Publish Advisories

GHSA-288c-cq4h-88gq
GHSA-65mr-fw35-qf44
GHSA-6j88-4936-7r36
GHSA-7jrq-v883-fw2x
GHSA-95wf-ppr8-fpf4
GHSA-c73r-qm22-rmxf
GHSA-gj96-4654-x98q
GHSA-pxv9-wjf4-mr7m
GHSA-qcf9-x527-mw6v
This commit is contained in:
advisory-database[bot]
2024-03-15 00:31:44 +00:00
parent 1174577fb0
commit c95f00aa49
9 changed files with 525 additions and 217 deletions
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65mr-fw35-qf44",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2024-26475"
],
"details": "An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26475"
},
{
"type": "WEB",
"url": "https://github.com/TronciuVlad/CVE-2024-26475"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T22:15:22Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6j88-4936-7r36",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2023-50677"
],
"details": "An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50677"
},
{
"type": "WEB",
"url": "https://gist.github.com/DMIND-NLL/b61b8d8d20271adf60fc717b3b48faff"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T22:15:22Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jrq-v883-fw2x",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2024-2249"
],
"details": "The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output escaping the user supplied attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2249"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3050316/lastudio-element-kit/trunk/includes/extensions/elementor/wrapper-link.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5113170a-5a53-4e53-84e6-56d9ba0740ed?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T22:15:22Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-95wf-ppr8-fpf4",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2023-42286"
],
"details": "There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42286"
},
{
"type": "WEB",
"url": "https://github.com/Nacl122/CVEReport/blob/main/CVE-2023-42286/CVE-2023-42286.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T22:15:22Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c73r-qm22-rmxf",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2024-1853"
],
"details": "Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1853"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/ellington"
},
{
"type": "WEB",
"url": "https://zemana.com/us/antilogger.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-283"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T23:15:45Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gj96-4654-x98q",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2024-26503"
],
"details": "Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to certbadge.php endpoint.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26503"
},
{
"type": "WEB",
"url": "https://www.less-secure.com/2024/03/open-eclass-cve-2024-26503-unrestricted.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T22:15:22Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxv9-wjf4-mr7m",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2024-26246"
],
"details": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26246"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26246"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T23:15:46Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qcf9-x527-mw6v",
"modified": "2024-03-15T00:30:22Z",
"published": "2024-03-15T00:30:22Z",
"aliases": [
"CVE-2024-26163"
],
"details": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26163"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26163"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T23:15:45Z"
}
}