diff --git a/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json b/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json index d3e36aec7d5..2467ece6904 100644 --- a/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json +++ b/advisories/unreviewed/2023/03/GHSA-fj3c-gq42-693w/GHSA-fj3c-gq42-693w.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json b/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json index 549f2c6dab0..8b55eaffd84 100644 --- a/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json +++ b/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-295v-9m5g-79q9", - "modified": "2023-07-06T06:30:17Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2023-3090" diff --git a/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json b/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json index 38927d37a24..edd9d5dce67 100644 --- a/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json +++ b/advisories/unreviewed/2023/06/GHSA-3652-93x3-2rrr/GHSA-3652-93x3-2rrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3652-93x3-2rrr", - "modified": "2023-06-26T12:30:22Z", + "modified": "2023-07-06T18:30:50Z", "published": "2023-06-26T12:30:22Z", "aliases": [ "CVE-2023-36631" ], "details": "** DISPUTED ** Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is \"this is intended behavior as the application can be locked using a password.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json b/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json index 8f75f20d564..cff35b48f03 100644 --- a/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json +++ b/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3jff-v2mx-4rwr", - "modified": "2023-06-26T21:30:59Z", + "modified": "2023-07-06T18:30:50Z", "published": "2023-06-26T21:30:59Z", "aliases": [ "CVE-2023-36252" ], "details": "An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-49vq-hvrf-jhjw/GHSA-49vq-hvrf-jhjw.json b/advisories/unreviewed/2023/06/GHSA-49vq-hvrf-jhjw/GHSA-49vq-hvrf-jhjw.json index bf8c54e8c6e..6af052922c9 100644 --- a/advisories/unreviewed/2023/06/GHSA-49vq-hvrf-jhjw/GHSA-49vq-hvrf-jhjw.json +++ b/advisories/unreviewed/2023/06/GHSA-49vq-hvrf-jhjw/GHSA-49vq-hvrf-jhjw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json b/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json index 8a58a07010b..93fbe6958a9 100644 --- a/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json +++ b/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4v9h-2pcw-v2q7", - "modified": "2023-06-27T18:30:34Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-27T18:30:34Z", "aliases": [ "CVE-2023-33566" ], "details": "An unauthorized node injection vulnerability has been identified in ROS2 Foxy Fitzroy versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could allow a malicious user to inject malicious ROS2 nodes into the system remotely. Once injected, these nodes could disrupt the normal operations of the system or cause other potentially harmful behavior.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json b/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json index ce8a81a7aab..6936ad74bcb 100644 --- a/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json +++ b/advisories/unreviewed/2023/06/GHSA-5xxc-86g5-876q/GHSA-5xxc-86g5-876q.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-502", "CWE-94" ], "severity": null, diff --git a/advisories/unreviewed/2023/06/GHSA-6q6r-9q5h-h93m/GHSA-6q6r-9q5h-h93m.json b/advisories/unreviewed/2023/06/GHSA-6q6r-9q5h-h93m/GHSA-6q6r-9q5h-h93m.json index 4d0c15c3dc2..d0a898a2aa5 100644 --- a/advisories/unreviewed/2023/06/GHSA-6q6r-9q5h-h93m/GHSA-6q6r-9q5h-h93m.json +++ b/advisories/unreviewed/2023/06/GHSA-6q6r-9q5h-h93m/GHSA-6q6r-9q5h-h93m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q6r-9q5h-h93m", - "modified": "2023-06-28T00:30:44Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-28T00:30:44Z", "aliases": [ "CVE-2023-25001" ], "details": "A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-85vj-ffxc-x8w8/GHSA-85vj-ffxc-x8w8.json b/advisories/unreviewed/2023/06/GHSA-85vj-ffxc-x8w8/GHSA-85vj-ffxc-x8w8.json index 7ef67b86f21..37ffe317121 100644 --- a/advisories/unreviewed/2023/06/GHSA-85vj-ffxc-x8w8/GHSA-85vj-ffxc-x8w8.json +++ b/advisories/unreviewed/2023/06/GHSA-85vj-ffxc-x8w8/GHSA-85vj-ffxc-x8w8.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1333" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-8r8v-fx37-wpw7/GHSA-8r8v-fx37-wpw7.json b/advisories/unreviewed/2023/06/GHSA-8r8v-fx37-wpw7/GHSA-8r8v-fx37-wpw7.json index a7f9e0da2dc..59f5101bc86 100644 --- a/advisories/unreviewed/2023/06/GHSA-8r8v-fx37-wpw7/GHSA-8r8v-fx37-wpw7.json +++ b/advisories/unreviewed/2023/06/GHSA-8r8v-fx37-wpw7/GHSA-8r8v-fx37-wpw7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8r8v-fx37-wpw7", - "modified": "2023-06-29T00:31:04Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-29T00:31:04Z", "aliases": [ "CVE-2023-3357" ], "details": "A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-9xhf-gx34-9q2g/GHSA-9xhf-gx34-9q2g.json b/advisories/unreviewed/2023/06/GHSA-9xhf-gx34-9q2g/GHSA-9xhf-gx34-9q2g.json index 11059968a9f..a6ec7138fa7 100644 --- a/advisories/unreviewed/2023/06/GHSA-9xhf-gx34-9q2g/GHSA-9xhf-gx34-9q2g.json +++ b/advisories/unreviewed/2023/06/GHSA-9xhf-gx34-9q2g/GHSA-9xhf-gx34-9q2g.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json b/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json index df2b1aa450c..91a348a8936 100644 --- a/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json +++ b/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqw3-c4x8-fq47", - "modified": "2023-06-27T18:30:34Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-27T18:30:34Z", "aliases": [ "CVE-2023-33567" ], "details": "An unauthorized access vulnerability has been discovered in ROS2 Foxy Fitzroy versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized access to multiple ROS2 nodes remotely. Unauthorized access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-hg6h-cj3j-wp77/GHSA-hg6h-cj3j-wp77.json b/advisories/unreviewed/2023/06/GHSA-hg6h-cj3j-wp77/GHSA-hg6h-cj3j-wp77.json index 4ffad8a29fc..5b907a6863c 100644 --- a/advisories/unreviewed/2023/06/GHSA-hg6h-cj3j-wp77/GHSA-hg6h-cj3j-wp77.json +++ b/advisories/unreviewed/2023/06/GHSA-hg6h-cj3j-wp77/GHSA-hg6h-cj3j-wp77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg6h-cj3j-wp77", - "modified": "2023-06-29T00:31:04Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-29T00:31:04Z", "aliases": [ "CVE-2023-3359" ], "details": "An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json b/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json index b9631ec6546..e410535894e 100644 --- a/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json +++ b/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36002" }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-0004" + }, { "type": "WEB", "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-005" diff --git a/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json b/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json index 7fac0aafd3f..e7f59cacba2 100644 --- a/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json +++ b/advisories/unreviewed/2023/06/GHSA-mfmf-m5jw-cfqh/GHSA-mfmf-m5jw-cfqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfmf-m5jw-cfqh", - "modified": "2023-06-28T03:31:03Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-28T03:31:03Z", "aliases": [ "CVE-2022-48505" ], "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-p642-fwhv-jwmj/GHSA-p642-fwhv-jwmj.json b/advisories/unreviewed/2023/06/GHSA-p642-fwhv-jwmj/GHSA-p642-fwhv-jwmj.json index 345655dfaf3..765791baacf 100644 --- a/advisories/unreviewed/2023/06/GHSA-p642-fwhv-jwmj/GHSA-p642-fwhv-jwmj.json +++ b/advisories/unreviewed/2023/06/GHSA-p642-fwhv-jwmj/GHSA-p642-fwhv-jwmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p642-fwhv-jwmj", - "modified": "2023-06-28T00:30:45Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-28T00:30:45Z", "aliases": [ "CVE-2023-25002" ], "details": "A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-q9h3-8p32-277m/GHSA-q9h3-8p32-277m.json b/advisories/unreviewed/2023/06/GHSA-q9h3-8p32-277m/GHSA-q9h3-8p32-277m.json index 296f0bf4663..0787a44a4f0 100644 --- a/advisories/unreviewed/2023/06/GHSA-q9h3-8p32-277m/GHSA-q9h3-8p32-277m.json +++ b/advisories/unreviewed/2023/06/GHSA-q9h3-8p32-277m/GHSA-q9h3-8p32-277m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9h3-8p32-277m", - "modified": "2023-06-28T21:30:29Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2023-33592" ], "details": "Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-qjwq-qh5c-p96w/GHSA-qjwq-qh5c-p96w.json b/advisories/unreviewed/2023/06/GHSA-qjwq-qh5c-p96w/GHSA-qjwq-qh5c-p96w.json index 2fa44467d9f..a7403453238 100644 --- a/advisories/unreviewed/2023/06/GHSA-qjwq-qh5c-p96w/GHSA-qjwq-qh5c-p96w.json +++ b/advisories/unreviewed/2023/06/GHSA-qjwq-qh5c-p96w/GHSA-qjwq-qh5c-p96w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qjwq-qh5c-p96w", - "modified": "2023-06-29T15:30:35Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-29T15:30:35Z", "aliases": [ "CVE-2015-1313" ], "details": "JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-425" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-rc54-8mxm-g5hf/GHSA-rc54-8mxm-g5hf.json b/advisories/unreviewed/2023/06/GHSA-rc54-8mxm-g5hf/GHSA-rc54-8mxm-g5hf.json index eb234f4a6ac..753cb682bb7 100644 --- a/advisories/unreviewed/2023/06/GHSA-rc54-8mxm-g5hf/GHSA-rc54-8mxm-g5hf.json +++ b/advisories/unreviewed/2023/06/GHSA-rc54-8mxm-g5hf/GHSA-rc54-8mxm-g5hf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rc54-8mxm-g5hf", - "modified": "2023-06-28T09:30:23Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-28T09:30:23Z", "aliases": [ "CVE-2023-3034" @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-rmg8-h2h6-5wwf/GHSA-rmg8-h2h6-5wwf.json b/advisories/unreviewed/2023/06/GHSA-rmg8-h2h6-5wwf/GHSA-rmg8-h2h6-5wwf.json index a2076886fc9..587e076da1c 100644 --- a/advisories/unreviewed/2023/06/GHSA-rmg8-h2h6-5wwf/GHSA-rmg8-h2h6-5wwf.json +++ b/advisories/unreviewed/2023/06/GHSA-rmg8-h2h6-5wwf/GHSA-rmg8-h2h6-5wwf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmg8-h2h6-5wwf", - "modified": "2023-06-29T00:31:04Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-29T00:31:04Z", "aliases": [ "CVE-2023-3358" ], "details": "A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json b/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json index b4d290f2f55..beeeb882ae1 100644 --- a/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json +++ b/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vv5w-jx3q-w898", - "modified": "2023-06-27T18:30:34Z", + "modified": "2023-07-06T18:30:51Z", "published": "2023-06-27T18:30:34Z", "aliases": [ "CVE-2023-34830" ], "details": "i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-4fr8-gmqr-2fwp/GHSA-4fr8-gmqr-2fwp.json b/advisories/unreviewed/2023/07/GHSA-4fr8-gmqr-2fwp/GHSA-4fr8-gmqr-2fwp.json new file mode 100644 index 00000000000..6204eda8358 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4fr8-gmqr-2fwp/GHSA-4fr8-gmqr-2fwp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fr8-gmqr-2fwp", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-30319" + ], + "details": "Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30319" + }, + { + "type": "WEB", + "url": "https://github.com/wliang6/ChatEngine/blame/fded8e710ad59f816867ad47d7fc4862f6502f3e/src/chatbotapp/LoginServlet.java#L30:L40" + }, + { + "type": "WEB", + "url": "https://payatu.com/advisory/cross-site-scripting-xxs-vulnerability-in-wliang6-chatengine/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5h7r-g3h4-hr2v/GHSA-5h7r-g3h4-hr2v.json b/advisories/unreviewed/2023/07/GHSA-5h7r-g3h4-hr2v/GHSA-5h7r-g3h4-hr2v.json new file mode 100644 index 00000000000..1c1afaf2c7a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5h7r-g3h4-hr2v/GHSA-5h7r-g3h4-hr2v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h7r-g3h4-hr2v", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-3528" + ], + "details": "A vulnerability was found in ThinuTech ThinuCMS 1.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument cat_id leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-233252.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3528" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233252" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-77v2-mcx8-5hqm/GHSA-77v2-mcx8-5hqm.json b/advisories/unreviewed/2023/07/GHSA-77v2-mcx8-5hqm/GHSA-77v2-mcx8-5hqm.json new file mode 100644 index 00000000000..6e5fa01fbe3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-77v2-mcx8-5hqm/GHSA-77v2-mcx8-5hqm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77v2-mcx8-5hqm", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-34192" + ], + "details": "Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34192" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7jq8-885h-574r/GHSA-7jq8-885h-574r.json b/advisories/unreviewed/2023/07/GHSA-7jq8-885h-574r/GHSA-7jq8-885h-574r.json new file mode 100644 index 00000000000..fb15abadbdf --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7jq8-885h-574r/GHSA-7jq8-885h-574r.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jq8-885h-574r", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-37453" + ], + "details": "An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37453" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/000000000000c0ffe505fe86c9ca@google.com/T/" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/000000000000e56434059580f86e@google.com/T/" + }, + { + "type": "WEB", + "url": "https://syzkaller.appspot.com/bug?extid=18996170f8096c6174d0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gqf7-xh28-qhmw/GHSA-gqf7-xh28-qhmw.json b/advisories/unreviewed/2023/07/GHSA-gqf7-xh28-qhmw/GHSA-gqf7-xh28-qhmw.json new file mode 100644 index 00000000000..d1629104a3e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gqf7-xh28-qhmw/GHSA-gqf7-xh28-qhmw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqf7-xh28-qhmw", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-30320" + ], + "details": "Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30320" + }, + { + "type": "WEB", + "url": "https://github.com/wliang6/ChatEngine/blob/master/src/chatbotapp/chatWindow.java#L71:L81" + }, + { + "type": "WEB", + "url": "https://payatu.com/advisory/cross-site-scripting-xss-vulnerability-in-wliang6-chatengine-allows-attackers-execute-arbitrary-code/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p2p8-49mr-gp6c/GHSA-p2p8-49mr-gp6c.json b/advisories/unreviewed/2023/07/GHSA-p2p8-49mr-gp6c/GHSA-p2p8-49mr-gp6c.json new file mode 100644 index 00000000000..fc437896fe0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p2p8-49mr-gp6c/GHSA-p2p8-49mr-gp6c.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2p8-49mr-gp6c", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-37454" + ], + "details": "An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37454" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/00000000000056e02f05dfb6e11a@google.com/T/" + }, + { + "type": "WEB", + "url": "https://syzkaller.appspot.com/bug?extid=26873a72980f8fa8bc55" + }, + { + "type": "WEB", + "url": "https://syzkaller.appspot.com/bug?extid=60864ed35b1073540d57" + }, + { + "type": "WEB", + "url": "https://syzkaller.appspot.com/bug?extid=61564e5023b7229ec85d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r49f-h295-cg9m/GHSA-r49f-h295-cg9m.json b/advisories/unreviewed/2023/07/GHSA-r49f-h295-cg9m/GHSA-r49f-h295-cg9m.json new file mode 100644 index 00000000000..c0def803eeb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r49f-h295-cg9m/GHSA-r49f-h295-cg9m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r49f-h295-cg9m", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-34193" + ], + "details": "File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via the ClientUploader function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34193" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vrrx-r38v-p3m7/GHSA-vrrx-r38v-p3m7.json b/advisories/unreviewed/2023/07/GHSA-vrrx-r38v-p3m7/GHSA-vrrx-r38v-p3m7.json new file mode 100644 index 00000000000..488621370ee --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vrrx-r38v-p3m7/GHSA-vrrx-r38v-p3m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrrx-r38v-p3m7", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-1298" + ], + "details": "ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1298" + }, + { + "type": "WEB", + "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1310230" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w663-c34c-q8hv/GHSA-w663-c34c-q8hv.json b/advisories/unreviewed/2023/07/GHSA-w663-c34c-q8hv/GHSA-w663-c34c-q8hv.json new file mode 100644 index 00000000000..45116277129 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w663-c34c-q8hv/GHSA-w663-c34c-q8hv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w663-c34c-q8hv", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-30321" + ], + "details": "Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30321" + }, + { + "type": "WEB", + "url": "https://github.com/wliang6/ChatEngine/blob/fded8e710ad59f816867ad47d7fc4862f6502f3e/src/chatbotapp/LoginServlet.java#L55:L64" + }, + { + "type": "WEB", + "url": "https://payatu.com/advisory/cross-site-scripting-xss-vulnerability-in-loginservlet-java-wliang6-chatengine-allows-attackers-to-execute-arbitrary-code/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json b/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json new file mode 100644 index 00000000000..bcb9b00bfdf --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w7wp-hxj3-m732/GHSA-w7wp-hxj3-m732.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7wp-hxj3-m732", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-29381" + ], + "details": "An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29381" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json b/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json new file mode 100644 index 00000000000..78ef6f01848 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wgxh-v2xq-j8vr/GHSA-wgxh-v2xq-j8vr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgxh-v2xq-j8vr", + "modified": "2023-07-06T18:30:51Z", + "published": "2023-07-06T18:30:51Z", + "aliases": [ + "CVE-2023-29382" + ], + "details": "An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29382" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file