --- a/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json +++ b/advisories/unreviewed/2024/08/GHSA-7w94-mp6m-pfq8/GHSA-7w94-mp6m-pfq8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json b/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json index bc2229f019a..0be9b52ec04 100644 --- a/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json +++ b/advisories/unreviewed/2024/11/GHSA-jmff-vhcc-w887/GHSA-jmff-vhcc-w887.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json b/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json index 96e41b3c314..a13609aa0be 100644 --- a/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json +++ b/advisories/unreviewed/2024/11/GHSA-rh49-w6rx-xcxg/GHSA-rh49-w6rx-xcxg.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-3q23-2j2r-mmw3/GHSA-3q23-2j2r-mmw3.json b/advisories/unreviewed/2024/12/GHSA-3q23-2j2r-mmw3/GHSA-3q23-2j2r-mmw3.json new file mode 100644 index 00000000000..92d8a0c3b1c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3q23-2j2r-mmw3/GHSA-3q23-2j2r-mmw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q23-2j2r-mmw3", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-55544" + ], + "details": "Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55544" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/security-research/st-polten-uas-multiple-vulnerabilities-in-oring-iap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json b/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json index a6213fa7ab3..d95a0daa802 100644 --- a/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json +++ b/advisories/unreviewed/2024/12/GHSA-3v69-2vx2-cxcc/GHSA-3v69-2vx2-cxcc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3v69-2vx2-cxcc", - "modified": "2024-12-07T00:31:03Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-07T00:31:03Z", "aliases": [ "CVE-2024-41647" ], "details": "Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-06T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json b/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json index 0563490f680..565ea213b12 100644 --- a/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json +++ b/advisories/unreviewed/2024/12/GHSA-3vmr-3jv9-76jr/GHSA-3vmr-3jv9-76jr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vmr-3jv9-76jr", - "modified": "2024-12-09T15:31:37Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-54919" ], "details": "A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T15:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4m2v-5c2p-cp8g/GHSA-4m2v-5c2p-cp8g.json b/advisories/unreviewed/2024/12/GHSA-4m2v-5c2p-cp8g/GHSA-4m2v-5c2p-cp8g.json new file mode 100644 index 00000000000..8d315d64ada --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4m2v-5c2p-cp8g/GHSA-4m2v-5c2p-cp8g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m2v-5c2p-cp8g", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-10495" + ], + "details": "An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10495" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/out-of-bounds-read-vulnerabilities-in-ni-labview-.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-529c-hjgw-g8wj/GHSA-529c-hjgw-g8wj.json b/advisories/unreviewed/2024/12/GHSA-529c-hjgw-g8wj/GHSA-529c-hjgw-g8wj.json new file mode 100644 index 00000000000..f97a94e0d52 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-529c-hjgw-g8wj/GHSA-529c-hjgw-g8wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-529c-hjgw-g8wj", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-53247" + ], + "details": "In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.2.461 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53247" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1205" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-52wq-8j3g-pvxx/GHSA-52wq-8j3g-pvxx.json b/advisories/unreviewed/2024/12/GHSA-52wq-8j3g-pvxx/GHSA-52wq-8j3g-pvxx.json new file mode 100644 index 00000000000..9b1863030ed --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-52wq-8j3g-pvxx/GHSA-52wq-8j3g-pvxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52wq-8j3g-pvxx", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-55547" + ], + "details": "SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55547" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/security-research/st-polten-uas-multiple-vulnerabilities-in-oring-iap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5c75-q5qv-27px/GHSA-5c75-q5qv-27px.json b/advisories/unreviewed/2024/12/GHSA-5c75-q5qv-27px/GHSA-5c75-q5qv-27px.json new file mode 100644 index 00000000000..dcd5c7680b1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5c75-q5qv-27px/GHSA-5c75-q5qv-27px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c75-q5qv-27px", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-55545" + ], + "details": "Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55545" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/security-research/st-polten-uas-multiple-vulnerabilities-in-oring-iap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5f45-h685-7ww2/GHSA-5f45-h685-7ww2.json b/advisories/unreviewed/2024/12/GHSA-5f45-h685-7ww2/GHSA-5f45-h685-7ww2.json index 604eee920d6..a7d0caac1ad 100644 --- a/advisories/unreviewed/2024/12/GHSA-5f45-h685-7ww2/GHSA-5f45-h685-7ww2.json +++ b/advisories/unreviewed/2024/12/GHSA-5f45-h685-7ww2/GHSA-5f45-h685-7ww2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json b/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json new file mode 100644 index 00000000000..a9d0531176a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5xh8-mfhp-x7wc/GHSA-5xh8-mfhp-x7wc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xh8-mfhp-x7wc", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-45493" + ], + "details": "An issue was discovered in MSA Safety FieldServer Gateways and Embedded Modules with build revisions before 7.0.0. The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45493" + }, + { + "type": "WEB", + "url": "https://us.msasafety.com/fieldserver" + }, + { + "type": "WEB", + "url": "https://us.msasafety.com/security-notices:" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6599-24wh-q2vp/GHSA-6599-24wh-q2vp.json b/advisories/unreviewed/2024/12/GHSA-6599-24wh-q2vp/GHSA-6599-24wh-q2vp.json new file mode 100644 index 00000000000..c64e36052d5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6599-24wh-q2vp/GHSA-6599-24wh-q2vp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6599-24wh-q2vp", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-53244" + ], + "details": "In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on “/en-US/app/search/report“ endpoint through “s“ parameter.
The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53244" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-65fr-wr9w-9m6v/GHSA-65fr-wr9w-9m6v.json b/advisories/unreviewed/2024/12/GHSA-65fr-wr9w-9m6v/GHSA-65fr-wr9w-9m6v.json index 39b8d9913a8..ea7ee15596a 100644 --- a/advisories/unreviewed/2024/12/GHSA-65fr-wr9w-9m6v/GHSA-65fr-wr9w-9m6v.json +++ b/advisories/unreviewed/2024/12/GHSA-65fr-wr9w-9m6v/GHSA-65fr-wr9w-9m6v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-6c5q-fg3g-qhhv/GHSA-6c5q-fg3g-qhhv.json b/advisories/unreviewed/2024/12/GHSA-6c5q-fg3g-qhhv/GHSA-6c5q-fg3g-qhhv.json index 546ae384173..1f0f19f710b 100644 --- a/advisories/unreviewed/2024/12/GHSA-6c5q-fg3g-qhhv/GHSA-6c5q-fg3g-qhhv.json +++ b/advisories/unreviewed/2024/12/GHSA-6c5q-fg3g-qhhv/GHSA-6c5q-fg3g-qhhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6c5q-fg3g-qhhv", - "modified": "2024-12-06T00:31:46Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-06T00:31:46Z", "aliases": [ "CVE-2024-53457" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-05T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6v27-62rg-jwq2/GHSA-6v27-62rg-jwq2.json b/advisories/unreviewed/2024/12/GHSA-6v27-62rg-jwq2/GHSA-6v27-62rg-jwq2.json new file mode 100644 index 00000000000..7600e5e3d54 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6v27-62rg-jwq2/GHSA-6v27-62rg-jwq2.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v27-62rg-jwq2", + "modified": "2024-12-10T18:31:06Z", + "published": "2024-12-10T18:31:06Z", + "aliases": [ + "CVE-2024-11592" + ], + "details": "A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11592" + }, + { + "type": "WEB", + "url": "https://github.com/Hacker0xone/CVE/issues/15" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285664" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285664" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.445719" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json b/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json index d2b11b198bb..901d56f4bfd 100644 --- a/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json +++ b/advisories/unreviewed/2024/12/GHSA-9696-g44j-7f38/GHSA-9696-g44j-7f38.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9696-g44j-7f38", - "modified": "2024-12-09T18:31:20Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-09T18:31:20Z", "aliases": [ "CVE-2024-54935" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T18:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-99f4-87g4-qw2h/GHSA-99f4-87g4-qw2h.json b/advisories/unreviewed/2024/12/GHSA-99f4-87g4-qw2h/GHSA-99f4-87g4-qw2h.json new file mode 100644 index 00000000000..59a848f0080 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-99f4-87g4-qw2h/GHSA-99f4-87g4-qw2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99f4-87g4-qw2h", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-53246" + ], + "details": "In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerability requires the exploitation of another vulnerability, such as a Risky Commands Bypass, for successful exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53246" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json b/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json index a3a477da3c0..6750039af6a 100644 --- a/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json +++ b/advisories/unreviewed/2024/12/GHSA-9m9r-rw59-qh84/GHSA-9m9r-rw59-qh84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9m9r-rw59-qh84", - "modified": "2024-12-10T06:31:40Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-10T06:31:40Z", "aliases": [ "CVE-2024-11107" ], "details": "The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c93m-w54c-8g9x/GHSA-c93m-w54c-8g9x.json b/advisories/unreviewed/2024/12/GHSA-c93m-w54c-8g9x/GHSA-c93m-w54c-8g9x.json new file mode 100644 index 00000000000..08a7b36d8ae --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c93m-w54c-8g9x/GHSA-c93m-w54c-8g9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c93m-w54c-8g9x", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-53243" + ], + "details": "In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53243" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1201" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f2r4-3q83-4c5x/GHSA-f2r4-3q83-4c5x.json b/advisories/unreviewed/2024/12/GHSA-f2r4-3q83-4c5x/GHSA-f2r4-3q83-4c5x.json new file mode 100644 index 00000000000..077a8d0eb66 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f2r4-3q83-4c5x/GHSA-f2r4-3q83-4c5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2r4-3q83-4c5x", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-55548" + ], + "details": "Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: through 2.01e.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55548" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/security-research/st-polten-uas-multiple-vulnerabilities-in-oring-iap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-703" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f7jp-grr4-2429/GHSA-f7jp-grr4-2429.json b/advisories/unreviewed/2024/12/GHSA-f7jp-grr4-2429/GHSA-f7jp-grr4-2429.json new file mode 100644 index 00000000000..836bedcc13f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f7jp-grr4-2429/GHSA-f7jp-grr4-2429.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7jp-grr4-2429", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-12286" + ], + "details": "MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12286" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fcx8-3xwg-jjq7/GHSA-fcx8-3xwg-jjq7.json b/advisories/unreviewed/2024/12/GHSA-fcx8-3xwg-jjq7/GHSA-fcx8-3xwg-jjq7.json new file mode 100644 index 00000000000..0f518e97fa0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fcx8-3xwg-jjq7/GHSA-fcx8-3xwg-jjq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcx8-3xwg-jjq7", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-55546" + ], + "details": "Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55546" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/security-research/st-polten-uas-multiple-vulnerabilities-in-oring-iap" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fj3q-j3q4-v62v/GHSA-fj3q-j3q4-v62v.json b/advisories/unreviewed/2024/12/GHSA-fj3q-j3q4-v62v/GHSA-fj3q-j3q4-v62v.json new file mode 100644 index 00000000000..0128431fd85 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fj3q-j3q4-v62v/GHSA-fj3q-j3q4-v62v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj3q-j3q4-v62v", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-10496" + ], + "details": "An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10496" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/out-of-bounds-read-vulnerabilities-in-ni-labview-.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json b/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json index ca61245c1ad..e0e571e9f8b 100644 --- a/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json +++ b/advisories/unreviewed/2024/12/GHSA-fppg-2vjw-7hf6/GHSA-fppg-2vjw-7hf6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fppg-2vjw-7hf6", - "modified": "2024-12-09T15:31:37Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-54929" ], "details": "KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hmrx-44gm-wjp8/GHSA-hmrx-44gm-wjp8.json b/advisories/unreviewed/2024/12/GHSA-hmrx-44gm-wjp8/GHSA-hmrx-44gm-wjp8.json new file mode 100644 index 00000000000..a54e03a83b6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hmrx-44gm-wjp8/GHSA-hmrx-44gm-wjp8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmrx-44gm-wjp8", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-10494" + ], + "details": "An out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10494" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/out-of-bounds-read-vulnerabilities-in-ni-labview-.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json b/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json new file mode 100644 index 00000000000..76a0c6a8dc9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwfm-86r3-467v", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-45494" + ], + "details": "An issue was discovered in MSA Safety FieldServer Gateways and Embedded Modules with build revisions before 7.0.0. The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45494" + }, + { + "type": "WEB", + "url": "https://us.msasafety.com/fieldserver" + }, + { + "type": "WEB", + "url": "https://us.msasafety.com/security-notices" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json b/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json index 050e81034a9..a67045a1012 100644 --- a/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json +++ b/advisories/unreviewed/2024/12/GHSA-j3vp-3p2j-8q53/GHSA-j3vp-3p2j-8q53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3vp-3p2j-8q53", - "modified": "2024-12-10T06:31:40Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-10T06:31:40Z", "aliases": [ "CVE-2024-10708" ], "details": "The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T06:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jr5v-q344-7hjg/GHSA-jr5v-q344-7hjg.json b/advisories/unreviewed/2024/12/GHSA-jr5v-q344-7hjg/GHSA-jr5v-q344-7hjg.json new file mode 100644 index 00000000000..2101570cfd1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jr5v-q344-7hjg/GHSA-jr5v-q344-7hjg.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr5v-q344-7hjg", + "modified": "2024-12-10T18:31:06Z", + "published": "2024-12-10T18:31:06Z", + "aliases": [ + "CVE-2024-11591" + ], + "details": "A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument sername leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11591" + }, + { + "type": "WEB", + "url": "https://github.com/Hacker0xone/CVE/issues/14" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.285663" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.285663" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.445718" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json b/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json new file mode 100644 index 00000000000..63ba167b94e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mw8h-4567-xqvj/GHSA-mw8h-4567-xqvj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw8h-4567-xqvj", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-46657" + ], + "details": "Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46657" + }, + { + "type": "WEB", + "url": "https://github.com/ArtifexSoftware/mupdf/commit/b5c898a30f068b5342e8263a2cd5b9f0be291aac" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/diff/?id=b5c898a30f068b5342e8263a2cd5b9f0be291aac" + }, + { + "type": "WEB", + "url": "https://gist.github.com/isumitpatel/615e6bd2621cb46b5d980ddb9db223e2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json b/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json index dd29f8f2642..4a79ded33bd 100644 --- a/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json +++ b/advisories/unreviewed/2024/12/GHSA-p55v-8989-68v9/GHSA-p55v-8989-68v9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p55v-8989-68v9", - "modified": "2024-12-09T15:31:37Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-54920" ], "details": "A SQL Injection vulnerability was found in the /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T15:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pfrv-7m84-m2v2/GHSA-pfrv-7m84-m2v2.json b/advisories/unreviewed/2024/12/GHSA-pfrv-7m84-m2v2/GHSA-pfrv-7m84-m2v2.json new file mode 100644 index 00000000000..dc9e9371ec8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pfrv-7m84-m2v2/GHSA-pfrv-7m84-m2v2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfrv-7m84-m2v2", + "modified": "2024-12-10T18:31:06Z", + "published": "2024-12-10T18:31:06Z", + "aliases": [ + "CVE-2024-45663" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45663" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175943" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T11:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json b/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json index a10daddcad1..5f954ad138a 100644 --- a/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json +++ b/advisories/unreviewed/2024/12/GHSA-pgg8-7hhg-9qjh/GHSA-pgg8-7hhg-9qjh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pgg8-7hhg-9qjh", - "modified": "2024-12-09T15:31:37Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-54936" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability was found in the /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T14:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json b/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json new file mode 100644 index 00000000000..7b110196501 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qp49-g67r-vh5q/GHSA-qp49-g67r-vh5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp49-g67r-vh5q", + "modified": "2024-12-10T18:31:07Z", + "published": "2024-12-10T18:31:07Z", + "aliases": [ + "CVE-2024-53245" + ], + "details": "In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read access to dashboards, could see the dashboard name and the dashboard XML by cloning the dashboard.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53245" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2024-1203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-10T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w6c8-g6h2-vv5g/GHSA-w6c8-g6h2-vv5g.json b/advisories/unreviewed/2024/12/GHSA-w6c8-g6h2-vv5g/GHSA-w6c8-g6h2-vv5g.json index 0edbdfb0172..8ae5a3b1d14 100644 --- a/advisories/unreviewed/2024/12/GHSA-w6c8-g6h2-vv5g/GHSA-w6c8-g6h2-vv5g.json +++ b/advisories/unreviewed/2024/12/GHSA-w6c8-g6h2-vv5g/GHSA-w6c8-g6h2-vv5g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json b/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json index 40fd6f50d34..1a2dfe79fbf 100644 --- a/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json +++ b/advisories/unreviewed/2024/12/GHSA-wc68-rh2f-56m4/GHSA-wc68-rh2f-56m4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wc68-rh2f-56m4", - "modified": "2024-12-09T15:31:37Z", + "modified": "2024-12-10T18:31:06Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-54937" ], "details": "A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-09T14:15:13Z"