From ce61bcd0051f3dbd67cf5f129f9ff9af6b43463f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 19 Nov 2024 21:32:44 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-24mx-5rm6-qcm5.json | 2 +- .../GHSA-w7wp-hxj3-m732.json | 2 +- .../GHSA-wgxh-v2xq-j8vr.json | 2 +- .../GHSA-95cc-jq89-8hvw.json | 2 +- .../GHSA-33r2-8g93-5hm2.json | 2 +- .../GHSA-9gv2-h67q-4h2v.json | 11 ++-- .../GHSA-g5x6-qxv4-vxw3.json | 9 ++-- .../GHSA-qcg7-33w2-mc2x.json | 11 ++-- .../GHSA-rh7m-5r57-4m46.json | 11 ++-- .../GHSA-wc5v-66fr-qmw9.json | 11 ++-- .../GHSA-5wp7-92wc-c55h.json | 11 ++-- .../GHSA-25mm-w878-4w74.json | 38 ++++++++++++++ .../GHSA-2pfx-377q-35vr.json | 38 ++++++++++++++ .../GHSA-2w64-4c9j-pq4x.json | 35 +++++++++++++ .../GHSA-3h9f-v388-6w84.json | 39 ++++++++++++++ .../GHSA-47g9-6fvg-823p.json | 35 +++++++++++++ .../GHSA-4mfx-rj6g-3m4p.json | 38 ++++++++++++++ .../GHSA-4pcq-7rw3-2jvx.json | 9 ++-- .../GHSA-5qh7-385v-fmqf.json | 35 +++++++++++++ .../GHSA-5v6c-5897-pqv6.json | 35 +++++++++++++ .../GHSA-735m-6fpp-9xv9.json | 35 +++++++++++++ .../GHSA-7c65-3hqv-hvmm.json | 2 +- .../GHSA-7p5f-7qpj-wpgq.json | 38 ++++++++++++++ .../GHSA-7pvh-576q-qpv3.json | 11 ++-- .../GHSA-7r4m-g29q-qf8v.json | 11 ++-- .../GHSA-7v22-q5cq-gc3v.json | 31 +++++++++++ .../GHSA-849w-8f8x-v945.json | 35 +++++++++++++ .../GHSA-92m5-rpfj-8332.json | 11 ++-- .../GHSA-9474-6fxf-wjj8.json | 38 ++++++++++++++ .../GHSA-99p7-c89v-ph5p.json | 35 +++++++++++++ .../GHSA-99xc-66p2-xpcg.json | 3 +- .../GHSA-9f4h-r2c7-m6w4.json | 2 +- .../GHSA-9wgr-rjc3-37wx.json | 35 +++++++++++++ .../GHSA-c76m-j64q-g5p2.json | 35 +++++++++++++ .../GHSA-c9hj-p989-pvmr.json | 35 +++++++++++++ .../GHSA-c9v7-fv5h-vr5j.json | 35 +++++++++++++ .../GHSA-fxqh-fxcq-8pfr.json | 3 +- .../GHSA-g42v-m6jh-g8qw.json | 35 +++++++++++++ .../GHSA-gc7r-mr2h-cg8h.json | 35 +++++++++++++ .../GHSA-ggcq-5v24-32h6.json | 35 +++++++++++++ .../GHSA-gp8c-83qw-c833.json | 35 +++++++++++++ .../GHSA-hfwx-j6h2-rmf7.json | 2 +- .../GHSA-hx77-9fm9-jx6j.json | 6 ++- .../GHSA-jcp5-52c9-m2w2.json | 38 ++++++++++++++ .../GHSA-jmg6-w85r-58w8.json | 11 ++-- .../GHSA-m833-cpj5-q368.json | 11 ++-- .../GHSA-mr5m-3jc5-v2f3.json | 39 ++++++++++++++ .../GHSA-mrh2-c3xg-pf82.json | 11 ++-- .../GHSA-mv5r-7xhv-c4gx.json | 9 ++-- .../GHSA-prf8-q9jr-xcfm.json | 35 +++++++++++++ .../GHSA-q222-99qr-rp2h.json | 39 ++++++++++++++ .../GHSA-q3fg-4x56-mx94.json | 2 +- .../GHSA-q8j2-m6jw-5583.json | 35 +++++++++++++ .../GHSA-qqfx-wfhx-8f56.json | 2 +- .../GHSA-v38r-cmm6-v8c3.json | 35 +++++++++++++ .../GHSA-v826-2933-8r2h.json | 42 +++++++++++++++ .../GHSA-vj76-xpgc-chxj.json | 35 +++++++++++++ .../GHSA-vjfm-r2x9-3672.json | 51 +++++++++++++++++++ .../GHSA-vw79-qcwr-vp64.json | 38 ++++++++++++++ .../GHSA-w7p8-rxjg-j7wx.json | 42 +++++++++++++++ .../GHSA-whfh-mm2w-723c.json | 3 +- .../GHSA-wq8w-m2g8-mv57.json | 11 ++-- .../GHSA-wx3f-2mg8-w779.json | 3 +- .../GHSA-x386-xj3c-xjx5.json | 35 +++++++++++++ .../GHSA-xmgx-2283-p55h.json | 2 +- 65 files changed, 1375 insertions(+), 73 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-25mm-w878-4w74/GHSA-25mm-w878-4w74.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2pfx-377q-35vr/GHSA-2pfx-377q-35vr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2w64-4c9j-pq4x/GHSA-2w64-4c9j-pq4x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json create mode 100644 advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4mfx-rj6g-3m4p/GHSA-4mfx-rj6g-3m4p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-735m-6fpp-9xv9/GHSA-735m-6fpp-9xv9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7p5f-7qpj-wpgq/GHSA-7p5f-7qpj-wpgq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7v22-q5cq-gc3v/GHSA-7v22-q5cq-gc3v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9474-6fxf-wjj8/GHSA-9474-6fxf-wjj8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c76m-j64q-g5p2/GHSA-c76m-j64q-g5p2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g42v-m6jh-g8qw/GHSA-g42v-m6jh-g8qw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jcp5-52c9-m2w2/GHSA-jcp5-52c9-m2w2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-prf8-q9jr-xcfm/GHSA-prf8-q9jr-xcfm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v826-2933-8r2h/GHSA-v826-2933-8r2h.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vj76-xpgc-chxj/GHSA-vj76-xpgc-chxj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vjfm-r2x9-3672/GHSA-vjfm-r2x9-3672.json create mode 100644 advisories/unreviewed/2024/11/GHSA-vw79-qcwr-vp64/GHSA-vw79-qcwr-vp64.json create mode 100644 advisories/unreviewed/2024/11/GHSA-w7p8-rxjg-j7wx/GHSA-w7p8-rxjg-j7wx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json diff --git a/advisories/unreviewed/2022/05/GHSA-24mx-5rm6-qcm5/GHSA-24mx-5rm6-qcm5.json b/advisories/unreviewed/2022/05/GHSA-24mx-5rm6-qcm5/GHSA-24mx-5rm6-qcm5.json index beff8371b57..2445d836ab6 100644 --- a/advisories/unreviewed/2022/05/GHSA-24mx-5rm6-qcm5/GHSA-24mx-5rm6-qcm5.json +++ b/advisories/unreviewed/2022/05/GHSA-24mx-5rm6-qcm5/GHSA-24mx-5rm6-qcm5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24mx-5rm6-qcm5", - "modified": "2022-05-13T01:13:34Z", + "modified": "2024-11-19T21:31:29Z", "published": "2022-05-13T01:13:34Z", "aliases": [ "CVE-2019-3821" diff --git a/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json b/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json index 4bd5099a7b0..6a9da30d873 100644 --- a/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json +++ b/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json b/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json index c68a026e689..16ca28e35e6 100644 --- a/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json +++ b/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-95cc-jq89-8hvw/GHSA-95cc-jq89-8hvw.json b/advisories/unreviewed/2023/11/GHSA-95cc-jq89-8hvw/GHSA-95cc-jq89-8hvw.json index 72e1460cbb9..778b1ea3d0c 100644 --- a/advisories/unreviewed/2023/11/GHSA-95cc-jq89-8hvw/GHSA-95cc-jq89-8hvw.json +++ b/advisories/unreviewed/2023/11/GHSA-95cc-jq89-8hvw/GHSA-95cc-jq89-8hvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-95cc-jq89-8hvw", - "modified": "2023-11-02T18:30:25Z", + "modified": "2024-11-19T21:31:30Z", "published": "2023-11-02T18:30:25Z", "aliases": [ "CVE-2022-4900" diff --git a/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json b/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json index 1da09226958..4a0413526ef 100644 --- a/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json +++ b/advisories/unreviewed/2024/03/GHSA-33r2-8g93-5hm2/GHSA-33r2-8g93-5hm2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-436" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9gv2-h67q-4h2v/GHSA-9gv2-h67q-4h2v.json b/advisories/unreviewed/2024/03/GHSA-9gv2-h67q-4h2v/GHSA-9gv2-h67q-4h2v.json index 9587ea4c834..dc961542dcb 100644 --- a/advisories/unreviewed/2024/03/GHSA-9gv2-h67q-4h2v/GHSA-9gv2-h67q-4h2v.json +++ b/advisories/unreviewed/2024/03/GHSA-9gv2-h67q-4h2v/GHSA-9gv2-h67q-4h2v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gv2-h67q-4h2v", - "modified": "2024-03-27T06:30:32Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-03-27T06:30:32Z", "aliases": [ "CVE-2023-45922" ], "details": "glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T05:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json b/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json index b8eb3d1ab92..fedec1a4b05 100644 --- a/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json +++ b/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5x6-qxv4-vxw3", - "modified": "2024-03-28T03:30:59Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-28013" ], "details": "Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to change settings via the internet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-330" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qcg7-33w2-mc2x/GHSA-qcg7-33w2-mc2x.json b/advisories/unreviewed/2024/03/GHSA-qcg7-33w2-mc2x/GHSA-qcg7-33w2-mc2x.json index 849936afc48..57200ad9238 100644 --- a/advisories/unreviewed/2024/03/GHSA-qcg7-33w2-mc2x/GHSA-qcg7-33w2-mc2x.json +++ b/advisories/unreviewed/2024/03/GHSA-qcg7-33w2-mc2x/GHSA-qcg7-33w2-mc2x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcg7-33w2-mc2x", - "modified": "2024-03-18T06:30:50Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-03-18T06:30:50Z", "aliases": [ "CVE-2024-28745" ], "details": "Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing another app installed on the user's device to access an arbitrary URL on 'ABEMA' App for Android via Intent. If this vulnerability is exploited, an arbitrary website may be displayed on the app, and as a result, the user may become a victim of a phishing attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rh7m-5r57-4m46/GHSA-rh7m-5r57-4m46.json b/advisories/unreviewed/2024/03/GHSA-rh7m-5r57-4m46/GHSA-rh7m-5r57-4m46.json index e3df606fc3e..00edb3a42a0 100644 --- a/advisories/unreviewed/2024/03/GHSA-rh7m-5r57-4m46/GHSA-rh7m-5r57-4m46.json +++ b/advisories/unreviewed/2024/03/GHSA-rh7m-5r57-4m46/GHSA-rh7m-5r57-4m46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rh7m-5r57-4m46", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20038" ], "details": "In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495932; Issue ID: ALPS08495932.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json b/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json index ad7f2d5df28..e00ed699b2f 100644 --- a/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json +++ b/advisories/unreviewed/2024/04/GHSA-wc5v-66fr-qmw9/GHSA-wc5v-66fr-qmw9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wc5v-66fr-qmw9", - "modified": "2024-04-08T15:30:33Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-04-08T15:30:33Z", "aliases": [ "CVE-2024-31813" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5wp7-92wc-c55h/GHSA-5wp7-92wc-c55h.json b/advisories/unreviewed/2024/05/GHSA-5wp7-92wc-c55h/GHSA-5wp7-92wc-c55h.json index 2c7179e35b0..c48c563fd1e 100644 --- a/advisories/unreviewed/2024/05/GHSA-5wp7-92wc-c55h/GHSA-5wp7-92wc-c55h.json +++ b/advisories/unreviewed/2024/05/GHSA-5wp7-92wc-c55h/GHSA-5wp7-92wc-c55h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wp7-92wc-c55h", - "modified": "2024-05-22T18:30:43Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-05-22T18:30:43Z", "aliases": [ "CVE-2024-31617" ], "details": "OpenLiteSpeed before 1.8.1 mishandles chunked encoding.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T18:15:10Z" diff --git a/advisories/unreviewed/2024/11/GHSA-25mm-w878-4w74/GHSA-25mm-w878-4w74.json b/advisories/unreviewed/2024/11/GHSA-25mm-w878-4w74/GHSA-25mm-w878-4w74.json new file mode 100644 index 00000000000..1b15ea18d6d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-25mm-w878-4w74/GHSA-25mm-w878-4w74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25mm-w878-4w74", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-45420" + ], + "details": "Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45420" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2pfx-377q-35vr/GHSA-2pfx-377q-35vr.json b/advisories/unreviewed/2024/11/GHSA-2pfx-377q-35vr/GHSA-2pfx-377q-35vr.json new file mode 100644 index 00000000000..257fbdfb90e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2pfx-377q-35vr/GHSA-2pfx-377q-35vr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pfx-377q-35vr", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-45419" + ], + "details": "Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45419" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-252" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2w64-4c9j-pq4x/GHSA-2w64-4c9j-pq4x.json b/advisories/unreviewed/2024/11/GHSA-2w64-4c9j-pq4x/GHSA-2w64-4c9j-pq4x.json new file mode 100644 index 00000000000..274670220d2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2w64-4c9j-pq4x/GHSA-2w64-4c9j-pq4x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w64-4c9j-pq4x", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9368" + ], + "details": "In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This could lead to local escalation of privilege with system  execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9368" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json b/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json new file mode 100644 index 00000000000..82734e6ca16 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3h9f-v388-6w84/GHSA-3h9f-v388-6w84.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h9f-v388-6w84", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-11395" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11395" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_19.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/377384894" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json b/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json new file mode 100644 index 00000000000..23de96499e4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-47g9-6fvg-823p/GHSA-47g9-6fvg-823p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47g9-6fvg-823p", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9366" + ], + "details": "In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9366" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4mfx-rj6g-3m4p/GHSA-4mfx-rj6g-3m4p.json b/advisories/unreviewed/2024/11/GHSA-4mfx-rj6g-3m4p/GHSA-4mfx-rj6g-3m4p.json new file mode 100644 index 00000000000..fa4c7e6ff5d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4mfx-rj6g-3m4p/GHSA-4mfx-rj6g-3m4p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mfx-rj6g-3m4p", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2024-50430" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/beaver-builder-lite-version/wordpress-beaver-builder-plugin-2-8-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4pcq-7rw3-2jvx/GHSA-4pcq-7rw3-2jvx.json b/advisories/unreviewed/2024/11/GHSA-4pcq-7rw3-2jvx/GHSA-4pcq-7rw3-2jvx.json index 08059ae6070..f34ad835001 100644 --- a/advisories/unreviewed/2024/11/GHSA-4pcq-7rw3-2jvx/GHSA-4pcq-7rw3-2jvx.json +++ b/advisories/unreviewed/2024/11/GHSA-4pcq-7rw3-2jvx/GHSA-4pcq-7rw3-2jvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pcq-7rw3-2jvx", - "modified": "2024-11-15T00:31:51Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-15T00:31:51Z", "aliases": [ "CVE-2017-13227" ], "details": "In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json b/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json new file mode 100644 index 00000000000..7fea651e181 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5qh7-385v-fmqf/GHSA-5qh7-385v-fmqf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qh7-385v-fmqf", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9348" + ], + "details": "In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9348" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json b/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json new file mode 100644 index 00000000000..b1bbed61186 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5v6c-5897-pqv6/GHSA-5v6c-5897-pqv6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v6c-5897-pqv6", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9410" + ], + "details": "In analyzeAxes of FontUtils.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9410" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-735m-6fpp-9xv9/GHSA-735m-6fpp-9xv9.json b/advisories/unreviewed/2024/11/GHSA-735m-6fpp-9xv9/GHSA-735m-6fpp-9xv9.json new file mode 100644 index 00000000000..d2e024a56a9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-735m-6fpp-9xv9/GHSA-735m-6fpp-9xv9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-735m-6fpp-9xv9", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9367" + ], + "details": "In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9367" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json b/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json index e4ed92052e0..a8e0fba1e39 100644 --- a/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json +++ b/advisories/unreviewed/2024/11/GHSA-7c65-3hqv-hvmm/GHSA-7c65-3hqv-hvmm.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-7p5f-7qpj-wpgq/GHSA-7p5f-7qpj-wpgq.json b/advisories/unreviewed/2024/11/GHSA-7p5f-7qpj-wpgq/GHSA-7p5f-7qpj-wpgq.json new file mode 100644 index 00000000000..b17876db830 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7p5f-7qpj-wpgq/GHSA-7p5f-7qpj-wpgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p5f-7qpj-wpgq", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-52360" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52360" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7pvh-576q-qpv3/GHSA-7pvh-576q-qpv3.json b/advisories/unreviewed/2024/11/GHSA-7pvh-576q-qpv3/GHSA-7pvh-576q-qpv3.json index 23f35967431..77f744bea7b 100644 --- a/advisories/unreviewed/2024/11/GHSA-7pvh-576q-qpv3/GHSA-7pvh-576q-qpv3.json +++ b/advisories/unreviewed/2024/11/GHSA-7pvh-576q-qpv3/GHSA-7pvh-576q-qpv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pvh-576q-qpv3", - "modified": "2024-11-15T00:31:52Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-15T00:31:52Z", "aliases": [ "CVE-2024-52613" ], "details": "A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafted MOV video file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json b/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json index 0e29a1a1437..f4293e080a0 100644 --- a/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json +++ b/advisories/unreviewed/2024/11/GHSA-7r4m-g29q-qf8v/GHSA-7r4m-g29q-qf8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7r4m-g29q-qf8v", - "modified": "2024-11-11T00:30:44Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-11-11T00:30:44Z", "aliases": [ "CVE-2021-41737" ], "details": "In Faust 2.23.1, an input file with the lines \"// r visualisation tCst\" and \"//process = +: L: abM-^Q;\" and \"process = route(3333333333333333333,2,1,2,3,1) : *;\" leads to stack consumption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-674" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-10T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7v22-q5cq-gc3v/GHSA-7v22-q5cq-gc3v.json b/advisories/unreviewed/2024/11/GHSA-7v22-q5cq-gc3v/GHSA-7v22-q5cq-gc3v.json new file mode 100644 index 00000000000..7ab8d9af00e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7v22-q5cq-gc3v/GHSA-7v22-q5cq-gc3v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v22-q5cq-gc3v", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-1271" + ], + "details": "Rejected reason: This CVE was previously published at https://bugzilla.redhat.com/show_bug.cgi?id=2262978 but later rejected for the following reason: The flaw requires an attacker to have superuser credentials which is a condition that already permits all impacts, hence not constituing a security vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1271" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json b/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json new file mode 100644 index 00000000000..1fcaefc2574 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-849w-8f8x-v945/GHSA-849w-8f8x-v945.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-849w-8f8x-v945", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9341" + ], + "details": "In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9341" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json b/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json index 2df9d61c28a..38d0a7f6e35 100644 --- a/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json +++ b/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92m5-rpfj-8332", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-44546" ], "details": "Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9474-6fxf-wjj8/GHSA-9474-6fxf-wjj8.json b/advisories/unreviewed/2024/11/GHSA-9474-6fxf-wjj8/GHSA-9474-6fxf-wjj8.json new file mode 100644 index 00000000000..0c4c2383d90 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9474-6fxf-wjj8/GHSA-9474-6fxf-wjj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9474-6fxf-wjj8", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-52359" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improper access controls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52359" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json b/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json new file mode 100644 index 00000000000..9439cf1ddf3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99p7-c89v-ph5p", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-52762" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the \"tz\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52762" + }, + { + "type": "WEB", + "url": "https://github.com/ganglia/ganglia-web/issues/382" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-99xc-66p2-xpcg/GHSA-99xc-66p2-xpcg.json b/advisories/unreviewed/2024/11/GHSA-99xc-66p2-xpcg/GHSA-99xc-66p2-xpcg.json index 7d6d4c7d3ff..ffe228be7d2 100644 --- a/advisories/unreviewed/2024/11/GHSA-99xc-66p2-xpcg/GHSA-99xc-66p2-xpcg.json +++ b/advisories/unreviewed/2024/11/GHSA-99xc-66p2-xpcg/GHSA-99xc-66p2-xpcg.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json b/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json index 4336f9d80b8..477edab4f04 100644 --- a/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json +++ b/advisories/unreviewed/2024/11/GHSA-9f4h-r2c7-m6w4/GHSA-9f4h-r2c7-m6w4.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json b/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json new file mode 100644 index 00000000000..c7efc9bfd35 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wgr-rjc3-37wx", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9371" + ], + "details": "In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9371" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c76m-j64q-g5p2/GHSA-c76m-j64q-g5p2.json b/advisories/unreviewed/2024/11/GHSA-c76m-j64q-g5p2/GHSA-c76m-j64q-g5p2.json new file mode 100644 index 00000000000..8e5fdfbfc3d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c76m-j64q-g5p2/GHSA-c76m-j64q-g5p2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c76m-j64q-g5p2", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9372" + ], + "details": "In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege in the bootloader with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9372" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json b/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json new file mode 100644 index 00000000000..47afd45c3c2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c9hj-p989-pvmr/GHSA-c9hj-p989-pvmr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9hj-p989-pvmr", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-52763" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the \"g\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52763" + }, + { + "type": "WEB", + "url": "https://github.com/ganglia/ganglia-web/issues/382" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json b/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json new file mode 100644 index 00000000000..f2ff59e4817 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c9v7-fv5h-vr5j/GHSA-c9v7-fv5h-vr5j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9v7-fv5h-vr5j", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9344" + ], + "details": "In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9344" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fxqh-fxcq-8pfr/GHSA-fxqh-fxcq-8pfr.json b/advisories/unreviewed/2024/11/GHSA-fxqh-fxcq-8pfr/GHSA-fxqh-fxcq-8pfr.json index 59a51c6ceb1..6f517f22490 100644 --- a/advisories/unreviewed/2024/11/GHSA-fxqh-fxcq-8pfr/GHSA-fxqh-fxcq-8pfr.json +++ b/advisories/unreviewed/2024/11/GHSA-fxqh-fxcq-8pfr/GHSA-fxqh-fxcq-8pfr.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-g42v-m6jh-g8qw/GHSA-g42v-m6jh-g8qw.json b/advisories/unreviewed/2024/11/GHSA-g42v-m6jh-g8qw/GHSA-g42v-m6jh-g8qw.json new file mode 100644 index 00000000000..98d18d302db --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g42v-m6jh-g8qw/GHSA-g42v-m6jh-g8qw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g42v-m6jh-g8qw", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9370" + ], + "details": "In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9370" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json b/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json new file mode 100644 index 00000000000..8dae4022d4e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gc7r-mr2h-cg8h/GHSA-gc7r-mr2h-cg8h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc7r-mr2h-cg8h", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9364" + ], + "details": "In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9364" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json b/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json new file mode 100644 index 00000000000..f8f390253e6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggcq-5v24-32h6", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9409" + ], + "details": "In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9409" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json b/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json new file mode 100644 index 00000000000..2544025e88c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gp8c-83qw-c833/GHSA-gp8c-83qw-c833.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp8c-83qw-c833", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9345" + ], + "details": "In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9345" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json b/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json index 21e6e43c739..6d56f5056cd 100644 --- a/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json +++ b/advisories/unreviewed/2024/11/GHSA-hfwx-j6h2-rmf7/GHSA-hfwx-j6h2-rmf7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-hx77-9fm9-jx6j/GHSA-hx77-9fm9-jx6j.json b/advisories/unreviewed/2024/11/GHSA-hx77-9fm9-jx6j/GHSA-hx77-9fm9-jx6j.json index bbf3d223045..8aac4ae01bf 100644 --- a/advisories/unreviewed/2024/11/GHSA-hx77-9fm9-jx6j/GHSA-hx77-9fm9-jx6j.json +++ b/advisories/unreviewed/2024/11/GHSA-hx77-9fm9-jx6j/GHSA-hx77-9fm9-jx6j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx77-9fm9-jx6j", - "modified": "2024-11-15T12:31:45Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-15T12:31:45Z", "aliases": [ "CVE-2024-10534" ], "details": "Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection.This issue affects Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS): before 2024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-jcp5-52c9-m2w2/GHSA-jcp5-52c9-m2w2.json b/advisories/unreviewed/2024/11/GHSA-jcp5-52c9-m2w2/GHSA-jcp5-52c9-m2w2.json new file mode 100644 index 00000000000..23d1d15fa04 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jcp5-52c9-m2w2/GHSA-jcp5-52c9-m2w2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcp5-52c9-m2w2", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-37070" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37070" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jmg6-w85r-58w8/GHSA-jmg6-w85r-58w8.json b/advisories/unreviewed/2024/11/GHSA-jmg6-w85r-58w8/GHSA-jmg6-w85r-58w8.json index 24668a9dcba..67b20396505 100644 --- a/advisories/unreviewed/2024/11/GHSA-jmg6-w85r-58w8/GHSA-jmg6-w85r-58w8.json +++ b/advisories/unreviewed/2024/11/GHSA-jmg6-w85r-58w8/GHSA-jmg6-w85r-58w8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmg6-w85r-58w8", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-25254" ], "details": "SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json b/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json index 70c8daf0ac4..c362ba34658 100644 --- a/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json +++ b/advisories/unreviewed/2024/11/GHSA-m833-cpj5-q368/GHSA-m833-cpj5-q368.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m833-cpj5-q368", - "modified": "2024-11-11T00:30:44Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-11-11T00:30:44Z", "aliases": [ "CVE-2021-35473" ], "details": "An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-10T23:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json b/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json new file mode 100644 index 00000000000..9c6cf055aae --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr5m-3jc5-v2f3", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2024-52759" + ], + "details": "D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52759" + }, + { + "type": "WEB", + "url": "https://github.com/faqiadegege/IoTVuln/blob/main/DI_8003_ip_position_asp_stackoverflow/detail.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mrh2-c3xg-pf82/GHSA-mrh2-c3xg-pf82.json b/advisories/unreviewed/2024/11/GHSA-mrh2-c3xg-pf82/GHSA-mrh2-c3xg-pf82.json index c32e4a45d14..0ef80ff3bc5 100644 --- a/advisories/unreviewed/2024/11/GHSA-mrh2-c3xg-pf82/GHSA-mrh2-c3xg-pf82.json +++ b/advisories/unreviewed/2024/11/GHSA-mrh2-c3xg-pf82/GHSA-mrh2-c3xg-pf82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrh2-c3xg-pf82", - "modified": "2024-11-13T21:30:32Z", + "modified": "2024-11-19T21:31:30Z", "published": "2024-11-11T03:30:45Z", "aliases": [ "CVE-2024-48939" ], "details": "Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T01:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mv5r-7xhv-c4gx/GHSA-mv5r-7xhv-c4gx.json b/advisories/unreviewed/2024/11/GHSA-mv5r-7xhv-c4gx/GHSA-mv5r-7xhv-c4gx.json index 3a354f93600..a952939957a 100644 --- a/advisories/unreviewed/2024/11/GHSA-mv5r-7xhv-c4gx/GHSA-mv5r-7xhv-c4gx.json +++ b/advisories/unreviewed/2024/11/GHSA-mv5r-7xhv-c4gx/GHSA-mv5r-7xhv-c4gx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mv5r-7xhv-c4gx", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2023-35659" ], "details": "In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-prf8-q9jr-xcfm/GHSA-prf8-q9jr-xcfm.json b/advisories/unreviewed/2024/11/GHSA-prf8-q9jr-xcfm/GHSA-prf8-q9jr-xcfm.json new file mode 100644 index 00000000000..6f5267820ee --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-prf8-q9jr-xcfm/GHSA-prf8-q9jr-xcfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prf8-q9jr-xcfm", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9369" + ], + "details": "In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9369" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json b/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json new file mode 100644 index 00000000000..40a38b66643 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q222-99qr-rp2h", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2024-52714" + ], + "details": "Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52714" + }, + { + "type": "WEB", + "url": "https://github.com/CLan-nad/CVE/blob/main/tenda/fromSetSysTime/1.md" + }, + { + "type": "WEB", + "url": "http://tenda.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json b/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json index cf96c856c83..62e49e5c97c 100644 --- a/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json +++ b/advisories/unreviewed/2024/11/GHSA-q3fg-4x56-mx94/GHSA-q3fg-4x56-mx94.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3fg-4x56-mx94", - "modified": "2024-11-18T18:30:49Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-15T12:31:45Z", "aliases": [ "CVE-2024-11182" diff --git a/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json b/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json new file mode 100644 index 00000000000..94474e8b1f4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q8j2-m6jw-5583/GHSA-q8j2-m6jw-5583.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8j2-m6jw-5583", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9346" + ], + "details": "In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9346" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qqfx-wfhx-8f56/GHSA-qqfx-wfhx-8f56.json b/advisories/unreviewed/2024/11/GHSA-qqfx-wfhx-8f56/GHSA-qqfx-wfhx-8f56.json index 9fadbee9f14..b2b4ebf2b40 100644 --- a/advisories/unreviewed/2024/11/GHSA-qqfx-wfhx-8f56/GHSA-qqfx-wfhx-8f56.json +++ b/advisories/unreviewed/2024/11/GHSA-qqfx-wfhx-8f56/GHSA-qqfx-wfhx-8f56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqfx-wfhx-8f56", - "modified": "2024-11-15T06:30:32Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-15T06:30:32Z", "aliases": [ "CVE-2024-10113" diff --git a/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json b/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json new file mode 100644 index 00000000000..da717da4462 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v38r-cmm6-v8c3/GHSA-v38r-cmm6-v8c3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v38r-cmm6-v8c3", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9339" + ], + "details": "In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9339" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v826-2933-8r2h/GHSA-v826-2933-8r2h.json b/advisories/unreviewed/2024/11/GHSA-v826-2933-8r2h/GHSA-v826-2933-8r2h.json new file mode 100644 index 00000000000..6cf377222a3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v826-2933-8r2h/GHSA-v826-2933-8r2h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v826-2933-8r2h", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2024-21697" + ], + "details": "This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows.\n\nThis RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.\n\nAtlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n Sourcetree for Mac 4.2: Upgrade to a release greater than or equal to 4.2.9\n Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.20\n\nSee the release notes ([https://www.sourcetreeapp.com/download-archives]). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center ([https://www.sourcetreeapp.com/download-archives]).\n\nThis vulnerability was reported via our Penetration Testing program.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21697" + }, + { + "type": "WEB", + "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1456179091" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/SRCTREE-8168" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vj76-xpgc-chxj/GHSA-vj76-xpgc-chxj.json b/advisories/unreviewed/2024/11/GHSA-vj76-xpgc-chxj/GHSA-vj76-xpgc-chxj.json new file mode 100644 index 00000000000..35cc87e2b6c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vj76-xpgc-chxj/GHSA-vj76-xpgc-chxj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj76-xpgc-chxj", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2018-9365" + ], + "details": "In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9365" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-07-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T21:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vjfm-r2x9-3672/GHSA-vjfm-r2x9-3672.json b/advisories/unreviewed/2024/11/GHSA-vjfm-r2x9-3672/GHSA-vjfm-r2x9-3672.json new file mode 100644 index 00000000000..9e55f3ac8b2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vjfm-r2x9-3672/GHSA-vjfm-r2x9-3672.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjfm-r2x9-3672", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2024-48694" + ], + "details": "File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48694" + }, + { + "type": "WEB", + "url": "https://avd.aliyun.com/detail?id=AVD-2023-1678930" + }, + { + "type": "WEB", + "url": "https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/32024c5dbb7ff60fa7347cccf6ebb3763a513e7a/docs/wiki/webapp/OfficeWeb365/OfficeWeb365%20SaveDraw%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md?plain=1#L24" + }, + { + "type": "WEB", + "url": "https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/OfficeWeb365-SaveDraw-%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md" + }, + { + "type": "WEB", + "url": "https://github.com/luck-ying/Library-POC/blob/master/2023HW/2023.8.15/OfficeWeb365_SaveDraw%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.py" + }, + { + "type": "WEB", + "url": "https://github.com/xuetang1125/OfficeWeb365/blob/main/OfficeWeb365%20SaveDraw%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E%20%282%29.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vw79-qcwr-vp64/GHSA-vw79-qcwr-vp64.json b/advisories/unreviewed/2024/11/GHSA-vw79-qcwr-vp64/GHSA-vw79-qcwr-vp64.json new file mode 100644 index 00000000000..2b93dc82f3c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vw79-qcwr-vp64/GHSA-vw79-qcwr-vp64.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw79-qcwr-vp64", + "modified": "2024-11-19T21:31:33Z", + "published": "2024-11-19T21:31:33Z", + "aliases": [ + "CVE-2024-45422" + ], + "details": "Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45422" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w7p8-rxjg-j7wx/GHSA-w7p8-rxjg-j7wx.json b/advisories/unreviewed/2024/11/GHSA-w7p8-rxjg-j7wx/GHSA-w7p8-rxjg-j7wx.json new file mode 100644 index 00000000000..11c8dfb226d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w7p8-rxjg-j7wx/GHSA-w7p8-rxjg-j7wx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7p8-rxjg-j7wx", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2024-51503" + ], + "details": "A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51503" + }, + { + "type": "WEB", + "url": "https://success.trendmicro.com/en-US/solution/KA-0018154" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-whfh-mm2w-723c/GHSA-whfh-mm2w-723c.json b/advisories/unreviewed/2024/11/GHSA-whfh-mm2w-723c/GHSA-whfh-mm2w-723c.json index ffa36bf3272..0119d41fa59 100644 --- a/advisories/unreviewed/2024/11/GHSA-whfh-mm2w-723c/GHSA-whfh-mm2w-723c.json +++ b/advisories/unreviewed/2024/11/GHSA-whfh-mm2w-723c/GHSA-whfh-mm2w-723c.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-wq8w-m2g8-mv57/GHSA-wq8w-m2g8-mv57.json b/advisories/unreviewed/2024/11/GHSA-wq8w-m2g8-mv57/GHSA-wq8w-m2g8-mv57.json index 3b74b931f43..ff7c65efd4f 100644 --- a/advisories/unreviewed/2024/11/GHSA-wq8w-m2g8-mv57/GHSA-wq8w-m2g8-mv57.json +++ b/advisories/unreviewed/2024/11/GHSA-wq8w-m2g8-mv57/GHSA-wq8w-m2g8-mv57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq8w-m2g8-mv57", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-19T21:31:31Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-50636" ], "details": "PyMOL 2.5.0 contains a vulnerability in its \"Run Script\" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function to achieve Remote Command Execution (RCE). This vulnerability arises because PyMOL treats .PYM files as Python scripts without properly validating or restricting the commands within the script, enabling attackers to run unauthorized commands in the context of the user running the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wx3f-2mg8-w779/GHSA-wx3f-2mg8-w779.json b/advisories/unreviewed/2024/11/GHSA-wx3f-2mg8-w779/GHSA-wx3f-2mg8-w779.json index d31cd4b2c76..73e35f70a47 100644 --- a/advisories/unreviewed/2024/11/GHSA-wx3f-2mg8-w779/GHSA-wx3f-2mg8-w779.json +++ b/advisories/unreviewed/2024/11/GHSA-wx3f-2mg8-w779/GHSA-wx3f-2mg8-w779.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json b/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json new file mode 100644 index 00000000000..dc91d9a2934 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x386-xj3c-xjx5/GHSA-x386-xj3c-xjx5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x386-xj3c-xjx5", + "modified": "2024-11-19T21:31:32Z", + "published": "2024-11-19T21:31:32Z", + "aliases": [ + "CVE-2018-9340" + ], + "details": "In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9340" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-06-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T19:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json b/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json index dd9284b575a..b3cda6f7ced 100644 --- a/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json +++ b/advisories/unreviewed/2024/11/GHSA-xmgx-2283-p55h/GHSA-xmgx-2283-p55h.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], "severity": "HIGH", "github_reviewed": false,