Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-07-08 18:32:45 +00:00
parent e57319cdcc
commit cdf2365acb
78 changed files with 1456 additions and 125 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78hx-gp6g-7mj6",
"modified": "2024-06-27T06:32:47Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-03-20T18:10:36Z",
"aliases": [
"CVE-2024-1394"
@@ -134,14 +134,6 @@
"type": "WEB",
"url": "https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2729"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2730"
@@ -162,6 +154,18 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4146"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4371"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4378"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4379"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-1394"
@@ -190,6 +194,10 @@
"type": "WEB",
"url": "https://vuln.go.dev/ID/GO-2024-2660.json"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1462"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1468"
@@ -257,6 +265,10 @@
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2569"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2729"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jvj3-gqjm-cg8p",
"modified": "2024-06-27T12:30:42Z",
"modified": "2024-07-08T18:31:14Z",
"published": "2023-11-28T12:31:25Z",
"aliases": [
"CVE-2023-5981"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1383"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-5981"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m6w-vxqg-9rmm",
"modified": "2024-06-25T21:31:10Z",
"modified": "2024-07-08T18:31:14Z",
"published": "2023-12-08T18:30:42Z",
"aliases": [
"CVE-2023-6606"
@@ -49,6 +49,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1404"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6606"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr4h-682w-x2ph",
"modified": "2024-03-12T06:30:45Z",
"modified": "2024-07-08T18:31:14Z",
"published": "2023-12-08T18:30:42Z",
"aliases": [
"CVE-2023-6610"
@@ -45,6 +45,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1248"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1404"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6610"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v727-f437-6cxx",
"modified": "2024-05-08T09:30:50Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2023-12-21T21:30:31Z",
"aliases": [
"CVE-2023-6546"
@@ -49,6 +49,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2394"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2093"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1614"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jrv-6m77-vrhq",
"modified": "2024-06-26T00:31:34Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-01-15T21:30:24Z",
"aliases": [
"CVE-2024-0565"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1614"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2093"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2394"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52x7-wcqq-wfjp",
"modified": "2024-03-12T06:30:45Z",
"modified": "2024-07-08T18:31:14Z",
"published": "2024-01-02T18:30:20Z",
"aliases": [
"CVE-2024-0193"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1248"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0193"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcx8-9rrj-7qxm",
"modified": "2024-06-27T12:30:43Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-01-16T15:30:27Z",
"aliases": [
"CVE-2024-0567"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1383"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0567"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qmff-49xc-7rf6",
"modified": "2024-06-25T21:31:10Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-01-17T18:31:36Z",
"aliases": [
"CVE-2024-0646"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0646"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1404"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x697-v25m-6phv",
"modified": "2024-06-27T12:30:42Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2024-0553"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1383"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0553"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-98fx-x879-qp6f",
"modified": "2024-06-25T21:31:10Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-02-07T21:30:27Z",
"aliases": [
"CVE-2023-6356"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1248"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3810"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v8xr-j3gp-fmxj",
"modified": "2024-06-25T21:31:10Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-02-07T21:30:27Z",
"aliases": [
"CVE-2023-6535"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1248"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3810"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xw3g-x45j-xxhh",
"modified": "2024-06-25T21:31:10Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-02-07T21:30:27Z",
"aliases": [
"CVE-2023-6536"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1248"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2094"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:3810"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv98-48f2-5vjr",
"modified": "2024-07-06T00:31:06Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2024-26621"
@@ -33,6 +33,10 @@
{
"type": "WEB",
"url": "https://zolutal.github.io/aslrnt"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/08/3"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvm7-rc5g-c98q",
"modified": "2024-07-03T00:34:10Z",
"modified": "2024-07-08T18:31:15Z",
"published": "2024-06-11T21:32:17Z",
"aliases": [
"CVE-2023-4727"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4222"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4367"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-4727"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29w9-rxvw-c7w4",
"modified": "2024-07-05T09:33:44Z",
"modified": "2024-07-08T18:31:16Z",
"published": "2024-07-05T09:33:44Z",
"aliases": [
"CVE-2024-39481"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mc: Fix graph walk in media_pipeline_start\n\nThe graph walk tries to follow all links, even if they are not between\npads. This causes a crash with, e.g. a MEDIA_LNK_FL_ANCILLARY_LINK link.\n\nFix this by allowing the walk to proceed only for MEDIA_LNK_FL_DATA_LINK\nlinks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -39,7 +42,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-05T07:15:10Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c6c-5vmc-49j8",
"modified": "2024-07-08T18:31:17Z",
"published": "2024-07-08T18:31:17Z",
"aliases": [
"CVE-2023-49595"
],
"details": "A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49595"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1878"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-08T16:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qjj-5hcf-4j4c",
"modified": "2024-07-08T18:31:18Z",
"published": "2024-07-08T18:31:18Z",
"aliases": [
"CVE-2023-50240"
],
"details": "Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `AdvDefaultPreference` request's parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50240"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1893"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-08T16:15:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rg9-mqj3-xwq5",
"modified": "2024-07-08T18:31:18Z",
"published": "2024-07-08T18:31:18Z",
"aliases": [
"CVE-2023-50381"
],
"details": "Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50381"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1899"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-08T16:15:06Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v2c-wv9c-g6cm",
"modified": "2024-07-05T18:34:17Z",
"modified": "2024-07-08T18:31:16Z",
"published": "2024-07-05T18:34:17Z",
"aliases": [
"CVE-2024-37769"
],
"details": "Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-05T16:15:05Z"

Some files were not shown because too many files have changed in this diff Show More