diff --git a/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json b/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json index a3db1009835..6fc0b99d8ae 100644 --- a/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json +++ b/advisories/github-reviewed/2024/03/GHSA-7w75-32cg-r6g2/GHSA-7w75-32cg-r6g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w75-32cg-r6g2", - "modified": "2024-03-15T16:27:54Z", + "modified": "2024-04-03T00:30:55Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-24549" @@ -217,6 +217,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240402-0002" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json b/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json index 04f3ba4a7af..3775b7ba990 100644 --- a/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json +++ b/advisories/github-reviewed/2024/03/GHSA-v682-8vv8-vpwr/GHSA-v682-8vv8-vpwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v682-8vv8-vpwr", - "modified": "2024-03-14T14:04:04Z", + "modified": "2024-04-03T00:30:54Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-23672" @@ -129,6 +129,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240402-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json index cf48f4b9da2..28d230d0e4d 100644 --- a/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json +++ b/advisories/unreviewed/2023/12/GHSA-v727-f437-6cxx/GHSA-v727-f437-6cxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v727-f437-6cxx", - "modified": "2024-04-02T21:30:27Z", + "modified": "2024-04-03T00:30:54Z", "published": "2023-12-21T21:30:31Z", "aliases": [ "CVE-2023-6546" @@ -65,6 +65,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1612" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1614" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6546" diff --git a/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json b/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json index fe403650558..a09ac964a89 100644 --- a/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json +++ b/advisories/unreviewed/2024/01/GHSA-4jrv-6m77-vrhq/GHSA-4jrv-6m77-vrhq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jrv-6m77-vrhq", - "modified": "2024-04-02T21:30:27Z", + "modified": "2024-04-03T00:30:54Z", "published": "2024-01-15T21:30:24Z", "aliases": [ "CVE-2024-0565" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1607" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1614" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-0565" diff --git a/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json b/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json index 027a7a24dff..898d795e5d2 100644 --- a/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json +++ b/advisories/unreviewed/2024/03/GHSA-fg9q-5cw2-p6r9/GHSA-fg9q-5cw2-p6r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fg9q-5cw2-p6r9", - "modified": "2024-03-07T21:30:21Z", + "modified": "2024-04-03T00:30:54Z", "published": "2024-03-07T21:30:21Z", "aliases": [ "CVE-2024-1725" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1725" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1559" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1725" diff --git a/advisories/unreviewed/2024/04/GHSA-39jw-2mcp-w35j/GHSA-39jw-2mcp-w35j.json b/advisories/unreviewed/2024/04/GHSA-39jw-2mcp-w35j/GHSA-39jw-2mcp-w35j.json new file mode 100644 index 00000000000..2ed5bc78eea --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-39jw-2mcp-w35j/GHSA-39jw-2mcp-w35j.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39jw-2mcp-w35j", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:56Z", + "aliases": [ + "CVE-2024-3221" + ], + "details": "A vulnerability classified as critical was found in SourceCodester PHP Task Management System 1.0. This vulnerability affects unknown code of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259066 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3221" + }, + { + "type": "WEB", + "url": "https://github.com/SLthendieck/cve-report/blob/main/1.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259066" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259066" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308626" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5jm7-9q58-m675/GHSA-5jm7-9q58-m675.json b/advisories/unreviewed/2024/04/GHSA-5jm7-9q58-m675/GHSA-5jm7-9q58-m675.json new file mode 100644 index 00000000000..94686869bcc --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5jm7-9q58-m675/GHSA-5jm7-9q58-m675.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jm7-9q58-m675", + "modified": "2024-04-03T00:30:55Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-3202" + ], + "details": "A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-259049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3202" + }, + { + "type": "WEB", + "url": "https://github.com/lcg-22266/cms/blob/main/2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259049" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259049" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303941" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7jjc-f4w2-6g7w/GHSA-7jjc-f4w2-6g7w.json b/advisories/unreviewed/2024/04/GHSA-7jjc-f4w2-6g7w/GHSA-7jjc-f4w2-6g7w.json new file mode 100644 index 00000000000..99dd619a89f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7jjc-f4w2-6g7w/GHSA-7jjc-f4w2-6g7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jjc-f4w2-6g7w", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:56Z", + "aliases": [ + "CVE-2024-3248" + ], + "details": "In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3248" + }, + { + "type": "WEB", + "url": "https://forum.xpdfreader.com/viewtopic.php?t=43657" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T23:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json b/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json new file mode 100644 index 00000000000..693107edad6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-97xg-px2h-jvxp/GHSA-97xg-px2h-jvxp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97xg-px2h-jvxp", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-3209" + ], + "details": "A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3209" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1qlUXvycOzGJygfkdQB9dGO6VwNRRZoih?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259055" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259055" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.304575" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T23:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-99jc-8q77-587x/GHSA-99jc-8q77-587x.json b/advisories/unreviewed/2024/04/GHSA-99jc-8q77-587x/GHSA-99jc-8q77-587x.json new file mode 100644 index 00000000000..6a2cb39f4ed --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-99jc-8q77-587x/GHSA-99jc-8q77-587x.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99jc-8q77-587x", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:56Z", + "aliases": [ + "CVE-2024-3222" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester PHP Task Management System 1.0. This issue affects some unknown processing of the file admin-password-change.php. The manipulation of the argument admin_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259067.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3222" + }, + { + "type": "WEB", + "url": "https://github.com/SLthendieck/cve-report/blob/main/2.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308627" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c38h-r4wc-m6rm/GHSA-c38h-r4wc-m6rm.json b/advisories/unreviewed/2024/04/GHSA-c38h-r4wc-m6rm/GHSA-c38h-r4wc-m6rm.json new file mode 100644 index 00000000000..3ae9dbd10a3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c38h-r4wc-m6rm/GHSA-c38h-r4wc-m6rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c38h-r4wc-m6rm", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:56Z", + "aliases": [ + "CVE-2024-3247" + ], + "details": "In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3247" + }, + { + "type": "WEB", + "url": "https://forum.xpdfreader.com/viewtopic.php?t=43597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T23:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json b/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json new file mode 100644 index 00000000000..028ed776ea3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c52r-8hmj-x4qg/GHSA-c52r-8hmj-x4qg.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c52r-8hmj-x4qg", + "modified": "2024-04-03T00:30:55Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-3204" + ], + "details": "A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259051. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3204" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.304557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c9h7-qc47-j43v/GHSA-c9h7-qc47-j43v.json b/advisories/unreviewed/2024/04/GHSA-c9h7-qc47-j43v/GHSA-c9h7-qc47-j43v.json new file mode 100644 index 00000000000..88470d7cbbf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c9h7-qc47-j43v/GHSA-c9h7-qc47-j43v.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9h7-qc47-j43v", + "modified": "2024-04-03T00:30:55Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-3205" + ], + "details": "A vulnerability was found in yaml libyaml up to 0.2.5 and classified as critical. Affected by this issue is the function yaml_emitter_emit_flow_sequence_item of the file /src/libyaml/src/emitter.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3205" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1lwNEs8wqwkUV52f3uQNYMPrxRuXPtGQs?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.304561" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T23:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json b/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json new file mode 100644 index 00000000000..6293dffc87f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh3p-6j2p-f5qv", + "modified": "2024-04-03T00:30:55Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-29434" + ], + "details": "An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29434" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Raybye/6cf4aa273e12a220056e38bec764d42d" + }, + { + "type": "WEB", + "url": "https://github.com/Raybye/alldata-bug/blob/main/alldata.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json b/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json new file mode 100644 index 00000000000..d67b9648010 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pf5m-h35j-7c4j/GHSA-pf5m-h35j-7c4j.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf5m-h35j-7c4j", + "modified": "2024-04-03T00:30:55Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-3203" + ], + "details": "A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259050 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3203" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1T1k3UeS09m65LjVXExUuZfedNQPWQWCo?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259050" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259050" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.304556" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wxj3-5cjf-39gh/GHSA-wxj3-5cjf-39gh.json b/advisories/unreviewed/2024/04/GHSA-wxj3-5cjf-39gh/GHSA-wxj3-5cjf-39gh.json new file mode 100644 index 00000000000..4393dc3a569 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wxj3-5cjf-39gh/GHSA-wxj3-5cjf-39gh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxj3-5cjf-39gh", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:56Z", + "aliases": [ + "CVE-2024-3218" + ], + "details": "A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259065 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3218" + }, + { + "type": "WEB", + "url": "https://github.com/garboa/cve_3/blob/main/file_put_content.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259065" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259065" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.308510" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-24" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-x6r6-h48x-gp8f/GHSA-x6r6-h48x-gp8f.json b/advisories/unreviewed/2024/04/GHSA-x6r6-h48x-gp8f/GHSA-x6r6-h48x-gp8f.json new file mode 100644 index 00000000000..471664010a9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-x6r6-h48x-gp8f/GHSA-x6r6-h48x-gp8f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6r6-h48x-gp8f", + "modified": "2024-04-03T00:30:56Z", + "published": "2024-04-03T00:30:55Z", + "aliases": [ + "CVE-2024-3207" + ], + "details": "A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file src/Simd/SimdMemoryStream.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. VDB-259054 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3207" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1z0JBsZ-QR3RsuAf-uyit_ZGXCh0rEvFq?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259054" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259054" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.304572" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-02T23:15:54Z" + } +} \ No newline at end of file