From c4535cd69f5f6be6a855a19a3b899a822a67fbfa Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 3 Oct 2024 21:32:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-882j-m7wv-38p6.json | 2 +- .../GHSA-26j2-2wp8-h95h.json | 2 +- .../GHSA-6653-c3g4-g7jm.json | 1 + .../GHSA-3cvg-j39v-pqwx.json | 2 +- .../GHSA-4ghh-vv6c-6p5m.json | 2 +- .../GHSA-cg26-wmrp-ggr4.json | 2 +- .../GHSA-cmv9-rhxg-f4xc.json | 2 +- .../GHSA-84hr-648m-6p8v.json | 11 +++-- .../GHSA-83cc-qgcr-qjcw.json | 2 +- .../GHSA-g5fx-mv2q-2jpr.json | 13 ++++-- .../GHSA-jm3x-qp4q-p8jr.json | 14 +++++-- .../GHSA-pvxg-5348-rxvf.json | 1 + .../GHSA-2g8x-wxp8-jhpg.json | 1 + .../GHSA-mhxx-5693-798f.json | 11 +++-- .../GHSA-224h-m2mg-r929.json | 39 +++++++++++++++++ .../GHSA-46m2-r42j-gr4p.json | 11 +++-- .../GHSA-5qpr-f47p-f6ch.json | 39 +++++++++++++++++ .../GHSA-63q2-3m87-pq6j.json | 42 +++++++++++++++++++ .../GHSA-683h-34r2-xc99.json | 39 +++++++++++++++++ .../GHSA-72cp-q9j9-fhvh.json | 9 ++-- .../GHSA-7cq8-ppvr-h6pr.json | 39 +++++++++++++++++ .../GHSA-7pfp-9xwm-7xfg.json | 42 +++++++++++++++++++ .../GHSA-82ch-xgf6-4685.json | 39 +++++++++++++++++ .../GHSA-8mx7-3ccx-q5cq.json | 11 +++-- .../GHSA-92rw-4jh9-x8q2.json | 39 +++++++++++++++++ .../GHSA-g7f6-jj92-wc77.json | 39 +++++++++++++++++ .../GHSA-gx28-329m-22gw.json | 39 +++++++++++++++++ .../GHSA-h66h-gwq7-wjq2.json | 42 +++++++++++++++++++ .../GHSA-jhrj-jf6x-vjjx.json | 39 +++++++++++++++++ .../GHSA-jj78-5fmv-mv28.json | 38 +++++++++++++++++ .../GHSA-p4hq-9rw5-2cwc.json | 11 +++-- .../GHSA-qxgf-2m78-27m8.json | 35 ++++++++++++++++ .../GHSA-wrwp-h7qf-jwgj.json | 42 +++++++++++++++++++ .../GHSA-x5qv-p3pm-x7fg.json | 42 +++++++++++++++++++ 34 files changed, 706 insertions(+), 36 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-224h-m2mg-r929/GHSA-224h-m2mg-r929.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json create mode 100644 advisories/unreviewed/2024/10/GHSA-63q2-3m87-pq6j/GHSA-63q2-3m87-pq6j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-683h-34r2-xc99/GHSA-683h-34r2-xc99.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7cq8-ppvr-h6pr/GHSA-7cq8-ppvr-h6pr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7pfp-9xwm-7xfg/GHSA-7pfp-9xwm-7xfg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-82ch-xgf6-4685/GHSA-82ch-xgf6-4685.json create mode 100644 advisories/unreviewed/2024/10/GHSA-92rw-4jh9-x8q2/GHSA-92rw-4jh9-x8q2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g7f6-jj92-wc77/GHSA-g7f6-jj92-wc77.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h66h-gwq7-wjq2/GHSA-h66h-gwq7-wjq2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jj78-5fmv-mv28/GHSA-jj78-5fmv-mv28.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wrwp-h7qf-jwgj/GHSA-wrwp-h7qf-jwgj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x5qv-p3pm-x7fg/GHSA-x5qv-p3pm-x7fg.json diff --git a/advisories/unreviewed/2022/05/GHSA-882j-m7wv-38p6/GHSA-882j-m7wv-38p6.json b/advisories/unreviewed/2022/05/GHSA-882j-m7wv-38p6/GHSA-882j-m7wv-38p6.json index 62ea8e1ae98..dfb7262d45a 100644 --- a/advisories/unreviewed/2022/05/GHSA-882j-m7wv-38p6/GHSA-882j-m7wv-38p6.json +++ b/advisories/unreviewed/2022/05/GHSA-882j-m7wv-38p6/GHSA-882j-m7wv-38p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-882j-m7wv-38p6", - "modified": "2022-05-14T01:06:14Z", + "modified": "2024-10-03T21:31:02Z", "published": "2022-05-14T01:06:14Z", "aliases": [ "CVE-2018-2628" diff --git a/advisories/unreviewed/2022/12/GHSA-26j2-2wp8-h95h/GHSA-26j2-2wp8-h95h.json b/advisories/unreviewed/2022/12/GHSA-26j2-2wp8-h95h/GHSA-26j2-2wp8-h95h.json index f4e1aaddb5b..66c59ccce29 100644 --- a/advisories/unreviewed/2022/12/GHSA-26j2-2wp8-h95h/GHSA-26j2-2wp8-h95h.json +++ b/advisories/unreviewed/2022/12/GHSA-26j2-2wp8-h95h/GHSA-26j2-2wp8-h95h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26j2-2wp8-h95h", - "modified": "2023-01-05T18:30:30Z", + "modified": "2024-10-03T21:31:02Z", "published": "2022-12-26T21:30:24Z", "aliases": [ "CVE-2020-12069" diff --git a/advisories/unreviewed/2023/04/GHSA-6653-c3g4-g7jm/GHSA-6653-c3g4-g7jm.json b/advisories/unreviewed/2023/04/GHSA-6653-c3g4-g7jm/GHSA-6653-c3g4-g7jm.json index 1544ccb9fe9..941f0c1db1f 100644 --- a/advisories/unreviewed/2023/04/GHSA-6653-c3g4-g7jm/GHSA-6653-c3g4-g7jm.json +++ b/advisories/unreviewed/2023/04/GHSA-6653-c3g4-g7jm/GHSA-6653-c3g4-g7jm.json @@ -64,6 +64,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-3cvg-j39v-pqwx/GHSA-3cvg-j39v-pqwx.json b/advisories/unreviewed/2023/08/GHSA-3cvg-j39v-pqwx/GHSA-3cvg-j39v-pqwx.json index c9d69eafe7c..029bc232cf6 100644 --- a/advisories/unreviewed/2023/08/GHSA-3cvg-j39v-pqwx/GHSA-3cvg-j39v-pqwx.json +++ b/advisories/unreviewed/2023/08/GHSA-3cvg-j39v-pqwx/GHSA-3cvg-j39v-pqwx.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-4ghh-vv6c-6p5m/GHSA-4ghh-vv6c-6p5m.json b/advisories/unreviewed/2023/08/GHSA-4ghh-vv6c-6p5m/GHSA-4ghh-vv6c-6p5m.json index b1002a9d850..e96ca8238fa 100644 --- a/advisories/unreviewed/2023/08/GHSA-4ghh-vv6c-6p5m/GHSA-4ghh-vv6c-6p5m.json +++ b/advisories/unreviewed/2023/08/GHSA-4ghh-vv6c-6p5m/GHSA-4ghh-vv6c-6p5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4ghh-vv6c-6p5m", - "modified": "2024-04-04T07:08:43Z", + "modified": "2024-10-03T21:31:03Z", "published": "2023-08-22T21:30:27Z", "aliases": [ "CVE-2023-37421" diff --git a/advisories/unreviewed/2023/08/GHSA-cg26-wmrp-ggr4/GHSA-cg26-wmrp-ggr4.json b/advisories/unreviewed/2023/08/GHSA-cg26-wmrp-ggr4/GHSA-cg26-wmrp-ggr4.json index a89206c73a0..22977f71d09 100644 --- a/advisories/unreviewed/2023/08/GHSA-cg26-wmrp-ggr4/GHSA-cg26-wmrp-ggr4.json +++ b/advisories/unreviewed/2023/08/GHSA-cg26-wmrp-ggr4/GHSA-cg26-wmrp-ggr4.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-cmv9-rhxg-f4xc/GHSA-cmv9-rhxg-f4xc.json b/advisories/unreviewed/2023/08/GHSA-cmv9-rhxg-f4xc/GHSA-cmv9-rhxg-f4xc.json index f5993213f09..072a683ea5e 100644 --- a/advisories/unreviewed/2023/08/GHSA-cmv9-rhxg-f4xc/GHSA-cmv9-rhxg-f4xc.json +++ b/advisories/unreviewed/2023/08/GHSA-cmv9-rhxg-f4xc/GHSA-cmv9-rhxg-f4xc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-84hr-648m-6p8v/GHSA-84hr-648m-6p8v.json b/advisories/unreviewed/2024/02/GHSA-84hr-648m-6p8v/GHSA-84hr-648m-6p8v.json index 50347364eaf..15568ee9f80 100644 --- a/advisories/unreviewed/2024/02/GHSA-84hr-648m-6p8v/GHSA-84hr-648m-6p8v.json +++ b/advisories/unreviewed/2024/02/GHSA-84hr-648m-6p8v/GHSA-84hr-648m-6p8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84hr-648m-6p8v", - "modified": "2024-02-13T03:30:20Z", + "modified": "2024-10-03T21:31:03Z", "published": "2024-02-13T03:30:20Z", "aliases": [ "CVE-2023-52060" ], "details": "A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T01:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-83cc-qgcr-qjcw/GHSA-83cc-qgcr-qjcw.json b/advisories/unreviewed/2024/06/GHSA-83cc-qgcr-qjcw/GHSA-83cc-qgcr-qjcw.json index 43fd45c5085..b1f5a2c5497 100644 --- a/advisories/unreviewed/2024/06/GHSA-83cc-qgcr-qjcw/GHSA-83cc-qgcr-qjcw.json +++ b/advisories/unreviewed/2024/06/GHSA-83cc-qgcr-qjcw/GHSA-83cc-qgcr-qjcw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-g5fx-mv2q-2jpr/GHSA-g5fx-mv2q-2jpr.json b/advisories/unreviewed/2024/06/GHSA-g5fx-mv2q-2jpr/GHSA-g5fx-mv2q-2jpr.json index e89adf30b70..c7d3261406d 100644 --- a/advisories/unreviewed/2024/06/GHSA-g5fx-mv2q-2jpr/GHSA-g5fx-mv2q-2jpr.json +++ b/advisories/unreviewed/2024/06/GHSA-g5fx-mv2q-2jpr/GHSA-g5fx-mv2q-2jpr.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-g5fx-mv2q-2jpr", - "modified": "2024-06-12T21:31:19Z", + "modified": "2024-10-03T21:31:03Z", "published": "2024-06-12T21:31:19Z", "aliases": [ "CVE-2024-3467" ], "details": "There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-12T21:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-jm3x-qp4q-p8jr/GHSA-jm3x-qp4q-p8jr.json b/advisories/unreviewed/2024/06/GHSA-jm3x-qp4q-p8jr/GHSA-jm3x-qp4q-p8jr.json index f32817f0d15..60a5bca0dac 100644 --- a/advisories/unreviewed/2024/06/GHSA-jm3x-qp4q-p8jr/GHSA-jm3x-qp4q-p8jr.json +++ b/advisories/unreviewed/2024/06/GHSA-jm3x-qp4q-p8jr/GHSA-jm3x-qp4q-p8jr.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-jm3x-qp4q-p8jr", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-10-03T21:31:03Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-38280" ], "details": "An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -25,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-313" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T17:15:51Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pvxg-5348-rxvf/GHSA-pvxg-5348-rxvf.json b/advisories/unreviewed/2024/07/GHSA-pvxg-5348-rxvf/GHSA-pvxg-5348-rxvf.json index 06f3ab1c042..ad31cb90069 100644 --- a/advisories/unreviewed/2024/07/GHSA-pvxg-5348-rxvf/GHSA-pvxg-5348-rxvf.json +++ b/advisories/unreviewed/2024/07/GHSA-pvxg-5348-rxvf/GHSA-pvxg-5348-rxvf.json @@ -37,6 +37,7 @@ "database_specific": { "cwe_ids": [ "CWE-1004", + "CWE-732", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json b/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json index db55a5ee629..91e7bbd1982 100644 --- a/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json +++ b/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-670", "CWE-783" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json b/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json index f8fc3ab1c5c..0a2bfcedbea 100644 --- a/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json +++ b/advisories/unreviewed/2024/09/GHSA-mhxx-5693-798f/GHSA-mhxx-5693-798f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhxx-5693-798f", - "modified": "2024-09-27T18:32:27Z", + "modified": "2024-10-03T21:31:04Z", "published": "2024-09-27T18:32:27Z", "aliases": [ "CVE-2024-46256" ], "details": "A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-224h-m2mg-r929/GHSA-224h-m2mg-r929.json b/advisories/unreviewed/2024/10/GHSA-224h-m2mg-r929/GHSA-224h-m2mg-r929.json new file mode 100644 index 00000000000..fdb118d0ba9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-224h-m2mg-r929/GHSA-224h-m2mg-r929.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-224h-m2mg-r929", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41591" + ], + "details": "DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41591" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json b/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json index ddda3a2f514..ab00f573397 100644 --- a/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json +++ b/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46m2-r42j-gr4p", - "modified": "2024-10-03T18:30:36Z", + "modified": "2024-10-03T21:31:04Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2024-45870" ], "details": "Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T16:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json b/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json new file mode 100644 index 00000000000..7784f684eed --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qpr-f47p-f6ch", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41588" + ], + "details": "The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41588" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-63q2-3m87-pq6j/GHSA-63q2-3m87-pq6j.json b/advisories/unreviewed/2024/10/GHSA-63q2-3m87-pq6j/GHSA-63q2-3m87-pq6j.json new file mode 100644 index 00000000000..8e021beb4d1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-63q2-3m87-pq6j/GHSA-63q2-3m87-pq6j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63q2-3m87-pq6j", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41592" + ], + "details": "DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41592" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-683h-34r2-xc99/GHSA-683h-34r2-xc99.json b/advisories/unreviewed/2024/10/GHSA-683h-34r2-xc99/GHSA-683h-34r2-xc99.json new file mode 100644 index 00000000000..cc2da2d1692 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-683h-34r2-xc99/GHSA-683h-34r2-xc99.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-683h-34r2-xc99", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41589" + ], + "details": "DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41589" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-72cp-q9j9-fhvh/GHSA-72cp-q9j9-fhvh.json b/advisories/unreviewed/2024/10/GHSA-72cp-q9j9-fhvh/GHSA-72cp-q9j9-fhvh.json index 6579f5f0ab2..d3ccd7f8605 100644 --- a/advisories/unreviewed/2024/10/GHSA-72cp-q9j9-fhvh/GHSA-72cp-q9j9-fhvh.json +++ b/advisories/unreviewed/2024/10/GHSA-72cp-q9j9-fhvh/GHSA-72cp-q9j9-fhvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72cp-q9j9-fhvh", - "modified": "2024-10-02T15:30:38Z", + "modified": "2024-10-03T21:31:04Z", "published": "2024-10-02T15:30:38Z", "aliases": [ "CVE-2024-44193" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-02T15:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7cq8-ppvr-h6pr/GHSA-7cq8-ppvr-h6pr.json b/advisories/unreviewed/2024/10/GHSA-7cq8-ppvr-h6pr/GHSA-7cq8-ppvr-h6pr.json new file mode 100644 index 00000000000..7f178303db0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7cq8-ppvr-h6pr/GHSA-7cq8-ppvr-h6pr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cq8-ppvr-h6pr", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41587" + ], + "details": "Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41587" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7pfp-9xwm-7xfg/GHSA-7pfp-9xwm-7xfg.json b/advisories/unreviewed/2024/10/GHSA-7pfp-9xwm-7xfg/GHSA-7pfp-9xwm-7xfg.json new file mode 100644 index 00000000000..31f65356ef2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7pfp-9xwm-7xfg/GHSA-7pfp-9xwm-7xfg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pfp-9xwm-7xfg", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41595" + ], + "details": "DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41595" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-82ch-xgf6-4685/GHSA-82ch-xgf6-4685.json b/advisories/unreviewed/2024/10/GHSA-82ch-xgf6-4685/GHSA-82ch-xgf6-4685.json new file mode 100644 index 00000000000..f8b90c7d1a5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-82ch-xgf6-4685/GHSA-82ch-xgf6-4685.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82ch-xgf6-4685", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41593" + ], + "details": "DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41593" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json b/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json index 3758467ffe2..829a4587402 100644 --- a/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json +++ b/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mx7-3ccx-q5cq", - "modified": "2024-10-03T18:30:36Z", + "modified": "2024-10-03T21:31:04Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2024-45871" ], "details": "Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T17:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-92rw-4jh9-x8q2/GHSA-92rw-4jh9-x8q2.json b/advisories/unreviewed/2024/10/GHSA-92rw-4jh9-x8q2/GHSA-92rw-4jh9-x8q2.json new file mode 100644 index 00000000000..00b471ae748 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-92rw-4jh9-x8q2/GHSA-92rw-4jh9-x8q2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92rw-4jh9-x8q2", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41586" + ], + "details": "A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41586" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g7f6-jj92-wc77/GHSA-g7f6-jj92-wc77.json b/advisories/unreviewed/2024/10/GHSA-g7f6-jj92-wc77/GHSA-g7f6-jj92-wc77.json new file mode 100644 index 00000000000..f9a36f0f331 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g7f6-jj92-wc77/GHSA-g7f6-jj92-wc77.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7f6-jj92-wc77", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41594" + ], + "details": "An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41594" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json b/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json new file mode 100644 index 00000000000..2da406c17a8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx28-329m-22gw", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41590" + ], + "details": "Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41590" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h66h-gwq7-wjq2/GHSA-h66h-gwq7-wjq2.json b/advisories/unreviewed/2024/10/GHSA-h66h-gwq7-wjq2/GHSA-h66h-gwq7-wjq2.json new file mode 100644 index 00000000000..24d155dd3e4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h66h-gwq7-wjq2/GHSA-h66h-gwq7-wjq2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h66h-gwq7-wjq2", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41584" + ], + "details": "DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41584" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json b/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json new file mode 100644 index 00000000000..fa67cf388f9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhrj-jf6x-vjjx", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41585" + ], + "details": "DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41585" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jj78-5fmv-mv28/GHSA-jj78-5fmv-mv28.json b/advisories/unreviewed/2024/10/GHSA-jj78-5fmv-mv28/GHSA-jj78-5fmv-mv28.json new file mode 100644 index 00000000000..ce4565c3149 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jj78-5fmv-mv28/GHSA-jj78-5fmv-mv28.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj78-5fmv-mv28", + "modified": "2024-10-03T21:31:05Z", + "published": "2024-10-03T21:31:05Z", + "aliases": [ + "CVE-2024-9266" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9266" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-9266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json b/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json index 12e04f7d89e..0ca4c317b04 100644 --- a/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json +++ b/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p4hq-9rw5-2cwc", - "modified": "2024-10-03T18:30:36Z", + "modified": "2024-10-03T21:31:04Z", "published": "2024-10-03T18:30:36Z", "aliases": [ "CVE-2024-45872" ], "details": "Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T17:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json b/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json new file mode 100644 index 00000000000..57cafbc31fc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxgf-2m78-27m8", + "modified": "2024-10-03T21:31:05Z", + "published": "2024-10-03T21:31:05Z", + "aliases": [ + "CVE-2024-46658" + ], + "details": "Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46658" + }, + { + "type": "WEB", + "url": "https://github.com/jackalkarlos/CVE-2024-46658/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wrwp-h7qf-jwgj/GHSA-wrwp-h7qf-jwgj.json b/advisories/unreviewed/2024/10/GHSA-wrwp-h7qf-jwgj/GHSA-wrwp-h7qf-jwgj.json new file mode 100644 index 00000000000..041c42a3f18 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wrwp-h7qf-jwgj/GHSA-wrwp-h7qf-jwgj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrwp-h7qf-jwgj", + "modified": "2024-10-03T21:31:05Z", + "published": "2024-10-03T21:31:05Z", + "aliases": [ + "CVE-2024-41596" + ], + "details": "Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41596" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x5qv-p3pm-x7fg/GHSA-x5qv-p3pm-x7fg.json b/advisories/unreviewed/2024/10/GHSA-x5qv-p3pm-x7fg/GHSA-x5qv-p3pm-x7fg.json new file mode 100644 index 00000000000..b96e781bd85 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x5qv-p3pm-x7fg/GHSA-x5qv-p3pm-x7fg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5qv-p3pm-x7fg", + "modified": "2024-10-03T21:31:04Z", + "published": "2024-10-03T21:31:04Z", + "aliases": [ + "CVE-2024-41583" + ], + "details": "DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41583" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draybreak-draytek-research" + }, + { + "type": "WEB", + "url": "https://www.forescout.com/resources/draytek14-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T19:15:04Z" + } +} \ No newline at end of file