From d1140e1bab6dddee5c2f3a6252beab174bfdc80a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jul 2024 18:34:26 +0000 Subject: [PATCH] Advisory Database Sync --- .../03/GHSA-65jp-cf4c-rcq6/GHSA-65jp-cf4c-rcq6.json | 2 +- .../05/GHSA-25r9-gpg2-xcwf/GHSA-25r9-gpg2-xcwf.json | 2 +- .../05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json | 3 ++- .../05/GHSA-4grg-84cr-6c2h/GHSA-4grg-84cr-6c2h.json | 3 ++- .../05/GHSA-57g4-6x5r-c4qc/GHSA-57g4-6x5r-c4qc.json | 2 +- .../05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json | 1 + .../05/GHSA-7pcp-8fjh-246q/GHSA-7pcp-8fjh-246q.json | 6 +++++- .../05/GHSA-cx5r-6jgc-m635/GHSA-cx5r-6jgc-m635.json | 2 +- .../05/GHSA-fvpv-m998-g6f8/GHSA-fvpv-m998-g6f8.json | 9 ++++++--- .../05/GHSA-jc6g-whc6-qfj3/GHSA-jc6g-whc6-qfj3.json | 2 +- .../05/GHSA-jcmg-8grx-m8j6/GHSA-jcmg-8grx-m8j6.json | 1 + .../05/GHSA-jj88-6656-w759/GHSA-jj88-6656-w759.json | 3 ++- .../05/GHSA-q7w5-cq9g-vhw8/GHSA-q7w5-cq9g-vhw8.json | 1 + .../05/GHSA-w39r-2vjm-hgjq/GHSA-w39r-2vjm-hgjq.json | 3 ++- .../05/GHSA-w458-qg9w-x8vm/GHSA-w458-qg9w-x8vm.json | 3 ++- .../09/GHSA-7mrh-jrcg-wc76/GHSA-7mrh-jrcg-wc76.json | 1 + .../09/GHSA-hr8v-98c3-7p3x/GHSA-hr8v-98c3-7p3x.json | 12 ++++++++++-- .../11/GHSA-c7rr-4vvg-c7r2/GHSA-c7rr-4vvg-c7r2.json | 2 +- .../11/GHSA-f594-4w5v-rpf5/GHSA-f594-4w5v-rpf5.json | 9 +++++++-- .../01/GHSA-2cqm-w497-9r99/GHSA-2cqm-w497-9r99.json | 2 +- .../01/GHSA-5jrg-vf8f-2h5c/GHSA-5jrg-vf8f-2h5c.json | 1 + .../07/GHSA-m82c-5hpw-48f7/GHSA-m82c-5hpw-48f7.json | 2 +- .../07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json | 3 ++- .../08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json | 2 +- .../08/GHSA-9ww7-xcfq-fwj7/GHSA-9ww7-xcfq-fwj7.json | 2 +- .../08/GHSA-w5x7-vwr2-4x27/GHSA-w5x7-vwr2-4x27.json | 2 +- .../09/GHSA-6wp3-hhxh-4vfp/GHSA-6wp3-hhxh-4vfp.json | 2 +- .../10/GHSA-87j2-5g9j-7jmv/GHSA-87j2-5g9j-7jmv.json | 2 +- .../10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json | 4 ++-- .../10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json | 2 +- .../10/GHSA-x3vv-qh4r-crf2/GHSA-x3vv-qh4r-crf2.json | 4 ++-- .../11/GHSA-8rh4-mxhq-673g/GHSA-8rh4-mxhq-673g.json | 2 +- .../11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json | 1 + .../12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json | 1 + .../01/GHSA-4pvg-f3m8-ff3j/GHSA-4pvg-f3m8-ff3j.json | 2 +- .../01/GHSA-8fmw-7mxc-55jq/GHSA-8fmw-7mxc-55jq.json | 2 +- .../01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json | 2 +- .../01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json | 2 +- .../01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json | 2 +- .../01/GHSA-vg6w-jr5m-86c8/GHSA-vg6w-jr5m-86c8.json | 3 ++- .../01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json | 2 +- .../02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json | 2 +- .../02/GHSA-2x93-8973-5mgq/GHSA-2x93-8973-5mgq.json | 1 + .../02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json | 2 +- .../02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json | 4 ++-- .../02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json | 3 ++- .../02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json | 11 +++++++---- .../02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json | 2 +- .../02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json | 11 +++++++---- .../02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json | 2 +- .../02/GHSA-pprj-563h-jxf6/GHSA-pprj-563h-jxf6.json | 11 +++++++---- .../02/GHSA-pwq2-c6f6-f36f/GHSA-pwq2-c6f6-f36f.json | 2 +- .../02/GHSA-vxv3-wgx2-xx92/GHSA-vxv3-wgx2-xx92.json | 9 ++++++--- .../02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json | 2 +- .../03/GHSA-2cp7-qpvm-rw54/GHSA-2cp7-qpvm-rw54.json | 2 +- .../03/GHSA-2pm2-cpjx-462g/GHSA-2pm2-cpjx-462g.json | 11 +++++++---- .../03/GHSA-2rpq-p6fh-7mx6/GHSA-2rpq-p6fh-7mx6.json | 11 +++++++---- .../03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json | 11 +++++++---- .../03/GHSA-57pr-424c-2xfr/GHSA-57pr-424c-2xfr.json | 9 ++++++--- .../03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json | 11 +++++++---- .../03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json | 9 ++++++--- .../03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json | 9 ++++++--- .../03/GHSA-6c2g-6j82-6fjx/GHSA-6c2g-6j82-6fjx.json | 11 +++++++---- .../03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json | 11 +++++++---- .../03/GHSA-6hhg-hj7x-7qv8/GHSA-6hhg-hj7x-7qv8.json | 9 ++++++--- .../03/GHSA-849m-v6gh-gmf9/GHSA-849m-v6gh-gmf9.json | 2 +- .../03/GHSA-96hc-g58p-3pq7/GHSA-96hc-g58p-3pq7.json | 11 +++++++---- .../03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json | 9 ++++++--- .../03/GHSA-99gp-rqx5-272f/GHSA-99gp-rqx5-272f.json | 11 +++++++---- .../03/GHSA-9crf-rxmh-772m/GHSA-9crf-rxmh-772m.json | 2 +- .../03/GHSA-cv2q-pmfm-5c4f/GHSA-cv2q-pmfm-5c4f.json | 11 +++++++---- .../03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json | 11 +++++++---- .../03/GHSA-g92w-952h-vqrj/GHSA-g92w-952h-vqrj.json | 11 +++++++---- .../03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json | 9 ++++++--- .../03/GHSA-gr8x-42gf-wmh7/GHSA-gr8x-42gf-wmh7.json | 11 +++++++---- .../03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json | 11 +++++++---- .../03/GHSA-h62m-673x-763w/GHSA-h62m-673x-763w.json | 2 +- .../03/GHSA-mq3q-f49j-4fjg/GHSA-mq3q-f49j-4fjg.json | 11 +++++++---- .../03/GHSA-mq8w-c2j9-rqxc/GHSA-mq8w-c2j9-rqxc.json | 9 ++++++--- .../03/GHSA-pp4p-q324-qhgr/GHSA-pp4p-q324-qhgr.json | 11 +++++++---- .../03/GHSA-q22h-9rc9-jpmp/GHSA-q22h-9rc9-jpmp.json | 2 +- .../03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json | 6 +++++- .../03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json | 9 ++++++--- .../03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json | 9 ++++++--- .../03/GHSA-r389-8fhp-frgf/GHSA-r389-8fhp-frgf.json | 11 +++++++---- .../03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json | 2 +- .../03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json | 9 ++++++--- .../03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json | 2 +- .../03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json | 11 +++++++---- .../03/GHSA-vhqq-r65q-2hff/GHSA-vhqq-r65q-2hff.json | 9 ++++++--- .../03/GHSA-w25q-j7hc-27j8/GHSA-w25q-j7hc-27j8.json | 9 ++++++--- .../03/GHSA-wrfj-mm2v-57mh/GHSA-wrfj-mm2v-57mh.json | 11 +++++++---- .../03/GHSA-x4jx-mwq9-xjr3/GHSA-x4jx-mwq9-xjr3.json | 11 +++++++---- .../03/GHSA-x7hf-f78p-hvvc/GHSA-x7hf-f78p-hvvc.json | 11 +++++++---- .../03/GHSA-xh22-rmr9-74w8/GHSA-xh22-rmr9-74w8.json | 2 +- .../03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json | 11 +++++++---- .../04/GHSA-c8x3-xmj9-whgh/GHSA-c8x3-xmj9-whgh.json | 11 +++++++---- .../04/GHSA-h3cj-5xfx-mg9x/GHSA-h3cj-5xfx-mg9x.json | 11 +++++++---- .../04/GHSA-m288-f8h5-gxr4/GHSA-m288-f8h5-gxr4.json | 11 +++++++---- .../04/GHSA-rcfx-wqqr-5v82/GHSA-rcfx-wqqr-5v82.json | 11 +++++++---- 100 files changed, 372 insertions(+), 209 deletions(-) diff --git a/advisories/unreviewed/2022/03/GHSA-65jp-cf4c-rcq6/GHSA-65jp-cf4c-rcq6.json b/advisories/unreviewed/2022/03/GHSA-65jp-cf4c-rcq6/GHSA-65jp-cf4c-rcq6.json index d33e342daa5..e8d3e7faeec 100644 --- a/advisories/unreviewed/2022/03/GHSA-65jp-cf4c-rcq6/GHSA-65jp-cf4c-rcq6.json +++ b/advisories/unreviewed/2022/03/GHSA-65jp-cf4c-rcq6/GHSA-65jp-cf4c-rcq6.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-25r9-gpg2-xcwf/GHSA-25r9-gpg2-xcwf.json b/advisories/unreviewed/2022/05/GHSA-25r9-gpg2-xcwf/GHSA-25r9-gpg2-xcwf.json index 7b89121b135..cf75d2b182e 100644 --- a/advisories/unreviewed/2022/05/GHSA-25r9-gpg2-xcwf/GHSA-25r9-gpg2-xcwf.json +++ b/advisories/unreviewed/2022/05/GHSA-25r9-gpg2-xcwf/GHSA-25r9-gpg2-xcwf.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json b/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json index 2c1343aaf0b..961ff8550ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json +++ b/advisories/unreviewed/2022/05/GHSA-44qp-5pm8-6j8p/GHSA-44qp-5pm8-6j8p.json @@ -68,7 +68,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-80" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4grg-84cr-6c2h/GHSA-4grg-84cr-6c2h.json b/advisories/unreviewed/2022/05/GHSA-4grg-84cr-6c2h/GHSA-4grg-84cr-6c2h.json index 9c8abf36338..83c8393e076 100644 --- a/advisories/unreviewed/2022/05/GHSA-4grg-84cr-6c2h/GHSA-4grg-84cr-6c2h.json +++ b/advisories/unreviewed/2022/05/GHSA-4grg-84cr-6c2h/GHSA-4grg-84cr-6c2h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-497" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-57g4-6x5r-c4qc/GHSA-57g4-6x5r-c4qc.json b/advisories/unreviewed/2022/05/GHSA-57g4-6x5r-c4qc/GHSA-57g4-6x5r-c4qc.json index 8d1b9666147..0b474092e70 100644 --- a/advisories/unreviewed/2022/05/GHSA-57g4-6x5r-c4qc/GHSA-57g4-6x5r-c4qc.json +++ b/advisories/unreviewed/2022/05/GHSA-57g4-6x5r-c4qc/GHSA-57g4-6x5r-c4qc.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-311" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json b/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json index 71e8f7c389e..4bf35bca329 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json +++ b/advisories/unreviewed/2022/05/GHSA-7hr6-j3qm-7p23/GHSA-7hr6-j3qm-7p23.json @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-7pcp-8fjh-246q/GHSA-7pcp-8fjh-246q.json b/advisories/unreviewed/2022/05/GHSA-7pcp-8fjh-246q/GHSA-7pcp-8fjh-246q.json index 29ca8c38823..1f63608974d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7pcp-8fjh-246q/GHSA-7pcp-8fjh-246q.json +++ b/advisories/unreviewed/2022/05/GHSA-7pcp-8fjh-246q/GHSA-7pcp-8fjh-246q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pcp-8fjh-246q", - "modified": "2022-06-04T00:00:33Z", + "modified": "2024-07-03T18:32:18Z", "published": "2022-05-24T17:31:37Z", "aliases": [ "CVE-2020-14871" @@ -44,6 +44,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/03/03/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/03/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-cx5r-6jgc-m635/GHSA-cx5r-6jgc-m635.json b/advisories/unreviewed/2022/05/GHSA-cx5r-6jgc-m635/GHSA-cx5r-6jgc-m635.json index e35b60f7e3a..7bae5153fa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-cx5r-6jgc-m635/GHSA-cx5r-6jgc-m635.json +++ b/advisories/unreviewed/2022/05/GHSA-cx5r-6jgc-m635/GHSA-cx5r-6jgc-m635.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx5r-6jgc-m635", - "modified": "2024-03-21T03:34:04Z", + "modified": "2024-07-03T18:32:28Z", "published": "2022-05-24T22:28:34Z", "aliases": [ "CVE-2021-26928" diff --git a/advisories/unreviewed/2022/05/GHSA-fvpv-m998-g6f8/GHSA-fvpv-m998-g6f8.json b/advisories/unreviewed/2022/05/GHSA-fvpv-m998-g6f8/GHSA-fvpv-m998-g6f8.json index d580856be25..aa9c0731131 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvpv-m998-g6f8/GHSA-fvpv-m998-g6f8.json +++ b/advisories/unreviewed/2022/05/GHSA-fvpv-m998-g6f8/GHSA-fvpv-m998-g6f8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvpv-m998-g6f8", - "modified": "2022-05-24T17:08:07Z", + "modified": "2024-07-03T18:32:08Z", "published": "2022-05-24T17:08:07Z", "aliases": [ "CVE-2016-7524" ], "details": "coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-jc6g-whc6-qfj3/GHSA-jc6g-whc6-qfj3.json b/advisories/unreviewed/2022/05/GHSA-jc6g-whc6-qfj3/GHSA-jc6g-whc6-qfj3.json index f604f7d2a6f..fd42a27acf2 100644 --- a/advisories/unreviewed/2022/05/GHSA-jc6g-whc6-qfj3/GHSA-jc6g-whc6-qfj3.json +++ b/advisories/unreviewed/2022/05/GHSA-jc6g-whc6-qfj3/GHSA-jc6g-whc6-qfj3.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-jcmg-8grx-m8j6/GHSA-jcmg-8grx-m8j6.json b/advisories/unreviewed/2022/05/GHSA-jcmg-8grx-m8j6/GHSA-jcmg-8grx-m8j6.json index a1dc40de538..988a2bef9b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-jcmg-8grx-m8j6/GHSA-jcmg-8grx-m8j6.json +++ b/advisories/unreviewed/2022/05/GHSA-jcmg-8grx-m8j6/GHSA-jcmg-8grx-m8j6.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-150", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-jj88-6656-w759/GHSA-jj88-6656-w759.json b/advisories/unreviewed/2022/05/GHSA-jj88-6656-w759/GHSA-jj88-6656-w759.json index 61369b602ab..b2c5a2ff24b 100644 --- a/advisories/unreviewed/2022/05/GHSA-jj88-6656-w759/GHSA-jj88-6656-w759.json +++ b/advisories/unreviewed/2022/05/GHSA-jj88-6656-w759/GHSA-jj88-6656-w759.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj88-6656-w759", - "modified": "2023-08-02T00:30:38Z", + "modified": "2024-07-03T18:32:33Z", "published": "2022-05-24T19:17:28Z", "aliases": [ "CVE-2021-41345" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-q7w5-cq9g-vhw8/GHSA-q7w5-cq9g-vhw8.json b/advisories/unreviewed/2022/05/GHSA-q7w5-cq9g-vhw8/GHSA-q7w5-cq9g-vhw8.json index b6856a4fc4a..6a624de3f5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7w5-cq9g-vhw8/GHSA-q7w5-cq9g-vhw8.json +++ b/advisories/unreviewed/2022/05/GHSA-q7w5-cq9g-vhw8/GHSA-q7w5-cq9g-vhw8.json @@ -100,6 +100,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-w39r-2vjm-hgjq/GHSA-w39r-2vjm-hgjq.json b/advisories/unreviewed/2022/05/GHSA-w39r-2vjm-hgjq/GHSA-w39r-2vjm-hgjq.json index 929fe432f6d..06ac0802bec 100644 --- a/advisories/unreviewed/2022/05/GHSA-w39r-2vjm-hgjq/GHSA-w39r-2vjm-hgjq.json +++ b/advisories/unreviewed/2022/05/GHSA-w39r-2vjm-hgjq/GHSA-w39r-2vjm-hgjq.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w458-qg9w-x8vm/GHSA-w458-qg9w-x8vm.json b/advisories/unreviewed/2022/05/GHSA-w458-qg9w-x8vm/GHSA-w458-qg9w-x8vm.json index 35201bb0328..c556e07d891 100644 --- a/advisories/unreviewed/2022/05/GHSA-w458-qg9w-x8vm/GHSA-w458-qg9w-x8vm.json +++ b/advisories/unreviewed/2022/05/GHSA-w458-qg9w-x8vm/GHSA-w458-qg9w-x8vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w458-qg9w-x8vm", - "modified": "2023-08-02T00:30:33Z", + "modified": "2024-07-03T18:32:28Z", "published": "2022-05-24T19:04:48Z", "aliases": [ "CVE-2021-31954" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-7mrh-jrcg-wc76/GHSA-7mrh-jrcg-wc76.json b/advisories/unreviewed/2022/09/GHSA-7mrh-jrcg-wc76/GHSA-7mrh-jrcg-wc76.json index 542518d3790..057bacba97b 100644 --- a/advisories/unreviewed/2022/09/GHSA-7mrh-jrcg-wc76/GHSA-7mrh-jrcg-wc76.json +++ b/advisories/unreviewed/2022/09/GHSA-7mrh-jrcg-wc76/GHSA-7mrh-jrcg-wc76.json @@ -68,6 +68,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-613", "CWE-74" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-hr8v-98c3-7p3x/GHSA-hr8v-98c3-7p3x.json b/advisories/unreviewed/2022/09/GHSA-hr8v-98c3-7p3x/GHSA-hr8v-98c3-7p3x.json index 9c93b864dc5..dd7b16f584e 100644 --- a/advisories/unreviewed/2022/09/GHSA-hr8v-98c3-7p3x/GHSA-hr8v-98c3-7p3x.json +++ b/advisories/unreviewed/2022/09/GHSA-hr8v-98c3-7p3x/GHSA-hr8v-98c3-7p3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr8v-98c3-7p3x", - "modified": "2022-09-10T00:00:29Z", + "modified": "2024-07-03T18:32:41Z", "published": "2022-09-06T00:00:27Z", "aliases": [ "CVE-2022-31814" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31814" }, + { + "type": "WEB", + "url": "https://github.com/pfsense/FreeBSD-ports/pull/1169" + }, + { + "type": "WEB", + "url": "https://github.com/pfsense/FreeBSD-ports/pull/1169/commits/071bdcf2d918c3e51cde11cf81fbd9b6f0379d7e" + }, { "type": "WEB", "url": "https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html" @@ -40,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-c7rr-4vvg-c7r2/GHSA-c7rr-4vvg-c7r2.json b/advisories/unreviewed/2022/11/GHSA-c7rr-4vvg-c7r2/GHSA-c7rr-4vvg-c7r2.json index e1bbb5d6f7c..cc3b799d593 100644 --- a/advisories/unreviewed/2022/11/GHSA-c7rr-4vvg-c7r2/GHSA-c7rr-4vvg-c7r2.json +++ b/advisories/unreviewed/2022/11/GHSA-c7rr-4vvg-c7r2/GHSA-c7rr-4vvg-c7r2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-f594-4w5v-rpf5/GHSA-f594-4w5v-rpf5.json b/advisories/unreviewed/2022/11/GHSA-f594-4w5v-rpf5/GHSA-f594-4w5v-rpf5.json index bed8a321b1d..6d2fc6b1af5 100644 --- a/advisories/unreviewed/2022/11/GHSA-f594-4w5v-rpf5/GHSA-f594-4w5v-rpf5.json +++ b/advisories/unreviewed/2022/11/GHSA-f594-4w5v-rpf5/GHSA-f594-4w5v-rpf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f594-4w5v-rpf5", - "modified": "2022-11-17T06:30:19Z", + "modified": "2024-07-03T18:32:47Z", "published": "2022-11-16T12:00:22Z", "aliases": [ "CVE-2022-43279" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43279" }, + { + "type": "WEB", + "url": "https://github.com/LimeSurvey/LimeSurvey/commit/42920389f99cdd25449eb7ace57f24417e83b692" + }, { "type": "WEB", "url": "https://brick-pamphlet-d24.notion.site/LimeSurvey-V5-4-4-background-update-php-SQL-injection-50e8fd6eba4644bb941b2c8d6fb7979a" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-89" + "CWE-89", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-2cqm-w497-9r99/GHSA-2cqm-w497-9r99.json b/advisories/unreviewed/2023/01/GHSA-2cqm-w497-9r99/GHSA-2cqm-w497-9r99.json index 21e062553c0..0c9be0513f6 100644 --- a/advisories/unreviewed/2023/01/GHSA-2cqm-w497-9r99/GHSA-2cqm-w497-9r99.json +++ b/advisories/unreviewed/2023/01/GHSA-2cqm-w497-9r99/GHSA-2cqm-w497-9r99.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-5jrg-vf8f-2h5c/GHSA-5jrg-vf8f-2h5c.json b/advisories/unreviewed/2023/01/GHSA-5jrg-vf8f-2h5c/GHSA-5jrg-vf8f-2h5c.json index eabeac878b2..7af08c083ce 100644 --- a/advisories/unreviewed/2023/01/GHSA-5jrg-vf8f-2h5c/GHSA-5jrg-vf8f-2h5c.json +++ b/advisories/unreviewed/2023/01/GHSA-5jrg-vf8f-2h5c/GHSA-5jrg-vf8f-2h5c.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-m82c-5hpw-48f7/GHSA-m82c-5hpw-48f7.json b/advisories/unreviewed/2023/07/GHSA-m82c-5hpw-48f7/GHSA-m82c-5hpw-48f7.json index f6d8006cbb0..eda3beb2950 100644 --- a/advisories/unreviewed/2023/07/GHSA-m82c-5hpw-48f7/GHSA-m82c-5hpw-48f7.json +++ b/advisories/unreviewed/2023/07/GHSA-m82c-5hpw-48f7/GHSA-m82c-5hpw-48f7.json @@ -60,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-924" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json b/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json index 63d82eb74a8..950f375c3b9 100644 --- a/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json +++ b/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7r4-77g3-vcrx", - "modified": "2023-12-21T03:30:32Z", + "modified": "2024-07-03T18:32:53Z", "published": "2023-07-06T19:24:09Z", "aliases": [ "CVE-2023-22934" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-108", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json index 2e56e2de476..364f960f89e 100644 --- a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json +++ b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-897q-36v3-jwhm", - "modified": "2024-02-08T00:32:18Z", + "modified": "2024-07-03T18:33:01Z", "published": "2023-08-03T18:30:35Z", "aliases": [ "CVE-2023-4132" diff --git a/advisories/unreviewed/2023/08/GHSA-9ww7-xcfq-fwj7/GHSA-9ww7-xcfq-fwj7.json b/advisories/unreviewed/2023/08/GHSA-9ww7-xcfq-fwj7/GHSA-9ww7-xcfq-fwj7.json index 7b6e2159f2b..633f9ddcc23 100644 --- a/advisories/unreviewed/2023/08/GHSA-9ww7-xcfq-fwj7/GHSA-9ww7-xcfq-fwj7.json +++ b/advisories/unreviewed/2023/08/GHSA-9ww7-xcfq-fwj7/GHSA-9ww7-xcfq-fwj7.json @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-w5x7-vwr2-4x27/GHSA-w5x7-vwr2-4x27.json b/advisories/unreviewed/2023/08/GHSA-w5x7-vwr2-4x27/GHSA-w5x7-vwr2-4x27.json index 85bdafd4b04..9e95bddf8cd 100644 --- a/advisories/unreviewed/2023/08/GHSA-w5x7-vwr2-4x27/GHSA-w5x7-vwr2-4x27.json +++ b/advisories/unreviewed/2023/08/GHSA-w5x7-vwr2-4x27/GHSA-w5x7-vwr2-4x27.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-351" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-6wp3-hhxh-4vfp/GHSA-6wp3-hhxh-4vfp.json b/advisories/unreviewed/2023/09/GHSA-6wp3-hhxh-4vfp/GHSA-6wp3-hhxh-4vfp.json index 96aa2d862a5..c812b4f8c51 100644 --- a/advisories/unreviewed/2023/09/GHSA-6wp3-hhxh-4vfp/GHSA-6wp3-hhxh-4vfp.json +++ b/advisories/unreviewed/2023/09/GHSA-6wp3-hhxh-4vfp/GHSA-6wp3-hhxh-4vfp.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-87j2-5g9j-7jmv/GHSA-87j2-5g9j-7jmv.json b/advisories/unreviewed/2023/10/GHSA-87j2-5g9j-7jmv/GHSA-87j2-5g9j-7jmv.json index 4c15ee9d6d8..685995b2bbe 100644 --- a/advisories/unreviewed/2023/10/GHSA-87j2-5g9j-7jmv/GHSA-87j2-5g9j-7jmv.json +++ b/advisories/unreviewed/2023/10/GHSA-87j2-5g9j-7jmv/GHSA-87j2-5g9j-7jmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87j2-5g9j-7jmv", - "modified": "2024-01-23T03:31:07Z", + "modified": "2024-07-03T18:33:10Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-34048" diff --git a/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json b/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json index c2359433ccf..5de0b6d23b3 100644 --- a/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json +++ b/advisories/unreviewed/2023/10/GHSA-cjgx-jx6j-cmg7/GHSA-cjgx-jx6j-cmg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjgx-jx6j-cmg7", - "modified": "2024-04-04T08:43:11Z", + "modified": "2024-07-03T18:33:10Z", "published": "2023-10-17T15:30:27Z", "aliases": [ "CVE-2023-20598" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json b/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json index 319df735b53..1d7c5a4f03a 100644 --- a/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json +++ b/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-x3vv-qh4r-crf2/GHSA-x3vv-qh4r-crf2.json b/advisories/unreviewed/2023/10/GHSA-x3vv-qh4r-crf2/GHSA-x3vv-qh4r-crf2.json index de453f46e10..1a44ce8e150 100644 --- a/advisories/unreviewed/2023/10/GHSA-x3vv-qh4r-crf2/GHSA-x3vv-qh4r-crf2.json +++ b/advisories/unreviewed/2023/10/GHSA-x3vv-qh4r-crf2/GHSA-x3vv-qh4r-crf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3vv-qh4r-crf2", - "modified": "2023-11-01T18:30:32Z", + "modified": "2024-07-03T18:33:12Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46316" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-234" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-8rh4-mxhq-673g/GHSA-8rh4-mxhq-673g.json b/advisories/unreviewed/2023/11/GHSA-8rh4-mxhq-673g/GHSA-8rh4-mxhq-673g.json index b13ad509972..43e44c629fd 100644 --- a/advisories/unreviewed/2023/11/GHSA-8rh4-mxhq-673g/GHSA-8rh4-mxhq-673g.json +++ b/advisories/unreviewed/2023/11/GHSA-8rh4-mxhq-673g/GHSA-8rh4-mxhq-673g.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json b/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json index c2becf7fa97..4bf6f68c6a7 100644 --- a/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json +++ b/advisories/unreviewed/2023/11/GHSA-98jh-839r-xp86/GHSA-98jh-839r-xp86.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-401" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json b/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json index 5405531e69e..75fa0cbf4be 100644 --- a/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json +++ b/advisories/unreviewed/2023/12/GHSA-r64h-95wm-rrfq/GHSA-r64h-95wm-rrfq.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-4pvg-f3m8-ff3j/GHSA-4pvg-f3m8-ff3j.json b/advisories/unreviewed/2024/01/GHSA-4pvg-f3m8-ff3j/GHSA-4pvg-f3m8-ff3j.json index c62a168c0be..ec01a4245bc 100644 --- a/advisories/unreviewed/2024/01/GHSA-4pvg-f3m8-ff3j/GHSA-4pvg-f3m8-ff3j.json +++ b/advisories/unreviewed/2024/01/GHSA-4pvg-f3m8-ff3j/GHSA-4pvg-f3m8-ff3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4pvg-f3m8-ff3j", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-07-03T18:33:21Z", "published": "2024-01-17T00:30:19Z", "aliases": [ "CVE-2024-0518" diff --git a/advisories/unreviewed/2024/01/GHSA-8fmw-7mxc-55jq/GHSA-8fmw-7mxc-55jq.json b/advisories/unreviewed/2024/01/GHSA-8fmw-7mxc-55jq/GHSA-8fmw-7mxc-55jq.json index 5812b6317b8..c8c22b2b0dc 100644 --- a/advisories/unreviewed/2024/01/GHSA-8fmw-7mxc-55jq/GHSA-8fmw-7mxc-55jq.json +++ b/advisories/unreviewed/2024/01/GHSA-8fmw-7mxc-55jq/GHSA-8fmw-7mxc-55jq.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-286" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json b/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json index 0ea9fb1bd95..04abb764254 100644 --- a/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json +++ b/advisories/unreviewed/2024/01/GHSA-983x-5446-qc2q/GHSA-983x-5446-qc2q.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json b/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json index 9051f3c543a..a78623bc6d3 100644 --- a/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json +++ b/advisories/unreviewed/2024/01/GHSA-9m57-xv2x-rj9v/GHSA-9m57-xv2x-rj9v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m57-xv2x-rj9v", - "modified": "2024-02-05T21:30:31Z", + "modified": "2024-07-03T18:33:23Z", "published": "2024-01-31T00:30:18Z", "aliases": [ "CVE-2024-1077" diff --git a/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json b/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json index 4a92f3f3fca..cf80ce91fa7 100644 --- a/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json +++ b/advisories/unreviewed/2024/01/GHSA-gvqj-cjp6-grrv/GHSA-gvqj-cjp6-grrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvqj-cjp6-grrv", - "modified": "2024-01-31T15:30:19Z", + "modified": "2024-07-03T18:33:23Z", "published": "2024-01-23T21:30:21Z", "aliases": [ "CVE-2023-52338" diff --git a/advisories/unreviewed/2024/01/GHSA-vg6w-jr5m-86c8/GHSA-vg6w-jr5m-86c8.json b/advisories/unreviewed/2024/01/GHSA-vg6w-jr5m-86c8/GHSA-vg6w-jr5m-86c8.json index c1d6c270c7b..ac8832ee34a 100644 --- a/advisories/unreviewed/2024/01/GHSA-vg6w-jr5m-86c8/GHSA-vg6w-jr5m-86c8.json +++ b/advisories/unreviewed/2024/01/GHSA-vg6w-jr5m-86c8/GHSA-vg6w-jr5m-86c8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vg6w-jr5m-86c8", - "modified": "2024-01-22T21:31:07Z", + "modified": "2024-07-03T18:33:21Z", "published": "2024-01-17T00:30:19Z", "aliases": [ "CVE-2024-0519" @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json b/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json index 52090ad4a5a..772611df485 100644 --- a/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json +++ b/advisories/unreviewed/2024/01/GHSA-w64x-j9r3-q79q/GHSA-w64x-j9r3-q79q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w64x-j9r3-q79q", - "modified": "2024-01-26T18:30:32Z", + "modified": "2024-07-03T18:33:20Z", "published": "2024-01-16T06:30:31Z", "aliases": [ "CVE-2023-22527" diff --git a/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json b/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json index c01d0bf3f0b..efd8780daa9 100644 --- a/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json +++ b/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-24rh-qhmv-p8j2", - "modified": "2024-06-07T09:30:45Z", + "modified": "2024-07-03T18:33:25Z", "published": "2024-02-02T15:30:28Z", "aliases": [ "CVE-2024-0253" diff --git a/advisories/unreviewed/2024/02/GHSA-2x93-8973-5mgq/GHSA-2x93-8973-5mgq.json b/advisories/unreviewed/2024/02/GHSA-2x93-8973-5mgq/GHSA-2x93-8973-5mgq.json index 0b18f08f16d..ad407660872 100644 --- a/advisories/unreviewed/2024/02/GHSA-2x93-8973-5mgq/GHSA-2x93-8973-5mgq.json +++ b/advisories/unreviewed/2024/02/GHSA-2x93-8973-5mgq/GHSA-2x93-8973-5mgq.json @@ -92,6 +92,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json b/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json index 99f54b497e1..00140421ca1 100644 --- a/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json +++ b/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3rpv-j58g-7jfj", - "modified": "2024-06-07T09:30:45Z", + "modified": "2024-07-03T18:33:25Z", "published": "2024-02-02T15:30:28Z", "aliases": [ "CVE-2024-0269" diff --git a/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json b/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json index 75584430a6f..8fdea4b60d2 100644 --- a/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json +++ b/advisories/unreviewed/2024/02/GHSA-6hrp-c93c-rq8p/GHSA-6hrp-c93c-rq8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hrp-c93c-rq8p", - "modified": "2024-02-08T21:30:34Z", + "modified": "2024-07-03T18:33:24Z", "published": "2024-02-01T09:30:18Z", "aliases": [ "CVE-2024-24548" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json b/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json index 1a954fa6d74..31ccb2ccd6a 100644 --- a/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json +++ b/advisories/unreviewed/2024/02/GHSA-73g2-fg3c-4vx6/GHSA-73g2-fg3c-4vx6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json b/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json index 1ebbaa6f65a..f0cffef3f99 100644 --- a/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json +++ b/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m48-vw34-vw84", - "modified": "2024-04-19T09:30:47Z", + "modified": "2024-07-03T18:33:34Z", "published": "2024-02-19T06:30:33Z", "aliases": [ "CVE-2024-26327" ], "details": "An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-19T05:15:22Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json b/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json index cc818b6caf7..90e2cb96563 100644 --- a/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json +++ b/advisories/unreviewed/2024/02/GHSA-8mxm-4gjm-vrc7/GHSA-8mxm-4gjm-vrc7.json @@ -44,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-789" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json b/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json index 09cea7f084a..9cecf0c37fb 100644 --- a/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json +++ b/advisories/unreviewed/2024/02/GHSA-c6gq-r463-842g/GHSA-c6gq-r463-842g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c6gq-r463-842g", - "modified": "2024-02-18T06:30:31Z", + "modified": "2024-07-03T18:33:29Z", "published": "2024-02-18T06:30:31Z", "aliases": [ "CVE-2023-52367" ], "details": "Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T04:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json b/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json index d2ae34ebad1..fa688794047 100644 --- a/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json +++ b/advisories/unreviewed/2024/02/GHSA-j6qm-xgxc-g34g/GHSA-j6qm-xgxc-g34g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-305" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pprj-563h-jxf6/GHSA-pprj-563h-jxf6.json b/advisories/unreviewed/2024/02/GHSA-pprj-563h-jxf6/GHSA-pprj-563h-jxf6.json index 4e889314f9e..7d8539b1574 100644 --- a/advisories/unreviewed/2024/02/GHSA-pprj-563h-jxf6/GHSA-pprj-563h-jxf6.json +++ b/advisories/unreviewed/2024/02/GHSA-pprj-563h-jxf6/GHSA-pprj-563h-jxf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pprj-563h-jxf6", - "modified": "2024-02-22T03:30:35Z", + "modified": "2024-07-03T18:33:34Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-25423" ], "details": "An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T01:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pwq2-c6f6-f36f/GHSA-pwq2-c6f6-f36f.json b/advisories/unreviewed/2024/02/GHSA-pwq2-c6f6-f36f/GHSA-pwq2-c6f6-f36f.json index 66fcf0d47a7..94b64de556e 100644 --- a/advisories/unreviewed/2024/02/GHSA-pwq2-c6f6-f36f/GHSA-pwq2-c6f6-f36f.json +++ b/advisories/unreviewed/2024/02/GHSA-pwq2-c6f6-f36f/GHSA-pwq2-c6f6-f36f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-280" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-vxv3-wgx2-xx92/GHSA-vxv3-wgx2-xx92.json b/advisories/unreviewed/2024/02/GHSA-vxv3-wgx2-xx92/GHSA-vxv3-wgx2-xx92.json index 20debffa647..18d4c2eefe9 100644 --- a/advisories/unreviewed/2024/02/GHSA-vxv3-wgx2-xx92/GHSA-vxv3-wgx2-xx92.json +++ b/advisories/unreviewed/2024/02/GHSA-vxv3-wgx2-xx92/GHSA-vxv3-wgx2-xx92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vxv3-wgx2-xx92", - "modified": "2024-02-12T18:31:07Z", + "modified": "2024-07-03T18:33:28Z", "published": "2024-02-12T18:31:07Z", "aliases": [ "CVE-2023-6082" ], "details": "The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-12T16:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json b/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json index 6b619205bb7..487d7ce7f32 100644 --- a/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json +++ b/advisories/unreviewed/2024/02/GHSA-x547-pm2q-2cr6/GHSA-x547-pm2q-2cr6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-250" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-2cp7-qpvm-rw54/GHSA-2cp7-qpvm-rw54.json b/advisories/unreviewed/2024/03/GHSA-2cp7-qpvm-rw54/GHSA-2cp7-qpvm-rw54.json index eb7962e7bf8..4023e824b50 100644 --- a/advisories/unreviewed/2024/03/GHSA-2cp7-qpvm-rw54/GHSA-2cp7-qpvm-rw54.json +++ b/advisories/unreviewed/2024/03/GHSA-2cp7-qpvm-rw54/GHSA-2cp7-qpvm-rw54.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-2pm2-cpjx-462g/GHSA-2pm2-cpjx-462g.json b/advisories/unreviewed/2024/03/GHSA-2pm2-cpjx-462g/GHSA-2pm2-cpjx-462g.json index 94d8fb032dd..3f58ee5730e 100644 --- a/advisories/unreviewed/2024/03/GHSA-2pm2-cpjx-462g/GHSA-2pm2-cpjx-462g.json +++ b/advisories/unreviewed/2024/03/GHSA-2pm2-cpjx-462g/GHSA-2pm2-cpjx-462g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pm2-cpjx-462g", - "modified": "2024-03-14T15:34:06Z", + "modified": "2024-07-03T18:33:45Z", "published": "2024-03-14T15:34:06Z", "aliases": [ "CVE-2024-28417" ], "details": "Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T13:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2rpq-p6fh-7mx6/GHSA-2rpq-p6fh-7mx6.json b/advisories/unreviewed/2024/03/GHSA-2rpq-p6fh-7mx6/GHSA-2rpq-p6fh-7mx6.json index d3878d3c00d..262ae2c5b49 100644 --- a/advisories/unreviewed/2024/03/GHSA-2rpq-p6fh-7mx6/GHSA-2rpq-p6fh-7mx6.json +++ b/advisories/unreviewed/2024/03/GHSA-2rpq-p6fh-7mx6/GHSA-2rpq-p6fh-7mx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2rpq-p6fh-7mx6", - "modified": "2024-03-03T09:30:38Z", + "modified": "2024-07-03T18:33:35Z", "published": "2024-03-03T09:30:38Z", "aliases": [ "CVE-2024-24302" ], "details": "An issue was discovered in Tunis Soft \"Product Designer\" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the postProcess() method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-03T09:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json b/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json index 999b4e5e849..3cbc6225e3c 100644 --- a/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json +++ b/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qv4-jm22-wqx7", - "modified": "2024-03-21T18:32:03Z", + "modified": "2024-07-03T18:33:48Z", "published": "2024-03-21T18:32:03Z", "aliases": [ "CVE-2024-29916" ], "details": "The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the \"Unsaflok\" issue. This occurs, in part, because the key derivation function relies only on a UID. This affects, for example, Saflok MT, and the Confidant, Quantum, RT, and Saffire series.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-407" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T17:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-57pr-424c-2xfr/GHSA-57pr-424c-2xfr.json b/advisories/unreviewed/2024/03/GHSA-57pr-424c-2xfr/GHSA-57pr-424c-2xfr.json index e699cfb4c47..9d881cad476 100644 --- a/advisories/unreviewed/2024/03/GHSA-57pr-424c-2xfr/GHSA-57pr-424c-2xfr.json +++ b/advisories/unreviewed/2024/03/GHSA-57pr-424c-2xfr/GHSA-57pr-424c-2xfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57pr-424c-2xfr", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-07-03T18:33:47Z", "published": "2024-03-21T12:31:56Z", "aliases": [ "CVE-2024-26307" ], "details": "Possible race condition vulnerability in Apache Doris.\nSome of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file.\nThis could theoretically happen, but the impact would be minimal.\nThis issue affects Apache Doris: before 1.2.8, before 2.0.4.\n\nUsers are recommended to upgrade to version 2.0.4, which fixes the issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T10:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json b/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json index 3bd453c4fd2..e9844c096d8 100644 --- a/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json +++ b/advisories/unreviewed/2024/03/GHSA-5hrr-2wgf-37hj/GHSA-5hrr-2wgf-37hj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hrr-2wgf-37hj", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-07-03T18:33:46Z", "published": "2024-03-20T15:32:38Z", "aliases": [ "CVE-2024-28562" ], "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::copyIntoFrameBuffer() component when reading images in EXR format.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T06:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json b/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json index 8429960d628..deabfbfe6b8 100644 --- a/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json +++ b/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pj4-f8gh-j3mr", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-07-03T18:33:49Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2886" ], "details": "Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T21:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json b/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json index 1c9d6b468dd..65d23da5e30 100644 --- a/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json +++ b/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5w42-fg4v-hv3r", - "modified": "2024-03-28T06:30:45Z", + "modified": "2024-07-03T18:33:54Z", "published": "2024-03-28T06:30:45Z", "aliases": [ "CVE-2024-0672" ], "details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T05:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6c2g-6j82-6fjx/GHSA-6c2g-6j82-6fjx.json b/advisories/unreviewed/2024/03/GHSA-6c2g-6j82-6fjx/GHSA-6c2g-6j82-6fjx.json index b5600188ba8..5bce5f380a1 100644 --- a/advisories/unreviewed/2024/03/GHSA-6c2g-6j82-6fjx/GHSA-6c2g-6j82-6fjx.json +++ b/advisories/unreviewed/2024/03/GHSA-6c2g-6j82-6fjx/GHSA-6c2g-6j82-6fjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6c2g-6j82-6fjx", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-07-03T18:33:49Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25389" ], "details": "RT-Thread through 5.0.2 generates random numbers with a weak algorithm of \"seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;\" in calc_random in drivers/misc/rt_random.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-338" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json b/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json index c547d98f0c7..85dfe793ffe 100644 --- a/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json +++ b/advisories/unreviewed/2024/03/GHSA-6h48-8w2f-5w94/GHSA-6h48-8w2f-5w94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6h48-8w2f-5w94", - "modified": "2024-04-20T00:31:52Z", + "modified": "2024-07-03T18:33:58Z", "published": "2024-03-29T06:30:30Z", "aliases": [ "CVE-2024-28960" ], "details": "An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T06:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6hhg-hj7x-7qv8/GHSA-6hhg-hj7x-7qv8.json b/advisories/unreviewed/2024/03/GHSA-6hhg-hj7x-7qv8/GHSA-6hhg-hj7x-7qv8.json index 0cdc9dae778..1e3ebc287d1 100644 --- a/advisories/unreviewed/2024/03/GHSA-6hhg-hj7x-7qv8/GHSA-6hhg-hj7x-7qv8.json +++ b/advisories/unreviewed/2024/03/GHSA-6hhg-hj7x-7qv8/GHSA-6hhg-hj7x-7qv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hhg-hj7x-7qv8", - "modified": "2024-03-23T03:30:24Z", + "modified": "2024-07-03T18:33:40Z", "published": "2024-03-06T21:31:34Z", "aliases": [ "CVE-2024-2173" ], "details": "Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T19:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-849m-v6gh-gmf9/GHSA-849m-v6gh-gmf9.json b/advisories/unreviewed/2024/03/GHSA-849m-v6gh-gmf9/GHSA-849m-v6gh-gmf9.json index e3cf3cbd59b..c0364d6164d 100644 --- a/advisories/unreviewed/2024/03/GHSA-849m-v6gh-gmf9/GHSA-849m-v6gh-gmf9.json +++ b/advisories/unreviewed/2024/03/GHSA-849m-v6gh-gmf9/GHSA-849m-v6gh-gmf9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-96hc-g58p-3pq7/GHSA-96hc-g58p-3pq7.json b/advisories/unreviewed/2024/03/GHSA-96hc-g58p-3pq7/GHSA-96hc-g58p-3pq7.json index 6c71a2e0fca..78cbba97792 100644 --- a/advisories/unreviewed/2024/03/GHSA-96hc-g58p-3pq7/GHSA-96hc-g58p-3pq7.json +++ b/advisories/unreviewed/2024/03/GHSA-96hc-g58p-3pq7/GHSA-96hc-g58p-3pq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96hc-g58p-3pq7", - "modified": "2024-03-28T21:30:31Z", + "modified": "2024-07-03T18:33:55Z", "published": "2024-03-28T21:30:31Z", "aliases": [ "CVE-2024-31062" ], "details": "Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json b/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json index a6080e5bcd5..a60692f60b0 100644 --- a/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json +++ b/advisories/unreviewed/2024/03/GHSA-97xx-95pm-5qv6/GHSA-97xx-95pm-5qv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97xx-95pm-5qv6", - "modified": "2024-06-10T18:30:53Z", + "modified": "2024-07-03T18:33:53Z", "published": "2024-03-27T09:30:41Z", "aliases": [ "CVE-2024-2004" ], "details": "When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T08:15:41Z" diff --git a/advisories/unreviewed/2024/03/GHSA-99gp-rqx5-272f/GHSA-99gp-rqx5-272f.json b/advisories/unreviewed/2024/03/GHSA-99gp-rqx5-272f/GHSA-99gp-rqx5-272f.json index e52e7fa70f4..398fa6675a3 100644 --- a/advisories/unreviewed/2024/03/GHSA-99gp-rqx5-272f/GHSA-99gp-rqx5-272f.json +++ b/advisories/unreviewed/2024/03/GHSA-99gp-rqx5-272f/GHSA-99gp-rqx5-272f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99gp-rqx5-272f", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-07-03T18:33:38Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20028" ], "details": "In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541687.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9crf-rxmh-772m/GHSA-9crf-rxmh-772m.json b/advisories/unreviewed/2024/03/GHSA-9crf-rxmh-772m/GHSA-9crf-rxmh-772m.json index 73bfa6c05f5..af06955431d 100644 --- a/advisories/unreviewed/2024/03/GHSA-9crf-rxmh-772m/GHSA-9crf-rxmh-772m.json +++ b/advisories/unreviewed/2024/03/GHSA-9crf-rxmh-772m/GHSA-9crf-rxmh-772m.json @@ -45,7 +45,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-680" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-cv2q-pmfm-5c4f/GHSA-cv2q-pmfm-5c4f.json b/advisories/unreviewed/2024/03/GHSA-cv2q-pmfm-5c4f/GHSA-cv2q-pmfm-5c4f.json index 162d7724cb1..ebb1e0e3135 100644 --- a/advisories/unreviewed/2024/03/GHSA-cv2q-pmfm-5c4f/GHSA-cv2q-pmfm-5c4f.json +++ b/advisories/unreviewed/2024/03/GHSA-cv2q-pmfm-5c4f/GHSA-cv2q-pmfm-5c4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv2q-pmfm-5c4f", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-07-03T18:33:38Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20024" ], "details": "In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541635; Issue ID: ALPS08541635.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json b/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json index 9ff87d9188e..abd2a9b277e 100644 --- a/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json +++ b/advisories/unreviewed/2024/03/GHSA-fw8f-f5ww-mpr8/GHSA-fw8f-f5ww-mpr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fw8f-f5ww-mpr8", - "modified": "2024-03-29T15:30:32Z", + "modified": "2024-07-03T18:33:58Z", "published": "2024-03-29T15:30:32Z", "aliases": [ "CVE-2024-30637" ], "details": "Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T14:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g92w-952h-vqrj/GHSA-g92w-952h-vqrj.json b/advisories/unreviewed/2024/03/GHSA-g92w-952h-vqrj/GHSA-g92w-952h-vqrj.json index b2d90b1bf3c..26e3d6ea331 100644 --- a/advisories/unreviewed/2024/03/GHSA-g92w-952h-vqrj/GHSA-g92w-952h-vqrj.json +++ b/advisories/unreviewed/2024/03/GHSA-g92w-952h-vqrj/GHSA-g92w-952h-vqrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g92w-952h-vqrj", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-07-03T18:33:50Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25395" ], "details": "A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json b/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json index 11b40501419..559abf56ad0 100644 --- a/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json +++ b/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gg9c-7j6m-3qq2", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-07-03T18:33:49Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2883" ], "details": "Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T21:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gr8x-42gf-wmh7/GHSA-gr8x-42gf-wmh7.json b/advisories/unreviewed/2024/03/GHSA-gr8x-42gf-wmh7/GHSA-gr8x-42gf-wmh7.json index 59748895591..07c02d7ab60 100644 --- a/advisories/unreviewed/2024/03/GHSA-gr8x-42gf-wmh7/GHSA-gr8x-42gf-wmh7.json +++ b/advisories/unreviewed/2024/03/GHSA-gr8x-42gf-wmh7/GHSA-gr8x-42gf-wmh7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr8x-42gf-wmh7", - "modified": "2024-07-02T09:32:05Z", + "modified": "2024-07-03T18:33:50Z", "published": "2024-03-27T06:30:32Z", "aliases": [ "CVE-2023-45924" ], "details": "libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T05:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json b/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json index 44d44f92aea..f4c288b7cd0 100644 --- a/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json +++ b/advisories/unreviewed/2024/03/GHSA-gvf4-7544-2wh5/GHSA-gvf4-7544-2wh5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvf4-7544-2wh5", - "modified": "2024-03-29T15:30:29Z", + "modified": "2024-07-03T18:33:58Z", "published": "2024-03-29T15:30:29Z", "aliases": [ "CVE-2024-30623" ], "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h62m-673x-763w/GHSA-h62m-673x-763w.json b/advisories/unreviewed/2024/03/GHSA-h62m-673x-763w/GHSA-h62m-673x-763w.json index 159d33e3300..7450f8c6764 100644 --- a/advisories/unreviewed/2024/03/GHSA-h62m-673x-763w/GHSA-h62m-673x-763w.json +++ b/advisories/unreviewed/2024/03/GHSA-h62m-673x-763w/GHSA-h62m-673x-763w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-mq3q-f49j-4fjg/GHSA-mq3q-f49j-4fjg.json b/advisories/unreviewed/2024/03/GHSA-mq3q-f49j-4fjg/GHSA-mq3q-f49j-4fjg.json index ea6df36730a..90dd7589d96 100644 --- a/advisories/unreviewed/2024/03/GHSA-mq3q-f49j-4fjg/GHSA-mq3q-f49j-4fjg.json +++ b/advisories/unreviewed/2024/03/GHSA-mq3q-f49j-4fjg/GHSA-mq3q-f49j-4fjg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq3q-f49j-4fjg", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-07-03T18:33:50Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25393" ], "details": "A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mq8w-c2j9-rqxc/GHSA-mq8w-c2j9-rqxc.json b/advisories/unreviewed/2024/03/GHSA-mq8w-c2j9-rqxc/GHSA-mq8w-c2j9-rqxc.json index e65def8dd0c..7400eec34be 100644 --- a/advisories/unreviewed/2024/03/GHSA-mq8w-c2j9-rqxc/GHSA-mq8w-c2j9-rqxc.json +++ b/advisories/unreviewed/2024/03/GHSA-mq8w-c2j9-rqxc/GHSA-mq8w-c2j9-rqxc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq8w-c2j9-rqxc", - "modified": "2024-05-03T15:30:36Z", + "modified": "2024-07-03T18:33:54Z", "published": "2024-03-27T09:30:41Z", "aliases": [ "CVE-2024-2398" ], "details": "When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T08:15:41Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pp4p-q324-qhgr/GHSA-pp4p-q324-qhgr.json b/advisories/unreviewed/2024/03/GHSA-pp4p-q324-qhgr/GHSA-pp4p-q324-qhgr.json index 9941a34e800..c222841310f 100644 --- a/advisories/unreviewed/2024/03/GHSA-pp4p-q324-qhgr/GHSA-pp4p-q324-qhgr.json +++ b/advisories/unreviewed/2024/03/GHSA-pp4p-q324-qhgr/GHSA-pp4p-q324-qhgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pp4p-q324-qhgr", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-07-03T18:33:38Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20034" ], "details": "In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q22h-9rc9-jpmp/GHSA-q22h-9rc9-jpmp.json b/advisories/unreviewed/2024/03/GHSA-q22h-9rc9-jpmp/GHSA-q22h-9rc9-jpmp.json index 12ce4f6def7..49a526531d2 100644 --- a/advisories/unreviewed/2024/03/GHSA-q22h-9rc9-jpmp/GHSA-q22h-9rc9-jpmp.json +++ b/advisories/unreviewed/2024/03/GHSA-q22h-9rc9-jpmp/GHSA-q22h-9rc9-jpmp.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json b/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json index 884688ca40c..fbe5ff145a2 100644 --- a/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json +++ b/advisories/unreviewed/2024/03/GHSA-q63v-rwfp-q5p2/GHSA-q63v-rwfp-q5p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q63v-rwfp-q5p2", - "modified": "2024-04-28T06:31:25Z", + "modified": "2024-07-03T18:33:40Z", "published": "2024-03-07T12:30:26Z", "aliases": [ "CVE-2024-1931" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RBR4H7RCVMJ6H76S4LLRSY5EBFTYWGXK" }, + { + "type": "WEB", + "url": "https://lists.freebsd.org/archives/freebsd-security/2024-July/000283.html" + }, { "type": "WEB", "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-1931.txt" diff --git a/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json b/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json index 26e2c07b417..bbdefd4da67 100644 --- a/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json +++ b/advisories/unreviewed/2024/03/GHSA-q75f-2pp5-9phj/GHSA-q75f-2pp5-9phj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q75f-2pp5-9phj", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-07-03T18:33:49Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2887" ], "details": "Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T21:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json b/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json index 2482ce28b8f..f59f3cd6ca9 100644 --- a/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json +++ b/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qccw-wmvp-8pv9", - "modified": "2024-03-29T06:30:30Z", + "modified": "2024-07-03T18:33:49Z", "published": "2024-03-26T21:30:48Z", "aliases": [ "CVE-2024-2885" ], "details": "Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T21:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r389-8fhp-frgf/GHSA-r389-8fhp-frgf.json b/advisories/unreviewed/2024/03/GHSA-r389-8fhp-frgf/GHSA-r389-8fhp-frgf.json index 20df27ef511..e4966c1ed31 100644 --- a/advisories/unreviewed/2024/03/GHSA-r389-8fhp-frgf/GHSA-r389-8fhp-frgf.json +++ b/advisories/unreviewed/2024/03/GHSA-r389-8fhp-frgf/GHSA-r389-8fhp-frgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r389-8fhp-frgf", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-07-03T18:33:40Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23246" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. An app may be able to break out of its sandbox.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json b/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json index d84f9af506f..1b1cc736208 100644 --- a/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json +++ b/advisories/unreviewed/2024/03/GHSA-r9x8-r5r4-mq7c/GHSA-r9x8-r5r4-mq7c.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-280" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json b/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json index a5205c36356..1c5b8a3c837 100644 --- a/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json +++ b/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rrmx-g79h-w4q7", - "modified": "2024-03-28T03:30:59Z", + "modified": "2024-07-03T18:33:54Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-28010" ], "details": "Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary OS command via the internet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-259" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json b/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json index ce8ccc762ec..7a4729d2c79 100644 --- a/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json +++ b/advisories/unreviewed/2024/03/GHSA-vcq2-59g4-9rm6/GHSA-vcq2-59g4-9rm6.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json b/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json index 014f08ecdc9..458497a3f65 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json +++ b/advisories/unreviewed/2024/03/GHSA-vhg5-jp6p-2pcw/GHSA-vhg5-jp6p-2pcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhg5-jp6p-2pcw", - "modified": "2024-05-01T18:30:36Z", + "modified": "2024-07-03T18:33:46Z", "published": "2024-03-20T15:32:38Z", "aliases": [ "CVE-2024-28563" ], "details": "Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the Imf_2_2::DwaCompressor::Classifier::Classifier() function when reading images in EXR format.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T06:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vhqq-r65q-2hff/GHSA-vhqq-r65q-2hff.json b/advisories/unreviewed/2024/03/GHSA-vhqq-r65q-2hff/GHSA-vhqq-r65q-2hff.json index 231f1c32cdf..8dcaddcc22c 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhqq-r65q-2hff/GHSA-vhqq-r65q-2hff.json +++ b/advisories/unreviewed/2024/03/GHSA-vhqq-r65q-2hff/GHSA-vhqq-r65q-2hff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhqq-r65q-2hff", - "modified": "2024-03-14T06:32:00Z", + "modified": "2024-07-03T18:33:44Z", "published": "2024-03-14T06:32:00Z", "aliases": [ "CVE-2024-22396" ], "details": "An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w25q-j7hc-27j8/GHSA-w25q-j7hc-27j8.json b/advisories/unreviewed/2024/03/GHSA-w25q-j7hc-27j8/GHSA-w25q-j7hc-27j8.json index 7bc8de83cf4..0ceeacfb01e 100644 --- a/advisories/unreviewed/2024/03/GHSA-w25q-j7hc-27j8/GHSA-w25q-j7hc-27j8.json +++ b/advisories/unreviewed/2024/03/GHSA-w25q-j7hc-27j8/GHSA-w25q-j7hc-27j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w25q-j7hc-27j8", - "modified": "2024-03-28T00:31:41Z", + "modified": "2024-07-03T18:33:54Z", "published": "2024-03-28T00:31:41Z", "aliases": [ "CVE-2024-0980" ], "details": "The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T00:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wrfj-mm2v-57mh/GHSA-wrfj-mm2v-57mh.json b/advisories/unreviewed/2024/03/GHSA-wrfj-mm2v-57mh/GHSA-wrfj-mm2v-57mh.json index 44416f0cfe7..2441e4923fa 100644 --- a/advisories/unreviewed/2024/03/GHSA-wrfj-mm2v-57mh/GHSA-wrfj-mm2v-57mh.json +++ b/advisories/unreviewed/2024/03/GHSA-wrfj-mm2v-57mh/GHSA-wrfj-mm2v-57mh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrfj-mm2v-57mh", - "modified": "2024-04-25T21:30:29Z", + "modified": "2024-07-03T18:33:46Z", "published": "2024-03-19T15:30:32Z", "aliases": [ "CVE-2024-28734" ], "details": "Cross Site Scripting vulnerability in Unit4 Financials by Coda v.2024Q1 allows a remote attacker to escalate privileges via a crafted script to the cols parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T14:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x4jx-mwq9-xjr3/GHSA-x4jx-mwq9-xjr3.json b/advisories/unreviewed/2024/03/GHSA-x4jx-mwq9-xjr3/GHSA-x4jx-mwq9-xjr3.json index 56e9c0ae263..070a014d4bf 100644 --- a/advisories/unreviewed/2024/03/GHSA-x4jx-mwq9-xjr3/GHSA-x4jx-mwq9-xjr3.json +++ b/advisories/unreviewed/2024/03/GHSA-x4jx-mwq9-xjr3/GHSA-x4jx-mwq9-xjr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4jx-mwq9-xjr3", - "modified": "2024-06-07T15:30:34Z", + "modified": "2024-07-03T18:33:47Z", "published": "2024-03-21T03:36:46Z", "aliases": [ "CVE-2024-24520" ], "details": "An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:52:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x7hf-f78p-hvvc/GHSA-x7hf-f78p-hvvc.json b/advisories/unreviewed/2024/03/GHSA-x7hf-f78p-hvvc/GHSA-x7hf-f78p-hvvc.json index 0e159ee256c..dc2c0a643c6 100644 --- a/advisories/unreviewed/2024/03/GHSA-x7hf-f78p-hvvc/GHSA-x7hf-f78p-hvvc.json +++ b/advisories/unreviewed/2024/03/GHSA-x7hf-f78p-hvvc/GHSA-x7hf-f78p-hvvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7hf-f78p-hvvc", - "modified": "2024-05-01T18:30:37Z", + "modified": "2024-07-03T18:33:49Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25392" ], "details": "An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xh22-rmr9-74w8/GHSA-xh22-rmr9-74w8.json b/advisories/unreviewed/2024/03/GHSA-xh22-rmr9-74w8/GHSA-xh22-rmr9-74w8.json index e4207ef680c..9291e1274e8 100644 --- a/advisories/unreviewed/2024/03/GHSA-xh22-rmr9-74w8/GHSA-xh22-rmr9-74w8.json +++ b/advisories/unreviewed/2024/03/GHSA-xh22-rmr9-74w8/GHSA-xh22-rmr9-74w8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json b/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json index 1d6224859d9..02f1913da37 100644 --- a/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json +++ b/advisories/unreviewed/2024/03/GHSA-xrrw-7rr2-829v/GHSA-xrrw-7rr2-829v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrrw-7rr2-829v", - "modified": "2024-05-07T06:30:35Z", + "modified": "2024-07-03T18:33:44Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23263" ], "details": "A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -89,9 +92,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c8x3-xmj9-whgh/GHSA-c8x3-xmj9-whgh.json b/advisories/unreviewed/2024/04/GHSA-c8x3-xmj9-whgh/GHSA-c8x3-xmj9-whgh.json index 35e4f8261db..3d1cb673b3f 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8x3-xmj9-whgh/GHSA-c8x3-xmj9-whgh.json +++ b/advisories/unreviewed/2024/04/GHSA-c8x3-xmj9-whgh/GHSA-c8x3-xmj9-whgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8x3-xmj9-whgh", - "modified": "2024-04-01T03:30:40Z", + "modified": "2024-07-03T18:34:01Z", "published": "2024-04-01T03:30:40Z", "aliases": [ "CVE-2024-20046" ], "details": "In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue ID: ALPS08485622.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h3cj-5xfx-mg9x/GHSA-h3cj-5xfx-mg9x.json b/advisories/unreviewed/2024/04/GHSA-h3cj-5xfx-mg9x/GHSA-h3cj-5xfx-mg9x.json index 68411040275..dd5a501fceb 100644 --- a/advisories/unreviewed/2024/04/GHSA-h3cj-5xfx-mg9x/GHSA-h3cj-5xfx-mg9x.json +++ b/advisories/unreviewed/2024/04/GHSA-h3cj-5xfx-mg9x/GHSA-h3cj-5xfx-mg9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3cj-5xfx-mg9x", - "modified": "2024-04-01T03:30:40Z", + "modified": "2024-07-03T18:34:00Z", "published": "2024-04-01T03:30:40Z", "aliases": [ "CVE-2024-20042" ], "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: ALPS08541780.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m288-f8h5-gxr4/GHSA-m288-f8h5-gxr4.json b/advisories/unreviewed/2024/04/GHSA-m288-f8h5-gxr4/GHSA-m288-f8h5-gxr4.json index 8a06f41e6d7..067c015978c 100644 --- a/advisories/unreviewed/2024/04/GHSA-m288-f8h5-gxr4/GHSA-m288-f8h5-gxr4.json +++ b/advisories/unreviewed/2024/04/GHSA-m288-f8h5-gxr4/GHSA-m288-f8h5-gxr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m288-f8h5-gxr4", - "modified": "2024-04-01T03:30:40Z", + "modified": "2024-07-03T18:34:00Z", "published": "2024-04-01T03:30:40Z", "aliases": [ "CVE-2024-20041" ], "details": "In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541746; Issue ID: ALPS08541746.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rcfx-wqqr-5v82/GHSA-rcfx-wqqr-5v82.json b/advisories/unreviewed/2024/04/GHSA-rcfx-wqqr-5v82/GHSA-rcfx-wqqr-5v82.json index 9054883218d..c3a9488f30d 100644 --- a/advisories/unreviewed/2024/04/GHSA-rcfx-wqqr-5v82/GHSA-rcfx-wqqr-5v82.json +++ b/advisories/unreviewed/2024/04/GHSA-rcfx-wqqr-5v82/GHSA-rcfx-wqqr-5v82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcfx-wqqr-5v82", - "modified": "2024-04-01T03:30:40Z", + "modified": "2024-07-03T18:34:00Z", "published": "2024-04-01T03:30:40Z", "aliases": [ "CVE-2024-20044" ], "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS08541784.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z"