From ca6e442532882dbd6823948938600a2f03e04522 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 5 Feb 2024 06:32:04 +0000 Subject: [PATCH] Publish Advisories GHSA-5rrq-v3j5-cwgm GHSA-9m57-xv2x-rj9v GHSA-fhq6-2w37-vh8q GHSA-rr4v-xrwq-7rhx GHSA-2rwq-3mr3-vq32 GHSA-32vr-pw5g-2xc5 GHSA-5mh8-m4xv-8wfr GHSA-73g2-fg3c-4vx6 GHSA-8gwc-m58g-hm5v GHSA-97rx-wgvh-p56f GHSA-987x-54mh-g54g GHSA-99ph-prqq-pm8j GHSA-fm5q-rjfv-9xc2 GHSA-grjc-q3pp-wg86 GHSA-j6qm-xgxc-g34g GHSA-jr3p-prh6-2crg GHSA-p8wr-r5ww-35j3 GHSA-px9w-2f28-5wvj GHSA-v4r9-2j27-fxxf GHSA-vqrv-v5q9-26w8 GHSA-w4r6-2p3v-r8w8 GHSA-w759-3hj5-qw74 GHSA-wpw2-f6x3-8f7j --- .../GHSA-5rrq-v3j5-cwgm.json | 4 ++ .../GHSA-9m57-xv2x-rj9v.json | 4 ++ .../GHSA-fhq6-2w37-vh8q.json | 4 ++ .../GHSA-rr4v-xrwq-7rhx.json | 4 ++ .../GHSA-2rwq-3mr3-vq32.json | 35 +++++++++++++++++ .../GHSA-32vr-pw5g-2xc5.json | 31 +++++++++++++++ .../GHSA-5mh8-m4xv-8wfr.json | 35 +++++++++++++++++ .../GHSA-73g2-fg3c-4vx6.json | 35 +++++++++++++++++ .../GHSA-8gwc-m58g-hm5v.json | 35 +++++++++++++++++ .../GHSA-97rx-wgvh-p56f.json | 38 +++++++++++++++++++ .../GHSA-987x-54mh-g54g.json | 35 +++++++++++++++++ .../GHSA-99ph-prqq-pm8j.json | 38 +++++++++++++++++++ .../GHSA-fm5q-rjfv-9xc2.json | 35 +++++++++++++++++ .../GHSA-grjc-q3pp-wg86.json | 35 +++++++++++++++++ .../GHSA-j6qm-xgxc-g34g.json | 35 +++++++++++++++++ .../GHSA-jr3p-prh6-2crg.json | 38 +++++++++++++++++++ .../GHSA-p8wr-r5ww-35j3.json | 38 +++++++++++++++++++ .../GHSA-px9w-2f28-5wvj.json | 35 +++++++++++++++++ .../GHSA-v4r9-2j27-fxxf.json | 35 +++++++++++++++++ .../GHSA-vqrv-v5q9-26w8.json | 35 +++++++++++++++++ .../GHSA-w4r6-2p3v-r8w8.json | 35 +++++++++++++++++ .../GHSA-w759-3hj5-qw74.json | 35 +++++++++++++++++ .../GHSA-wpw2-f6x3-8f7j.json | 38 +++++++++++++++++++ 23 files changed, 692 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-2rwq-3mr3-vq32/GHSA-2rwq-3mr3-vq32.json create mode 100644 advisories/unreviewed/2024/02/GHSA-32vr-pw5g-2xc5/GHSA-32vr-pw5g-2xc5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5mh8-m4xv-8wfr/GHSA-5mh8-m4xv-8wfr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8gwc-m58g-hm5v/GHSA-8gwc-m58g-hm5v.json create mode 100644 advisories/unreviewed/2024/02/GHSA-97rx-wgvh-p56f/GHSA-97rx-wgvh-p56f.json create mode 100644 advisories/unreviewed/2024/02/GHSA-987x-54mh-g54g/GHSA-987x-54mh-g54g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-99ph-prqq-pm8j/GHSA-99ph-prqq-pm8j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fm5q-rjfv-9xc2/GHSA-fm5q-rjfv-9xc2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-grjc-q3pp-wg86/GHSA-grjc-q3pp-wg86.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-jr3p-prh6-2crg/GHSA-jr3p-prh6-2crg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p8wr-r5ww-35j3/GHSA-p8wr-r5ww-35j3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-px9w-2f28-5wvj/GHSA-px9w-2f28-5wvj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v4r9-2j27-fxxf/GHSA-v4r9-2j27-fxxf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vqrv-v5q9-26w8/GHSA-vqrv-v5q9-26w8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w4r6-2p3v-r8w8/GHSA-w4r6-2p3v-r8w8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w759-3hj5-qw74/GHSA-w759-3hj5-qw74.json create mode 100644 advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json diff --git a/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json b/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json index ca3d4e28ab1..5ed40c5e0e2 100644 --- a/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json +++ b/advisories/unreviewed/2024/01/GHSA-5rrq-v3j5-cwgm/GHSA-5rrq-v3j5-cwgm.json @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUXJY3YC3VGIJW2AOHL4NZ7ZK7BRYWY/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCVKRHRWPMITSVFBHQBSNXOVJAKT547Q/" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json b/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json index 03eca1c9460..c72a513447c 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json +++ b/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUXJY3YC3VGIJW2AOHL4NZ7ZK7BRYWY/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCVKRHRWPMITSVFBHQBSNXOVJAKT547Q/" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json b/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json index ef12add82e9..1624df20fdd 100644 --- a/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json +++ b/advisories/unreviewed/2024/01/GHSA-fhq6-2w37-vh8q/GHSA-fhq6-2w37-vh8q.json @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NEUXJY3YC3VGIJW2AOHL4NZ7ZK7BRYWY/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCVKRHRWPMITSVFBHQBSNXOVJAKT547Q/" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json b/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json index 20bbf934360..7912ebd0218 100644 --- a/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json +++ b/advisories/unreviewed/2024/01/GHSA-rr4v-xrwq-7rhx/GHSA-rr4v-xrwq-7rhx.json @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OBADMKHQLJOBA32Q7XPNSYMVHVAFDCB/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHLZQ47HM64NDOHMHYO7VIJFYD5ZPPYN/" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/15/3" diff --git a/advisories/unreviewed/2024/02/GHSA-2rwq-3mr3-vq32/GHSA-2rwq-3mr3-vq32.json b/advisories/unreviewed/2024/02/GHSA-2rwq-3mr3-vq32/GHSA-2rwq-3mr3-vq32.json new file mode 100644 index 00000000000..a23d6451af3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2rwq-3mr3-vq32/GHSA-2rwq-3mr3-vq32.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rwq-3mr3-vq32", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20009" + ], + "details": "In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441150; Issue ID: ALPS08441150.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20009" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-32vr-pw5g-2xc5/GHSA-32vr-pw5g-2xc5.json b/advisories/unreviewed/2024/02/GHSA-32vr-pw5g-2xc5/GHSA-32vr-pw5g-2xc5.json new file mode 100644 index 00000000000..4e2b64c7058 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-32vr-pw5g-2xc5/GHSA-32vr-pw5g-2xc5.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32vr-pw5g-2xc5", + "modified": "2024-02-05T06:30:29Z", + "published": "2024-02-05T06:30:29Z", + "aliases": [ + "CVE-2023-47170" + ], + "details": "Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2023.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47170" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5mh8-m4xv-8wfr/GHSA-5mh8-m4xv-8wfr.json b/advisories/unreviewed/2024/02/GHSA-5mh8-m4xv-8wfr/GHSA-5mh8-m4xv-8wfr.json new file mode 100644 index 00000000000..fd58d777424 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5mh8-m4xv-8wfr/GHSA-5mh8-m4xv-8wfr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mh8-m4xv-8wfr", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20011" + ], + "details": "In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20011" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json b/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json new file mode 100644 index 00000000000..4374f3d4184 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73g2-fg3c-4vx6", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20016" + ], + "details": "In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20016" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8gwc-m58g-hm5v/GHSA-8gwc-m58g-hm5v.json b/advisories/unreviewed/2024/02/GHSA-8gwc-m58g-hm5v/GHSA-8gwc-m58g-hm5v.json new file mode 100644 index 00000000000..8ad919d0451 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8gwc-m58g-hm5v/GHSA-8gwc-m58g-hm5v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gwc-m58g-hm5v", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20003" + ], + "details": "In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01191612 (MSV-981).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20003" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-97rx-wgvh-p56f/GHSA-97rx-wgvh-p56f.json b/advisories/unreviewed/2024/02/GHSA-97rx-wgvh-p56f/GHSA-97rx-wgvh-p56f.json new file mode 100644 index 00000000000..8bec38ee935 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-97rx-wgvh-p56f/GHSA-97rx-wgvh-p56f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97rx-wgvh-p56f", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-24866" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Reflected XSS.This issue affects Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo: from n/a through 2.2.24.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/biteship/wordpress-biteship-plugin-2-2-24-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-987x-54mh-g54g/GHSA-987x-54mh-g54g.json b/advisories/unreviewed/2024/02/GHSA-987x-54mh-g54g/GHSA-987x-54mh-g54g.json new file mode 100644 index 00000000000..ff436fea400 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-987x-54mh-g54g/GHSA-987x-54mh-g54g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-987x-54mh-g54g", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20002" + ], + "details": "In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID: DTV03961715.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20002" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-99ph-prqq-pm8j/GHSA-99ph-prqq-pm8j.json b/advisories/unreviewed/2024/02/GHSA-99ph-prqq-pm8j/GHSA-99ph-prqq-pm8j.json new file mode 100644 index 00000000000..3d6b5a92c5d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-99ph-prqq-pm8j/GHSA-99ph-prqq-pm8j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99ph-prqq-pm8j", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-24870" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-iframe/wordpress-advanced-iframe-plugin-2023-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fm5q-rjfv-9xc2/GHSA-fm5q-rjfv-9xc2.json b/advisories/unreviewed/2024/02/GHSA-fm5q-rjfv-9xc2/GHSA-fm5q-rjfv-9xc2.json new file mode 100644 index 00000000000..9dde49884aa --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fm5q-rjfv-9xc2/GHSA-fm5q-rjfv-9xc2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm5q-rjfv-9xc2", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20007" + ], + "details": "In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issue ID: ALPS08441369.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20007" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-grjc-q3pp-wg86/GHSA-grjc-q3pp-wg86.json b/advisories/unreviewed/2024/02/GHSA-grjc-q3pp-wg86/GHSA-grjc-q3pp-wg86.json new file mode 100644 index 00000000000..b18596f2ec9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-grjc-q3pp-wg86/GHSA-grjc-q3pp-wg86.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grjc-q3pp-wg86", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20006" + ], + "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20006" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json b/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json new file mode 100644 index 00000000000..173335a2393 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6qm-xgxc-g34g", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20015" + ], + "details": "In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20015" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jr3p-prh6-2crg/GHSA-jr3p-prh6-2crg.json b/advisories/unreviewed/2024/02/GHSA-jr3p-prh6-2crg/GHSA-jr3p-prh6-2crg.json new file mode 100644 index 00000000000..f62839534a9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jr3p-prh6-2crg/GHSA-jr3p-prh6-2crg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr3p-prh6-2crg", + "modified": "2024-02-05T06:30:29Z", + "published": "2024-02-05T06:30:29Z", + "aliases": [ + "CVE-2023-51504" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51504" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dans-gcal/wordpress-dan-s-embedder-for-google-calendar-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p8wr-r5ww-35j3/GHSA-p8wr-r5ww-35j3.json b/advisories/unreviewed/2024/02/GHSA-p8wr-r5ww-35j3/GHSA-p8wr-r5ww-35j3.json new file mode 100644 index 00000000000..f3c6276233f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p8wr-r5ww-35j3/GHSA-p8wr-r5ww-35j3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8wr-r5ww-35j3", + "modified": "2024-02-05T06:30:30Z", + "published": "2024-02-05T06:30:30Z", + "aliases": [ + "CVE-2023-5800" + ], + "details": "Vintage,\nmember of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi\ndid not have a sufficient input validation allowing for a possible remote code\nexecution. This flaw can only be exploited after authenticating with an\noperator- or administrator-privileged service account. Axis has released patched AXIS OS\nversions for the highlighted flaw. Please refer to the Axis security advisory\nfor more information and solution.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5800" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/89/d9/99/cve-2023-5800-en-US-424339.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-px9w-2f28-5wvj/GHSA-px9w-2f28-5wvj.json b/advisories/unreviewed/2024/02/GHSA-px9w-2f28-5wvj/GHSA-px9w-2f28-5wvj.json new file mode 100644 index 00000000000..0249dbadb17 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-px9w-2f28-5wvj/GHSA-px9w-2f28-5wvj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px9w-2f28-5wvj", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20004" + ], + "details": "In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20004" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v4r9-2j27-fxxf/GHSA-v4r9-2j27-fxxf.json b/advisories/unreviewed/2024/02/GHSA-v4r9-2j27-fxxf/GHSA-v4r9-2j27-fxxf.json new file mode 100644 index 00000000000..0fa27a0ed63 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v4r9-2j27-fxxf/GHSA-v4r9-2j27-fxxf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4r9-2j27-fxxf", + "modified": "2024-02-05T06:30:30Z", + "published": "2024-02-05T06:30:30Z", + "aliases": [ + "CVE-2024-20001" + ], + "details": "In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID: DTV03961601.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20001" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vqrv-v5q9-26w8/GHSA-vqrv-v5q9-26w8.json b/advisories/unreviewed/2024/02/GHSA-vqrv-v5q9-26w8/GHSA-vqrv-v5q9-26w8.json new file mode 100644 index 00000000000..56443e3fbdc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vqrv-v5q9-26w8/GHSA-vqrv-v5q9-26w8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqrv-v5q9-26w8", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20010" + ], + "details": "In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue ID: ALPS08358560.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20010" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w4r6-2p3v-r8w8/GHSA-w4r6-2p3v-r8w8.json b/advisories/unreviewed/2024/02/GHSA-w4r6-2p3v-r8w8/GHSA-w4r6-2p3v-r8w8.json new file mode 100644 index 00000000000..463c0c847bf --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w4r6-2p3v-r8w8/GHSA-w4r6-2p3v-r8w8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4r6-2p3v-r8w8", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20012" + ], + "details": "In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20012" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w759-3hj5-qw74/GHSA-w759-3hj5-qw74.json b/advisories/unreviewed/2024/02/GHSA-w759-3hj5-qw74/GHSA-w759-3hj5-qw74.json new file mode 100644 index 00000000000..48d31151861 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w759-3hj5-qw74/GHSA-w759-3hj5-qw74.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w759-3hj5-qw74", + "modified": "2024-02-05T06:30:31Z", + "published": "2024-02-05T06:30:31Z", + "aliases": [ + "CVE-2024-20013" + ], + "details": "In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Issue ID: ALPS08308608.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20013" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/February-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json b/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json new file mode 100644 index 00000000000..59992d2cd46 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wpw2-f6x3-8f7j/GHSA-wpw2-f6x3-8f7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpw2-f6x3-8f7j", + "modified": "2024-02-05T06:30:29Z", + "published": "2024-02-05T06:30:29Z", + "aliases": [ + "CVE-2023-5677" + ], + "details": "Brandon\nRothel from QED Secure Solutions has found that the VAPIX API tcptest.cgi\ndid not have a sufficient input validation allowing for a possible remote code\nexecution. This flaw can only be exploited after authenticating with an\noperator- or administrator-privileged service account. The impact of exploiting\nthis vulnerability is lower with operator-privileges compared to\nadministrator-privileges service accounts. Axis has released patched AXIS OS\nversions for the highlighted flaw. Please refer to the Axis security advisory\nfor more information and solution. \n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5677" + }, + { + "type": "WEB", + "url": "https://www.axis.com/dam/public/a9/dd/f1/cve-2023-5677-en-US-424335.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T06:15:46Z" + } +} \ No newline at end of file