diff --git a/advisories/unreviewed/2023/12/GHSA-g5qg-mm6j-8cm3/GHSA-g5qg-mm6j-8cm3.json b/advisories/unreviewed/2023/12/GHSA-g5qg-mm6j-8cm3/GHSA-g5qg-mm6j-8cm3.json index fd9c7701732..6ddba34bf88 100644 --- a/advisories/unreviewed/2023/12/GHSA-g5qg-mm6j-8cm3/GHSA-g5qg-mm6j-8cm3.json +++ b/advisories/unreviewed/2023/12/GHSA-g5qg-mm6j-8cm3/GHSA-g5qg-mm6j-8cm3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qg-mm6j-8cm3", - "modified": "2023-12-14T15:30:22Z", + "modified": "2024-02-15T12:30:50Z", "published": "2023-12-14T15:30:22Z", "aliases": [ "CVE-2023-6545" @@ -23,7 +23,7 @@ }, { "type": "WEB", - "url": "https://cert.vde.com/en/advisories/VDE-2023-067/" + "url": "https://cert.vde.com/en/advisories/VDE-2023-067" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-354c-44cw-pr4g/GHSA-354c-44cw-pr4g.json b/advisories/unreviewed/2024/02/GHSA-354c-44cw-pr4g/GHSA-354c-44cw-pr4g.json new file mode 100644 index 00000000000..2101323a9d1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-354c-44cw-pr4g/GHSA-354c-44cw-pr4g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-354c-44cw-pr4g", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-20740" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20740" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3fvm-ppjr-8489/GHSA-3fvm-ppjr-8489.json b/advisories/unreviewed/2024/02/GHSA-3fvm-ppjr-8489/GHSA-3fvm-ppjr-8489.json new file mode 100644 index 00000000000..9b1c0a73f2f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3fvm-ppjr-8489/GHSA-3fvm-ppjr-8489.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fvm-ppjr-8489", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-20725" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20725" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-454p-pvqj-9jv5/GHSA-454p-pvqj-9jv5.json b/advisories/unreviewed/2024/02/GHSA-454p-pvqj-9jv5/GHSA-454p-pvqj-9jv5.json new file mode 100644 index 00000000000..cfedd96bd1c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-454p-pvqj-9jv5/GHSA-454p-pvqj-9jv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-454p-pvqj-9jv5", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-20741" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20741" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-123" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4fp9-p6f3-3qq2/GHSA-4fp9-p6f3-3qq2.json b/advisories/unreviewed/2024/02/GHSA-4fp9-p6f3-3qq2/GHSA-4fp9-p6f3-3qq2.json new file mode 100644 index 00000000000..ca11ad8ef18 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4fp9-p6f3-3qq2/GHSA-4fp9-p6f3-3qq2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fp9-p6f3-3qq2", + "modified": "2024-02-15T12:30:52Z", + "published": "2024-02-15T12:30:52Z", + "aliases": [ + "CVE-2024-20744" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20744" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4xjr-mrmq-3hff/GHSA-4xjr-mrmq-3hff.json b/advisories/unreviewed/2024/02/GHSA-4xjr-mrmq-3hff/GHSA-4xjr-mrmq-3hff.json new file mode 100644 index 00000000000..a305bedf08a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4xjr-mrmq-3hff/GHSA-4xjr-mrmq-3hff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xjr-mrmq-3hff", + "modified": "2024-02-15T12:30:52Z", + "published": "2024-02-15T12:30:52Z", + "aliases": [ + "CVE-2024-20742" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20742" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5cfg-7c2f-q2g6/GHSA-5cfg-7c2f-q2g6.json b/advisories/unreviewed/2024/02/GHSA-5cfg-7c2f-q2g6/GHSA-5cfg-7c2f-q2g6.json new file mode 100644 index 00000000000..4f00b9594dd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5cfg-7c2f-q2g6/GHSA-5cfg-7c2f-q2g6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cfg-7c2f-q2g6", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-20724" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20724" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-78p5-2vmq-27q9/GHSA-78p5-2vmq-27q9.json b/advisories/unreviewed/2024/02/GHSA-78p5-2vmq-27q9/GHSA-78p5-2vmq-27q9.json new file mode 100644 index 00000000000..13c0f8de25b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-78p5-2vmq-27q9/GHSA-78p5-2vmq-27q9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78p5-2vmq-27q9", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-0390" + ], + "details": "INPRAX \"iZZi connect\" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the recuperation unit \"reQnet iZZi\".This issue affects \"iZZi connect\" application versions before 2024010401.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0390" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/02/CVE-2024-0390" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/02/CVE-2024-0390" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jmjh-5m3f-8c5h/GHSA-jmjh-5m3f-8c5h.json b/advisories/unreviewed/2024/02/GHSA-jmjh-5m3f-8c5h/GHSA-jmjh-5m3f-8c5h.json new file mode 100644 index 00000000000..a3da2615ce8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jmjh-5m3f-8c5h/GHSA-jmjh-5m3f-8c5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmjh-5m3f-8c5h", + "modified": "2024-02-15T12:30:52Z", + "published": "2024-02-15T12:30:52Z", + "aliases": [ + "CVE-2024-20743" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20743" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pf37-hj8r-43wq/GHSA-pf37-hj8r-43wq.json b/advisories/unreviewed/2024/02/GHSA-pf37-hj8r-43wq/GHSA-pf37-hj8r-43wq.json new file mode 100644 index 00000000000..ef1c6b476db --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pf37-hj8r-43wq/GHSA-pf37-hj8r-43wq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf37-hj8r-43wq", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-20722" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20722" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-pjh2-2j7m-242m/GHSA-pjh2-2j7m-242m.json b/advisories/unreviewed/2024/02/GHSA-pjh2-2j7m-242m/GHSA-pjh2-2j7m-242m.json new file mode 100644 index 00000000000..09829ae65e3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-pjh2-2j7m-242m/GHSA-pjh2-2j7m-242m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjh2-2j7m-242m", + "modified": "2024-02-15T12:30:51Z", + "published": "2024-02-15T12:30:51Z", + "aliases": [ + "CVE-2024-20723" + ], + "details": "Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20723" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-15T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json b/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json index 30692cd7f85..5912cdc3152 100644 --- a/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json +++ b/advisories/unreviewed/2024/02/GHSA-qxwj-fm5r-rhx8/GHSA-qxwj-fm5r-rhx8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxwj-fm5r-rhx8", - "modified": "2024-02-15T09:30:35Z", + "modified": "2024-02-15T12:30:51Z", "published": "2024-02-15T06:31:36Z", "aliases": [ "CVE-2023-46596" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://cwe.mitre.org/data/definitions/79.html" + }, + { + "type": "WEB", + "url": "https://www.algosec.com/docs/en/cves/Content/tech-notes/cves/cve-2023-46596.htm" } ], "database_specific": {