Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-23 15:32:25 +00:00
parent c8ff23cdcc
commit cdc0c060ad
29 changed files with 294 additions and 52 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8wx-w8wv-8q47",
"modified": "2022-09-18T00:00:31Z",
"modified": "2024-09-23T15:30:58Z",
"published": "2022-09-15T00:00:16Z",
"aliases": [
"CVE-2022-2277"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2277"
},
{
"type": "WEB",
"url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true"
},
{
"type": "WEB",
"url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5c9-vc82-389p",
"modified": "2023-12-06T21:30:58Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2023-12-01T15:31:22Z",
"aliases": [
"CVE-2023-4518"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-639"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pf5-j72f-jhxp",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2024-07-11T18:31:13Z",
"aliases": [
"CVE-2024-39528"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-556v-xwc9-3f54",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2024-07-11T18:31:13Z",
"aliases": [
"CVE-2024-39521"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cr76-625x-q34w",
"modified": "2024-07-11T18:31:12Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2024-07-11T18:31:12Z",
"aliases": [
"CVE-2024-39519"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fwg6-3hj3-4g7v",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2024-07-11T18:31:13Z",
"aliases": [
"CVE-2024-39524"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc7h-2w78-ph5w",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2024-07-11T18:31:12Z",
"aliases": [
"CVE-2024-39520"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h69r-jw3j-854f",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-07-11T18:31:13Z",
"aliases": [
"CVE-2024-39529"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6rm-92w9-33cw",
"modified": "2024-07-11T18:31:13Z",
"modified": "2024-09-23T15:30:59Z",
"published": "2024-07-11T18:31:13Z",
"aliases": [
"CVE-2024-39523"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vc4m-x7gg-xqpc",
"modified": "2024-08-01T15:31:55Z",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-07-12T15:31:26Z",
"aliases": [
"CVE-2024-39340"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39340"
},
{
"type": "WEB",
"url": "https://wiki.securepoint.de/Advisory/CVE-2024-39340"
},
{
"type": "WEB",
"url": "https://wiki.securepoint.de/UTM/Changelog"
File diff suppressed because one or more lines are too long
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x56-wxfv-qqrm",
"modified": "2024-09-20T21:31:39Z",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-09-20T21:31:39Z",
"aliases": [
"CVE-2024-46645"
],
"details": "eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-20T21:15:12Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-458x-pm5m-qh42",
"modified": "2024-09-20T21:31:39Z",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-09-20T21:31:39Z",
"aliases": [
"CVE-2024-46644"
],
"details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-20T21:15:12Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5h5g-fhm4-c644",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-09-23T15:31:00Z",
"aliases": [
"CVE-2024-23972"
],
"details": "Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the USB host driver. A crafted USB configuration descriptor can trigger an overflow of a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the device.\n\nWas ZDI-CAN-23185",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23972"
},
{
"type": "WEB",
"url": "https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax5500/software/00274156"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-876"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-23T15:15:13Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cx3-28wh-wjwv",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-09-23T15:31:00Z",
"aliases": [
"CVE-2024-23933"
],
"details": "Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of \tSony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the Apple CarPlay protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.\n\nWas ZDI-CAN-23238",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23933"
},
{
"type": "WEB",
"url": "https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax5500/software/00274156"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-877"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-23T15:15:13Z"
}
}
File diff suppressed because one or more lines are too long
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q3p-cf37-rf5w",
"modified": "2024-09-20T21:31:39Z",
"modified": "2024-09-23T15:31:00Z",
"published": "2024-09-20T21:31:39Z",
"aliases": [
"CVE-2024-46648"
],
"details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-20T21:15:13Z"

Some files were not shown because too many files have changed in this diff Show More