Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-10-03 21:32:31 +00:00
parent e0edab241f
commit c4535cd69f
34 changed files with 706 additions and 36 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-882j-m7wv-38p6",
"modified": "2022-05-14T01:06:14Z",
"modified": "2024-10-03T21:31:02Z",
"published": "2022-05-14T01:06:14Z",
"aliases": [
"CVE-2018-2628"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26j2-2wp8-h95h",
"modified": "2023-01-05T18:30:30Z",
"modified": "2024-10-03T21:31:02Z",
"published": "2022-12-26T21:30:24Z",
"aliases": [
"CVE-2020-12069"
@@ -64,6 +64,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4ghh-vv6c-6p5m",
"modified": "2024-04-04T07:08:43Z",
"modified": "2024-10-03T21:31:03Z",
"published": "2023-08-22T21:30:27Z",
"aliases": [
"CVE-2023-37421"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-84hr-648m-6p8v",
"modified": "2024-02-13T03:30:20Z",
"modified": "2024-10-03T21:31:03Z",
"published": "2024-02-13T03:30:20Z",
"aliases": [
"CVE-2023-52060"
],
"details": "A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T01:15:08Z"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,21 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5fx-mv2q-2jpr",
"modified": "2024-06-12T21:31:19Z",
"modified": "2024-10-03T21:31:03Z",
"published": "2024-06-12T21:31:19Z",
"aliases": [
"CVE-2024-3467"
],
"details": "There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -27,7 +34,7 @@
"cwe_ids": [
"CWE-502"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-12T21:15:50Z"
@@ -1,14 +1,21 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jm3x-qp4q-p8jr",
"modified": "2024-06-13T18:31:58Z",
"modified": "2024-10-03T21:31:03Z",
"published": "2024-06-13T18:31:58Z",
"aliases": [
"CVE-2024-38280"
],
"details": "An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
@@ -25,9 +32,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312",
"CWE-313"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-13T17:15:51Z"
@@ -37,6 +37,7 @@
"database_specific": {
"cwe_ids": [
"CWE-1004",
"CWE-732",
"CWE-79"
],
"severity": "MODERATE",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-670",
"CWE-783"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mhxx-5693-798f",
"modified": "2024-09-27T18:32:27Z",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-09-27T18:32:27Z",
"aliases": [
"CVE-2024-46256"
],
"details": "A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-27T18:15:05Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-224h-m2mg-r929",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-10-03T21:31:04Z",
"aliases": [
"CVE-2024-41591"
],
"details": "DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41591"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draybreak-draytek-research"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draytek14-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T19:15:04Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46m2-r42j-gr4p",
"modified": "2024-10-03T18:30:36Z",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-10-03T18:30:36Z",
"aliases": [
"CVE-2024-45870"
],
"details": "Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T16:15:06Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qpr-f47p-f6ch",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-10-03T21:31:04Z",
"aliases": [
"CVE-2024-41588"
],
"details": "The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41588"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draybreak-draytek-research"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draytek14-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T19:15:04Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63q2-3m87-pq6j",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-10-03T21:31:04Z",
"aliases": [
"CVE-2024-41592"
],
"details": "DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41592"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draybreak-draytek-research"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draytek14-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T19:15:04Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-683h-34r2-xc99",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-10-03T21:31:04Z",
"aliases": [
"CVE-2024-41589"
],
"details": "DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41589"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draybreak-draytek-research"
},
{
"type": "WEB",
"url": "https://www.forescout.com/resources/draytek14-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-03T19:15:04Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72cp-q9j9-fhvh",
"modified": "2024-10-02T15:30:38Z",
"modified": "2024-10-03T21:31:04Z",
"published": "2024-10-02T15:30:38Z",
"aliases": [
"CVE-2024-44193"
],
"details": "A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-02T15:15:14Z"

Some files were not shown because too many files have changed in this diff Show More