diff --git a/advisories/github-reviewed/2022/05/GHSA-f8qx-mjcq-wfgx/GHSA-f8qx-mjcq-wfgx.json b/advisories/github-reviewed/2022/05/GHSA-f8qx-mjcq-wfgx/GHSA-f8qx-mjcq-wfgx.json index 3fb0fc695f5..cda11f150a4 100644 --- a/advisories/github-reviewed/2022/05/GHSA-f8qx-mjcq-wfgx/GHSA-f8qx-mjcq-wfgx.json +++ b/advisories/github-reviewed/2022/05/GHSA-f8qx-mjcq-wfgx/GHSA-f8qx-mjcq-wfgx.json @@ -253,6 +253,14 @@ "type": "WEB", "url": "https://github.com/dotnet/announcements/issues/162" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZW4CBI26KSO3PRL3HLVVISXPPOYUHSXO/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT/" diff --git a/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json b/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json index 82edf30a7cc..1da22a95693 100644 --- a/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json +++ b/advisories/unreviewed/2022/05/GHSA-22pr-mvmh-vgg5/GHSA-22pr-mvmh-vgg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22pr-mvmh-vgg5", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1502" ], "details": "An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json b/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json index 79c141dfb0f..7be98f1aaf6 100644 --- a/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json +++ b/advisories/unreviewed/2022/05/GHSA-24v5-4mc2-gcq9/GHSA-24v5-4mc2-gcq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24v5-4mc2-gcq9", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1500" ], "details": "A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1499, CVE-2020-1501.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-25qw-9qm7-q8v7/GHSA-25qw-9qm7-q8v7.json b/advisories/unreviewed/2022/05/GHSA-25qw-9qm7-q8v7/GHSA-25qw-9qm7-q8v7.json index de4885da3f5..cfc32baf683 100644 --- a/advisories/unreviewed/2022/05/GHSA-25qw-9qm7-q8v7/GHSA-25qw-9qm7-q8v7.json +++ b/advisories/unreviewed/2022/05/GHSA-25qw-9qm7-q8v7/GHSA-25qw-9qm7-q8v7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25qw-9qm7-q8v7", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1577" ], "details": "An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-28mp-5jqq-gwr6/GHSA-28mp-5jqq-gwr6.json b/advisories/unreviewed/2022/05/GHSA-28mp-5jqq-gwr6/GHSA-28mp-5jqq-gwr6.json index 6d70a1a2d41..96dd5313901 100644 --- a/advisories/unreviewed/2022/05/GHSA-28mp-5jqq-gwr6/GHSA-28mp-5jqq-gwr6.json +++ b/advisories/unreviewed/2022/05/GHSA-28mp-5jqq-gwr6/GHSA-28mp-5jqq-gwr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28mp-5jqq-gwr6", - "modified": "2022-05-24T17:25:58Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:58Z", "aliases": [ "CVE-2020-1565" ], "details": "An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-2c4m-3h92-jwwp/GHSA-2c4m-3h92-jwwp.json b/advisories/unreviewed/2022/05/GHSA-2c4m-3h92-jwwp/GHSA-2c4m-3h92-jwwp.json index 089ed5d004d..5017d87e482 100644 --- a/advisories/unreviewed/2022/05/GHSA-2c4m-3h92-jwwp/GHSA-2c4m-3h92-jwwp.json +++ b/advisories/unreviewed/2022/05/GHSA-2c4m-3h92-jwwp/GHSA-2c4m-3h92-jwwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2c4m-3h92-jwwp", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1483" ], "details": "A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Memory Corruption Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-2cj6-37mq-778q/GHSA-2cj6-37mq-778q.json b/advisories/unreviewed/2022/05/GHSA-2cj6-37mq-778q/GHSA-2cj6-37mq-778q.json index ab7e25b57ba..d100c721649 100644 --- a/advisories/unreviewed/2022/05/GHSA-2cj6-37mq-778q/GHSA-2cj6-37mq-778q.json +++ b/advisories/unreviewed/2022/05/GHSA-2cj6-37mq-778q/GHSA-2cj6-37mq-778q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2cj6-37mq-778q", - "modified": "2022-05-24T17:25:58Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:58Z", "aliases": [ "CVE-2020-1563" ], "details": "A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-2p3p-3j6c-h3fv/GHSA-2p3p-3j6c-h3fv.json b/advisories/unreviewed/2022/05/GHSA-2p3p-3j6c-h3fv/GHSA-2p3p-3j6c-h3fv.json index deb9942653b..24730ce7cbe 100644 --- a/advisories/unreviewed/2022/05/GHSA-2p3p-3j6c-h3fv/GHSA-2p3p-3j6c-h3fv.json +++ b/advisories/unreviewed/2022/05/GHSA-2p3p-3j6c-h3fv/GHSA-2p3p-3j6c-h3fv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2p3p-3j6c-h3fv", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1512" ], "details": "An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-338q-vjff-j9cr/GHSA-338q-vjff-j9cr.json b/advisories/unreviewed/2022/05/GHSA-338q-vjff-j9cr/GHSA-338q-vjff-j9cr.json index c1b5c19cac4..6b2a38ee396 100644 --- a/advisories/unreviewed/2022/05/GHSA-338q-vjff-j9cr/GHSA-338q-vjff-j9cr.json +++ b/advisories/unreviewed/2022/05/GHSA-338q-vjff-j9cr/GHSA-338q-vjff-j9cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-338q-vjff-j9cr", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1536" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-34qp-h26w-rh76/GHSA-34qp-h26w-rh76.json b/advisories/unreviewed/2022/05/GHSA-34qp-h26w-rh76/GHSA-34qp-h26w-rh76.json index 9102283af95..c42723a108b 100644 --- a/advisories/unreviewed/2022/05/GHSA-34qp-h26w-rh76/GHSA-34qp-h26w-rh76.json +++ b/advisories/unreviewed/2022/05/GHSA-34qp-h26w-rh76/GHSA-34qp-h26w-rh76.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34qp-h26w-rh76", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1511" ], "details": "An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-35v6-2x4q-9wxq/GHSA-35v6-2x4q-9wxq.json b/advisories/unreviewed/2022/05/GHSA-35v6-2x4q-9wxq/GHSA-35v6-2x4q-9wxq.json index e7a4f9271e4..bd1fe0c4754 100644 --- a/advisories/unreviewed/2022/05/GHSA-35v6-2x4q-9wxq/GHSA-35v6-2x4q-9wxq.json +++ b/advisories/unreviewed/2022/05/GHSA-35v6-2x4q-9wxq/GHSA-35v6-2x4q-9wxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35v6-2x4q-9wxq", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1510" ], "details": "An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-38w2-hqmc-w8j8/GHSA-38w2-hqmc-w8j8.json b/advisories/unreviewed/2022/05/GHSA-38w2-hqmc-w8j8/GHSA-38w2-hqmc-w8j8.json index f065b33f063..3ac2762d3e4 100644 --- a/advisories/unreviewed/2022/05/GHSA-38w2-hqmc-w8j8/GHSA-38w2-hqmc-w8j8.json +++ b/advisories/unreviewed/2022/05/GHSA-38w2-hqmc-w8j8/GHSA-38w2-hqmc-w8j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38w2-hqmc-w8j8", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1561" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1562.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-3fm7-mwcq-hr7j/GHSA-3fm7-mwcq-hr7j.json b/advisories/unreviewed/2022/05/GHSA-3fm7-mwcq-hr7j/GHSA-3fm7-mwcq-hr7j.json index d328e89738d..e361b20db62 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fm7-mwcq-hr7j/GHSA-3fm7-mwcq-hr7j.json +++ b/advisories/unreviewed/2022/05/GHSA-3fm7-mwcq-hr7j/GHSA-3fm7-mwcq-hr7j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3fm7-mwcq-hr7j", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1551" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-3qr6-g6hh-j6wj/GHSA-3qr6-g6hh-j6wj.json b/advisories/unreviewed/2022/05/GHSA-3qr6-g6hh-j6wj/GHSA-3qr6-g6hh-j6wj.json index 5548795d62f..2aa2b490d26 100644 --- a/advisories/unreviewed/2022/05/GHSA-3qr6-g6hh-j6wj/GHSA-3qr6-g6hh-j6wj.json +++ b/advisories/unreviewed/2022/05/GHSA-3qr6-g6hh-j6wj/GHSA-3qr6-g6hh-j6wj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qr6-g6hh-j6wj", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1515" ], "details": "An elevation of privilege vulnerability exists when the Windows Telephony Server improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Telephony Server Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-424x-wf7g-f967/GHSA-424x-wf7g-f967.json b/advisories/unreviewed/2022/05/GHSA-424x-wf7g-f967/GHSA-424x-wf7g-f967.json index e589446d0da..9f0cfc15e6c 100644 --- a/advisories/unreviewed/2022/05/GHSA-424x-wf7g-f967/GHSA-424x-wf7g-f967.json +++ b/advisories/unreviewed/2022/05/GHSA-424x-wf7g-f967/GHSA-424x-wf7g-f967.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-424x-wf7g-f967", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1555" ], "details": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1380, CVE-2020-1570.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-434x-f5f5-g62j/GHSA-434x-f5f5-g62j.json b/advisories/unreviewed/2022/05/GHSA-434x-f5f5-g62j/GHSA-434x-f5f5-g62j.json index 2bd50dd5b88..64b0988a0a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-434x-f5f5-g62j/GHSA-434x-f5f5-g62j.json +++ b/advisories/unreviewed/2022/05/GHSA-434x-f5f5-g62j/GHSA-434x-f5f5-g62j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-434x-f5f5-g62j", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1470" ], "details": "An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1484, CVE-2020-1516.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-454g-5jw2-mrmh/GHSA-454g-5jw2-mrmh.json b/advisories/unreviewed/2022/05/GHSA-454g-5jw2-mrmh/GHSA-454g-5jw2-mrmh.json index 22b3cbb00d8..e06df0ac102 100644 --- a/advisories/unreviewed/2022/05/GHSA-454g-5jw2-mrmh/GHSA-454g-5jw2-mrmh.json +++ b/advisories/unreviewed/2022/05/GHSA-454g-5jw2-mrmh/GHSA-454g-5jw2-mrmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-454g-5jw2-mrmh", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1585" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1560, CVE-2020-1574.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-48m2-ccvh-ph6c/GHSA-48m2-ccvh-ph6c.json b/advisories/unreviewed/2022/05/GHSA-48m2-ccvh-ph6c/GHSA-48m2-ccvh-ph6c.json index 7a5b061f51e..c7abf1649bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-48m2-ccvh-ph6c/GHSA-48m2-ccvh-ph6c.json +++ b/advisories/unreviewed/2022/05/GHSA-48m2-ccvh-ph6c/GHSA-48m2-ccvh-ph6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48m2-ccvh-ph6c", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1535" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-48x7-3977-wh2q/GHSA-48x7-3977-wh2q.json b/advisories/unreviewed/2022/05/GHSA-48x7-3977-wh2q/GHSA-48x7-3977-wh2q.json index 4d7487082ff..14bc5a9f04a 100644 --- a/advisories/unreviewed/2022/05/GHSA-48x7-3977-wh2q/GHSA-48x7-3977-wh2q.json +++ b/advisories/unreviewed/2022/05/GHSA-48x7-3977-wh2q/GHSA-48x7-3977-wh2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48x7-3977-wh2q", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1560" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1574, CVE-2020-1585.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-493h-gp3v-m2v5/GHSA-493h-gp3v-m2v5.json b/advisories/unreviewed/2022/05/GHSA-493h-gp3v-m2v5/GHSA-493h-gp3v-m2v5.json index f82f1267a9c..5bf67f92490 100644 --- a/advisories/unreviewed/2022/05/GHSA-493h-gp3v-m2v5/GHSA-493h-gp3v-m2v5.json +++ b/advisories/unreviewed/2022/05/GHSA-493h-gp3v-m2v5/GHSA-493h-gp3v-m2v5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-493h-gp3v-m2v5", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1499" ], "details": "A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1500, CVE-2020-1501.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json b/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json index ad7b9d4f2d6..e0e067268da 100644 --- a/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json +++ b/advisories/unreviewed/2022/05/GHSA-4m6w-c9j7-h7cg/GHSA-4m6w-c9j7-h7cg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4m6w-c9j7-h7cg", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1531" ], "details": "An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Accounts Control Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-4q3c-h85r-3g9j/GHSA-4q3c-h85r-3g9j.json b/advisories/unreviewed/2022/05/GHSA-4q3c-h85r-3g9j/GHSA-4q3c-h85r-3g9j.json index 7cbd209f7cf..a7edf9df145 100644 --- a/advisories/unreviewed/2022/05/GHSA-4q3c-h85r-3g9j/GHSA-4q3c-h85r-3g9j.json +++ b/advisories/unreviewed/2022/05/GHSA-4q3c-h85r-3g9j/GHSA-4q3c-h85r-3g9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4q3c-h85r-3g9j", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1549" ], "details": "An elevation of privilege vulnerability exists when the Windows CDP User Components improperly handle memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CDP User Components Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1550.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-4x77-w84f-4qch/GHSA-4x77-w84f-4qch.json b/advisories/unreviewed/2022/05/GHSA-4x77-w84f-4qch/GHSA-4x77-w84f-4qch.json index f61e7328703..efcb009d3d3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4x77-w84f-4qch/GHSA-4x77-w84f-4qch.json +++ b/advisories/unreviewed/2022/05/GHSA-4x77-w84f-4qch/GHSA-4x77-w84f-4qch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x77-w84f-4qch", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1558" ], "details": "A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1473, CVE-2020-1557, CVE-2020-1564.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json b/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json index 96ac27c1eb0..d2b66e2d775 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json +++ b/advisories/unreviewed/2022/05/GHSA-5c27-m4xg-q78c/GHSA-5c27-m4xg-q78c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5c27-m4xg-q78c", - "modified": "2022-05-24T17:25:53Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:53Z", "aliases": [ "CVE-2020-1526" ], "details": "An elevation of privilege vulnerability exists when the Windows Network Connection Broker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Connection Broker Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-5hgp-4qjx-wghq/GHSA-5hgp-4qjx-wghq.json b/advisories/unreviewed/2022/05/GHSA-5hgp-4qjx-wghq/GHSA-5hgp-4qjx-wghq.json index 6b8bbcda86d..b3d9a1f7d4d 100644 --- a/advisories/unreviewed/2022/05/GHSA-5hgp-4qjx-wghq/GHSA-5hgp-4qjx-wghq.json +++ b/advisories/unreviewed/2022/05/GHSA-5hgp-4qjx-wghq/GHSA-5hgp-4qjx-wghq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hgp-4qjx-wghq", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1550" ], "details": "An elevation of privilege vulnerability exists when the Windows CDP User Components improperly handle memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CDP User Components Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1549.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-65fm-xp7m-qw2x/GHSA-65fm-xp7m-qw2x.json b/advisories/unreviewed/2022/05/GHSA-65fm-xp7m-qw2x/GHSA-65fm-xp7m-qw2x.json index 30f5b4e5931..ee61eec6b06 100644 --- a/advisories/unreviewed/2022/05/GHSA-65fm-xp7m-qw2x/GHSA-65fm-xp7m-qw2x.json +++ b/advisories/unreviewed/2022/05/GHSA-65fm-xp7m-qw2x/GHSA-65fm-xp7m-qw2x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-65fm-xp7m-qw2x", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1564" ], "details": "A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1473, CVE-2020-1557, CVE-2020-1558.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6824-47qf-3pvf/GHSA-6824-47qf-3pvf.json b/advisories/unreviewed/2022/05/GHSA-6824-47qf-3pvf/GHSA-6824-47qf-3pvf.json index 83812894cf3..3001ed7e77e 100644 --- a/advisories/unreviewed/2022/05/GHSA-6824-47qf-3pvf/GHSA-6824-47qf-3pvf.json +++ b/advisories/unreviewed/2022/05/GHSA-6824-47qf-3pvf/GHSA-6824-47qf-3pvf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6824-47qf-3pvf", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1495" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1494, CVE-2020-1496, CVE-2020-1498, CVE-2020-1504.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json b/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json index 10944d1eb7d..4a6595d2303 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json +++ b/advisories/unreviewed/2022/05/GHSA-6mch-9mqr-vw5g/GHSA-6mch-9mqr-vw5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mch-9mqr-vw5g", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1525" ], "details": "A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1379, CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1554.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-6pcm-x8v9-rgxq/GHSA-6pcm-x8v9-rgxq.json b/advisories/unreviewed/2022/05/GHSA-6pcm-x8v9-rgxq/GHSA-6pcm-x8v9-rgxq.json index ae670f31ed6..5a708580712 100644 --- a/advisories/unreviewed/2022/05/GHSA-6pcm-x8v9-rgxq/GHSA-6pcm-x8v9-rgxq.json +++ b/advisories/unreviewed/2022/05/GHSA-6pcm-x8v9-rgxq/GHSA-6pcm-x8v9-rgxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pcm-x8v9-rgxq", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1455" ], "details": "A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files, aka 'Microsoft SQL Server Management Studio Denial of Service Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-6v82-h24c-ccc8/GHSA-6v82-h24c-ccc8.json b/advisories/unreviewed/2022/05/GHSA-6v82-h24c-ccc8/GHSA-6v82-h24c-ccc8.json index 1b07c7ca35c..190d1b42192 100644 --- a/advisories/unreviewed/2022/05/GHSA-6v82-h24c-ccc8/GHSA-6v82-h24c-ccc8.json +++ b/advisories/unreviewed/2022/05/GHSA-6v82-h24c-ccc8/GHSA-6v82-h24c-ccc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6v82-h24c-ccc8", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1547" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-728c-44hv-wjw2/GHSA-728c-44hv-wjw2.json b/advisories/unreviewed/2022/05/GHSA-728c-44hv-wjw2/GHSA-728c-44hv-wjw2.json index 1438d8424e6..084519b1613 100644 --- a/advisories/unreviewed/2022/05/GHSA-728c-44hv-wjw2/GHSA-728c-44hv-wjw2.json +++ b/advisories/unreviewed/2022/05/GHSA-728c-44hv-wjw2/GHSA-728c-44hv-wjw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-728c-44hv-wjw2", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1522" ], "details": "An elevation of privilege vulnerability exists when the Windows Speech Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Speech Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1521.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-75g4-7255-wxgc/GHSA-75g4-7255-wxgc.json b/advisories/unreviewed/2022/05/GHSA-75g4-7255-wxgc/GHSA-75g4-7255-wxgc.json index 7d818a10762..45714b93b14 100644 --- a/advisories/unreviewed/2022/05/GHSA-75g4-7255-wxgc/GHSA-75g4-7255-wxgc.json +++ b/advisories/unreviewed/2022/05/GHSA-75g4-7255-wxgc/GHSA-75g4-7255-wxgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75g4-7255-wxgc", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1464" ], "details": "A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -26,6 +29,10 @@ "type": "WEB", "url": "https://krebsonsecurity.com/2020/08/microsoft-put-off-fixing-zero-day-for-2-years/" }, + { + "type": "WEB", + "url": "https://medium.com/%40TalBeerySec/glueball-the-story-of-cve-2020-1464-50091a1f98bd" + }, { "type": "WEB", "url": "https://medium.com/@TalBeerySec/glueball-the-story-of-cve-2020-1464-50091a1f98bd" @@ -37,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-774c-xc8q-c8cj/GHSA-774c-xc8q-c8cj.json b/advisories/unreviewed/2022/05/GHSA-774c-xc8q-c8cj/GHSA-774c-xc8q-c8cj.json index 31c89a87190..7af0ae8f136 100644 --- a/advisories/unreviewed/2022/05/GHSA-774c-xc8q-c8cj/GHSA-774c-xc8q-c8cj.json +++ b/advisories/unreviewed/2022/05/GHSA-774c-xc8q-c8cj/GHSA-774c-xc8q-c8cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-774c-xc8q-c8cj", - "modified": "2022-05-24T17:25:45Z", + "modified": "2024-01-04T03:30:31Z", "published": "2022-05-24T17:25:45Z", "aliases": [ "CVE-2020-1182" ], "details": "A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11, aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-7hfr-27xh-fr6q/GHSA-7hfr-27xh-fr6q.json b/advisories/unreviewed/2022/05/GHSA-7hfr-27xh-fr6q/GHSA-7hfr-27xh-fr6q.json index 30155ca2d99..48595f13f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hfr-27xh-fr6q/GHSA-7hfr-27xh-fr6q.json +++ b/advisories/unreviewed/2022/05/GHSA-7hfr-27xh-fr6q/GHSA-7hfr-27xh-fr6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hfr-27xh-fr6q", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1544" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-7rr2-mfr6-x27q/GHSA-7rr2-mfr6-x27q.json b/advisories/unreviewed/2022/05/GHSA-7rr2-mfr6-x27q/GHSA-7rr2-mfr6-x27q.json index d3d16288ff7..1bf66ff1b8d 100644 --- a/advisories/unreviewed/2022/05/GHSA-7rr2-mfr6-x27q/GHSA-7rr2-mfr6-x27q.json +++ b/advisories/unreviewed/2022/05/GHSA-7rr2-mfr6-x27q/GHSA-7rr2-mfr6-x27q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rr2-mfr6-x27q", - "modified": "2022-05-24T17:25:48Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:48Z", "aliases": [ "CVE-2020-1485" ], "details": "An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory, aka 'Windows Image Acquisition Service Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1474.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8495-5w8h-83c5/GHSA-8495-5w8h-83c5.json b/advisories/unreviewed/2022/05/GHSA-8495-5w8h-83c5/GHSA-8495-5w8h-83c5.json index c26f64ecad3..a6fe151d1fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-8495-5w8h-83c5/GHSA-8495-5w8h-83c5.json +++ b/advisories/unreviewed/2022/05/GHSA-8495-5w8h-83c5/GHSA-8495-5w8h-83c5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8495-5w8h-83c5", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1467" ], "details": "An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-86jr-j4g9-rv52/GHSA-86jr-j4g9-rv52.json b/advisories/unreviewed/2022/05/GHSA-86jr-j4g9-rv52/GHSA-86jr-j4g9-rv52.json index 3ff09094310..57ba49d550b 100644 --- a/advisories/unreviewed/2022/05/GHSA-86jr-j4g9-rv52/GHSA-86jr-j4g9-rv52.json +++ b/advisories/unreviewed/2022/05/GHSA-86jr-j4g9-rv52/GHSA-86jr-j4g9-rv52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-86jr-j4g9-rv52", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1498" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1494, CVE-2020-1495, CVE-2020-1496, CVE-2020-1504.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json b/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json index 16bbf2560c1..4e45eda145f 100644 --- a/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json +++ b/advisories/unreviewed/2022/05/GHSA-87gf-f47g-jf9m/GHSA-87gf-f47g-jf9m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87gf-f47g-jf9m", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1527" ], "details": "An elevation of privilege vulnerability exists when the Windows Custom Protocol Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Custom Protocol Engine Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8m4h-93rx-x9x3/GHSA-8m4h-93rx-x9x3.json b/advisories/unreviewed/2022/05/GHSA-8m4h-93rx-x9x3/GHSA-8m4h-93rx-x9x3.json index 455f3ccf8dc..79f6058f0fd 100644 --- a/advisories/unreviewed/2022/05/GHSA-8m4h-93rx-x9x3/GHSA-8m4h-93rx-x9x3.json +++ b/advisories/unreviewed/2022/05/GHSA-8m4h-93rx-x9x3/GHSA-8m4h-93rx-x9x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8m4h-93rx-x9x3", - "modified": "2022-05-24T17:25:47Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:47Z", "aliases": [ "CVE-2020-1476" ], "details": "An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files, aka 'ASP.NET and .NET Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8qv6-hpmq-2qqm/GHSA-8qv6-hpmq-2qqm.json b/advisories/unreviewed/2022/05/GHSA-8qv6-hpmq-2qqm/GHSA-8qv6-hpmq-2qqm.json index 6d5962bf712..665c610b4f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-8qv6-hpmq-2qqm/GHSA-8qv6-hpmq-2qqm.json +++ b/advisories/unreviewed/2022/05/GHSA-8qv6-hpmq-2qqm/GHSA-8qv6-hpmq-2qqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qv6-hpmq-2qqm", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1584" ], "details": "An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrslvr.dll Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8vxj-2f8q-fqx4/GHSA-8vxj-2f8q-fqx4.json b/advisories/unreviewed/2022/05/GHSA-8vxj-2f8q-fqx4/GHSA-8vxj-2f8q-fqx4.json index 41acdcef97b..67ca21561f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vxj-2f8q-fqx4/GHSA-8vxj-2f8q-fqx4.json +++ b/advisories/unreviewed/2022/05/GHSA-8vxj-2f8q-fqx4/GHSA-8vxj-2f8q-fqx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vxj-2f8q-fqx4", - "modified": "2022-05-24T17:25:45Z", + "modified": "2024-01-04T03:30:31Z", "published": "2022-05-24T17:25:45Z", "aliases": [ "CVE-2020-1339" ], "details": "A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects, aka 'Windows Media Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json b/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json index fab7eda0cef..04e41d62f21 100644 --- a/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json +++ b/advisories/unreviewed/2022/05/GHSA-8w6h-27hq-jp76/GHSA-8w6h-27hq-jp76.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w6h-27hq-jp76", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1533" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1556.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8wq4-p7h6-5j9p/GHSA-8wq4-p7h6-5j9p.json b/advisories/unreviewed/2022/05/GHSA-8wq4-p7h6-5j9p/GHSA-8wq4-p7h6-5j9p.json index c86130bba5b..d1d96958f03 100644 --- a/advisories/unreviewed/2022/05/GHSA-8wq4-p7h6-5j9p/GHSA-8wq4-p7h6-5j9p.json +++ b/advisories/unreviewed/2022/05/GHSA-8wq4-p7h6-5j9p/GHSA-8wq4-p7h6-5j9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wq4-p7h6-5j9p", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1517" ], "details": "An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows File Server Resource Management Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1518.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-97j9-x88r-5g6v/GHSA-97j9-x88r-5g6v.json b/advisories/unreviewed/2022/05/GHSA-97j9-x88r-5g6v/GHSA-97j9-x88r-5g6v.json index ff712be653b..0c796667f0b 100644 --- a/advisories/unreviewed/2022/05/GHSA-97j9-x88r-5g6v/GHSA-97j9-x88r-5g6v.json +++ b/advisories/unreviewed/2022/05/GHSA-97j9-x88r-5g6v/GHSA-97j9-x88r-5g6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97j9-x88r-5g6v", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1583" ], "details": "An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1503.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-97m2-pg4j-9jcw/GHSA-97m2-pg4j-9jcw.json b/advisories/unreviewed/2022/05/GHSA-97m2-pg4j-9jcw/GHSA-97m2-pg4j-9jcw.json index 7e25fefa4ce..77a863fb496 100644 --- a/advisories/unreviewed/2022/05/GHSA-97m2-pg4j-9jcw/GHSA-97m2-pg4j-9jcw.json +++ b/advisories/unreviewed/2022/05/GHSA-97m2-pg4j-9jcw/GHSA-97m2-pg4j-9jcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97m2-pg4j-9jcw", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1486" ], "details": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1417, CVE-2020-1566.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-9895-993j-hjwm/GHSA-9895-993j-hjwm.json b/advisories/unreviewed/2022/05/GHSA-9895-993j-hjwm/GHSA-9895-993j-hjwm.json index 40b86458ed1..2bd64d8a1e7 100644 --- a/advisories/unreviewed/2022/05/GHSA-9895-993j-hjwm/GHSA-9895-993j-hjwm.json +++ b/advisories/unreviewed/2022/05/GHSA-9895-993j-hjwm/GHSA-9895-993j-hjwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9895-993j-hjwm", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1582" ], "details": "A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-9fj9-5r8v-mh44/GHSA-9fj9-5r8v-mh44.json b/advisories/unreviewed/2022/05/GHSA-9fj9-5r8v-mh44/GHSA-9fj9-5r8v-mh44.json index 23b944d0629..6c4057080fa 100644 --- a/advisories/unreviewed/2022/05/GHSA-9fj9-5r8v-mh44/GHSA-9fj9-5r8v-mh44.json +++ b/advisories/unreviewed/2022/05/GHSA-9fj9-5r8v-mh44/GHSA-9fj9-5r8v-mh44.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fj9-5r8v-mh44", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1466" ], "details": "A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-9mv8-62q2-x7p7/GHSA-9mv8-62q2-x7p7.json b/advisories/unreviewed/2022/05/GHSA-9mv8-62q2-x7p7/GHSA-9mv8-62q2-x7p7.json index df46a389dc8..3ad265aa8f0 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mv8-62q2-x7p7/GHSA-9mv8-62q2-x7p7.json +++ b/advisories/unreviewed/2022/05/GHSA-9mv8-62q2-x7p7/GHSA-9mv8-62q2-x7p7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mv8-62q2-x7p7", - "modified": "2022-05-24T17:25:45Z", + "modified": "2024-01-04T03:30:31Z", "published": "2022-05-24T17:25:45Z", "aliases": [ "CVE-2020-1337" ], "details": "An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-367" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-c4v2-jmhg-vhq8/GHSA-c4v2-jmhg-vhq8.json b/advisories/unreviewed/2022/05/GHSA-c4v2-jmhg-vhq8/GHSA-c4v2-jmhg-vhq8.json index 5e9dc91316f..b9df9dd0e1b 100644 --- a/advisories/unreviewed/2022/05/GHSA-c4v2-jmhg-vhq8/GHSA-c4v2-jmhg-vhq8.json +++ b/advisories/unreviewed/2022/05/GHSA-c4v2-jmhg-vhq8/GHSA-c4v2-jmhg-vhq8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4v2-jmhg-vhq8", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1496" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1494, CVE-2020-1495, CVE-2020-1498, CVE-2020-1504.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-c94w-hqmm-2c97/GHSA-c94w-hqmm-2c97.json b/advisories/unreviewed/2022/05/GHSA-c94w-hqmm-2c97/GHSA-c94w-hqmm-2c97.json index 7ab16a35e9f..fdbb828cf54 100644 --- a/advisories/unreviewed/2022/05/GHSA-c94w-hqmm-2c97/GHSA-c94w-hqmm-2c97.json +++ b/advisories/unreviewed/2022/05/GHSA-c94w-hqmm-2c97/GHSA-c94w-hqmm-2c97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c94w-hqmm-2c97", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1524" ], "details": "An elevation of privilege vulnerability exists when the Windows Speech Shell Components improperly handle memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Speech Shell Components Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cjp5-p4x3-x7jg/GHSA-cjp5-p4x3-x7jg.json b/advisories/unreviewed/2022/05/GHSA-cjp5-p4x3-x7jg/GHSA-cjp5-p4x3-x7jg.json index 572ecdae539..2ac6153a871 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjp5-p4x3-x7jg/GHSA-cjp5-p4x3-x7jg.json +++ b/advisories/unreviewed/2022/05/GHSA-cjp5-p4x3-x7jg/GHSA-cjp5-p4x3-x7jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjp5-p4x3-x7jg", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1459" ], "details": "An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation, aka 'Windows ARM Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-203" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json b/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json index f28f3f36e69..27754e45344 100644 --- a/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json +++ b/advisories/unreviewed/2022/05/GHSA-cp2r-rvgm-x6rh/GHSA-cp2r-rvgm-x6rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cp2r-rvgm-x6rh", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1516" ], "details": "An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1470, CVE-2020-1484.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cqx5-p2pr-988q/GHSA-cqx5-p2pr-988q.json b/advisories/unreviewed/2022/05/GHSA-cqx5-p2pr-988q/GHSA-cqx5-p2pr-988q.json index d38931dfd47..882126580f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqx5-p2pr-988q/GHSA-cqx5-p2pr-988q.json +++ b/advisories/unreviewed/2022/05/GHSA-cqx5-p2pr-988q/GHSA-cqx5-p2pr-988q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqx5-p2pr-988q", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1568" ], "details": "A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cwm2-mgm4-98xx/GHSA-cwm2-mgm4-98xx.json b/advisories/unreviewed/2022/05/GHSA-cwm2-mgm4-98xx/GHSA-cwm2-mgm4-98xx.json index ded9430d421..1616bfd3f7b 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwm2-mgm4-98xx/GHSA-cwm2-mgm4-98xx.json +++ b/advisories/unreviewed/2022/05/GHSA-cwm2-mgm4-98xx/GHSA-cwm2-mgm4-98xx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwm2-mgm4-98xx", - "modified": "2022-05-24T17:25:48Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:48Z", "aliases": [ "CVE-2020-1489" ], "details": "An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1513.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-f9xw-vp24-h259/GHSA-f9xw-vp24-h259.json b/advisories/unreviewed/2022/05/GHSA-f9xw-vp24-h259/GHSA-f9xw-vp24-h259.json index b01f00a790c..fd8210e9704 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9xw-vp24-h259/GHSA-f9xw-vp24-h259.json +++ b/advisories/unreviewed/2022/05/GHSA-f9xw-vp24-h259/GHSA-f9xw-vp24-h259.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9xw-vp24-h259", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1542" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-ffgx-6737-mpr2/GHSA-ffgx-6737-mpr2.json b/advisories/unreviewed/2022/05/GHSA-ffgx-6737-mpr2/GHSA-ffgx-6737-mpr2.json index 7b141737c34..1475cd9b048 100644 --- a/advisories/unreviewed/2022/05/GHSA-ffgx-6737-mpr2/GHSA-ffgx-6737-mpr2.json +++ b/advisories/unreviewed/2022/05/GHSA-ffgx-6737-mpr2/GHSA-ffgx-6737-mpr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffgx-6737-mpr2", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1567" ], "details": "A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-fg3v-hf2h-29r9/GHSA-fg3v-hf2h-29r9.json b/advisories/unreviewed/2022/05/GHSA-fg3v-hf2h-29r9/GHSA-fg3v-hf2h-29r9.json index 65933e2e4d0..bf1b0993358 100644 --- a/advisories/unreviewed/2022/05/GHSA-fg3v-hf2h-29r9/GHSA-fg3v-hf2h-29r9.json +++ b/advisories/unreviewed/2022/05/GHSA-fg3v-hf2h-29r9/GHSA-fg3v-hf2h-29r9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fg3v-hf2h-29r9", - "modified": "2022-05-24T17:25:57Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:57Z", "aliases": [ "CVE-2020-1562" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1561.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-fgwc-xm6v-j769/GHSA-fgwc-xm6v-j769.json b/advisories/unreviewed/2022/05/GHSA-fgwc-xm6v-j769/GHSA-fgwc-xm6v-j769.json index 84ffaa1ea63..6a3cb849f88 100644 --- a/advisories/unreviewed/2022/05/GHSA-fgwc-xm6v-j769/GHSA-fgwc-xm6v-j769.json +++ b/advisories/unreviewed/2022/05/GHSA-fgwc-xm6v-j769/GHSA-fgwc-xm6v-j769.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fgwc-xm6v-j769", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1553" ], "details": "An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-fwg6-66g7-28f5/GHSA-fwg6-66g7-28f5.json b/advisories/unreviewed/2022/05/GHSA-fwg6-66g7-28f5/GHSA-fwg6-66g7-28f5.json index 9485c39a5b8..08656c853e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-fwg6-66g7-28f5/GHSA-fwg6-66g7-28f5.json +++ b/advisories/unreviewed/2022/05/GHSA-fwg6-66g7-28f5/GHSA-fwg6-66g7-28f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fwg6-66g7-28f5", - "modified": "2022-05-24T17:25:45Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:45Z", "aliases": [ "CVE-2020-1383" ], "details": "An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled, aka 'Windows RRAS Service Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-g2qp-jch9-4f53/GHSA-g2qp-jch9-4f53.json b/advisories/unreviewed/2022/05/GHSA-g2qp-jch9-4f53/GHSA-g2qp-jch9-4f53.json index a6a3740f9c3..aece3b20774 100644 --- a/advisories/unreviewed/2022/05/GHSA-g2qp-jch9-4f53/GHSA-g2qp-jch9-4f53.json +++ b/advisories/unreviewed/2022/05/GHSA-g2qp-jch9-4f53/GHSA-g2qp-jch9-4f53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2qp-jch9-4f53", - "modified": "2022-05-24T17:25:48Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:48Z", "aliases": [ "CVE-2020-1477" ], "details": "A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1379, CVE-2020-1478, CVE-2020-1492, CVE-2020-1525, CVE-2020-1554.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-g3rh-644p-2xqv/GHSA-g3rh-644p-2xqv.json b/advisories/unreviewed/2022/05/GHSA-g3rh-644p-2xqv/GHSA-g3rh-644p-2xqv.json index b70288fbe14..055be5f60bb 100644 --- a/advisories/unreviewed/2022/05/GHSA-g3rh-644p-2xqv/GHSA-g3rh-644p-2xqv.json +++ b/advisories/unreviewed/2022/05/GHSA-g3rh-644p-2xqv/GHSA-g3rh-644p-2xqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3rh-644p-2xqv", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1541" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json b/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json index 1050347dad6..c5b7bd1cc37 100644 --- a/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json +++ b/advisories/unreviewed/2022/05/GHSA-g7cf-4hgh-v7qf/GHSA-g7cf-4hgh-v7qf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7cf-4hgh-v7qf", - "modified": "2022-05-24T17:25:53Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:53Z", "aliases": [ "CVE-2020-1537" ], "details": "An elevation of privilege vulnerability exists when the Windows Remote Access improperly handles file operations, aka 'Windows Remote Access Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1530.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-gc5h-xf3g-h5x4/GHSA-gc5h-xf3g-h5x4.json b/advisories/unreviewed/2022/05/GHSA-gc5h-xf3g-h5x4/GHSA-gc5h-xf3g-h5x4.json index e9cc6b90111..b436e0fcae3 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc5h-xf3g-h5x4/GHSA-gc5h-xf3g-h5x4.json +++ b/advisories/unreviewed/2022/05/GHSA-gc5h-xf3g-h5x4/GHSA-gc5h-xf3g-h5x4.json @@ -25,6 +25,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ST6X3A2XXYMGD4INR26DQ4FP4QSM753B/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAPQQZZAT4TG3XVRTAFV2Y3S7OAHFBUP/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/" diff --git a/advisories/unreviewed/2022/05/GHSA-gf86-frf5-frmh/GHSA-gf86-frf5-frmh.json b/advisories/unreviewed/2022/05/GHSA-gf86-frf5-frmh/GHSA-gf86-frf5-frmh.json index aebcdc12006..bc6419fcad9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf86-frf5-frmh/GHSA-gf86-frf5-frmh.json +++ b/advisories/unreviewed/2022/05/GHSA-gf86-frf5-frmh/GHSA-gf86-frf5-frmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gf86-frf5-frmh", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1487" ], "details": "An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-gvmp-f3pg-q7hj/GHSA-gvmp-f3pg-q7hj.json b/advisories/unreviewed/2022/05/GHSA-gvmp-f3pg-q7hj/GHSA-gvmp-f3pg-q7hj.json index e87b5eee529..fb190024d66 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvmp-f3pg-q7hj/GHSA-gvmp-f3pg-q7hj.json +++ b/advisories/unreviewed/2022/05/GHSA-gvmp-f3pg-q7hj/GHSA-gvmp-f3pg-q7hj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvmp-f3pg-q7hj", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1505" ], "details": "An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-gvwc-32h3-8jq6/GHSA-gvwc-32h3-8jq6.json b/advisories/unreviewed/2022/05/GHSA-gvwc-32h3-8jq6/GHSA-gvwc-32h3-8jq6.json index 6b46f5aa909..63d11aadbc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvwc-32h3-8jq6/GHSA-gvwc-32h3-8jq6.json +++ b/advisories/unreviewed/2022/05/GHSA-gvwc-32h3-8jq6/GHSA-gvwc-32h3-8jq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gvwc-32h3-8jq6", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1578" ], "details": "An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka 'Windows Kernel Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-gw5q-x3f2-7p39/GHSA-gw5q-x3f2-7p39.json b/advisories/unreviewed/2022/05/GHSA-gw5q-x3f2-7p39/GHSA-gw5q-x3f2-7p39.json index 06621f69ff8..119b5ca74e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-gw5q-x3f2-7p39/GHSA-gw5q-x3f2-7p39.json +++ b/advisories/unreviewed/2022/05/GHSA-gw5q-x3f2-7p39/GHSA-gw5q-x3f2-7p39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gw5q-x3f2-7p39", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1519" ], "details": "An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1538.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h3cx-2wcp-gffv/GHSA-h3cx-2wcp-gffv.json b/advisories/unreviewed/2022/05/GHSA-h3cx-2wcp-gffv/GHSA-h3cx-2wcp-gffv.json index bc87a4a883a..7e86d656aac 100644 --- a/advisories/unreviewed/2022/05/GHSA-h3cx-2wcp-gffv/GHSA-h3cx-2wcp-gffv.json +++ b/advisories/unreviewed/2022/05/GHSA-h3cx-2wcp-gffv/GHSA-h3cx-2wcp-gffv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3cx-2wcp-gffv", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1579" ], "details": "An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Function Discovery SSDP Provider Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h43f-9gcw-qmpf/GHSA-h43f-9gcw-qmpf.json b/advisories/unreviewed/2022/05/GHSA-h43f-9gcw-qmpf/GHSA-h43f-9gcw-qmpf.json index d4e5b90144d..8fa49501f33 100644 --- a/advisories/unreviewed/2022/05/GHSA-h43f-9gcw-qmpf/GHSA-h43f-9gcw-qmpf.json +++ b/advisories/unreviewed/2022/05/GHSA-h43f-9gcw-qmpf/GHSA-h43f-9gcw-qmpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h43f-9gcw-qmpf", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1521" ], "details": "An elevation of privilege vulnerability exists when the Windows Speech Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Speech Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1522.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h59q-pcqf-7vwp/GHSA-h59q-pcqf-7vwp.json b/advisories/unreviewed/2022/05/GHSA-h59q-pcqf-7vwp/GHSA-h59q-pcqf-7vwp.json index f7ee9f817e3..70f7a940aa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-h59q-pcqf-7vwp/GHSA-h59q-pcqf-7vwp.json +++ b/advisories/unreviewed/2022/05/GHSA-h59q-pcqf-7vwp/GHSA-h59q-pcqf-7vwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h59q-pcqf-7vwp", - "modified": "2022-05-24T17:25:47Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:47Z", "aliases": [ "CVE-2020-1475" ], "details": "An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in memory, aka 'Windows Server Resource Management Service Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h86w-hh9w-5776/GHSA-h86w-hh9w-5776.json b/advisories/unreviewed/2022/05/GHSA-h86w-hh9w-5776/GHSA-h86w-hh9w-5776.json index a35b29e36b4..a445cb27002 100644 --- a/advisories/unreviewed/2022/05/GHSA-h86w-hh9w-5776/GHSA-h86w-hh9w-5776.json +++ b/advisories/unreviewed/2022/05/GHSA-h86w-hh9w-5776/GHSA-h86w-hh9w-5776.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h86w-hh9w-5776", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1504" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1494, CVE-2020-1495, CVE-2020-1496, CVE-2020-1498.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json b/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json index 536b6ad4fcc..bae7c717eef 100644 --- a/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json +++ b/advisories/unreviewed/2022/05/GHSA-hf48-cw5q-wjpm/GHSA-hf48-cw5q-wjpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf48-cw5q-wjpm", - "modified": "2022-05-24T17:25:53Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:53Z", "aliases": [ "CVE-2020-1530" ], "details": "An elevation of privilege vulnerability exists when Windows Remote Access improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Remote Access Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1537.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hg8m-5gg6-3vv9/GHSA-hg8m-5gg6-3vv9.json b/advisories/unreviewed/2022/05/GHSA-hg8m-5gg6-3vv9/GHSA-hg8m-5gg6-3vv9.json index 3bdc96c2781..3479a1d2dde 100644 --- a/advisories/unreviewed/2022/05/GHSA-hg8m-5gg6-3vv9/GHSA-hg8m-5gg6-3vv9.json +++ b/advisories/unreviewed/2022/05/GHSA-hg8m-5gg6-3vv9/GHSA-hg8m-5gg6-3vv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg8m-5gg6-3vv9", - "modified": "2022-05-24T17:25:44Z", + "modified": "2024-01-04T03:30:31Z", "published": "2022-05-24T17:25:44Z", "aliases": [ "CVE-2020-0604" ], "details": "A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hprw-5fj5-p822/GHSA-hprw-5fj5-p822.json b/advisories/unreviewed/2022/05/GHSA-hprw-5fj5-p822/GHSA-hprw-5fj5-p822.json index a9020b20f7d..b19f4ce5b39 100644 --- a/advisories/unreviewed/2022/05/GHSA-hprw-5fj5-p822/GHSA-hprw-5fj5-p822.json +++ b/advisories/unreviewed/2022/05/GHSA-hprw-5fj5-p822/GHSA-hprw-5fj5-p822.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hprw-5fj5-p822", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:31Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1379" ], "details": "A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1525, CVE-2020-1554.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hq4j-6h2x-588w/GHSA-hq4j-6h2x-588w.json b/advisories/unreviewed/2022/05/GHSA-hq4j-6h2x-588w/GHSA-hq4j-6h2x-588w.json index f514a25cbca..f0390fa8088 100644 --- a/advisories/unreviewed/2022/05/GHSA-hq4j-6h2x-588w/GHSA-hq4j-6h2x-588w.json +++ b/advisories/unreviewed/2022/05/GHSA-hq4j-6h2x-588w/GHSA-hq4j-6h2x-588w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq4j-6h2x-588w", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1501" ], "details": "A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1499, CVE-2020-1500.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-j6gj-p9mw-9wgg/GHSA-j6gj-p9mw-9wgg.json b/advisories/unreviewed/2022/05/GHSA-j6gj-p9mw-9wgg/GHSA-j6gj-p9mw-9wgg.json index dec6d040a24..cdd824ae8ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6gj-p9mw-9wgg/GHSA-j6gj-p9mw-9wgg.json +++ b/advisories/unreviewed/2022/05/GHSA-j6gj-p9mw-9wgg/GHSA-j6gj-p9mw-9wgg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6gj-p9mw-9wgg", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1573" ], "details": "A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1580.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-jqh5-2q9r-65gg/GHSA-jqh5-2q9r-65gg.json b/advisories/unreviewed/2022/05/GHSA-jqh5-2q9r-65gg/GHSA-jqh5-2q9r-65gg.json index 25a20743f94..593b9ef5641 100644 --- a/advisories/unreviewed/2022/05/GHSA-jqh5-2q9r-65gg/GHSA-jqh5-2q9r-65gg.json +++ b/advisories/unreviewed/2022/05/GHSA-jqh5-2q9r-65gg/GHSA-jqh5-2q9r-65gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqh5-2q9r-65gg", - "modified": "2022-05-24T17:25:48Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:48Z", "aliases": [ "CVE-2020-1479" ], "details": "An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-m8ff-4vvh-r9f2/GHSA-m8ff-4vvh-r9f2.json b/advisories/unreviewed/2022/05/GHSA-m8ff-4vvh-r9f2/GHSA-m8ff-4vvh-r9f2.json index 470fb98e36f..83a3b1a9a8e 100644 --- a/advisories/unreviewed/2022/05/GHSA-m8ff-4vvh-r9f2/GHSA-m8ff-4vvh-r9f2.json +++ b/advisories/unreviewed/2022/05/GHSA-m8ff-4vvh-r9f2/GHSA-m8ff-4vvh-r9f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m8ff-4vvh-r9f2", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1417" ], "details": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1486, CVE-2020-1566.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json b/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json index 0d1ffc31ac0..6f30cd12fa4 100644 --- a/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json +++ b/advisories/unreviewed/2022/05/GHSA-m93c-j7hg-hwmj/GHSA-m93c-j7hg-hwmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m93c-j7hg-hwmj", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1529" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1480.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json b/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json index 2dbee324fb9..be948bcc029 100644 --- a/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json +++ b/advisories/unreviewed/2022/05/GHSA-m942-g3j4-p4jh/GHSA-m942-g3j4-p4jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m942-g3j4-p4jh", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1538" ], "details": "An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1519.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mc28-wfh9-r7p4/GHSA-mc28-wfh9-r7p4.json b/advisories/unreviewed/2022/05/GHSA-mc28-wfh9-r7p4/GHSA-mc28-wfh9-r7p4.json index 64e4d21d765..b8c3894c2bf 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc28-wfh9-r7p4/GHSA-mc28-wfh9-r7p4.json +++ b/advisories/unreviewed/2022/05/GHSA-mc28-wfh9-r7p4/GHSA-mc28-wfh9-r7p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mc28-wfh9-r7p4", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1480" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1529.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mj2p-jqh8-c5vw/GHSA-mj2p-jqh8-c5vw.json b/advisories/unreviewed/2022/05/GHSA-mj2p-jqh8-c5vw/GHSA-mj2p-jqh8-c5vw.json index 5253afa20ce..3720ccf46e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mj2p-jqh8-c5vw/GHSA-mj2p-jqh8-c5vw.json +++ b/advisories/unreviewed/2022/05/GHSA-mj2p-jqh8-c5vw/GHSA-mj2p-jqh8-c5vw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj2p-jqh8-c5vw", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1490" ], "details": "An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mmr5-x5m7-54r3/GHSA-mmr5-x5m7-54r3.json b/advisories/unreviewed/2022/05/GHSA-mmr5-x5m7-54r3/GHSA-mmr5-x5m7-54r3.json index 35b9b48699e..aa0a2f7e806 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmr5-x5m7-54r3/GHSA-mmr5-x5m7-54r3.json +++ b/advisories/unreviewed/2022/05/GHSA-mmr5-x5m7-54r3/GHSA-mmr5-x5m7-54r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mmr5-x5m7-54r3", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1543" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mrgf-fpr7-x8p4/GHSA-mrgf-fpr7-x8p4.json b/advisories/unreviewed/2022/05/GHSA-mrgf-fpr7-x8p4/GHSA-mrgf-fpr7-x8p4.json index 137fe6acf06..6a9469e7dbf 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrgf-fpr7-x8p4/GHSA-mrgf-fpr7-x8p4.json +++ b/advisories/unreviewed/2022/05/GHSA-mrgf-fpr7-x8p4/GHSA-mrgf-fpr7-x8p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrgf-fpr7-x8p4", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1587" ], "details": "An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSock improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-mxf8-c4gw-pc7v/GHSA-mxf8-c4gw-pc7v.json b/advisories/unreviewed/2022/05/GHSA-mxf8-c4gw-pc7v/GHSA-mxf8-c4gw-pc7v.json index 37a6bb1b4df..5e949c0c289 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxf8-c4gw-pc7v/GHSA-mxf8-c4gw-pc7v.json +++ b/advisories/unreviewed/2022/05/GHSA-mxf8-c4gw-pc7v/GHSA-mxf8-c4gw-pc7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxf8-c4gw-pc7v", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1509" ], "details": "An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-p546-hw2g-2622/GHSA-p546-hw2g-2622.json b/advisories/unreviewed/2022/05/GHSA-p546-hw2g-2622/GHSA-p546-hw2g-2622.json index 6b3831030f0..246edef9ef2 100644 --- a/advisories/unreviewed/2022/05/GHSA-p546-hw2g-2622/GHSA-p546-hw2g-2622.json +++ b/advisories/unreviewed/2022/05/GHSA-p546-hw2g-2622/GHSA-p546-hw2g-2622.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p546-hw2g-2622", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1570" ], "details": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1380, CVE-2020-1555.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-p734-hj82-4cvx/GHSA-p734-hj82-4cvx.json b/advisories/unreviewed/2022/05/GHSA-p734-hj82-4cvx/GHSA-p734-hj82-4cvx.json index 6a2e2857728..2fc2aafcb2d 100644 --- a/advisories/unreviewed/2022/05/GHSA-p734-hj82-4cvx/GHSA-p734-hj82-4cvx.json +++ b/advisories/unreviewed/2022/05/GHSA-p734-hj82-4cvx/GHSA-p734-hj82-4cvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p734-hj82-4cvx", - "modified": "2022-05-24T17:25:45Z", + "modified": "2024-01-04T03:30:31Z", "published": "2022-05-24T17:25:45Z", "aliases": [ "CVE-2020-1046" ], "details": "A remote code execution vulnerability exists when Microsoft .NET Framework processes input, aka '.NET Framework Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-p78h-8xq8-x7pq/GHSA-p78h-8xq8-x7pq.json b/advisories/unreviewed/2022/05/GHSA-p78h-8xq8-x7pq/GHSA-p78h-8xq8-x7pq.json index 0a0bf3edcc6..c1e23ca4928 100644 --- a/advisories/unreviewed/2022/05/GHSA-p78h-8xq8-x7pq/GHSA-p78h-8xq8-x7pq.json +++ b/advisories/unreviewed/2022/05/GHSA-p78h-8xq8-x7pq/GHSA-p78h-8xq8-x7pq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p78h-8xq8-x7pq", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1557" ], "details": "A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1473, CVE-2020-1558, CVE-2020-1564.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-pj97-g38f-3qg4/GHSA-pj97-g38f-3qg4.json b/advisories/unreviewed/2022/05/GHSA-pj97-g38f-3qg4/GHSA-pj97-g38f-3qg4.json index 0aff8cd37f1..1d89899caef 100644 --- a/advisories/unreviewed/2022/05/GHSA-pj97-g38f-3qg4/GHSA-pj97-g38f-3qg4.json +++ b/advisories/unreviewed/2022/05/GHSA-pj97-g38f-3qg4/GHSA-pj97-g38f-3qg4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pj97-g38f-3qg4", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1574" ], "details": "A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1560, CVE-2020-1585.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-pwm8-7wmq-v7qm/GHSA-pwm8-7wmq-v7qm.json b/advisories/unreviewed/2022/05/GHSA-pwm8-7wmq-v7qm/GHSA-pwm8-7wmq-v7qm.json index d0b2821b303..f1122e5168a 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwm8-7wmq-v7qm/GHSA-pwm8-7wmq-v7qm.json +++ b/advisories/unreviewed/2022/05/GHSA-pwm8-7wmq-v7qm/GHSA-pwm8-7wmq-v7qm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwm8-7wmq-v7qm", - "modified": "2022-05-24T17:25:58Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:58Z", "aliases": [ "CVE-2020-1571" ], "details": "An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Setup Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-q33x-4qqr-jwvx/GHSA-q33x-4qqr-jwvx.json b/advisories/unreviewed/2022/05/GHSA-q33x-4qqr-jwvx/GHSA-q33x-4qqr-jwvx.json index 149255ed8d6..6b46ae78499 100644 --- a/advisories/unreviewed/2022/05/GHSA-q33x-4qqr-jwvx/GHSA-q33x-4qqr-jwvx.json +++ b/advisories/unreviewed/2022/05/GHSA-q33x-4qqr-jwvx/GHSA-q33x-4qqr-jwvx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q33x-4qqr-jwvx", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1539" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-q3jg-mphp-wvv9/GHSA-q3jg-mphp-wvv9.json b/advisories/unreviewed/2022/05/GHSA-q3jg-mphp-wvv9/GHSA-q3jg-mphp-wvv9.json index 26529c61694..4964cdec6b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-q3jg-mphp-wvv9/GHSA-q3jg-mphp-wvv9.json +++ b/advisories/unreviewed/2022/05/GHSA-q3jg-mphp-wvv9/GHSA-q3jg-mphp-wvv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3jg-mphp-wvv9", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1548" ], "details": "An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows WaasMedic Service Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json b/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json index 31158f33efc..ec2d53821f5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json +++ b/advisories/unreviewed/2022/05/GHSA-qcr8-x47x-6hrg/GHSA-qcr8-x47x-6hrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcr8-x47x-6hrg", - "modified": "2022-05-24T17:25:53Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:53Z", "aliases": [ "CVE-2020-1534" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qgjq-wxv3-5p46/GHSA-qgjq-wxv3-5p46.json b/advisories/unreviewed/2022/05/GHSA-qgjq-wxv3-5p46/GHSA-qgjq-wxv3-5p46.json index 02bb693c3f9..efb9492f8d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgjq-wxv3-5p46/GHSA-qgjq-wxv3-5p46.json +++ b/advisories/unreviewed/2022/05/GHSA-qgjq-wxv3-5p46/GHSA-qgjq-wxv3-5p46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qgjq-wxv3-5p46", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1518" ], "details": "An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows File Server Resource Management Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1517.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json b/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json index a3b358b8a7c..aebfedd7ceb 100644 --- a/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json +++ b/advisories/unreviewed/2022/05/GHSA-qgxw-h3gp-6wg8/GHSA-qgxw-h3gp-6wg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qgxw-h3gp-6wg8", - "modified": "2022-05-24T17:25:52Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:52Z", "aliases": [ "CVE-2020-1520" ], "details": "A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Windows Font Driver Host handles memory., aka 'Windows Font Driver Host Remote Code Execution Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qh97-33pg-j9vx/GHSA-qh97-33pg-j9vx.json b/advisories/unreviewed/2022/05/GHSA-qh97-33pg-j9vx/GHSA-qh97-33pg-j9vx.json index 6302a981fb0..a6df1786315 100644 --- a/advisories/unreviewed/2022/05/GHSA-qh97-33pg-j9vx/GHSA-qh97-33pg-j9vx.json +++ b/advisories/unreviewed/2022/05/GHSA-qh97-33pg-j9vx/GHSA-qh97-33pg-j9vx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh97-33pg-j9vx", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1552" ], "details": "An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qjjh-qjhr-48qh/GHSA-qjjh-qjhr-48qh.json b/advisories/unreviewed/2022/05/GHSA-qjjh-qjhr-48qh/GHSA-qjjh-qjhr-48qh.json index 0dcdf79e40a..2a4ba376c86 100644 --- a/advisories/unreviewed/2022/05/GHSA-qjjh-qjhr-48qh/GHSA-qjjh-qjhr-48qh.json +++ b/advisories/unreviewed/2022/05/GHSA-qjjh-qjhr-48qh/GHSA-qjjh-qjhr-48qh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qjjh-qjhr-48qh", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1580" ], "details": "A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1573.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qp95-9c4p-ffgj/GHSA-qp95-9c4p-ffgj.json b/advisories/unreviewed/2022/05/GHSA-qp95-9c4p-ffgj/GHSA-qp95-9c4p-ffgj.json index ca178592826..b5fe39fff8f 100644 --- a/advisories/unreviewed/2022/05/GHSA-qp95-9c4p-ffgj/GHSA-qp95-9c4p-ffgj.json +++ b/advisories/unreviewed/2022/05/GHSA-qp95-9c4p-ffgj/GHSA-qp95-9c4p-ffgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp95-9c4p-ffgj", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1566" ], "details": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1417, CVE-2020-1486.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-qq8w-fhxq-rfwv/GHSA-qq8w-fhxq-rfwv.json b/advisories/unreviewed/2022/05/GHSA-qq8w-fhxq-rfwv/GHSA-qq8w-fhxq-rfwv.json index 65778956606..5725155fbe1 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq8w-fhxq-rfwv/GHSA-qq8w-fhxq-rfwv.json +++ b/advisories/unreviewed/2022/05/GHSA-qq8w-fhxq-rfwv/GHSA-qq8w-fhxq-rfwv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qq8w-fhxq-rfwv", - "modified": "2022-05-24T17:25:47Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:47Z", "aliases": [ "CVE-2020-1474" ], "details": "An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory, aka 'Windows Image Acquisition Service Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1485.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-r7q3-qvg7-w57c/GHSA-r7q3-qvg7-w57c.json b/advisories/unreviewed/2022/05/GHSA-r7q3-qvg7-w57c/GHSA-r7q3-qvg7-w57c.json index 29f63612fc5..643e0745aa1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7q3-qvg7-w57c/GHSA-r7q3-qvg7-w57c.json +++ b/advisories/unreviewed/2022/05/GHSA-r7q3-qvg7-w57c/GHSA-r7q3-qvg7-w57c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7q3-qvg7-w57c", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1546" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rc33-jmrq-r7gp/GHSA-rc33-jmrq-r7gp.json b/advisories/unreviewed/2022/05/GHSA-rc33-jmrq-r7gp/GHSA-rc33-jmrq-r7gp.json index 47259b9b841..19f6af267ae 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc33-jmrq-r7gp/GHSA-rc33-jmrq-r7gp.json +++ b/advisories/unreviewed/2022/05/GHSA-rc33-jmrq-r7gp/GHSA-rc33-jmrq-r7gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rc33-jmrq-r7gp", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1494" ], "details": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1495, CVE-2020-1496, CVE-2020-1498, CVE-2020-1504.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json b/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json index d99ab66e6ba..0e5d6b29e9c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json +++ b/advisories/unreviewed/2022/05/GHSA-rqrm-jq4f-7ph5/GHSA-rqrm-jq4f-7ph5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqrm-jq4f-7ph5", - "modified": "2022-05-24T17:25:53Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:53Z", "aliases": [ "CVE-2020-1528" ], "details": "An elevation of privilege vulnerability exists when the Windows Radio Manager API improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Radio Manager API Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v4p4-8hcj-96vv/GHSA-v4p4-8hcj-96vv.json b/advisories/unreviewed/2022/05/GHSA-v4p4-8hcj-96vv/GHSA-v4p4-8hcj-96vv.json index 7fcc9fcf142..5afa1577667 100644 --- a/advisories/unreviewed/2022/05/GHSA-v4p4-8hcj-96vv/GHSA-v4p4-8hcj-96vv.json +++ b/advisories/unreviewed/2022/05/GHSA-v4p4-8hcj-96vv/GHSA-v4p4-8hcj-96vv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4p4-8hcj-96vv", - "modified": "2022-05-24T17:25:51Z", + "modified": "2024-01-04T03:30:34Z", "published": "2022-05-24T17:25:51Z", "aliases": [ "CVE-2020-1513" ], "details": "An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1489.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-v6m6-xmww-qh8j/GHSA-v6m6-xmww-qh8j.json b/advisories/unreviewed/2022/05/GHSA-v6m6-xmww-qh8j/GHSA-v6m6-xmww-qh8j.json index 92aea8b7d62..5fa2ae5d0f8 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6m6-xmww-qh8j/GHSA-v6m6-xmww-qh8j.json +++ b/advisories/unreviewed/2022/05/GHSA-v6m6-xmww-qh8j/GHSA-v6m6-xmww-qh8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6m6-xmww-qh8j", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1492" ], "details": "A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1379, CVE-2020-1477, CVE-2020-1478, CVE-2020-1525, CVE-2020-1554.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json b/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json index 644b80e6740..bcbd1a378ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json +++ b/advisories/unreviewed/2022/05/GHSA-vf2x-qf2w-jf86/GHSA-vf2x-qf2w-jf86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf2x-qf2w-jf86", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1497" ], "details": "An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vfx9-2vhh-x45q/GHSA-vfx9-2vhh-x45q.json b/advisories/unreviewed/2022/05/GHSA-vfx9-2vhh-x45q/GHSA-vfx9-2vhh-x45q.json index 42aa3983fa0..e9175c2f42d 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfx9-2vhh-x45q/GHSA-vfx9-2vhh-x45q.json +++ b/advisories/unreviewed/2022/05/GHSA-vfx9-2vhh-x45q/GHSA-vfx9-2vhh-x45q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfx9-2vhh-x45q", - "modified": "2022-05-24T17:25:50Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:50Z", "aliases": [ "CVE-2020-1503" ], "details": "An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1583.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vj26-434x-j322/GHSA-vj26-434x-j322.json b/advisories/unreviewed/2022/05/GHSA-vj26-434x-j322/GHSA-vj26-434x-j322.json index 5855a27c63b..a30eeb690f7 100644 --- a/advisories/unreviewed/2022/05/GHSA-vj26-434x-j322/GHSA-vj26-434x-j322.json +++ b/advisories/unreviewed/2022/05/GHSA-vj26-434x-j322/GHSA-vj26-434x-j322.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj26-434x-j322", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1545" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vrgf-94vf-3xxm/GHSA-vrgf-94vf-3xxm.json b/advisories/unreviewed/2022/05/GHSA-vrgf-94vf-3xxm/GHSA-vrgf-94vf-3xxm.json index c9bc4946fdc..0329dd1c437 100644 --- a/advisories/unreviewed/2022/05/GHSA-vrgf-94vf-3xxm/GHSA-vrgf-94vf-3xxm.json +++ b/advisories/unreviewed/2022/05/GHSA-vrgf-94vf-3xxm/GHSA-vrgf-94vf-3xxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vrgf-94vf-3xxm", - "modified": "2022-05-24T17:25:48Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:48Z", "aliases": [ "CVE-2020-1478" ], "details": "A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1379, CVE-2020-1477, CVE-2020-1492, CVE-2020-1525, CVE-2020-1554.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vwg3-wrxv-2xmc/GHSA-vwg3-wrxv-2xmc.json b/advisories/unreviewed/2022/05/GHSA-vwg3-wrxv-2xmc/GHSA-vwg3-wrxv-2xmc.json index 5c63a60bae9..24ea1e4a235 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwg3-wrxv-2xmc/GHSA-vwg3-wrxv-2xmc.json +++ b/advisories/unreviewed/2022/05/GHSA-vwg3-wrxv-2xmc/GHSA-vwg3-wrxv-2xmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwg3-wrxv-2xmc", - "modified": "2022-05-24T17:25:54Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:54Z", "aliases": [ "CVE-2020-1540" ], "details": "An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1536, CVE-2020-1539, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-w9gm-mcw6-q45x/GHSA-w9gm-mcw6-q45x.json b/advisories/unreviewed/2022/05/GHSA-w9gm-mcw6-q45x/GHSA-w9gm-mcw6-q45x.json index 795b6c68601..e4f3531ded6 100644 --- a/advisories/unreviewed/2022/05/GHSA-w9gm-mcw6-q45x/GHSA-w9gm-mcw6-q45x.json +++ b/advisories/unreviewed/2022/05/GHSA-w9gm-mcw6-q45x/GHSA-w9gm-mcw6-q45x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9gm-mcw6-q45x", - "modified": "2022-05-24T17:26:01Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:01Z", "aliases": [ "CVE-2020-1591" ], "details": "A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-wpjv-j566-pfwc/GHSA-wpjv-j566-pfwc.json b/advisories/unreviewed/2022/05/GHSA-wpjv-j566-pfwc/GHSA-wpjv-j566-pfwc.json index 97219975f95..2ed285d7b3f 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpjv-j566-pfwc/GHSA-wpjv-j566-pfwc.json +++ b/advisories/unreviewed/2022/05/GHSA-wpjv-j566-pfwc/GHSA-wpjv-j566-pfwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpjv-j566-pfwc", - "modified": "2022-05-24T17:26:00Z", + "modified": "2024-01-04T03:30:37Z", "published": "2022-05-24T17:26:00Z", "aliases": [ "CVE-2020-1581" ], "details": "An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory, aka 'Microsoft Office Click-to-Run Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-wvr6-9968-cvwm/GHSA-wvr6-9968-cvwm.json b/advisories/unreviewed/2022/05/GHSA-wvr6-9968-cvwm/GHSA-wvr6-9968-cvwm.json index e3c4b6056c8..c87068fdd3a 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvr6-9968-cvwm/GHSA-wvr6-9968-cvwm.json +++ b/advisories/unreviewed/2022/05/GHSA-wvr6-9968-cvwm/GHSA-wvr6-9968-cvwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvr6-9968-cvwm", - "modified": "2022-05-24T17:25:49Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:49Z", "aliases": [ "CVE-2020-1488" ], "details": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json b/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json index dc94e959ea3..ff249f168a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json +++ b/advisories/unreviewed/2022/05/GHSA-x3v3-356g-f4j9/GHSA-x3v3-356g-f4j9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x3v3-356g-f4j9", - "modified": "2022-05-24T17:25:57Z", + "modified": "2024-01-04T03:30:36Z", "published": "2022-05-24T17:25:57Z", "aliases": [ "CVE-2020-1569" ], "details": "A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-x7w4-rm2c-m9gp/GHSA-x7w4-rm2c-m9gp.json b/advisories/unreviewed/2022/05/GHSA-x7w4-rm2c-m9gp/GHSA-x7w4-rm2c-m9gp.json index 4a6f33f1d93..882054d9a53 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7w4-rm2c-m9gp/GHSA-x7w4-rm2c-m9gp.json +++ b/advisories/unreviewed/2022/05/GHSA-x7w4-rm2c-m9gp/GHSA-x7w4-rm2c-m9gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7w4-rm2c-m9gp", - "modified": "2022-05-24T17:25:56Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:56Z", "aliases": [ "CVE-2020-1556" ], "details": "An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1533.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-xj6q-3qm4-vg6w/GHSA-xj6q-3qm4-vg6w.json b/advisories/unreviewed/2022/05/GHSA-xj6q-3qm4-vg6w/GHSA-xj6q-3qm4-vg6w.json index 7d5da1fb06b..8717c363d94 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj6q-3qm4-vg6w/GHSA-xj6q-3qm4-vg6w.json +++ b/advisories/unreviewed/2022/05/GHSA-xj6q-3qm4-vg6w/GHSA-xj6q-3qm4-vg6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj6q-3qm4-vg6w", - "modified": "2022-05-24T17:25:48Z", + "modified": "2024-01-04T03:30:33Z", "published": "2022-05-24T17:25:48Z", "aliases": [ "CVE-2020-1484" ], "details": "An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1470, CVE-2020-1516.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-xm4c-7jqp-5wcr/GHSA-xm4c-7jqp-5wcr.json b/advisories/unreviewed/2022/05/GHSA-xm4c-7jqp-5wcr/GHSA-xm4c-7jqp-5wcr.json index 451f99e16cf..107af7b24de 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm4c-7jqp-5wcr/GHSA-xm4c-7jqp-5wcr.json +++ b/advisories/unreviewed/2022/05/GHSA-xm4c-7jqp-5wcr/GHSA-xm4c-7jqp-5wcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xm4c-7jqp-5wcr", - "modified": "2022-05-24T17:25:55Z", + "modified": "2024-01-04T03:30:35Z", "published": "2022-05-24T17:25:55Z", "aliases": [ "CVE-2020-1554" ], "details": "A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1379, CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1525.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-xw59-4mp5-9chf/GHSA-xw59-4mp5-9chf.json b/advisories/unreviewed/2022/05/GHSA-xw59-4mp5-9chf/GHSA-xw59-4mp5-9chf.json index e990661c43c..0dda7c80a21 100644 --- a/advisories/unreviewed/2022/05/GHSA-xw59-4mp5-9chf/GHSA-xw59-4mp5-9chf.json +++ b/advisories/unreviewed/2022/05/GHSA-xw59-4mp5-9chf/GHSA-xw59-4mp5-9chf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xw59-4mp5-9chf", - "modified": "2022-05-24T17:25:46Z", + "modified": "2024-01-04T03:30:32Z", "published": "2022-05-24T17:25:46Z", "aliases": [ "CVE-2020-1473" ], "details": "A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/12/GHSA-23r7-3wvp-5358/GHSA-23r7-3wvp-5358.json b/advisories/unreviewed/2023/12/GHSA-23r7-3wvp-5358/GHSA-23r7-3wvp-5358.json index 89e48af5fc4..e99a2053f9e 100644 --- a/advisories/unreviewed/2023/12/GHSA-23r7-3wvp-5358/GHSA-23r7-3wvp-5358.json +++ b/advisories/unreviewed/2023/12/GHSA-23r7-3wvp-5358/GHSA-23r7-3wvp-5358.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23r7-3wvp-5358", - "modified": "2023-12-27T00:30:25Z", + "modified": "2024-01-04T03:30:38Z", "published": "2023-12-27T00:30:25Z", "aliases": [ "CVE-2023-48003" ], "details": "An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '