diff --git a/advisories/unreviewed/2024/09/GHSA-22cw-hj59-vjwv/GHSA-22cw-hj59-vjwv.json b/advisories/unreviewed/2024/09/GHSA-22cw-hj59-vjwv/GHSA-22cw-hj59-vjwv.json new file mode 100644 index 00000000000..3f114cd4e63 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-22cw-hj59-vjwv/GHSA-22cw-hj59-vjwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22cw-hj59-vjwv", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34646" + ], + "details": "Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34646" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json b/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json new file mode 100644 index 00000000000..c2d86537426 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2fh4-99wm-m59g/GHSA-2fh4-99wm-m59g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fh4-99wm-m59g", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34652" + ], + "details": "Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34652" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json b/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json new file mode 100644 index 00000000000..961f9dfd4a9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2jjj-25f5-6pvh/GHSA-2jjj-25f5-6pvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jjj-25f5-6pvh", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34660" + ], + "details": "Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34660" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3c9v-5fr8-87x5/GHSA-3c9v-5fr8-87x5.json b/advisories/unreviewed/2024/09/GHSA-3c9v-5fr8-87x5/GHSA-3c9v-5fr8-87x5.json new file mode 100644 index 00000000000..5a1d571b5d5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3c9v-5fr8-87x5/GHSA-3c9v-5fr8-87x5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c9v-5fr8-87x5", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34649" + ], + "details": "Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34649" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-46mj-66fr-v8v7/GHSA-46mj-66fr-v8v7.json b/advisories/unreviewed/2024/09/GHSA-46mj-66fr-v8v7/GHSA-46mj-66fr-v8v7.json new file mode 100644 index 00000000000..550318fd316 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-46mj-66fr-v8v7/GHSA-46mj-66fr-v8v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46mj-66fr-v8v7", + "modified": "2024-09-04T06:30:40Z", + "published": "2024-09-04T06:30:40Z", + "aliases": [ + "CVE-2024-34637" + ], + "details": "Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34637" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-46w4-96qw-3vqf/GHSA-46w4-96qw-3vqf.json b/advisories/unreviewed/2024/09/GHSA-46w4-96qw-3vqf/GHSA-46w4-96qw-3vqf.json new file mode 100644 index 00000000000..5b20e9cd3a9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-46w4-96qw-3vqf/GHSA-46w4-96qw-3vqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46w4-96qw-3vqf", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34659" + ], + "details": "Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34659" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json b/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json new file mode 100644 index 00000000000..c4d77377efb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52p3-42f9-q8gp", + "modified": "2024-09-04T06:30:42Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-8325" + ], + "details": "The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the ‘blockspare_render_social_sharing_block’ function in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8325" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3145729" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c23995c6-989e-48d2-ba60-b0bf7b750245?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json b/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json new file mode 100644 index 00000000000..8cb7f9ae51a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-58p8-2q88-9m3p/GHSA-58p8-2q88-9m3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58p8-2q88-9m3p", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34639" + ], + "details": "Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34639" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8hgh-pwh5-74qq/GHSA-8hgh-pwh5-74qq.json b/advisories/unreviewed/2024/09/GHSA-8hgh-pwh5-74qq/GHSA-8hgh-pwh5-74qq.json new file mode 100644 index 00000000000..da9f6cc53fa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8hgh-pwh5-74qq/GHSA-8hgh-pwh5-74qq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hgh-pwh5-74qq", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34656" + ], + "details": "Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34656" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json b/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json new file mode 100644 index 00000000000..3eae7aaa93f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8vqw-9f68-8m8p/GHSA-8vqw-9f68-8m8p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vqw-9f68-8m8p", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34648" + ], + "details": "Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34648" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c826-p37x-6qgw/GHSA-c826-p37x-6qgw.json b/advisories/unreviewed/2024/09/GHSA-c826-p37x-6qgw/GHSA-c826-p37x-6qgw.json new file mode 100644 index 00000000000..540be53c059 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c826-p37x-6qgw/GHSA-c826-p37x-6qgw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c826-p37x-6qgw", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34640" + ], + "details": "Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34640" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json b/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json new file mode 100644 index 00000000000..3254089ffc7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5v6-6qcg-mrg8", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-6889" + ], + "details": "The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6889" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9651abd1-0f66-418e-85a7-2de0c5e91bed" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json b/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json new file mode 100644 index 00000000000..8a18a29183d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gggp-8r87-v88f/GHSA-gggp-8r87-v88f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gggp-8r87-v88f", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34657" + ], + "details": "Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34657" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json b/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json new file mode 100644 index 00000000000..1989514aa27 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-grr4-6qxm-23qc/GHSA-grr4-6qxm-23qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grr4-6qxm-23qc", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34650" + ], + "details": "Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34650" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h229-6mp7-pxrm/GHSA-h229-6mp7-pxrm.json b/advisories/unreviewed/2024/09/GHSA-h229-6mp7-pxrm/GHSA-h229-6mp7-pxrm.json new file mode 100644 index 00000000000..a77d1828b7a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h229-6mp7-pxrm/GHSA-h229-6mp7-pxrm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h229-6mp7-pxrm", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34643" + ], + "details": "Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34643" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json b/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json new file mode 100644 index 00000000000..4019a0ff44b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hmgr-rm4x-vvjh/GHSA-hmgr-rm4x-vvjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmgr-rm4x-vvjh", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34642" + ], + "details": "Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34642" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json b/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json new file mode 100644 index 00000000000..222e65ba59a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j44j-crfp-mcpr/GHSA-j44j-crfp-mcpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j44j-crfp-mcpr", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34651" + ], + "details": "Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34651" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j9jq-pgcg-7c7v/GHSA-j9jq-pgcg-7c7v.json b/advisories/unreviewed/2024/09/GHSA-j9jq-pgcg-7c7v/GHSA-j9jq-pgcg-7c7v.json new file mode 100644 index 00000000000..d79aa34a2b7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j9jq-pgcg-7c7v/GHSA-j9jq-pgcg-7c7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9jq-pgcg-7c7v", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34655" + ], + "details": "Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34655" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jcc4-pc56-fg47/GHSA-jcc4-pc56-fg47.json b/advisories/unreviewed/2024/09/GHSA-jcc4-pc56-fg47/GHSA-jcc4-pc56-fg47.json new file mode 100644 index 00000000000..2be1ea0479a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jcc4-pc56-fg47/GHSA-jcc4-pc56-fg47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcc4-pc56-fg47", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34641" + ], + "details": "Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34641" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json b/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json new file mode 100644 index 00000000000..46230c2a27c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwxp-gwr3-g9q3", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-7786" + ], + "details": "The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7786" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f44e6f8f-3ef2-45c9-ae9c-9403305a548a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json b/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json new file mode 100644 index 00000000000..e62c6929716 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m553-jg82-m2p2/GHSA-m553-jg82-m2p2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m553-jg82-m2p2", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34658" + ], + "details": "Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34658" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json b/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json new file mode 100644 index 00000000000..7dc2f80a162 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p6rh-3qqf-r3cq/GHSA-p6rh-3qqf-r3cq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rh-3qqf-r3cq", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34661" + ], + "details": "Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34661" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json b/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json new file mode 100644 index 00000000000..374957df4d7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3xw-vphm-88j4", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-6888" + ], + "details": "The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6888" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f4df74c2-4c95-4d1c-97c1-ebfc225f6b93" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q5c8-fvh9-grjr/GHSA-q5c8-fvh9-grjr.json b/advisories/unreviewed/2024/09/GHSA-q5c8-fvh9-grjr/GHSA-q5c8-fvh9-grjr.json new file mode 100644 index 00000000000..7586fd4f4fc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q5c8-fvh9-grjr/GHSA-q5c8-fvh9-grjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5c8-fvh9-grjr", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34654" + ], + "details": "Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34654" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rr3v-hgx9-cq3r/GHSA-rr3v-hgx9-cq3r.json b/advisories/unreviewed/2024/09/GHSA-rr3v-hgx9-cq3r/GHSA-rr3v-hgx9-cq3r.json new file mode 100644 index 00000000000..4bd1cb5bdb2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rr3v-hgx9-cq3r/GHSA-rr3v-hgx9-cq3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr3v-hgx9-cq3r", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34645" + ], + "details": "Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34645" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json b/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json new file mode 100644 index 00000000000..f6fcfab00d7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjjf-x2fh-7rqj", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-6926" + ], + "details": "The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6926" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9ce96ce5-fcf0-4d7a-b562-f63ea3418d93" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vxrr-25rh-4mqw/GHSA-vxrr-25rh-4mqw.json b/advisories/unreviewed/2024/09/GHSA-vxrr-25rh-4mqw/GHSA-vxrr-25rh-4mqw.json new file mode 100644 index 00000000000..a0cb1a0cadb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vxrr-25rh-4mqw/GHSA-vxrr-25rh-4mqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxrr-25rh-4mqw", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34644" + ], + "details": "Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34644" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json b/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json new file mode 100644 index 00000000000..4bc0c1dfce5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wj9f-3j22-wx34/GHSA-wj9f-3j22-wx34.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj9f-3j22-wx34", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34653" + ], + "details": "Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34653" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json b/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json new file mode 100644 index 00000000000..6cbb4a48999 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ww4q-5m6p-gm46/GHSA-ww4q-5m6p-gm46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww4q-5m6p-gm46", + "modified": "2024-09-04T06:30:40Z", + "published": "2024-09-04T06:30:40Z", + "aliases": [ + "CVE-2024-34638" + ], + "details": "Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34638" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json b/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json new file mode 100644 index 00000000000..c1cfb0b4122 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwjw-jqq2-7xjv", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-6020" + ], + "details": "The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6020" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f3526320-3abd-4ddb-8f73-778741bd9c48" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json b/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json new file mode 100644 index 00000000000..a283068a4e6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3f6-2323-r899", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-6722" + ], + "details": "The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6722" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ce909d3c-2ef2-4167-87c4-75b5effb2a4d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xq75-f8hh-4vh3/GHSA-xq75-f8hh-4vh3.json b/advisories/unreviewed/2024/09/GHSA-xq75-f8hh-4vh3/GHSA-xq75-f8hh-4vh3.json new file mode 100644 index 00000000000..a1f822e3d58 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xq75-f8hh-4vh3/GHSA-xq75-f8hh-4vh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq75-f8hh-4vh3", + "modified": "2024-09-04T06:30:41Z", + "published": "2024-09-04T06:30:41Z", + "aliases": [ + "CVE-2024-34647" + ], + "details": "Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34647" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2024&month=09" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T06:15:13Z" + } +} \ No newline at end of file