From c92a29e9ed96fb6410206dacae239e5726c26bab Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 31 Oct 2024 18:32:42 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-586p-749j-fhwp.json | 18 +++++++- .../GHSA-c5gv-fcxr-pxg7.json | 2 +- .../GHSA-fc44-r4gx-vw32.json | 2 +- .../GHSA-w99g-jxj5-xvfw.json | 2 +- .../GHSA-7j4q-xf7j-jxcp.json | 11 +++-- .../GHSA-8gff-fw8j-cgf3.json | 11 +++-- .../GHSA-f8gg-fh4p-4795.json | 11 +++-- .../GHSA-h6rg-3v58-mp3f.json | 11 +++-- .../GHSA-hqmx-8fhj-72gr.json | 11 +++-- .../GHSA-hvfx-qp2c-x42h.json | 4 +- .../GHSA-jx5h-83p8-r7p5.json | 11 +++-- .../GHSA-xfgg-h5qg-vvvx.json | 9 ++-- .../GHSA-2cpc-3p3h-5rwq.json | 9 ++-- .../GHSA-563m-xr38-7c3j.json | 9 ++-- .../GHSA-62pr-mr57-m7xm.json | 9 ++-- .../GHSA-7xc6-rqxq-w4qm.json | 9 ++-- .../GHSA-8g69-6rgj-v638.json | 11 +++-- .../GHSA-9mvw-qw27-cc95.json | 11 +++-- .../GHSA-c8gp-pfr5-2mm3.json | 9 ++-- .../GHSA-crf3-v2gr-xr72.json | 2 +- .../GHSA-hpmw-vh9j-2pxc.json | 11 +++-- .../GHSA-hv62-rcrq-hx82.json | 11 +++-- .../GHSA-qc99-8rmf-q4mv.json | 9 ++-- .../GHSA-3q9p-q428-g22j.json | 9 ++-- .../GHSA-3vh3-mqwm-fjh6.json | 11 +++-- .../GHSA-3x8x-qmm7-6f56.json | 11 +++-- .../GHSA-5wrr-m725-w8jw.json | 2 +- .../GHSA-6cq5-38vf-h3g2.json | 11 +++-- .../GHSA-73jw-m44p-r46h.json | 9 ++-- .../GHSA-88h4-jw57-85v9.json | 2 +- .../GHSA-cg9r-m2qr-hvvj.json | 11 +++-- .../GHSA-gvpw-gp9p-m67j.json | 2 +- .../GHSA-m5gq-xfj3-7366.json | 11 +++-- .../GHSA-mfg2-g3m8-3wmh.json | 2 +- .../GHSA-mqf9-26mh-8fj9.json | 2 +- .../GHSA-p5gx-xhhr-34q8.json | 9 ++-- .../GHSA-pwxx-fx4j-ffv3.json | 11 +++-- .../GHSA-qfh3-r9xh-mmwf.json | 11 +++-- .../GHSA-qrqj-j85r-f7h4.json | 9 ++-- .../GHSA-r5cc-f7pr-5v73.json | 2 +- .../GHSA-wv8p-qvw7-q865.json | 9 ++-- .../GHSA-2wwr-x9v6-x82m.json | 9 ++-- .../GHSA-cx5c-hrvr-85gj.json | 9 ++-- .../GHSA-fmqm-f3m4-fg43.json | 11 +++-- .../GHSA-fqjc-cfjx-7rv8.json | 11 +++-- .../GHSA-g684-gpwp-v5mj.json | 11 +++-- .../GHSA-j7xm-pf76-qww8.json | 9 ++-- .../GHSA-m3rr-r7v6-x79r.json | 11 +++-- .../GHSA-mgpj-gvmw-xq4j.json | 9 ++-- .../GHSA-r92r-c64c-j7jx.json | 9 ++-- .../GHSA-vh8v-4rwj-rmrh.json | 11 +++-- .../GHSA-vjm5-8qhg-f872.json | 9 ++-- .../GHSA-w5h9-gvgr-jhpg.json | 9 ++-- .../GHSA-w9fp-75mc-76ff.json | 9 ++-- .../GHSA-wc23-543f-rmp8.json | 11 +++-- .../GHSA-3m7q-mm9c-3r6p.json | 2 +- .../GHSA-82r3-68h3-qr79.json | 4 +- .../GHSA-jm94-9wqr-p9p4.json | 2 +- .../GHSA-jxrh-69wr-rj95.json | 11 +++-- .../GHSA-2rhx-838f-x5jw.json | 2 +- .../GHSA-2f7m-hc5g-9cqc.json | 11 +++-- .../GHSA-2qq8-8fw2-5hhq.json | 3 +- .../GHSA-3x5w-67jh-3785.json | 11 +++-- .../GHSA-46c8-p74g-hqqh.json | 11 +++-- .../GHSA-4j93-qfwm-6xrv.json | 11 +++-- .../GHSA-5qhh-w7j8-f42j.json | 11 +++-- .../GHSA-6723-8fqj-mw26.json | 2 +- .../GHSA-6c6m-6wj2-c9h3.json | 11 +++-- .../GHSA-7w36-gg3q-f3vg.json | 11 +++-- .../GHSA-84c3-765r-7fjp.json | 11 +++-- .../GHSA-8cgr-vwjm-54q7.json | 11 +++-- .../GHSA-9v8c-rf9v-pf96.json | 42 +++++++++++++++++++ .../GHSA-c68x-6hmf-xw2p.json | 11 +++-- .../GHSA-cvm9-cv4j-fhwp.json | 11 +++-- .../GHSA-f3xm-22x6-vg3g.json | 1 + .../GHSA-f7rc-79mv-v26v.json | 11 +++-- .../GHSA-fqq4-8x5p-9g5p.json | 11 +++-- .../GHSA-g233-2p4r-3q7v.json | 38 +++++++++++++++++ .../GHSA-g56g-9mxr-9pgw.json | 11 +++-- .../GHSA-hf48-3p5r-fp4x.json | 2 +- .../GHSA-hxrv-64jf-fgmr.json | 11 +++-- .../GHSA-jg9m-4m4c-v7c8.json | 11 +++-- .../GHSA-jm5c-w4xp-6794.json | 3 +- .../GHSA-jp7p-mxpw-mf6m.json | 11 +++-- .../GHSA-jwgw-4h9p-rxx6.json | 11 +++-- .../GHSA-p26r-gfgc-c47h.json | 10 ++++- .../GHSA-p8vr-968q-whxq.json | 9 ++-- .../GHSA-pxm6-wc5v-cphj.json | 11 +++-- .../GHSA-q4vh-3r4j-jv2p.json | 11 +++-- .../GHSA-q97q-7j3c-mx9j.json | 1 + .../GHSA-qf6h-766m-v7v7.json | 35 ++++++++++++++++ .../GHSA-qq59-g9rc-v6vx.json | 35 ++++++++++++++++ .../GHSA-rq35-f7p2-6pp9.json | 11 +++-- .../GHSA-rwqj-v7mx-c4x7.json | 11 +++-- .../GHSA-vwj9-2733-p4wv.json | 38 +++++++++++++++++ .../GHSA-wvj9-mrxw-ww9p.json | 11 +++-- .../GHSA-xhx7-6233-wm3w.json | 11 +++-- 97 files changed, 701 insertions(+), 278 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-9v8c-rf9v-pf96/GHSA-9v8c-rf9v-pf96.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g233-2p4r-3q7v/GHSA-g233-2p4r-3q7v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qf6h-766m-v7v7/GHSA-qf6h-766m-v7v7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qq59-g9rc-v6vx/GHSA-qq59-g9rc-v6vx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vwj9-2733-p4wv/GHSA-vwj9-2733-p4wv.json diff --git a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json index f623d07b62a..3049e15e213 100644 --- a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json +++ b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-586p-749j-fhwp", - "modified": "2024-10-31T00:30:36Z", + "modified": "2024-10-31T18:31:17Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-9675" @@ -60,6 +60,22 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8679" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8703" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8707" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8708" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8709" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9675" diff --git a/advisories/unreviewed/2023/07/GHSA-c5gv-fcxr-pxg7/GHSA-c5gv-fcxr-pxg7.json b/advisories/unreviewed/2023/07/GHSA-c5gv-fcxr-pxg7/GHSA-c5gv-fcxr-pxg7.json index fe4b696db77..e8dbdb78463 100644 --- a/advisories/unreviewed/2023/07/GHSA-c5gv-fcxr-pxg7/GHSA-c5gv-fcxr-pxg7.json +++ b/advisories/unreviewed/2023/07/GHSA-c5gv-fcxr-pxg7/GHSA-c5gv-fcxr-pxg7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-273" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-fc44-r4gx-vw32/GHSA-fc44-r4gx-vw32.json b/advisories/unreviewed/2023/07/GHSA-fc44-r4gx-vw32/GHSA-fc44-r4gx-vw32.json index 2516db874cf..c8b07d305ee 100644 --- a/advisories/unreviewed/2023/07/GHSA-fc44-r4gx-vw32/GHSA-fc44-r4gx-vw32.json +++ b/advisories/unreviewed/2023/07/GHSA-fc44-r4gx-vw32/GHSA-fc44-r4gx-vw32.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-w99g-jxj5-xvfw/GHSA-w99g-jxj5-xvfw.json b/advisories/unreviewed/2023/07/GHSA-w99g-jxj5-xvfw/GHSA-w99g-jxj5-xvfw.json index a884a0647e2..5294e43429c 100644 --- a/advisories/unreviewed/2023/07/GHSA-w99g-jxj5-xvfw/GHSA-w99g-jxj5-xvfw.json +++ b/advisories/unreviewed/2023/07/GHSA-w99g-jxj5-xvfw/GHSA-w99g-jxj5-xvfw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json b/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json index a5d973dc9e7..d535737bacf 100644 --- a/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json +++ b/advisories/unreviewed/2024/02/GHSA-7j4q-xf7j-jxcp/GHSA-7j4q-xf7j-jxcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j4q-xf7j-jxcp", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-26467" ], "details": "A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:27:59Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8gff-fw8j-cgf3/GHSA-8gff-fw8j-cgf3.json b/advisories/unreviewed/2024/02/GHSA-8gff-fw8j-cgf3/GHSA-8gff-fw8j-cgf3.json index e0152bbd59a..41f8dc6b864 100644 --- a/advisories/unreviewed/2024/02/GHSA-8gff-fw8j-cgf3/GHSA-8gff-fw8j-cgf3.json +++ b/advisories/unreviewed/2024/02/GHSA-8gff-fw8j-cgf3/GHSA-8gff-fw8j-cgf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gff-fw8j-cgf3", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-0016" ], "details": "In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T20:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json index 12aee891b0f..e886172f740 100644 --- a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json +++ b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8gg-fh4p-4795", - "modified": "2024-02-26T18:30:28Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1669" ], "details": "Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T04:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h6rg-3v58-mp3f/GHSA-h6rg-3v58-mp3f.json b/advisories/unreviewed/2024/02/GHSA-h6rg-3v58-mp3f/GHSA-h6rg-3v58-mp3f.json index ae828ba2ddd..69b5e4b4e03 100644 --- a/advisories/unreviewed/2024/02/GHSA-h6rg-3v58-mp3f/GHSA-h6rg-3v58-mp3f.json +++ b/advisories/unreviewed/2024/02/GHSA-h6rg-3v58-mp3f/GHSA-h6rg-3v58-mp3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6rg-3v58-mp3f", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40105" ], "details": "In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hqmx-8fhj-72gr/GHSA-hqmx-8fhj-72gr.json b/advisories/unreviewed/2024/02/GHSA-hqmx-8fhj-72gr/GHSA-hqmx-8fhj-72gr.json index 2db32e947ee..44ae0a23cb2 100644 --- a/advisories/unreviewed/2024/02/GHSA-hqmx-8fhj-72gr/GHSA-hqmx-8fhj-72gr.json +++ b/advisories/unreviewed/2024/02/GHSA-hqmx-8fhj-72gr/GHSA-hqmx-8fhj-72gr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hqmx-8fhj-72gr", - "modified": "2024-02-29T03:33:18Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-26472" ], "details": "A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the selector or validator parameters in offer.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:19Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hvfx-qp2c-x42h/GHSA-hvfx-qp2c-x42h.json b/advisories/unreviewed/2024/02/GHSA-hvfx-qp2c-x42h/GHSA-hvfx-qp2c-x42h.json index 5b8852091e0..4ccf2621db2 100644 --- a/advisories/unreviewed/2024/02/GHSA-hvfx-qp2c-x42h/GHSA-hvfx-qp2c-x42h.json +++ b/advisories/unreviewed/2024/02/GHSA-hvfx-qp2c-x42h/GHSA-hvfx-qp2c-x42h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hvfx-qp2c-x42h", - "modified": "2024-02-20T18:30:34Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-20T18:30:34Z", "aliases": [ "CVE-2024-21678" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-jx5h-83p8-r7p5/GHSA-jx5h-83p8-r7p5.json b/advisories/unreviewed/2024/02/GHSA-jx5h-83p8-r7p5/GHSA-jx5h-83p8-r7p5.json index 38b26137b8f..d926dfd99a3 100644 --- a/advisories/unreviewed/2024/02/GHSA-jx5h-83p8-r7p5/GHSA-jx5h-83p8-r7p5.json +++ b/advisories/unreviewed/2024/02/GHSA-jx5h-83p8-r7p5/GHSA-jx5h-83p8-r7p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx5h-83p8-r7p5", - "modified": "2024-02-22T06:30:34Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-22T06:30:34Z", "aliases": [ "CVE-2024-26490" ], "details": "A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T06:15:57Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xfgg-h5qg-vvvx/GHSA-xfgg-h5qg-vvvx.json b/advisories/unreviewed/2024/02/GHSA-xfgg-h5qg-vvvx/GHSA-xfgg-h5qg-vvvx.json index 9e163599f5c..73f05512ea3 100644 --- a/advisories/unreviewed/2024/02/GHSA-xfgg-h5qg-vvvx/GHSA-xfgg-h5qg-vvvx.json +++ b/advisories/unreviewed/2024/02/GHSA-xfgg-h5qg-vvvx/GHSA-xfgg-h5qg-vvvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfgg-h5qg-vvvx", - "modified": "2024-02-28T09:30:38Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47034" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/64s: Fix pte update for kernel memory on radix\n\nWhen adding a PTE a ptesync is needed to order the update of the PTE\nwith subsequent accesses otherwise a spurious fault may be raised.\n\nradix__set_pte_at() does not do this for performance gains. For\nnon-kernel memory this is not an issue as any faults of this kind are\ncorrected by the page fault handler. For kernel memory these faults\nare not handled. The current solution is that there is a ptesync in\nflush_cache_vmap() which should be called when mapping from the\nvmalloc region.\n\nHowever, map_kernel_page() does not call flush_cache_vmap(). This is\ntroublesome in particular for code patching with Strict RWX on radix.\nIn do_patch_instruction() the page frame that contains the instruction\nto be patched is mapped and then immediately patched. With no ordering\nor synchronization between setting up the PTE and writing to the page\nit is possible for faults.\n\nAs the code patching is done using __put_user_asm_goto() the resulting\nfault is obscured - but using a normal store instead it can be seen:\n\n BUG: Unable to handle kernel data access on write at 0xc008000008f24a3c\n Faulting instruction address: 0xc00000000008bd74\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA PowerNV\n Modules linked in: nop_module(PO+) [last unloaded: nop_module]\n CPU: 4 PID: 757 Comm: sh Tainted: P O 5.10.0-rc5-01361-ge3c1b78c8440-dirty #43\n NIP: c00000000008bd74 LR: c00000000008bd50 CTR: c000000000025810\n REGS: c000000016f634a0 TRAP: 0300 Tainted: P O (5.10.0-rc5-01361-ge3c1b78c8440-dirty)\n MSR: 9000000000009033 CR: 44002884 XER: 00000000\n CFAR: c00000000007c68c DAR: c008000008f24a3c DSISR: 42000000 IRQMASK: 1\n\nThis results in the kind of issue reported here:\n https://lore.kernel.org/linuxppc-dev/15AC5B0E-A221-4B8C-9039-FA96B8EF7C88@lca.pw/\n\nChris Riedl suggested a reliable way to reproduce the issue:\n $ mount -t debugfs none /sys/kernel/debug\n $ (while true; do echo function > /sys/kernel/debug/tracing/current_tracer ; echo nop > /sys/kernel/debug/tracing/current_tracer ; done) &\n\nTurning ftrace on and off does a large amount of code patching which\nin usually less then 5min will crash giving a trace like:\n\n ftrace-powerpc: (____ptrval____): replaced (4b473b11) != old (60000000)\n ------------[ ftrace bug ]------------\n ftrace failed to modify\n [] napi_busy_loop+0xc/0x390\n actual: 11:3b:47:4b\n Setting ftrace call site to call ftrace function\n ftrace record flags: 80000001\n (1)\n expected tramp: c00000000006c96c\n ------------[ cut here ]------------\n WARNING: CPU: 4 PID: 809 at kernel/trace/ftrace.c:2065 ftrace_bug+0x28c/0x2e8\n Modules linked in: nop_module(PO-) [last unloaded: nop_module]\n CPU: 4 PID: 809 Comm: sh Tainted: P O 5.10.0-rc5-01360-gf878ccaf250a #1\n NIP: c00000000024f334 LR: c00000000024f330 CTR: c0000000001a5af0\n REGS: c000000004c8b760 TRAP: 0700 Tainted: P O (5.10.0-rc5-01360-gf878ccaf250a)\n MSR: 900000000282b033 CR: 28008848 XER: 20040000\n CFAR: c0000000001a9c98 IRQMASK: 0\n GPR00: c00000000024f330 c000000004c8b9f0 c000000002770600 0000000000000022\n GPR04: 00000000ffff7fff c000000004c8b6d0 0000000000000027 c0000007fe9bcdd8\n GPR08: 0000000000000023 ffffffffffffffd8 0000000000000027 c000000002613118\n GPR12: 0000000000008000 c0000007fffdca00 0000000000000000 0000000000000000\n GPR16: 0000000023ec37c5 0000000000000000 0000000000000000 0000000000000008\n GPR20: c000000004c8bc90 c0000000027a2d20 c000000004c8bcd0 c000000002612fe8\n GPR24: 0000000000000038 0000000000000030 0000000000000028 0000000000000020\n GPR28: c000000000ff1b68 c000000000bf8e5c c00000000312f700 c000000000fbb9b0\n NIP ftrace_bug+0x28c/0x2e8\n LR ftrace_bug+0x288/0x2e8\n Call T\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json b/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json index ab1186d6c8b..bb617d32018 100644 --- a/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json +++ b/advisories/unreviewed/2024/03/GHSA-2cpc-3p3h-5rwq/GHSA-2cpc-3p3h-5rwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2cpc-3p3h-5rwq", - "modified": "2024-06-26T00:31:35Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-06T09:30:29Z", "aliases": [ "CVE-2024-26627" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Move scsi_host_busy() out of host lock for waking up EH handler\n\nInside scsi_eh_wakeup(), scsi_host_busy() is called & checked with host\nlock every time for deciding if error handler kthread needs to be waken up.\n\nThis can be too heavy in case of recovery, such as:\n\n - N hardware queues\n\n - queue depth is M for each hardware queue\n\n - each scsi_host_busy() iterates over (N * M) tag/requests\n\nIf recovery is triggered in case that all requests are in-flight, each\nscsi_eh_wakeup() is strictly serialized, when scsi_eh_wakeup() is called\nfor the last in-flight request, scsi_host_busy() has been run for (N * M -\n1) times, and request has been iterated for (N*M - 1) * (N * M) times.\n\nIf both N and M are big enough, hard lockup can be triggered on acquiring\nhost lock, and it is observed on mpi3mr(128 hw queues, queue depth 8169).\n\nFix the issue by calling scsi_host_busy() outside the host lock. We don't\nneed the host lock for getting busy count because host the lock never\ncovers that.\n\n[mkp: Drop unnecessary 'busy' variables pointed out by Bart]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-563m-xr38-7c3j/GHSA-563m-xr38-7c3j.json b/advisories/unreviewed/2024/03/GHSA-563m-xr38-7c3j/GHSA-563m-xr38-7c3j.json index 661ff907b70..7de3c3233f9 100644 --- a/advisories/unreviewed/2024/03/GHSA-563m-xr38-7c3j/GHSA-563m-xr38-7c3j.json +++ b/advisories/unreviewed/2024/03/GHSA-563m-xr38-7c3j/GHSA-563m-xr38-7c3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-563m-xr38-7c3j", - "modified": "2024-03-25T09:32:35Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-25T09:32:35Z", "aliases": [ "CVE-2021-47147" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: ocp: Fix a resource leak in an error handling path\n\nIf an error occurs after a successful 'pci_ioremap_bar()' call, it must be\nundone by a corresponding 'pci_iounmap()' call, as already done in the\nremove function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T09:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json b/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json index 2863384e54d..24848f7c4f0 100644 --- a/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json +++ b/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62pr-mr57-m7xm", - "modified": "2024-06-26T00:31:35Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-18T12:30:35Z", "aliases": [ "CVE-2023-52617" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: switchtec: Fix stdev_release() crash after surprise hot remove\n\nA PCI device hot removal may occur while stdev->cdev is held open. The call\nto stdev_release() then happens during close or exit, at a point way past\nswitchtec_pci_remove(). Otherwise the last ref would vanish with the\ntrailing put_device(), just before return.\n\nAt that later point in time, the devm cleanup has already removed the\nstdev->mmio_mrpc mapping. Also, the stdev->pdev reference was not a counted\none. Therefore, in DMA mode, the iowrite32() in stdev_release() will cause\na fatal page fault, and the subsequent dma_free_coherent(), if reached,\nwould pass a stale &stdev->pdev->dev pointer.\n\nFix by moving MRPC DMA shutdown into switchtec_pci_remove(), after\nstdev_kill(). Counting the stdev->pdev ref is now optional, but may prevent\nfuture accidents.\n\nReproducible via the script at\nhttps://lore.kernel.org/r/20231113212150.96410-1-dns@arista.com", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T11:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7xc6-rqxq-w4qm/GHSA-7xc6-rqxq-w4qm.json b/advisories/unreviewed/2024/03/GHSA-7xc6-rqxq-w4qm/GHSA-7xc6-rqxq-w4qm.json index cee934c11fa..92ba643ef3d 100644 --- a/advisories/unreviewed/2024/03/GHSA-7xc6-rqxq-w4qm/GHSA-7xc6-rqxq-w4qm.json +++ b/advisories/unreviewed/2024/03/GHSA-7xc6-rqxq-w4qm/GHSA-7xc6-rqxq-w4qm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7xc6-rqxq-w4qm", - "modified": "2024-03-04T18:30:39Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-04T18:30:39Z", "aliases": [ "CVE-2021-47099" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nveth: ensure skb entering GRO are not cloned.\n\nAfter commit d3256efd8e8b (\"veth: allow enabling NAPI even without XDP\"),\nif GRO is enabled on a veth device and TSO is disabled on the peer\ndevice, TCP skbs will go through the NAPI callback. If there is no XDP\nprogram attached, the veth code does not perform any share check, and\nshared/cloned skbs could enter the GRO engine.\n\nIgnat reported a BUG triggered later-on due to the above condition:\n\n[ 53.970529][ C1] kernel BUG at net/core/skbuff.c:3574!\n[ 53.981755][ C1] invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\n[ 53.982634][ C1] CPU: 1 PID: 19 Comm: ksoftirqd/1 Not tainted 5.16.0-rc5+ #25\n[ 53.982634][ C1] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n[ 53.982634][ C1] RIP: 0010:skb_shift+0x13ef/0x23b0\n[ 53.982634][ C1] Code: ea 03 0f b6 04 02 48 89 fa 83 e2 07 38 d0\n7f 08 84 c0 0f 85 41 0c 00 00 41 80 7f 02 00 4d 8d b5 d0 00 00 00 0f\n85 74 f5 ff ff <0f> 0b 4d 8d 77 20 be 04 00 00 00 4c 89 44 24 78 4c 89\nf7 4c 89 8c\n[ 53.982634][ C1] RSP: 0018:ffff8881008f7008 EFLAGS: 00010246\n[ 53.982634][ C1] RAX: 0000000000000000 RBX: ffff8881180b4c80 RCX: 0000000000000000\n[ 53.982634][ C1] RDX: 0000000000000002 RSI: ffff8881180b4d3c RDI: ffff88810bc9cac2\n[ 53.982634][ C1] RBP: ffff8881008f70b8 R08: ffff8881180b4cf4 R09: ffff8881180b4cf0\n[ 53.982634][ C1] R10: ffffed1022999e5c R11: 0000000000000002 R12: 0000000000000590\n[ 53.982634][ C1] R13: ffff88810f940c80 R14: ffff88810f940d50 R15: ffff88810bc9cac0\n[ 53.982634][ C1] FS: 0000000000000000(0000) GS:ffff888235880000(0000) knlGS:0000000000000000\n[ 53.982634][ C1] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 53.982634][ C1] CR2: 00007ff5f9b86680 CR3: 0000000108ce8004 CR4: 0000000000170ee0\n[ 53.982634][ C1] Call Trace:\n[ 53.982634][ C1] \n[ 53.982634][ C1] tcp_sacktag_walk+0xaba/0x18e0\n[ 53.982634][ C1] tcp_sacktag_write_queue+0xe7b/0x3460\n[ 53.982634][ C1] tcp_ack+0x2666/0x54b0\n[ 53.982634][ C1] tcp_rcv_established+0x4d9/0x20f0\n[ 53.982634][ C1] tcp_v4_do_rcv+0x551/0x810\n[ 53.982634][ C1] tcp_v4_rcv+0x22ed/0x2ed0\n[ 53.982634][ C1] ip_protocol_deliver_rcu+0x96/0xaf0\n[ 53.982634][ C1] ip_local_deliver_finish+0x1e0/0x2f0\n[ 53.982634][ C1] ip_sublist_rcv_finish+0x211/0x440\n[ 53.982634][ C1] ip_list_rcv_finish.constprop.0+0x424/0x660\n[ 53.982634][ C1] ip_list_rcv+0x2c8/0x410\n[ 53.982634][ C1] __netif_receive_skb_list_core+0x65c/0x910\n[ 53.982634][ C1] netif_receive_skb_list_internal+0x5f9/0xcb0\n[ 53.982634][ C1] napi_complete_done+0x188/0x6e0\n[ 53.982634][ C1] gro_cell_poll+0x10c/0x1d0\n[ 53.982634][ C1] __napi_poll+0xa1/0x530\n[ 53.982634][ C1] net_rx_action+0x567/0x1270\n[ 53.982634][ C1] __do_softirq+0x28a/0x9ba\n[ 53.982634][ C1] run_ksoftirqd+0x32/0x60\n[ 53.982634][ C1] smpboot_thread_fn+0x559/0x8c0\n[ 53.982634][ C1] kthread+0x3b9/0x490\n[ 53.982634][ C1] ret_from_fork+0x22/0x30\n[ 53.982634][ C1] \n\nAddress the issue by skipping the GRO stage for shared or cloned skbs.\nTo reduce the chance of OoO, try to unclone the skbs before giving up.\n\nv1 -> v2:\n - use avoid skb_copy and fallback to netif_receive_skb - Eric", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8g69-6rgj-v638/GHSA-8g69-6rgj-v638.json b/advisories/unreviewed/2024/03/GHSA-8g69-6rgj-v638/GHSA-8g69-6rgj-v638.json index 551124a573a..a8237f88e14 100644 --- a/advisories/unreviewed/2024/03/GHSA-8g69-6rgj-v638/GHSA-8g69-6rgj-v638.json +++ b/advisories/unreviewed/2024/03/GHSA-8g69-6rgj-v638/GHSA-8g69-6rgj-v638.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g69-6rgj-v638", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23230" ], "details": "This issue was addressed with improved file handling. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9mvw-qw27-cc95/GHSA-9mvw-qw27-cc95.json b/advisories/unreviewed/2024/03/GHSA-9mvw-qw27-cc95/GHSA-9mvw-qw27-cc95.json index 75e57bd45c3..b53b7bc9cad 100644 --- a/advisories/unreviewed/2024/03/GHSA-9mvw-qw27-cc95/GHSA-9mvw-qw27-cc95.json +++ b/advisories/unreviewed/2024/03/GHSA-9mvw-qw27-cc95/GHSA-9mvw-qw27-cc95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mvw-qw27-cc95", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-03T00:30:31Z", "aliases": [ "CVE-2023-52508" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()\n\nThe nvme_fc_fcp_op structure describing an AEN operation is initialized with a\nnull request structure pointer. An FC LLDD may make a call to\nnvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation.\n\nAdd validation of the request structure pointer before dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json b/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json index 027f4876dd0..8f7bc2b7e3b 100644 --- a/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json +++ b/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8gp-pfr5-2mm3", - "modified": "2024-03-18T12:30:35Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-18T12:30:35Z", "aliases": [ "CVE-2024-26638" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: always initialize struct msghdr completely\n\nsyzbot complains that msg->msg_get_inq value can be uninitialized [1]\n\nstruct msghdr got many new fields recently, we should always make\nsure their values is zero by default.\n\n[1]\n BUG: KMSAN: uninit-value in tcp_recvmsg+0x686/0xac0 net/ipv4/tcp.c:2571\n tcp_recvmsg+0x686/0xac0 net/ipv4/tcp.c:2571\n inet_recvmsg+0x131/0x580 net/ipv4/af_inet.c:879\n sock_recvmsg_nosec net/socket.c:1044 [inline]\n sock_recvmsg+0x12b/0x1e0 net/socket.c:1066\n __sock_xmit+0x236/0x5c0 drivers/block/nbd.c:538\n nbd_read_reply drivers/block/nbd.c:732 [inline]\n recv_work+0x262/0x3100 drivers/block/nbd.c:863\n process_one_work kernel/workqueue.c:2627 [inline]\n process_scheduled_works+0x104e/0x1e70 kernel/workqueue.c:2700\n worker_thread+0xf45/0x1490 kernel/workqueue.c:2781\n kthread+0x3ed/0x540 kernel/kthread.c:388\n ret_from_fork+0x66/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:242\n\nLocal variable msg created at:\n __sock_xmit+0x4c/0x5c0 drivers/block/nbd.c:513\n nbd_read_reply drivers/block/nbd.c:732 [inline]\n recv_work+0x262/0x3100 drivers/block/nbd.c:863\n\nCPU: 1 PID: 7465 Comm: kworker/u5:1 Not tainted 6.7.0-rc7-syzkaller-00041-gf016f7547aee #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\nWorkqueue: nbd5-recv recv_work", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T11:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-crf3-v2gr-xr72/GHSA-crf3-v2gr-xr72.json b/advisories/unreviewed/2024/03/GHSA-crf3-v2gr-xr72/GHSA-crf3-v2gr-xr72.json index ee037e12b1a..0f344d9582d 100644 --- a/advisories/unreviewed/2024/03/GHSA-crf3-v2gr-xr72/GHSA-crf3-v2gr-xr72.json +++ b/advisories/unreviewed/2024/03/GHSA-crf3-v2gr-xr72/GHSA-crf3-v2gr-xr72.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json b/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json index 5ce99fc3c2d..567cea02aa2 100644 --- a/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json +++ b/advisories/unreviewed/2024/03/GHSA-hpmw-vh9j-2pxc/GHSA-hpmw-vh9j-2pxc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hpmw-vh9j-2pxc", - "modified": "2024-03-20T15:32:22Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-20T15:32:22Z", "aliases": [ "CVE-2024-28092" ], "details": "UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via RgFirewallEL.asp, RgDdns.asp, RgTime.asp, RgDiagnostics.asp, or RgParentalBasic.asp. The affected fields are SMTP Server Name, SMTP Username, Host Name, Time Server 1, Time Server 2, Time Server 3, Target, Add Keyword, Add Domain, and Add Allowed Domain.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T21:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hv62-rcrq-hx82/GHSA-hv62-rcrq-hx82.json b/advisories/unreviewed/2024/03/GHSA-hv62-rcrq-hx82/GHSA-hv62-rcrq-hx82.json index f4dde8be339..e3d7b709ba5 100644 --- a/advisories/unreviewed/2024/03/GHSA-hv62-rcrq-hx82/GHSA-hv62-rcrq-hx82.json +++ b/advisories/unreviewed/2024/03/GHSA-hv62-rcrq-hx82/GHSA-hv62-rcrq-hx82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hv62-rcrq-hx82", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-0561" ], "details": "The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:17Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json b/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json index 9138dc08f6d..9633e5fd640 100644 --- a/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json +++ b/advisories/unreviewed/2024/03/GHSA-qc99-8rmf-q4mv/GHSA-qc99-8rmf-q4mv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc99-8rmf-q4mv", - "modified": "2024-05-07T06:30:35Z", + "modified": "2024-10-31T18:31:15Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23280" ], "details": "An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -79,7 +82,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json b/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json index 9f8f9f11b6e..5ffdee18268 100644 --- a/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json +++ b/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q9p-q428-g22j", - "modified": "2024-04-08T06:31:29Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-08T06:31:29Z", "aliases": [ "CVE-2024-1292" ], "details": "The wpb-show-core WordPress plugin before 2.6 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T05:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3vh3-mqwm-fjh6/GHSA-3vh3-mqwm-fjh6.json b/advisories/unreviewed/2024/04/GHSA-3vh3-mqwm-fjh6/GHSA-3vh3-mqwm-fjh6.json index 9f436374956..f609067df78 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vh3-mqwm-fjh6/GHSA-3vh3-mqwm-fjh6.json +++ b/advisories/unreviewed/2024/04/GHSA-3vh3-mqwm-fjh6/GHSA-3vh3-mqwm-fjh6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vh3-mqwm-fjh6", - "modified": "2024-04-02T18:31:19Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-02T18:31:19Z", "aliases": [ "CVE-2024-30808" ], "details": "An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T18:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3x8x-qmm7-6f56/GHSA-3x8x-qmm7-6f56.json b/advisories/unreviewed/2024/04/GHSA-3x8x-qmm7-6f56/GHSA-3x8x-qmm7-6f56.json index 22470918db2..773ebc52c3f 100644 --- a/advisories/unreviewed/2024/04/GHSA-3x8x-qmm7-6f56/GHSA-3x8x-qmm7-6f56.json +++ b/advisories/unreviewed/2024/04/GHSA-3x8x-qmm7-6f56/GHSA-3x8x-qmm7-6f56.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x8x-qmm7-6f56", - "modified": "2024-06-27T12:30:45Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26889" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix possible buffer overflow\n\nstruct hci_dev_info has a fixed size name[8] field so in the event that\nhdev->name is bigger than that strcpy would attempt to write past its\nsize, so this fixes this problem by switching to use strscpy.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -65,9 +68,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json b/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json index db8ed2dd344..38f146ddc32 100644 --- a/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json +++ b/advisories/unreviewed/2024/04/GHSA-5wrr-m725-w8jw/GHSA-5wrr-m725-w8jw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json b/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json index 1a3a98b72b0..33f6b9091bf 100644 --- a/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json +++ b/advisories/unreviewed/2024/04/GHSA-6cq5-38vf-h3g2/GHSA-6cq5-38vf-h3g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cq5-38vf-h3g2", - "modified": "2024-04-10T18:30:47Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-23734" ], "details": "Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T16:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-73jw-m44p-r46h/GHSA-73jw-m44p-r46h.json b/advisories/unreviewed/2024/04/GHSA-73jw-m44p-r46h/GHSA-73jw-m44p-r46h.json index 0037bed01fe..00e00383442 100644 --- a/advisories/unreviewed/2024/04/GHSA-73jw-m44p-r46h/GHSA-73jw-m44p-r46h.json +++ b/advisories/unreviewed/2024/04/GHSA-73jw-m44p-r46h/GHSA-73jw-m44p-r46h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73jw-m44p-r46h", - "modified": "2024-04-11T18:30:54Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-11T18:30:54Z", "aliases": [ "CVE-2024-0881" ], "details": "The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not prevent password protected posts from being displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T16:15:24Z" diff --git a/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json b/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json index c8f740da492..acb3d10b38c 100644 --- a/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json +++ b/advisories/unreviewed/2024/04/GHSA-88h4-jw57-85v9/GHSA-88h4-jw57-85v9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json b/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json index 8a233a50d01..46199474fd2 100644 --- a/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json +++ b/advisories/unreviewed/2024/04/GHSA-cg9r-m2qr-hvvj/GHSA-cg9r-m2qr-hvvj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cg9r-m2qr-hvvj", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52541" ], "details": "Authentication vulnerability in the API for app pre-loading.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gvpw-gp9p-m67j/GHSA-gvpw-gp9p-m67j.json b/advisories/unreviewed/2024/04/GHSA-gvpw-gp9p-m67j/GHSA-gvpw-gp9p-m67j.json index 67a491370bd..2153dad4a9d 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvpw-gp9p-m67j/GHSA-gvpw-gp9p-m67j.json +++ b/advisories/unreviewed/2024/04/GHSA-gvpw-gp9p-m67j/GHSA-gvpw-gp9p-m67j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json b/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json index f13de5c70fb..bcaa13bff0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json +++ b/advisories/unreviewed/2024/04/GHSA-m5gq-xfj3-7366/GHSA-m5gq-xfj3-7366.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5gq-xfj3-7366", - "modified": "2024-04-09T00:30:41Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-09T00:30:41Z", "aliases": [ "CVE-2024-23079" ], "details": "JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T23:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mfg2-g3m8-3wmh/GHSA-mfg2-g3m8-3wmh.json b/advisories/unreviewed/2024/04/GHSA-mfg2-g3m8-3wmh/GHSA-mfg2-g3m8-3wmh.json index 6e1a005ced5..d8aac352da2 100644 --- a/advisories/unreviewed/2024/04/GHSA-mfg2-g3m8-3wmh/GHSA-mfg2-g3m8-3wmh.json +++ b/advisories/unreviewed/2024/04/GHSA-mfg2-g3m8-3wmh/GHSA-mfg2-g3m8-3wmh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-mqf9-26mh-8fj9/GHSA-mqf9-26mh-8fj9.json b/advisories/unreviewed/2024/04/GHSA-mqf9-26mh-8fj9/GHSA-mqf9-26mh-8fj9.json index f9ea049f6c7..4d2adce0770 100644 --- a/advisories/unreviewed/2024/04/GHSA-mqf9-26mh-8fj9/GHSA-mqf9-26mh-8fj9.json +++ b/advisories/unreviewed/2024/04/GHSA-mqf9-26mh-8fj9/GHSA-mqf9-26mh-8fj9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-p5gx-xhhr-34q8/GHSA-p5gx-xhhr-34q8.json b/advisories/unreviewed/2024/04/GHSA-p5gx-xhhr-34q8/GHSA-p5gx-xhhr-34q8.json index 337ee8f01a5..fe8b3e7ff9f 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5gx-xhhr-34q8/GHSA-p5gx-xhhr-34q8.json +++ b/advisories/unreviewed/2024/04/GHSA-p5gx-xhhr-34q8/GHSA-p5gx-xhhr-34q8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5gx-xhhr-34q8", - "modified": "2024-04-22T15:30:42Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-22T15:30:42Z", "aliases": [ "CVE-2023-38299" ], "details": "Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: AT&T Calypso (ATT/U318AA/U318AA:10/QP1A.190711.020/1632369780:user/release-keys); Nokia C100 (Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_190:user/release-keys and Nokia/DrakeLite_02US/DKT:12/SP1A.210812.016/02US_1_270:user/release-keys); Nokia C200 (Nokia/Drake_02US/DRK:12/SP1A.210812.016/02US_1_080:user/release-keys); and BLU View 3 (BLU/B140DL/B140DL:11/RP1A.200720.011/1628014629:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1632535579:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1637325978:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1650073052:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1657087912:user/release-keys, BLU/B140DL/B140DL:11/RP1A.200720.011/1666316280:user/release-keys, and BLU/B140DL/B140DL:11/RP1A.200720.011/1672371162:user/release-keys). This malicious app reads from the \"persist.sys.imei1\" system property to indirectly obtain the device IMEI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-22T15:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pwxx-fx4j-ffv3/GHSA-pwxx-fx4j-ffv3.json b/advisories/unreviewed/2024/04/GHSA-pwxx-fx4j-ffv3/GHSA-pwxx-fx4j-ffv3.json index 477a1bc102e..8bb414439d3 100644 --- a/advisories/unreviewed/2024/04/GHSA-pwxx-fx4j-ffv3/GHSA-pwxx-fx4j-ffv3.json +++ b/advisories/unreviewed/2024/04/GHSA-pwxx-fx4j-ffv3/GHSA-pwxx-fx4j-ffv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwxx-fx4j-ffv3", - "modified": "2024-04-02T09:30:40Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2023-52631" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fix an NULL dereference bug\n\nThe issue here is when this is called from ntfs_load_attr_list(). The\n\"size\" comes from le32_to_cpu(attr->res.data_size) so it can't overflow\non a 64bit systems but on 32bit systems the \"+ 1023\" can overflow and\nthe result is zero. This means that the kmalloc will succeed by\nreturning the ZERO_SIZE_PTR and then the memcpy() will crash with an\nOops on the next line.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:40Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json b/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json index a50d0a70a67..b9e15c666a6 100644 --- a/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json +++ b/advisories/unreviewed/2024/04/GHSA-qfh3-r9xh-mmwf/GHSA-qfh3-r9xh-mmwf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfh3-r9xh-mmwf", - "modified": "2024-04-04T09:30:34Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-04T09:30:34Z", "aliases": [ "CVE-2023-25200" ], "details": "An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and obtain sensitive information in a victim's browser.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T07:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qrqj-j85r-f7h4/GHSA-qrqj-j85r-f7h4.json b/advisories/unreviewed/2024/04/GHSA-qrqj-j85r-f7h4/GHSA-qrqj-j85r-f7h4.json index 5dee5bb8c74..bf6b040c6bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-qrqj-j85r-f7h4/GHSA-qrqj-j85r-f7h4.json +++ b/advisories/unreviewed/2024/04/GHSA-qrqj-j85r-f7h4/GHSA-qrqj-j85r-f7h4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrqj-j85r-f7h4", - "modified": "2024-04-15T06:30:34Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-15T06:30:34Z", "aliases": [ "CVE-2024-1310" ], "details": "The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:14Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json b/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json index 4f3bf87499d..f5d4f742b2c 100644 --- a/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json +++ b/advisories/unreviewed/2024/04/GHSA-r5cc-f7pr-5v73/GHSA-r5cc-f7pr-5v73.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json b/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json index 63b21e428ee..0e233d0b128 100644 --- a/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json +++ b/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv8p-qvw7-q865", - "modified": "2024-04-02T06:30:31Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-04-02T06:30:31Z", "aliases": [ "CVE-2024-2369" ], "details": "The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T05:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2wwr-x9v6-x82m/GHSA-2wwr-x9v6-x82m.json b/advisories/unreviewed/2024/05/GHSA-2wwr-x9v6-x82m/GHSA-2wwr-x9v6-x82m.json index b6d399296e2..c7554bad171 100644 --- a/advisories/unreviewed/2024/05/GHSA-2wwr-x9v6-x82m/GHSA-2wwr-x9v6-x82m.json +++ b/advisories/unreviewed/2024/05/GHSA-2wwr-x9v6-x82m/GHSA-2wwr-x9v6-x82m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wwr-x9v6-x82m", - "modified": "2024-05-21T18:31:20Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52776" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix dfs-radar and temperature event locking\n\nThe ath12k active pdevs are protected by RCU but the DFS-radar and\ntemperature event handling code calling ath12k_mac_get_ar_by_pdev_id()\nwas not marked as a read-side critical section.\n\nMark the code in question as RCU read-side critical sections to avoid\nany potential use-after-free issues.\n\nNote that the temperature event handler looks like a place holder\ncurrently but would still trigger an RCU lockdep splat.\n\nCompile tested only.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json b/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json index 68aaf2374e7..1ac8735546b 100644 --- a/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json +++ b/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx5c-hrvr-85gj", - "modified": "2024-10-17T15:31:07Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27072" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: usbtv: Remove useless locks in usbtv_video_free()\n\nRemove locks calls in usbtv_video_free() because\nare useless and may led to a deadlock as reported here:\nhttps://syzkaller.appspot.com/x/bisect.txt?x=166dc872180000\nAlso remove usbtv_stop() call since it will be called when\nunregistering the device.\n\nBefore 'c838530d230b' this issue would only be noticed if you\ndisconnect while streaming and now it is noticeable even when\ndisconnecting while not streaming.\n\n\n[hverkuil: fix minor spelling mistake in log message]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:51Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json b/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json index 83acdb97547..2814e09d9d0 100644 --- a/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json +++ b/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fmqm-f3m4-fg43", - "modified": "2024-05-22T09:31:45Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47471" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: mxsfb: Fix NULL pointer dereference crash on unload\n\nThe mxsfb->crtc.funcs may already be NULL when unloading the driver,\nin which case calling mxsfb_irq_disable() via drm_irq_uninstall() from\nmxsfb_unload() leads to NULL pointer dereference.\n\nSince all we care about is masking the IRQ and mxsfb->base is still\nvalid, just use that to clear and mask the IRQ.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json b/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json index 7ca654f105a..b2a53f2d8a1 100644 --- a/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json +++ b/advisories/unreviewed/2024/05/GHSA-fqjc-cfjx-7rv8/GHSA-fqjc-cfjx-7rv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqjc-cfjx-7rv8", - "modified": "2024-06-10T18:31:05Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-31T00:30:44Z", "aliases": [ "CVE-2024-5498" ], "details": "Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-30T23:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g684-gpwp-v5mj/GHSA-g684-gpwp-v5mj.json b/advisories/unreviewed/2024/05/GHSA-g684-gpwp-v5mj/GHSA-g684-gpwp-v5mj.json index 50e5b0a070d..a27d7d22432 100644 --- a/advisories/unreviewed/2024/05/GHSA-g684-gpwp-v5mj/GHSA-g684-gpwp-v5mj.json +++ b/advisories/unreviewed/2024/05/GHSA-g684-gpwp-v5mj/GHSA-g684-gpwp-v5mj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g684-gpwp-v5mj", - "modified": "2024-05-23T18:30:56Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-23T18:30:56Z", "aliases": [ "CVE-2024-5143" ], "details": "A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T17:15:31Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j7xm-pf76-qww8/GHSA-j7xm-pf76-qww8.json b/advisories/unreviewed/2024/05/GHSA-j7xm-pf76-qww8/GHSA-j7xm-pf76-qww8.json index 76d13b6aa71..9409fede72f 100644 --- a/advisories/unreviewed/2024/05/GHSA-j7xm-pf76-qww8/GHSA-j7xm-pf76-qww8.json +++ b/advisories/unreviewed/2024/05/GHSA-j7xm-pf76-qww8/GHSA-j7xm-pf76-qww8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7xm-pf76-qww8", - "modified": "2024-05-21T18:31:21Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52811" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ibmvfc: Remove BUG_ON in the case of an empty event pool\n\nIn practice the driver should never send more commands than are allocated\nto a queue's event pool. In the unlikely event that this happens, the code\nasserts a BUG_ON, and in the case that the kernel is not configured to\ncrash on panic returns a junk event pointer from the empty event list\ncausing things to spiral from there. This BUG_ON is a historical artifact\nof the ibmvfc driver first being upstreamed, and it is well known now that\nthe use of BUG_ON is bad practice except in the most unrecoverable\nscenario. There is nothing about this scenario that prevents the driver\nfrom recovering and carrying on.\n\nRemove the BUG_ON in question from ibmvfc_get_event() and return a NULL\npointer in the case of an empty event pool. Update all call sites to\nibmvfc_get_event() to check for a NULL pointer and perfrom the appropriate\nfailure or recovery action.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:19Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m3rr-r7v6-x79r/GHSA-m3rr-r7v6-x79r.json b/advisories/unreviewed/2024/05/GHSA-m3rr-r7v6-x79r/GHSA-m3rr-r7v6-x79r.json index 4a192bd4981..8291c8e4d9d 100644 --- a/advisories/unreviewed/2024/05/GHSA-m3rr-r7v6-x79r/GHSA-m3rr-r7v6-x79r.json +++ b/advisories/unreviewed/2024/05/GHSA-m3rr-r7v6-x79r/GHSA-m3rr-r7v6-x79r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3rr-r7v6-x79r", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2023-24204" ], "details": "SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T17:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mgpj-gvmw-xq4j/GHSA-mgpj-gvmw-xq4j.json b/advisories/unreviewed/2024/05/GHSA-mgpj-gvmw-xq4j/GHSA-mgpj-gvmw-xq4j.json index 749488a967b..d8bdce2937b 100644 --- a/advisories/unreviewed/2024/05/GHSA-mgpj-gvmw-xq4j/GHSA-mgpj-gvmw-xq4j.json +++ b/advisories/unreviewed/2024/05/GHSA-mgpj-gvmw-xq4j/GHSA-mgpj-gvmw-xq4j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgpj-gvmw-xq4j", - "modified": "2024-06-27T12:30:46Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-19T09:34:46Z", "aliases": [ "CVE-2024-35877" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/pat: fix VM_PAT handling in COW mappings\n\nPAT handling won't do the right thing in COW mappings: the first PTE (or,\nin fact, all PTEs) can be replaced during write faults to point at anon\nfolios. Reliably recovering the correct PFN and cachemode using\nfollow_phys() from PTEs will not work in COW mappings.\n\nUsing follow_phys(), we might just get the address+protection of the anon\nfolio (which is very wrong), or fail on swap/nonswap entries, failing\nfollow_phys() and triggering a WARN_ON_ONCE() in untrack_pfn() and\ntrack_pfn_copy(), not properly calling free_pfn_range().\n\nIn free_pfn_range(), we either wouldn't call memtype_free() or would call\nit with the wrong range, possibly leaking memory.\n\nTo fix that, let's update follow_phys() to refuse returning anon folios,\nand fallback to using the stored PFN inside vma->vm_pgoff for COW mappings\nif we run into that.\n\nWe will now properly handle untrack_pfn() with COW mappings, where we\ndon't need the cachemode. We'll have to fail fork()->track_pfn_copy() if\nthe first page was replaced by an anon folio, though: we'd have to store\nthe cachemode in the VMA to make this work, likely growing the VMA size.\n\nFor now, lets keep it simple and let track_pfn_copy() just fail in that\ncase: it would have failed in the past with swap/nonswap entries already,\nand it would have done the wrong thing with anon folios.\n\nSimple reproducer to trigger the WARN_ON_ONCE() in untrack_pfn():\n\n<--- C reproducer --->\n #include \n #include \n #include \n #include \n\n int main(void)\n {\n struct io_uring_params p = {};\n int ring_fd;\n size_t size;\n char *map;\n\n ring_fd = io_uring_setup(1, &p);\n if (ring_fd < 0) {\n perror(\"io_uring_setup\");\n return 1;\n }\n size = p.sq_off.array + p.sq_entries * sizeof(unsigned);\n\n /* Map the submission queue ring MAP_PRIVATE */\n map = mmap(0, size, PROT_READ | PROT_WRITE, MAP_PRIVATE,\n ring_fd, IORING_OFF_SQ_RING);\n if (map == MAP_FAILED) {\n perror(\"mmap\");\n return 1;\n }\n\n /* We have at least one page. Let's COW it. */\n *map = 0;\n pause();\n return 0;\n }\n<--- C reproducer --->\n\nOn a system with 16 GiB RAM and swap configured:\n # ./iouring &\n # memhog 16G\n # killall iouring\n[ 301.552930] ------------[ cut here ]------------\n[ 301.553285] WARNING: CPU: 7 PID: 1402 at arch/x86/mm/pat/memtype.c:1060 untrack_pfn+0xf4/0x100\n[ 301.553989] Modules linked in: binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_g\n[ 301.558232] CPU: 7 PID: 1402 Comm: iouring Not tainted 6.7.5-100.fc38.x86_64 #1\n[ 301.558772] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebu4\n[ 301.559569] RIP: 0010:untrack_pfn+0xf4/0x100\n[ 301.559893] Code: 75 c4 eb cf 48 8b 43 10 8b a8 e8 00 00 00 3b 6b 28 74 b8 48 8b 7b 30 e8 ea 1a f7 000\n[ 301.561189] RSP: 0018:ffffba2c0377fab8 EFLAGS: 00010282\n[ 301.561590] RAX: 00000000ffffffea RBX: ffff9208c8ce9cc0 RCX: 000000010455e047\n[ 301.562105] RDX: 07fffffff0eb1e0a RSI: 0000000000000000 RDI: ffff9208c391d200\n[ 301.562628] RBP: 0000000000000000 R08: ffffba2c0377fab8 R09: 0000000000000000\n[ 301.563145] R10: ffff9208d2292d50 R11: 0000000000000002 R12: 00007fea890e0000\n[ 301.563669] R13: 0000000000000000 R14: ffffba2c0377fc08 R15: 0000000000000000\n[ 301.564186] FS: 0000000000000000(0000) GS:ffff920c2fbc0000(0000) knlGS:0000000000000000\n[ 301.564773] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 301.565197] CR2: 00007fea88ee8a20 CR3: 00000001033a8000 CR4: 0000000000750ef0\n[ 301.565725] PKRU: 55555554\n[ 301.565944] Call Trace:\n[ 301.566148] \n[ 301.566325] ? untrack_pfn+0xf4/0x100\n[ 301.566618] ? __warn+0x81/0x130\n[ 301.566876] ? untrack_pfn+0xf4/0x100\n[ 3\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T09:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r92r-c64c-j7jx/GHSA-r92r-c64c-j7jx.json b/advisories/unreviewed/2024/05/GHSA-r92r-c64c-j7jx/GHSA-r92r-c64c-j7jx.json index 6d1843874ad..d6c0fbe1481 100644 --- a/advisories/unreviewed/2024/05/GHSA-r92r-c64c-j7jx/GHSA-r92r-c64c-j7jx.json +++ b/advisories/unreviewed/2024/05/GHSA-r92r-c64c-j7jx/GHSA-r92r-c64c-j7jx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r92r-c64c-j7jx", - "modified": "2024-05-21T18:31:17Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-21T18:31:17Z", "aliases": [ "CVE-2021-47432" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/generic-radix-tree.c: Don't overflow in peek()\n\nWhen we started spreading new inode numbers throughout most of the 64\nbit inode space, that triggered some corner case bugs, in particular\nsome integer overflows related to the radix tree code. Oops.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json b/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json index dd4c3dfb165..fe42a85ba90 100644 --- a/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json +++ b/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vh8v-4rwj-rmrh", - "modified": "2024-05-22T06:30:38Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-22T06:30:38Z", "aliases": [ "CVE-2024-31395" ], "details": "Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with an editor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the schedule management page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T05:15:53Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vjm5-8qhg-f872/GHSA-vjm5-8qhg-f872.json b/advisories/unreviewed/2024/05/GHSA-vjm5-8qhg-f872/GHSA-vjm5-8qhg-f872.json index 5aff90489b8..6a3d40cdc55 100644 --- a/advisories/unreviewed/2024/05/GHSA-vjm5-8qhg-f872/GHSA-vjm5-8qhg-f872.json +++ b/advisories/unreviewed/2024/05/GHSA-vjm5-8qhg-f872/GHSA-vjm5-8qhg-f872.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjm5-8qhg-f872", - "modified": "2024-05-01T06:31:42Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-01T06:31:42Z", "aliases": [ "CVE-2024-26977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npci_iounmap(): Fix MMIO mapping leak\n\nThe #ifdef ARCH_HAS_GENERIC_IOPORT_MAP accidentally also guards iounmap(),\nwhich means MMIO mappings are leaked.\n\nMove the guard so we call iounmap() for MMIO mappings.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w5h9-gvgr-jhpg/GHSA-w5h9-gvgr-jhpg.json b/advisories/unreviewed/2024/05/GHSA-w5h9-gvgr-jhpg/GHSA-w5h9-gvgr-jhpg.json index 839e26b0541..d9b90e558de 100644 --- a/advisories/unreviewed/2024/05/GHSA-w5h9-gvgr-jhpg/GHSA-w5h9-gvgr-jhpg.json +++ b/advisories/unreviewed/2024/05/GHSA-w5h9-gvgr-jhpg/GHSA-w5h9-gvgr-jhpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5h9-gvgr-jhpg", - "modified": "2024-05-21T15:31:39Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-21T15:31:39Z", "aliases": [ "CVE-2021-47228" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/ioremap: Map EFI-reserved memory as encrypted for SEV\n\nSome drivers require memory that is marked as EFI boot services\ndata. In order for this memory to not be re-used by the kernel\nafter ExitBootServices(), efi_mem_reserve() is used to preserve it\nby inserting a new EFI memory descriptor and marking it with the\nEFI_MEMORY_RUNTIME attribute.\n\nUnder SEV, memory marked with the EFI_MEMORY_RUNTIME attribute needs to\nbe mapped encrypted by Linux, otherwise the kernel might crash at boot\nlike below:\n\n EFI Variables Facility v0.08 2004-May-17\n general protection fault, probably for non-canonical address 0x3597688770a868b2: 0000 [#1] SMP NOPTI\n CPU: 13 PID: 1 Comm: swapper/0 Not tainted 5.12.4-2-default #1 openSUSE Tumbleweed\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n RIP: 0010:efi_mokvar_entry_next\n [...]\n Call Trace:\n efi_mokvar_sysfs_init\n ? efi_mokvar_table_init\n do_one_initcall\n ? __kmalloc\n kernel_init_freeable\n ? rest_init\n kernel_init\n ret_from_fork\n\nExpand the __ioremap_check_other() function to additionally check for\nthis other type of boot data reserved at runtime and indicate that it\nshould be mapped encrypted for an SEV guest.\n\n [ bp: Massage commit message. ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w9fp-75mc-76ff/GHSA-w9fp-75mc-76ff.json b/advisories/unreviewed/2024/05/GHSA-w9fp-75mc-76ff/GHSA-w9fp-75mc-76ff.json index e0e4f5bdff6..c8db5bc69c7 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9fp-75mc-76ff/GHSA-w9fp-75mc-76ff.json +++ b/advisories/unreviewed/2024/05/GHSA-w9fp-75mc-76ff/GHSA-w9fp-75mc-76ff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9fp-75mc-76ff", - "modified": "2024-05-21T15:31:43Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-21T15:31:43Z", "aliases": [ "CVE-2021-47333" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: alcor_pci: fix null-ptr-deref when there is no PCI bridge\n\nThere is an issue with the ASPM(optional) capability checking function.\nA device might be attached to root complex directly, in this case,\nbus->self(bridge) will be NULL, thus priv->parent_pdev is NULL.\nSince alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's\nASPM capability and populate parent_cap_off, which will be used later by\nalcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do\nhere is to avoid checking the capability if we are on the root complex.\nThis will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply\nreturn when bring called, effectively disable ASPM for the device.\n\n[ 1.246492] BUG: kernel NULL pointer dereference, address: 00000000000000c0\n[ 1.248731] RIP: 0010:pci_read_config_byte+0x5/0x40\n[ 1.253998] Call Trace:\n[ 1.254131] ? alcor_pci_find_cap_offset.isra.0+0x3a/0x100 [alcor_pci]\n[ 1.254476] alcor_pci_probe+0x169/0x2d5 [alcor_pci]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wc23-543f-rmp8/GHSA-wc23-543f-rmp8.json b/advisories/unreviewed/2024/05/GHSA-wc23-543f-rmp8/GHSA-wc23-543f-rmp8.json index d60bb80a9c1..57c8f7843c5 100644 --- a/advisories/unreviewed/2024/05/GHSA-wc23-543f-rmp8/GHSA-wc23-543f-rmp8.json +++ b/advisories/unreviewed/2024/05/GHSA-wc23-543f-rmp8/GHSA-wc23-543f-rmp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wc23-543f-rmp8", - "modified": "2024-05-03T03:30:47Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-05-03T03:30:47Z", "aliases": [ "CVE-2024-34401" ], "details": "Savsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T01:15:48Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3m7q-mm9c-3r6p/GHSA-3m7q-mm9c-3r6p.json b/advisories/unreviewed/2024/06/GHSA-3m7q-mm9c-3r6p/GHSA-3m7q-mm9c-3r6p.json index 53ec46f45f8..d7320f14443 100644 --- a/advisories/unreviewed/2024/06/GHSA-3m7q-mm9c-3r6p/GHSA-3m7q-mm9c-3r6p.json +++ b/advisories/unreviewed/2024/06/GHSA-3m7q-mm9c-3r6p/GHSA-3m7q-mm9c-3r6p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-82r3-68h3-qr79/GHSA-82r3-68h3-qr79.json b/advisories/unreviewed/2024/06/GHSA-82r3-68h3-qr79/GHSA-82r3-68h3-qr79.json index 28bdb209f2e..ee332b4be42 100644 --- a/advisories/unreviewed/2024/06/GHSA-82r3-68h3-qr79/GHSA-82r3-68h3-qr79.json +++ b/advisories/unreviewed/2024/06/GHSA-82r3-68h3-qr79/GHSA-82r3-68h3-qr79.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82r3-68h3-qr79", - "modified": "2024-06-08T06:30:37Z", + "modified": "2024-10-31T18:31:16Z", "published": "2024-06-08T06:30:37Z", "aliases": [ "CVE-2024-5087" @@ -60,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jm94-9wqr-p9p4/GHSA-jm94-9wqr-p9p4.json b/advisories/unreviewed/2024/06/GHSA-jm94-9wqr-p9p4/GHSA-jm94-9wqr-p9p4.json index 00426dbc127..7e867944a87 100644 --- a/advisories/unreviewed/2024/06/GHSA-jm94-9wqr-p9p4/GHSA-jm94-9wqr-p9p4.json +++ b/advisories/unreviewed/2024/06/GHSA-jm94-9wqr-p9p4/GHSA-jm94-9wqr-p9p4.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-jxrh-69wr-rj95/GHSA-jxrh-69wr-rj95.json b/advisories/unreviewed/2024/07/GHSA-jxrh-69wr-rj95/GHSA-jxrh-69wr-rj95.json index a541cb9fc48..0e6b8615ed8 100644 --- a/advisories/unreviewed/2024/07/GHSA-jxrh-69wr-rj95/GHSA-jxrh-69wr-rj95.json +++ b/advisories/unreviewed/2024/07/GHSA-jxrh-69wr-rj95/GHSA-jxrh-69wr-rj95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxrh-69wr-rj95", - "modified": "2024-07-09T21:30:38Z", + "modified": "2024-10-31T18:31:17Z", "published": "2024-07-09T21:30:38Z", "aliases": [ "CVE-2024-31312" ], "details": "In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T21:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json b/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json index 8545f26d6c3..b257a2127f0 100644 --- a/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json +++ b/advisories/unreviewed/2024/08/GHSA-2rhx-838f-x5jw/GHSA-2rhx-838f-x5jw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json b/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json index 0f42eca3e0e..1affdec6e13 100644 --- a/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json +++ b/advisories/unreviewed/2024/10/GHSA-2f7m-hc5g-9cqc/GHSA-2f7m-hc5g-9cqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2f7m-hc5g-9cqc", - "modified": "2024-10-30T21:30:41Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:41Z", "aliases": [ "CVE-2024-51424" ], "details": "An issue in Ethereum v.1.12.2 allows remote attacker to execute arbitrary code via the Owned.setOwner function", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2qq8-8fw2-5hhq/GHSA-2qq8-8fw2-5hhq.json b/advisories/unreviewed/2024/10/GHSA-2qq8-8fw2-5hhq/GHSA-2qq8-8fw2-5hhq.json index 4833a2eb820..c0b4bd6cd83 100644 --- a/advisories/unreviewed/2024/10/GHSA-2qq8-8fw2-5hhq/GHSA-2qq8-8fw2-5hhq.json +++ b/advisories/unreviewed/2024/10/GHSA-2qq8-8fw2-5hhq/GHSA-2qq8-8fw2-5hhq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json b/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json index 0b064f436ee..59a2b84f944 100644 --- a/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json +++ b/advisories/unreviewed/2024/10/GHSA-3x5w-67jh-3785/GHSA-3x5w-67jh-3785.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x5w-67jh-3785", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-31975" ], "details": "EnGenius ESR580 devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json b/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json index 06251159709..66307c266d3 100644 --- a/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json +++ b/advisories/unreviewed/2024/10/GHSA-46c8-p74g-hqqh/GHSA-46c8-p74g-hqqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46c8-p74g-hqqh", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-48241" ], "details": "An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json b/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json index 3d0769b6b4e..fe102e15ce0 100644 --- a/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json +++ b/advisories/unreviewed/2024/10/GHSA-4j93-qfwm-6xrv/GHSA-4j93-qfwm-6xrv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j93-qfwm-6xrv", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-51419" ], "details": "Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json b/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json index de794dc7b67..51f1bc7594f 100644 --- a/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json +++ b/advisories/unreviewed/2024/10/GHSA-5qhh-w7j8-f42j/GHSA-5qhh-w7j8-f42j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qhh-w7j8-f42j", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-48272" ], "details": "D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-521" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T20:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json b/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json index e09ce363ec9..ee0123be6eb 100644 --- a/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json +++ b/advisories/unreviewed/2024/10/GHSA-6723-8fqj-mw26/GHSA-6723-8fqj-mw26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6723-8fqj-mw26", - "modified": "2024-10-29T15:32:05Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-29T15:32:05Z", "aliases": [ "CVE-2024-9505" diff --git a/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json b/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json index 44f605bf568..fdfbea45834 100644 --- a/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json +++ b/advisories/unreviewed/2024/10/GHSA-6c6m-6wj2-c9h3/GHSA-6c6m-6wj2-c9h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6c6m-6wj2-c9h3", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-42041" ], "details": "The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json b/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json index f43227b9732..ba29c9a69bb 100644 --- a/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json +++ b/advisories/unreviewed/2024/10/GHSA-7w36-gg3q-f3vg/GHSA-7w36-gg3q-f3vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7w36-gg3q-f3vg", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-48093" ], "details": "Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json b/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json index 4209ffab9dc..d19fca49b33 100644 --- a/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json +++ b/advisories/unreviewed/2024/10/GHSA-84c3-765r-7fjp/GHSA-84c3-765r-7fjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84c3-765r-7fjp", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-51242" ], "details": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8cgr-vwjm-54q7/GHSA-8cgr-vwjm-54q7.json b/advisories/unreviewed/2024/10/GHSA-8cgr-vwjm-54q7/GHSA-8cgr-vwjm-54q7.json index ae7825d4faf..c943e81c04a 100644 --- a/advisories/unreviewed/2024/10/GHSA-8cgr-vwjm-54q7/GHSA-8cgr-vwjm-54q7.json +++ b/advisories/unreviewed/2024/10/GHSA-8cgr-vwjm-54q7/GHSA-8cgr-vwjm-54q7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cgr-vwjm-54q7", - "modified": "2024-10-29T03:31:06Z", + "modified": "2024-10-31T18:31:17Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50074" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparport: Proper fix for array out-of-bounds access\n\nThe recent fix for array out-of-bounds accesses replaced sprintf()\ncalls blindly with snprintf(). However, since snprintf() returns the\nwould-be-printed size, not the actually output size, the length\ncalculation can still go over the given limit.\n\nUse scnprintf() instead of snprintf(), which returns the actually\noutput letters, for addressing the potential out-of-bounds access\nproperly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T01:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9v8c-rf9v-pf96/GHSA-9v8c-rf9v-pf96.json b/advisories/unreviewed/2024/10/GHSA-9v8c-rf9v-pf96/GHSA-9v8c-rf9v-pf96.json new file mode 100644 index 00000000000..7c96eb69193 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9v8c-rf9v-pf96/GHSA-9v8c-rf9v-pf96.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v8c-rf9v-pf96", + "modified": "2024-10-31T18:31:19Z", + "published": "2024-10-31T18:31:19Z", + "aliases": [ + "CVE-2024-51430" + ], + "details": "Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name parameter on the diagnostic/add-test.php component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51430" + }, + { + "type": "WEB", + "url": "https://github.com/BLACK-SCORP10/CVE-2024-51430" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json b/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json index b3c0c45e0aa..8f7930bf733 100644 --- a/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json +++ b/advisories/unreviewed/2024/10/GHSA-c68x-6hmf-xw2p/GHSA-c68x-6hmf-xw2p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c68x-6hmf-xw2p", - "modified": "2024-10-30T21:30:41Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:41Z", "aliases": [ "CVE-2024-51425" ], "details": "Insecure Permissions vulnerability in Ethereum v.1.12.2 allows a remote attacker to escalate privileges via the WaterToken Contract.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json b/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json index 2f43476b6e1..36fabdd1541 100644 --- a/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json +++ b/advisories/unreviewed/2024/10/GHSA-cvm9-cv4j-fhwp/GHSA-cvm9-cv4j-fhwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvm9-cv4j-fhwp", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-48648" ], "details": "A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json b/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json index 21ba26707fc..ca0d9f0d284 100644 --- a/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json +++ b/advisories/unreviewed/2024/10/GHSA-f3xm-22x6-vg3g/GHSA-f3xm-22x6-vg3g.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-610", "CWE-73" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json b/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json index 4d666507161..c611f099939 100644 --- a/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json +++ b/advisories/unreviewed/2024/10/GHSA-f7rc-79mv-v26v/GHSA-f7rc-79mv-v26v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f7rc-79mv-v26v", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-51243" ], "details": "The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json b/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json index 454b22a50af..17a26c5e96c 100644 --- a/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json +++ b/advisories/unreviewed/2024/10/GHSA-fqq4-8x5p-9g5p/GHSA-fqq4-8x5p-9g5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqq4-8x5p-9g5p", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-48807" ], "details": "Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g233-2p4r-3q7v/GHSA-g233-2p4r-3q7v.json b/advisories/unreviewed/2024/10/GHSA-g233-2p4r-3q7v/GHSA-g233-2p4r-3q7v.json new file mode 100644 index 00000000000..c292f7fd936 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g233-2p4r-3q7v/GHSA-g233-2p4r-3q7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g233-2p4r-3q7v", + "modified": "2024-10-31T18:31:19Z", + "published": "2024-10-31T18:31:19Z", + "aliases": [ + "CVE-2024-8185" + ], + "details": "Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself.\n\nThis vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8185" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2024-26-vault-vulnerable-to-denial-of-service-through-memory-exhaustion-when-processing-raft-cluster-join-requests/71047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-636" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json b/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json index 4da1ac146a7..92def4cc204 100644 --- a/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json +++ b/advisories/unreviewed/2024/10/GHSA-g56g-9mxr-9pgw/GHSA-g56g-9mxr-9pgw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g56g-9mxr-9pgw", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-31973" ], "details": "Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json b/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json index 7c55b4e6917..a8b9ec8315f 100644 --- a/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json +++ b/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json b/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json index 72559f4f9c1..cf02e612265 100644 --- a/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json +++ b/advisories/unreviewed/2024/10/GHSA-hxrv-64jf-fgmr/GHSA-hxrv-64jf-fgmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxrv-64jf-fgmr", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-31972" ], "details": "EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulnerable fields this way are executed immediately when a user logs into the admin page. This affects /admin/wifi/wlan1 and /admin/wifi/wlan_guest.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json b/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json index bc033351a50..66518260d98 100644 --- a/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json +++ b/advisories/unreviewed/2024/10/GHSA-jg9m-4m4c-v7c8/GHSA-jg9m-4m4c-v7c8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jg9m-4m4c-v7c8", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-48214" ], "details": "KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jm5c-w4xp-6794/GHSA-jm5c-w4xp-6794.json b/advisories/unreviewed/2024/10/GHSA-jm5c-w4xp-6794/GHSA-jm5c-w4xp-6794.json index 75b7fc2c7cc..69f2a4f093c 100644 --- a/advisories/unreviewed/2024/10/GHSA-jm5c-w4xp-6794/GHSA-jm5c-w4xp-6794.json +++ b/advisories/unreviewed/2024/10/GHSA-jm5c-w4xp-6794/GHSA-jm5c-w4xp-6794.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-321" + "CWE-321", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json b/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json index 3380daa8baa..a9e6d93afa9 100644 --- a/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json +++ b/advisories/unreviewed/2024/10/GHSA-jp7p-mxpw-mf6m/GHSA-jp7p-mxpw-mf6m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jp7p-mxpw-mf6m", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-46531" ], "details": "phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T19:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json b/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json index 2fff5f3230e..7ad81301591 100644 --- a/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json +++ b/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwgw-4h9p-rxx6", - "modified": "2024-10-31T15:30:59Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-31T15:30:59Z", "aliases": [ "CVE-2024-51254" ], "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T14:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json b/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json index 36fbe987f8c..26cef4ae4cd 100644 --- a/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json +++ b/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p26r-gfgc-c47h", - "modified": "2024-10-15T18:30:49Z", + "modified": "2024-10-31T18:31:17Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-46528" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46528" }, + { + "type": "WEB", + "url": "https://github.com/kubesphere/kubesphere/issues/6227" + }, + { + "type": "WEB", + "url": "https://kubesphere.io" + }, { "type": "WEB", "url": "https://okankurtulus.com.tr/2024/09/09/idor-vulnerability-in-kubesphere" diff --git a/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json b/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json index 799f2df155b..4334b4c88ce 100644 --- a/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json +++ b/advisories/unreviewed/2024/10/GHSA-p8vr-968q-whxq/GHSA-p8vr-968q-whxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8vr-968q-whxq", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-37573" ], "details": "The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.talkatone.vedroid.ui.launcher.OutgoingCallInterceptor component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json b/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json index d103caeaf96..a1d6f6bc5fa 100644 --- a/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json +++ b/advisories/unreviewed/2024/10/GHSA-pxm6-wc5v-cphj/GHSA-pxm6-wc5v-cphj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxm6-wc5v-cphj", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-48202" ], "details": "icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T19:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q4vh-3r4j-jv2p/GHSA-q4vh-3r4j-jv2p.json b/advisories/unreviewed/2024/10/GHSA-q4vh-3r4j-jv2p/GHSA-q4vh-3r4j-jv2p.json index 41b046b6da6..5a4bf9b418d 100644 --- a/advisories/unreviewed/2024/10/GHSA-q4vh-3r4j-jv2p/GHSA-q4vh-3r4j-jv2p.json +++ b/advisories/unreviewed/2024/10/GHSA-q4vh-3r4j-jv2p/GHSA-q4vh-3r4j-jv2p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q4vh-3r4j-jv2p", - "modified": "2024-10-31T03:30:45Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-31T03:30:45Z", "aliases": [ "CVE-2024-48311" ], "details": "Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-31T02:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json b/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json index 9695f4972e9..1b60b2fba22 100644 --- a/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json +++ b/advisories/unreviewed/2024/10/GHSA-q97q-7j3c-mx9j/GHSA-q97q-7j3c-mx9j.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-29" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-qf6h-766m-v7v7/GHSA-qf6h-766m-v7v7.json b/advisories/unreviewed/2024/10/GHSA-qf6h-766m-v7v7/GHSA-qf6h-766m-v7v7.json new file mode 100644 index 00000000000..769a3933e1c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qf6h-766m-v7v7/GHSA-qf6h-766m-v7v7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf6h-766m-v7v7", + "modified": "2024-10-31T18:31:19Z", + "published": "2024-10-31T18:31:19Z", + "aliases": [ + "CVE-2024-51260" + ], + "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51260" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qq59-g9rc-v6vx/GHSA-qq59-g9rc-v6vx.json b/advisories/unreviewed/2024/10/GHSA-qq59-g9rc-v6vx/GHSA-qq59-g9rc-v6vx.json new file mode 100644 index 00000000000..e48eee4c882 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qq59-g9rc-v6vx/GHSA-qq59-g9rc-v6vx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq59-g9rc-v6vx", + "modified": "2024-10-31T18:31:19Z", + "published": "2024-10-31T18:31:19Z", + "aliases": [ + "CVE-2024-51255" + ], + "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51255" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json b/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json index c95d7376d44..0ce41b0230f 100644 --- a/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json +++ b/advisories/unreviewed/2024/10/GHSA-rq35-f7p2-6pp9/GHSA-rq35-f7p2-6pp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rq35-f7p2-6pp9", - "modified": "2024-10-30T21:30:41Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:41Z", "aliases": [ "CVE-2024-51427" ], "details": "An issue in Ethereum v.1.12.2 allows remote attacker to execute arbitrary code via the PepeGxng smart contract mint function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json b/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json index b5453af3241..b7dd7698d15 100644 --- a/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json +++ b/advisories/unreviewed/2024/10/GHSA-rwqj-v7mx-c4x7/GHSA-rwqj-v7mx-c4x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwqj-v7mx-c4x7", - "modified": "2024-10-30T21:30:40Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:40Z", "aliases": [ "CVE-2024-48271" ], "details": "D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-521" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T20:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vwj9-2733-p4wv/GHSA-vwj9-2733-p4wv.json b/advisories/unreviewed/2024/10/GHSA-vwj9-2733-p4wv/GHSA-vwj9-2733-p4wv.json new file mode 100644 index 00000000000..49123cfe0d1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vwj9-2733-p4wv/GHSA-vwj9-2733-p4wv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwj9-2733-p4wv", + "modified": "2024-10-31T18:31:19Z", + "published": "2024-10-31T18:31:19Z", + "aliases": [ + "CVE-2024-7883" + ], + "details": "When using Arm Cortex-M Security Extensions (CMSE), Secure stack \ncontents can be leaked to Non-secure state via floating-point registers \nwhen a Secure to Non-secure function call is made that returns a \nfloating-point value and when this is the first use of floating-point \nsince entering Secure state. This allows an attacker to read a limited \nquantity of Secure stack contents with an impact on confidentiality. \nThis issue is specific to code generated using LLVM-based compilers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7883" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-226" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json b/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json index 020bbd88cd3..c4059c422d4 100644 --- a/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json +++ b/advisories/unreviewed/2024/10/GHSA-wvj9-mrxw-ww9p/GHSA-wvj9-mrxw-ww9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvj9-mrxw-ww9p", - "modified": "2024-10-30T18:30:49Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T18:30:49Z", "aliases": [ "CVE-2024-36060" ], "details": "EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T18:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json b/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json index 1ffebfd54f6..5b010894817 100644 --- a/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json +++ b/advisories/unreviewed/2024/10/GHSA-xhx7-6233-wm3w/GHSA-xhx7-6233-wm3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xhx7-6233-wm3w", - "modified": "2024-10-30T21:30:41Z", + "modified": "2024-10-31T18:31:18Z", "published": "2024-10-30T21:30:41Z", "aliases": [ "CVE-2024-51426" ], "details": "Insecure Permissions vulnerability in Ethereum v.1.12.2 allows a remote attacker to escalate privileges via the _transfer function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-30T21:15:15Z"