diff --git a/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json b/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json index 53fa0be2216..35ca1ce70ec 100644 --- a/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json +++ b/advisories/unreviewed/2021/12/GHSA-qwgg-mr66-9fcp/GHSA-qwgg-mr66-9fcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qwgg-mr66-9fcp", - "modified": "2021-12-18T00:01:48Z", + "modified": "2024-01-21T03:30:25Z", "published": "2021-12-16T00:01:38Z", "aliases": [ "CVE-2021-43675" ], "details": "Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/04/GHSA-pj56-w5gq-p5wr/GHSA-pj56-w5gq-p5wr.json b/advisories/unreviewed/2022/04/GHSA-pj56-w5gq-p5wr/GHSA-pj56-w5gq-p5wr.json index ca9958d6b6b..813f91dec1c 100644 --- a/advisories/unreviewed/2022/04/GHSA-pj56-w5gq-p5wr/GHSA-pj56-w5gq-p5wr.json +++ b/advisories/unreviewed/2022/04/GHSA-pj56-w5gq-p5wr/GHSA-pj56-w5gq-p5wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pj56-w5gq-p5wr", - "modified": "2022-04-30T18:21:02Z", + "modified": "2024-01-21T03:30:23Z", "published": "2022-04-30T18:21:02Z", "aliases": [ "CVE-2002-1372" ], "details": "Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -61,7 +64,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-252" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-24jq-h48j-g592/GHSA-24jq-h48j-g592.json b/advisories/unreviewed/2022/05/GHSA-24jq-h48j-g592/GHSA-24jq-h48j-g592.json index b13e82abe0e..926f2e93168 100644 --- a/advisories/unreviewed/2022/05/GHSA-24jq-h48j-g592/GHSA-24jq-h48j-g592.json +++ b/advisories/unreviewed/2022/05/GHSA-24jq-h48j-g592/GHSA-24jq-h48j-g592.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24jq-h48j-g592", - "modified": "2022-05-02T00:11:23Z", + "modified": "2024-01-21T03:30:23Z", "published": "2022-05-02T00:11:23Z", "aliases": [ "CVE-2008-4577" ], "details": "The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -89,7 +92,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-4532-mwp5-jccg/GHSA-4532-mwp5-jccg.json b/advisories/unreviewed/2022/05/GHSA-4532-mwp5-jccg/GHSA-4532-mwp5-jccg.json index e1ba4ff6520..d13a745c758 100644 --- a/advisories/unreviewed/2022/05/GHSA-4532-mwp5-jccg/GHSA-4532-mwp5-jccg.json +++ b/advisories/unreviewed/2022/05/GHSA-4532-mwp5-jccg/GHSA-4532-mwp5-jccg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4532-mwp5-jccg", - "modified": "2022-05-01T07:03:48Z", + "modified": "2024-01-21T03:30:23Z", "published": "2022-05-01T07:03:48Z", "aliases": [ "CVE-2006-2916" ], "details": "artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -113,7 +116,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-273" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json b/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json index 1fa943d1862..e147539d8b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json +++ b/advisories/unreviewed/2022/05/GHSA-53p3-f48x-w9j5/GHSA-53p3-f48x-w9j5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-53p3-f48x-w9j5", - "modified": "2022-05-01T02:16:18Z", + "modified": "2024-01-21T03:30:23Z", "published": "2022-05-01T02:16:18Z", "aliases": [ "CVE-2005-3274" ], "details": "Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -54,6 +57,10 @@ "type": "WEB", "url": "http://www.debian.org/security/2005/dsa-922" }, + { + "type": "WEB", + "url": "http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git%3Ba=commit%3Bh=e684f066dff5628bb61ad1912de6e8058b5b4c7d" + }, { "type": "WEB", "url": "http://www.kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=e684f066dff5628bb61ad1912de6e8058b5b4c7d" @@ -101,7 +108,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-8qp2-79w8-8586/GHSA-8qp2-79w8-8586.json b/advisories/unreviewed/2022/05/GHSA-8qp2-79w8-8586/GHSA-8qp2-79w8-8586.json index cf3eeb5e1d2..310cd4a9ff5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qp2-79w8-8586/GHSA-8qp2-79w8-8586.json +++ b/advisories/unreviewed/2022/05/GHSA-8qp2-79w8-8586/GHSA-8qp2-79w8-8586.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qp2-79w8-8586", - "modified": "2022-05-17T00:12:49Z", + "modified": "2024-01-21T03:30:25Z", "published": "2022-05-17T00:12:49Z", "aliases": [ "CVE-2012-2055" ], "details": "GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a \"mass assignment\" vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-913" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-j359-qhq6-r897/GHSA-j359-qhq6-r897.json b/advisories/unreviewed/2022/05/GHSA-j359-qhq6-r897/GHSA-j359-qhq6-r897.json index 8a9506935ee..98e7d213bc8 100644 --- a/advisories/unreviewed/2022/05/GHSA-j359-qhq6-r897/GHSA-j359-qhq6-r897.json +++ b/advisories/unreviewed/2022/05/GHSA-j359-qhq6-r897/GHSA-j359-qhq6-r897.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j359-qhq6-r897", - "modified": "2022-05-17T01:54:55Z", + "modified": "2024-01-21T03:30:24Z", "published": "2022-05-17T01:54:55Z", "aliases": [ "CVE-2011-2520" ], "details": "fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,7 +64,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-j5vc-w2jr-hw4p/GHSA-j5vc-w2jr-hw4p.json b/advisories/unreviewed/2022/05/GHSA-j5vc-w2jr-hw4p/GHSA-j5vc-w2jr-hw4p.json index fa0cf7d087b..2979079cb99 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5vc-w2jr-hw4p/GHSA-j5vc-w2jr-hw4p.json +++ b/advisories/unreviewed/2022/05/GHSA-j5vc-w2jr-hw4p/GHSA-j5vc-w2jr-hw4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5vc-w2jr-hw4p", - "modified": "2022-05-14T02:37:45Z", + "modified": "2024-01-21T03:30:24Z", "published": "2022-05-14T02:37:45Z", "aliases": [ "CVE-2008-7109" ], "details": "The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json b/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json index 969f5feb2e4..ad41d520d6a 100644 --- a/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json +++ b/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json @@ -45,7 +45,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-m9h3-f3g9-fqrf/GHSA-m9h3-f3g9-fqrf.json b/advisories/unreviewed/2022/05/GHSA-m9h3-f3g9-fqrf/GHSA-m9h3-f3g9-fqrf.json index 98538e25ddd..856de94705e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9h3-f3g9-fqrf/GHSA-m9h3-f3g9-fqrf.json +++ b/advisories/unreviewed/2022/05/GHSA-m9h3-f3g9-fqrf/GHSA-m9h3-f3g9-fqrf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9h3-f3g9-fqrf", - "modified": "2022-05-02T06:10:57Z", + "modified": "2024-01-21T03:30:24Z", "published": "2022-05-02T06:10:57Z", "aliases": [ "CVE-2010-0211" ], "details": "The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -97,7 +100,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-252" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qmxq-rh22-gxp8/GHSA-qmxq-rh22-gxp8.json b/advisories/unreviewed/2022/05/GHSA-qmxq-rh22-gxp8/GHSA-qmxq-rh22-gxp8.json index 4ef1cc58ee4..281f443358c 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmxq-rh22-gxp8/GHSA-qmxq-rh22-gxp8.json +++ b/advisories/unreviewed/2022/05/GHSA-qmxq-rh22-gxp8/GHSA-qmxq-rh22-gxp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmxq-rh22-gxp8", - "modified": "2022-05-17T01:49:38Z", + "modified": "2024-01-21T03:30:25Z", "published": "2022-05-17T01:49:38Z", "aliases": [ "CVE-2012-0911" ], "details": "TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,6 +60,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-502", "CWE-94" ], "severity": "HIGH",