diff --git a/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json b/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json index d42f0d30d03..cd32700e466 100644 --- a/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json +++ b/advisories/unreviewed/2023/09/GHSA-j66v-q82h-4f8h/GHSA-j66v-q82h-4f8h.json @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7558" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:0089" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-42753" diff --git a/advisories/unreviewed/2023/11/GHSA-9rc5-4p7c-qp9h/GHSA-9rc5-4p7c-qp9h.json b/advisories/unreviewed/2023/11/GHSA-9rc5-4p7c-qp9h/GHSA-9rc5-4p7c-qp9h.json index a52e9094080..11318d10059 100644 --- a/advisories/unreviewed/2023/11/GHSA-9rc5-4p7c-qp9h/GHSA-9rc5-4p7c-qp9h.json +++ b/advisories/unreviewed/2023/11/GHSA-9rc5-4p7c-qp9h/GHSA-9rc5-4p7c-qp9h.json @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48121" }, + { + "type": "WEB", + "url": "https://joerngermany.github.io/ezviz_vulnerability/" + }, { "type": "WEB", "url": "https://www.ezviz.com/data-security/security-notice/detail/911" + }, + { + "type": "WEB", + "url": "https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-pfh2-hfmq-phg5/GHSA-pfh2-hfmq-phg5.json b/advisories/unreviewed/2023/12/GHSA-pfh2-hfmq-phg5/GHSA-pfh2-hfmq-phg5.json index c61d0ea620a..85c6ac1fc1d 100644 --- a/advisories/unreviewed/2023/12/GHSA-pfh2-hfmq-phg5/GHSA-pfh2-hfmq-phg5.json +++ b/advisories/unreviewed/2023/12/GHSA-pfh2-hfmq-phg5/GHSA-pfh2-hfmq-phg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfh2-hfmq-phg5", - "modified": "2023-12-27T21:31:01Z", + "modified": "2024-01-09T15:30:28Z", "published": "2023-12-27T21:31:01Z", "aliases": [ "CVE-2023-51074" ], "details": "json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-27T21:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json b/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json index 0feddaa761a..ae01f44bb7e 100644 --- a/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json +++ b/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33rw-cjxq-8rgp", - "modified": "2024-01-05T12:30:21Z", + "modified": "2024-01-09T15:30:33Z", "published": "2024-01-05T12:30:21Z", "aliases": [ "CVE-2023-51538" diff --git a/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json b/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json index 912f1947c72..9dff6c47b25 100644 --- a/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json +++ b/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3pfj-g4wr-qj3j", - "modified": "2024-01-03T00:30:23Z", + "modified": "2024-01-09T15:30:33Z", "published": "2024-01-03T00:30:23Z", "aliases": [ "CVE-2020-26625" ], "details": "A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T22:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json b/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json index a7c1ce565a4..f0d0977ad7a 100644 --- a/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json +++ b/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9frx-f993-wf86", - "modified": "2024-01-05T12:30:23Z", + "modified": "2024-01-09T15:30:33Z", "published": "2024-01-05T12:30:23Z", "aliases": [ "CVE-2023-51673" diff --git a/advisories/unreviewed/2024/01/GHSA-9r9p-4477-qf64/GHSA-9r9p-4477-qf64.json b/advisories/unreviewed/2024/01/GHSA-9r9p-4477-qf64/GHSA-9r9p-4477-qf64.json new file mode 100644 index 00000000000..0f8f4e78660 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9r9p-4477-qf64/GHSA-9r9p-4477-qf64.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r9p-4477-qf64", + "modified": "2024-01-09T15:30:33Z", + "published": "2024-01-09T15:30:33Z", + "aliases": [ + "CVE-2024-0206" + ], + "details": "\nA symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0206" + }, + { + "type": "WEB", + "url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10415" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json b/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json index da356c26e71..14a47d0afe5 100644 --- a/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json +++ b/advisories/unreviewed/2024/01/GHSA-c543-q7r3-jw94/GHSA-c543-q7r3-jw94.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-c653-w7m8-34r2/GHSA-c653-w7m8-34r2.json b/advisories/unreviewed/2024/01/GHSA-c653-w7m8-34r2/GHSA-c653-w7m8-34r2.json new file mode 100644 index 00000000000..324a1f871ec --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c653-w7m8-34r2/GHSA-c653-w7m8-34r2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c653-w7m8-34r2", + "modified": "2024-01-09T15:30:33Z", + "published": "2024-01-09T15:30:33Z", + "aliases": [ + "CVE-2023-7221" + ], + "details": "A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7221" + }, + { + "type": "WEB", + "url": "https://github.com/jylsec/vuldb/blob/main/TOTOLINK/T6/1/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249855" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249855" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g2wq-4jp5-xm5p/GHSA-g2wq-4jp5-xm5p.json b/advisories/unreviewed/2024/01/GHSA-g2wq-4jp5-xm5p/GHSA-g2wq-4jp5-xm5p.json new file mode 100644 index 00000000000..1bf6cb78d1f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g2wq-4jp5-xm5p/GHSA-g2wq-4jp5-xm5p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2wq-4jp5-xm5p", + "modified": "2024-01-09T15:30:33Z", + "published": "2024-01-09T15:30:33Z", + "aliases": [ + "CVE-2022-28975" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28975" + }, + { + "type": "WEB", + "url": "https://piotrryciak.com/posts/xss-infoblox/" + }, + { + "type": "WEB", + "url": "http://infoblox.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json b/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json index 7accf2a6ab3..65e9ec9d725 100644 --- a/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json +++ b/advisories/unreviewed/2024/01/GHSA-q9h6-c2ff-prcp/GHSA-q9h6-c2ff-prcp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-qmfw-q6m7-ff6j/GHSA-qmfw-q6m7-ff6j.json b/advisories/unreviewed/2024/01/GHSA-qmfw-q6m7-ff6j/GHSA-qmfw-q6m7-ff6j.json new file mode 100644 index 00000000000..141df2ce189 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qmfw-q6m7-ff6j/GHSA-qmfw-q6m7-ff6j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmfw-q6m7-ff6j", + "modified": "2024-01-09T15:30:33Z", + "published": "2024-01-09T15:30:33Z", + "aliases": [ + "CVE-2024-0213" + ], + "details": "\nA buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0213" + }, + { + "type": "WEB", + "url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-09T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json b/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json index 77a2a92133e..042d9cfa8dc 100644 --- a/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json +++ b/advisories/unreviewed/2024/01/GHSA-wxqg-47fv-wf96/GHSA-wxqg-47fv-wf96.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false,