diff --git a/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json b/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json index 491cd13e43e..dab23a13e64 100644 --- a/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json +++ b/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wrp-6fg6-hmc5", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-08-27T18:36:46Z", "published": "2024-04-16T06:30:28Z", "aliases": [ "CVE-2024-22262" @@ -97,7 +97,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/unreviewed/2022/04/GHSA-j5fm-fr9f-2w9w/GHSA-j5fm-fr9f-2w9w.json b/advisories/unreviewed/2022/04/GHSA-j5fm-fr9f-2w9w/GHSA-j5fm-fr9f-2w9w.json index 7b23bd5cdac..7ed6f82ac42 100644 --- a/advisories/unreviewed/2022/04/GHSA-j5fm-fr9f-2w9w/GHSA-j5fm-fr9f-2w9w.json +++ b/advisories/unreviewed/2022/04/GHSA-j5fm-fr9f-2w9w/GHSA-j5fm-fr9f-2w9w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j5fm-fr9f-2w9w", - "modified": "2022-04-29T02:58:22Z", + "modified": "2024-08-27T18:31:33Z", "published": "2022-04-29T02:58:22Z", "aliases": [ "CVE-2004-0798" diff --git a/advisories/unreviewed/2022/05/GHSA-249x-3qx4-8h7p/GHSA-249x-3qx4-8h7p.json b/advisories/unreviewed/2022/05/GHSA-249x-3qx4-8h7p/GHSA-249x-3qx4-8h7p.json index d55f282fdf0..d735667444c 100644 --- a/advisories/unreviewed/2022/05/GHSA-249x-3qx4-8h7p/GHSA-249x-3qx4-8h7p.json +++ b/advisories/unreviewed/2022/05/GHSA-249x-3qx4-8h7p/GHSA-249x-3qx4-8h7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-249x-3qx4-8h7p", - "modified": "2022-05-17T01:09:24Z", + "modified": "2024-08-27T18:31:33Z", "published": "2022-05-17T01:09:24Z", "aliases": [ "CVE-2015-8261" diff --git a/advisories/unreviewed/2022/05/GHSA-6hrr-q3r6-mc76/GHSA-6hrr-q3r6-mc76.json b/advisories/unreviewed/2022/05/GHSA-6hrr-q3r6-mc76/GHSA-6hrr-q3r6-mc76.json index 418d825e548..6f981a36f83 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hrr-q3r6-mc76/GHSA-6hrr-q3r6-mc76.json +++ b/advisories/unreviewed/2022/05/GHSA-6hrr-q3r6-mc76/GHSA-6hrr-q3r6-mc76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hrr-q3r6-mc76", - "modified": "2022-05-17T01:45:47Z", + "modified": "2024-08-27T18:31:34Z", "published": "2022-05-17T01:45:47Z", "aliases": [ "CVE-2012-2601" diff --git a/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json b/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json index 5fca82a3f4b..d05d7c421e5 100644 --- a/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json +++ b/advisories/unreviewed/2024/01/GHSA-4fr6-x37h-wjwr/GHSA-4fr6-x37h-wjwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fr6-x37h-wjwr", - "modified": "2024-01-11T18:31:22Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-01-03T21:30:31Z", "aliases": [ "CVE-2023-5880" diff --git a/advisories/unreviewed/2024/01/GHSA-8qcc-g56h-g74w/GHSA-8qcc-g56h-g74w.json b/advisories/unreviewed/2024/01/GHSA-8qcc-g56h-g74w/GHSA-8qcc-g56h-g74w.json index e476e27407e..0d98c80cf90 100644 --- a/advisories/unreviewed/2024/01/GHSA-8qcc-g56h-g74w/GHSA-8qcc-g56h-g74w.json +++ b/advisories/unreviewed/2024/01/GHSA-8qcc-g56h-g74w/GHSA-8qcc-g56h-g74w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-qf96-mmrf-rj2q/GHSA-qf96-mmrf-rj2q.json b/advisories/unreviewed/2024/01/GHSA-qf96-mmrf-rj2q/GHSA-qf96-mmrf-rj2q.json index 4c33eacfdf2..d4011e65d16 100644 --- a/advisories/unreviewed/2024/01/GHSA-qf96-mmrf-rj2q/GHSA-qf96-mmrf-rj2q.json +++ b/advisories/unreviewed/2024/01/GHSA-qf96-mmrf-rj2q/GHSA-qf96-mmrf-rj2q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf96-mmrf-rj2q", - "modified": "2024-01-19T21:30:34Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-01-16T09:30:19Z", "aliases": [ "CVE-2023-52114" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json b/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json index 2333bbef6ab..38f4ee2e772 100644 --- a/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json +++ b/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xr5r-3m93-q3f2", - "modified": "2024-01-19T21:30:34Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-01-16T12:30:26Z", "aliases": [ "CVE-2023-52105" diff --git a/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json b/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json index 277f9242ffc..1796a944ff3 100644 --- a/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json +++ b/advisories/unreviewed/2024/02/GHSA-3q5r-g7hx-jv3c/GHSA-3q5r-g7hx-jv3c.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-27" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json b/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json index 47ffc101691..b11d4f764c2 100644 --- a/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json +++ b/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqvf-8g7j-7gh5", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42942" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. A malicious app may be able to gain root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-29hx-fjxp-2fcx/GHSA-29hx-fjxp-2fcx.json b/advisories/unreviewed/2024/03/GHSA-29hx-fjxp-2fcx/GHSA-29hx-fjxp-2fcx.json index 79edd278c0c..49a47158a0b 100644 --- a/advisories/unreviewed/2024/03/GHSA-29hx-fjxp-2fcx/GHSA-29hx-fjxp-2fcx.json +++ b/advisories/unreviewed/2024/03/GHSA-29hx-fjxp-2fcx/GHSA-29hx-fjxp-2fcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29hx-fjxp-2fcx", - "modified": "2024-03-11T21:31:27Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-11T21:31:27Z", "aliases": [ "CVE-2024-27236" ], "details": "In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-42pj-35w6-4jwg/GHSA-42pj-35w6-4jwg.json b/advisories/unreviewed/2024/03/GHSA-42pj-35w6-4jwg/GHSA-42pj-35w6-4jwg.json index 8b720853077..366a730c570 100644 --- a/advisories/unreviewed/2024/03/GHSA-42pj-35w6-4jwg/GHSA-42pj-35w6-4jwg.json +++ b/advisories/unreviewed/2024/03/GHSA-42pj-35w6-4jwg/GHSA-42pj-35w6-4jwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42pj-35w6-4jwg", - "modified": "2024-03-28T18:30:47Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-28T18:30:47Z", "aliases": [ "CVE-2023-42974" ], "details": "A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-54mj-hcw7-m39p/GHSA-54mj-hcw7-m39p.json b/advisories/unreviewed/2024/03/GHSA-54mj-hcw7-m39p/GHSA-54mj-hcw7-m39p.json index d32b528ca5e..8747c55a242 100644 --- a/advisories/unreviewed/2024/03/GHSA-54mj-hcw7-m39p/GHSA-54mj-hcw7-m39p.json +++ b/advisories/unreviewed/2024/03/GHSA-54mj-hcw7-m39p/GHSA-54mj-hcw7-m39p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54mj-hcw7-m39p", - "modified": "2024-03-18T03:30:32Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-18T03:30:32Z", "aliases": [ "CVE-2022-47036" ], "details": "Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for \"debug login\" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, its is fixed in newer hardware, which would typically bs used with firmware 2.1.1 or later.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T03:15:05Z" diff --git a/advisories/unreviewed/2024/03/GHSA-985m-w4vj-29hv/GHSA-985m-w4vj-29hv.json b/advisories/unreviewed/2024/03/GHSA-985m-w4vj-29hv/GHSA-985m-w4vj-29hv.json index a036ce1dd39..76e760757b8 100644 --- a/advisories/unreviewed/2024/03/GHSA-985m-w4vj-29hv/GHSA-985m-w4vj-29hv.json +++ b/advisories/unreviewed/2024/03/GHSA-985m-w4vj-29hv/GHSA-985m-w4vj-29hv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-985m-w4vj-29hv", - "modified": "2024-03-11T21:31:25Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-11T21:31:25Z", "aliases": [ "CVE-2024-25988" ], "details": "In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mghx-3qf4-fx45/GHSA-mghx-3qf4-fx45.json b/advisories/unreviewed/2024/03/GHSA-mghx-3qf4-fx45/GHSA-mghx-3qf4-fx45.json index 339d7265854..8075a05c5b7 100644 --- a/advisories/unreviewed/2024/03/GHSA-mghx-3qf4-fx45/GHSA-mghx-3qf4-fx45.json +++ b/advisories/unreviewed/2024/03/GHSA-mghx-3qf4-fx45/GHSA-mghx-3qf4-fx45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mghx-3qf4-fx45", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27226" ], "details": "In tmu_config_gov_params of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mjxv-wcxg-9mv9/GHSA-mjxv-wcxg-9mv9.json b/advisories/unreviewed/2024/03/GHSA-mjxv-wcxg-9mv9/GHSA-mjxv-wcxg-9mv9.json index 76c19161a68..d597bb251e1 100644 --- a/advisories/unreviewed/2024/03/GHSA-mjxv-wcxg-9mv9/GHSA-mjxv-wcxg-9mv9.json +++ b/advisories/unreviewed/2024/03/GHSA-mjxv-wcxg-9mv9/GHSA-mjxv-wcxg-9mv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjxv-wcxg-9mv9", - "modified": "2024-03-11T21:31:23Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-11T21:31:23Z", "aliases": [ "CVE-2024-22005" ], "details": "In TBD of TBD, there is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rvw4-7ggj-6vq9/GHSA-rvw4-7ggj-6vq9.json b/advisories/unreviewed/2024/03/GHSA-rvw4-7ggj-6vq9/GHSA-rvw4-7ggj-6vq9.json index 02ddc0cdf34..7184f783883 100644 --- a/advisories/unreviewed/2024/03/GHSA-rvw4-7ggj-6vq9/GHSA-rvw4-7ggj-6vq9.json +++ b/advisories/unreviewed/2024/03/GHSA-rvw4-7ggj-6vq9/GHSA-rvw4-7ggj-6vq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rvw4-7ggj-6vq9", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23234" ], "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to execute arbitrary code with kernel privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v223-c39x-4wxf/GHSA-v223-c39x-4wxf.json b/advisories/unreviewed/2024/03/GHSA-v223-c39x-4wxf/GHSA-v223-c39x-4wxf.json index f3038163d69..76d11d6d394 100644 --- a/advisories/unreviewed/2024/03/GHSA-v223-c39x-4wxf/GHSA-v223-c39x-4wxf.json +++ b/advisories/unreviewed/2024/03/GHSA-v223-c39x-4wxf/GHSA-v223-c39x-4wxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v223-c39x-4wxf", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27208" ], "details": "In TBD of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2wvh-6639-8hph/GHSA-2wvh-6639-8hph.json b/advisories/unreviewed/2024/04/GHSA-2wvh-6639-8hph/GHSA-2wvh-6639-8hph.json index 11487ceec76..2ff26fffa46 100644 --- a/advisories/unreviewed/2024/04/GHSA-2wvh-6639-8hph/GHSA-2wvh-6639-8hph.json +++ b/advisories/unreviewed/2024/04/GHSA-2wvh-6639-8hph/GHSA-2wvh-6639-8hph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wvh-6639-8hph", - "modified": "2024-04-30T00:30:35Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-04-30T00:30:35Z", "aliases": [ "CVE-2024-34048" ], "details": "O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T00:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json b/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json index 656eb6ab01d..4796a19293a 100644 --- a/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json +++ b/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-363m-3jp4-qg24", - "modified": "2024-04-01T06:30:31Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-01T06:30:31Z", "aliases": [ "CVE-2024-2263" ], "details": "Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T05:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json b/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json index cf093b2d391..982a5c6c7b6 100644 --- a/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json +++ b/advisories/unreviewed/2024/04/GHSA-6gv8-hx3q-gqrw/GHSA-6gv8-hx3q-gqrw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6gv8-hx3q-gqrw", - "modified": "2024-04-05T21:32:44Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-05T21:32:44Z", "aliases": [ "CVE-2024-29746" ], "details": "In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6pg9-cqrm-937h/GHSA-6pg9-cqrm-937h.json b/advisories/unreviewed/2024/04/GHSA-6pg9-cqrm-937h/GHSA-6pg9-cqrm-937h.json index f294eff7bb9..cee8df52d58 100644 --- a/advisories/unreviewed/2024/04/GHSA-6pg9-cqrm-937h/GHSA-6pg9-cqrm-937h.json +++ b/advisories/unreviewed/2024/04/GHSA-6pg9-cqrm-937h/GHSA-6pg9-cqrm-937h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pg9-cqrm-937h", - "modified": "2024-04-02T21:30:29Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-02T21:30:29Z", "aliases": [ "CVE-2024-29432" ], "details": "Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T21:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json b/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json index 3de019397b4..704a1e324c6 100644 --- a/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json +++ b/advisories/unreviewed/2024/04/GHSA-749f-97mp-r5j9/GHSA-749f-97mp-r5j9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-73" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9576-cchc-4f79/GHSA-9576-cchc-4f79.json b/advisories/unreviewed/2024/04/GHSA-9576-cchc-4f79/GHSA-9576-cchc-4f79.json index 75838ef700c..6d4c37a98f0 100644 --- a/advisories/unreviewed/2024/04/GHSA-9576-cchc-4f79/GHSA-9576-cchc-4f79.json +++ b/advisories/unreviewed/2024/04/GHSA-9576-cchc-4f79/GHSA-9576-cchc-4f79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9576-cchc-4f79", - "modified": "2024-04-02T06:30:32Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-02T06:30:32Z", "aliases": [ "CVE-2024-1274" ], "details": "The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T06:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-95g8-gqrv-f83g/GHSA-95g8-gqrv-f83g.json b/advisories/unreviewed/2024/04/GHSA-95g8-gqrv-f83g/GHSA-95g8-gqrv-f83g.json index e994774e769..0d2bf008a03 100644 --- a/advisories/unreviewed/2024/04/GHSA-95g8-gqrv-f83g/GHSA-95g8-gqrv-f83g.json +++ b/advisories/unreviewed/2024/04/GHSA-95g8-gqrv-f83g/GHSA-95g8-gqrv-f83g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95g8-gqrv-f83g", - "modified": "2024-04-11T03:35:00Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-11T03:35:00Z", "aliases": [ "CVE-2024-29937" ], "details": "NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T01:25:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cw24-292m-q722/GHSA-cw24-292m-q722.json b/advisories/unreviewed/2024/04/GHSA-cw24-292m-q722/GHSA-cw24-292m-q722.json index 35c1c23c0a0..4de7b150611 100644 --- a/advisories/unreviewed/2024/04/GHSA-cw24-292m-q722/GHSA-cw24-292m-q722.json +++ b/advisories/unreviewed/2024/04/GHSA-cw24-292m-q722/GHSA-cw24-292m-q722.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cw24-292m-q722", - "modified": "2024-04-01T15:30:29Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-01T15:30:29Z", "aliases": [ "CVE-2024-30865" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T15:15:55Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json b/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json index c2005449160..be2f2ea7ade 100644 --- a/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json +++ b/advisories/unreviewed/2024/04/GHSA-gxgx-2mvf-9gh5/GHSA-gxgx-2mvf-9gh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxgx-2mvf-9gh5", - "modified": "2024-04-10T15:30:40Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-10T15:30:40Z", "aliases": [ "CVE-2024-23080" ], "details": "Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T13:51:38Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p768-2fq7-r2q4/GHSA-p768-2fq7-r2q4.json b/advisories/unreviewed/2024/04/GHSA-p768-2fq7-r2q4/GHSA-p768-2fq7-r2q4.json index 26fe55c9059..4ddaa4b9f0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-p768-2fq7-r2q4/GHSA-p768-2fq7-r2q4.json +++ b/advisories/unreviewed/2024/04/GHSA-p768-2fq7-r2q4/GHSA-p768-2fq7-r2q4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p768-2fq7-r2q4", - "modified": "2024-04-01T18:30:56Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-01T18:30:56Z", "aliases": [ "CVE-2024-30867" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T16:15:54Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json b/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json index 61395a5a1c7..fd9ce8ffe28 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json +++ b/advisories/unreviewed/2024/04/GHSA-pfrw-8j6p-xmx6/GHSA-pfrw-8j6p-xmx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfrw-8j6p-xmx6", - "modified": "2024-04-02T09:30:42Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-31002" ], "details": "Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T08:15:59Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json b/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json index 16f982e6db8..b7d1bb70647 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json +++ b/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pgrq-g235-jm37", - "modified": "2024-04-03T15:30:41Z", + "modified": "2024-08-27T18:31:34Z", "published": "2024-04-03T15:30:41Z", "aliases": [ "CVE-2024-30569" ], "details": "An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T13:16:02Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x752-fh3c-ch6r/GHSA-x752-fh3c-ch6r.json b/advisories/unreviewed/2024/04/GHSA-x752-fh3c-ch6r/GHSA-x752-fh3c-ch6r.json index 09c94874bd8..fedbdc9eb2d 100644 --- a/advisories/unreviewed/2024/04/GHSA-x752-fh3c-ch6r/GHSA-x752-fh3c-ch6r.json +++ b/advisories/unreviewed/2024/04/GHSA-x752-fh3c-ch6r/GHSA-x752-fh3c-ch6r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x339-928h-52pw/GHSA-x339-928h-52pw.json b/advisories/unreviewed/2024/05/GHSA-x339-928h-52pw/GHSA-x339-928h-52pw.json index 1430660e4a8..258c8c3855d 100644 --- a/advisories/unreviewed/2024/05/GHSA-x339-928h-52pw/GHSA-x339-928h-52pw.json +++ b/advisories/unreviewed/2024/05/GHSA-x339-928h-52pw/GHSA-x339-928h-52pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x339-928h-52pw", - "modified": "2024-05-14T15:32:53Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27460" ], "details": "A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:12:33Z" diff --git a/advisories/unreviewed/2024/06/GHSA-33h3-4p7j-r54j/GHSA-33h3-4p7j-r54j.json b/advisories/unreviewed/2024/06/GHSA-33h3-4p7j-r54j/GHSA-33h3-4p7j-r54j.json index f836784df35..8d165282542 100644 --- a/advisories/unreviewed/2024/06/GHSA-33h3-4p7j-r54j/GHSA-33h3-4p7j-r54j.json +++ b/advisories/unreviewed/2024/06/GHSA-33h3-4p7j-r54j/GHSA-33h3-4p7j-r54j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-33h3-4p7j-r54j", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47616" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA: Fix use-after-free in rxe_queue_cleanup\n\nOn error handling path in rxe_qp_from_init() qp->sq.queue is freed and\nthen rxe_create_qp() will drop last reference to this object. qp clean up\nfunction will try to free this queue one time and it causes UAF bug.\n\nFix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:56Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3h59-8483-h44f/GHSA-3h59-8483-h44f.json b/advisories/unreviewed/2024/06/GHSA-3h59-8483-h44f/GHSA-3h59-8483-h44f.json index 7d3bd6d187c..93fdf97bae8 100644 --- a/advisories/unreviewed/2024/06/GHSA-3h59-8483-h44f/GHSA-3h59-8483-h44f.json +++ b/advisories/unreviewed/2024/06/GHSA-3h59-8483-h44f/GHSA-3h59-8483-h44f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3h59-8483-h44f", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38600" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: Fix deadlocks with kctl removals at disconnection\n\nIn snd_card_disconnect(), we set card->shutdown flag at the beginning,\ncall callbacks and do sync for card->power_ref_sleep waiters at the\nend. The callback may delete a kctl element, and this can lead to a\ndeadlock when the device was in the suspended state. Namely:\n\n* A process waits for the power up at snd_power_ref_and_wait() in\n snd_ctl_info() or read/write() inside card->controls_rwsem.\n\n* The system gets disconnected meanwhile, and the driver tries to\n delete a kctl via snd_ctl_remove*(); it tries to take\n card->controls_rwsem again, but this is already locked by the\n above. Since the sleeper isn't woken up, this deadlocks.\n\nAn easy fix is to wake up sleepers before processing the driver\ndisconnect callbacks but right after setting the card->shutdown flag.\nThen all sleepers will abort immediately, and the code flows again.\n\nSo, basically this patch moves the wait_event() call at the right\ntiming. While we're at it, just to be sure, call wait_event_all()\ninstead of wait_event(), although we don't use exclusive events on\nthis queue for now.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:19Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3xcp-65mf-qfv3/GHSA-3xcp-65mf-qfv3.json b/advisories/unreviewed/2024/06/GHSA-3xcp-65mf-qfv3/GHSA-3xcp-65mf-qfv3.json index 22b5d88732c..bda0e6dcca7 100644 --- a/advisories/unreviewed/2024/06/GHSA-3xcp-65mf-qfv3/GHSA-3xcp-65mf-qfv3.json +++ b/advisories/unreviewed/2024/06/GHSA-3xcp-65mf-qfv3/GHSA-3xcp-65mf-qfv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3xcp-65mf-qfv3", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47610" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix null ptr access msm_ioctl_gem_submit()\n\nFix the below null pointer dereference in msm_ioctl_gem_submit():\n\n 26545.260705: Call trace:\n 26545.263223: kref_put+0x1c/0x60\n 26545.266452: msm_ioctl_gem_submit+0x254/0x744\n 26545.270937: drm_ioctl_kernel+0xa8/0x124\n 26545.274976: drm_ioctl+0x21c/0x33c\n 26545.278478: drm_compat_ioctl+0xdc/0xf0\n 26545.282428: __arm64_compat_sys_ioctl+0xc8/0x100\n 26545.287169: el0_svc_common+0xf8/0x250\n 26545.291025: do_el0_svc_compat+0x28/0x54\n 26545.295066: el0_svc_compat+0x10/0x1c\n 26545.298838: el0_sync_compat_handler+0xa8/0xcc\n 26545.303403: el0_sync_compat+0x188/0x1c0\n 26545.307445: Code: d503201f d503201f 52800028 4b0803e8 (b8680008)\n 26545.318799: Kernel panic - not syncing: Oops: Fatal exception", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5583-qmch-62x6/GHSA-5583-qmch-62x6.json b/advisories/unreviewed/2024/06/GHSA-5583-qmch-62x6/GHSA-5583-qmch-62x6.json index 236f76eb79c..a4da19f9a75 100644 --- a/advisories/unreviewed/2024/06/GHSA-5583-qmch-62x6/GHSA-5583-qmch-62x6.json +++ b/advisories/unreviewed/2024/06/GHSA-5583-qmch-62x6/GHSA-5583-qmch-62x6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5583-qmch-62x6", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47604" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvduse: check that offset is within bounds in get_config()\n\nThis condition checks \"len\" but it does not check \"offset\" and that\ncould result in an out of bounds read if \"offset > dev->config_size\".\nThe problem is that since both variables are unsigned the\n\"dev->config_size - offset\" subtraction would result in a very high\nunsigned value.\n\nI think these checks might not be necessary because \"len\" and \"offset\"\nare supposed to already have been validated using the\nvhost_vdpa_config_validate() function. But I do not know the code\nperfectly, and I like to be safe.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7vv8-23mh-rqfj/GHSA-7vv8-23mh-rqfj.json b/advisories/unreviewed/2024/06/GHSA-7vv8-23mh-rqfj/GHSA-7vv8-23mh-rqfj.json index ca1f00f2349..2f41f631425 100644 --- a/advisories/unreviewed/2024/06/GHSA-7vv8-23mh-rqfj/GHSA-7vv8-23mh-rqfj.json +++ b/advisories/unreviewed/2024/06/GHSA-7vv8-23mh-rqfj/GHSA-7vv8-23mh-rqfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vv8-23mh-rqfj", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47612" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: fix segfault in nfc_genl_dump_devices_done\n\nWhen kmalloc in nfc_genl_dump_devices() fails then\nnfc_genl_dump_devices_done() segfaults as below\n\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 25 Comm: kworker/0:1 Not tainted 5.16.0-rc4-01180-g2a987e65025e-dirty #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-6.fc35 04/01/2014\nWorkqueue: events netlink_sock_destruct_work\nRIP: 0010:klist_iter_exit+0x26/0x80\nCall Trace:\n\nclass_dev_iter_exit+0x15/0x20\nnfc_genl_dump_devices_done+0x3b/0x50\ngenl_lock_done+0x84/0xd0\nnetlink_sock_destruct+0x8f/0x270\n__sk_destruct+0x64/0x3b0\nsk_destruct+0xa8/0xd0\n__sk_free+0x2e8/0x3d0\nsk_free+0x51/0x90\nnetlink_sock_destruct_work+0x1c/0x20\nprocess_one_work+0x411/0x710\nworker_thread+0x6fd/0xa80", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7vxw-8c3h-6mgh/GHSA-7vxw-8c3h-6mgh.json b/advisories/unreviewed/2024/06/GHSA-7vxw-8c3h-6mgh/GHSA-7vxw-8c3h-6mgh.json index 44ec105d7fb..364169a718a 100644 --- a/advisories/unreviewed/2024/06/GHSA-7vxw-8c3h-6mgh/GHSA-7vxw-8c3h-6mgh.json +++ b/advisories/unreviewed/2024/06/GHSA-7vxw-8c3h-6mgh/GHSA-7vxw-8c3h-6mgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vxw-8c3h-6mgh", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38602" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Fix reference count leak issues of ax25_dev\n\nThe ax25_addr_ax25dev() and ax25_dev_device_down() exist a reference\ncount leak issue of the object \"ax25_dev\".\n\nMemory leak issue in ax25_addr_ax25dev():\n\nThe reference count of the object \"ax25_dev\" can be increased multiple\ntimes in ax25_addr_ax25dev(). This will cause a memory leak.\n\nMemory leak issues in ax25_dev_device_down():\n\nThe reference count of ax25_dev is set to 1 in ax25_dev_device_up() and\nthen increase the reference count when ax25_dev is added to ax25_dev_list.\nAs a result, the reference count of ax25_dev is 2. But when the device is\nshutting down. The ax25_dev_device_down() drops the reference count once\nor twice depending on if we goto unlock_put or not, which will cause\nmemory leak.\n\nAs for the issue of ax25_addr_ax25dev(), it is impossible for one pointer\nto be on a list twice. So add a break in ax25_addr_ax25dev(). As for the\nissue of ax25_dev_device_down(), increase the reference count of ax25_dev\nonce in ax25_dev_device_up() and decrease the reference count of ax25_dev\nafter it is removed from the ax25_dev_list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:20Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8wpj-v5qv-3wf4/GHSA-8wpj-v5qv-3wf4.json b/advisories/unreviewed/2024/06/GHSA-8wpj-v5qv-3wf4/GHSA-8wpj-v5qv-3wf4.json index d1cc9eacdd1..fa9021dbe42 100644 --- a/advisories/unreviewed/2024/06/GHSA-8wpj-v5qv-3wf4/GHSA-8wpj-v5qv-3wf4.json +++ b/advisories/unreviewed/2024/06/GHSA-8wpj-v5qv-3wf4/GHSA-8wpj-v5qv-3wf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wpj-v5qv-3wf4", - "modified": "2024-06-29T06:31:40Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-29T06:31:40Z", "aliases": [ "CVE-2024-37371" ], "details": "In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-28T23:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gr6r-fxgm-72rq/GHSA-gr6r-fxgm-72rq.json b/advisories/unreviewed/2024/06/GHSA-gr6r-fxgm-72rq/GHSA-gr6r-fxgm-72rq.json index bbdfc090289..b4c926c753c 100644 --- a/advisories/unreviewed/2024/06/GHSA-gr6r-fxgm-72rq/GHSA-gr6r-fxgm-72rq.json +++ b/advisories/unreviewed/2024/06/GHSA-gr6r-fxgm-72rq/GHSA-gr6r-fxgm-72rq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr6r-fxgm-72rq", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47600" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm btree remove: fix use after free in rebalance_children()\n\nMove dm_tm_unlock() after dm_tm_dec().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h7wh-wpqg-g2jm/GHSA-h7wh-wpqg-g2jm.json b/advisories/unreviewed/2024/06/GHSA-h7wh-wpqg-g2jm/GHSA-h7wh-wpqg-g2jm.json index 219bd7b4430..575cadde80b 100644 --- a/advisories/unreviewed/2024/06/GHSA-h7wh-wpqg-g2jm/GHSA-h7wh-wpqg-g2jm.json +++ b/advisories/unreviewed/2024/06/GHSA-h7wh-wpqg-g2jm/GHSA-h7wh-wpqg-g2jm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7wh-wpqg-g2jm", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47598" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch_cake: do not call cake_destroy() from cake_init()\n\nqdiscs are not supposed to call their own destroy() method\nfrom init(), because core stack already does that.\n\nsyzbot was able to trigger use after free:\n\nDEBUG_LOCKS_WARN_ON(lock->magic != lock)\nWARNING: CPU: 0 PID: 21902 at kernel/locking/mutex.c:586 __mutex_lock_common kernel/locking/mutex.c:586 [inline]\nWARNING: CPU: 0 PID: 21902 at kernel/locking/mutex.c:586 __mutex_lock+0x9ec/0x12f0 kernel/locking/mutex.c:740\nModules linked in:\nCPU: 0 PID: 21902 Comm: syz-executor189 Not tainted 5.16.0-rc4-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:__mutex_lock_common kernel/locking/mutex.c:586 [inline]\nRIP: 0010:__mutex_lock+0x9ec/0x12f0 kernel/locking/mutex.c:740\nCode: 08 84 d2 0f 85 19 08 00 00 8b 05 97 38 4b 04 85 c0 0f 85 27 f7 ff ff 48 c7 c6 20 00 ac 89 48 c7 c7 a0 fe ab 89 e8 bf 76 ba ff <0f> 0b e9 0d f7 ff ff 48 8b 44 24 40 48 8d b8 c8 08 00 00 48 89 f8\nRSP: 0018:ffffc9000627f290 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: ffff88802315d700 RSI: ffffffff815f1db8 RDI: fffff52000c4fe44\nRBP: ffff88818f28e000 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffffff815ebb5e R11: 0000000000000000 R12: 0000000000000000\nR13: dffffc0000000000 R14: ffffc9000627f458 R15: 0000000093c30000\nFS: 0000555556abc400(0000) GS:ffff8880b9c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fda689c3303 CR3: 000000001cfbb000 CR4: 0000000000350ef0\nCall Trace:\n \n tcf_chain0_head_change_cb_del+0x2e/0x3d0 net/sched/cls_api.c:810\n tcf_block_put_ext net/sched/cls_api.c:1381 [inline]\n tcf_block_put_ext net/sched/cls_api.c:1376 [inline]\n tcf_block_put+0xbc/0x130 net/sched/cls_api.c:1394\n cake_destroy+0x3f/0x80 net/sched/sch_cake.c:2695\n qdisc_create.constprop.0+0x9da/0x10f0 net/sched/sch_api.c:1293\n tc_modify_qdisc+0x4c5/0x1980 net/sched/sch_api.c:1660\n rtnetlink_rcv_msg+0x413/0xb80 net/core/rtnetlink.c:5571\n netlink_rcv_skb+0x153/0x420 net/netlink/af_netlink.c:2496\n netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]\n netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0x904/0xdf0 net/netlink/af_netlink.c:1921\n sock_sendmsg_nosec net/socket.c:704 [inline]\n sock_sendmsg+0xcf/0x120 net/socket.c:724\n ____sys_sendmsg+0x6e8/0x810 net/socket.c:2409\n ___sys_sendmsg+0xf3/0x170 net/socket.c:2463\n __sys_sendmsg+0xe5/0x1b0 net/socket.c:2492\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f1bb06badb9\nCode: Unable to access opcode bytes at RIP 0x7f1bb06bad8f.\nRSP: 002b:00007fff3012a658 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007f1bb06badb9\nRDX: 0000000000000000 RSI: 00000000200007c0 RDI: 0000000000000003\nRBP: 0000000000000000 R08: 0000000000000003 R09: 0000000000000003\nR10: 0000000000000003 R11: 0000000000000246 R12: 00007fff3012a688\nR13: 00007fff3012a6a0 R14: 00007fff3012a6e0 R15: 00000000000013c2\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hwf6-8434-65rv/GHSA-hwf6-8434-65rv.json b/advisories/unreviewed/2024/06/GHSA-hwf6-8434-65rv/GHSA-hwf6-8434-65rv.json index 1c09776029f..2680a7d824a 100644 --- a/advisories/unreviewed/2024/06/GHSA-hwf6-8434-65rv/GHSA-hwf6-8434-65rv.json +++ b/advisories/unreviewed/2024/06/GHSA-hwf6-8434-65rv/GHSA-hwf6-8434-65rv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwf6-8434-65rv", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47601" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntee: amdtee: fix an IS_ERR() vs NULL bug\n\nThe __get_free_pages() function does not return error pointers it returns\nNULL so fix this condition to avoid a NULL dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-phj6-5vrc-g27m/GHSA-phj6-5vrc-g27m.json b/advisories/unreviewed/2024/06/GHSA-phj6-5vrc-g27m/GHSA-phj6-5vrc-g27m.json index b9344dbdd7a..f9a00bb6d47 100644 --- a/advisories/unreviewed/2024/06/GHSA-phj6-5vrc-g27m/GHSA-phj6-5vrc-g27m.json +++ b/advisories/unreviewed/2024/06/GHSA-phj6-5vrc-g27m/GHSA-phj6-5vrc-g27m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phj6-5vrc-g27m", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47590" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix deadlock in __mptcp_push_pending()\n\n__mptcp_push_pending() may call mptcp_flush_join_list() with subflow\nsocket lock held. If such call hits mptcp_sockopt_sync_all() then\nsubsequently __mptcp_sockopt_sync() could try to lock the subflow\nsocket for itself, causing a deadlock.\n\nsysrq: Show Blocked State\ntask:ss-server state:D stack: 0 pid: 938 ppid: 1 flags:0x00000000\nCall Trace:\n \n __schedule+0x2d6/0x10c0\n ? __mod_memcg_state+0x4d/0x70\n ? csum_partial+0xd/0x20\n ? _raw_spin_lock_irqsave+0x26/0x50\n schedule+0x4e/0xc0\n __lock_sock+0x69/0x90\n ? do_wait_intr_irq+0xa0/0xa0\n __lock_sock_fast+0x35/0x50\n mptcp_sockopt_sync_all+0x38/0xc0\n __mptcp_push_pending+0x105/0x200\n mptcp_sendmsg+0x466/0x490\n sock_sendmsg+0x57/0x60\n __sys_sendto+0xf0/0x160\n ? do_wait_intr_irq+0xa0/0xa0\n ? fpregs_restore_userregs+0x12/0xd0\n __x64_sys_sendto+0x20/0x30\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f9ba546c2d0\nRSP: 002b:00007ffdc3b762d8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f9ba56c8060 RCX: 00007f9ba546c2d0\nRDX: 000000000000077a RSI: 0000000000e5e180 RDI: 0000000000000234\nRBP: 0000000000cc57f0 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007f9ba56c8060\nR13: 0000000000b6ba60 R14: 0000000000cc7840 R15: 41d8685b1d7901b8\n \n\nFix the issue by using __mptcp_flush_join_list() instead of plain\nmptcp_flush_join_list() inside __mptcp_push_pending(), as suggested by\nFlorian. The sockopt sync will be deferred to the workqueue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-r5hw-wwq6-43px/GHSA-r5hw-wwq6-43px.json b/advisories/unreviewed/2024/06/GHSA-r5hw-wwq6-43px/GHSA-r5hw-wwq6-43px.json index f5141f1560c..ca6b9a0ea93 100644 --- a/advisories/unreviewed/2024/06/GHSA-r5hw-wwq6-43px/GHSA-r5hw-wwq6-43px.json +++ b/advisories/unreviewed/2024/06/GHSA-r5hw-wwq6-43px/GHSA-r5hw-wwq6-43px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r5hw-wwq6-43px", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2021-47576" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Sanity check block descriptor length in resp_mode_select()\n\nIn resp_mode_select() sanity check the block descriptor len to avoid UAF.\n\nBUG: KASAN: use-after-free in resp_mode_select+0xa4c/0xb40 drivers/scsi/scsi_debug.c:2509\nRead of size 1 at addr ffff888026670f50 by task scsicmd/15032\n\nCPU: 1 PID: 15032 Comm: scsicmd Not tainted 5.15.0-01d0625 #15\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nCall Trace:\n \n dump_stack_lvl+0x89/0xb5 lib/dump_stack.c:107\n print_address_description.constprop.9+0x28/0x160 mm/kasan/report.c:257\n kasan_report.cold.14+0x7d/0x117 mm/kasan/report.c:443\n __asan_report_load1_noabort+0x14/0x20 mm/kasan/report_generic.c:306\n resp_mode_select+0xa4c/0xb40 drivers/scsi/scsi_debug.c:2509\n schedule_resp+0x4af/0x1a10 drivers/scsi/scsi_debug.c:5483\n scsi_debug_queuecommand+0x8c9/0x1e70 drivers/scsi/scsi_debug.c:7537\n scsi_queue_rq+0x16b4/0x2d10 drivers/scsi/scsi_lib.c:1521\n blk_mq_dispatch_rq_list+0xb9b/0x2700 block/blk-mq.c:1640\n __blk_mq_sched_dispatch_requests+0x28f/0x590 block/blk-mq-sched.c:325\n blk_mq_sched_dispatch_requests+0x105/0x190 block/blk-mq-sched.c:358\n __blk_mq_run_hw_queue+0xe5/0x150 block/blk-mq.c:1762\n __blk_mq_delay_run_hw_queue+0x4f8/0x5c0 block/blk-mq.c:1839\n blk_mq_run_hw_queue+0x18d/0x350 block/blk-mq.c:1891\n blk_mq_sched_insert_request+0x3db/0x4e0 block/blk-mq-sched.c:474\n blk_execute_rq_nowait+0x16b/0x1c0 block/blk-exec.c:63\n sg_common_write.isra.18+0xeb3/0x2000 drivers/scsi/sg.c:837\n sg_new_write.isra.19+0x570/0x8c0 drivers/scsi/sg.c:775\n sg_ioctl_common+0x14d6/0x2710 drivers/scsi/sg.c:941\n sg_ioctl+0xa2/0x180 drivers/scsi/sg.c:1166\n __x64_sys_ioctl+0x19d/0x220 fs/ioctl.c:52\n do_syscall_64+0x3a/0x80 arch/x86/entry/common.c:50\n entry_SYSCALL_64_after_hwframe+0x44/0xae arch/x86/entry/entry_64.S:113", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rh54-rh9r-p3ph/GHSA-rh54-rh9r-p3ph.json b/advisories/unreviewed/2024/06/GHSA-rh54-rh9r-p3ph/GHSA-rh54-rh9r-p3ph.json index 2ed0d678136..a280d28719c 100644 --- a/advisories/unreviewed/2024/06/GHSA-rh54-rh9r-p3ph/GHSA-rh54-rh9r-p3ph.json +++ b/advisories/unreviewed/2024/06/GHSA-rh54-rh9r-p3ph/GHSA-rh54-rh9r-p3ph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rh54-rh9r-p3ph", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38608" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix netif state handling\n\nmlx5e_suspend cleans resources only if netif_device_present() returns\ntrue. However, mlx5e_resume changes the state of netif, via\nmlx5e_nic_enable, only if reg_state == NETREG_REGISTERED.\nIn the below case, the above leads to NULL-ptr Oops[1] and memory\nleaks:\n\nmlx5e_probe\n _mlx5e_resume\n mlx5e_attach_netdev\n mlx5e_nic_enable <-- netdev not reg, not calling netif_device_attach()\n register_netdev <-- failed for some reason.\nERROR_FLOW:\n _mlx5e_suspend <-- netif_device_present return false, resources aren't freed :(\n\nHence, clean resources in this case as well.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0010 [#1] SMP\nCPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at0xffffffffffffffd6.\nRSP: 0018:ffff888178aaf758 EFLAGS: 00010246\nCall Trace:\n \n ? __die+0x20/0x60\n ? page_fault_oops+0x14c/0x3c0\n ? exc_page_fault+0x75/0x140\n ? asm_exc_page_fault+0x22/0x30\n notifier_call_chain+0x35/0xb0\n blocking_notifier_call_chain+0x3d/0x60\n mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core]\n mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core]\n mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib]\n mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib]\n __mlx5_ib_add+0x34/0xd0 [mlx5_ib]\n mlx5r_probe+0xe1/0x210 [mlx5_ib]\n ? auxiliary_match_id+0x6a/0x90\n auxiliary_bus_probe+0x38/0x80\n ? driver_sysfs_add+0x51/0x80\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n bus_probe_device+0x86/0xa0\n device_add+0x637/0x840\n __auxiliary_device_add+0x3b/0xa0\n add_adev+0xc9/0x140 [mlx5_core]\n mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core]\n mlx5_register_device+0x53/0xa0 [mlx5_core]\n mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core]\n mlx5_init_one+0x3b/0x60 [mlx5_core]\n probe_one+0x44c/0x730 [mlx5_core]\n local_pci_probe+0x3e/0x90\n pci_device_probe+0xbf/0x210\n ? kernfs_create_link+0x5d/0xa0\n ? sysfs_do_create_link_sd+0x60/0xc0\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n pci_bus_add_device+0x54/0x80\n pci_iov_add_virtfn+0x2e6/0x320\n sriov_enable+0x208/0x420\n mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core]\n sriov_numvfs_store+0xae/0x1a0\n kernfs_fop_write_iter+0x10c/0x1a0\n vfs_write+0x291/0x3c0\n ksys_write+0x5f/0xe0\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n CR2: 0000000000000000\n ---[ end trace 0000000000000000 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:20Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wjfp-mxjr-ch9p/GHSA-wjfp-mxjr-ch9p.json b/advisories/unreviewed/2024/06/GHSA-wjfp-mxjr-ch9p/GHSA-wjfp-mxjr-ch9p.json index 712fc9303f3..b4cfc40a724 100644 --- a/advisories/unreviewed/2024/06/GHSA-wjfp-mxjr-ch9p/GHSA-wjfp-mxjr-ch9p.json +++ b/advisories/unreviewed/2024/06/GHSA-wjfp-mxjr-ch9p/GHSA-wjfp-mxjr-ch9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjfp-mxjr-ch9p", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47614" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix a user-after-free in add_pble_prm\n\nWhen irdma_hmc_sd_one fails, 'chunk' is freed while its still on the PBLE\ninfo list.\n\nAdd the chunk entry to the PBLE info list only after successful setting of\nthe SD in irdma_hmc_sd_one.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wvrw-2fv8-cjvx/GHSA-wvrw-2fv8-cjvx.json b/advisories/unreviewed/2024/06/GHSA-wvrw-2fv8-cjvx/GHSA-wvrw-2fv8-cjvx.json index 4f0895140af..6eba75b5be2 100644 --- a/advisories/unreviewed/2024/06/GHSA-wvrw-2fv8-cjvx/GHSA-wvrw-2fv8-cjvx.json +++ b/advisories/unreviewed/2024/06/GHSA-wvrw-2fv8-cjvx/GHSA-wvrw-2fv8-cjvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvrw-2fv8-cjvx", - "modified": "2024-06-29T06:31:40Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-06-29T06:31:40Z", "aliases": [ "CVE-2024-37370" ], "details": "In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-28T22:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-855m-rfwj-vwj6/GHSA-855m-rfwj-vwj6.json b/advisories/unreviewed/2024/07/GHSA-855m-rfwj-vwj6/GHSA-855m-rfwj-vwj6.json index c71beadfa39..dff4922912a 100644 --- a/advisories/unreviewed/2024/07/GHSA-855m-rfwj-vwj6/GHSA-855m-rfwj-vwj6.json +++ b/advisories/unreviewed/2024/07/GHSA-855m-rfwj-vwj6/GHSA-855m-rfwj-vwj6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json b/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json index 1c5ad24b6be..1f1887ef919 100644 --- a/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json +++ b/advisories/unreviewed/2024/07/GHSA-8fxq-mgg4-pxg6/GHSA-8fxq-mgg4-pxg6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-8v54-983f-9crw/GHSA-8v54-983f-9crw.json b/advisories/unreviewed/2024/07/GHSA-8v54-983f-9crw/GHSA-8v54-983f-9crw.json index ecc023d7f6f..38797ef4f14 100644 --- a/advisories/unreviewed/2024/07/GHSA-8v54-983f-9crw/GHSA-8v54-983f-9crw.json +++ b/advisories/unreviewed/2024/07/GHSA-8v54-983f-9crw/GHSA-8v54-983f-9crw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-98v6-w4jr-4h5x/GHSA-98v6-w4jr-4h5x.json b/advisories/unreviewed/2024/07/GHSA-98v6-w4jr-4h5x/GHSA-98v6-w4jr-4h5x.json index b6defcee3c4..d791db17b2e 100644 --- a/advisories/unreviewed/2024/07/GHSA-98v6-w4jr-4h5x/GHSA-98v6-w4jr-4h5x.json +++ b/advisories/unreviewed/2024/07/GHSA-98v6-w4jr-4h5x/GHSA-98v6-w4jr-4h5x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-fp47-2qf9-ppjw/GHSA-fp47-2qf9-ppjw.json b/advisories/unreviewed/2024/07/GHSA-fp47-2qf9-ppjw/GHSA-fp47-2qf9-ppjw.json index 6b3508872cd..5e99e2dcfac 100644 --- a/advisories/unreviewed/2024/07/GHSA-fp47-2qf9-ppjw/GHSA-fp47-2qf9-ppjw.json +++ b/advisories/unreviewed/2024/07/GHSA-fp47-2qf9-ppjw/GHSA-fp47-2qf9-ppjw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json b/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json index 11db2d18c8c..c43c79750fd 100644 --- a/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json +++ b/advisories/unreviewed/2024/07/GHSA-w8hv-qc2j-9q6f/GHSA-w8hv-qc2j-9q6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8hv-qc2j-9q6f", - "modified": "2024-07-03T18:48:26Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-07-03T18:48:26Z", "aliases": [ "CVE-2024-39248" ], "details": "A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field at /admin.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T17:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json b/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json new file mode 100644 index 00000000000..02f64ac477c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gjq-7pvc-8hj3", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-8200" + ], + "details": "The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it possible for unauthenticated attackers to update an API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8200" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/reviews-feed/tags/1.1.2/class/Common/Builder/SBR_Feed_Saver_Manager.php#L699" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3125315" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5d9e20f7-813c-4691-bce4-d0ff4774ae48?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json b/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json new file mode 100644 index 00000000000..ccf9c114480 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-364c-g6gq-6jw3/GHSA-364c-g6gq-6jw3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-364c-g6gq-6jw3", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-44340" + ], + "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44340" + }, + { + "type": "WEB", + "url": "https://github.com/yali-1002/some-poc/blob/main/CVE-2024-44340" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + }, + { + "type": "WEB", + "url": "http://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DIR-846W" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3pph-x43c-2v7f/GHSA-3pph-x43c-2v7f.json b/advisories/unreviewed/2024/08/GHSA-3pph-x43c-2v7f/GHSA-3pph-x43c-2v7f.json index 14a9150dda7..5637a1fdf4a 100644 --- a/advisories/unreviewed/2024/08/GHSA-3pph-x43c-2v7f/GHSA-3pph-x43c-2v7f.json +++ b/advisories/unreviewed/2024/08/GHSA-3pph-x43c-2v7f/GHSA-3pph-x43c-2v7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3pph-x43c-2v7f", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44934" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: wait for previous gc cycles when removing port\n\nsyzbot hit a use-after-free[1] which is caused because the bridge doesn't\nmake sure that all previous garbage has been collected when removing a\nport. What happens is:\n CPU 1 CPU 2\n start gc cycle remove port\n acquire gc lock first\n wait for lock\n call br_multicasg_gc() directly\n acquire lock now but free port\n the port can be freed\n while grp timers still\n running\n\nMake sure all previous gc cycles have finished by using flush_work before\nfreeing the port.\n\n[1]\n BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699\n\n CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024\n Call Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n call_timer_fn+0x1a3/0x610 kernel/time/timer.c:1792\n expire_timers kernel/time/timer.c:1843 [inline]\n __run_timers+0x74b/0xaf0 kernel/time/timer.c:2417\n __run_timer_base kernel/time/timer.c:2428 [inline]\n __run_timer_base kernel/time/timer.c:2421 [inline]\n run_timer_base+0x111/0x190 kernel/time/timer.c:2437", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json b/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json new file mode 100644 index 00000000000..ede67436833 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3qv5-2hqj-p2wq/GHSA-3qv5-2hqj-p2wq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qv5-2hqj-p2wq", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-44341" + ], + "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44341" + }, + { + "type": "WEB", + "url": "https://github.com/yali-1002/some-poc/blob/main/CVE-2024-44341" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + }, + { + "type": "WEB", + "url": "http://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DIR-846W" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json b/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json index 97f3773e173..26839644338 100644 --- a/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json +++ b/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3xww-gg44-m2qc", - "modified": "2024-08-26T18:33:33Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-23T18:33:01Z", "aliases": [ "CVE-2024-42756" ], "details": "An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T16:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5h76-r73j-v39g/GHSA-5h76-r73j-v39g.json b/advisories/unreviewed/2024/08/GHSA-5h76-r73j-v39g/GHSA-5h76-r73j-v39g.json new file mode 100644 index 00000000000..7fe7074ab8b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5h76-r73j-v39g/GHSA-5h76-r73j-v39g.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h76-r73j-v39g", + "modified": "2024-08-27T18:31:38Z", + "published": "2024-08-27T18:31:38Z", + "aliases": [ + "CVE-2024-8208" + ], + "details": "A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file editClient.php. The manipulation of the argument AGENT ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8208" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275917" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393511" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-62rx-986c-7pg7/GHSA-62rx-986c-7pg7.json b/advisories/unreviewed/2024/08/GHSA-62rx-986c-7pg7/GHSA-62rx-986c-7pg7.json index aa6444ac2dd..7cd394df5d6 100644 --- a/advisories/unreviewed/2024/08/GHSA-62rx-986c-7pg7/GHSA-62rx-986c-7pg7.json +++ b/advisories/unreviewed/2024/08/GHSA-62rx-986c-7pg7/GHSA-62rx-986c-7pg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62rx-986c-7pg7", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-43911" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix NULL dereference at band check in starting tx ba session\n\nIn MLD connection, link_data/link_conf are dynamically allocated. They\ndon't point to vif->bss_conf. So, there will be no chanreq assigned to\nvif->bss_conf and then the chan will be NULL. Tweak the code to check\nht_supported/vht_supported/has_he/has_eht on sta deflink.\n\nCrash log (with rtw89 version under MLO development):\n[ 9890.526087] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 9890.526102] #PF: supervisor read access in kernel mode\n[ 9890.526105] #PF: error_code(0x0000) - not-present page\n[ 9890.526109] PGD 0 P4D 0\n[ 9890.526114] Oops: 0000 [#1] PREEMPT SMP PTI\n[ 9890.526119] CPU: 2 PID: 6367 Comm: kworker/u16:2 Kdump: loaded Tainted: G OE 6.9.0 #1\n[ 9890.526123] Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB3WW (2.73 ) 11/28/2018\n[ 9890.526126] Workqueue: phy2 rtw89_core_ba_work [rtw89_core]\n[ 9890.526203] RIP: 0010:ieee80211_start_tx_ba_session (net/mac80211/agg-tx.c:618 (discriminator 1)) mac80211\n[ 9890.526279] Code: f7 e8 d5 93 3e ea 48 83 c4 28 89 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 49 8b 84 24 e0 f1 ff ff 48 8b 80 90 1b 00 00 <83> 38 03 0f 84 37 fe ff ff bb ea ff ff ff eb cc 49 8b 84 24 10 f3\nAll code\n========\n 0:\tf7 e8 \timul %eax\n 2:\td5 \t(bad)\n 3:\t93 \txchg %eax,%ebx\n 4:\t3e ea \tds (bad)\n 6:\t48 83 c4 28 \tadd $0x28,%rsp\n a:\t89 d8 \tmov %ebx,%eax\n c:\t5b \tpop %rbx\n d:\t41 5c \tpop %r12\n f:\t41 5d \tpop %r13\n 11:\t41 5e \tpop %r14\n 13:\t41 5f \tpop %r15\n 15:\t5d \tpop %rbp\n 16:\tc3 \tretq\n 17:\tcc \tint3\n 18:\tcc \tint3\n 19:\tcc \tint3\n 1a:\tcc \tint3\n 1b:\t49 8b 84 24 e0 f1 ff \tmov -0xe20(%r12),%rax\n 22:\tff\n 23:\t48 8b 80 90 1b 00 00 \tmov 0x1b90(%rax),%rax\n 2a:*\t83 38 03 \tcmpl $0x3,(%rax)\t\t<-- trapping instruction\n 2d:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe6a\n 33:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n 38:\teb cc \tjmp 0x6\n 3a:\t49 \trex.WB\n 3b:\t8b \t.byte 0x8b\n 3c:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 3f:\tf3 \trepz\n\nCode starting with the faulting instruction\n===========================================\n 0:\t83 38 03 \tcmpl $0x3,(%rax)\n 3:\t0f 84 37 fe ff ff \tje 0xfffffffffffffe40\n 9:\tbb ea ff ff ff \tmov $0xffffffea,%ebx\n e:\teb cc \tjmp 0xffffffffffffffdc\n 10:\t49 \trex.WB\n 11:\t8b \t.byte 0x8b\n 12:\t84 24 10 \ttest %ah,(%rax,%rdx,1)\n 15:\tf3 \trepz\n[ 9890.526285] RSP: 0018:ffffb8db09013d68 EFLAGS: 00010246\n[ 9890.526291] RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff9308e0d656c8\n[ 9890.526295] RDX: 0000000000000000 RSI: ffffffffab99460b RDI: ffffffffab9a7685\n[ 9890.526300] RBP: ffffb8db09013db8 R08: 0000000000000000 R09: 0000000000000873\n[ 9890.526304] R10: ffff9308e0d64800 R11: 0000000000000002 R12: ffff9308e5ff6e70\n[ 9890.526308] R13: ffff930952500e20 R14: ffff9309192a8c00 R15: 0000000000000000\n[ 9890.526313] FS: 0000000000000000(0000) GS:ffff930b4e700000(0000) knlGS:0000000000000000\n[ 9890.526316] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9890.526318] CR2: 0000000000000000 CR3: 0000000391c58005 CR4: 00000000001706f0\n[ 9890.526321] Call Trace:\n[ 9890.526324] \n[ 9890.526327] ? show_regs (arch/x86/kernel/dumpstack.c:479)\n[ 9890.526335] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n[ 9890.526340] ? page_fault_oops (arch/x86/mm/fault.c:713)\n[ 9890.526347] ? search_module_extables (kernel/module/main.c:3256 (discriminator\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json b/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json index ab24c1929e8..75db548ef92 100644 --- a/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json +++ b/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json b/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json index be2938f9b8c..0ba2886bbf9 100644 --- a/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json +++ b/advisories/unreviewed/2024/08/GHSA-6fcq-8rv2-rc2j/GHSA-6fcq-8rv2-rc2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fcq-8rv2-rc2j", - "modified": "2024-08-23T18:33:02Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-23T18:33:02Z", "aliases": [ "CVE-2024-32501" ], "details": "A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T17:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6j9q-v6p5-9p93/GHSA-6j9q-v6p5-9p93.json b/advisories/unreviewed/2024/08/GHSA-6j9q-v6p5-9p93/GHSA-6j9q-v6p5-9p93.json index 9373328e7dc..84c11d48b67 100644 --- a/advisories/unreviewed/2024/08/GHSA-6j9q-v6p5-9p93/GHSA-6j9q-v6p5-9p93.json +++ b/advisories/unreviewed/2024/08/GHSA-6j9q-v6p5-9p93/GHSA-6j9q-v6p5-9p93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6j9q-v6p5-9p93", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48915" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: Fix TZ_GET_TRIP NULL pointer dereference\n\nDo not call get_trip_hyst() from thermal_genl_cmd_tz_get_trip() if\nthe thermal zone does not define one.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json b/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json new file mode 100644 index 00000000000..eea2fb52e6c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6q99-8h4h-jqfw/GHSA-6q99-8h4h-jqfw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q99-8h4h-jqfw", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2022-39996" + ], + "details": "Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39996" + }, + { + "type": "WEB", + "url": "https://github.com/uyhacked/Teldat-s-Router/blob/main/Teldat" + }, + { + "type": "WEB", + "url": "https://github.com/uyhacked/Teldat-s-Router/blob/main/Teldat%27s%20Router%20Vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-76mr-xp5q-rcx7/GHSA-76mr-xp5q-rcx7.json b/advisories/unreviewed/2024/08/GHSA-76mr-xp5q-rcx7/GHSA-76mr-xp5q-rcx7.json index 9b31a58d62f..41b838e86b7 100644 --- a/advisories/unreviewed/2024/08/GHSA-76mr-xp5q-rcx7/GHSA-76mr-xp5q-rcx7.json +++ b/advisories/unreviewed/2024/08/GHSA-76mr-xp5q-rcx7/GHSA-76mr-xp5q-rcx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76mr-xp5q-rcx7", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:37Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44942" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/inline.c:258!\nCPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0\nRIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258\nCall Trace:\n f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834\n f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315\n do_writepages+0x35b/0x870 mm/page-writeback.c:2612\n __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650\n writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941\n wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117\n wb_do_writeback fs/fs-writeback.c:2264 [inline]\n wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335\n worker_thread+0x86d/0xd70 kernel/workqueue.c:3416\n kthread+0x2f2/0x390 kernel/kthread.c:388\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nThe root cause is: inline_data inode can be fuzzed, so that there may\nbe valid blkaddr in its direct node, once f2fs triggers background GC\nto migrate the block, it will hit f2fs_bug_on() during dirty page\nwriteback.\n\nLet's add sanity check on F2FS_INLINE_DATA flag in inode during GC,\nso that, it can forbid migrating inline_data inode's data block for\nfixing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T12:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7cfc-62qm-phmg/GHSA-7cfc-62qm-phmg.json b/advisories/unreviewed/2024/08/GHSA-7cfc-62qm-phmg/GHSA-7cfc-62qm-phmg.json new file mode 100644 index 00000000000..1a20ba3c423 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7cfc-62qm-phmg/GHSA-7cfc-62qm-phmg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cfc-62qm-phmg", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-45264" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45264" + }, + { + "type": "WEB", + "url": "https://github.com/TheHermione/CVE-2024-45264" + }, + { + "type": "WEB", + "url": "https://skyss.ru" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7j9r-86q2-3pwq/GHSA-7j9r-86q2-3pwq.json b/advisories/unreviewed/2024/08/GHSA-7j9r-86q2-3pwq/GHSA-7j9r-86q2-3pwq.json index 7231c6ec2a3..cba2becf95f 100644 --- a/advisories/unreviewed/2024/08/GHSA-7j9r-86q2-3pwq/GHSA-7j9r-86q2-3pwq.json +++ b/advisories/unreviewed/2024/08/GHSA-7j9r-86q2-3pwq/GHSA-7j9r-86q2-3pwq.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json b/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json index c1248219f7c..0eda4f3bf34 100644 --- a/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json +++ b/advisories/unreviewed/2024/08/GHSA-7r5c-r5ww-995h/GHSA-7r5c-r5ww-995h.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json b/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json index 2b13796587c..e80e71a3b6d 100644 --- a/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json +++ b/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v24-gjqv-fwg7", - "modified": "2024-08-26T18:33:33Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-39717" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://support.versa-networks.com/support/solutions/articles/23000026724-versa-director-ha-port-exploit-discovery-remediation" + }, + { + "type": "WEB", + "url": "https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json b/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json index 4943ceee609..bf9e6891303 100644 --- a/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json +++ b/advisories/unreviewed/2024/08/GHSA-896v-mq35-7wx7/GHSA-896v-mq35-7wx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-896v-mq35-7wx7", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-27T18:31:37Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-39097" ], "details": "There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T15:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json b/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json new file mode 100644 index 00000000000..214ffcc02e7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-98g8-h992-mhww/GHSA-98g8-h992-mhww.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98g8-h992-mhww", + "modified": "2024-08-27T18:31:38Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-36068" + ], + "details": "An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36068" + }, + { + "type": "WEB", + "url": "https://www.rubrik.com/advisories/rbk-20240619-v0044" + }, + { + "type": "WEB", + "url": "https://www.rubrik.com/products/cloud-data-management" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c45v-q3w8-jqpq/GHSA-c45v-q3w8-jqpq.json b/advisories/unreviewed/2024/08/GHSA-c45v-q3w8-jqpq/GHSA-c45v-q3w8-jqpq.json index 98531d8f4b7..5257414e754 100644 --- a/advisories/unreviewed/2024/08/GHSA-c45v-q3w8-jqpq/GHSA-c45v-q3w8-jqpq.json +++ b/advisories/unreviewed/2024/08/GHSA-c45v-q3w8-jqpq/GHSA-c45v-q3w8-jqpq.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-f2cf-vg85-495f/GHSA-f2cf-vg85-495f.json b/advisories/unreviewed/2024/08/GHSA-f2cf-vg85-495f/GHSA-f2cf-vg85-495f.json index 6e5935691ff..39c9f95eb25 100644 --- a/advisories/unreviewed/2024/08/GHSA-f2cf-vg85-495f/GHSA-f2cf-vg85-495f.json +++ b/advisories/unreviewed/2024/08/GHSA-f2cf-vg85-495f/GHSA-f2cf-vg85-495f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2cf-vg85-495f", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48918" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niwlwifi: mvm: check debugfs_dir ptr before use\n\nWhen \"debugfs=off\" is used on the kernel command line, iwiwifi's\nmvm module uses an invalid/unchecked debugfs_dir pointer and causes\na BUG:\n\n BUG: kernel NULL pointer dereference, address: 000000000000004f\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP\n CPU: 1 PID: 503 Comm: modprobe Tainted: G W 5.17.0-rc5 #7\n Hardware name: Dell Inc. Inspiron 15 5510/076F7Y, BIOS 2.4.1 11/05/2021\n RIP: 0010:iwl_mvm_dbgfs_register+0x692/0x700 [iwlmvm]\n Code: 69 a0 be 80 01 00 00 48 c7 c7 50 73 6a a0 e8 95 cf ee e0 48 8b 83 b0 1e 00 00 48 c7 c2 54 73 6a a0 be 64 00 00 00 48 8d 7d 8c <48> 8b 48 50 e8 15 22 07 e1 48 8b 43 28 48 8d 55 8c 48 c7 c7 5f 73\n RSP: 0018:ffffc90000a0ba68 EFLAGS: 00010246\n RAX: ffffffffffffffff RBX: ffff88817d6e3328 RCX: ffff88817d6e3328\n RDX: ffffffffa06a7354 RSI: 0000000000000064 RDI: ffffc90000a0ba6c\n RBP: ffffc90000a0bae0 R08: ffffffff824e4880 R09: ffffffffa069d620\n R10: ffffc90000a0ba00 R11: ffffffffffffffff R12: 0000000000000000\n R13: ffffc90000a0bb28 R14: ffff88817d6e3328 R15: ffff88817d6e3320\n FS: 00007f64dd92d740(0000) GS:ffff88847f640000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000004f CR3: 000000016fc79001 CR4: 0000000000770ee0\n PKRU: 55555554\n Call Trace:\n \n ? iwl_mvm_mac_setup_register+0xbdc/0xda0 [iwlmvm]\n iwl_mvm_start_post_nvm+0x71/0x100 [iwlmvm]\n iwl_op_mode_mvm_start+0xab8/0xb30 [iwlmvm]\n _iwl_op_mode_start+0x6f/0xd0 [iwlwifi]\n iwl_opmode_register+0x6a/0xe0 [iwlwifi]\n ? 0xffffffffa0231000\n iwl_mvm_init+0x35/0x1000 [iwlmvm]\n ? 0xffffffffa0231000\n do_one_initcall+0x5a/0x1b0\n ? kmem_cache_alloc+0x1e5/0x2f0\n ? do_init_module+0x1e/0x220\n do_init_module+0x48/0x220\n load_module+0x2602/0x2bc0\n ? __kernel_read+0x145/0x2e0\n ? kernel_read_file+0x229/0x290\n __do_sys_finit_module+0xc5/0x130\n ? __do_sys_finit_module+0xc5/0x130\n __x64_sys_finit_module+0x13/0x20\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7f64dda564dd\n Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 1b 29 0f 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffdba393f88 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f64dda564dd\n RDX: 0000000000000000 RSI: 00005575399e2ab2 RDI: 0000000000000001\n RBP: 000055753a91c5e0 R08: 0000000000000000 R09: 0000000000000002\n R10: 0000000000000001 R11: 0000000000000246 R12: 00005575399e2ab2\n R13: 000055753a91ceb0 R14: 0000000000000000 R15: 000055753a923018\n \n Modules linked in: btintel(+) btmtk bluetooth vfat snd_hda_codec_hdmi fat snd_hda_codec_realtek snd_hda_codec_generic iwlmvm(+) snd_sof_pci_intel_tgl mac80211 snd_sof_intel_hda_common soundwire_intel soundwire_generic_allocation soundwire_cadence soundwire_bus snd_sof_intel_hda snd_sof_pci snd_sof snd_sof_xtensa_dsp snd_soc_hdac_hda snd_hda_ext_core snd_soc_acpi_intel_match snd_soc_acpi snd_soc_core btrfs snd_compress snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec raid6_pq iwlwifi snd_hda_core snd_pcm snd_timer snd soundcore cfg80211 intel_ish_ipc(+) thunderbolt rfkill intel_ishtp ucsi_acpi wmi i2c_hid_acpi i2c_hid evdev\n CR2: 000000000000004f\n ---[ end trace 0000000000000000 ]---\n\nCheck the debugfs_dir pointer for an error before using it.\n\n[change to make both conditional]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f5r3-g3cg-82j6/GHSA-f5r3-g3cg-82j6.json b/advisories/unreviewed/2024/08/GHSA-f5r3-g3cg-82j6/GHSA-f5r3-g3cg-82j6.json index 0005d459edc..36d21d62c85 100644 --- a/advisories/unreviewed/2024/08/GHSA-f5r3-g3cg-82j6/GHSA-f5r3-g3cg-82j6.json +++ b/advisories/unreviewed/2024/08/GHSA-f5r3-g3cg-82j6/GHSA-f5r3-g3cg-82j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5r3-g3cg-82j6", - "modified": "2024-08-25T00:30:32Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-25T00:30:32Z", "aliases": [ "CVE-2024-45239" ], "details": "An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-24T23:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f628-324p-cgr6/GHSA-f628-324p-cgr6.json b/advisories/unreviewed/2024/08/GHSA-f628-324p-cgr6/GHSA-f628-324p-cgr6.json index a7fd1ca6110..86f8073d8ec 100644 --- a/advisories/unreviewed/2024/08/GHSA-f628-324p-cgr6/GHSA-f628-324p-cgr6.json +++ b/advisories/unreviewed/2024/08/GHSA-f628-324p-cgr6/GHSA-f628-324p-cgr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f628-324p-cgr6", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:37Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44935" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: Fix null-ptr-deref in reuseport_add_sock().\n\nsyzbot reported a null-ptr-deref while accessing sk2->sk_reuseport_cb in\nreuseport_add_sock(). [0]\n\nThe repro first creates a listener with SO_REUSEPORT. Then, it creates\nanother listener on the same port and concurrently closes the first\nlistener.\n\nThe second listen() calls reuseport_add_sock() with the first listener as\nsk2, where sk2->sk_reuseport_cb is not expected to be cleared concurrently,\nbut the close() does clear it by reuseport_detach_sock().\n\nThe problem is SCTP does not properly synchronise reuseport_alloc(),\nreuseport_add_sock(), and reuseport_detach_sock().\n\nThe caller of reuseport_alloc() and reuseport_{add,detach}_sock() must\nprovide synchronisation for sockets that are classified into the same\nreuseport group.\n\nOtherwise, such sockets form multiple identical reuseport groups, and\nall groups except one would be silently dead.\n\n 1. Two sockets call listen() concurrently\n 2. No socket in the same group found in sctp_ep_hashtable[]\n 3. Two sockets call reuseport_alloc() and form two reuseport groups\n 4. Only one group hit first in __sctp_rcv_lookup_endpoint() receives\n incoming packets\n\nAlso, the reported null-ptr-deref could occur.\n\nTCP/UDP guarantees that would not happen by holding the hash bucket lock.\n\nLet's apply the locking strategy to __sctp_hash_endpoint() and\n__sctp_unhash_endpoint().\n\n[0]:\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nCPU: 1 UID: 0 PID: 10230 Comm: syz-executor119 Not tainted 6.10.0-syzkaller-12585-g301927d2d2eb #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024\nRIP: 0010:reuseport_add_sock+0x27e/0x5e0 net/core/sock_reuseport.c:350\nCode: 00 0f b7 5d 00 bf 01 00 00 00 89 de e8 1b a4 ff f7 83 fb 01 0f 85 a3 01 00 00 e8 6d a0 ff f7 49 8d 7e 12 48 89 f8 48 c1 e8 03 <42> 0f b6 04 28 84 c0 0f 85 4b 02 00 00 41 0f b7 5e 12 49 8d 7e 14\nRSP: 0018:ffffc9000b947c98 EFLAGS: 00010202\nRAX: 0000000000000002 RBX: ffff8880252ddf98 RCX: ffff888079478000\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000012\nRBP: 0000000000000001 R08: ffffffff8993e18d R09: 1ffffffff1fef385\nR10: dffffc0000000000 R11: fffffbfff1fef386 R12: ffff8880252ddac0\nR13: dffffc0000000000 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f24e45b96c0(0000) GS:ffff8880b9300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffcced5f7b8 CR3: 00000000241be000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __sctp_hash_endpoint net/sctp/input.c:762 [inline]\n sctp_hash_endpoint+0x52a/0x600 net/sctp/input.c:790\n sctp_listen_start net/sctp/socket.c:8570 [inline]\n sctp_inet_listen+0x767/0xa20 net/sctp/socket.c:8625\n __sys_listen_socket net/socket.c:1883 [inline]\n __sys_listen+0x1b7/0x230 net/socket.c:1894\n __do_sys_listen net/socket.c:1902 [inline]\n __se_sys_listen net/socket.c:1900 [inline]\n __x64_sys_listen+0x5a/0x70 net/socket.c:1900\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f24e46039b9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 91 1a 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f24e45b9228 EFLAGS: 00000246 ORIG_RAX: 0000000000000032\nRAX: ffffffffffffffda RBX: 00007f24e468e428 RCX: 00007f24e46039b9\nRDX: 00007f24e46039b9 RSI: 0000000000000003 RDI: 0000000000000004\nRBP: 00007f24e468e420 R08: 00007f24e45b96c0 R09: 00007f24e45b96c0\nR10: 00007f24e45b96c0 R11: 0000000000000246 R12: 00007f24e468e42c\nR13:\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json b/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json new file mode 100644 index 00000000000..bf9977b03b9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjcf-776g-8w8g", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-40395" + ], + "details": "An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40395" + }, + { + "type": "WEB", + "url": "https://pastebin.com/9dc4LYGA" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h3w8-q2j6-4h9m/GHSA-h3w8-q2j6-4h9m.json b/advisories/unreviewed/2024/08/GHSA-h3w8-q2j6-4h9m/GHSA-h3w8-q2j6-4h9m.json index 6c95e6ac2ec..dfd30a06d61 100644 --- a/advisories/unreviewed/2024/08/GHSA-h3w8-q2j6-4h9m/GHSA-h3w8-q2j6-4h9m.json +++ b/advisories/unreviewed/2024/08/GHSA-h3w8-q2j6-4h9m/GHSA-h3w8-q2j6-4h9m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3w8-q2j6-4h9m", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44932" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix UAFs when destroying the queues\n\nThe second tagged commit started sometimes (very rarely, but possible)\nthrowing WARNs from\nnet/core/page_pool.c:page_pool_disable_direct_recycling().\nTurned out idpf frees interrupt vectors with embedded NAPIs *before*\nfreeing the queues making page_pools' NAPI pointers lead to freed\nmemory before these pools are destroyed by libeth.\nIt's not clear whether there are other accesses to the freed vectors\nwhen destroying the queues, but anyway, we usually free queue/interrupt\nvectors only when the queues are destroyed and the NAPIs are guaranteed\nto not be referenced anywhere.\n\nInvert the allocation and freeing logic making queue/interrupt vectors\nbe allocated first and freed last. Vectors don't require queues to be\npresent, so this is safe. Additionally, this change allows to remove\nthat useless queue->q_vector pointer cleanup, as vectors are still\nvalid when freeing the queues (+ both are freed within one function,\nso it's not clear why nullify the pointers at all).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json b/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json index 65609775387..69f4c561281 100644 --- a/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json +++ b/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6q6-xxwv-mm6v", - "modified": "2024-08-25T00:30:31Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-25T00:30:31Z", "aliases": [ "CVE-2024-45234" ], "details": "An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER decoder, reaching a point in the code that panics when faced with data not encoded in DER. Because Fort is an RPKI Relying Party, a panic can lead to Route Origin Validation unavailability, which can lead to compromised routing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-24T23:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hg7f-mj9p-7743/GHSA-hg7f-mj9p-7743.json b/advisories/unreviewed/2024/08/GHSA-hg7f-mj9p-7743/GHSA-hg7f-mj9p-7743.json index 43fbf9ae7a0..6147a877c76 100644 --- a/advisories/unreviewed/2024/08/GHSA-hg7f-mj9p-7743/GHSA-hg7f-mj9p-7743.json +++ b/advisories/unreviewed/2024/08/GHSA-hg7f-mj9p-7743/GHSA-hg7f-mj9p-7743.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json b/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json index 6f9b5dc8f11..b784723ecdc 100644 --- a/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json +++ b/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw6m-6w6g-wxq7", - "modified": "2024-08-26T21:30:34Z", + "modified": "2024-08-27T18:31:37Z", "published": "2024-08-26T21:30:34Z", "aliases": [ "CVE-2024-44797" ], "details": "A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json b/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json index a7842de4ae7..7627212937b 100644 --- a/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json +++ b/advisories/unreviewed/2024/08/GHSA-j26h-qjc9-68hh/GHSA-j26h-qjc9-68hh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j26h-qjc9-68hh", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-27T18:31:37Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2023-49582" ], "details": "Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. \n\nThis issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)\n\nUsers are recommended to upgrade to APR version 1.7.5, which fixes this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-732" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T14:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j2cw-jh9j-qmpx/GHSA-j2cw-jh9j-qmpx.json b/advisories/unreviewed/2024/08/GHSA-j2cw-jh9j-qmpx/GHSA-j2cw-jh9j-qmpx.json index b05c9751f22..049f351e49d 100644 --- a/advisories/unreviewed/2024/08/GHSA-j2cw-jh9j-qmpx/GHSA-j2cw-jh9j-qmpx.json +++ b/advisories/unreviewed/2024/08/GHSA-j2cw-jh9j-qmpx/GHSA-j2cw-jh9j-qmpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2cw-jh9j-qmpx", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48913" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblktrace: fix use after free for struct blk_trace\n\nWhen tracing the whole disk, 'dropped' and 'msg' will be created\nunder 'q->debugfs_dir' and 'bt->dir' is NULL, thus blk_trace_free()\nwon't remove those files. What's worse, the following UAF can be\ntriggered because of accessing stale 'dropped' and 'msg':\n\n==================================================================\nBUG: KASAN: use-after-free in blk_dropped_read+0x89/0x100\nRead of size 4 at addr ffff88816912f3d8 by task blktrace/1188\n\nCPU: 27 PID: 1188 Comm: blktrace Not tainted 5.17.0-rc4-next-20220217+ #469\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ?-20190727_073836-4\nCall Trace:\n \n dump_stack_lvl+0x34/0x44\n print_address_description.constprop.0.cold+0xab/0x381\n ? blk_dropped_read+0x89/0x100\n ? blk_dropped_read+0x89/0x100\n kasan_report.cold+0x83/0xdf\n ? blk_dropped_read+0x89/0x100\n kasan_check_range+0x140/0x1b0\n blk_dropped_read+0x89/0x100\n ? blk_create_buf_file_callback+0x20/0x20\n ? kmem_cache_free+0xa1/0x500\n ? do_sys_openat2+0x258/0x460\n full_proxy_read+0x8f/0xc0\n vfs_read+0xc6/0x260\n ksys_read+0xb9/0x150\n ? vfs_write+0x3d0/0x3d0\n ? fpregs_assert_state_consistent+0x55/0x60\n ? exit_to_user_mode_prepare+0x39/0x1e0\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7fbc080d92fd\nCode: ce 20 00 00 75 10 b8 00 00 00 00 0f 05 48 3d 01 f0 ff ff 73 31 c3 48 83 1\nRSP: 002b:00007fbb95ff9cb0 EFLAGS: 00000293 ORIG_RAX: 0000000000000000\nRAX: ffffffffffffffda RBX: 00007fbb95ff9dc0 RCX: 00007fbc080d92fd\nRDX: 0000000000000100 RSI: 00007fbb95ff9cc0 RDI: 0000000000000045\nRBP: 0000000000000045 R08: 0000000000406299 R09: 00000000fffffffd\nR10: 000000000153afa0 R11: 0000000000000293 R12: 00007fbb780008c0\nR13: 00007fbb78000938 R14: 0000000000608b30 R15: 00007fbb780029c8\n \n\nAllocated by task 1050:\n kasan_save_stack+0x1e/0x40\n __kasan_kmalloc+0x81/0xa0\n do_blk_trace_setup+0xcb/0x410\n __blk_trace_setup+0xac/0x130\n blk_trace_ioctl+0xe9/0x1c0\n blkdev_ioctl+0xf1/0x390\n __x64_sys_ioctl+0xa5/0xe0\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nFreed by task 1050:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_set_free_info+0x20/0x30\n __kasan_slab_free+0x103/0x180\n kfree+0x9a/0x4c0\n __blk_trace_remove+0x53/0x70\n blk_trace_ioctl+0x199/0x1c0\n blkdev_common_ioctl+0x5e9/0xb30\n blkdev_ioctl+0x1a5/0x390\n __x64_sys_ioctl+0xa5/0xe0\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nThe buggy address belongs to the object at ffff88816912f380\n which belongs to the cache kmalloc-96 of size 96\nThe buggy address is located 88 bytes inside of\n 96-byte region [ffff88816912f380, ffff88816912f3e0)\nThe buggy address belongs to the page:\npage:000000009a1b4e7c refcount:1 mapcount:0 mapping:0000000000000000 index:0x0f\nflags: 0x17ffffc0000200(slab|node=0|zone=2|lastcpupid=0x1fffff)\nraw: 0017ffffc0000200 ffffea00044f1100 dead000000000002 ffff88810004c780\nraw: 0000000000000000 0000000000200020 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff88816912f280: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ffff88816912f300: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n>ffff88816912f380: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ^\n ffff88816912f400: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ffff88816912f480: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n==================================================================", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j88q-33h3-g8px/GHSA-j88q-33h3-g8px.json b/advisories/unreviewed/2024/08/GHSA-j88q-33h3-g8px/GHSA-j88q-33h3-g8px.json index 38c3f072ae7..f4d92575286 100644 --- a/advisories/unreviewed/2024/08/GHSA-j88q-33h3-g8px/GHSA-j88q-33h3-g8px.json +++ b/advisories/unreviewed/2024/08/GHSA-j88q-33h3-g8px/GHSA-j88q-33h3-g8px.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-j96q-j829-h7g8/GHSA-j96q-j829-h7g8.json b/advisories/unreviewed/2024/08/GHSA-j96q-j829-h7g8/GHSA-j96q-j829-h7g8.json index 1774d3ed889..d37e69948cc 100644 --- a/advisories/unreviewed/2024/08/GHSA-j96q-j829-h7g8/GHSA-j96q-j829-h7g8.json +++ b/advisories/unreviewed/2024/08/GHSA-j96q-j829-h7g8/GHSA-j96q-j829-h7g8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j96q-j829-h7g8", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48919" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix double free race when mount fails in cifs_get_root()\n\nWhen cifs_get_root() fails during cifs_smb3_do_mount() we call\ndeactivate_locked_super() which eventually will call delayed_free() which\nwill free the context.\nIn this situation we should not proceed to enter the out: section in\ncifs_smb3_do_mount() and free the same resources a second time.\n\n[Thu Feb 10 12:59:06 2022] BUG: KASAN: use-after-free in rcu_cblist_dequeue+0x32/0x60\n[Thu Feb 10 12:59:06 2022] Read of size 8 at addr ffff888364f4d110 by task swapper/1/0\n\n[Thu Feb 10 12:59:06 2022] CPU: 1 PID: 0 Comm: swapper/1 Tainted: G OE 5.17.0-rc3+ #4\n[Thu Feb 10 12:59:06 2022] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.0 12/17/2019\n[Thu Feb 10 12:59:06 2022] Call Trace:\n[Thu Feb 10 12:59:06 2022] \n[Thu Feb 10 12:59:06 2022] dump_stack_lvl+0x5d/0x78\n[Thu Feb 10 12:59:06 2022] print_address_description.constprop.0+0x24/0x150\n[Thu Feb 10 12:59:06 2022] ? rcu_cblist_dequeue+0x32/0x60\n[Thu Feb 10 12:59:06 2022] kasan_report.cold+0x7d/0x117\n[Thu Feb 10 12:59:06 2022] ? rcu_cblist_dequeue+0x32/0x60\n[Thu Feb 10 12:59:06 2022] __asan_load8+0x86/0xa0\n[Thu Feb 10 12:59:06 2022] rcu_cblist_dequeue+0x32/0x60\n[Thu Feb 10 12:59:06 2022] rcu_core+0x547/0xca0\n[Thu Feb 10 12:59:06 2022] ? call_rcu+0x3c0/0x3c0\n[Thu Feb 10 12:59:06 2022] ? __this_cpu_preempt_check+0x13/0x20\n[Thu Feb 10 12:59:06 2022] ? lock_is_held_type+0xea/0x140\n[Thu Feb 10 12:59:06 2022] rcu_core_si+0xe/0x10\n[Thu Feb 10 12:59:06 2022] __do_softirq+0x1d4/0x67b\n[Thu Feb 10 12:59:06 2022] __irq_exit_rcu+0x100/0x150\n[Thu Feb 10 12:59:06 2022] irq_exit_rcu+0xe/0x30\n[Thu Feb 10 12:59:06 2022] sysvec_hyperv_stimer0+0x9d/0xc0\n...\n[Thu Feb 10 12:59:07 2022] Freed by task 58179:\n[Thu Feb 10 12:59:07 2022] kasan_save_stack+0x26/0x50\n[Thu Feb 10 12:59:07 2022] kasan_set_track+0x25/0x30\n[Thu Feb 10 12:59:07 2022] kasan_set_free_info+0x24/0x40\n[Thu Feb 10 12:59:07 2022] ____kasan_slab_free+0x137/0x170\n[Thu Feb 10 12:59:07 2022] __kasan_slab_free+0x12/0x20\n[Thu Feb 10 12:59:07 2022] slab_free_freelist_hook+0xb3/0x1d0\n[Thu Feb 10 12:59:07 2022] kfree+0xcd/0x520\n[Thu Feb 10 12:59:07 2022] cifs_smb3_do_mount+0x149/0xbe0 [cifs]\n[Thu Feb 10 12:59:07 2022] smb3_get_tree+0x1a0/0x2e0 [cifs]\n[Thu Feb 10 12:59:07 2022] vfs_get_tree+0x52/0x140\n[Thu Feb 10 12:59:07 2022] path_mount+0x635/0x10c0\n[Thu Feb 10 12:59:07 2022] __x64_sys_mount+0x1bf/0x210\n[Thu Feb 10 12:59:07 2022] do_syscall_64+0x5c/0xc0\n[Thu Feb 10 12:59:07 2022] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n[Thu Feb 10 12:59:07 2022] Last potentially related work creation:\n[Thu Feb 10 12:59:07 2022] kasan_save_stack+0x26/0x50\n[Thu Feb 10 12:59:07 2022] __kasan_record_aux_stack+0xb6/0xc0\n[Thu Feb 10 12:59:07 2022] kasan_record_aux_stack_noalloc+0xb/0x10\n[Thu Feb 10 12:59:07 2022] call_rcu+0x76/0x3c0\n[Thu Feb 10 12:59:07 2022] cifs_umount+0xce/0xe0 [cifs]\n[Thu Feb 10 12:59:07 2022] cifs_kill_sb+0xc8/0xe0 [cifs]\n[Thu Feb 10 12:59:07 2022] deactivate_locked_super+0x5d/0xd0\n[Thu Feb 10 12:59:07 2022] cifs_smb3_do_mount+0xab9/0xbe0 [cifs]\n[Thu Feb 10 12:59:07 2022] smb3_get_tree+0x1a0/0x2e0 [cifs]\n[Thu Feb 10 12:59:07 2022] vfs_get_tree+0x52/0x140\n[Thu Feb 10 12:59:07 2022] path_mount+0x635/0x10c0\n[Thu Feb 10 12:59:07 2022] __x64_sys_mount+0x1bf/0x210\n[Thu Feb 10 12:59:07 2022] do_syscall_64+0x5c/0xc0\n[Thu Feb 10 12:59:07 2022] entry_SYSCALL_64_after_hwframe+0x44/0xae", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m6c2-4qxx-95pf/GHSA-m6c2-4qxx-95pf.json b/advisories/unreviewed/2024/08/GHSA-m6c2-4qxx-95pf/GHSA-m6c2-4qxx-95pf.json new file mode 100644 index 00000000000..a1457aa7c10 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m6c2-4qxx-95pf/GHSA-m6c2-4qxx-95pf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6c2-4qxx-95pf", + "modified": "2024-08-27T18:31:38Z", + "published": "2024-08-27T18:31:38Z", + "aliases": [ + "CVE-2024-8209" + ], + "details": "A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file addClient.php. The manipulation of the argument CLIENT ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275918" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393512" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p534-c2v5-6ch3/GHSA-p534-c2v5-6ch3.json b/advisories/unreviewed/2024/08/GHSA-p534-c2v5-6ch3/GHSA-p534-c2v5-6ch3.json index d8d04c5d8ed..04cb15ff1c3 100644 --- a/advisories/unreviewed/2024/08/GHSA-p534-c2v5-6ch3/GHSA-p534-c2v5-6ch3.json +++ b/advisories/unreviewed/2024/08/GHSA-p534-c2v5-6ch3/GHSA-p534-c2v5-6ch3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p534-c2v5-6ch3", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44933" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl()\n\nA recent commit has modified the code in __bnxt_reserve_rings() to\nset the default RSS indirection table to default only when the number\nof RX rings is changing. While this works for newer firmware that\nrequires RX ring reservations, it causes the regression on older\nfirmware not requiring RX ring resrvations (BNXT_NEW_RM() returns\nfalse).\n\nWith older firmware, RX ring reservations are not required and so\nhw_resc->resv_rx_rings is not always set to the proper value. The\ncomparison:\n\nif (old_rx_rings != bp->hw_resc.resv_rx_rings)\n\nin __bnxt_reserve_rings() may be false even when the RX rings are\nchanging. This will cause __bnxt_reserve_rings() to skip setting\nthe default RSS indirection table to default to match the current\nnumber of RX rings. This may later cause bnxt_fill_hw_rss_tbl() to\nuse an out-of-range index.\n\nWe already have bnxt_check_rss_tbl_no_rmgr() to handle exactly this\nscenario. We just need to move it up in bnxt_need_reserve_rings()\nto be called unconditionally when using older firmware. Without the\nfix, if the TX rings are changing, we'll skip the\nbnxt_check_rss_tbl_no_rmgr() call and __bnxt_reserve_rings() may also\nskip the bnxt_set_dflt_rss_indir_tbl() call for the reason explained\nin the last paragraph. Without setting the default RSS indirection\ntable to default, it causes the regression:\n\nBUG: KASAN: slab-out-of-bounds in __bnxt_hwrm_vnic_set_rss+0xb79/0xe40\nRead of size 2 at addr ffff8881c5809618 by task ethtool/31525\nCall Trace:\n__bnxt_hwrm_vnic_set_rss+0xb79/0xe40\n bnxt_hwrm_vnic_rss_cfg_p5+0xf7/0x460\n __bnxt_setup_vnic_p5+0x12e/0x270\n __bnxt_open_nic+0x2262/0x2f30\n bnxt_open_nic+0x5d/0xf0\n ethnl_set_channels+0x5d4/0xb30\n ethnl_default_set_doit+0x2f1/0x620", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json b/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json new file mode 100644 index 00000000000..7d6bfee1b4e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p6m4-jqc8-546h/GHSA-p6m4-jqc8-546h.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6m4-jqc8-546h", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-41622" + ], + "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41622" + }, + { + "type": "WEB", + "url": "https://github.com/yali-1002/some-poc/blob/main/CVE-2024-41622" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + }, + { + "type": "WEB", + "url": "http://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DIR-846W" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-px8f-pf56-946w/GHSA-px8f-pf56-946w.json b/advisories/unreviewed/2024/08/GHSA-px8f-pf56-946w/GHSA-px8f-pf56-946w.json new file mode 100644 index 00000000000..6a3b54ea1c6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-px8f-pf56-946w/GHSA-px8f-pf56-946w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px8f-pf56-946w", + "modified": "2024-08-27T18:31:38Z", + "published": "2024-08-27T18:31:38Z", + "aliases": [ + "CVE-2024-7720" + ], + "details": "HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7720" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11074404-11074432-16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q758-vrcm-h66f/GHSA-q758-vrcm-h66f.json b/advisories/unreviewed/2024/08/GHSA-q758-vrcm-h66f/GHSA-q758-vrcm-h66f.json index ca19317b195..a59d5762068 100644 --- a/advisories/unreviewed/2024/08/GHSA-q758-vrcm-h66f/GHSA-q758-vrcm-h66f.json +++ b/advisories/unreviewed/2024/08/GHSA-q758-vrcm-h66f/GHSA-q758-vrcm-h66f.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-q866-q5rw-qh69/GHSA-q866-q5rw-qh69.json b/advisories/unreviewed/2024/08/GHSA-q866-q5rw-qh69/GHSA-q866-q5rw-qh69.json index 9a4fa2315f0..da7586fc850 100644 --- a/advisories/unreviewed/2024/08/GHSA-q866-q5rw-qh69/GHSA-q866-q5rw-qh69.json +++ b/advisories/unreviewed/2024/08/GHSA-q866-q5rw-qh69/GHSA-q866-q5rw-qh69.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-qff8-h2gh-57qq/GHSA-qff8-h2gh-57qq.json b/advisories/unreviewed/2024/08/GHSA-qff8-h2gh-57qq/GHSA-qff8-h2gh-57qq.json index 0520f7c7924..7836a1ea446 100644 --- a/advisories/unreviewed/2024/08/GHSA-qff8-h2gh-57qq/GHSA-qff8-h2gh-57qq.json +++ b/advisories/unreviewed/2024/08/GHSA-qff8-h2gh-57qq/GHSA-qff8-h2gh-57qq.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-v5cx-w2w4-m488/GHSA-v5cx-w2w4-m488.json b/advisories/unreviewed/2024/08/GHSA-v5cx-w2w4-m488/GHSA-v5cx-w2w4-m488.json index 9eb11f807e8..f947adafd23 100644 --- a/advisories/unreviewed/2024/08/GHSA-v5cx-w2w4-m488/GHSA-v5cx-w2w4-m488.json +++ b/advisories/unreviewed/2024/08/GHSA-v5cx-w2w4-m488/GHSA-v5cx-w2w4-m488.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5cx-w2w4-m488", - "modified": "2024-08-25T00:30:32Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-25T00:30:31Z", "aliases": [ "CVE-2024-45236" ], "details": "An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses the set's elements without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-24T23:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vcfw-6vgj-6mgp/GHSA-vcfw-6vgj-6mgp.json b/advisories/unreviewed/2024/08/GHSA-vcfw-6vgj-6mgp/GHSA-vcfw-6vgj-6mgp.json index 151d9172122..b55b44cd347 100644 --- a/advisories/unreviewed/2024/08/GHSA-vcfw-6vgj-6mgp/GHSA-vcfw-6vgj-6mgp.json +++ b/advisories/unreviewed/2024/08/GHSA-vcfw-6vgj-6mgp/GHSA-vcfw-6vgj-6mgp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vcfw-6vgj-6mgp", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-27T18:31:35Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48912" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: fix use-after-free in __nf_register_net_hook()\n\nWe must not dereference @new_hooks after nf_hook_mutex has been released,\nbecause other threads might have freed our allocated hooks already.\n\nBUG: KASAN: use-after-free in nf_hook_entries_get_hook_ops include/linux/netfilter.h:130 [inline]\nBUG: KASAN: use-after-free in hooks_validate net/netfilter/core.c:171 [inline]\nBUG: KASAN: use-after-free in __nf_register_net_hook+0x77a/0x820 net/netfilter/core.c:438\nRead of size 2 at addr ffff88801c1a8000 by task syz-executor237/4430\n\nCPU: 1 PID: 4430 Comm: syz-executor237 Not tainted 5.17.0-rc5-syzkaller-00306-g2293be58d6a1 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0x8d/0x336 mm/kasan/report.c:255\n __kasan_report mm/kasan/report.c:442 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:459\n nf_hook_entries_get_hook_ops include/linux/netfilter.h:130 [inline]\n hooks_validate net/netfilter/core.c:171 [inline]\n __nf_register_net_hook+0x77a/0x820 net/netfilter/core.c:438\n nf_register_net_hook+0x114/0x170 net/netfilter/core.c:571\n nf_register_net_hooks+0x59/0xc0 net/netfilter/core.c:587\n nf_synproxy_ipv6_init+0x85/0xe0 net/netfilter/nf_synproxy_core.c:1218\n synproxy_tg6_check+0x30d/0x560 net/ipv6/netfilter/ip6t_SYNPROXY.c:81\n xt_check_target+0x26c/0x9e0 net/netfilter/x_tables.c:1038\n check_target net/ipv6/netfilter/ip6_tables.c:530 [inline]\n find_check_entry.constprop.0+0x7f1/0x9e0 net/ipv6/netfilter/ip6_tables.c:573\n translate_table+0xc8b/0x1750 net/ipv6/netfilter/ip6_tables.c:735\n do_replace net/ipv6/netfilter/ip6_tables.c:1153 [inline]\n do_ip6t_set_ctl+0x56e/0xb90 net/ipv6/netfilter/ip6_tables.c:1639\n nf_setsockopt+0x83/0xe0 net/netfilter/nf_sockopt.c:101\n ipv6_setsockopt+0x122/0x180 net/ipv6/ipv6_sockglue.c:1024\n rawv6_setsockopt+0xd3/0x6a0 net/ipv6/raw.c:1084\n __sys_setsockopt+0x2db/0x610 net/socket.c:2180\n __do_sys_setsockopt net/socket.c:2191 [inline]\n __se_sys_setsockopt net/socket.c:2188 [inline]\n __x64_sys_setsockopt+0xba/0x150 net/socket.c:2188\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f65a1ace7d9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 71 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f65a1a7f308 EFLAGS: 00000246 ORIG_RAX: 0000000000000036\nRAX: ffffffffffffffda RBX: 0000000000000006 RCX: 00007f65a1ace7d9\nRDX: 0000000000000040 RSI: 0000000000000029 RDI: 0000000000000003\nRBP: 00007f65a1b574c8 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000020000000 R11: 0000000000000246 R12: 00007f65a1b55130\nR13: 00007f65a1b574c0 R14: 00007f65a1b24090 R15: 0000000000022000\n \n\nThe buggy address belongs to the page:\npage:ffffea0000706a00 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1c1a8\nflags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000000000 ffffea0001c1b108 ffffea000046dd08 0000000000000000\nraw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as freed\npage last allocated via order 2, migratetype Unmovable, gfp_mask 0x52dc0(GFP_KERNEL|__GFP_NOWARN|__GFP_NORETRY|__GFP_COMP|__GFP_ZERO), pid 4430, ts 1061781545818, free_ts 1061791488993\n prep_new_page mm/page_alloc.c:2434 [inline]\n get_page_from_freelist+0xa72/0x2f50 mm/page_alloc.c:4165\n __alloc_pages+0x1b2/0x500 mm/page_alloc.c:5389\n __alloc_pages_node include/linux/gfp.h:572 [inline]\n alloc_pages_node include/linux/gfp.h:595 [inline]\n kmalloc_large_node+0x62/0x130 mm/slub.c:4438\n __kmalloc_node+0x35a/0x4a0 mm/slub.\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vm7f-w6gx-mxh8/GHSA-vm7f-w6gx-mxh8.json b/advisories/unreviewed/2024/08/GHSA-vm7f-w6gx-mxh8/GHSA-vm7f-w6gx-mxh8.json index 97e0b1a9cab..51384558a20 100644 --- a/advisories/unreviewed/2024/08/GHSA-vm7f-w6gx-mxh8/GHSA-vm7f-w6gx-mxh8.json +++ b/advisories/unreviewed/2024/08/GHSA-vm7f-w6gx-mxh8/GHSA-vm7f-w6gx-mxh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vm7f-w6gx-mxh8", - "modified": "2024-08-22T03:31:34Z", + "modified": "2024-08-27T18:31:36Z", "published": "2024-08-22T03:31:34Z", "aliases": [ "CVE-2022-48924" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: int340x: fix memory leak in int3400_notify()\n\nIt is easy to hit the below memory leaks in my TigerLake platform:\n\nunreferenced object 0xffff927c8b91dbc0 (size 32):\n comm \"kworker/0:2\", pid 112, jiffies 4294893323 (age 83.604s)\n hex dump (first 32 bytes):\n 4e 41 4d 45 3d 49 4e 54 33 34 30 30 20 54 68 65 NAME=INT3400 The\n 72 6d 61 6c 00 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b a5 rmal.kkkkkkkkkk.\n backtrace:\n [] __kmalloc_track_caller+0x2fe/0x4a0\n [] kvasprintf+0x65/0xd0\n [] kasprintf+0x4e/0x70\n [] int3400_notify+0x82/0x120 [int3400_thermal]\n [] acpi_ev_notify_dispatch+0x54/0x71\n [] acpi_os_execute_deferred+0x17/0x30\n [] process_one_work+0x21a/0x3f0\n [] worker_thread+0x4a/0x3b0\n [] kthread+0xfd/0x130\n [] ret_from_fork+0x1f/0x30\n\nFix it by calling kfree() accordingly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T02:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w3ph-7hx8-wxg6/GHSA-w3ph-7hx8-wxg6.json b/advisories/unreviewed/2024/08/GHSA-w3ph-7hx8-wxg6/GHSA-w3ph-7hx8-wxg6.json index 2dfd37e8475..25d59abed75 100644 --- a/advisories/unreviewed/2024/08/GHSA-w3ph-7hx8-wxg6/GHSA-w3ph-7hx8-wxg6.json +++ b/advisories/unreviewed/2024/08/GHSA-w3ph-7hx8-wxg6/GHSA-w3ph-7hx8-wxg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3ph-7hx8-wxg6", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-27T18:31:37Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44937" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: intel-vbtn: Protect ACPI notify handler against recursion\n\nSince commit e2ffcda16290 (\"ACPI: OSL: Allow Notify () handlers to run on\nall CPUs\") ACPI notify handlers like the intel-vbtn notify_handler() may\nrun on multiple CPU cores racing with themselves.\n\nThis race gets hit on Dell Venue 7140 tablets when undocking from\nthe keyboard, causing the handler to try and register priv->switches_dev\ntwice, as can be seen from the dev_info() message getting logged twice:\n\n[ 83.861800] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n[ 83.861858] input: Intel Virtual Switches as /devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17\n[ 83.861865] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event\n\nAfter which things go seriously wrong:\n[ 83.861872] sysfs: cannot create duplicate filename '/devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17'\n...\n[ 83.861967] kobject: kobject_add_internal failed for input17 with -EEXIST, don't try to register things with the same name in the same directory.\n[ 83.877338] BUG: kernel NULL pointer dereference, address: 0000000000000018\n...\n\nProtect intel-vbtn notify_handler() from racing with itself with a mutex\nto fix this.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T11:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json b/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json new file mode 100644 index 00000000000..eb312ccd46d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whcw-39v8-h8p9", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-8199" + ], + "details": "The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_api_key' function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update API Key options.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8199" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/reviews-feed/tags/1.1.2/class/Common/Builder/SBR_Feed_Saver_Manager.php#L699" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3125315" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc3e89e5-2e7e-497e-b340-b787ebdf3711?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json b/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json new file mode 100644 index 00000000000..7d75470b841 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wwqr-qf45-7869/GHSA-wwqr-qf45-7869.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwqr-qf45-7869", + "modified": "2024-08-27T18:31:37Z", + "published": "2024-08-27T18:31:37Z", + "aliases": [ + "CVE-2024-44342" + ], + "details": "D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44342" + }, + { + "type": "WEB", + "url": "https://github.com/yali-1002/some-poc/blob/main/CVE-2024-44342" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + }, + { + "type": "WEB", + "url": "http://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DIR-846W" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json b/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json new file mode 100644 index 00000000000..21911869e43 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x72g-3j3q-w4wf", + "modified": "2024-08-27T18:31:38Z", + "published": "2024-08-27T18:31:38Z", + "aliases": [ + "CVE-2024-42851" + ], + "details": "Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42851" + }, + { + "type": "WEB", + "url": "https://github.com/T1anyang/fuzzing/blob/main/exiftags/crash.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-27T18:15:14Z" + } +} \ No newline at end of file