From d887cdeeabdc8abd18da40a131172a1e77f56c88 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 Feb 2024 15:32:07 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2rqw-v265-jf8c.json | 6 +- .../GHSA-hq7p-j377-6v63.json | 6 +- .../GHSA-28q9-rp4x-j7g7.json | 10 ++- .../GHSA-6wfm-7hqx-39wg.json | 9 ++- .../GHSA-8wgq-vhc2-3cqc.json | 2 +- .../GHSA-9c7h-3j4x-5hw6.json | 10 ++- .../GHSA-9q6c-grq3-7prg.json | 62 +++++++++++++++++- .../GHSA-mmjc-3g2p-897m.json | 10 ++- .../GHSA-mw47-2hrx-68vv.json | 2 +- .../GHSA-qcm3-q3pj-vw39.json | 10 ++- .../GHSA-v25x-3wqw-87r9.json | 10 ++- .../GHSA-55v6-vvqw-j3qq.json | 9 ++- .../GHSA-7w42-h9j5-82q5.json | 1 + .../GHSA-8p42-r5f7-3m7g.json | 9 ++- .../GHSA-f6r7-g7pj-vhjx.json | 7 +- .../GHSA-hfr6-pxvf-frf7.json | 65 ++++++++++++++++++- .../GHSA-jhxw-fqxp-j75j.json | 10 ++- .../GHSA-m9m5-q9x5-6877.json | 9 ++- .../GHSA-mpw2-6pxv-5r2w.json | 7 +- .../GHSA-rpcf-xw9j-7c7j.json | 13 +++- .../GHSA-w3j5-qjf6-g9gf.json | 6 +- .../GHSA-x9c5-c5mj-wjjx.json | 9 ++- .../GHSA-36cr-wp3c-5h2p.json | 4 +- .../GHSA-3777-fm87-36r8.json | 4 +- .../GHSA-4w75-4x78-6882.json | 4 +- .../GHSA-72w4-56w3-7485.json | 4 +- .../GHSA-8w3x-9pj3-2gw8.json | 4 +- .../GHSA-94hm-2957-3gcc.json | 4 +- .../GHSA-g22j-4jxh-2vc7.json | 4 +- .../GHSA-gp23-w687-38gc.json | 4 +- .../GHSA-h26m-gxx2-8f39.json | 4 +- .../GHSA-h85c-f8f5-f6q9.json | 4 +- .../GHSA-hg43-j454-5m9f.json | 4 +- .../GHSA-hwqw-p9h2-q5q4.json | 4 +- .../GHSA-q53r-r56j-6vxp.json | 4 +- .../GHSA-qw3p-g4v7-86mq.json | 4 +- .../GHSA-vp9w-43wr-g8fj.json | 4 ++ .../GHSA-wf2q-fvpq-94cc.json | 4 +- .../GHSA-wwgm-wrpv-h3h4.json | 4 +- .../GHSA-rv3g-cgph-cc24.json | 4 +- .../GHSA-fcg7-9x44-gx43.json | 4 ++ .../GHSA-p4m9-r3rr-cx92.json | 8 ++- .../GHSA-w5h6-8xc7-vp2c.json | 4 +- .../GHSA-95jr-7vvp-xrg6.json | 4 ++ .../GHSA-mcx8-9rrj-7qxm.json | 4 ++ .../GHSA-x697-v25m-6phv.json | 4 ++ .../GHSA-24rh-qhmv-p8j2.json | 38 +++++++++++ .../GHSA-283h-3w9j-26xq.json | 42 ++++++++++++ .../GHSA-3rpv-j58g-7jfj.json | 38 +++++++++++ .../GHSA-42fh-xcj5-fxwg.json | 38 +++++++++++ .../GHSA-439f-fqrh-gmv2.json | 38 +++++++++++ .../GHSA-6rq5-p8rc-hp83.json | 46 +++++++++++++ .../GHSA-7mjm-4vrc-ghvc.json | 1 + .../GHSA-7pjv-fxwg-c5c3.json | 42 ++++++++++++ .../GHSA-9hch-g858-cr9j.json | 42 ++++++++++++ .../GHSA-fh42-q9qf-98jh.json | 42 ++++++++++++ .../GHSA-h66j-qwj8-p6m9.json | 42 ++++++++++++ .../GHSA-px37-v4hm-7f6q.json | 3 +- .../GHSA-q45w-f72f-v464.json | 38 +++++++++++ .../GHSA-w57g-4hpj-6p36.json | 38 +++++++++++ 60 files changed, 780 insertions(+), 90 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-283h-3w9j-26xq/GHSA-283h-3w9j-26xq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-42fh-xcj5-fxwg/GHSA-42fh-xcj5-fxwg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-439f-fqrh-gmv2/GHSA-439f-fqrh-gmv2.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6rq5-p8rc-hp83/GHSA-6rq5-p8rc-hp83.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7pjv-fxwg-c5c3/GHSA-7pjv-fxwg-c5c3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9hch-g858-cr9j/GHSA-9hch-g858-cr9j.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fh42-q9qf-98jh/GHSA-fh42-q9qf-98jh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q45w-f72f-v464/GHSA-q45w-f72f-v464.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w57g-4hpj-6p36/GHSA-w57g-4hpj-6p36.json diff --git a/advisories/github-reviewed/2021/08/GHSA-2rqw-v265-jf8c/GHSA-2rqw-v265-jf8c.json b/advisories/github-reviewed/2021/08/GHSA-2rqw-v265-jf8c/GHSA-2rqw-v265-jf8c.json index 06aedbe1ecb..b0bb3bcdc2f 100644 --- a/advisories/github-reviewed/2021/08/GHSA-2rqw-v265-jf8c/GHSA-2rqw-v265-jf8c.json +++ b/advisories/github-reviewed/2021/08/GHSA-2rqw-v265-jf8c/GHSA-2rqw-v265-jf8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rqw-v265-jf8c", - "modified": "2023-07-03T22:56:34Z", + "modified": "2024-02-02T15:30:27Z", "published": "2021-08-26T20:36:51Z", "aliases": [ "CVE-2021-22942" @@ -85,6 +85,10 @@ "type": "WEB", "url": "https://rubygems.org/gems/actionpack" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0005/" + }, { "type": "WEB", "url": "https://weblog.rubyonrails.org/2021/8/19/Rails-6-0-4-1-and-6-1-4-1-have-been-released/" diff --git a/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json b/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json index 975aff7592e..c0e0093e99c 100644 --- a/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json +++ b/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq7p-j377-6v63", - "modified": "2023-05-16T15:47:47Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-01-18T18:20:19Z", "aliases": [ "CVE-2023-22794" @@ -98,6 +98,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2023-22794.yml" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0008/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5372" diff --git a/advisories/unreviewed/2022/04/GHSA-28q9-rp4x-j7g7/GHSA-28q9-rp4x-j7g7.json b/advisories/unreviewed/2022/04/GHSA-28q9-rp4x-j7g7/GHSA-28q9-rp4x-j7g7.json index 281bc99854d..922c25e3f77 100644 --- a/advisories/unreviewed/2022/04/GHSA-28q9-rp4x-j7g7/GHSA-28q9-rp4x-j7g7.json +++ b/advisories/unreviewed/2022/04/GHSA-28q9-rp4x-j7g7/GHSA-28q9-rp4x-j7g7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28q9-rp4x-j7g7", - "modified": "2022-04-29T01:27:11Z", + "modified": "2024-02-02T15:30:25Z", "published": "2022-04-29T01:27:11Z", "aliases": [ "CVE-2003-0899" ], "details": "Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to \"<\" and \">\" sequences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-131" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-6wfm-7hqx-39wg/GHSA-6wfm-7hqx-39wg.json b/advisories/unreviewed/2022/04/GHSA-6wfm-7hqx-39wg/GHSA-6wfm-7hqx-39wg.json index edc519d41ec..79c9fdfd685 100644 --- a/advisories/unreviewed/2022/04/GHSA-6wfm-7hqx-39wg/GHSA-6wfm-7hqx-39wg.json +++ b/advisories/unreviewed/2022/04/GHSA-6wfm-7hqx-39wg/GHSA-6wfm-7hqx-39wg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6wfm-7hqx-39wg", - "modified": "2022-04-29T01:28:19Z", + "modified": "2024-02-02T15:30:25Z", "published": "2022-04-29T01:28:19Z", "aliases": [ "CVE-2003-1564" ], "details": "libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the \"billion laughs attack.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-776" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-8wgq-vhc2-3cqc/GHSA-8wgq-vhc2-3cqc.json b/advisories/unreviewed/2022/04/GHSA-8wgq-vhc2-3cqc/GHSA-8wgq-vhc2-3cqc.json index be342c168d5..32a142942fd 100644 --- a/advisories/unreviewed/2022/04/GHSA-8wgq-vhc2-3cqc/GHSA-8wgq-vhc2-3cqc.json +++ b/advisories/unreviewed/2022/04/GHSA-8wgq-vhc2-3cqc/GHSA-8wgq-vhc2-3cqc.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-9c7h-3j4x-5hw6/GHSA-9c7h-3j4x-5hw6.json b/advisories/unreviewed/2022/04/GHSA-9c7h-3j4x-5hw6/GHSA-9c7h-3j4x-5hw6.json index 6897651dc28..aa10a488c43 100644 --- a/advisories/unreviewed/2022/04/GHSA-9c7h-3j4x-5hw6/GHSA-9c7h-3j4x-5hw6.json +++ b/advisories/unreviewed/2022/04/GHSA-9c7h-3j4x-5hw6/GHSA-9c7h-3j4x-5hw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9c7h-3j4x-5hw6", - "modified": "2022-04-29T01:27:25Z", + "modified": "2024-02-02T15:30:25Z", "published": "2022-04-29T01:27:25Z", "aliases": [ "CVE-2003-1048" ], "details": "Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -85,7 +88,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-415" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json b/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json index ce345071280..c0052506f47 100644 --- a/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json +++ b/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9q6c-grq3-7prg", - "modified": "2022-04-29T02:58:17Z", + "modified": "2024-02-02T15:30:26Z", "published": "2022-04-29T02:58:17Z", "aliases": [ "CVE-2004-0747" ], "details": "Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -22,54 +25,106 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/17384" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E" @@ -125,7 +180,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-131" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-mmjc-3g2p-897m/GHSA-mmjc-3g2p-897m.json b/advisories/unreviewed/2022/04/GHSA-mmjc-3g2p-897m/GHSA-mmjc-3g2p-897m.json index 216ebfe8a79..be98324e3dd 100644 --- a/advisories/unreviewed/2022/04/GHSA-mmjc-3g2p-897m/GHSA-mmjc-3g2p-897m.json +++ b/advisories/unreviewed/2022/04/GHSA-mmjc-3g2p-897m/GHSA-mmjc-3g2p-897m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mmjc-3g2p-897m", - "modified": "2022-04-29T01:26:36Z", + "modified": "2024-02-02T15:30:25Z", "published": "2022-04-29T01:26:36Z", "aliases": [ "CVE-2003-0545" ], "details": "Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,7 +64,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-415" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-mw47-2hrx-68vv/GHSA-mw47-2hrx-68vv.json b/advisories/unreviewed/2022/04/GHSA-mw47-2hrx-68vv/GHSA-mw47-2hrx-68vv.json index bd5e7f1fa84..f626def3ccd 100644 --- a/advisories/unreviewed/2022/04/GHSA-mw47-2hrx-68vv/GHSA-mw47-2hrx-68vv.json +++ b/advisories/unreviewed/2022/04/GHSA-mw47-2hrx-68vv/GHSA-mw47-2hrx-68vv.json @@ -37,7 +37,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-qcm3-q3pj-vw39/GHSA-qcm3-q3pj-vw39.json b/advisories/unreviewed/2022/04/GHSA-qcm3-q3pj-vw39/GHSA-qcm3-q3pj-vw39.json index 0c041cb32d2..519ab933178 100644 --- a/advisories/unreviewed/2022/04/GHSA-qcm3-q3pj-vw39/GHSA-qcm3-q3pj-vw39.json +++ b/advisories/unreviewed/2022/04/GHSA-qcm3-q3pj-vw39/GHSA-qcm3-q3pj-vw39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcm3-q3pj-vw39", - "modified": "2022-04-29T02:58:20Z", + "modified": "2024-02-02T15:30:26Z", "published": "2022-04-29T02:58:20Z", "aliases": [ "CVE-2004-0772" ], "details": "Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -69,7 +72,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-415" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-v25x-3wqw-87r9/GHSA-v25x-3wqw-87r9.json b/advisories/unreviewed/2022/04/GHSA-v25x-3wqw-87r9/GHSA-v25x-3wqw-87r9.json index a725017a342..35f9c095c58 100644 --- a/advisories/unreviewed/2022/04/GHSA-v25x-3wqw-87r9/GHSA-v25x-3wqw-87r9.json +++ b/advisories/unreviewed/2022/04/GHSA-v25x-3wqw-87r9/GHSA-v25x-3wqw-87r9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v25x-3wqw-87r9", - "modified": "2022-04-29T02:59:26Z", + "modified": "2024-02-02T15:30:25Z", "published": "2022-04-29T02:59:26Z", "aliases": [ "CVE-2004-1363" ], "details": "Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,7 +56,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-131" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-55v6-vvqw-j3qq/GHSA-55v6-vvqw-j3qq.json b/advisories/unreviewed/2022/05/GHSA-55v6-vvqw-j3qq/GHSA-55v6-vvqw-j3qq.json index ddbc26bf343..07478d23271 100644 --- a/advisories/unreviewed/2022/05/GHSA-55v6-vvqw-j3qq/GHSA-55v6-vvqw-j3qq.json +++ b/advisories/unreviewed/2022/05/GHSA-55v6-vvqw-j3qq/GHSA-55v6-vvqw-j3qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-55v6-vvqw-j3qq", - "modified": "2022-05-24T17:08:53Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-24T17:08:53Z", "aliases": [ "CVE-2020-0022" ], "details": "In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-682" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-7w42-h9j5-82q5/GHSA-7w42-h9j5-82q5.json b/advisories/unreviewed/2022/05/GHSA-7w42-h9j5-82q5/GHSA-7w42-h9j5-82q5.json index df8f583a49c..ca48e9831d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w42-h9j5-82q5/GHSA-7w42-h9j5-82q5.json +++ b/advisories/unreviewed/2022/05/GHSA-7w42-h9j5-82q5/GHSA-7w42-h9j5-82q5.json @@ -65,6 +65,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-8p42-r5f7-3m7g/GHSA-8p42-r5f7-3m7g.json b/advisories/unreviewed/2022/05/GHSA-8p42-r5f7-3m7g/GHSA-8p42-r5f7-3m7g.json index f1bee7f7022..9f28f347aae 100644 --- a/advisories/unreviewed/2022/05/GHSA-8p42-r5f7-3m7g/GHSA-8p42-r5f7-3m7g.json +++ b/advisories/unreviewed/2022/05/GHSA-8p42-r5f7-3m7g/GHSA-8p42-r5f7-3m7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8p42-r5f7-3m7g", - "modified": "2022-05-01T02:04:59Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-01T02:04:59Z", "aliases": [ "CVE-2005-2103" ], "details": "Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,7 +56,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-131" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-f6r7-g7pj-vhjx/GHSA-f6r7-g7pj-vhjx.json b/advisories/unreviewed/2022/05/GHSA-f6r7-g7pj-vhjx/GHSA-f6r7-g7pj-vhjx.json index e08ff390323..796a05a4bfb 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6r7-g7pj-vhjx/GHSA-f6r7-g7pj-vhjx.json +++ b/advisories/unreviewed/2022/05/GHSA-f6r7-g7pj-vhjx/GHSA-f6r7-g7pj-vhjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6r7-g7pj-vhjx", - "modified": "2022-05-01T01:53:02Z", + "modified": "2024-02-02T15:30:26Z", "published": "2022-05-01T01:53:02Z", "aliases": [ "CVE-2005-0891" ], "details": "Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hfr6-pxvf-frf7/GHSA-hfr6-pxvf-frf7.json b/advisories/unreviewed/2022/05/GHSA-hfr6-pxvf-frf7/GHSA-hfr6-pxvf-frf7.json index 09f313081dc..c20a339a26f 100644 --- a/advisories/unreviewed/2022/05/GHSA-hfr6-pxvf-frf7/GHSA-hfr6-pxvf-frf7.json +++ b/advisories/unreviewed/2022/05/GHSA-hfr6-pxvf-frf7/GHSA-hfr6-pxvf-frf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfr6-pxvf-frf7", - "modified": "2022-05-02T03:30:19Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-02T03:30:19Z", "aliases": [ "CVE-2009-1955" ], "details": "The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -18,58 +21,114 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-1955" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b@%3Ccvs.httpd.apache.org%3E" @@ -261,7 +320,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-776" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-jhxw-fqxp-j75j/GHSA-jhxw-fqxp-j75j.json b/advisories/unreviewed/2022/05/GHSA-jhxw-fqxp-j75j/GHSA-jhxw-fqxp-j75j.json index 8f81dcf7db1..67e640ac1e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-jhxw-fqxp-j75j/GHSA-jhxw-fqxp-j75j.json +++ b/advisories/unreviewed/2022/05/GHSA-jhxw-fqxp-j75j/GHSA-jhxw-fqxp-j75j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhxw-fqxp-j75j", - "modified": "2022-05-01T17:52:04Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-01T17:52:04Z", "aliases": [ "CVE-2007-1285" ], "details": "The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -173,7 +176,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-674" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-m9m5-q9x5-6877/GHSA-m9m5-q9x5-6877.json b/advisories/unreviewed/2022/05/GHSA-m9m5-q9x5-6877/GHSA-m9m5-q9x5-6877.json index 11511b82bb1..0d9f9c0f4f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-m9m5-q9x5-6877/GHSA-m9m5-q9x5-6877.json +++ b/advisories/unreviewed/2022/05/GHSA-m9m5-q9x5-6877/GHSA-m9m5-q9x5-6877.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9m5-q9x5-6877", - "modified": "2022-05-01T23:31:45Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-01T23:31:45Z", "aliases": [ "CVE-2008-0599" ], "details": "The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -165,7 +168,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-131" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-mpw2-6pxv-5r2w/GHSA-mpw2-6pxv-5r2w.json b/advisories/unreviewed/2022/05/GHSA-mpw2-6pxv-5r2w/GHSA-mpw2-6pxv-5r2w.json index 976f79178ea..5a539e876ff 100644 --- a/advisories/unreviewed/2022/05/GHSA-mpw2-6pxv-5r2w/GHSA-mpw2-6pxv-5r2w.json +++ b/advisories/unreviewed/2022/05/GHSA-mpw2-6pxv-5r2w/GHSA-mpw2-6pxv-5r2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mpw2-6pxv-5r2w", - "modified": "2022-05-24T17:37:34Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-24T17:37:34Z", "aliases": [ "CVE-2019-25011" ], "details": "NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rpcf-xw9j-7c7j/GHSA-rpcf-xw9j-7c7j.json b/advisories/unreviewed/2022/05/GHSA-rpcf-xw9j-7c7j/GHSA-rpcf-xw9j-7c7j.json index c70adf20e56..3a72edc466b 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpcf-xw9j-7c7j/GHSA-rpcf-xw9j-7c7j.json +++ b/advisories/unreviewed/2022/05/GHSA-rpcf-xw9j-7c7j/GHSA-rpcf-xw9j-7c7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rpcf-xw9j-7c7j", - "modified": "2022-05-17T01:59:37Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-17T01:59:37Z", "aliases": [ "CVE-2011-1755" ], "details": "jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -66,6 +69,10 @@ "type": "WEB", "url": "http://support.apple.com/kb/HT5002" }, + { + "type": "WEB", + "url": "http://www.mail-archive.com/jabberd2%40lists.xiaoka.com/msg01655.html" + }, { "type": "WEB", "url": "http://www.mail-archive.com/jabberd2@lists.xiaoka.com/msg01655.html" @@ -85,7 +92,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-776" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w3j5-qjf6-g9gf/GHSA-w3j5-qjf6-g9gf.json b/advisories/unreviewed/2022/05/GHSA-w3j5-qjf6-g9gf/GHSA-w3j5-qjf6-g9gf.json index d632def9ddf..0e9a6c79bf5 100644 --- a/advisories/unreviewed/2022/05/GHSA-w3j5-qjf6-g9gf/GHSA-w3j5-qjf6-g9gf.json +++ b/advisories/unreviewed/2022/05/GHSA-w3j5-qjf6-g9gf/GHSA-w3j5-qjf6-g9gf.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11236" }, + { + "type": "WEB", + "url": "http://linux.bkbits.net:8080/linux-2.6/cset%4043483fddCiQX1WyG_orbko06TrjMVA" + }, { "type": "WEB", "url": "http://linux.bkbits.net:8080/linux-2.6/cset@43483fddCiQX1WyG_orbko06TrjMVA" @@ -45,7 +49,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-x9c5-c5mj-wjjx/GHSA-x9c5-c5mj-wjjx.json b/advisories/unreviewed/2022/05/GHSA-x9c5-c5mj-wjjx/GHSA-x9c5-c5mj-wjjx.json index bd2b64a4ebb..66a01859d48 100644 --- a/advisories/unreviewed/2022/05/GHSA-x9c5-c5mj-wjjx/GHSA-x9c5-c5mj-wjjx.json +++ b/advisories/unreviewed/2022/05/GHSA-x9c5-c5mj-wjjx/GHSA-x9c5-c5mj-wjjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9c5-c5mj-wjjx", - "modified": "2022-05-01T23:58:24Z", + "modified": "2024-02-02T15:30:27Z", "published": "2022-05-01T23:58:24Z", "aliases": [ "CVE-2008-3281" ], "details": "libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -189,7 +192,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-776" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-36cr-wp3c-5h2p/GHSA-36cr-wp3c-5h2p.json b/advisories/unreviewed/2023/05/GHSA-36cr-wp3c-5h2p/GHSA-36cr-wp3c-5h2p.json index da696343f1e..9db4409793b 100644 --- a/advisories/unreviewed/2023/05/GHSA-36cr-wp3c-5h2p/GHSA-36cr-wp3c-5h2p.json +++ b/advisories/unreviewed/2023/05/GHSA-36cr-wp3c-5h2p/GHSA-36cr-wp3c-5h2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36cr-wp3c-5h2p", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33793" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-3777-fm87-36r8/GHSA-3777-fm87-36r8.json b/advisories/unreviewed/2023/05/GHSA-3777-fm87-36r8/GHSA-3777-fm87-36r8.json index 82fd003382e..f2f57d86b72 100644 --- a/advisories/unreviewed/2023/05/GHSA-3777-fm87-36r8/GHSA-3777-fm87-36r8.json +++ b/advisories/unreviewed/2023/05/GHSA-3777-fm87-36r8/GHSA-3777-fm87-36r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3777-fm87-36r8", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33788" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-4w75-4x78-6882/GHSA-4w75-4x78-6882.json b/advisories/unreviewed/2023/05/GHSA-4w75-4x78-6882/GHSA-4w75-4x78-6882.json index 11c6635fcf2..c184f08f4f9 100644 --- a/advisories/unreviewed/2023/05/GHSA-4w75-4x78-6882/GHSA-4w75-4x78-6882.json +++ b/advisories/unreviewed/2023/05/GHSA-4w75-4x78-6882/GHSA-4w75-4x78-6882.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4w75-4x78-6882", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33791" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-72w4-56w3-7485/GHSA-72w4-56w3-7485.json b/advisories/unreviewed/2023/05/GHSA-72w4-56w3-7485/GHSA-72w4-56w3-7485.json index bb1d3599555..831fab0f27d 100644 --- a/advisories/unreviewed/2023/05/GHSA-72w4-56w3-7485/GHSA-72w4-56w3-7485.json +++ b/advisories/unreviewed/2023/05/GHSA-72w4-56w3-7485/GHSA-72w4-56w3-7485.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-72w4-56w3-7485", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:27Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33786" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-8w3x-9pj3-2gw8/GHSA-8w3x-9pj3-2gw8.json b/advisories/unreviewed/2023/05/GHSA-8w3x-9pj3-2gw8/GHSA-8w3x-9pj3-2gw8.json index d62735ea8b9..bc71e641337 100644 --- a/advisories/unreviewed/2023/05/GHSA-8w3x-9pj3-2gw8/GHSA-8w3x-9pj3-2gw8.json +++ b/advisories/unreviewed/2023/05/GHSA-8w3x-9pj3-2gw8/GHSA-8w3x-9pj3-2gw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8w3x-9pj3-2gw8", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:27Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33787" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-94hm-2957-3gcc/GHSA-94hm-2957-3gcc.json b/advisories/unreviewed/2023/05/GHSA-94hm-2957-3gcc/GHSA-94hm-2957-3gcc.json index 2999d3bfbcd..f7f991215b0 100644 --- a/advisories/unreviewed/2023/05/GHSA-94hm-2957-3gcc/GHSA-94hm-2957-3gcc.json +++ b/advisories/unreviewed/2023/05/GHSA-94hm-2957-3gcc/GHSA-94hm-2957-3gcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94hm-2957-3gcc", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:20Z", "aliases": [ "CVE-2023-33800" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:11Z" diff --git a/advisories/unreviewed/2023/05/GHSA-g22j-4jxh-2vc7/GHSA-g22j-4jxh-2vc7.json b/advisories/unreviewed/2023/05/GHSA-g22j-4jxh-2vc7/GHSA-g22j-4jxh-2vc7.json index 0c855b96688..00601978de6 100644 --- a/advisories/unreviewed/2023/05/GHSA-g22j-4jxh-2vc7/GHSA-g22j-4jxh-2vc7.json +++ b/advisories/unreviewed/2023/05/GHSA-g22j-4jxh-2vc7/GHSA-g22j-4jxh-2vc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g22j-4jxh-2vc7", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33796" @@ -34,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-gp23-w687-38gc/GHSA-gp23-w687-38gc.json b/advisories/unreviewed/2023/05/GHSA-gp23-w687-38gc/GHSA-gp23-w687-38gc.json index cf6cb8e53d5..2f153993672 100644 --- a/advisories/unreviewed/2023/05/GHSA-gp23-w687-38gc/GHSA-gp23-w687-38gc.json +++ b/advisories/unreviewed/2023/05/GHSA-gp23-w687-38gc/GHSA-gp23-w687-38gc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gp23-w687-38gc", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33797" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-h26m-gxx2-8f39/GHSA-h26m-gxx2-8f39.json b/advisories/unreviewed/2023/05/GHSA-h26m-gxx2-8f39/GHSA-h26m-gxx2-8f39.json index b3d6cacf50c..278246ad235 100644 --- a/advisories/unreviewed/2023/05/GHSA-h26m-gxx2-8f39/GHSA-h26m-gxx2-8f39.json +++ b/advisories/unreviewed/2023/05/GHSA-h26m-gxx2-8f39/GHSA-h26m-gxx2-8f39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h26m-gxx2-8f39", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33795" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-h85c-f8f5-f6q9/GHSA-h85c-f8f5-f6q9.json b/advisories/unreviewed/2023/05/GHSA-h85c-f8f5-f6q9/GHSA-h85c-f8f5-f6q9.json index 1e8377df966..32af5773aed 100644 --- a/advisories/unreviewed/2023/05/GHSA-h85c-f8f5-f6q9/GHSA-h85c-f8f5-f6q9.json +++ b/advisories/unreviewed/2023/05/GHSA-h85c-f8f5-f6q9/GHSA-h85c-f8f5-f6q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h85c-f8f5-f6q9", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33789" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-hg43-j454-5m9f/GHSA-hg43-j454-5m9f.json b/advisories/unreviewed/2023/05/GHSA-hg43-j454-5m9f/GHSA-hg43-j454-5m9f.json index 3e81dfd008d..d02bbad9885 100644 --- a/advisories/unreviewed/2023/05/GHSA-hg43-j454-5m9f/GHSA-hg43-j454-5m9f.json +++ b/advisories/unreviewed/2023/05/GHSA-hg43-j454-5m9f/GHSA-hg43-j454-5m9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hg43-j454-5m9f", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:20Z", "aliases": [ "CVE-2023-33799" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:11Z" diff --git a/advisories/unreviewed/2023/05/GHSA-hwqw-p9h2-q5q4/GHSA-hwqw-p9h2-q5q4.json b/advisories/unreviewed/2023/05/GHSA-hwqw-p9h2-q5q4/GHSA-hwqw-p9h2-q5q4.json index da6232f3866..ede4a1f3506 100644 --- a/advisories/unreviewed/2023/05/GHSA-hwqw-p9h2-q5q4/GHSA-hwqw-p9h2-q5q4.json +++ b/advisories/unreviewed/2023/05/GHSA-hwqw-p9h2-q5q4/GHSA-hwqw-p9h2-q5q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwqw-p9h2-q5q4", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33792" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-q53r-r56j-6vxp/GHSA-q53r-r56j-6vxp.json b/advisories/unreviewed/2023/05/GHSA-q53r-r56j-6vxp/GHSA-q53r-r56j-6vxp.json index 65a0218c991..92838a4bd4a 100644 --- a/advisories/unreviewed/2023/05/GHSA-q53r-r56j-6vxp/GHSA-q53r-r56j-6vxp.json +++ b/advisories/unreviewed/2023/05/GHSA-q53r-r56j-6vxp/GHSA-q53r-r56j-6vxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q53r-r56j-6vxp", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33790" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-qw3p-g4v7-86mq/GHSA-qw3p-g4v7-86mq.json b/advisories/unreviewed/2023/05/GHSA-qw3p-g4v7-86mq/GHSA-qw3p-g4v7-86mq.json index cc36782decd..517895dcd91 100644 --- a/advisories/unreviewed/2023/05/GHSA-qw3p-g4v7-86mq/GHSA-qw3p-g4v7-86mq.json +++ b/advisories/unreviewed/2023/05/GHSA-qw3p-g4v7-86mq/GHSA-qw3p-g4v7-86mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw3p-g4v7-86mq", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:27Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33785" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-vp9w-43wr-g8fj/GHSA-vp9w-43wr-g8fj.json b/advisories/unreviewed/2023/05/GHSA-vp9w-43wr-g8fj/GHSA-vp9w-43wr-g8fj.json index d598592a10d..3f0c57ca934 100644 --- a/advisories/unreviewed/2023/05/GHSA-vp9w-43wr-g8fj/GHSA-vp9w-43wr-g8fj.json +++ b/advisories/unreviewed/2023/05/GHSA-vp9w-43wr-g8fj/GHSA-vp9w-43wr-g8fj.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0004/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/05/GHSA-wf2q-fvpq-94cc/GHSA-wf2q-fvpq-94cc.json b/advisories/unreviewed/2023/05/GHSA-wf2q-fvpq-94cc/GHSA-wf2q-fvpq-94cc.json index 9cb64252071..e242af6db05 100644 --- a/advisories/unreviewed/2023/05/GHSA-wf2q-fvpq-94cc/GHSA-wf2q-fvpq-94cc.json +++ b/advisories/unreviewed/2023/05/GHSA-wf2q-fvpq-94cc/GHSA-wf2q-fvpq-94cc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wf2q-fvpq-94cc", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33794" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/05/GHSA-wwgm-wrpv-h3h4/GHSA-wwgm-wrpv-h3h4.json b/advisories/unreviewed/2023/05/GHSA-wwgm-wrpv-h3h4/GHSA-wwgm-wrpv-h3h4.json index fc8c234442e..7a0b01ca630 100644 --- a/advisories/unreviewed/2023/05/GHSA-wwgm-wrpv-h3h4/GHSA-wwgm-wrpv-h3h4.json +++ b/advisories/unreviewed/2023/05/GHSA-wwgm-wrpv-h3h4/GHSA-wwgm-wrpv-h3h4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwgm-wrpv-h3h4", - "modified": "2023-05-27T06:30:41Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-05-24T21:30:19Z", "aliases": [ "CVE-2023-33798" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T20:15:10Z" diff --git a/advisories/unreviewed/2023/06/GHSA-rv3g-cgph-cc24/GHSA-rv3g-cgph-cc24.json b/advisories/unreviewed/2023/06/GHSA-rv3g-cgph-cc24/GHSA-rv3g-cgph-cc24.json index 12956ab6a6a..ead3339d3b2 100644 --- a/advisories/unreviewed/2023/06/GHSA-rv3g-cgph-cc24/GHSA-rv3g-cgph-cc24.json +++ b/advisories/unreviewed/2023/06/GHSA-rv3g-cgph-cc24/GHSA-rv3g-cgph-cc24.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv3g-cgph-cc24", - "modified": "2023-06-23T18:30:22Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-06-14T21:30:40Z", "aliases": [ "CVE-2023-34565" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-14T21:15:09Z" diff --git a/advisories/unreviewed/2023/07/GHSA-fcg7-9x44-gx43/GHSA-fcg7-9x44-gx43.json b/advisories/unreviewed/2023/07/GHSA-fcg7-9x44-gx43/GHSA-fcg7-9x44-gx43.json index e15f8741efd..2d09d15e586 100644 --- a/advisories/unreviewed/2023/07/GHSA-fcg7-9x44-gx43/GHSA-fcg7-9x44-gx43.json +++ b/advisories/unreviewed/2023/07/GHSA-fcg7-9x44-gx43/GHSA-fcg7-9x44-gx43.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0003/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" diff --git a/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json b/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json index d07b646deaf..a483d2fdc85 100644 --- a/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json +++ b/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4m9-r3rr-cx92", - "modified": "2023-07-24T15:30:27Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-07-24T15:30:27Z", "aliases": [ "CVE-2023-3863" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0002/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5480" @@ -50,7 +54,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-24T15:15:09Z" diff --git a/advisories/unreviewed/2023/09/GHSA-w5h6-8xc7-vp2c/GHSA-w5h6-8xc7-vp2c.json b/advisories/unreviewed/2023/09/GHSA-w5h6-8xc7-vp2c/GHSA-w5h6-8xc7-vp2c.json index 30eb8248898..467c977ebe7 100644 --- a/advisories/unreviewed/2023/09/GHSA-w5h6-8xc7-vp2c/GHSA-w5h6-8xc7-vp2c.json +++ b/advisories/unreviewed/2023/09/GHSA-w5h6-8xc7-vp2c/GHSA-w5h6-8xc7-vp2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5h6-8xc7-vp2c", - "modified": "2023-09-22T03:30:50Z", + "modified": "2024-02-02T15:30:28Z", "published": "2023-09-21T00:31:16Z", "aliases": [ "CVE-2023-36234" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-20T22:15:12Z" diff --git a/advisories/unreviewed/2024/01/GHSA-95jr-7vvp-xrg6/GHSA-95jr-7vvp-xrg6.json b/advisories/unreviewed/2024/01/GHSA-95jr-7vvp-xrg6/GHSA-95jr-7vvp-xrg6.json index c793e96bc01..1343145f757 100644 --- a/advisories/unreviewed/2024/01/GHSA-95jr-7vvp-xrg6/GHSA-95jr-7vvp-xrg6.json +++ b/advisories/unreviewed/2024/01/GHSA-95jr-7vvp-xrg6/GHSA-95jr-7vvp-xrg6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://drive.google.com/drive/folders/1ZFjWlD5axvhWp--I7tuiZ9uOpSBmU_f6?usp=drive_link" }, + { + "type": "WEB", + "url": "https://github.com/beraoudabdelkhalek/research/tree/main/CVEs/CVE-2024-0720" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.251544" diff --git a/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json b/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json index 20de0a8e499..c2c8bc840ee 100644 --- a/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json +++ b/advisories/unreviewed/2024/01/GHSA-mcx8-9rrj-7qxm/GHSA-mcx8-9rrj-7qxm.json @@ -45,6 +45,10 @@ "type": "WEB", "url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0011/" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/19/3" diff --git a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json index b5190663f34..808fd3ed6d7 100644 --- a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json +++ b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json @@ -49,6 +49,10 @@ "type": "WEB", "url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0011/" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/19/3" diff --git a/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json b/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json new file mode 100644 index 00000000000..336838ea105 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-24rh-qhmv-p8j2/GHSA-24rh-qhmv-p8j2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24rh-qhmv-p8j2", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2024-0253" + ], + "details": "ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0253" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-283h-3w9j-26xq/GHSA-283h-3w9j-26xq.json b/advisories/unreviewed/2024/02/GHSA-283h-3w9j-26xq/GHSA-283h-3w9j-26xq.json new file mode 100644 index 00000000000..1c78902e11d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-283h-3w9j-26xq/GHSA-283h-3w9j-26xq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-283h-3w9j-26xq", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-38273" + ], + "details": "IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38273" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/260733" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7105357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json b/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json new file mode 100644 index 00000000000..58ffa26c78a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3rpv-j58g-7jfj/GHSA-3rpv-j58g-7jfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rpv-j58g-7jfj", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2024-0269" + ], + "details": "ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0269" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/sqlfix-7271.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-42fh-xcj5-fxwg/GHSA-42fh-xcj5-fxwg.json b/advisories/unreviewed/2024/02/GHSA-42fh-xcj5-fxwg/GHSA-42fh-xcj5-fxwg.json new file mode 100644 index 00000000000..c8596e1ffb6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-42fh-xcj5-fxwg/GHSA-42fh-xcj5-fxwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42fh-xcj5-fxwg", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-6675" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server.This issue affects CyberMath: from v.1.4 before v.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6675" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-439f-fqrh-gmv2/GHSA-439f-fqrh-gmv2.json b/advisories/unreviewed/2024/02/GHSA-439f-fqrh-gmv2/GHSA-439f-fqrh-gmv2.json new file mode 100644 index 00000000000..4a6da24a636 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-439f-fqrh-gmv2/GHSA-439f-fqrh-gmv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-439f-fqrh-gmv2", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-6672" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from v1.4 before v1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6672" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6rq5-p8rc-hp83/GHSA-6rq5-p8rc-hp83.json b/advisories/unreviewed/2024/02/GHSA-6rq5-p8rc-hp83/GHSA-6rq5-p8rc-hp83.json new file mode 100644 index 00000000000..86cfd031bfc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6rq5-p8rc-hp83/GHSA-6rq5-p8rc-hp83.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rq5-p8rc-hp83", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2024-1184" + ], + "details": "A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-252674 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1184" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/vuldb/10-exploit-perl.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252674" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7mjm-4vrc-ghvc/GHSA-7mjm-4vrc-ghvc.json b/advisories/unreviewed/2024/02/GHSA-7mjm-4vrc-ghvc/GHSA-7mjm-4vrc-ghvc.json index 85d290ce0da..fb76e1fc8e9 100644 --- a/advisories/unreviewed/2024/02/GHSA-7mjm-4vrc-ghvc/GHSA-7mjm-4vrc-ghvc.json +++ b/advisories/unreviewed/2024/02/GHSA-7mjm-4vrc-ghvc/GHSA-7mjm-4vrc-ghvc.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-308" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-7pjv-fxwg-c5c3/GHSA-7pjv-fxwg-c5c3.json b/advisories/unreviewed/2024/02/GHSA-7pjv-fxwg-c5c3/GHSA-7pjv-fxwg-c5c3.json new file mode 100644 index 00000000000..92685e38adb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7pjv-fxwg-c5c3/GHSA-7pjv-fxwg-c5c3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pjv-fxwg-c5c3", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-47144" + ], + "details": "IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270271.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47144" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/270271" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7105139" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9hch-g858-cr9j/GHSA-9hch-g858-cr9j.json b/advisories/unreviewed/2024/02/GHSA-9hch-g858-cr9j/GHSA-9hch-g858-cr9j.json new file mode 100644 index 00000000000..dd28bb71ffa --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9hch-g858-cr9j/GHSA-9hch-g858-cr9j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hch-g858-cr9j", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-47143" + ], + "details": "IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47143" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/270270" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7105139" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fh42-q9qf-98jh/GHSA-fh42-q9qf-98jh.json b/advisories/unreviewed/2024/02/GHSA-fh42-q9qf-98jh/GHSA-fh42-q9qf-98jh.json new file mode 100644 index 00000000000..53db7e7a84c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fh42-q9qf-98jh/GHSA-fh42-q9qf-98jh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh42-q9qf-98jh", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-47148" + ], + "details": "IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 270599.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47148" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/270599" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7096482" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json b/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json new file mode 100644 index 00000000000..f96fd04acc9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h66j-qwj8-p6m9/GHSA-h66j-qwj8-p6m9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h66j-qwj8-p6m9", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-47142" + ], + "details": "IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47142" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/270267" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7105139" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-px37-v4hm-7f6q/GHSA-px37-v4hm-7f6q.json b/advisories/unreviewed/2024/02/GHSA-px37-v4hm-7f6q/GHSA-px37-v4hm-7f6q.json index 5257db6be59..e5b00f4fa08 100644 --- a/advisories/unreviewed/2024/02/GHSA-px37-v4hm-7f6q/GHSA-px37-v4hm-7f6q.json +++ b/advisories/unreviewed/2024/02/GHSA-px37-v4hm-7f6q/GHSA-px37-v4hm-7f6q.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-598" + "CWE-598", + "CWE-668" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-q45w-f72f-v464/GHSA-q45w-f72f-v464.json b/advisories/unreviewed/2024/02/GHSA-q45w-f72f-v464/GHSA-q45w-f72f-v464.json new file mode 100644 index 00000000000..7fa8f6d792b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q45w-f72f-v464/GHSA-q45w-f72f-v464.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q45w-f72f-v464", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-6673" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Reflected XSS.This issue affects CyberMath: from v.1.4 before v.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6673" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w57g-4hpj-6p36/GHSA-w57g-4hpj-6p36.json b/advisories/unreviewed/2024/02/GHSA-w57g-4hpj-6p36/GHSA-w57g-4hpj-6p36.json new file mode 100644 index 00000000000..2471f4a18a0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w57g-4hpj-6p36/GHSA-w57g-4hpj-6p36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w57g-4hpj-6p36", + "modified": "2024-02-02T15:30:28Z", + "published": "2024-02-02T15:30:28Z", + "aliases": [ + "CVE-2023-6676" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery.This issue affects CyberMath: from v1.4 before v1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6676" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-02T13:15:09Z" + } +} \ No newline at end of file