diff --git a/advisories/unreviewed/2023/09/GHSA-qmqc-m76c-pmrm/GHSA-qmqc-m76c-pmrm.json b/advisories/unreviewed/2023/09/GHSA-qmqc-m76c-pmrm/GHSA-qmqc-m76c-pmrm.json index ddea807f3d2..f9fa4cb9a41 100644 --- a/advisories/unreviewed/2023/09/GHSA-qmqc-m76c-pmrm/GHSA-qmqc-m76c-pmrm.json +++ b/advisories/unreviewed/2023/09/GHSA-qmqc-m76c-pmrm/GHSA-qmqc-m76c-pmrm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmqc-m76c-pmrm", - "modified": "2023-09-12T18:30:22Z", + "modified": "2024-01-05T18:30:20Z", "published": "2023-09-12T18:30:22Z", "aliases": [ "CVE-2023-38146" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38146" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176391/Themebleed-Windows-11-Themes-Arbitrary-Code-Execution.html" } ], "database_specific": { "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-12T17:15:17Z" diff --git a/advisories/unreviewed/2023/12/GHSA-226q-4p65-9p8c/GHSA-226q-4p65-9p8c.json b/advisories/unreviewed/2023/12/GHSA-226q-4p65-9p8c/GHSA-226q-4p65-9p8c.json index 540fa68bdf8..6a85f7d270d 100644 --- a/advisories/unreviewed/2023/12/GHSA-226q-4p65-9p8c/GHSA-226q-4p65-9p8c.json +++ b/advisories/unreviewed/2023/12/GHSA-226q-4p65-9p8c/GHSA-226q-4p65-9p8c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-25jp-v3h8-rhhg/GHSA-25jp-v3h8-rhhg.json b/advisories/unreviewed/2023/12/GHSA-25jp-v3h8-rhhg/GHSA-25jp-v3h8-rhhg.json index 5f2ce8c24ee..681c8c99bf6 100644 --- a/advisories/unreviewed/2023/12/GHSA-25jp-v3h8-rhhg/GHSA-25jp-v3h8-rhhg.json +++ b/advisories/unreviewed/2023/12/GHSA-25jp-v3h8-rhhg/GHSA-25jp-v3h8-rhhg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25jp-v3h8-rhhg", - "modified": "2023-12-29T15:30:36Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:36Z", "aliases": [ "CVE-2023-51378" diff --git a/advisories/unreviewed/2023/12/GHSA-2cfj-r94q-xgfj/GHSA-2cfj-r94q-xgfj.json b/advisories/unreviewed/2023/12/GHSA-2cfj-r94q-xgfj/GHSA-2cfj-r94q-xgfj.json index 9edac634f89..cd3b3597415 100644 --- a/advisories/unreviewed/2023/12/GHSA-2cfj-r94q-xgfj/GHSA-2cfj-r94q-xgfj.json +++ b/advisories/unreviewed/2023/12/GHSA-2cfj-r94q-xgfj/GHSA-2cfj-r94q-xgfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cfj-r94q-xgfj", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-50881" diff --git a/advisories/unreviewed/2023/12/GHSA-2gh4-q9qq-fc54/GHSA-2gh4-q9qq-fc54.json b/advisories/unreviewed/2023/12/GHSA-2gh4-q9qq-fc54/GHSA-2gh4-q9qq-fc54.json index 93d5f39ad17..4b4654e059d 100644 --- a/advisories/unreviewed/2023/12/GHSA-2gh4-q9qq-fc54/GHSA-2gh4-q9qq-fc54.json +++ b/advisories/unreviewed/2023/12/GHSA-2gh4-q9qq-fc54/GHSA-2gh4-q9qq-fc54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gh4-q9qq-fc54", - "modified": "2023-12-29T12:30:41Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T12:30:41Z", "aliases": [ "CVE-2023-50901" diff --git a/advisories/unreviewed/2023/12/GHSA-398r-735q-g9wg/GHSA-398r-735q-g9wg.json b/advisories/unreviewed/2023/12/GHSA-398r-735q-g9wg/GHSA-398r-735q-g9wg.json index ac1535eceae..a9ebce5fdb6 100644 --- a/advisories/unreviewed/2023/12/GHSA-398r-735q-g9wg/GHSA-398r-735q-g9wg.json +++ b/advisories/unreviewed/2023/12/GHSA-398r-735q-g9wg/GHSA-398r-735q-g9wg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-398r-735q-g9wg", - "modified": "2023-12-28T12:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T12:30:19Z", "aliases": [ "CVE-2023-50853" diff --git a/advisories/unreviewed/2023/12/GHSA-3rp7-3qfg-r7f3/GHSA-3rp7-3qfg-r7f3.json b/advisories/unreviewed/2023/12/GHSA-3rp7-3qfg-r7f3/GHSA-3rp7-3qfg-r7f3.json index 9eda50aee7e..44a0c4d7b8a 100644 --- a/advisories/unreviewed/2023/12/GHSA-3rp7-3qfg-r7f3/GHSA-3rp7-3qfg-r7f3.json +++ b/advisories/unreviewed/2023/12/GHSA-3rp7-3qfg-r7f3/GHSA-3rp7-3qfg-r7f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3rp7-3qfg-r7f3", - "modified": "2023-12-29T15:30:36Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:36Z", "aliases": [ "CVE-2023-51470" diff --git a/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json b/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json index bacd8f4aac2..8c4516f389e 100644 --- a/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json +++ b/advisories/unreviewed/2023/12/GHSA-44xq-r8h3-q4q6/GHSA-44xq-r8h3-q4q6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/openssh/openssh-portable/commit/881d9c6af9da4257c69c327c4e2f1508b2fa754b" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240105-0005/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5586" diff --git a/advisories/unreviewed/2023/12/GHSA-456m-rhjg-6cq3/GHSA-456m-rhjg-6cq3.json b/advisories/unreviewed/2023/12/GHSA-456m-rhjg-6cq3/GHSA-456m-rhjg-6cq3.json index 2da3f9a86a6..7222a3013a5 100644 --- a/advisories/unreviewed/2023/12/GHSA-456m-rhjg-6cq3/GHSA-456m-rhjg-6cq3.json +++ b/advisories/unreviewed/2023/12/GHSA-456m-rhjg-6cq3/GHSA-456m-rhjg-6cq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-456m-rhjg-6cq3", - "modified": "2023-12-28T12:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T12:30:19Z", "aliases": [ "CVE-2023-50849" diff --git a/advisories/unreviewed/2023/12/GHSA-5gfw-4p9h-vh8j/GHSA-5gfw-4p9h-vh8j.json b/advisories/unreviewed/2023/12/GHSA-5gfw-4p9h-vh8j/GHSA-5gfw-4p9h-vh8j.json index 8b4068ad837..7ed1dfb525e 100644 --- a/advisories/unreviewed/2023/12/GHSA-5gfw-4p9h-vh8j/GHSA-5gfw-4p9h-vh8j.json +++ b/advisories/unreviewed/2023/12/GHSA-5gfw-4p9h-vh8j/GHSA-5gfw-4p9h-vh8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gfw-4p9h-vh8j", - "modified": "2023-12-29T15:30:36Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:36Z", "aliases": [ "CVE-2023-51545" diff --git a/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json b/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json index 1056fa00d26..f407059a166 100644 --- a/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json +++ b/advisories/unreviewed/2023/12/GHSA-5mq4-x9g5-4vc4/GHSA-5mq4-x9g5-4vc4.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202312-17" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240105-0005/" + }, { "type": "WEB", "url": "https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.html" diff --git a/advisories/unreviewed/2023/12/GHSA-5rcq-25vc-g8qr/GHSA-5rcq-25vc-g8qr.json b/advisories/unreviewed/2023/12/GHSA-5rcq-25vc-g8qr/GHSA-5rcq-25vc-g8qr.json index 961d3b57a54..02a5ca1aa7b 100644 --- a/advisories/unreviewed/2023/12/GHSA-5rcq-25vc-g8qr/GHSA-5rcq-25vc-g8qr.json +++ b/advisories/unreviewed/2023/12/GHSA-5rcq-25vc-g8qr/GHSA-5rcq-25vc-g8qr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rcq-25vc-g8qr", - "modified": "2023-12-24T06:30:32Z", + "modified": "2024-01-05T18:30:23Z", "published": "2023-12-24T06:30:32Z", "aliases": [ "CVE-2023-51765" ], "details": "sendmail through at least 8.14.7 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the sendmail server, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports . but some other popular e-mail servers do not.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -81,9 +84,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-24T06:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-5rp3-83j5-w2g4/GHSA-5rp3-83j5-w2g4.json b/advisories/unreviewed/2023/12/GHSA-5rp3-83j5-w2g4/GHSA-5rp3-83j5-w2g4.json index a11295c6979..4c87bbdde96 100644 --- a/advisories/unreviewed/2023/12/GHSA-5rp3-83j5-w2g4/GHSA-5rp3-83j5-w2g4.json +++ b/advisories/unreviewed/2023/12/GHSA-5rp3-83j5-w2g4/GHSA-5rp3-83j5-w2g4.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://binarly.io/posts/finding_logofail_the_dangers_of_image_parsing_during_system_boot/index.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240105-0002/" + }, { "type": "WEB", "url": "https://www.insyde.com/security-pledge" diff --git a/advisories/unreviewed/2023/12/GHSA-6348-qpvc-cw5w/GHSA-6348-qpvc-cw5w.json b/advisories/unreviewed/2023/12/GHSA-6348-qpvc-cw5w/GHSA-6348-qpvc-cw5w.json index 6c491cc6280..196162d249f 100644 --- a/advisories/unreviewed/2023/12/GHSA-6348-qpvc-cw5w/GHSA-6348-qpvc-cw5w.json +++ b/advisories/unreviewed/2023/12/GHSA-6348-qpvc-cw5w/GHSA-6348-qpvc-cw5w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-6hxc-6hfm-wgvq/GHSA-6hxc-6hfm-wgvq.json b/advisories/unreviewed/2023/12/GHSA-6hxc-6hfm-wgvq/GHSA-6hxc-6hfm-wgvq.json index 14c6a6c6638..ae9bcc2d72c 100644 --- a/advisories/unreviewed/2023/12/GHSA-6hxc-6hfm-wgvq/GHSA-6hxc-6hfm-wgvq.json +++ b/advisories/unreviewed/2023/12/GHSA-6hxc-6hfm-wgvq/GHSA-6hxc-6hfm-wgvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hxc-6hfm-wgvq", - "modified": "2023-12-29T15:30:37Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:37Z", "aliases": [ "CVE-2023-51468" diff --git a/advisories/unreviewed/2023/12/GHSA-6p7c-wj96-hf8h/GHSA-6p7c-wj96-hf8h.json b/advisories/unreviewed/2023/12/GHSA-6p7c-wj96-hf8h/GHSA-6p7c-wj96-hf8h.json index 76772dd9ff5..81707c7a62d 100644 --- a/advisories/unreviewed/2023/12/GHSA-6p7c-wj96-hf8h/GHSA-6p7c-wj96-hf8h.json +++ b/advisories/unreviewed/2023/12/GHSA-6p7c-wj96-hf8h/GHSA-6p7c-wj96-hf8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6p7c-wj96-hf8h", - "modified": "2023-12-29T15:30:36Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:36Z", "aliases": [ "CVE-2023-51414" diff --git a/advisories/unreviewed/2023/12/GHSA-6pvf-3c4h-qg2h/GHSA-6pvf-3c4h-qg2h.json b/advisories/unreviewed/2023/12/GHSA-6pvf-3c4h-qg2h/GHSA-6pvf-3c4h-qg2h.json index 91b53d75065..65ee780bfe3 100644 --- a/advisories/unreviewed/2023/12/GHSA-6pvf-3c4h-qg2h/GHSA-6pvf-3c4h-qg2h.json +++ b/advisories/unreviewed/2023/12/GHSA-6pvf-3c4h-qg2h/GHSA-6pvf-3c4h-qg2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pvf-3c4h-qg2h", - "modified": "2023-12-28T06:30:24Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T06:30:24Z", "aliases": [ "CVE-2023-51006" ], "details": "An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T04:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-6w7f-vrx5-q78q/GHSA-6w7f-vrx5-q78q.json b/advisories/unreviewed/2023/12/GHSA-6w7f-vrx5-q78q/GHSA-6w7f-vrx5-q78q.json index 73b1097b53e..9834816aee5 100644 --- a/advisories/unreviewed/2023/12/GHSA-6w7f-vrx5-q78q/GHSA-6w7f-vrx5-q78q.json +++ b/advisories/unreviewed/2023/12/GHSA-6w7f-vrx5-q78q/GHSA-6w7f-vrx5-q78q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6w7f-vrx5-q78q", - "modified": "2023-12-28T15:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T15:30:19Z", "aliases": [ "CVE-2023-50470" ], "details": "A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-87fm-wcxm-mcmx/GHSA-87fm-wcxm-mcmx.json b/advisories/unreviewed/2023/12/GHSA-87fm-wcxm-mcmx/GHSA-87fm-wcxm-mcmx.json index 0cb43aa6835..424b106a05b 100644 --- a/advisories/unreviewed/2023/12/GHSA-87fm-wcxm-mcmx/GHSA-87fm-wcxm-mcmx.json +++ b/advisories/unreviewed/2023/12/GHSA-87fm-wcxm-mcmx/GHSA-87fm-wcxm-mcmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87fm-wcxm-mcmx", - "modified": "2023-12-12T18:31:31Z", + "modified": "2024-01-05T18:30:21Z", "published": "2023-12-06T18:31:05Z", "aliases": [ "CVE-2023-39538" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023009.pdf" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240105-0003/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-8cp4-ffj7-48q5/GHSA-8cp4-ffj7-48q5.json b/advisories/unreviewed/2023/12/GHSA-8cp4-ffj7-48q5/GHSA-8cp4-ffj7-48q5.json index fb18518c042..20be97667ee 100644 --- a/advisories/unreviewed/2023/12/GHSA-8cp4-ffj7-48q5/GHSA-8cp4-ffj7-48q5.json +++ b/advisories/unreviewed/2023/12/GHSA-8cp4-ffj7-48q5/GHSA-8cp4-ffj7-48q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8cp4-ffj7-48q5", - "modified": "2023-12-29T15:30:37Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:37Z", "aliases": [ "CVE-2023-51527" diff --git a/advisories/unreviewed/2023/12/GHSA-9cjp-v48x-fx42/GHSA-9cjp-v48x-fx42.json b/advisories/unreviewed/2023/12/GHSA-9cjp-v48x-fx42/GHSA-9cjp-v48x-fx42.json index 2660d01b677..477dad6f872 100644 --- a/advisories/unreviewed/2023/12/GHSA-9cjp-v48x-fx42/GHSA-9cjp-v48x-fx42.json +++ b/advisories/unreviewed/2023/12/GHSA-9cjp-v48x-fx42/GHSA-9cjp-v48x-fx42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9cjp-v48x-fx42", - "modified": "2023-12-28T15:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T15:30:19Z", "aliases": [ "CVE-2023-46987" ], "details": "SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9mc7-vqwr-28vc/GHSA-9mc7-vqwr-28vc.json b/advisories/unreviewed/2023/12/GHSA-9mc7-vqwr-28vc/GHSA-9mc7-vqwr-28vc.json index 136b1d3356e..f1cec53e540 100644 --- a/advisories/unreviewed/2023/12/GHSA-9mc7-vqwr-28vc/GHSA-9mc7-vqwr-28vc.json +++ b/advisories/unreviewed/2023/12/GHSA-9mc7-vqwr-28vc/GHSA-9mc7-vqwr-28vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mc7-vqwr-28vc", - "modified": "2023-12-29T12:30:41Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T12:30:41Z", "aliases": [ "CVE-2023-50896" diff --git a/advisories/unreviewed/2023/12/GHSA-9p9v-6p34-p6gj/GHSA-9p9v-6p34-p6gj.json b/advisories/unreviewed/2023/12/GHSA-9p9v-6p34-p6gj/GHSA-9p9v-6p34-p6gj.json index 325a51fd94f..a2490e46f0f 100644 --- a/advisories/unreviewed/2023/12/GHSA-9p9v-6p34-p6gj/GHSA-9p9v-6p34-p6gj.json +++ b/advisories/unreviewed/2023/12/GHSA-9p9v-6p34-p6gj/GHSA-9p9v-6p34-p6gj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9p9v-6p34-p6gj", - "modified": "2023-12-30T18:30:37Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-30T18:30:37Z", "aliases": [ "CVE-2023-50589" ], "details": "Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter on the login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-30T17:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-9q5r-h9jj-276p/GHSA-9q5r-h9jj-276p.json b/advisories/unreviewed/2023/12/GHSA-9q5r-h9jj-276p/GHSA-9q5r-h9jj-276p.json index a451cb33517..83f39c722da 100644 --- a/advisories/unreviewed/2023/12/GHSA-9q5r-h9jj-276p/GHSA-9q5r-h9jj-276p.json +++ b/advisories/unreviewed/2023/12/GHSA-9q5r-h9jj-276p/GHSA-9q5r-h9jj-276p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9q5r-h9jj-276p", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-50332" ], "details": "Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6. If this vulnerability is exploited, a user may delete or suspend its own account without the user's intention.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-c8r9-3pm5-m364/GHSA-c8r9-3pm5-m364.json b/advisories/unreviewed/2023/12/GHSA-c8r9-3pm5-m364/GHSA-c8r9-3pm5-m364.json index c44744e3463..98e58f18954 100644 --- a/advisories/unreviewed/2023/12/GHSA-c8r9-3pm5-m364/GHSA-c8r9-3pm5-m364.json +++ b/advisories/unreviewed/2023/12/GHSA-c8r9-3pm5-m364/GHSA-c8r9-3pm5-m364.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-f58r-qgwq-jfxv/GHSA-f58r-qgwq-jfxv.json b/advisories/unreviewed/2023/12/GHSA-f58r-qgwq-jfxv/GHSA-f58r-qgwq-jfxv.json index 8bafd7c2c00..2b548112758 100644 --- a/advisories/unreviewed/2023/12/GHSA-f58r-qgwq-jfxv/GHSA-f58r-qgwq-jfxv.json +++ b/advisories/unreviewed/2023/12/GHSA-f58r-qgwq-jfxv/GHSA-f58r-qgwq-jfxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f58r-qgwq-jfxv", - "modified": "2023-12-28T00:30:20Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T00:30:20Z", "aliases": [ "CVE-2023-46918" ], "details": "Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-27T22:15:16Z" diff --git a/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json b/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json index 5b9dd944d7b..eb89db51a3b 100644 --- a/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json +++ b/advisories/unreviewed/2023/12/GHSA-fvcr-3mhq-rw2x/GHSA-fvcr-3mhq-rw2x.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-g2fv-w76j-v7p7/GHSA-g2fv-w76j-v7p7.json b/advisories/unreviewed/2023/12/GHSA-g2fv-w76j-v7p7/GHSA-g2fv-w76j-v7p7.json index 56e8841d041..569cb87255a 100644 --- a/advisories/unreviewed/2023/12/GHSA-g2fv-w76j-v7p7/GHSA-g2fv-w76j-v7p7.json +++ b/advisories/unreviewed/2023/12/GHSA-g2fv-w76j-v7p7/GHSA-g2fv-w76j-v7p7.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1272" + "CWE-1272", + "CWE-212" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-gjh4-p42j-ccc9/GHSA-gjh4-p42j-ccc9.json b/advisories/unreviewed/2023/12/GHSA-gjh4-p42j-ccc9/GHSA-gjh4-p42j-ccc9.json index ad295cdb55b..9b08024f3b8 100644 --- a/advisories/unreviewed/2023/12/GHSA-gjh4-p42j-ccc9/GHSA-gjh4-p42j-ccc9.json +++ b/advisories/unreviewed/2023/12/GHSA-gjh4-p42j-ccc9/GHSA-gjh4-p42j-ccc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjh4-p42j-ccc9", - "modified": "2023-12-29T15:30:34Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:34Z", "aliases": [ "CVE-2023-51354" diff --git a/advisories/unreviewed/2023/12/GHSA-gvx9-4gx5-gpvm/GHSA-gvx9-4gx5-gpvm.json b/advisories/unreviewed/2023/12/GHSA-gvx9-4gx5-gpvm/GHSA-gvx9-4gx5-gpvm.json index 5721150504c..1bc6663d944 100644 --- a/advisories/unreviewed/2023/12/GHSA-gvx9-4gx5-gpvm/GHSA-gvx9-4gx5-gpvm.json +++ b/advisories/unreviewed/2023/12/GHSA-gvx9-4gx5-gpvm/GHSA-gvx9-4gx5-gpvm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-h26v-qgm2-w7j4/GHSA-h26v-qgm2-w7j4.json b/advisories/unreviewed/2023/12/GHSA-h26v-qgm2-w7j4/GHSA-h26v-qgm2-w7j4.json index dda94bef513..1e23096780a 100644 --- a/advisories/unreviewed/2023/12/GHSA-h26v-qgm2-w7j4/GHSA-h26v-qgm2-w7j4.json +++ b/advisories/unreviewed/2023/12/GHSA-h26v-qgm2-w7j4/GHSA-h26v-qgm2-w7j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h26v-qgm2-w7j4", - "modified": "2023-12-26T15:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-26T15:30:19Z", "aliases": [ "CVE-2023-51104" ], "details": "A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon pnm_binary_read_image() of load-pnm.c line 527.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T15:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hh7p-pq2q-6p59/GHSA-hh7p-pq2q-6p59.json b/advisories/unreviewed/2023/12/GHSA-hh7p-pq2q-6p59/GHSA-hh7p-pq2q-6p59.json index 5a4013b4f9e..c3d38b714e3 100644 --- a/advisories/unreviewed/2023/12/GHSA-hh7p-pq2q-6p59/GHSA-hh7p-pq2q-6p59.json +++ b/advisories/unreviewed/2023/12/GHSA-hh7p-pq2q-6p59/GHSA-hh7p-pq2q-6p59.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hh7p-pq2q-6p59", - "modified": "2023-12-26T15:30:20Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-26T15:30:20Z", "aliases": [ "CVE-2023-51107" ], "details": "A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon compute_color() of jquant2.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T15:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-hwcx-3vrw-26jm/GHSA-hwcx-3vrw-26jm.json b/advisories/unreviewed/2023/12/GHSA-hwcx-3vrw-26jm/GHSA-hwcx-3vrw-26jm.json index bb948b5dd53..81605409c32 100644 --- a/advisories/unreviewed/2023/12/GHSA-hwcx-3vrw-26jm/GHSA-hwcx-3vrw-26jm.json +++ b/advisories/unreviewed/2023/12/GHSA-hwcx-3vrw-26jm/GHSA-hwcx-3vrw-26jm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwcx-3vrw-26jm", - "modified": "2023-12-29T12:30:41Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-29T12:30:41Z", "aliases": [ "CVE-2022-44589" diff --git a/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json b/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json index 3cc77fce02f..740366d6654 100644 --- a/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json +++ b/advisories/unreviewed/2023/12/GHSA-j5jm-hg4x-w8rx/GHSA-j5jm-hg4x-w8rx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5jm-hg4x-w8rx", - "modified": "2023-12-24T06:30:31Z", + "modified": "2024-01-05T18:30:23Z", "published": "2023-12-24T06:30:31Z", "aliases": [ "CVE-2023-51764" ], "details": "Postfix through 3.8.4 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the Postfix server, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports . but some other popular e-mail servers do not. To prevent attack variants (by always disallowing without ), a different solution is required: the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-24T05:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jq4q-j8h2-mg3r/GHSA-jq4q-j8h2-mg3r.json b/advisories/unreviewed/2023/12/GHSA-jq4q-j8h2-mg3r/GHSA-jq4q-j8h2-mg3r.json index 93368c03a2f..3c771ef20f1 100644 --- a/advisories/unreviewed/2023/12/GHSA-jq4q-j8h2-mg3r/GHSA-jq4q-j8h2-mg3r.json +++ b/advisories/unreviewed/2023/12/GHSA-jq4q-j8h2-mg3r/GHSA-jq4q-j8h2-mg3r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jq4q-j8h2-mg3r", - "modified": "2023-12-28T00:30:20Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T00:30:20Z", "aliases": [ "CVE-2023-49002" ], "details": "An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-27T22:15:16Z" diff --git a/advisories/unreviewed/2023/12/GHSA-m49c-46jg-fj9c/GHSA-m49c-46jg-fj9c.json b/advisories/unreviewed/2023/12/GHSA-m49c-46jg-fj9c/GHSA-m49c-46jg-fj9c.json index 6763458cc09..470271a12c2 100644 --- a/advisories/unreviewed/2023/12/GHSA-m49c-46jg-fj9c/GHSA-m49c-46jg-fj9c.json +++ b/advisories/unreviewed/2023/12/GHSA-m49c-46jg-fj9c/GHSA-m49c-46jg-fj9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m49c-46jg-fj9c", - "modified": "2023-12-26T15:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-26T15:30:19Z", "aliases": [ "CVE-2023-51103" ], "details": "A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon fz_new_pixmap_from_float_data() of pixmap.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T15:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-mv97-cv2v-gqc7/GHSA-mv97-cv2v-gqc7.json b/advisories/unreviewed/2023/12/GHSA-mv97-cv2v-gqc7/GHSA-mv97-cv2v-gqc7.json index c304eb2bc23..3bc75b2a983 100644 --- a/advisories/unreviewed/2023/12/GHSA-mv97-cv2v-gqc7/GHSA-mv97-cv2v-gqc7.json +++ b/advisories/unreviewed/2023/12/GHSA-mv97-cv2v-gqc7/GHSA-mv97-cv2v-gqc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mv97-cv2v-gqc7", - "modified": "2023-12-30T18:30:37Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-30T18:30:37Z", "aliases": [ "CVE-2023-50651" ], "details": "TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-30T17:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json b/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json index 45def5a60dd..6b6eb6447c0 100644 --- a/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json +++ b/advisories/unreviewed/2023/12/GHSA-pxf9-jjq8-hvw8/GHSA-pxf9-jjq8-hvw8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-rf9c-wvjw-39jq/GHSA-rf9c-wvjw-39jq.json b/advisories/unreviewed/2023/12/GHSA-rf9c-wvjw-39jq/GHSA-rf9c-wvjw-39jq.json index a5030bef5ab..41930661c36 100644 --- a/advisories/unreviewed/2023/12/GHSA-rf9c-wvjw-39jq/GHSA-rf9c-wvjw-39jq.json +++ b/advisories/unreviewed/2023/12/GHSA-rf9c-wvjw-39jq/GHSA-rf9c-wvjw-39jq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-rqjq-h72m-vgr3/GHSA-rqjq-h72m-vgr3.json b/advisories/unreviewed/2023/12/GHSA-rqjq-h72m-vgr3/GHSA-rqjq-h72m-vgr3.json index fbd816b33d4..4ecaae9e219 100644 --- a/advisories/unreviewed/2023/12/GHSA-rqjq-h72m-vgr3/GHSA-rqjq-h72m-vgr3.json +++ b/advisories/unreviewed/2023/12/GHSA-rqjq-h72m-vgr3/GHSA-rqjq-h72m-vgr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqjq-h72m-vgr3", - "modified": "2023-12-28T03:30:26Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T03:30:26Z", "aliases": [ "CVE-2023-34829" ], "details": "Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T03:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-v837-vv94-4c8w/GHSA-v837-vv94-4c8w.json b/advisories/unreviewed/2023/12/GHSA-v837-vv94-4c8w/GHSA-v837-vv94-4c8w.json index ac296510642..6a10b55fedc 100644 --- a/advisories/unreviewed/2023/12/GHSA-v837-vv94-4c8w/GHSA-v837-vv94-4c8w.json +++ b/advisories/unreviewed/2023/12/GHSA-v837-vv94-4c8w/GHSA-v837-vv94-4c8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v837-vv94-4c8w", - "modified": "2023-12-30T18:30:37Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-30T18:30:37Z", "aliases": [ "CVE-2023-50110" ], "details": "TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-30T17:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json b/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json index 133d06e7410..8be71a370f8 100644 --- a/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json +++ b/advisories/unreviewed/2023/12/GHSA-w8hx-5jwc-x79j/GHSA-w8hx-5jwc-x79j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8hx-5jwc-x79j", - "modified": "2023-12-26T15:30:19Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-26T15:30:19Z", "aliases": [ "CVE-2023-51105" ], "details": "A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T15:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-wfv4-v3vj-4vq5/GHSA-wfv4-v3vj-4vq5.json b/advisories/unreviewed/2023/12/GHSA-wfv4-v3vj-4vq5/GHSA-wfv4-v3vj-4vq5.json index 913ab6a7006..2c2084b5554 100644 --- a/advisories/unreviewed/2023/12/GHSA-wfv4-v3vj-4vq5/GHSA-wfv4-v3vj-4vq5.json +++ b/advisories/unreviewed/2023/12/GHSA-wfv4-v3vj-4vq5/GHSA-wfv4-v3vj-4vq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfv4-v3vj-4vq5", - "modified": "2023-12-29T15:30:37Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T15:30:37Z", "aliases": [ "CVE-2023-51473" diff --git a/advisories/unreviewed/2023/12/GHSA-whp6-m9cx-g59h/GHSA-whp6-m9cx-g59h.json b/advisories/unreviewed/2023/12/GHSA-whp6-m9cx-g59h/GHSA-whp6-m9cx-g59h.json index 4db47d45711..d9b1bde642f 100644 --- a/advisories/unreviewed/2023/12/GHSA-whp6-m9cx-g59h/GHSA-whp6-m9cx-g59h.json +++ b/advisories/unreviewed/2023/12/GHSA-whp6-m9cx-g59h/GHSA-whp6-m9cx-g59h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-whp6-m9cx-g59h", - "modified": "2023-12-29T00:30:38Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-29T00:30:38Z", "aliases": [ "CVE-2023-52152" ], "details": "mupnp/net/uri.c in mUPnP for C through 3.0.2 has an out-of-bounds read and application crash because it lacks a certain host length recalculation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T23:15:44Z" diff --git a/advisories/unreviewed/2023/12/GHSA-wqhq-5qc6-w4g3/GHSA-wqhq-5qc6-w4g3.json b/advisories/unreviewed/2023/12/GHSA-wqhq-5qc6-w4g3/GHSA-wqhq-5qc6-w4g3.json index 9bc53d0a066..abc7b8b83a9 100644 --- a/advisories/unreviewed/2023/12/GHSA-wqhq-5qc6-w4g3/GHSA-wqhq-5qc6-w4g3.json +++ b/advisories/unreviewed/2023/12/GHSA-wqhq-5qc6-w4g3/GHSA-wqhq-5qc6-w4g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqhq-5qc6-w4g3", - "modified": "2023-12-28T06:30:24Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-28T06:30:24Z", "aliases": [ "CVE-2023-51010" ], "details": "An issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL without any filtering or checking.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-28T04:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-x9w6-j9p6-2qp6/GHSA-x9w6-j9p6-2qp6.json b/advisories/unreviewed/2023/12/GHSA-x9w6-j9p6-2qp6/GHSA-x9w6-j9p6-2qp6.json index d6dc697c013..7b4c323b49d 100644 --- a/advisories/unreviewed/2023/12/GHSA-x9w6-j9p6-2qp6/GHSA-x9w6-j9p6-2qp6.json +++ b/advisories/unreviewed/2023/12/GHSA-x9w6-j9p6-2qp6/GHSA-x9w6-j9p6-2qp6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9w6-j9p6-2qp6", - "modified": "2023-12-26T15:30:20Z", + "modified": "2024-01-05T18:30:24Z", "published": "2023-12-26T15:30:20Z", "aliases": [ "CVE-2023-51106" ], "details": "A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon pnm_binary_read_image() of load-pnm.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T15:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-xfmh-hq5h-g7mp/GHSA-xfmh-hq5h-g7mp.json b/advisories/unreviewed/2023/12/GHSA-xfmh-hq5h-g7mp/GHSA-xfmh-hq5h-g7mp.json index 7ca25f8e505..bbd5a25ac1d 100644 --- a/advisories/unreviewed/2023/12/GHSA-xfmh-hq5h-g7mp/GHSA-xfmh-hq5h-g7mp.json +++ b/advisories/unreviewed/2023/12/GHSA-xfmh-hq5h-g7mp/GHSA-xfmh-hq5h-g7mp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfmh-hq5h-g7mp", - "modified": "2023-12-29T12:30:42Z", + "modified": "2024-01-05T18:30:25Z", "published": "2023-12-29T12:30:42Z", "aliases": [ "CVE-2023-50889" diff --git a/advisories/unreviewed/2023/12/GHSA-xhch-7j88-pg68/GHSA-xhch-7j88-pg68.json b/advisories/unreviewed/2023/12/GHSA-xhch-7j88-pg68/GHSA-xhch-7j88-pg68.json index 1c7d890c255..51b40c51100 100644 --- a/advisories/unreviewed/2023/12/GHSA-xhch-7j88-pg68/GHSA-xhch-7j88-pg68.json +++ b/advisories/unreviewed/2023/12/GHSA-xhch-7j88-pg68/GHSA-xhch-7j88-pg68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xhch-7j88-pg68", - "modified": "2023-12-16T03:30:17Z", + "modified": "2024-01-05T18:30:21Z", "published": "2023-12-06T18:31:05Z", "aliases": [ "CVE-2023-39539" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/AMI-SA-2023009.pdf" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240105-0003/" + }, { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/811862" diff --git a/advisories/unreviewed/2024/01/GHSA-2gfx-5m5m-qcxg/GHSA-2gfx-5m5m-qcxg.json b/advisories/unreviewed/2024/01/GHSA-2gfx-5m5m-qcxg/GHSA-2gfx-5m5m-qcxg.json new file mode 100644 index 00000000000..2ea16683146 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2gfx-5m5m-qcxg/GHSA-2gfx-5m5m-qcxg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gfx-5m5m-qcxg", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-45043" + ], + "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.4.2596 build 20231128 and later\nQuTS hero h5.1.4.2596 build 20231128 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45043" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json b/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json new file mode 100644 index 00000000000..2c0f74a0b27 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3qxp-p56x-r4h3/GHSA-3qxp-p56x-r4h3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qxp-p56x-r4h3", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34322" + ], + "details": "For migration as well as to work around kernels unaware of L1TF (see\nXSA-273), PV guests may be run in shadow paging mode. Since Xen itself\nneeds to be mapped when PV guests run, Xen and shadowed PV guests run\ndirectly the respective shadow page tables. For 64-bit PV guests this\nmeans running on the shadow of the guest root page table.\n\nIn the course of dealing with shortage of memory in the shadow pool\nassociated with a domain, shadows of page tables may be torn down. This\ntearing down may include the shadow root page table that the CPU in\nquestion is presently running on. While a precaution exists to\nsupposedly prevent the tearing down of the underlying live page table,\nthe time window covered by that precaution isn't large enough.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34322" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-438.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3w95-fv8q-2wr8/GHSA-3w95-fv8q-2wr8.json b/advisories/unreviewed/2024/01/GHSA-3w95-fv8q-2wr8/GHSA-3w95-fv8q-2wr8.json new file mode 100644 index 00000000000..b432621f9df --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3w95-fv8q-2wr8/GHSA-3w95-fv8q-2wr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w95-fv8q-2wr8", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-47560" + ], + "details": "An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following version:\nQuMagie 2.2.1 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47560" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-23" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json b/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json new file mode 100644 index 00000000000..30126289155 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4rmw-8gh7-w6g3/GHSA-4rmw-8gh7-w6g3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rmw-8gh7-w6g3", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-46836" + ], + "details": "The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative\nReturn Stack Overflow) are not IRQ-safe. It was believed that the\nmitigations always operated in contexts with IRQs disabled.\n\nHowever, the original XSA-254 fix for Meltdown (XPTI) deliberately left\ninterrupts enabled on two entry paths; one unconditionally, and one\nconditionally on whether XPTI was active.\n\nAs BTC/SRSO and Meltdown affect different CPU vendors, the mitigations\nare not active together by default. Therefore, there is a race\ncondition whereby a malicious PV guest can bypass BTC/SRSO protections\nand launch a BTC/SRSO attack against Xen.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46836" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-446.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4v35-68f6-rfpq/GHSA-4v35-68f6-rfpq.json b/advisories/unreviewed/2024/01/GHSA-4v35-68f6-rfpq/GHSA-4v35-68f6-rfpq.json new file mode 100644 index 00000000000..bffc93fffbe --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4v35-68f6-rfpq/GHSA-4v35-68f6-rfpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v35-68f6-rfpq", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-41289" + ], + "details": "An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following version:\nQcalAgent 1.1.8 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41289" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-34" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json b/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json new file mode 100644 index 00000000000..2fbcb1408c0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7fx2-c8rv-2w4f/GHSA-7fx2-c8rv-2w4f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fx2-c8rv-2w4f", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34327" + ], + "details": "\n[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nAMD CPUs since ~2014 have extensions to normal x86 debugging functionality.\nXen supports guests using these extensions.\n\nUnfortunately there are errors in Xen's handling of the guest state, leading\nto denials of service.\n\n 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of\n a previous vCPUs debug mask state.\n\n 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.\n This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock\n up the CPU entirely.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34327" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-444.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json b/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json new file mode 100644 index 00000000000..38b7394f57b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-85fq-cwc3-mp4q/GHSA-85fq-cwc3-mp4q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85fq-cwc3-mp4q", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34323" + ], + "details": "When a transaction is committed, C Xenstored will first check\nthe quota is correct before attempting to commit any nodes. It would\nbe possible that accounting is temporarily negative if a node has\nbeen removed outside of the transaction.\n\nUnfortunately, some versions of C Xenstored are assuming that the\nquota cannot be negative and are using assert() to confirm it. This\nwill lead to C Xenstored crash when tools are built without -DNDEBUG\n(this is the default).\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34323" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-440.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json b/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json new file mode 100644 index 00000000000..0dc8b0c8df5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c2mm-wq7p-rpm8/GHSA-c2mm-wq7p-rpm8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2mm-wq7p-rpm8", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-46835" + ], + "details": "The current setup of the quarantine page tables assumes that the\nquarantine domain (dom_io) has been initialized with an address width\nof DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and hence 4 page table levels.\n\nHowever dom_io being a PV domain gets the AMD-Vi IOMMU page tables\nlevels based on the maximum (hot pluggable) RAM address, and hence on\nsystems with no RAM above the 512GB mark only 3 page-table levels are\nconfigured in the IOMMU.\n\nOn systems without RAM above the 512GB boundary\namd_iommu_quarantine_init() will setup page tables for the scratch\npage with 4 levels, while the IOMMU will be configured to use 3 levels\nonly, resulting in the last page table directory (PDE) effectively\nbecoming a page table entry (PTE), and hence a device in quarantine\nmode gaining write access to the page destined to be a PDE.\n\nDue to this page table level mismatch, the sink page the device gets\nread/write access to is no longer cleared between device assignment,\npossibly leading to data leaks.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46835" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-445.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-chg5-w539-53mr/GHSA-chg5-w539-53mr.json b/advisories/unreviewed/2024/01/GHSA-chg5-w539-53mr/GHSA-chg5-w539-53mr.json new file mode 100644 index 00000000000..8e199be44f1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-chg5-w539-53mr/GHSA-chg5-w539-53mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chg5-w539-53mr", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-41287" + ], + "details": "A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network.\n\nWe have already fixed the vulnerability in the following version:\nVideo Station 5.7.2 ( 2023/11/23 ) and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41287" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-55" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json b/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json new file mode 100644 index 00000000000..a39458664ae --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fm4g-p248-j5wj/GHSA-fm4g-p248-j5wj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm4g-p248-j5wj", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34328" + ], + "details": "\n[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nAMD CPUs since ~2014 have extensions to normal x86 debugging functionality.\nXen supports guests using these extensions.\n\nUnfortunately there are errors in Xen's handling of the guest state, leading\nto denials of service.\n\n 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of\n a previous vCPUs debug mask state.\n\n 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.\n This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock\n up the CPU entirely.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34328" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-444.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-frmj-qjf3-xxj4/GHSA-frmj-qjf3-xxj4.json b/advisories/unreviewed/2024/01/GHSA-frmj-qjf3-xxj4/GHSA-frmj-qjf3-xxj4.json new file mode 100644 index 00000000000..2d0d68782cd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-frmj-qjf3-xxj4/GHSA-frmj-qjf3-xxj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frmj-qjf3-xxj4", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-41288" + ], + "details": "An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following version:\nVideo Station 5.7.2 ( 2023/11/23 ) and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41288" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-55" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json b/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json new file mode 100644 index 00000000000..8a53ae9b54f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gwmw-qvr5-88j2/GHSA-gwmw-qvr5-88j2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwmw-qvr5-88j2", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34325" + ], + "details": "\n[This CNA information record relates to multiple CVEs; the\ntext explains which aspects/vulnerabilities correspond to which CVE.]\n\nlibfsimage contains parsing code for several filesystems, most of them based on\ngrub-legacy code. libfsimage is used by pygrub to inspect guest disks.\n\nPygrub runs as the same user as the toolstack (root in a priviledged domain).\n\nAt least one issue has been reported to the Xen Security Team that allows an\nattacker to trigger a stack buffer overflow in libfsimage. After further\nanalisys the Xen Security Team is no longer confident in the suitability of\nlibfsimage when run against guest controlled input with super user priviledges.\n\nIn order to not affect current deployments that rely on pygrub patches are\nprovided in the resolution section of the advisory that allow running pygrub in\ndeprivileged mode.\n\nCVE-2023-4949 refers to the original issue in the upstream grub\nproject (\"An attacker with local access to a system (either through a\ndisk or external drive) can present a modified XFS partition to\ngrub-legacy in such a way to exploit a memory corruption in grub’s XFS\nfile system implementation.\") CVE-2023-34325 refers specifically to\nthe vulnerabilities in Xen's copy of libfsimage, which is decended\nfrom a very old version of grub.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34325" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-443.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jmff-phw8-mjfm/GHSA-jmff-phw8-mjfm.json b/advisories/unreviewed/2024/01/GHSA-jmff-phw8-mjfm/GHSA-jmff-phw8-mjfm.json new file mode 100644 index 00000000000..4b038399c63 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jmff-phw8-mjfm/GHSA-jmff-phw8-mjfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmff-phw8-mjfm", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-45042" + ], + "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.4.2596 build 20231128 and later\nQuTS hero h5.1.4.2596 build 20231128 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45042" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json b/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json new file mode 100644 index 00000000000..ab6eec2faeb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mjvw-frxx-6hm5/GHSA-mjvw-frxx-6hm5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjvw-frxx-6hm5", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34326" + ], + "details": "The caching invalidation guidelines from the AMD-Vi specification (48882—Rev\n3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction\n(see stale DMA mappings) if some fields of the DTE are updated but the IOMMU\nTLB is not flushed.\n\nSuch stale DMA mappings can point to memory ranges not owned by the guest, thus\nallowing access to unindented memory regions.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34326" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-442.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json b/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json new file mode 100644 index 00000000000..d80caf9be68 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p5q9-hxvv-3rqq/GHSA-p5q9-hxvv-3rqq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5q9-hxvv-3rqq", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-34321" + ], + "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34321" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-437.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pr66-q9h8-2vj7/GHSA-pr66-q9h8-2vj7.json b/advisories/unreviewed/2024/01/GHSA-pr66-q9h8-2vj7/GHSA-pr66-q9h8-2vj7.json new file mode 100644 index 00000000000..bfdc68e3abe --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pr66-q9h8-2vj7/GHSA-pr66-q9h8-2vj7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr66-q9h8-2vj7", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-45039" + ], + "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.4.2596 build 20231128 and later\nQuTS hero h5.1.4.2596 build 20231128 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45039" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q6m8-qqcx-ww7p/GHSA-q6m8-qqcx-ww7p.json b/advisories/unreviewed/2024/01/GHSA-q6m8-qqcx-ww7p/GHSA-q6m8-qqcx-ww7p.json new file mode 100644 index 00000000000..6e9f1179366 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q6m8-qqcx-ww7p/GHSA-q6m8-qqcx-ww7p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6m8-qqcx-ww7p", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-47219" + ], + "details": "A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.\n\nWe have already fixed the vulnerability in the following version:\nQuMagie 2.2.1 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47219" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-32" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json b/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json new file mode 100644 index 00000000000..5b3a1eb852d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v75r-qqcp-59c7/GHSA-v75r-qqcp-59c7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v75r-qqcp-59c7", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-46837" + ], + "details": "Arm provides multiple helpers to clean & invalidate the cache\nfor a given region. This is, for instance, used when allocating\nguest memory to ensure any writes (such as the ones during scrubbing)\nhave reached memory before handing over the page to a guest.\n\nUnfortunately, the arithmetics in the helpers can overflow and would\nthen result to skip the cache cleaning/invalidation. Therefore there\nis no guarantee when all the writes will reach the memory.\n\nThis undefined behavior was meant to be addressed by XSA-437, but the\napproach was not sufficient.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46837" + }, + { + "type": "WEB", + "url": "https://xenbits.xenproject.org/xsa/advisory-447.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vcg2-xp5m-jf8w/GHSA-vcg2-xp5m-jf8w.json b/advisories/unreviewed/2024/01/GHSA-vcg2-xp5m-jf8w/GHSA-vcg2-xp5m-jf8w.json new file mode 100644 index 00000000000..cee7b6696a1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vcg2-xp5m-jf8w/GHSA-vcg2-xp5m-jf8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcg2-xp5m-jf8w", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-45044" + ], + "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.4.2596 build 20231128 and later\nQuTS hero h5.1.4.2596 build 20231128 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45044" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vqxw-xvvw-r4g2/GHSA-vqxw-xvvw-r4g2.json b/advisories/unreviewed/2024/01/GHSA-vqxw-xvvw-r4g2/GHSA-vqxw-xvvw-r4g2.json new file mode 100644 index 00000000000..772e7d76b30 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vqxw-xvvw-r4g2/GHSA-vqxw-xvvw-r4g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqxw-xvvw-r4g2", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-45040" + ], + "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.4.2596 build 20231128 and later\nQuTS hero h5.1.4.2596 build 20231128 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45040" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vwrg-xv3f-vx5j/GHSA-vwrg-xv3f-vx5j.json b/advisories/unreviewed/2024/01/GHSA-vwrg-xv3f-vx5j/GHSA-vwrg-xv3f-vx5j.json new file mode 100644 index 00000000000..f0acf2365ef --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vwrg-xv3f-vx5j/GHSA-vwrg-xv3f-vx5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwrg-xv3f-vx5j", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-39294" + ], + "details": "An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.3.2578 build 20231110 and later\nQuTS hero h5.1.3.2578 build 20231110 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39294" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xh38-hrrg-8cjv/GHSA-xh38-hrrg-8cjv.json b/advisories/unreviewed/2024/01/GHSA-xh38-hrrg-8cjv/GHSA-xh38-hrrg-8cjv.json new file mode 100644 index 00000000000..5c6fd528d1d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xh38-hrrg-8cjv/GHSA-xh38-hrrg-8cjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh38-hrrg-8cjv", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-39296" + ], + "details": "A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.3.2578 build 20231110 and later\nQuTS hero h5.1.3.2578 build 20231110 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39296" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-64" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xvwp-q2w5-88cf/GHSA-xvwp-q2w5-88cf.json b/advisories/unreviewed/2024/01/GHSA-xvwp-q2w5-88cf/GHSA-xvwp-q2w5-88cf.json new file mode 100644 index 00000000000..c08cee5c259 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xvwp-q2w5-88cf/GHSA-xvwp-q2w5-88cf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvwp-q2w5-88cf", + "modified": "2024-01-05T18:30:25Z", + "published": "2024-01-05T18:30:25Z", + "aliases": [ + "CVE-2023-45041" + ], + "details": "A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.1.4.2596 build 20231128 and later\nQuTS hero h5.1.4.2596 build 20231128 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45041" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xwq3-6vm6-9m42/GHSA-xwq3-6vm6-9m42.json b/advisories/unreviewed/2024/01/GHSA-xwq3-6vm6-9m42/GHSA-xwq3-6vm6-9m42.json new file mode 100644 index 00000000000..74cebea28ce --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xwq3-6vm6-9m42/GHSA-xwq3-6vm6-9m42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwq3-6vm6-9m42", + "modified": "2024-01-05T18:30:26Z", + "published": "2024-01-05T18:30:26Z", + "aliases": [ + "CVE-2023-47559" + ], + "details": "A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.\n\nWe have already fixed the vulnerability in the following version:\nQuMagie 2.2.1 and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47559" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-23" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T17:15:11Z" + } +} \ No newline at end of file