From d1eb249816c9d202ec8bebb8b8492689d1049b8e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Jun 2024 03:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jhj7-p3xq-vh37.json | 14 ++++++- .../GHSA-pxv8-29mc-xx76.json | 8 +++- .../GHSA-23h8-4q9g-xc4f.json | 6 ++- .../GHSA-4rqc-6cwc-8fr7.json | 6 ++- .../GHSA-533q-6g64-xmc7.json | 6 ++- .../GHSA-f9p5-24wv-w5qx.json | 6 ++- .../GHSA-fgcf-ch4w-m3f6.json | 6 ++- .../GHSA-fr4j-vgg6-426q.json | 6 ++- .../GHSA-hf32-jrph-5wp2.json | 6 ++- .../GHSA-r553-v847-23pr.json | 6 ++- .../GHSA-354c-38ff-3cw6.json | 35 ++++++++++++++++ .../GHSA-37hm-8cwf-jp7f.json | 35 ++++++++++++++++ .../GHSA-3x3g-7ggq-rm95.json | 35 ++++++++++++++++ .../GHSA-4w8c-j9fj-jw7x.json | 35 ++++++++++++++++ .../GHSA-568c-mgmg-28q2.json | 35 ++++++++++++++++ .../GHSA-628q-5gqp-mr86.json | 42 +++++++++++++++++++ .../GHSA-6xv6-j448-ffr5.json | 35 ++++++++++++++++ .../GHSA-7w58-2c67-8xhv.json | 35 ++++++++++++++++ .../GHSA-84g5-5pmf-46fw.json | 35 ++++++++++++++++ .../GHSA-95c3-qh99-cvf2.json | 35 ++++++++++++++++ .../GHSA-cv9m-q4c9-4vr9.json | 42 +++++++++++++++++++ .../GHSA-ffcq-3472-r63j.json | 35 ++++++++++++++++ .../GHSA-gwgm-rvh4-63c2.json | 35 ++++++++++++++++ .../GHSA-mv7f-hqh8-jwpv.json | 35 ++++++++++++++++ .../GHSA-q2gr-59x6-9fh4.json | 35 ++++++++++++++++ .../GHSA-r94p-w2wf-q9c9.json | 35 ++++++++++++++++ .../GHSA-w3q4-wghg-w5gc.json | 38 +++++++++++++++++ .../GHSA-xjph-r444-9j84.json | 38 +++++++++++++++++ 28 files changed, 709 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json create mode 100644 advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json create mode 100644 advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json create mode 100644 advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json create mode 100644 advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json create mode 100644 advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json create mode 100644 advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json create mode 100644 advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json create mode 100644 advisories/unreviewed/2024/06/GHSA-95c3-qh99-cvf2/GHSA-95c3-qh99-cvf2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json create mode 100644 advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json create mode 100644 advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json create mode 100644 advisories/unreviewed/2024/06/GHSA-w3q4-wghg-w5gc/GHSA-w3q4-wghg-w5gc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-xjph-r444-9j84/GHSA-xjph-r444-9j84.json diff --git a/advisories/unreviewed/2022/05/GHSA-jhj7-p3xq-vh37/GHSA-jhj7-p3xq-vh37.json b/advisories/unreviewed/2022/05/GHSA-jhj7-p3xq-vh37/GHSA-jhj7-p3xq-vh37.json index 5d1c64b5bec..2eace9149a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhj7-p3xq-vh37/GHSA-jhj7-p3xq-vh37.json +++ b/advisories/unreviewed/2022/05/GHSA-jhj7-p3xq-vh37/GHSA-jhj7-p3xq-vh37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhj7-p3xq-vh37", - "modified": "2023-01-30T21:30:22Z", + "modified": "2024-06-25T03:31:06Z", "published": "2022-05-24T17:03:13Z", "aliases": [ "CVE-2019-14861" @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/05/msg00023.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PJH3ROOFYMOATD2UEPC47P5RPBDTY77E" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNKA4YIPV7AZR7KK3GW6L3HKGHSGJZFE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJH3ROOFYMOATD2UEPC47P5RPBDTY77E" @@ -64,6 +72,10 @@ { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00038.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/06/24/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-pxv8-29mc-xx76/GHSA-pxv8-29mc-xx76.json b/advisories/unreviewed/2023/11/GHSA-pxv8-29mc-xx76/GHSA-pxv8-29mc-xx76.json index 9526fa87332..b272d958c08 100644 --- a/advisories/unreviewed/2023/11/GHSA-pxv8-29mc-xx76/GHSA-pxv8-29mc-xx76.json +++ b/advisories/unreviewed/2023/11/GHSA-pxv8-29mc-xx76/GHSA-pxv8-29mc-xx76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxv8-29mc-xx76", - "modified": "2023-11-13T09:30:25Z", + "modified": "2024-06-25T03:31:06Z", "published": "2023-11-13T09:30:25Z", "aliases": [ "CVE-2023-5037" @@ -17,11 +17,15 @@ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5037" + }, + { + "type": "WEB", + "url": "https://www.hanwhavision.com/wp-content/uploads/2024/06/Camera-Vulnerability-Report-CVE-2023-5037-5038.pdf" } ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json b/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json index b648a693000..b1e7dfc56f1 100644 --- a/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json +++ b/advisories/unreviewed/2024/02/GHSA-23h8-4q9g-xc4f/GHSA-23h8-4q9g-xc4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23h8-4q9g-xc4f", - "modified": "2024-03-18T00:30:43Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23131" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json b/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json index e78378ba12a..abd9862f11a 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json +++ b/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rqc-6cwc-8fr7", - "modified": "2024-03-18T00:30:42Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T03:30:36Z", "aliases": [ "CVE-2024-23127" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json b/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json index fc2df4cec65..84b658fc6bb 100644 --- a/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json +++ b/advisories/unreviewed/2024/02/GHSA-533q-6g64-xmc7/GHSA-533q-6g64-xmc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-533q-6g64-xmc7", - "modified": "2024-03-18T00:30:43Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23129" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json b/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json index b5cedee68e2..399a2149cf6 100644 --- a/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json +++ b/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f9p5-24wv-w5qx", - "modified": "2024-03-13T03:31:06Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23122" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json b/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json index 235cf64b339..eb5380d362d 100644 --- a/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json +++ b/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgcf-ch4w-m3f6", - "modified": "2024-03-13T03:31:06Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23123" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json b/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json index 955221ceacb..221e55a0bec 100644 --- a/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json +++ b/advisories/unreviewed/2024/02/GHSA-fr4j-vgg6-426q/GHSA-fr4j-vgg6-426q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr4j-vgg6-426q", - "modified": "2024-03-18T00:30:43Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23130" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-hf32-jrph-5wp2/GHSA-hf32-jrph-5wp2.json b/advisories/unreviewed/2024/02/GHSA-hf32-jrph-5wp2/GHSA-hf32-jrph-5wp2.json index 5bdc05d45c9..27a35dc6b17 100644 --- a/advisories/unreviewed/2024/02/GHSA-hf32-jrph-5wp2/GHSA-hf32-jrph-5wp2.json +++ b/advisories/unreviewed/2024/02/GHSA-hf32-jrph-5wp2/GHSA-hf32-jrph-5wp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hf32-jrph-5wp2", - "modified": "2024-03-18T00:30:42Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T06:30:32Z", "aliases": [ "CVE-2024-23128" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json b/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json index 3656f1e78a2..c70678cc5c5 100644 --- a/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json +++ b/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r553-v847-23pr", - "modified": "2024-03-18T00:30:43Z", + "modified": "2024-06-25T03:31:06Z", "published": "2024-02-22T06:30:33Z", "aliases": [ "CVE-2024-23137" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json b/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json new file mode 100644 index 00000000000..bcb09d580c6 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-354c-38ff-3cw6/GHSA-354c-38ff-3cw6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-354c-38ff-3cw6", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-37002" + ], + "details": "A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37002" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json b/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json new file mode 100644 index 00000000000..3b835ce8e28 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-37hm-8cwf-jp7f/GHSA-37hm-8cwf-jp7f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37hm-8cwf-jp7f", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-37001" + ], + "details": "[A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37001" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json b/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json new file mode 100644 index 00000000000..1014ced9ca8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-3x3g-7ggq-rm95/GHSA-3x3g-7ggq-rm95.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3g-7ggq-rm95", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23144" + ], + "details": "A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk applications, can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23144" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json b/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json new file mode 100644 index 00000000000..791a9d60902 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4w8c-j9fj-jw7x/GHSA-4w8c-j9fj-jw7x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w8c-j9fj-jw7x", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23143" + ], + "details": "A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23143" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json b/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json new file mode 100644 index 00000000000..41f39503b7f --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-568c-mgmg-28q2/GHSA-568c-mgmg-28q2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-568c-mgmg-28q2", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23146" + ], + "details": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23146" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json b/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json new file mode 100644 index 00000000000..bab7a45fd64 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-628q-5gqp-mr86/GHSA-628q-5gqp-mr86.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-628q-5gqp-mr86", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-6295" + ], + "details": "udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6295" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7895-80dac-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7894-aebd8-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json b/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json new file mode 100644 index 00000000000..38253329f50 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-6xv6-j448-ffr5/GHSA-6xv6-j448-ffr5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xv6-j448-ffr5", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23142" + ], + "details": "A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23142" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json b/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json new file mode 100644 index 00000000000..a896ec740f9 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7w58-2c67-8xhv/GHSA-7w58-2c67-8xhv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w58-2c67-8xhv", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23148" + ], + "details": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23148" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json b/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json new file mode 100644 index 00000000000..a6644f9134e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84g5-5pmf-46fw", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23149" + ], + "details": "A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23149" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-95c3-qh99-cvf2/GHSA-95c3-qh99-cvf2.json b/advisories/unreviewed/2024/06/GHSA-95c3-qh99-cvf2/GHSA-95c3-qh99-cvf2.json new file mode 100644 index 00000000000..00be3b5258a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-95c3-qh99-cvf2/GHSA-95c3-qh99-cvf2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95c3-qh99-cvf2", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2023-5038" + ], + "details": "badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5038" + }, + { + "type": "WEB", + "url": "https://www.hanwhavision.com/wp-content/uploads/2024/06/Camera-Vulnerability-Report-CVE-2023-5037-5038.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json b/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json new file mode 100644 index 00000000000..7d233e6fb3a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-cv9m-q4c9-4vr9/GHSA-cv9m-q4c9-4vr9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv9m-q4c9-4vr9", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-6294" + ], + "details": "udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6294" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-7893-43ecd-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7892-aafd2-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json b/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json new file mode 100644 index 00000000000..b1b58335341 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-ffcq-3472-r63j/GHSA-ffcq-3472-r63j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffcq-3472-r63j", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23141" + ], + "details": "A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23141" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json b/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json new file mode 100644 index 00000000000..462f0dad1f4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-gwgm-rvh4-63c2/GHSA-gwgm-rvh4-63c2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwgm-rvh4-63c2", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23147" + ], + "details": "A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23147" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json b/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json new file mode 100644 index 00000000000..79a2d636d57 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mv7f-hqh8-jwpv/GHSA-mv7f-hqh8-jwpv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv7f-hqh8-jwpv", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23145" + ], + "details": "A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23145" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json b/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json new file mode 100644 index 00000000000..1aa175e6dfc --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-q2gr-59x6-9fh4/GHSA-q2gr-59x6-9fh4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2gr-59x6-9fh4", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-23140" + ], + "details": "A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23140" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json b/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json new file mode 100644 index 00000000000..9a143211733 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-r94p-w2wf-q9c9/GHSA-r94p-w2wf-q9c9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r94p-w2wf-q9c9", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:07Z", + "aliases": [ + "CVE-2024-37000" + ], + "details": "A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37000" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-w3q4-wghg-w5gc/GHSA-w3q4-wghg-w5gc.json b/advisories/unreviewed/2024/06/GHSA-w3q4-wghg-w5gc/GHSA-w3q4-wghg-w5gc.json new file mode 100644 index 00000000000..78275883e4e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-w3q4-wghg-w5gc/GHSA-w3q4-wghg-w5gc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3q4-wghg-w5gc", + "modified": "2024-06-25T03:31:06Z", + "published": "2024-06-25T03:31:06Z", + "aliases": [ + "CVE-2023-6198" + ], + "details": "Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6198" + }, + { + "type": "WEB", + "url": "https://www.baicells.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-xjph-r444-9j84/GHSA-xjph-r444-9j84.json b/advisories/unreviewed/2024/06/GHSA-xjph-r444-9j84/GHSA-xjph-r444-9j84.json new file mode 100644 index 00000000000..065feabd3d4 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-xjph-r444-9j84/GHSA-xjph-r444-9j84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjph-r444-9j84", + "modified": "2024-06-25T03:31:07Z", + "published": "2024-06-25T03:31:06Z", + "aliases": [ + "CVE-2024-22385" + ], + "details": "Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22385" + }, + { + "type": "WEB", + "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2024-129/index.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T02:15:10Z" + } +} \ No newline at end of file