From cdc0c060adf5a595f74e52efcb9a85b72cf80417 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 23 Sep 2024 15:32:25 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-m8wx-w8wv-8q47.json | 6 ++- .../GHSA-c2xj-xc27-698r.json | 2 +- .../GHSA-j6xj-ghv6-rv32.json | 2 +- .../GHSA-g5c9-vc82-389p.json | 2 +- .../GHSA-7g45-4xm2-qxvf.json | 3 +- .../GHSA-2pf5-j72f-jhxp.json | 2 +- .../GHSA-556v-xwc9-3f54.json | 2 +- .../GHSA-cr76-625x-q34w.json | 2 +- .../GHSA-fwg6-3hj3-4g7v.json | 2 +- .../GHSA-gc7h-2w78-ph5w.json | 2 +- .../GHSA-h69r-jw3j-854f.json | 2 +- .../GHSA-q6rm-92w9-33cw.json | 2 +- .../GHSA-vc4m-x7gg-xqpc.json | 6 ++- .../GHSA-2mh2-9xm5-m59q.json | 11 +++-- .../GHSA-2x56-wxfv-qqrm.json | 11 +++-- .../GHSA-458x-pm5m-qh42.json | 11 +++-- .../GHSA-5h5g-fhm4-c644.json | 42 +++++++++++++++++++ .../GHSA-6cx3-28wh-wjwv.json | 42 +++++++++++++++++++ .../GHSA-6mh5-7p3w-gfg6.json | 9 ++-- .../GHSA-6q3p-cf37-rf5w.json | 11 +++-- .../GHSA-9398-9vm3-q46v.json | 42 +++++++++++++++++++ .../GHSA-9f35-qf4j-2v26.json | 11 +++-- .../GHSA-c2m5-hm36-mq75.json | 9 ++-- .../GHSA-crwg-8vm3-26rf.json | 11 +++-- .../GHSA-f8cf-9769-43r2.json | 11 +++-- .../GHSA-fq8w-cfr6-8fqg.json | 2 +- .../GHSA-mxj5-w2rm-4rhf.json | 35 ++++++++++++++++ .../GHSA-rcch-4525-rq2f.json | 42 +++++++++++++++++++ .../GHSA-vvqc-xqxj-mg66.json | 11 +++-- 29 files changed, 294 insertions(+), 52 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-5h5g-fhm4-c644/GHSA-5h5g-fhm4-c644.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rcch-4525-rq2f/GHSA-rcch-4525-rq2f.json diff --git a/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json b/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json index 445c3360f42..9057a0cce48 100644 --- a/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json +++ b/advisories/unreviewed/2022/09/GHSA-m8wx-w8wv-8q47/GHSA-m8wx-w8wv-8q47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8wx-w8wv-8q47", - "modified": "2022-09-18T00:00:31Z", + "modified": "2024-09-23T15:30:58Z", "published": "2022-09-15T00:00:16Z", "aliases": [ "CVE-2022-2277" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2277" }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true" + }, { "type": "WEB", "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch" diff --git a/advisories/unreviewed/2023/10/GHSA-c2xj-xc27-698r/GHSA-c2xj-xc27-698r.json b/advisories/unreviewed/2023/10/GHSA-c2xj-xc27-698r/GHSA-c2xj-xc27-698r.json index 61a23cb8fbf..0e2ea1cf74c 100644 --- a/advisories/unreviewed/2023/10/GHSA-c2xj-xc27-698r/GHSA-c2xj-xc27-698r.json +++ b/advisories/unreviewed/2023/10/GHSA-c2xj-xc27-698r/GHSA-c2xj-xc27-698r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-j6xj-ghv6-rv32/GHSA-j6xj-ghv6-rv32.json b/advisories/unreviewed/2023/10/GHSA-j6xj-ghv6-rv32/GHSA-j6xj-ghv6-rv32.json index 80a5a95e212..eb45d69f031 100644 --- a/advisories/unreviewed/2023/10/GHSA-j6xj-ghv6-rv32/GHSA-j6xj-ghv6-rv32.json +++ b/advisories/unreviewed/2023/10/GHSA-j6xj-ghv6-rv32/GHSA-j6xj-ghv6-rv32.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json b/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json index 952888dbad8..55770f3da4f 100644 --- a/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json +++ b/advisories/unreviewed/2023/12/GHSA-g5c9-vc82-389p/GHSA-g5c9-vc82-389p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5c9-vc82-389p", - "modified": "2023-12-06T21:30:58Z", + "modified": "2024-09-23T15:30:59Z", "published": "2023-12-01T15:31:22Z", "aliases": [ "CVE-2023-4518" diff --git a/advisories/unreviewed/2024/06/GHSA-7g45-4xm2-qxvf/GHSA-7g45-4xm2-qxvf.json b/advisories/unreviewed/2024/06/GHSA-7g45-4xm2-qxvf/GHSA-7g45-4xm2-qxvf.json index c9ba372dbd7..1137ebb3e64 100644 --- a/advisories/unreviewed/2024/06/GHSA-7g45-4xm2-qxvf/GHSA-7g45-4xm2-qxvf.json +++ b/advisories/unreviewed/2024/06/GHSA-7g45-4xm2-qxvf/GHSA-7g45-4xm2-qxvf.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2pf5-j72f-jhxp/GHSA-2pf5-j72f-jhxp.json b/advisories/unreviewed/2024/07/GHSA-2pf5-j72f-jhxp/GHSA-2pf5-j72f-jhxp.json index 2928bfecb2b..f16f7f3b60b 100644 --- a/advisories/unreviewed/2024/07/GHSA-2pf5-j72f-jhxp/GHSA-2pf5-j72f-jhxp.json +++ b/advisories/unreviewed/2024/07/GHSA-2pf5-j72f-jhxp/GHSA-2pf5-j72f-jhxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pf5-j72f-jhxp", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-09-23T15:30:59Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39528" diff --git a/advisories/unreviewed/2024/07/GHSA-556v-xwc9-3f54/GHSA-556v-xwc9-3f54.json b/advisories/unreviewed/2024/07/GHSA-556v-xwc9-3f54/GHSA-556v-xwc9-3f54.json index b4b492049da..368c90f5ca6 100644 --- a/advisories/unreviewed/2024/07/GHSA-556v-xwc9-3f54/GHSA-556v-xwc9-3f54.json +++ b/advisories/unreviewed/2024/07/GHSA-556v-xwc9-3f54/GHSA-556v-xwc9-3f54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-556v-xwc9-3f54", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-09-23T15:30:59Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39521" diff --git a/advisories/unreviewed/2024/07/GHSA-cr76-625x-q34w/GHSA-cr76-625x-q34w.json b/advisories/unreviewed/2024/07/GHSA-cr76-625x-q34w/GHSA-cr76-625x-q34w.json index c11a9ef1b1f..7afd97dfd90 100644 --- a/advisories/unreviewed/2024/07/GHSA-cr76-625x-q34w/GHSA-cr76-625x-q34w.json +++ b/advisories/unreviewed/2024/07/GHSA-cr76-625x-q34w/GHSA-cr76-625x-q34w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr76-625x-q34w", - "modified": "2024-07-11T18:31:12Z", + "modified": "2024-09-23T15:30:59Z", "published": "2024-07-11T18:31:12Z", "aliases": [ "CVE-2024-39519" diff --git a/advisories/unreviewed/2024/07/GHSA-fwg6-3hj3-4g7v/GHSA-fwg6-3hj3-4g7v.json b/advisories/unreviewed/2024/07/GHSA-fwg6-3hj3-4g7v/GHSA-fwg6-3hj3-4g7v.json index 0dd359dc626..6c2e249bbc3 100644 --- a/advisories/unreviewed/2024/07/GHSA-fwg6-3hj3-4g7v/GHSA-fwg6-3hj3-4g7v.json +++ b/advisories/unreviewed/2024/07/GHSA-fwg6-3hj3-4g7v/GHSA-fwg6-3hj3-4g7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwg6-3hj3-4g7v", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-09-23T15:30:59Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39524" diff --git a/advisories/unreviewed/2024/07/GHSA-gc7h-2w78-ph5w/GHSA-gc7h-2w78-ph5w.json b/advisories/unreviewed/2024/07/GHSA-gc7h-2w78-ph5w/GHSA-gc7h-2w78-ph5w.json index 2dcc7a7ae7c..3b9068770eb 100644 --- a/advisories/unreviewed/2024/07/GHSA-gc7h-2w78-ph5w/GHSA-gc7h-2w78-ph5w.json +++ b/advisories/unreviewed/2024/07/GHSA-gc7h-2w78-ph5w/GHSA-gc7h-2w78-ph5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc7h-2w78-ph5w", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-09-23T15:30:59Z", "published": "2024-07-11T18:31:12Z", "aliases": [ "CVE-2024-39520" diff --git a/advisories/unreviewed/2024/07/GHSA-h69r-jw3j-854f/GHSA-h69r-jw3j-854f.json b/advisories/unreviewed/2024/07/GHSA-h69r-jw3j-854f/GHSA-h69r-jw3j-854f.json index b6154e28abf..136f0a9d09b 100644 --- a/advisories/unreviewed/2024/07/GHSA-h69r-jw3j-854f/GHSA-h69r-jw3j-854f.json +++ b/advisories/unreviewed/2024/07/GHSA-h69r-jw3j-854f/GHSA-h69r-jw3j-854f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h69r-jw3j-854f", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39529" diff --git a/advisories/unreviewed/2024/07/GHSA-q6rm-92w9-33cw/GHSA-q6rm-92w9-33cw.json b/advisories/unreviewed/2024/07/GHSA-q6rm-92w9-33cw/GHSA-q6rm-92w9-33cw.json index a67b999a4db..f71df50d5d7 100644 --- a/advisories/unreviewed/2024/07/GHSA-q6rm-92w9-33cw/GHSA-q6rm-92w9-33cw.json +++ b/advisories/unreviewed/2024/07/GHSA-q6rm-92w9-33cw/GHSA-q6rm-92w9-33cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q6rm-92w9-33cw", - "modified": "2024-07-11T18:31:13Z", + "modified": "2024-09-23T15:30:59Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39523" diff --git a/advisories/unreviewed/2024/07/GHSA-vc4m-x7gg-xqpc/GHSA-vc4m-x7gg-xqpc.json b/advisories/unreviewed/2024/07/GHSA-vc4m-x7gg-xqpc/GHSA-vc4m-x7gg-xqpc.json index bc5670aca3e..98fc54b732c 100644 --- a/advisories/unreviewed/2024/07/GHSA-vc4m-x7gg-xqpc/GHSA-vc4m-x7gg-xqpc.json +++ b/advisories/unreviewed/2024/07/GHSA-vc4m-x7gg-xqpc/GHSA-vc4m-x7gg-xqpc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vc4m-x7gg-xqpc", - "modified": "2024-08-01T15:31:55Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-07-12T15:31:26Z", "aliases": [ "CVE-2024-39340" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39340" }, + { + "type": "WEB", + "url": "https://wiki.securepoint.de/Advisory/CVE-2024-39340" + }, { "type": "WEB", "url": "https://wiki.securepoint.de/UTM/Changelog" diff --git a/advisories/unreviewed/2024/09/GHSA-2mh2-9xm5-m59q/GHSA-2mh2-9xm5-m59q.json b/advisories/unreviewed/2024/09/GHSA-2mh2-9xm5-m59q/GHSA-2mh2-9xm5-m59q.json index fec7d3ca76b..94e15a843d3 100644 --- a/advisories/unreviewed/2024/09/GHSA-2mh2-9xm5-m59q/GHSA-2mh2-9xm5-m59q.json +++ b/advisories/unreviewed/2024/09/GHSA-2mh2-9xm5-m59q/GHSA-2mh2-9xm5-m59q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mh2-9xm5-m59q", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46678" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: change ipsec_lock from spin lock to mutex\n\nIn the cited commit, bond->ipsec_lock is added to protect ipsec_list,\nhence xdo_dev_state_add and xdo_dev_state_delete are called inside\nthis lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep,\n\"scheduling while atomic\" will be triggered when changing bond's\nactive slave.\n\n[ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200\n[ 101.055726] Modules linked in:\n[ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1\n[ 101.058760] Hardware name:\n[ 101.059434] Call Trace:\n[ 101.059436] \n[ 101.060873] dump_stack_lvl+0x51/0x60\n[ 101.061275] __schedule_bug+0x4e/0x60\n[ 101.061682] __schedule+0x612/0x7c0\n[ 101.062078] ? __mod_timer+0x25c/0x370\n[ 101.062486] schedule+0x25/0xd0\n[ 101.062845] schedule_timeout+0x77/0xf0\n[ 101.063265] ? asm_common_interrupt+0x22/0x40\n[ 101.063724] ? __bpf_trace_itimer_state+0x10/0x10\n[ 101.064215] __wait_for_common+0x87/0x190\n[ 101.064648] ? usleep_range_state+0x90/0x90\n[ 101.065091] cmd_exec+0x437/0xb20 [mlx5_core]\n[ 101.065569] mlx5_cmd_do+0x1e/0x40 [mlx5_core]\n[ 101.066051] mlx5_cmd_exec+0x18/0x30 [mlx5_core]\n[ 101.066552] mlx5_crypto_create_dek_key+0xea/0x120 [mlx5_core]\n[ 101.067163] ? bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[ 101.067738] ? kmalloc_trace+0x4d/0x350\n[ 101.068156] mlx5_ipsec_create_sa_ctx+0x33/0x100 [mlx5_core]\n[ 101.068747] mlx5e_xfrm_add_state+0x47b/0xaa0 [mlx5_core]\n[ 101.069312] bond_change_active_slave+0x392/0x900 [bonding]\n[ 101.069868] bond_option_active_slave_set+0x1c2/0x240 [bonding]\n[ 101.070454] __bond_opt_set+0xa6/0x430 [bonding]\n[ 101.070935] __bond_opt_set_notify+0x2f/0x90 [bonding]\n[ 101.071453] bond_opt_tryset_rtnl+0x72/0xb0 [bonding]\n[ 101.071965] bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[ 101.072567] kernfs_fop_write_iter+0x10c/0x1a0\n[ 101.073033] vfs_write+0x2d8/0x400\n[ 101.073416] ? alloc_fd+0x48/0x180\n[ 101.073798] ksys_write+0x5f/0xe0\n[ 101.074175] do_syscall_64+0x52/0x110\n[ 101.074576] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nAs bond_ipsec_add_sa_all and bond_ipsec_del_sa_all are only called\nfrom bond_change_active_slave, which requires holding the RTNL lock.\nAnd bond_ipsec_add_sa and bond_ipsec_del_sa are xfrm state\nxdo_dev_state_add and xdo_dev_state_delete APIs, which are in user\ncontext. So ipsec_lock doesn't have to be spin lock, change it to\nmutex, and thus the above issue can be resolved.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json b/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json index 507ff3ad33b..fbfb6b77896 100644 --- a/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json +++ b/advisories/unreviewed/2024/09/GHSA-2x56-wxfv-qqrm/GHSA-2x56-wxfv-qqrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2x56-wxfv-qqrm", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46645" ], "details": "eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json b/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json index 417fcd64ad7..e9f711ae972 100644 --- a/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json +++ b/advisories/unreviewed/2024/09/GHSA-458x-pm5m-qh42/GHSA-458x-pm5m-qh42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-458x-pm5m-qh42", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46644" ], "details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5h5g-fhm4-c644/GHSA-5h5g-fhm4-c644.json b/advisories/unreviewed/2024/09/GHSA-5h5g-fhm4-c644/GHSA-5h5g-fhm4-c644.json new file mode 100644 index 00000000000..0fcf82d456c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5h5g-fhm4-c644/GHSA-5h5g-fhm4-c644.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h5g-fhm4-c644", + "modified": "2024-09-23T15:31:00Z", + "published": "2024-09-23T15:31:00Z", + "aliases": [ + "CVE-2024-23972" + ], + "details": "Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the USB host driver. A crafted USB configuration descriptor can trigger an overflow of a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the device.\n\nWas ZDI-CAN-23185", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23972" + }, + { + "type": "WEB", + "url": "https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax5500/software/00274156" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-876" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json b/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json new file mode 100644 index 00000000000..266b4290674 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6cx3-28wh-wjwv/GHSA-6cx3-28wh-wjwv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cx3-28wh-wjwv", + "modified": "2024-09-23T15:31:00Z", + "published": "2024-09-23T15:31:00Z", + "aliases": [ + "CVE-2024-23933" + ], + "details": "Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of \tSony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the Apple CarPlay protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.\n\nWas ZDI-CAN-23238", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23933" + }, + { + "type": "WEB", + "url": "https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax5500/software/00274156" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-877" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6mh5-7p3w-gfg6/GHSA-6mh5-7p3w-gfg6.json b/advisories/unreviewed/2024/09/GHSA-6mh5-7p3w-gfg6/GHSA-6mh5-7p3w-gfg6.json index 3ff00839331..6b37b929faa 100644 --- a/advisories/unreviewed/2024/09/GHSA-6mh5-7p3w-gfg6/GHSA-6mh5-7p3w-gfg6.json +++ b/advisories/unreviewed/2024/09/GHSA-6mh5-7p3w-gfg6/GHSA-6mh5-7p3w-gfg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mh5-7p3w-gfg6", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46680" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix random crash seen while removing driver\n\nThis fixes the random kernel crash seen while removing the driver, when\nrunning the load/unload test over multiple iterations.\n\n1) modprobe btnxpuart\n2) hciconfig hci0 reset\n3) hciconfig (check hci0 interface up with valid BD address)\n4) modprobe -r btnxpuart\nRepeat steps 1 to 4\n\nThe ps_wakeup() call in btnxpuart_close() schedules the psdata->work(),\nwhich gets scheduled after module is removed, causing a kernel crash.\n\nThis hidden issue got highlighted after enabling Power Save by default\nin 4183a7be7700 (Bluetooth: btnxpuart: Enable Power Save feature on\nstartup)\n\nThe new ps_cleanup() deasserts UART break immediately while closing\nserdev device, cancels any scheduled ps_work and destroys the ps_lock\nmutex.\n\n[ 85.884604] Unable to handle kernel paging request at virtual address ffffd4a61638f258\n[ 85.884624] Mem abort info:\n[ 85.884625] ESR = 0x0000000086000007\n[ 85.884628] EC = 0x21: IABT (current EL), IL = 32 bits\n[ 85.884633] SET = 0, FnV = 0\n[ 85.884636] EA = 0, S1PTW = 0\n[ 85.884638] FSC = 0x07: level 3 translation fault\n[ 85.884642] swapper pgtable: 4k pages, 48-bit VAs, pgdp=0000000041dd0000\n[ 85.884646] [ffffd4a61638f258] pgd=1000000095fff003, p4d=1000000095fff003, pud=100000004823d003, pmd=100000004823e003, pte=0000000000000000\n[ 85.884662] Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n[ 85.890932] Modules linked in: algif_hash algif_skcipher af_alg overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_spdif snd_soc_fsl_micfil snd_soc_fsl_sai snd_soc_fsl_utils gpio_ir_recv rc_core fuse [last unloaded: btnxpuart(O)]\n[ 85.927297] CPU: 1 PID: 67 Comm: kworker/1:3 Tainted: G O 6.1.36+g937b1be4345a #1\n[ 85.936176] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 85.936182] Workqueue: events 0xffffd4a61638f380\n[ 85.936198] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 85.952817] pc : 0xffffd4a61638f258\n[ 85.952823] lr : 0xffffd4a61638f258\n[ 85.952827] sp : ffff8000084fbd70\n[ 85.952829] x29: ffff8000084fbd70 x28: 0000000000000000 x27: 0000000000000000\n[ 85.963112] x26: ffffd4a69133f000 x25: ffff4bf1c8540990 x24: ffff4bf215b87305\n[ 85.963119] x23: ffff4bf215b87300 x22: ffff4bf1c85409d0 x21: ffff4bf1c8540970\n[ 85.977382] x20: 0000000000000000 x19: ffff4bf1c8540880 x18: 0000000000000000\n[ 85.977391] x17: 0000000000000000 x16: 0000000000000133 x15: 0000ffffe2217090\n[ 85.977399] x14: 0000000000000001 x13: 0000000000000133 x12: 0000000000000139\n[ 85.977407] x11: 0000000000000001 x10: 0000000000000a60 x9 : ffff8000084fbc50\n[ 85.977417] x8 : ffff4bf215b7d000 x7 : ffff4bf215b83b40 x6 : 00000000000003e8\n[ 85.977424] x5 : 00000000410fd030 x4 : 0000000000000000 x3 : 0000000000000000\n[ 85.977432] x2 : 0000000000000000 x1 : ffff4bf1c4265880 x0 : 0000000000000000\n[ 85.977443] Call trace:\n[ 85.977446] 0xffffd4a61638f258\n[ 85.977451] 0xffffd4a61638f3e8\n[ 85.977455] process_one_work+0x1d4/0x330\n[ 85.977464] worker_thread+0x6c/0x430\n[ 85.977471] kthread+0x108/0x10c\n[ 85.977476] ret_from_fork+0x10/0x20\n[ 85.977488] Code: bad PC value\n[ 85.977491] ---[ end trace 0000000000000000 ]---\n\nPreset since v6.9.11", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json b/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json index 57ba0e13035..a09ca935b5f 100644 --- a/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json +++ b/advisories/unreviewed/2024/09/GHSA-6q3p-cf37-rf5w/GHSA-6q3p-cf37-rf5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q3p-cf37-rf5w", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46648" ], "details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json b/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json new file mode 100644 index 00000000000..aec333a6031 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9398-9vm3-q46v/GHSA-9398-9vm3-q46v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9398-9vm3-q46v", + "modified": "2024-09-23T15:31:00Z", + "published": "2024-09-23T15:31:00Z", + "aliases": [ + "CVE-2024-23934" + ], + "details": "Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of WMV/ASF files. A crafted Extended Content Description Object in a WMV media file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.\n\n. Was ZDI-CAN-22994.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23934" + }, + { + "type": "WEB", + "url": "https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax5500/software/00274156" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-875" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json b/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json index 471e8af3d10..1d13d57cbf5 100644 --- a/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json +++ b/advisories/unreviewed/2024/09/GHSA-9f35-qf4j-2v26/GHSA-9f35-qf4j-2v26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f35-qf4j-2v26", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46647" ], "details": "eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c2m5-hm36-mq75/GHSA-c2m5-hm36-mq75.json b/advisories/unreviewed/2024/09/GHSA-c2m5-hm36-mq75/GHSA-c2m5-hm36-mq75.json index c675b67c773..8ac925142fb 100644 --- a/advisories/unreviewed/2024/09/GHSA-c2m5-hm36-mq75/GHSA-c2m5-hm36-mq75.json +++ b/advisories/unreviewed/2024/09/GHSA-c2m5-hm36-mq75/GHSA-c2m5-hm36-mq75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2m5-hm36-mq75", - "modified": "2024-09-13T06:30:43Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46679" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: check device is present when getting link settings\n\nA sysfs reader can race with a device reset or removal, attempting to\nread device state when the device is not actually present. eg:\n\n [exception RIP: qed_get_current_link+17]\n #8 [ffffb9e4f2907c48] qede_get_link_ksettings at ffffffffc07a994a [qede]\n #9 [ffffb9e4f2907cd8] __rh_call_get_link_ksettings at ffffffff992b01a3\n #10 [ffffb9e4f2907d38] __ethtool_get_link_ksettings at ffffffff992b04e4\n #11 [ffffb9e4f2907d90] duplex_show at ffffffff99260300\n #12 [ffffb9e4f2907e38] dev_attr_show at ffffffff9905a01c\n #13 [ffffb9e4f2907e50] sysfs_kf_seq_show at ffffffff98e0145b\n #14 [ffffb9e4f2907e68] seq_read at ffffffff98d902e3\n #15 [ffffb9e4f2907ec8] vfs_read at ffffffff98d657d1\n #16 [ffffb9e4f2907f00] ksys_read at ffffffff98d65c3f\n #17 [ffffb9e4f2907f38] do_syscall_64 at ffffffff98a052fb\n\n crash> struct net_device.state ffff9a9d21336000\n state = 5,\n\nstate 5 is __LINK_STATE_START (0b1) and __LINK_STATE_NOCARRIER (0b100).\nThe device is not present, note lack of __LINK_STATE_PRESENT (0b10).\n\nThis is the same sort of panic as observed in commit 4224cfd7fb65\n(\"net-sysfs: add check for netdevice being present to speed_show\").\n\nThere are many other callers of __ethtool_get_link_ksettings() which\ndon't have a device presence check.\n\nMove this check into ethtool to protect all callers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-crwg-8vm3-26rf/GHSA-crwg-8vm3-26rf.json b/advisories/unreviewed/2024/09/GHSA-crwg-8vm3-26rf/GHSA-crwg-8vm3-26rf.json index 20fb687ecd0..6d8a2c491ff 100644 --- a/advisories/unreviewed/2024/09/GHSA-crwg-8vm3-26rf/GHSA-crwg-8vm3-26rf.json +++ b/advisories/unreviewed/2024/09/GHSA-crwg-8vm3-26rf/GHSA-crwg-8vm3-26rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crwg-8vm3-26rf", - "modified": "2024-09-13T06:30:42Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-13T06:30:42Z", "aliases": [ "CVE-2024-46676" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: Add poll mod list filling check\n\nIn case of im_protocols value is 1 and tm_protocols value is 0 this\ncombination successfully passes the check\n'if (!im_protocols && !tm_protocols)' in the nfc_start_poll().\nBut then after pn533_poll_create_mod_list() call in pn533_start_poll()\npoll mod list will remain empty and dev->poll_mod_count will remain 0\nwhich lead to division by zero.\n\nNormally no im protocol has value 1 in the mask, so this combination is\nnot expected by driver. But these protocol values actually come from\nuserspace via Netlink interface (NFC_CMD_START_POLL operation). So a\nbroken or malicious program may pass a message containing a \"bad\"\ncombination of protocol parameter values so that dev->poll_mod_count\nis not incremented inside pn533_poll_create_mod_list(), thus leading\nto division by zero.\nCall trace looks like:\nnfc_genl_start_poll()\n nfc_start_poll()\n ->start_poll()\n pn533_start_poll()\n\nAdd poll mod list filling check.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-13T06:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json b/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json index 71aa3724b9a..444ecb72182 100644 --- a/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json +++ b/advisories/unreviewed/2024/09/GHSA-f8cf-9769-43r2/GHSA-f8cf-9769-43r2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8cf-9769-43r2", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46646" ], "details": "eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fq8w-cfr6-8fqg/GHSA-fq8w-cfr6-8fqg.json b/advisories/unreviewed/2024/09/GHSA-fq8w-cfr6-8fqg/GHSA-fq8w-cfr6-8fqg.json index c240c2d138c..2ad66a60d20 100644 --- a/advisories/unreviewed/2024/09/GHSA-fq8w-cfr6-8fqg/GHSA-fq8w-cfr6-8fqg.json +++ b/advisories/unreviewed/2024/09/GHSA-fq8w-cfr6-8fqg/GHSA-fq8w-cfr6-8fqg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fq8w-cfr6-8fqg", - "modified": "2024-09-16T14:37:28Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-16T14:37:28Z", "aliases": [ "CVE-2024-45833" diff --git a/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json b/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json new file mode 100644 index 00000000000..f6d644a5b19 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mxj5-w2rm-4rhf/GHSA-mxj5-w2rm-4rhf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxj5-w2rm-4rhf", + "modified": "2024-09-23T15:31:00Z", + "published": "2024-09-23T15:31:00Z", + "aliases": [ + "CVE-2024-46241" + ], + "details": "PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46241" + }, + { + "type": "WEB", + "url": "https://github.com/npemma2/PHP_DairyFarm_XSS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rcch-4525-rq2f/GHSA-rcch-4525-rq2f.json b/advisories/unreviewed/2024/09/GHSA-rcch-4525-rq2f/GHSA-rcch-4525-rq2f.json new file mode 100644 index 00000000000..2097eb9cf78 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rcch-4525-rq2f/GHSA-rcch-4525-rq2f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcch-4525-rq2f", + "modified": "2024-09-23T15:31:00Z", + "published": "2024-09-23T15:31:00Z", + "aliases": [ + "CVE-2024-23922" + ], + "details": "Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of software update packages. An attacker can leverage this vulnerability to execute code in the context of the device.\n\nWas ZDI-CAN-22939", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23922" + }, + { + "type": "WEB", + "url": "https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax5500/software/00274156" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-874" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-23T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json b/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json index 9412e310c47..3dba1934a21 100644 --- a/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json +++ b/advisories/unreviewed/2024/09/GHSA-vvqc-xqxj-mg66/GHSA-vvqc-xqxj-mg66.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvqc-xqxj-mg66", - "modified": "2024-09-20T21:31:39Z", + "modified": "2024-09-23T15:31:00Z", "published": "2024-09-20T21:31:39Z", "aliases": [ "CVE-2024-46649" ], "details": "eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-20T21:15:13Z"