diff --git a/advisories/unreviewed/2024/03/GHSA-77h7-8788-mfv3/GHSA-77h7-8788-mfv3.json b/advisories/unreviewed/2024/03/GHSA-77h7-8788-mfv3/GHSA-77h7-8788-mfv3.json index 9061fb3bd67..1df3ceab960 100644 --- a/advisories/unreviewed/2024/03/GHSA-77h7-8788-mfv3/GHSA-77h7-8788-mfv3.json +++ b/advisories/unreviewed/2024/03/GHSA-77h7-8788-mfv3/GHSA-77h7-8788-mfv3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77h7-8788-mfv3", - "modified": "2024-03-23T03:30:24Z", + "modified": "2024-11-20T21:30:42Z", "published": "2024-03-11T21:31:27Z", "aliases": [ "CVE-2024-2357" ], "details": "The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json b/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json index 06a45176313..7a7f372a934 100644 --- a/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json +++ b/advisories/unreviewed/2024/04/GHSA-9vvr-3g53-9w72/GHSA-9vvr-3g53-9w72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vvr-3g53-9w72", - "modified": "2024-04-26T06:30:35Z", + "modified": "2024-11-20T21:30:43Z", "published": "2024-04-26T06:30:35Z", "aliases": [ "CVE-2024-3048" ], "details": "The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T05:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json b/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json index 7a1724c3b9c..6c95dd2c17d 100644 --- a/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json +++ b/advisories/unreviewed/2024/04/GHSA-h2vp-92vw-43mf/GHSA-h2vp-92vw-43mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2vp-92vw-43mf", - "modified": "2024-04-26T15:30:31Z", + "modified": "2024-11-20T21:30:43Z", "published": "2024-04-26T15:30:31Z", "aliases": [ "CVE-2024-3076" ], "details": "The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T14:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json b/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json index 19159da9fb3..84c82ba9791 100644 --- a/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json +++ b/advisories/unreviewed/2024/04/GHSA-j9j7-vrc8-64wq/GHSA-j9j7-vrc8-64wq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9j7-vrc8-64wq", - "modified": "2024-04-10T15:30:32Z", + "modified": "2024-11-20T21:30:42Z", "published": "2024-04-09T18:30:22Z", "aliases": [ "CVE-2024-3281" ], "details": "A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-09T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json b/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json index 328040de814..015e9b435e0 100644 --- a/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json +++ b/advisories/unreviewed/2024/04/GHSA-qgpm-9vqg-rgrr/GHSA-qgpm-9vqg-rgrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qgpm-9vqg-rgrr", - "modified": "2024-04-04T15:30:34Z", + "modified": "2024-11-20T21:30:42Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-2759" ], "details": "Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin for PrestaShop from v1 through v4.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -32,7 +35,7 @@ "CWE-284", "CWE-552" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T14:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json b/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json index 3dece24cb2c..891e1ec36d6 100644 --- a/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json +++ b/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hfh-q9rg-j934", - "modified": "2024-05-16T06:30:51Z", + "modified": "2024-11-20T21:30:43Z", "published": "2024-05-16T06:30:50Z", "aliases": [ "CVE-2024-3644" ], "details": "The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T06:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json b/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json index 9eb83d733b0..52589e23c26 100644 --- a/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json +++ b/advisories/unreviewed/2024/05/GHSA-p3vp-jg8v-gfmh/GHSA-p3vp-jg8v-gfmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3vp-jg8v-gfmh", - "modified": "2024-05-15T06:30:44Z", + "modified": "2024-11-20T21:30:43Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3629" ], "details": "The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json index 52d29622fad..72bf124f2b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json +++ b/advisories/unreviewed/2024/05/GHSA-p6qv-frqj-63r6/GHSA-p6qv-frqj-63r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6qv-frqj-63r6", - "modified": "2024-05-02T06:30:31Z", + "modified": "2024-11-20T21:30:43Z", "published": "2024-05-02T06:30:31Z", "aliases": [ "CVE-2024-3471" ], "details": "The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T06:15:50Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json b/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json index 485fccc2f21..f664b6f9323 100644 --- a/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json +++ b/advisories/unreviewed/2024/08/GHSA-2rv8-p95w-9w54/GHSA-2rv8-p95w-9w54.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json b/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json index 3a01c1f29c5..2cc5d0b3e7f 100644 --- a/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json +++ b/advisories/unreviewed/2024/08/GHSA-36w4-5gpx-jw2f/GHSA-36w4-5gpx-jw2f.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json b/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json index c1ca6a13f69..003f15e1580 100644 --- a/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json +++ b/advisories/unreviewed/2024/08/GHSA-727j-8989-82f7/GHSA-727j-8989-82f7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json b/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json index 71ac22992b3..2c3ead44f8e 100644 --- a/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json +++ b/advisories/unreviewed/2024/08/GHSA-f4wh-w575-w6c3/GHSA-f4wh-w575-w6c3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json b/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json index 87a5952bff8..2b84523ee18 100644 --- a/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json +++ b/advisories/unreviewed/2024/08/GHSA-jf35-v6mp-xvp9/GHSA-jf35-v6mp-xvp9.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json b/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json index 9903f3b3c5b..679c1065035 100644 --- a/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json +++ b/advisories/unreviewed/2024/08/GHSA-pv26-xp92-c6p8/GHSA-pv26-xp92-c6p8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json b/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json index 87f4798fe37..0e7a94515cf 100644 --- a/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json +++ b/advisories/unreviewed/2024/08/GHSA-v2v8-fj72-c4fm/GHSA-v2v8-fj72-c4fm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json b/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json index 0bac43231f5..fa81f94fa60 100644 --- a/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json +++ b/advisories/unreviewed/2024/08/GHSA-xq4h-4mpj-q5jr/GHSA-xq4h-4mpj-q5jr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-5cgp-4j3x-f85m/GHSA-5cgp-4j3x-f85m.json b/advisories/unreviewed/2024/09/GHSA-5cgp-4j3x-f85m/GHSA-5cgp-4j3x-f85m.json index 2dc554267b2..a7e54691de6 100644 --- a/advisories/unreviewed/2024/09/GHSA-5cgp-4j3x-f85m/GHSA-5cgp-4j3x-f85m.json +++ b/advisories/unreviewed/2024/09/GHSA-5cgp-4j3x-f85m/GHSA-5cgp-4j3x-f85m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5cgp-4j3x-f85m", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46812" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration\n\n[Why]\nCoverity reports Memory - illegal accesses.\n\n[How]\nSkip inactive planes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-cx75-fvjc-vvr8/GHSA-cx75-fvjc-vvr8.json b/advisories/unreviewed/2024/09/GHSA-cx75-fvjc-vvr8/GHSA-cx75-fvjc-vvr8.json index 5ef49af57e8..7e04e1cd2d9 100644 --- a/advisories/unreviewed/2024/09/GHSA-cx75-fvjc-vvr8/GHSA-cx75-fvjc-vvr8.json +++ b/advisories/unreviewed/2024/09/GHSA-cx75-fvjc-vvr8/GHSA-cx75-fvjc-vvr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx75-fvjc-vvr8", - "modified": "2024-09-18T09:30:38Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46794" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Fix data leak in mmio_read()\n\nThe mmio_read() function makes a TDVMCALL to retrieve MMIO data for an\naddress from the VMM.\n\nSean noticed that mmio_read() unintentionally exposes the value of an\ninitialized variable (val) on the stack to the VMM.\n\nThis variable is only needed as an output value. It did not need to be\npassed to the VMM in the first place.\n\nDo not send the original value of *val to the VMM.\n\n[ dhansen: clarify what 'val' is used for. ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gxrj-c4gh-g3gr/GHSA-gxrj-c4gh-g3gr.json b/advisories/unreviewed/2024/09/GHSA-gxrj-c4gh-g3gr/GHSA-gxrj-c4gh-g3gr.json index d0796e22fdc..e3cc5728786 100644 --- a/advisories/unreviewed/2024/09/GHSA-gxrj-c4gh-g3gr/GHSA-gxrj-c4gh-g3gr.json +++ b/advisories/unreviewed/2024/09/GHSA-gxrj-c4gh-g3gr/GHSA-gxrj-c4gh-g3gr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxrj-c4gh-g3gr", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46827" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix firmware crash due to invalid peer nss\n\nCurrently, if the access point receives an association\nrequest containing an Extended HE Capabilities Information\nElement with an invalid MCS-NSS, it triggers a firmware\ncrash.\n\nThis issue arises when EHT-PHY capabilities shows support\nfor a bandwidth and MCS-NSS set for that particular\nbandwidth is filled by zeros and due to this, driver obtains\npeer_nss as 0 and sending this value to firmware causes\ncrash.\n\nAddress this issue by implementing a validation step for\nthe peer_nss value before passing it to the firmware. If\nthe value is greater than zero, proceed with forwarding\nit to the firmware. However, if the value is invalid,\nreject the association request to prevent potential\nfirmware crashes.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7683-mrww-rjhc/GHSA-7683-mrww-rjhc.json b/advisories/unreviewed/2024/10/GHSA-7683-mrww-rjhc/GHSA-7683-mrww-rjhc.json index 1dc93127548..23025f11a06 100644 --- a/advisories/unreviewed/2024/10/GHSA-7683-mrww-rjhc/GHSA-7683-mrww-rjhc.json +++ b/advisories/unreviewed/2024/10/GHSA-7683-mrww-rjhc/GHSA-7683-mrww-rjhc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7683-mrww-rjhc", - "modified": "2024-10-21T21:30:54Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50065" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: Change to non-blocking allocation in ntfs_d_hash\n\nd_hash is done while under \"rcu-walk\" and should not sleep.\n__get_name() allocates using GFP_KERNEL, having the possibility\nto sleep when under memory pressure. Change the allocation to\nGFP_NOWAIT.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pxgm-f458-hpx2/GHSA-pxgm-f458-hpx2.json b/advisories/unreviewed/2024/10/GHSA-pxgm-f458-hpx2/GHSA-pxgm-f458-hpx2.json index c7b6c780062..1aa1b251852 100644 --- a/advisories/unreviewed/2024/10/GHSA-pxgm-f458-hpx2/GHSA-pxgm-f458-hpx2.json +++ b/advisories/unreviewed/2024/10/GHSA-pxgm-f458-hpx2/GHSA-pxgm-f458-hpx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxgm-f458-hpx2", - "modified": "2024-10-21T21:30:54Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50060" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: check if we need to reschedule during overflow flush\n\nIn terms of normal application usage, this list will always be empty.\nAnd if an application does overflow a bit, it'll have a few entries.\nHowever, nothing obviously prevents syzbot from running a test case\nthat generates a ton of overflow entries, and then flushing them can\ntake quite a while.\n\nCheck for needing to reschedule while flushing, and drop our locks and\ndo so if necessary. There's no state to maintain here as overflows\nalways prune from head-of-list, hence it's fine to drop and reacquire\nthe locks at the end of the loop.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json b/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json index cba89d9c9d8..b7eac78b666 100644 --- a/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json +++ b/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x464-67pg-rxcc", - "modified": "2024-10-21T21:30:54Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50056" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: Fix ERR_PTR dereference in uvc_v4l2.c\n\nFix potential dereferencing of ERR_PTR() in find_format_by_pix()\nand uvc_v4l2_enum_format().\n\nFix the following smatch errors:\n\ndrivers/usb/gadget/function/uvc_v4l2.c:124 find_format_by_pix()\nerror: 'fmtdesc' dereferencing possible ERR_PTR()\n\ndrivers/usb/gadget/function/uvc_v4l2.c:392 uvc_v4l2_enum_format()\nerror: 'fmtdesc' dereferencing possible ERR_PTR()\n\nAlso, fix similar issue in uvc_v4l2_try_format() for potential\ndereferencing of ERR_PTR().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2hrg-xmqp-9q4v/GHSA-2hrg-xmqp-9q4v.json b/advisories/unreviewed/2024/11/GHSA-2hrg-xmqp-9q4v/GHSA-2hrg-xmqp-9q4v.json new file mode 100644 index 00000000000..63f63fe0c4d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2hrg-xmqp-9q4v/GHSA-2hrg-xmqp-9q4v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hrg-xmqp-9q4v", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-52702" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the component install\\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52702" + }, + { + "type": "WEB", + "url": "https://github.com/mybb/mybb/issues/4859" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json b/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json index 2329b22aa3b..c27ec853d20 100644 --- a/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json +++ b/advisories/unreviewed/2024/11/GHSA-3vj4-j93w-77x3/GHSA-3vj4-j93w-77x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vj4-j93w-77x3", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9480" ], "details": "In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json b/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json index 400cef72c9c..0d37fd8e057 100644 --- a/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json +++ b/advisories/unreviewed/2024/11/GHSA-3w8x-p539-469j/GHSA-3w8x-p539-469j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w8x-p539-469j", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9468" ], "details": "In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T17:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json b/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json index e6432ed1160..769dd396024 100644 --- a/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json +++ b/advisories/unreviewed/2024/11/GHSA-45c5-w4j9-w656/GHSA-45c5-w4j9-w656.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45c5-w4j9-w656", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9471" ], "details": "In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json b/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json new file mode 100644 index 00000000000..8c726dcccc7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-48wm-4cr2-qrfh/GHSA-48wm-4cr2-qrfh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48wm-4cr2-qrfh", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-52701" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52701" + }, + { + "type": "WEB", + "url": "https://github.com/Piwigo/Piwigo/issues/2261" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json b/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json index 93316f4ace9..86fde07155d 100644 --- a/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json +++ b/advisories/unreviewed/2024/11/GHSA-4g42-h44f-r666/GHSA-4g42-h44f-r666.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g42-h44f-r666", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9470" ], "details": "In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json b/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json new file mode 100644 index 00000000000..30d6b2e213c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5pwf-rq3f-8vg9/GHSA-5pwf-rq3f-8vg9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pwf-rq3f-8vg9", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48533" + ], + "details": "A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48533" + }, + { + "type": "WEB", + "url": "https://github.com/esoft-planner-cve/esoft_planner_cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json b/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json index 480abb62d02..9eedd42c344 100644 --- a/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json +++ b/advisories/unreviewed/2024/11/GHSA-5rg2-32x4-8gcx/GHSA-5rg2-32x4-8gcx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rg2-32x4-8gcx", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9477" ], "details": "In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-294" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json b/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json index eb4db79f633..88662c29351 100644 --- a/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json +++ b/advisories/unreviewed/2024/11/GHSA-69r9-55p9-j6ww/GHSA-69r9-55p9-j6ww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69r9-55p9-j6ww", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9485" ], "details": "In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-733q-89m7-5784/GHSA-733q-89m7-5784.json b/advisories/unreviewed/2024/11/GHSA-733q-89m7-5784/GHSA-733q-89m7-5784.json new file mode 100644 index 00000000000..7783a269f46 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-733q-89m7-5784/GHSA-733q-89m7-5784.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-733q-89m7-5784", + "modified": "2024-11-20T21:30:49Z", + "published": "2024-11-20T21:30:49Z", + "aliases": [ + "CVE-2024-48983" + ], + "details": "An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet header. A buffer is then allocated to contain the entire packet, the size of which is calculated as the length of the packet body determined earlier plus the header length. WsfMsgAlloc then increments this again by sizeof(wsfMsg_t). This may cause an integer overflow that results in the buffer being significantly too small to contain the entire packet. This may cause a buffer overflow of up to 65 KB . This bug is trivial to exploit for a denial of service but can generally not be exploited further because the exploitable buffer is dynamically allocated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48983" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/pull/388" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/blob/54e8693ef4ff7e025018094f290a1d5cf380941f/connectivity/FEATURE_BLE/libraries/cordio_stack/wsf/sources/port/baremetal/wsf_msg.c#L72" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-75h3-mqmc-mfpc/GHSA-75h3-mqmc-mfpc.json b/advisories/unreviewed/2024/11/GHSA-75h3-mqmc-mfpc/GHSA-75h3-mqmc-mfpc.json new file mode 100644 index 00000000000..d501fd25dbe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-75h3-mqmc-mfpc/GHSA-75h3-mqmc-mfpc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75h3-mqmc-mfpc", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48534" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48534" + }, + { + "type": "WEB", + "url": "https://github.com/esoft-planner-cve/esoft_planner_cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79x8-79gq-rxxc/GHSA-79x8-79gq-rxxc.json b/advisories/unreviewed/2024/11/GHSA-79x8-79gq-rxxc/GHSA-79x8-79gq-rxxc.json new file mode 100644 index 00000000000..60e4ea63401 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-79x8-79gq-rxxc/GHSA-79x8-79gq-rxxc.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79x8-79gq-rxxc", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-45510" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code into specific fields of an e-mail message. When the victim adds the attacker to their contacts, the malicious code is stored and executed when viewing the contact list. This can lead to unauthorized actions such as arbitrary mail sending, mailbox exfiltration, profile picture alteration, and other malicious actions. Proper sanitization and escaping of input fields are necessary to mitigate this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45510" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-99m9-pgm3-57w3/GHSA-99m9-pgm3-57w3.json b/advisories/unreviewed/2024/11/GHSA-99m9-pgm3-57w3/GHSA-99m9-pgm3-57w3.json new file mode 100644 index 00000000000..f64471a2b84 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-99m9-pgm3-57w3/GHSA-99m9-pgm3-57w3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99m9-pgm3-57w3", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-52765" + ], + "details": "H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52765" + }, + { + "type": "WEB", + "url": "http://tjr181.com/2024/11/08/H3C%20GR-1800AX" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json b/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json index 9439cf1ddf3..b5301b831ee 100644 --- a/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json +++ b/advisories/unreviewed/2024/11/GHSA-99p7-c89v-ph5p/GHSA-99p7-c89v-ph5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99p7-c89v-ph5p", - "modified": "2024-11-19T21:31:33Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-19T21:31:33Z", "aliases": [ "CVE-2024-52762" ], "details": "A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the \"tz\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9f2w-8h7w-mrqr/GHSA-9f2w-8h7w-mrqr.json b/advisories/unreviewed/2024/11/GHSA-9f2w-8h7w-mrqr/GHSA-9f2w-8h7w-mrqr.json new file mode 100644 index 00000000000..8f297169d6d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9f2w-8h7w-mrqr/GHSA-9f2w-8h7w-mrqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f2w-8h7w-mrqr", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48531" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48531" + }, + { + "type": "WEB", + "url": "https://github.com/esoft-planner-cve/esoft_planner_cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json b/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json index c7efc9bfd35..9eda131bf7c 100644 --- a/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json +++ b/advisories/unreviewed/2024/11/GHSA-9wgr-rjc3-37wx/GHSA-9wgr-rjc3-37wx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9wgr-rjc3-37wx", - "modified": "2024-11-19T21:31:33Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-11-19T21:31:33Z", "aliases": [ "CVE-2018-9371" ], "details": "In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T20:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json b/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json index 27666bf24d1..701f6852a1d 100644 --- a/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json +++ b/advisories/unreviewed/2024/11/GHSA-ch8j-7gjj-5qxq/GHSA-ch8j-7gjj-5qxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch8j-7gjj-5qxq", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9486" ], "details": "In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fmpp-8f7j-vvr4/GHSA-fmpp-8f7j-vvr4.json b/advisories/unreviewed/2024/11/GHSA-fmpp-8f7j-vvr4/GHSA-fmpp-8f7j-vvr4.json new file mode 100644 index 00000000000..83af8dcd515 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fmpp-8f7j-vvr4/GHSA-fmpp-8f7j-vvr4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmpp-8f7j-vvr4", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-45511" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45511" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fwhr-m7pf-h2c2/GHSA-fwhr-m7pf-h2c2.json b/advisories/unreviewed/2024/11/GHSA-fwhr-m7pf-h2c2/GHSA-fwhr-m7pf-h2c2.json new file mode 100644 index 00000000000..21a36d9d920 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fwhr-m7pf-h2c2/GHSA-fwhr-m7pf-h2c2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwhr-m7pf-h2c2", + "modified": "2024-11-20T21:30:49Z", + "published": "2024-11-20T21:30:49Z", + "aliases": [ + "CVE-2024-52754" + ], + "details": "D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52754" + }, + { + "type": "WEB", + "url": "https://github.com/faqiadegege/IoTVuln/blob/main/DI_8003_tgfile_htm_stackoverflow/detail.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json b/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json index 8cbc59643f1..d467c33110a 100644 --- a/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json +++ b/advisories/unreviewed/2024/11/GHSA-fwpv-rgxh-fj74/GHSA-fwpv-rgxh-fj74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fwpv-rgxh-fj74", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9475" ], "details": "In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation of privilege via Bluetooth, if the recipient has enabled SIP calls with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json b/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json index f8f390253e6..b9ad8bd7e50 100644 --- a/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json +++ b/advisories/unreviewed/2024/11/GHSA-ggcq-5v24-32h6/GHSA-ggcq-5v24-32h6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggcq-5v24-32h6", - "modified": "2024-11-19T21:31:33Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-19T21:31:33Z", "aliases": [ "CVE-2018-9409" ], "details": "In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T20:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json b/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json new file mode 100644 index 00000000000..1ac2aae3a3d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ghhj-rq38-j6jp/GHSA-ghhj-rq38-j6jp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghhj-rq38-j6jp", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48986" + ], + "details": "An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. Certain events cause a callback, the logic for which allocates a buffer (the length of which is determined by looking up the event type in a table). The subsequent write operation, however, copies the amount of data specified in the packet header, which may lead to a buffer overflow. This bug is trivial to exploit for a denial of service but is not certain to suffice to bring the system down and can generally not be exploited further because the exploitable buffer is dynamically allocated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48986" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/pull/385" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/blob/54e8693ef4ff7e025018094f290a1d5cf380941f/connectivity/FEATURE_BLE/libraries/cordio_stack/ble-host/sources/hci/dual_chip/hci_evt.c#L3018" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json b/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json index 735be52f082..10bb72950ad 100644 --- a/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json +++ b/advisories/unreviewed/2024/11/GHSA-hpv6-625j-5g5j/GHSA-hpv6-625j-5g5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hpv6-625j-5g5j", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9483" ], "details": "In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json b/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json new file mode 100644 index 00000000000..50f776ee20e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j27h-7c89-c3c6/GHSA-j27h-7c89-c3c6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j27h-7c89-c3c6", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-52677" + ], + "details": "HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52677" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/CVE-2024-52677" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/test/blob/main/upload.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json b/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json new file mode 100644 index 00000000000..514d73847b3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j33p-727h-4cv5/GHSA-j33p-727h-4cv5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j33p-727h-4cv5", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48536" + ], + "details": "Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48536" + }, + { + "type": "WEB", + "url": "https://github.com/esoft-planner-cve/esoft_planner_cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json b/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json index c73c7d34450..04ba48f9829 100644 --- a/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json +++ b/advisories/unreviewed/2024/11/GHSA-j5fv-4rwc-jmx5/GHSA-j5fv-4rwc-jmx5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5fv-4rwc-jmx5", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9484" ], "details": "In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json b/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json index d70d04c17e7..d2111190812 100644 --- a/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json +++ b/advisories/unreviewed/2024/11/GHSA-jw3w-mjq9-m7wp/GHSA-jw3w-mjq9-m7wp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw3w-mjq9-m7wp", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9479" ], "details": "In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json b/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json new file mode 100644 index 00000000000..cf429a6a0fe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mcpp-gh22-hwjw/GHSA-mcpp-gh22-hwjw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcpp-gh22-hwjw", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48530" + ], + "details": "An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48530" + }, + { + "type": "WEB", + "url": "https://github.com/esoft-planner-cve/esoft_planner_cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json b/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json index 9c6cf055aae..230fa1aef08 100644 --- a/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json +++ b/advisories/unreviewed/2024/11/GHSA-mr5m-3jc5-v2f3/GHSA-mr5m-3jc5-v2f3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mr5m-3jc5-v2f3", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2024-52759" ], "details": "D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json b/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json index c0215d7f43f..115bc559b2d 100644 --- a/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json +++ b/advisories/unreviewed/2024/11/GHSA-mr8h-x3p6-5r8q/GHSA-mr8h-x3p6-5r8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mr8h-x3p6-5r8q", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9472" ], "details": "In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json b/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json new file mode 100644 index 00000000000..88debe370b4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8x9-vqx9-g5pw", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48984" + ], + "details": "An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports by reading a byte from an input stream. It then fetches the length of the first report, uses it to calculate the beginning of the second report, etc. In doing this, it tracks the largest report so it can later allocate a buffer that fits every individual report (but only one at a time). It does not, however, validate that these addresses are all contained within the buffer passed to hciEvtProcessLeExtAdvReport. It is then possible, though unlikely, that the buffer designated to hold the reports is allocated in such a way that one of these out-of-bounds length fields is contained within the new buffer. When the (n-1)th report is copied, it overwrites the length field of the nth report. This now corrupted length field is then used for a memcpy into the new buffer, which may lead to a buffer overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48984" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/pull/387" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/blob/54e8693ef4ff7e025018094f290a1d5cf380941f/connectivity/FEATURE_BLE/libraries/cordio_stack/ble-host/sources/hci/dual_chip/hci_evt.c#L1317" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p9h5-xg4q-c272/GHSA-p9h5-xg4q-c272.json b/advisories/unreviewed/2024/11/GHSA-p9h5-xg4q-c272/GHSA-p9h5-xg4q-c272.json new file mode 100644 index 00000000000..40bcadd1eea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p9h5-xg4q-c272/GHSA-p9h5-xg4q-c272.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9h5-xg4q-c272", + "modified": "2024-11-20T21:30:49Z", + "published": "2024-11-20T21:30:49Z", + "aliases": [ + "CVE-2024-33439" + ], + "details": "An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33439" + }, + { + "type": "WEB", + "url": "https://gist.github.com/QuartzDust/848acfddff02c881eb86dd302e859e80" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json b/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json index e26c40406e4..b658804e202 100644 --- a/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json +++ b/advisories/unreviewed/2024/11/GHSA-pmcm-f4m7-v52m/GHSA-pmcm-f4m7-v52m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmcm-f4m7-v52m", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9469" ], "details": "In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local escalation of privilege in a privileged app with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T17:15:09Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json b/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json index 0566232ca11..8276c174f59 100644 --- a/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json +++ b/advisories/unreviewed/2024/11/GHSA-pmgw-894q-7f55/GHSA-pmgw-894q-7f55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmgw-894q-7f55", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9482" ], "details": "In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json b/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json index b196fb8232a..4440414fc5b 100644 --- a/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json +++ b/advisories/unreviewed/2024/11/GHSA-pqf7-5pw8-wxvr/GHSA-pqf7-5pw8-wxvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqf7-5pw8-wxvr", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9474" ], "details": "In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-prvh-6xrh-q7g5/GHSA-prvh-6xrh-q7g5.json b/advisories/unreviewed/2024/11/GHSA-prvh-6xrh-q7g5/GHSA-prvh-6xrh-q7g5.json new file mode 100644 index 00000000000..e93674a9bde --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-prvh-6xrh-q7g5/GHSA-prvh-6xrh-q7g5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prvh-6xrh-q7g5", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48535" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48535" + }, + { + "type": "WEB", + "url": "https://github.com/esoft-planner-cve/esoft_planner_cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json b/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json index 8715ee82c1c..3923ee640c6 100644 --- a/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json +++ b/advisories/unreviewed/2024/11/GHSA-pxvr-wp2h-6jcm/GHSA-pxvr-wp2h-6jcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxvr-wp2h-6jcm", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9487" ], "details": "In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json b/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json index 40a38b66643..b3910b496c7 100644 --- a/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json +++ b/advisories/unreviewed/2024/11/GHSA-q222-99qr-rp2h/GHSA-q222-99qr-rp2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q222-99qr-rp2h", - "modified": "2024-11-19T21:31:32Z", + "modified": "2024-11-20T21:30:48Z", "published": "2024-11-19T21:31:32Z", "aliases": [ "CVE-2024-52714" ], "details": "Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T19:15:08Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q5q7-8864-fg9c/GHSA-q5q7-8864-fg9c.json b/advisories/unreviewed/2024/11/GHSA-q5q7-8864-fg9c/GHSA-q5q7-8864-fg9c.json new file mode 100644 index 00000000000..067c130de7b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q5q7-8864-fg9c/GHSA-q5q7-8864-fg9c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5q7-8864-fg9c", + "modified": "2024-11-20T21:30:49Z", + "published": "2024-11-20T21:30:49Z", + "aliases": [ + "CVE-2024-48981" + ], + "details": "An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking up the identifying first byte and matching it against a table of possible lengths. The initial parsing function, hciTrSerialRxIncoming does not drop packets with invalid identifiers but also does not set a safe default for the length of unknown packets' headers, leading to a buffer overflow. This can be leveraged into an arbitrary write by an attacker. It is possible to overwrite the pointer to a not-yet-allocated buffer that is supposed to receive the contents of the packet body. One can then overwrite the state variable used by the function to determine which state of packet parsing is currently occurring. Because the buffer is allocated when the last byte of the header has been copied, the combination of having a bad header length variable that will never match the counter variable and being able to overwrite the state variable with the resulting buffer overflow can be used to advance the function to the next step while skipping the buffer allocation and resulting pointer write. The next 16 bytes from the packet body are then written wherever the corrupted data pointer is pointing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48981" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/pull/374" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/blob/54e8693ef4ff7e025018094f290a1d5cf380941f/connectivity/FEATURE_BLE/source/cordio/stack_adaptation/hci_tr.c#L161" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json b/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json new file mode 100644 index 00000000000..5eaf40d4960 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r8wg-wr62-xwrv/GHSA-r8wg-wr62-xwrv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8wg-wr62-xwrv", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-48982" + ], + "details": "An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assumed to be greater than or equal to 3, but the software doesn't ensure that this is the case. Supplying a length less than 3 leads to a buffer overflow in a buffer that is allocated later. It is simultaneously possible to cause another integer overflow by supplying large length values because the provided length value is increased by a few bytes to account for additional information that is supposed to be stored there. This bug is trivial to exploit for a denial of service but is not certain to suffice to bring the system down and can generally not be exploited further because the exploitable buffer is dynamically allocated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48982" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/pull/386" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/blob/54e8693ef4ff7e025018094f290a1d5cf380941f/connectivity/FEATURE_BLE/libraries/cordio_stack/ble-host/sources/hci/dual_chip/hci_evt.c#L2748" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json b/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json index 2150d9718a0..71ad8f758d0 100644 --- a/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json +++ b/advisories/unreviewed/2024/11/GHSA-rmc4-mqv6-cmwx/GHSA-rmc4-mqv6-cmwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmc4-mqv6-cmwx", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9478" ], "details": "In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vchv-pqrf-xh97/GHSA-vchv-pqrf-xh97.json b/advisories/unreviewed/2024/11/GHSA-vchv-pqrf-xh97/GHSA-vchv-pqrf-xh97.json new file mode 100644 index 00000000000..c6b9135b52a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vchv-pqrf-xh97/GHSA-vchv-pqrf-xh97.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vchv-pqrf-xh97", + "modified": "2024-11-20T21:30:49Z", + "published": "2024-11-20T21:30:49Z", + "aliases": [ + "CVE-2024-48985" + ], + "details": "An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet data. A buffer is then allocated to contain the entire packet, the size of which is calculated as the length of the packet body determined earlier and the header length. If the allocate fails because the specified packet is too large, no exception handling occurs and hciTrSerialRxIncoming continues to write bytes into the 4-byte large temporary header buffer, leading to a buffer overflow. This can be leveraged into an arbitrary write by an attacker. It is possible to overwrite the pointer to the buffer that is supposed to receive the contents of the packet body but which couldn't be allocated. One can then overwrite the state variable used by the function to determine which step of the parsing process is currently being executed. This advances the function to the next state, where it proceeds to copy data to that arbitrary location. The packet body is then written wherever the corrupted data pointer is pointing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48985" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/pull/384" + }, + { + "type": "WEB", + "url": "https://github.com/mbed-ce/mbed-os/blob/54e8693ef4ff7e025018094f290a1d5cf380941f/connectivity/FEATURE_BLE/source/cordio/stack_adaptation/hci_tr.c#L200" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w7jp-xrvv-jcjf/GHSA-w7jp-xrvv-jcjf.json b/advisories/unreviewed/2024/11/GHSA-w7jp-xrvv-jcjf/GHSA-w7jp-xrvv-jcjf.json new file mode 100644 index 00000000000..8e9fbb05db3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w7jp-xrvv-jcjf/GHSA-w7jp-xrvv-jcjf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7jp-xrvv-jcjf", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-52757" + ], + "details": "D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52757" + }, + { + "type": "WEB", + "url": "https://github.com/faqiadegege/IoTVuln/blob/main/DI_8003_arp_sys_asp_stackoverflow/detail.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json b/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json index e64a82002d5..d4cada51db0 100644 --- a/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json +++ b/advisories/unreviewed/2024/11/GHSA-wjgf-x45f-9vgf/GHSA-wjgf-x45f-9vgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjgf-x45f-9vgf", - "modified": "2024-11-20T18:32:18Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:18Z", "aliases": [ "CVE-2024-52739" ], "details": "D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wpvf-5mc3-hv6m/GHSA-wpvf-5mc3-hv6m.json b/advisories/unreviewed/2024/11/GHSA-wpvf-5mc3-hv6m/GHSA-wpvf-5mc3-hv6m.json new file mode 100644 index 00000000000..f68ef175e51 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wpvf-5mc3-hv6m/GHSA-wpvf-5mc3-hv6m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpvf-5mc3-hv6m", + "modified": "2024-11-20T21:30:50Z", + "published": "2024-11-20T21:30:50Z", + "aliases": [ + "CVE-2024-49203" + ], + "details": "Querydsl 5.1.0 allows SQL/HQL injection in orderBy in JPAQuery.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49203" + }, + { + "type": "WEB", + "url": "https://github.com/querydsl/querydsl/issues/3757" + }, + { + "type": "WEB", + "url": "https://github.com/querydsl/querydsl/releases/tag/QUERYDSL_5_1_0" + }, + { + "type": "WEB", + "url": "https://www.csirt.sk/querydsl-java-library-vulnerability-permits-sql-hql-injection.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json b/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json index 1897c2040f4..93327c8bc1a 100644 --- a/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json +++ b/advisories/unreviewed/2024/11/GHSA-xc7x-w33q-rvw9/GHSA-xc7x-w33q-rvw9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc7x-w33q-rvw9", - "modified": "2024-11-20T18:32:17Z", + "modified": "2024-11-20T21:30:49Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2018-9481" ], "details": "In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T18:15:19Z"