mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-8w48-m6hx-rjw2 GHSA-cf9m-q836-vf26 GHSA-f836-7jqw-3684 GHSA-hr8g-f6r6-mr22 GHSA-pwgm-jvqv-6v8p GHSA-qqr6-vm23-m488 GHSA-vwxc-3cfr-37jq GHSA-qmhj-m29v-gvmr
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8w48-m6hx-rjw2",
|
||||
"modified": "2024-01-15T18:14:23Z",
|
||||
"modified": "2024-11-22T20:15:48Z",
|
||||
"published": "2022-05-17T05:37:39Z",
|
||||
"aliases": [
|
||||
"CVE-2011-3587"
|
||||
@@ -68,6 +68,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=742297"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-26.yaml"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/zopefoundation/Zope"
|
||||
@@ -80,6 +84,10 @@
|
||||
"type": "WEB",
|
||||
"url": "http://plone.org/products/plone-hotfix/releases/20110928"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://plone.org/products/plone/security/advisories/20110928"
|
||||
@@ -87,6 +95,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cf9m-q836-vf26",
|
||||
"modified": "2023-08-16T23:22:49Z",
|
||||
"modified": "2024-11-22T20:14:42Z",
|
||||
"published": "2022-05-17T04:50:15Z",
|
||||
"aliases": [
|
||||
"CVE-2014-0006"
|
||||
@@ -90,6 +90,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/openstack/swift"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/swift/PYSEC-2014-116.yaml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://rhn.redhat.com/errata/RHSA-2014-0232.html"
|
||||
|
||||
+14
-41
@@ -1,17 +1,26 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f836-7jqw-3684",
|
||||
"modified": "2022-05-01T06:59:15Z",
|
||||
"modified": "2024-11-22T20:15:58Z",
|
||||
"published": "2022-05-01T06:59:15Z",
|
||||
"aliases": [
|
||||
"CVE-2006-2458"
|
||||
],
|
||||
"summary": "Libextractor multiple heap-based buffer overflows",
|
||||
"details": "Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "PyPI",
|
||||
"name": "extractor"
|
||||
},
|
||||
"versions": [
|
||||
"0.5"
|
||||
]
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
@@ -28,32 +37,12 @@
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://gnunet.org/libextractor"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://secunia.com/advisories/20150"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://secunia.com/advisories/20160"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://secunia.com/advisories/20326"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://secunia.com/advisories/20457"
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/extractor/PYSEC-2006-4.yaml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://securityreason.com/securityalert/916"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://securitytracker.com/id?1016118"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.debian.org/security/2006/dsa-1081"
|
||||
@@ -61,22 +50,6 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.gentoo.org/security/en/glsa/glsa-200605-14.xml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.novell.com/linux/security/advisories/2006-06-02.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.securityfocus.com/archive/1/434288/100/0/threaded"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.securityfocus.com/bid/18021"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.vupen.com/english/advisories/2006/1848"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
@@ -84,8 +57,8 @@
|
||||
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-11-22T20:15:58Z",
|
||||
"nvd_published_at": "2006-05-18T23:02:00Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hr8g-f6r6-mr22",
|
||||
"modified": "2024-04-02T20:39:05Z",
|
||||
"modified": "2024-11-22T20:16:10Z",
|
||||
"published": "2022-05-26T00:01:27Z",
|
||||
"aliases": [
|
||||
"CVE-2022-30595"
|
||||
@@ -44,6 +44,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/python-pillow/Pillow/commit/c846cc881ebe34e3518412c2e3636433d9947280"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-43145.yaml"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/python-pillow/Pillow"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pwgm-jvqv-6v8p",
|
||||
"modified": "2024-05-14T17:25:59Z",
|
||||
"modified": "2024-11-22T20:15:03Z",
|
||||
"published": "2022-05-17T05:37:14Z",
|
||||
"aliases": [
|
||||
"CVE-2011-4030"
|
||||
@@ -85,6 +85,10 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/plone/Plone"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://plone.org/products/plone-hotfix/releases/20110928"
|
||||
@@ -96,14 +100,6 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://secunia.com/advisories/46323"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.securityfocus.com/bid/50287"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
+50
-4
@@ -1,11 +1,12 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qqr6-vm23-m488",
|
||||
"modified": "2022-05-14T03:02:50Z",
|
||||
"modified": "2024-11-22T20:15:21Z",
|
||||
"published": "2022-05-14T03:02:50Z",
|
||||
"aliases": [
|
||||
"CVE-2018-1000516"
|
||||
],
|
||||
"summary": "Galaxy cross-site scripting (XSS)",
|
||||
"details": "The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site scripting (XSS) attacks. In this form of attack, a malicious person can create a URL which, when opened by a Galaxy user or administrator, would allow the malicious user to execute arbitrary Javascript. that can result in Arbitrary JavaScript code execution. This attack appear to be exploitable via The victim must interact with component on page witch contains injected JavaScript code.. This vulnerability appears to have been fixed in v14.10.1, v15.01.",
|
||||
"severity": [
|
||||
{
|
||||
@@ -14,7 +15,44 @@
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "PyPI",
|
||||
"name": "galaxy-app"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "0"
|
||||
},
|
||||
{
|
||||
"fixed": "14.10.1"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "PyPI",
|
||||
"name": "galaxy-app"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "15.0"
|
||||
},
|
||||
{
|
||||
"fixed": "15.01"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
@@ -24,6 +62,14 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://galaxyproject.org/archive/dev-news-briefs/2015-01-13/#security"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/galaxyproject/galaxy"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/galaxy-app/PYSEC-2018-149.yaml"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
@@ -31,8 +77,8 @@
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-11-22T20:15:21Z",
|
||||
"nvd_published_at": "2018-06-26T16:29:00Z"
|
||||
}
|
||||
}
|
||||
+31
-8
@@ -1,23 +1,50 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vwxc-3cfr-37jq",
|
||||
"modified": "2022-05-04T00:27:48Z",
|
||||
"modified": "2024-11-22T20:16:20Z",
|
||||
"published": "2022-05-04T00:27:48Z",
|
||||
"aliases": [
|
||||
"CVE-2012-0054"
|
||||
],
|
||||
"summary": "GoLismero symlink attack",
|
||||
"details": "libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"affected": [
|
||||
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "PyPI",
|
||||
"name": "golismero"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "0"
|
||||
},
|
||||
{
|
||||
"last_affected": "0.6.3"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-0054"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/golismero/golismero"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/golismero/PYSEC-2012-31.yaml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://code.google.com/p/golismero/source/detail?r=2b3bb43d68676efd687361f7de29380189031ab8"
|
||||
@@ -29,10 +56,6 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2012/01/17/7"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.osvdb.org/78472"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
@@ -40,8 +63,8 @@
|
||||
"CWE-59"
|
||||
],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-11-22T20:16:20Z",
|
||||
"nvd_published_at": "2012-03-19T19:55:00Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qmhj-m29v-gvmr",
|
||||
"modified": "2022-08-18T14:18:37Z",
|
||||
"modified": "2024-11-22T20:16:31Z",
|
||||
"published": "2022-08-18T14:18:37Z",
|
||||
"aliases": [
|
||||
"CVE-2022-36024"
|
||||
@@ -54,6 +54,10 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/Pycord-Development/pycord"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/py-cord/PYSEC-2022-43146.yaml"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
Reference in New Issue
Block a user