diff --git a/advisories/unreviewed/2021/11/GHSA-jpw2-cwxg-4qv8/GHSA-jpw2-cwxg-4qv8.json b/advisories/unreviewed/2021/11/GHSA-jpw2-cwxg-4qv8/GHSA-jpw2-cwxg-4qv8.json index 7406425006b..5ea42463dc8 100644 --- a/advisories/unreviewed/2021/11/GHSA-jpw2-cwxg-4qv8/GHSA-jpw2-cwxg-4qv8.json +++ b/advisories/unreviewed/2021/11/GHSA-jpw2-cwxg-4qv8/GHSA-jpw2-cwxg-4qv8.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/acassen/keepalived/commit/7977fec0be89ae6fe87405b3f8da2f0b5e415e3d" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00012.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5226RYNMNB7FL4MSJDIBBGPUWH6LMRYV/" diff --git a/advisories/unreviewed/2022/02/GHSA-p58g-823f-vq5p/GHSA-p58g-823f-vq5p.json b/advisories/unreviewed/2022/02/GHSA-p58g-823f-vq5p/GHSA-p58g-823f-vq5p.json index 80756cf3b56..734228dd859 100644 --- a/advisories/unreviewed/2022/02/GHSA-p58g-823f-vq5p/GHSA-p58g-823f-vq5p.json +++ b/advisories/unreviewed/2022/02/GHSA-p58g-823f-vq5p/GHSA-p58g-823f-vq5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p58g-823f-vq5p", - "modified": "2022-02-18T00:00:55Z", + "modified": "2023-04-10T21:30:21Z", "published": "2022-02-11T00:00:45Z", "aliases": [ "CVE-2022-0020" ], "details": "A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -21,6 +24,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2022-0020" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171782/Palo-Alto-Cortex-XSOAR-6.5.0-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-mfx7-787g-3rp3/GHSA-mfx7-787g-3rp3.json b/advisories/unreviewed/2022/05/GHSA-mfx7-787g-3rp3/GHSA-mfx7-787g-3rp3.json index bdcc8f04447..b6cc3274e5a 100644 --- a/advisories/unreviewed/2022/05/GHSA-mfx7-787g-3rp3/GHSA-mfx7-787g-3rp3.json +++ b/advisories/unreviewed/2022/05/GHSA-mfx7-787g-3rp3/GHSA-mfx7-787g-3rp3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfx7-787g-3rp3", - "modified": "2022-05-24T17:37:39Z", + "modified": "2023-04-10T21:30:22Z", "published": "2022-05-24T17:37:39Z", "aliases": [ "CVE-2020-35391" ], "details": "Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -21,11 +24,16 @@ { "type": "WEB", "url": "https://medium.com/@signalhilltech/tenda-n300-authentication-bypass-via-malformed-http-request-header-5b8744ca685e" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171773/Tenda-N300-F3-12.01.01.48-Header-Processing.html" } ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-425" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json b/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json index 37f26adeb99..b1e401d90d5 100644 --- a/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json +++ b/advisories/unreviewed/2022/12/GHSA-3m6m-9xmh-j828/GHSA-3m6m-9xmh-j828.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21117" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171781/Symantec-Messaging-Gateway-10.7.4-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/02/GHSA-3w56-qhmc-wqwr/GHSA-3w56-qhmc-wqwr.json b/advisories/unreviewed/2023/02/GHSA-3w56-qhmc-wqwr/GHSA-3w56-qhmc-wqwr.json index 060c7910876..0390f8a549a 100644 --- a/advisories/unreviewed/2023/02/GHSA-3w56-qhmc-wqwr/GHSA-3w56-qhmc-wqwr.json +++ b/advisories/unreviewed/2023/02/GHSA-3w56-qhmc-wqwr/GHSA-3w56-qhmc-wqwr.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/6952319" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171772/IBM-Aspera-Faspex-4.4.1-YAML-Deserialization.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/02/GHSA-5v93-vgwv-qch2/GHSA-5v93-vgwv-qch2.json b/advisories/unreviewed/2023/02/GHSA-5v93-vgwv-qch2/GHSA-5v93-vgwv-qch2.json index 5f686802aa5..d6a36a1c382 100644 --- a/advisories/unreviewed/2023/02/GHSA-5v93-vgwv-qch2/GHSA-5v93-vgwv-qch2.json +++ b/advisories/unreviewed/2023/02/GHSA-5v93-vgwv-qch2/GHSA-5v93-vgwv-qch2.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29273" }, + { + "type": "WEB", + "url": "https://docs.netgate.com/downloads/pfSense-SA-22_05.webgui.asc" + }, { "type": "WEB", "url": "https://docs.netgate.com/pfsense/en/latest/releases/index.html#current-and-upcoming-supported-releases" diff --git a/advisories/unreviewed/2023/02/GHSA-f9jv-w5v2-f33c/GHSA-f9jv-w5v2-f33c.json b/advisories/unreviewed/2023/02/GHSA-f9jv-w5v2-f33c/GHSA-f9jv-w5v2-f33c.json index 7527c1f272e..c6236ccda83 100644 --- a/advisories/unreviewed/2023/02/GHSA-f9jv-w5v2-f33c/GHSA-f9jv-w5v2-f33c.json +++ b/advisories/unreviewed/2023/02/GHSA-f9jv-w5v2-f33c/GHSA-f9jv-w5v2-f33c.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/patrickhener/CVE-2023-22855/blob/main/advisory/advisory.md" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/51239" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/171046/Kardex-Mlog-MCC-5.7.12-0-a203c2a213-master-File-Inclusion-Remote-Code-Execution.html" diff --git a/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json b/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json index e5f554425a2..cb62c29b7d8 100644 --- a/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json +++ b/advisories/unreviewed/2023/03/GHSA-4gvm-5c8j-gw57/GHSA-4gvm-5c8j-gw57.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://github.com/bigzooooz/CVE-2023-26692#readme" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171787/ZCBS-ZBBS-ZPBS-4.14k-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-4wcm-rwhh-gjfc/GHSA-4wcm-rwhh-gjfc.json b/advisories/unreviewed/2023/03/GHSA-4wcm-rwhh-gjfc/GHSA-4wcm-rwhh-gjfc.json index 58e471905be..c951e8cbe43 100644 --- a/advisories/unreviewed/2023/03/GHSA-4wcm-rwhh-gjfc/GHSA-4wcm-rwhh-gjfc.json +++ b/advisories/unreviewed/2023/03/GHSA-4wcm-rwhh-gjfc/GHSA-4wcm-rwhh-gjfc.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23399" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171767/Microsoft-Excel-365-MSO-2302-Build-16.0.16130.20186-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-77pg-3832-hjf8/GHSA-77pg-3832-hjf8.json b/advisories/unreviewed/2023/03/GHSA-77pg-3832-hjf8/GHSA-77pg-3832-hjf8.json index a447f37975f..caa50f093d2 100644 --- a/advisories/unreviewed/2023/03/GHSA-77pg-3832-hjf8/GHSA-77pg-3832-hjf8.json +++ b/advisories/unreviewed/2023/03/GHSA-77pg-3832-hjf8/GHSA-77pg-3832-hjf8.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/ahmedalroky/Disclosures/blob/main/apesystems/os_command_injection.md" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171775/Altenergy-Power-Control-Software-C1.2.5-Command-Injection.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-8fgr-w2w7-3965/GHSA-8fgr-w2w7-3965.json b/advisories/unreviewed/2023/03/GHSA-8fgr-w2w7-3965/GHSA-8fgr-w2w7-3965.json index d1def06c8cb..57bd077d3d5 100644 --- a/advisories/unreviewed/2023/03/GHSA-8fgr-w2w7-3965/GHSA-8fgr-w2w7-3965.json +++ b/advisories/unreviewed/2023/03/GHSA-8fgr-w2w7-3965/GHSA-8fgr-w2w7-3965.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/sunktitanic/Injection-vulnerability-in-Paradox-Security-Systems-IPR512" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171783/Paradox-Security-Systems-IPR512-Denial-Of-Service.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-g98m-73rh-c5j6/GHSA-g98m-73rh-c5j6.json b/advisories/unreviewed/2023/03/GHSA-g98m-73rh-c5j6/GHSA-g98m-73rh-c5j6.json index 72523201ef1..46a0ed3ff9b 100644 --- a/advisories/unreviewed/2023/03/GHSA-g98m-73rh-c5j6/GHSA-g98m-73rh-c5j6.json +++ b/advisories/unreviewed/2023/03/GHSA-g98m-73rh-c5j6/GHSA-g98m-73rh-c5j6.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.ibm.com/support/pages/node/6959969" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171770/IBM-Instana-243-0-Missing-Authentication.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-j2jf-89hq-7g58/GHSA-j2jf-89hq-7g58.json b/advisories/unreviewed/2023/03/GHSA-j2jf-89hq-7g58/GHSA-j2jf-89hq-7g58.json index 63a053ea1a4..4d8c5724eda 100644 --- a/advisories/unreviewed/2023/03/GHSA-j2jf-89hq-7g58/GHSA-j2jf-89hq-7g58.json +++ b/advisories/unreviewed/2023/03/GHSA-j2jf-89hq-7g58/GHSA-j2jf-89hq-7g58.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://crbug.com/1417185" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171796/Chrome-base-SampleVectorBase-MoveSingleSampleToCounts-Heap-Buffer-Overflow.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-j4xg-w995-95xh/GHSA-j4xg-w995-95xh.json b/advisories/unreviewed/2023/03/GHSA-j4xg-w995-95xh/GHSA-j4xg-w995-95xh.json index 77fd7fb6ccf..02209fed81e 100644 --- a/advisories/unreviewed/2023/03/GHSA-j4xg-w995-95xh/GHSA-j4xg-w995-95xh.json +++ b/advisories/unreviewed/2023/03/GHSA-j4xg-w995-95xh/GHSA-j4xg-w995-95xh.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://fortiguard.com/psirt/FG-IR-22-388" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171766/FortiRecorder-6.4.3-Denial-Of-Service.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-v88r-4mgh-ph8r/GHSA-v88r-4mgh-ph8r.json b/advisories/unreviewed/2023/03/GHSA-v88r-4mgh-ph8r/GHSA-v88r-4mgh-ph8r.json index 696bde603e2..66e0fe34ad9 100644 --- a/advisories/unreviewed/2023/03/GHSA-v88r-4mgh-ph8r/GHSA-v88r-4mgh-ph8r.json +++ b/advisories/unreviewed/2023/03/GHSA-v88r-4mgh-ph8r/GHSA-v88r-4mgh-ph8r.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23420" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171794/Windows-Kernel-Registry-Key-Issue.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json b/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json index c7469bd62a8..a04db03f1bf 100644 --- a/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json +++ b/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://redmine.pfsense.org/issues/13574" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171791/pfsenseCE-2.6.0-Protection-Bypass.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/03/GHSA-x29m-q7qj-f3cp/GHSA-x29m-q7qj-f3cp.json b/advisories/unreviewed/2023/03/GHSA-x29m-q7qj-f3cp/GHSA-x29m-q7qj-f3cp.json index f8a28ebb8ca..b9cca3ef020 100644 --- a/advisories/unreviewed/2023/03/GHSA-x29m-q7qj-f3cp/GHSA-x29m-q7qj-f3cp.json +++ b/advisories/unreviewed/2023/03/GHSA-x29m-q7qj-f3cp/GHSA-x29m-q7qj-f3cp.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://crbug.com/1415328" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171795/Chrome-base-debug-ActivityUserData-ActivityUserData-Heap-Buffer-Overflow.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-2chr-h4px-85v9/GHSA-2chr-h4px-85v9.json b/advisories/unreviewed/2023/04/GHSA-2chr-h4px-85v9/GHSA-2chr-h4px-85v9.json new file mode 100644 index 00000000000..eac5f0e9fb7 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-2chr-h4px-85v9/GHSA-2chr-h4px-85v9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2chr-h4px-85v9", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2022-46703" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to read sensitive location information", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46703" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213530" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213531" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213532" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json b/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json new file mode 100644 index 00000000000..d248f7b4f2b --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-2p4x-63mg-m275/GHSA-2p4x-63mg-m275.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p4x-63mg-m275", + "modified": "2023-04-10T21:30:20Z", + "published": "2023-04-10T21:30:20Z", + "aliases": [ + "CVE-2023-27178" + ], + "details": "An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40797" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27178" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Hadi999/4bc173bfb802c229b9bb397fa906847b" + }, + { + "type": "WEB", + "url": "https://salsa.debian.org/php-team/php/-/blob/dc253886b5b2e9bc8d9e36db787abb083a667fd8/debian/php-cgi.conf#L5-6" + }, + { + "type": "WEB", + "url": "https://www.gdidees.eu/cms-1-0.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-37p5-738j-5p3x/GHSA-37p5-738j-5p3x.json b/advisories/unreviewed/2023/04/GHSA-37p5-738j-5p3x/GHSA-37p5-738j-5p3x.json new file mode 100644 index 00000000000..37581de925a --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-37p5-738j-5p3x/GHSA-37p5-738j-5p3x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37p5-738j-5p3x", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2022-46717" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46717" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213530" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-4vjm-pw8m-56h5/GHSA-4vjm-pw8m-56h5.json b/advisories/unreviewed/2023/04/GHSA-4vjm-pw8m-56h5/GHSA-4vjm-pw8m-56h5.json new file mode 100644 index 00000000000..b4311b1d0cd --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-4vjm-pw8m-56h5/GHSA-4vjm-pw8m-56h5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vjm-pw8m-56h5", + "modified": "2023-04-10T21:30:20Z", + "published": "2023-04-10T21:30:20Z", + "aliases": [ + "CVE-2023-27076" + ], + "details": "Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27076" + }, + { + "type": "WEB", + "url": "https://github.com/B2eFly/Router/blob/main/Tenda/G103/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json b/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json index b793fa8c90d..2a2da2144c3 100644 --- a/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json +++ b/advisories/unreviewed/2023/04/GHSA-4wg5-gmxh-4r2r/GHSA-4wg5-gmxh-4r2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wg5-gmxh-4r2r", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2023-26437" ], "details": "Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json b/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json index eb6c601997c..495ea6a5fb4 100644 --- a/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json +++ b/advisories/unreviewed/2023/04/GHSA-5v5x-x8hh-7ffj/GHSA-5v5x-x8hh-7ffj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5v5x-x8hh-7ffj", - "modified": "2023-04-04T15:30:28Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:28Z", "aliases": [ "CVE-2022-48435" ], "details": "In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-532" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T14:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-629m-3vhg-jm6g/GHSA-629m-3vhg-jm6g.json b/advisories/unreviewed/2023/04/GHSA-629m-3vhg-jm6g/GHSA-629m-3vhg-jm6g.json index 653105089c8..6e905507c49 100644 --- a/advisories/unreviewed/2023/04/GHSA-629m-3vhg-jm6g/GHSA-629m-3vhg-jm6g.json +++ b/advisories/unreviewed/2023/04/GHSA-629m-3vhg-jm6g/GHSA-629m-3vhg-jm6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-629m-3vhg-jm6g", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-26777" ], "details": "Cross Site Scripting vulnerability found in :ouislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-6783-6wx3-fm82/GHSA-6783-6wx3-fm82.json b/advisories/unreviewed/2023/04/GHSA-6783-6wx3-fm82/GHSA-6783-6wx3-fm82.json new file mode 100644 index 00000000000..d655f85f539 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-6783-6wx3-fm82/GHSA-6783-6wx3-fm82.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6783-6wx3-fm82", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26066" + ], + "details": "Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26066" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26066.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-6qjh-p74q-89mv/GHSA-6qjh-p74q-89mv.json b/advisories/unreviewed/2023/04/GHSA-6qjh-p74q-89mv/GHSA-6qjh-p74q-89mv.json new file mode 100644 index 00000000000..7e6e22b8d77 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-6qjh-p74q-89mv/GHSA-6qjh-p74q-89mv.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qjh-p74q-89mv", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2023-28205" + ], + "details": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.7.5 and iPadOS 15.7.5, Safari 16.4.1, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28205" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213720" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213721" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213722" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213723" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-7hpc-6gxc-8w7q/GHSA-7hpc-6gxc-8w7q.json b/advisories/unreviewed/2023/04/GHSA-7hpc-6gxc-8w7q/GHSA-7hpc-6gxc-8w7q.json new file mode 100644 index 00000000000..76f299a3ff6 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-7hpc-6gxc-8w7q/GHSA-7hpc-6gxc-8w7q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hpc-6gxc-8w7q", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26065" + ], + "details": "Certain Lexmark devices through 2023-02-19 have an Integer Overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26065" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26065.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json b/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json index 2b4d0e72d04..be801d89bf7 100644 --- a/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json +++ b/advisories/unreviewed/2023/04/GHSA-84x2-qv2c-9cvx/GHSA-84x2-qv2c-9cvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84x2-qv2c-9cvx", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-43771" ], "details": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-872w-8755-cjg5/GHSA-872w-8755-cjg5.json b/advisories/unreviewed/2023/04/GHSA-872w-8755-cjg5/GHSA-872w-8755-cjg5.json new file mode 100644 index 00000000000..f01db3cec9a --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-872w-8755-cjg5/GHSA-872w-8755-cjg5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-872w-8755-cjg5", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26063" + ], + "details": "Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26063" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26063.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-87wc-7p2c-x5h9/GHSA-87wc-7p2c-x5h9.json b/advisories/unreviewed/2023/04/GHSA-87wc-7p2c-x5h9/GHSA-87wc-7p2c-x5h9.json index 9a3e6eb98e2..ecc6f0405ad 100644 --- a/advisories/unreviewed/2023/04/GHSA-87wc-7p2c-x5h9/GHSA-87wc-7p2c-x5h9.json +++ b/advisories/unreviewed/2023/04/GHSA-87wc-7p2c-x5h9/GHSA-87wc-7p2c-x5h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87wc-7p2c-x5h9", - "modified": "2023-04-04T15:30:28Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:28Z", "aliases": [ "CVE-2020-19692" ], "details": "Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json b/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json index b42acc83852..78692f08ca6 100644 --- a/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json +++ b/advisories/unreviewed/2023/04/GHSA-8f7j-8hjh-h4v8/GHSA-8f7j-8hjh-h4v8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8f7j-8hjh-h4v8", - "modified": "2023-04-04T03:30:16Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T03:30:16Z", "aliases": [ "CVE-2023-26855" ], "details": "The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-330" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T02:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json b/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json index 13b5662e600..67fd42f501b 100644 --- a/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json +++ b/advisories/unreviewed/2023/04/GHSA-8g46-vcjj-g5qj/GHSA-8g46-vcjj-g5qj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g46-vcjj-g5qj", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-23259" ], "details": "An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json b/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json index ec2bcf3ec75..fe40513b8c8 100644 --- a/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json +++ b/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pwj-3gh6-824j", - "modified": "2023-04-04T00:30:15Z", + "modified": "2023-04-10T21:30:24Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-0614" ], "details": "The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T23:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json b/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json index f9381ae039e..477d8bf12a1 100644 --- a/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json +++ b/advisories/unreviewed/2023/04/GHSA-9m49-j2g8-82x8/GHSA-9m49-j2g8-82x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m49-j2g8-82x8", - "modified": "2023-04-04T15:30:28Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:28Z", "aliases": [ "CVE-2020-19695" ], "details": "Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-f5cj-2ghc-vgwm/GHSA-f5cj-2ghc-vgwm.json b/advisories/unreviewed/2023/04/GHSA-f5cj-2ghc-vgwm/GHSA-f5cj-2ghc-vgwm.json new file mode 100644 index 00000000000..89241cb4760 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-f5cj-2ghc-vgwm/GHSA-f5cj-2ghc-vgwm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5cj-2ghc-vgwm", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26495" + ], + "details": "An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26495" + }, + { + "type": "WEB", + "url": "https://www.opendesign.com/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-f6xp-59jq-r35c/GHSA-f6xp-59jq-r35c.json b/advisories/unreviewed/2023/04/GHSA-f6xp-59jq-r35c/GHSA-f6xp-59jq-r35c.json index 9f0646c4387..6c17dc7ff4d 100644 --- a/advisories/unreviewed/2023/04/GHSA-f6xp-59jq-r35c/GHSA-f6xp-59jq-r35c.json +++ b/advisories/unreviewed/2023/04/GHSA-f6xp-59jq-r35c/GHSA-f6xp-59jq-r35c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6xp-59jq-r35c", - "modified": "2023-04-04T15:30:28Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:28Z", "aliases": [ "CVE-2020-19278" ], "details": "Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json b/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json index 179dddc44d9..1970fe60615 100644 --- a/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json +++ b/advisories/unreviewed/2023/04/GHSA-f97q-33hc-5qr8/GHSA-f97q-33hc-5qr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f97q-33hc-5qr8", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-23258" ], "details": "An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-fgm4-rp4m-mcwr/GHSA-fgm4-rp4m-mcwr.json b/advisories/unreviewed/2023/04/GHSA-fgm4-rp4m-mcwr/GHSA-fgm4-rp4m-mcwr.json new file mode 100644 index 00000000000..c74b702f2cf --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-fgm4-rp4m-mcwr/GHSA-fgm4-rp4m-mcwr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgm4-rp4m-mcwr", + "modified": "2023-04-10T21:30:20Z", + "published": "2023-04-10T21:30:20Z", + "aliases": [ + "CVE-2023-26773" + ], + "details": "Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26773" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/171686/Sales-Tracker-Management-System-1.0-Cross-Site-Scripting.html" + }, + { + "type": "WEB", + "url": "https://twitter.com/retrymp3" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/16061/sales-tracker-management-system-using-php-free-source-code.html" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/users/tips23" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-fp72-rfxv-mxwh/GHSA-fp72-rfxv-mxwh.json b/advisories/unreviewed/2023/04/GHSA-fp72-rfxv-mxwh/GHSA-fp72-rfxv-mxwh.json new file mode 100644 index 00000000000..7673932f6c0 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-fp72-rfxv-mxwh/GHSA-fp72-rfxv-mxwh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp72-rfxv-mxwh", + "modified": "2023-04-10T21:30:20Z", + "published": "2023-04-10T21:30:20Z", + "aliases": [ + "CVE-2023-26466" + ], + "details": "A user with non-Admin access can change a configuration file on the client to modify the Server URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26466" + }, + { + "type": "WEB", + "url": "https://support.pega.com/support-doc/pega-security-advisory-b23-robotics-and-workforce-intelligence-local-privilege" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-fxjr-wp58-m6x4/GHSA-fxjr-wp58-m6x4.json b/advisories/unreviewed/2023/04/GHSA-fxjr-wp58-m6x4/GHSA-fxjr-wp58-m6x4.json index e9e086e8587..5eb51f028c4 100644 --- a/advisories/unreviewed/2023/04/GHSA-fxjr-wp58-m6x4/GHSA-fxjr-wp58-m6x4.json +++ b/advisories/unreviewed/2023/04/GHSA-fxjr-wp58-m6x4/GHSA-fxjr-wp58-m6x4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxjr-wp58-m6x4", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-26775" ], "details": "File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-g277-4m9p-49hv/GHSA-g277-4m9p-49hv.json b/advisories/unreviewed/2023/04/GHSA-g277-4m9p-49hv/GHSA-g277-4m9p-49hv.json index bb7564d70cb..aa506108b75 100644 --- a/advisories/unreviewed/2023/04/GHSA-g277-4m9p-49hv/GHSA-g277-4m9p-49hv.json +++ b/advisories/unreviewed/2023/04/GHSA-g277-4m9p-49hv/GHSA-g277-4m9p-49hv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g277-4m9p-49hv", - "modified": "2023-04-04T15:30:28Z", + "modified": "2023-04-10T21:30:24Z", "published": "2023-04-04T15:30:28Z", "aliases": [ "CVE-2020-19279" ], "details": "Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/b3log/wide/issues/355" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-g277-4m9p-49hv" } ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json b/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json index 614784c24c0..b9a3d3abf34 100644 --- a/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json +++ b/advisories/unreviewed/2023/04/GHSA-g6pr-f698-8rc4/GHSA-g6pr-f698-8rc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6pr-f698-8rc4", - "modified": "2023-04-04T15:30:28Z", + "modified": "2023-04-10T21:30:24Z", "published": "2023-04-04T15:30:28Z", "aliases": [ "CVE-2020-19693" ], "details": "An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-gcx9-562f-5mwm/GHSA-gcx9-562f-5mwm.json b/advisories/unreviewed/2023/04/GHSA-gcx9-562f-5mwm/GHSA-gcx9-562f-5mwm.json new file mode 100644 index 00000000000..4dd2004dc61 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-gcx9-562f-5mwm/GHSA-gcx9-562f-5mwm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcx9-562f-5mwm", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26069" + ], + "details": "Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26069" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26069.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-gmph-wf7j-9gcm/GHSA-gmph-wf7j-9gcm.json b/advisories/unreviewed/2023/04/GHSA-gmph-wf7j-9gcm/GHSA-gmph-wf7j-9gcm.json index a79c3db773b..5e4a9832838 100644 --- a/advisories/unreviewed/2023/04/GHSA-gmph-wf7j-9gcm/GHSA-gmph-wf7j-9gcm.json +++ b/advisories/unreviewed/2023/04/GHSA-gmph-wf7j-9gcm/GHSA-gmph-wf7j-9gcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmph-wf7j-9gcm", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2021-28235" ], "details": "Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-gpj8-f6gc-m2qq/GHSA-gpj8-f6gc-m2qq.json b/advisories/unreviewed/2023/04/GHSA-gpj8-f6gc-m2qq/GHSA-gpj8-f6gc-m2qq.json index 7c5d5ade15a..325b88ab432 100644 --- a/advisories/unreviewed/2023/04/GHSA-gpj8-f6gc-m2qq/GHSA-gpj8-f6gc-m2qq.json +++ b/advisories/unreviewed/2023/04/GHSA-gpj8-f6gc-m2qq/GHSA-gpj8-f6gc-m2qq.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.224841" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171790/Online-Computer-And-Laptop-Store-1.0-Shell-Upload.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-gq63-p39p-jrjf/GHSA-gq63-p39p-jrjf.json b/advisories/unreviewed/2023/04/GHSA-gq63-p39p-jrjf/GHSA-gq63-p39p-jrjf.json index 0a356dcb842..82029cc37bc 100644 --- a/advisories/unreviewed/2023/04/GHSA-gq63-p39p-jrjf/GHSA-gq63-p39p-jrjf.json +++ b/advisories/unreviewed/2023/04/GHSA-gq63-p39p-jrjf/GHSA-gq63-p39p-jrjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gq63-p39p-jrjf", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2023-26750" ], "details": "SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json b/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json index 8d91c4f2346..c7b3b70560c 100644 --- a/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json +++ b/advisories/unreviewed/2023/04/GHSA-h4w3-5jjx-jxhm/GHSA-h4w3-5jjx-jxhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4w3-5jjx-jxhm", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2021-3267" ], "details": "File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-hhph-6cw5-hfgq/GHSA-hhph-6cw5-hfgq.json b/advisories/unreviewed/2023/04/GHSA-hhph-6cw5-hfgq/GHSA-hhph-6cw5-hfgq.json new file mode 100644 index 00000000000..94a2e6a8a72 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-hhph-6cw5-hfgq/GHSA-hhph-6cw5-hfgq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhph-6cw5-hfgq", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26068" + ], + "details": "Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26068" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26068.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-hwgg-9h9g-m6fw/GHSA-hwgg-9h9g-m6fw.json b/advisories/unreviewed/2023/04/GHSA-hwgg-9h9g-m6fw/GHSA-hwgg-9h9g-m6fw.json index aea6ba4ba8a..0c766c68cd8 100644 --- a/advisories/unreviewed/2023/04/GHSA-hwgg-9h9g-m6fw/GHSA-hwgg-9h9g-m6fw.json +++ b/advisories/unreviewed/2023/04/GHSA-hwgg-9h9g-m6fw/GHSA-hwgg-9h9g-m6fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwgg-9h9g-m6fw", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-29312" ], "details": "An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-jh2r-r7vr-5mm2/GHSA-jh2r-r7vr-5mm2.json b/advisories/unreviewed/2023/04/GHSA-jh2r-r7vr-5mm2/GHSA-jh2r-r7vr-5mm2.json new file mode 100644 index 00000000000..6bad150ff10 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-jh2r-r7vr-5mm2/GHSA-jh2r-r7vr-5mm2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh2r-r7vr-5mm2", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2022-46716" + ], + "details": "A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2. Private Relay functionality did not match system settings", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46716" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213530" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213532" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json b/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json index 1acd9e2f838..8e5c8348dd2 100644 --- a/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json +++ b/advisories/unreviewed/2023/04/GHSA-jv2f-j4fc-4c7g/GHSA-jv2f-j4fc-4c7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jv2f-j4fc-4c7g", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-23257" ], "details": "Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json b/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json index 96a32b127b5..311fbea54ab 100644 --- a/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json +++ b/advisories/unreviewed/2023/04/GHSA-m96c-h623-g6w7/GHSA-m96c-h623-g6w7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m96c-h623-g6w7", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2021-31707" ], "details": "Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/Kitesky/KiteCMS/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224929" } ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-mrrc-m4c6-35m8/GHSA-mrrc-m4c6-35m8.json b/advisories/unreviewed/2023/04/GHSA-mrrc-m4c6-35m8/GHSA-mrrc-m4c6-35m8.json new file mode 100644 index 00000000000..d42f7c37bb8 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-mrrc-m4c6-35m8/GHSA-mrrc-m4c6-35m8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrrc-m4c6-35m8", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2022-42858" + ], + "details": "A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42858" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213532" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-pv66-8fqr-94c7/GHSA-pv66-8fqr-94c7.json b/advisories/unreviewed/2023/04/GHSA-pv66-8fqr-94c7/GHSA-pv66-8fqr-94c7.json new file mode 100644 index 00000000000..b265bdfae48 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-pv66-8fqr-94c7/GHSA-pv66-8fqr-94c7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv66-8fqr-94c7", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2022-46709" + ], + "details": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16. An app may be able to execute arbitrary code with kernel privileges", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46709" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213446" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json b/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json index 800160ade20..4587acc7974 100644 --- a/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json +++ b/advisories/unreviewed/2023/04/GHSA-q23x-8jfp-8j7q/GHSA-q23x-8jfp-8j7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q23x-8jfp-8j7q", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-22533" ], "details": "Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json b/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json index 0ed367e6875..73414abc16f 100644 --- a/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json +++ b/advisories/unreviewed/2023/04/GHSA-q552-8jxx-pwh8/GHSA-q552-8jxx-pwh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q552-8jxx-pwh8", - "modified": "2023-04-03T21:32:47Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-03T21:32:47Z", "aliases": [ "CVE-2022-3960" ], "details": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-03T19:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-qmpx-7mr8-9whr/GHSA-qmpx-7mr8-9whr.json b/advisories/unreviewed/2023/04/GHSA-qmpx-7mr8-9whr/GHSA-qmpx-7mr8-9whr.json new file mode 100644 index 00000000000..081c2bd3dcf --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-qmpx-7mr8-9whr/GHSA-qmpx-7mr8-9whr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmpx-7mr8-9whr", + "modified": "2023-04-10T21:30:20Z", + "published": "2023-04-10T21:30:20Z", + "aliases": [ + "CVE-2023-28093" + ], + "details": "A user with a compromised configuration can start an unsigned binary as a service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28093" + }, + { + "type": "WEB", + "url": "https://support.pega.com/support-doc/pega-security-advisory-b23-robotics-and-workforce-intelligence-local-privilege" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-qrr8-87qr-7r3c/GHSA-qrr8-87qr-7r3c.json b/advisories/unreviewed/2023/04/GHSA-qrr8-87qr-7r3c/GHSA-qrr8-87qr-7r3c.json new file mode 100644 index 00000000000..34475971bc3 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-qrr8-87qr-7r3c/GHSA-qrr8-87qr-7r3c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrr8-87qr-7r3c", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26070" + ], + "details": "Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26070" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26070.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json b/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json index f746b430e20..fbc03c0b7a7 100644 --- a/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json +++ b/advisories/unreviewed/2023/04/GHSA-r4fh-qhv9-8jcf/GHSA-r4fh-qhv9-8jcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4fh-qhv9-8jcf", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:23Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-23260" ], "details": "An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-v2qx-4m4h-cjmg/GHSA-v2qx-4m4h-cjmg.json b/advisories/unreviewed/2023/04/GHSA-v2qx-4m4h-cjmg/GHSA-v2qx-4m4h-cjmg.json new file mode 100644 index 00000000000..53d995327b8 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-v2qx-4m4h-cjmg/GHSA-v2qx-4m4h-cjmg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2qx-4m4h-cjmg", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26067" + ], + "details": "Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26067" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26067.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-v8j8-9873-8h3w/GHSA-v8j8-9873-8h3w.json b/advisories/unreviewed/2023/04/GHSA-v8j8-9873-8h3w/GHSA-v8j8-9873-8h3w.json new file mode 100644 index 00000000000..04f4a41ff67 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-v8j8-9873-8h3w/GHSA-v8j8-9873-8h3w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8j8-9873-8h3w", + "modified": "2023-04-10T21:30:22Z", + "published": "2023-04-10T21:30:22Z", + "aliases": [ + "CVE-2022-32871" + ], + "details": "A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with physical access to a device may be able to use Siri to access private calendar information", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32871" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213446" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-vf58-526w-4qf9/GHSA-vf58-526w-4qf9.json b/advisories/unreviewed/2023/04/GHSA-vf58-526w-4qf9/GHSA-vf58-526w-4qf9.json index 77d37459f54..85e1af52844 100644 --- a/advisories/unreviewed/2023/04/GHSA-vf58-526w-4qf9/GHSA-vf58-526w-4qf9.json +++ b/advisories/unreviewed/2023/04/GHSA-vf58-526w-4qf9/GHSA-vf58-526w-4qf9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf58-526w-4qf9", - "modified": "2023-04-04T15:30:26Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:26Z", "aliases": [ "CVE-2023-26776" ], "details": "Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the title parameter of the post_receiver-services.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-vg9g-fp3v-9gx8/GHSA-vg9g-fp3v-9gx8.json b/advisories/unreviewed/2023/04/GHSA-vg9g-fp3v-9gx8/GHSA-vg9g-fp3v-9gx8.json new file mode 100644 index 00000000000..a1b5774a51c --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-vg9g-fp3v-9gx8/GHSA-vg9g-fp3v-9gx8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg9g-fp3v-9gx8", + "modified": "2023-04-10T21:30:21Z", + "published": "2023-04-10T21:30:21Z", + "aliases": [ + "CVE-2023-26064" + ], + "details": "Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26064" + }, + { + "type": "WEB", + "url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-26064.pdf" + }, + { + "type": "WEB", + "url": "https://support.lexmark.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json b/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json index 7c8a49dc8c3..e498bb89f9a 100644 --- a/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json +++ b/advisories/unreviewed/2023/04/GHSA-w6gp-23fq-qcc4/GHSA-w6gp-23fq-qcc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w6gp-23fq-qcc4", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-23327" ], "details": "Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json b/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json index 9141bb8630b..9923dac9a2a 100644 --- a/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json +++ b/advisories/unreviewed/2023/04/GHSA-x6cc-r4w4-6rjq/GHSA-x6cc-r4w4-6rjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6cc-r4w4-6rjq", - "modified": "2023-04-04T15:30:27Z", + "modified": "2023-04-10T21:30:22Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2023-26733" ], "details": "Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrame function in tinytiffreader.c file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-04T15:15:00Z"