Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-04 03:31:53 +00:00
parent cca8a7d918
commit db0e3f6529
139 changed files with 1160 additions and 288 deletions
@@ -253,6 +253,14 @@
"type": "WEB",
"url": "https://github.com/dotnet/announcements/issues/162"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZW4CBI26KSO3PRL3HLVVISXPPOYUHSXO/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT/"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22pr-mvmh-vgg5",
"modified": "2022-05-24T17:25:50Z",
"modified": "2024-01-04T03:30:33Z",
"published": "2022-05-24T17:25:50Z",
"aliases": [
"CVE-2020-1502"
],
"details": "An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24v5-4mc2-gcq9",
"modified": "2022-05-24T17:25:50Z",
"modified": "2024-01-04T03:30:33Z",
"published": "2022-05-24T17:25:50Z",
"aliases": [
"CVE-2020-1500"
],
"details": "A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1499, CVE-2020-1501.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25qw-9qm7-q8v7",
"modified": "2022-05-24T17:26:00Z",
"modified": "2024-01-04T03:30:37Z",
"published": "2022-05-24T17:26:00Z",
"aliases": [
"CVE-2020-1577"
],
"details": "An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28mp-5jqq-gwr6",
"modified": "2022-05-24T17:25:58Z",
"modified": "2024-01-04T03:30:36Z",
"published": "2022-05-24T17:25:58Z",
"aliases": [
"CVE-2020-1565"
],
"details": "An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c4m-3h92-jwwp",
"modified": "2022-05-24T17:25:49Z",
"modified": "2024-01-04T03:30:33Z",
"published": "2022-05-24T17:25:49Z",
"aliases": [
"CVE-2020-1483"
],
"details": "A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Memory Corruption Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cj6-37mq-778q",
"modified": "2022-05-24T17:25:58Z",
"modified": "2024-01-04T03:30:36Z",
"published": "2022-05-24T17:25:58Z",
"aliases": [
"CVE-2020-1563"
],
"details": "A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p3p-3j6c-h3fv",
"modified": "2022-05-24T17:25:51Z",
"modified": "2024-01-04T03:30:34Z",
"published": "2022-05-24T17:25:51Z",
"aliases": [
"CVE-2020-1512"
],
"details": "An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Information Disclosure Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-338q-vjff-j9cr",
"modified": "2022-05-24T17:25:54Z",
"modified": "2024-01-04T03:30:34Z",
"published": "2022-05-24T17:25:54Z",
"aliases": [
"CVE-2020-1536"
],
"details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34qp-h26w-rh76",
"modified": "2022-05-24T17:25:50Z",
"modified": "2024-01-04T03:30:34Z",
"published": "2022-05-24T17:25:50Z",
"aliases": [
"CVE-2020-1511"
],
"details": "An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35v6-2x4q-9wxq",
"modified": "2022-05-24T17:25:51Z",
"modified": "2024-01-04T03:30:34Z",
"published": "2022-05-24T17:25:51Z",
"aliases": [
"CVE-2020-1510"
],
"details": "An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38w2-hqmc-w8j8",
"modified": "2022-05-24T17:25:56Z",
"modified": "2024-01-04T03:30:36Z",
"published": "2022-05-24T17:25:56Z",
"aliases": [
"CVE-2020-1561"
],
"details": "A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1562.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3fm7-mwcq-hr7j",
"modified": "2022-05-24T17:25:55Z",
"modified": "2024-01-04T03:30:35Z",
"published": "2022-05-24T17:25:55Z",
"aliases": [
"CVE-2020-1551"
],
"details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qr6-g6hh-j6wj",
"modified": "2022-05-24T17:25:51Z",
"modified": "2024-01-04T03:30:34Z",
"published": "2022-05-24T17:25:51Z",
"aliases": [
"CVE-2020-1515"
],
"details": "An elevation of privilege vulnerability exists when the Windows Telephony Server improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Telephony Server Elevation of Privilege Vulnerability'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-424x-wf7g-f967",
"modified": "2022-05-24T17:25:56Z",
"modified": "2024-01-04T03:30:35Z",
"published": "2022-05-24T17:25:56Z",
"aliases": [
"CVE-2020-1555"
],
"details": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1380, CVE-2020-1570.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-434x-f5f5-g62j",
"modified": "2022-05-24T17:25:46Z",
"modified": "2024-01-04T03:30:32Z",
"published": "2022-05-24T17:25:46Z",
"aliases": [
"CVE-2020-1470"
],
"details": "An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1484, CVE-2020-1516.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-454g-5jw2-mrmh",
"modified": "2022-05-24T17:26:01Z",
"modified": "2024-01-04T03:30:37Z",
"published": "2022-05-24T17:26:01Z",
"aliases": [
"CVE-2020-1585"
],
"details": "A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1560, CVE-2020-1574.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48m2-ccvh-ph6c",
"modified": "2022-05-24T17:25:54Z",
"modified": "2024-01-04T03:30:34Z",
"published": "2022-05-24T17:25:54Z",
"aliases": [
"CVE-2020-1535"
],
"details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48x7-3977-wh2q",
"modified": "2022-05-24T17:25:55Z",
"modified": "2024-01-04T03:30:36Z",
"published": "2022-05-24T17:25:55Z",
"aliases": [
"CVE-2020-1560"
],
"details": "A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1574, CVE-2020-1585.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-493h-gp3v-m2v5",
"modified": "2022-05-24T17:25:50Z",
"modified": "2024-01-04T03:30:33Z",
"published": "2022-05-24T17:25:50Z",
"aliases": [
"CVE-2020-1499"
],
"details": "A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1500, CVE-2020-1501.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [

Some files were not shown because too many files have changed in this diff Show More