diff --git a/advisories/unreviewed/2024/02/GHSA-3x35-4hvx-j24p/GHSA-3x35-4hvx-j24p.json b/advisories/unreviewed/2024/02/GHSA-3x35-4hvx-j24p/GHSA-3x35-4hvx-j24p.json index 88eaed8bd26..133cc25a5d1 100644 --- a/advisories/unreviewed/2024/02/GHSA-3x35-4hvx-j24p/GHSA-3x35-4hvx-j24p.json +++ b/advisories/unreviewed/2024/02/GHSA-3x35-4hvx-j24p/GHSA-3x35-4hvx-j24p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x35-4hvx-j24p", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-08-21T21:30:44Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-0023" ], "details": "In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T20:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p5pj-43hq-q22g/GHSA-p5pj-43hq-q22g.json b/advisories/unreviewed/2024/05/GHSA-p5pj-43hq-q22g/GHSA-p5pj-43hq-q22g.json index 08b20d71f20..19e87da44ed 100644 --- a/advisories/unreviewed/2024/05/GHSA-p5pj-43hq-q22g/GHSA-p5pj-43hq-q22g.json +++ b/advisories/unreviewed/2024/05/GHSA-p5pj-43hq-q22g/GHSA-p5pj-43hq-q22g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5pj-43hq-q22g", - "modified": "2024-05-05T15:30:28Z", + "modified": "2024-08-21T21:30:44Z", "published": "2024-05-05T15:30:28Z", "aliases": [ "CVE-2024-34474" ], "details": "Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\\Clario and tries to load DLLs from there as SYSTEM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T15:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rq44-cfp6-2c3c/GHSA-rq44-cfp6-2c3c.json b/advisories/unreviewed/2024/05/GHSA-rq44-cfp6-2c3c/GHSA-rq44-cfp6-2c3c.json index 2df755bd2e4..4d54def6420 100644 --- a/advisories/unreviewed/2024/05/GHSA-rq44-cfp6-2c3c/GHSA-rq44-cfp6-2c3c.json +++ b/advisories/unreviewed/2024/05/GHSA-rq44-cfp6-2c3c/GHSA-rq44-cfp6-2c3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rq44-cfp6-2c3c", - "modified": "2024-06-10T18:30:57Z", + "modified": "2024-08-21T21:30:44Z", "published": "2024-05-05T21:30:30Z", "aliases": [ "CVE-2024-34502" ], "details": "An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-05T19:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-3cf4-3gwv-8jwp/GHSA-3cf4-3gwv-8jwp.json b/advisories/unreviewed/2024/07/GHSA-3cf4-3gwv-8jwp/GHSA-3cf4-3gwv-8jwp.json index 4c33af6f31d..5d0a8f8190c 100644 --- a/advisories/unreviewed/2024/07/GHSA-3cf4-3gwv-8jwp/GHSA-3cf4-3gwv-8jwp.json +++ b/advisories/unreviewed/2024/07/GHSA-3cf4-3gwv-8jwp/GHSA-3cf4-3gwv-8jwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cf4-3gwv-8jwp", - "modified": "2024-07-30T09:31:51Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-30T09:31:51Z", "aliases": [ "CVE-2024-42102" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again\"\n\nPatch series \"mm: Avoid possible overflows in dirty throttling\".\n\nDirty throttling logic assumes dirty limits in page units fit into\n32-bits. This patch series makes sure this is true (see patch 2/2 for\nmore details).\n\n\nThis patch (of 2):\n\nThis reverts commit 9319b647902cbd5cc884ac08a8a6d54ce111fc78.\n\nThe commit is broken in several ways. Firstly, the removed (u64) cast\nfrom the multiplication will introduce a multiplication overflow on 32-bit\narchs if wb_thresh * bg_thresh >= 1<<32 (which is actually common - the\ndefault settings with 4GB of RAM will trigger this). Secondly, the\ndiv64_u64() is unnecessarily expensive on 32-bit archs. We have\ndiv64_ul() in case we want to be safe & cheap. Thirdly, if dirty\nthresholds are larger than 1<<32 pages, then dirty balancing is going to\nblow up in many other spectacular ways anyway so trying to fix one\npossible overflow is just moot.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4869-v738-xvvg/GHSA-4869-v738-xvvg.json b/advisories/unreviewed/2024/07/GHSA-4869-v738-xvvg/GHSA-4869-v738-xvvg.json index 970d5fe98ea..0203256b470 100644 --- a/advisories/unreviewed/2024/07/GHSA-4869-v738-xvvg/GHSA-4869-v738-xvvg.json +++ b/advisories/unreviewed/2024/07/GHSA-4869-v738-xvvg/GHSA-4869-v738-xvvg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4869-v738-xvvg", - "modified": "2024-07-01T15:32:22Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-01T15:32:22Z", "aliases": [ "CVE-2024-39013" ], "details": "2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-55w4-2fh8-255h/GHSA-55w4-2fh8-255h.json b/advisories/unreviewed/2024/07/GHSA-55w4-2fh8-255h/GHSA-55w4-2fh8-255h.json index 3a46d96d35c..8e80e8b473b 100644 --- a/advisories/unreviewed/2024/07/GHSA-55w4-2fh8-255h/GHSA-55w4-2fh8-255h.json +++ b/advisories/unreviewed/2024/07/GHSA-55w4-2fh8-255h/GHSA-55w4-2fh8-255h.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-67v3-v6h4-rfpq/GHSA-67v3-v6h4-rfpq.json b/advisories/unreviewed/2024/07/GHSA-67v3-v6h4-rfpq/GHSA-67v3-v6h4-rfpq.json index 782607152b0..4e620dc3dc9 100644 --- a/advisories/unreviewed/2024/07/GHSA-67v3-v6h4-rfpq/GHSA-67v3-v6h4-rfpq.json +++ b/advisories/unreviewed/2024/07/GHSA-67v3-v6h4-rfpq/GHSA-67v3-v6h4-rfpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67v3-v6h4-rfpq", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41061" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix array-index-out-of-bounds in dml2/FCLKChangeSupport\n\n[Why]\nPotential out of bounds access in dml2_calculate_rq_and_dlg_params()\nbecause the value of out_lowest_state_idx used as an index for FCLKChangeSupport\narray can be greater than 1.\n\n[How]\nCurrently dml2 core specifies identical values for all FCLKChangeSupport\nelements. Always use index 0 in the condition to avoid out of bounds access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-77q5-g293-rv7c/GHSA-77q5-g293-rv7c.json b/advisories/unreviewed/2024/07/GHSA-77q5-g293-rv7c/GHSA-77q5-g293-rv7c.json index 2b02742f5f7..3980a0e1018 100644 --- a/advisories/unreviewed/2024/07/GHSA-77q5-g293-rv7c/GHSA-77q5-g293-rv7c.json +++ b/advisories/unreviewed/2024/07/GHSA-77q5-g293-rv7c/GHSA-77q5-g293-rv7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77q5-g293-rv7c", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41058" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: fix slab-use-after-free in fscache_withdraw_volume()\n\nWe got the following issue in our fault injection stress test:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in fscache_withdraw_volume+0x2e1/0x370\nRead of size 4 at addr ffff88810680be08 by task ondemand-04-dae/5798\n\nCPU: 0 PID: 5798 Comm: ondemand-04-dae Not tainted 6.8.0-dirty #565\nCall Trace:\n kasan_check_range+0xf6/0x1b0\n fscache_withdraw_volume+0x2e1/0x370\n cachefiles_withdraw_volume+0x31/0x50\n cachefiles_withdraw_cache+0x3ad/0x900\n cachefiles_put_unbind_pincount+0x1f6/0x250\n cachefiles_daemon_release+0x13b/0x290\n __fput+0x204/0xa00\n task_work_run+0x139/0x230\n\nAllocated by task 5820:\n __kmalloc+0x1df/0x4b0\n fscache_alloc_volume+0x70/0x600\n __fscache_acquire_volume+0x1c/0x610\n erofs_fscache_register_volume+0x96/0x1a0\n erofs_fscache_register_fs+0x49a/0x690\n erofs_fc_fill_super+0x6c0/0xcc0\n vfs_get_super+0xa9/0x140\n vfs_get_tree+0x8e/0x300\n do_new_mount+0x28c/0x580\n [...]\n\nFreed by task 5820:\n kfree+0xf1/0x2c0\n fscache_put_volume.part.0+0x5cb/0x9e0\n erofs_fscache_unregister_fs+0x157/0x1b0\n erofs_kill_sb+0xd9/0x1c0\n deactivate_locked_super+0xa3/0x100\n vfs_get_super+0x105/0x140\n vfs_get_tree+0x8e/0x300\n do_new_mount+0x28c/0x580\n [...]\n==================================================================\n\nFollowing is the process that triggers the issue:\n\n mount failed | daemon exit\n------------------------------------------------------------\n deactivate_locked_super cachefiles_daemon_release\n erofs_kill_sb\n erofs_fscache_unregister_fs\n fscache_relinquish_volume\n __fscache_relinquish_volume\n fscache_put_volume(fscache_volume, fscache_volume_put_relinquish)\n zero = __refcount_dec_and_test(&fscache_volume->ref, &ref);\n cachefiles_put_unbind_pincount\n cachefiles_daemon_unbind\n cachefiles_withdraw_cache\n cachefiles_withdraw_volumes\n list_del_init(&volume->cache_link)\n fscache_free_volume(fscache_volume)\n cache->ops->free_volume\n cachefiles_free_volume\n list_del_init(&cachefiles_volume->cache_link);\n kfree(fscache_volume)\n cachefiles_withdraw_volume\n fscache_withdraw_volume\n fscache_volume->n_accesses\n // fscache_volume UAF !!!\n\nThe fscache_volume in cache->volumes must not have been freed yet, but its\nreference count may be 0. So use the new fscache_try_get_volume() helper\nfunction try to get its reference count.\n\nIf the reference count of fscache_volume is 0, fscache_put_volume() is\nfreeing it, so wait for it to be removed from cache->volumes.\n\nIf its reference count is not 0, call cachefiles_withdraw_volume() with\nreference count protection to avoid the above issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-997q-9m6q-gr23/GHSA-997q-9m6q-gr23.json b/advisories/unreviewed/2024/07/GHSA-997q-9m6q-gr23/GHSA-997q-9m6q-gr23.json index 6df94b4c10e..8576da96676 100644 --- a/advisories/unreviewed/2024/07/GHSA-997q-9m6q-gr23/GHSA-997q-9m6q-gr23.json +++ b/advisories/unreviewed/2024/07/GHSA-997q-9m6q-gr23/GHSA-997q-9m6q-gr23.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-f9fx-wvgj-vvxm/GHSA-f9fx-wvgj-vvxm.json b/advisories/unreviewed/2024/07/GHSA-f9fx-wvgj-vvxm/GHSA-f9fx-wvgj-vvxm.json index 9f9400fe992..5905eda0531 100644 --- a/advisories/unreviewed/2024/07/GHSA-f9fx-wvgj-vvxm/GHSA-f9fx-wvgj-vvxm.json +++ b/advisories/unreviewed/2024/07/GHSA-f9fx-wvgj-vvxm/GHSA-f9fx-wvgj-vvxm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9fx-wvgj-vvxm", - "modified": "2024-07-29T15:30:43Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-29T15:30:43Z", "aliases": [ "CVE-2024-41053" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix ufshcd_abort_one racing issue\n\nWhen ufshcd_abort_one is racing with the completion ISR, the completed tag\nof the request's mq_hctx pointer will be set to NULL by ISR. Return\nsuccess when request is completed by ISR because ufshcd_abort_one does not\nneed to do anything.\n\nThe racing flow is:\n\nThread A\nufshcd_err_handler\t\t\t\t\tstep 1\n\t...\n\tufshcd_abort_one\n\t\tufshcd_try_to_abort_task\n\t\t\tufshcd_cmd_inflight(true)\tstep 3\n\t\tufshcd_mcq_req_to_hwq\n\t\t\tblk_mq_unique_tag\n\t\t\t\trq->mq_hctx->queue_num\tstep 5\n\nThread B\nufs_mtk_mcq_intr(cq complete ISR)\t\t\tstep 2\n\tscsi_done\n\t\t...\n\t\t__blk_mq_free_request\n\t\t\trq->mq_hctx = NULL;\t\tstep 4\n\nBelow is KE back trace.\n ufshcd_try_to_abort_task: cmd at tag 41 not pending in the device.\n ufshcd_try_to_abort_task: cmd at tag=41 is cleared.\n Aborting tag 41 / CDB 0x28 succeeded\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000194\n pc : [0xffffffddd7a79bf8] blk_mq_unique_tag+0x8/0x14\n lr : [0xffffffddd6155b84] ufshcd_mcq_req_to_hwq+0x1c/0x40 [ufs_mediatek_mod_ise]\n do_mem_abort+0x58/0x118\n el1_abort+0x3c/0x5c\n el1h_64_sync_handler+0x54/0x90\n el1h_64_sync+0x68/0x6c\n blk_mq_unique_tag+0x8/0x14\n ufshcd_err_handler+0xae4/0xfa8 [ufs_mediatek_mod_ise]\n process_one_work+0x208/0x4fc\n worker_thread+0x228/0x438\n kthread+0x104/0x1d4\n ret_from_fork+0x10/0x20", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g3v7-q58w-w9qx/GHSA-g3v7-q58w-w9qx.json b/advisories/unreviewed/2024/07/GHSA-g3v7-q58w-w9qx/GHSA-g3v7-q58w-w9qx.json index df6aa9dd7b2..a3ddf7a3cb4 100644 --- a/advisories/unreviewed/2024/07/GHSA-g3v7-q58w-w9qx/GHSA-g3v7-q58w-w9qx.json +++ b/advisories/unreviewed/2024/07/GHSA-g3v7-q58w-w9qx/GHSA-g3v7-q58w-w9qx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3v7-q58w-w9qx", - "modified": "2024-07-30T09:31:51Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-30T09:31:51Z", "aliases": [ "CVE-2024-42108" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rswitch: Avoid use-after-free in rswitch_poll()\n\nThe use-after-free is actually in rswitch_tx_free(), which is inlined in\nrswitch_poll(). Since `skb` and `gq->skbs[gq->dirty]` are in fact the\nsame pointer, the skb is first freed using dev_kfree_skb_any(), then the\nvalue in skb->len is used to update the interface statistics.\n\nLet's move around the instructions to use skb->len before the skb is\nfreed.\n\nThis bug is trivial to reproduce using KFENCE. It will trigger a splat\nevery few packets. A simple ARP request or ICMP echo request is enough.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p8fr-g8w4-cvv6/GHSA-p8fr-g8w4-cvv6.json b/advisories/unreviewed/2024/07/GHSA-p8fr-g8w4-cvv6/GHSA-p8fr-g8w4-cvv6.json index 3806efdfa5f..d0e44733170 100644 --- a/advisories/unreviewed/2024/07/GHSA-p8fr-g8w4-cvv6/GHSA-p8fr-g8w4-cvv6.json +++ b/advisories/unreviewed/2024/07/GHSA-p8fr-g8w4-cvv6/GHSA-p8fr-g8w4-cvv6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8fr-g8w4-cvv6", - "modified": "2024-07-01T15:32:24Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-01T15:32:24Z", "aliases": [ "CVE-2024-39014" ], "details": "ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T13:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rhm4-r455-38cm/GHSA-rhm4-r455-38cm.json b/advisories/unreviewed/2024/07/GHSA-rhm4-r455-38cm/GHSA-rhm4-r455-38cm.json index d67499ee0e2..102a1f7192a 100644 --- a/advisories/unreviewed/2024/07/GHSA-rhm4-r455-38cm/GHSA-rhm4-r455-38cm.json +++ b/advisories/unreviewed/2024/07/GHSA-rhm4-r455-38cm/GHSA-rhm4-r455-38cm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rhm4-r455-38cm", - "modified": "2024-07-29T15:30:43Z", + "modified": "2024-08-21T21:30:45Z", "published": "2024-07-29T15:30:43Z", "aliases": [ "CVE-2024-41052" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Init the count variable in collecting hot-reset devices\n\nThe count variable is used without initialization, it results in mistakes\nin the device counting and crashes the userspace if the get hot reset info\npath is triggered.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2xc5-3f92-ffpr/GHSA-2xc5-3f92-ffpr.json b/advisories/unreviewed/2024/08/GHSA-2xc5-3f92-ffpr/GHSA-2xc5-3f92-ffpr.json new file mode 100644 index 00000000000..17aee61485d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2xc5-3f92-ffpr/GHSA-2xc5-3f92-ffpr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xc5-3f92-ffpr", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7978" + ], + "details": "Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7978" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40060358" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3466-hwg6-rp7h/GHSA-3466-hwg6-rp7h.json b/advisories/unreviewed/2024/08/GHSA-3466-hwg6-rp7h/GHSA-3466-hwg6-rp7h.json new file mode 100644 index 00000000000..5ccbfd40540 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3466-hwg6-rp7h/GHSA-3466-hwg6-rp7h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3466-hwg6-rp7h", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7979" + ], + "details": "Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7979" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/356064205" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-374f-438q-472r/GHSA-374f-438q-472r.json b/advisories/unreviewed/2024/08/GHSA-374f-438q-472r/GHSA-374f-438q-472r.json new file mode 100644 index 00000000000..d98127b6a06 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-374f-438q-472r/GHSA-374f-438q-472r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-374f-438q-472r", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7968" + ], + "details": "Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7968" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/349253666" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4pj3-wmgx-2h8r/GHSA-4pj3-wmgx-2h8r.json b/advisories/unreviewed/2024/08/GHSA-4pj3-wmgx-2h8r/GHSA-4pj3-wmgx-2h8r.json new file mode 100644 index 00000000000..f4d93f50134 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4pj3-wmgx-2h8r/GHSA-4pj3-wmgx-2h8r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pj3-wmgx-2h8r", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7966" + ], + "details": "Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7966" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/355465305" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json b/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json new file mode 100644 index 00000000000..e4ee28484ab --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57cq-jgq2-x7vg", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7967" + ], + "details": "Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7967" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/355731798" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json b/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json new file mode 100644 index 00000000000..fadcb661051 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-682f-6p39-r4r2", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-20466" + ], + "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device.\n\nThis vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An attacker with read-only Administrator privileges for the web-based management interface on an affected device could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20466" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-info-exp-vdF8Jbyk" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6j9j-7v9j-7mf7/GHSA-6j9j-7v9j-7mf7.json b/advisories/unreviewed/2024/08/GHSA-6j9j-7v9j-7mf7/GHSA-6j9j-7v9j-7mf7.json new file mode 100644 index 00000000000..58c7a7d37b7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6j9j-7v9j-7mf7/GHSA-6j9j-7v9j-7mf7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j9j-7v9j-7mf7", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7964" + ], + "details": "Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7964" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/358296941" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7gqg-87vr-36c4/GHSA-7gqg-87vr-36c4.json b/advisories/unreviewed/2024/08/GHSA-7gqg-87vr-36c4/GHSA-7gqg-87vr-36c4.json index c976cff089d..93d175450ca 100644 --- a/advisories/unreviewed/2024/08/GHSA-7gqg-87vr-36c4/GHSA-7gqg-87vr-36c4.json +++ b/advisories/unreviewed/2024/08/GHSA-7gqg-87vr-36c4/GHSA-7gqg-87vr-36c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gqg-87vr-36c4", - "modified": "2024-08-20T03:32:25Z", + "modified": "2024-08-21T21:30:46Z", "published": "2024-08-20T03:32:25Z", "aliases": [ "CVE-2024-7949" @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.394046" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json b/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json new file mode 100644 index 00000000000..e545c5f5a4f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8p7p-r9xv-w8g4/GHSA-8p7p-r9xv-w8g4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p7p-r9xv-w8g4", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7980" + ], + "details": "Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7980" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/356328460" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8v6h-j8r8-9mjq/GHSA-8v6h-j8r8-9mjq.json b/advisories/unreviewed/2024/08/GHSA-8v6h-j8r8-9mjq/GHSA-8v6h-j8r8-9mjq.json new file mode 100644 index 00000000000..8c11fb77ff5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8v6h-j8r8-9mjq/GHSA-8v6h-j8r8-9mjq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v6h-j8r8-9mjq", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-8033" + ], + "details": "Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker who convinced a user to install a malicious application to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8033" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/350256139" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9rxp-vmhg-9p4x/GHSA-9rxp-vmhg-9p4x.json b/advisories/unreviewed/2024/08/GHSA-9rxp-vmhg-9p4x/GHSA-9rxp-vmhg-9p4x.json new file mode 100644 index 00000000000..cfeb17b62de --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9rxp-vmhg-9p4x/GHSA-9rxp-vmhg-9p4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rxp-vmhg-9p4x", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-20486" + ], + "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.\n\nThis vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20486" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-csrf-y4ZUz5Rj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json b/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json new file mode 100644 index 00000000000..6e258ccca8a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wpw-58rw-f8gm", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7981" + ], + "details": "Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7981" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40067456" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c769-hhrx-qp4m/GHSA-c769-hhrx-qp4m.json b/advisories/unreviewed/2024/08/GHSA-c769-hhrx-qp4m/GHSA-c769-hhrx-qp4m.json index 86a8c723606..d28ce56a535 100644 --- a/advisories/unreviewed/2024/08/GHSA-c769-hhrx-qp4m/GHSA-c769-hhrx-qp4m.json +++ b/advisories/unreviewed/2024/08/GHSA-c769-hhrx-qp4m/GHSA-c769-hhrx-qp4m.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json b/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json new file mode 100644 index 00000000000..ca72506bed2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7v6-r97x-ppjq", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7974" + ], + "details": "Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7974" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339141099" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f6fm-8rjv-g8ww/GHSA-f6fm-8rjv-g8ww.json b/advisories/unreviewed/2024/08/GHSA-f6fm-8rjv-g8ww/GHSA-f6fm-8rjv-g8ww.json index 513ceace730..1a36ebdaceb 100644 --- a/advisories/unreviewed/2024/08/GHSA-f6fm-8rjv-g8ww/GHSA-f6fm-8rjv-g8ww.json +++ b/advisories/unreviewed/2024/08/GHSA-f6fm-8rjv-g8ww/GHSA-f6fm-8rjv-g8ww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6fm-8rjv-g8ww", - "modified": "2024-08-14T03:31:09Z", + "modified": "2024-08-21T21:30:46Z", "published": "2024-08-14T03:31:09Z", "aliases": [ "CVE-2024-20083" ], "details": "In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-14T03:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fvhq-6pjg-jc69/GHSA-fvhq-6pjg-jc69.json b/advisories/unreviewed/2024/08/GHSA-fvhq-6pjg-jc69/GHSA-fvhq-6pjg-jc69.json index da93e2a1e36..f5312a86946 100644 --- a/advisories/unreviewed/2024/08/GHSA-fvhq-6pjg-jc69/GHSA-fvhq-6pjg-jc69.json +++ b/advisories/unreviewed/2024/08/GHSA-fvhq-6pjg-jc69/GHSA-fvhq-6pjg-jc69.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fvhq-6pjg-jc69", - "modified": "2024-08-18T18:30:35Z", + "modified": "2024-08-21T21:30:46Z", "published": "2024-08-18T18:30:35Z", "aliases": [ "CVE-2024-7909" @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.388436" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json b/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json index b149a47992a..d56b8556935 100644 --- a/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json +++ b/advisories/unreviewed/2024/08/GHSA-grxj-hmrx-25w5/GHSA-grxj-hmrx-25w5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grxj-hmrx-25w5", - "modified": "2024-08-21T18:31:28Z", + "modified": "2024-08-21T21:30:46Z", "published": "2024-08-21T18:31:28Z", "aliases": [ "CVE-2024-43022" ], "details": "An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory traversal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T17:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h2w6-mvpr-jj72/GHSA-h2w6-mvpr-jj72.json b/advisories/unreviewed/2024/08/GHSA-h2w6-mvpr-jj72/GHSA-h2w6-mvpr-jj72.json index 949e4945bf2..82d9cf7a451 100644 --- a/advisories/unreviewed/2024/08/GHSA-h2w6-mvpr-jj72/GHSA-h2w6-mvpr-jj72.json +++ b/advisories/unreviewed/2024/08/GHSA-h2w6-mvpr-jj72/GHSA-h2w6-mvpr-jj72.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-hg5m-x49p-g9h8/GHSA-hg5m-x49p-g9h8.json b/advisories/unreviewed/2024/08/GHSA-hg5m-x49p-g9h8/GHSA-hg5m-x49p-g9h8.json new file mode 100644 index 00000000000..c3e42832baf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hg5m-x49p-g9h8/GHSA-hg5m-x49p-g9h8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg5m-x49p-g9h8", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-8035" + ], + "details": "Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8035" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40059470" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json b/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json new file mode 100644 index 00000000000..320ef8bb623 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j2gf-fhx6-5xrq/GHSA-j2gf-fhx6-5xrq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2gf-fhx6-5xrq", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7973" + ], + "details": "Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7973" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/345518608" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jhcm-h49j-fwww/GHSA-jhcm-h49j-fwww.json b/advisories/unreviewed/2024/08/GHSA-jhcm-h49j-fwww/GHSA-jhcm-h49j-fwww.json new file mode 100644 index 00000000000..b64933d5477 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jhcm-h49j-fwww/GHSA-jhcm-h49j-fwww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhcm-h49j-fwww", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-20417" + ], + "details": "Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks.\n\nThese vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20417" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rest-5bPKrNtZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json b/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json new file mode 100644 index 00000000000..2aea47f00d1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p269-768c-9733/GHSA-p269-768c-9733.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p269-768c-9733", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7975" + ], + "details": "Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7975" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/347588491" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json b/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json new file mode 100644 index 00000000000..608fa785722 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p34g-w82h-w82c/GHSA-p34g-w82h-w82c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p34g-w82h-w82c", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-8034" + ], + "details": "Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8034" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/353858776" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p8h7-64p8-w5pq/GHSA-p8h7-64p8-w5pq.json b/advisories/unreviewed/2024/08/GHSA-p8h7-64p8-w5pq/GHSA-p8h7-64p8-w5pq.json new file mode 100644 index 00000000000..0b7ec25eec0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p8h7-64p8-w5pq/GHSA-p8h7-64p8-w5pq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8h7-64p8-w5pq", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7969" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7969" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/351865302" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pgqc-fvj2-w9mh/GHSA-pgqc-fvj2-w9mh.json b/advisories/unreviewed/2024/08/GHSA-pgqc-fvj2-w9mh/GHSA-pgqc-fvj2-w9mh.json new file mode 100644 index 00000000000..efd501ac5f6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pgqc-fvj2-w9mh/GHSA-pgqc-fvj2-w9mh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgqc-fvj2-w9mh", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-41572" + ], + "details": "Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41572" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/12NAfZ2VrMvJug1JVSzfz9PwCuttnlwzP" + }, + { + "type": "WEB", + "url": "https://medium.com/%40ChadSecurity/cve-2024-41572-68397fae354b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json b/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json new file mode 100644 index 00000000000..831b5535bf6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq5w-h3jm-m95c", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7971" + ], + "details": "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7971" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/360700873" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q3q8-95m2-545r/GHSA-q3q8-95m2-545r.json b/advisories/unreviewed/2024/08/GHSA-q3q8-95m2-545r/GHSA-q3q8-95m2-545r.json new file mode 100644 index 00000000000..deb330be9cd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q3q8-95m2-545r/GHSA-q3q8-95m2-545r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3q8-95m2-545r", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7972" + ], + "details": "Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7972" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/345960102" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q6gq-mjvm-55fm/GHSA-q6gq-mjvm-55fm.json b/advisories/unreviewed/2024/08/GHSA-q6gq-mjvm-55fm/GHSA-q6gq-mjvm-55fm.json new file mode 100644 index 00000000000..0b4bfdf2649 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q6gq-mjvm-55fm/GHSA-q6gq-mjvm-55fm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6gq-mjvm-55fm", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-20488" + ], + "details": "A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20488" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-xss-9zmfHyZ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q8gr-qpfg-hv8p/GHSA-q8gr-qpfg-hv8p.json b/advisories/unreviewed/2024/08/GHSA-q8gr-qpfg-hv8p/GHSA-q8gr-qpfg-hv8p.json new file mode 100644 index 00000000000..32e72c1898a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q8gr-qpfg-hv8p/GHSA-q8gr-qpfg-hv8p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8gr-qpfg-hv8p", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-6386" + ], + "details": "The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6386" + }, + { + "type": "WEB", + "url": "https://sec.stealthcopter.com/wpml-rce-via-twig-ssti" + }, + { + "type": "WEB", + "url": "https://wpml.org" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f7fc91cc-e529-4362-8269-bf7ee0766e1e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json b/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json new file mode 100644 index 00000000000..2550d9845f1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r3h8-2v74-r6qj/GHSA-r3h8-2v74-r6qj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3h8-2v74-r6qj", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7976" + ], + "details": "Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7976" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/339654392" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v4c3-qgm8-jh35/GHSA-v4c3-qgm8-jh35.json b/advisories/unreviewed/2024/08/GHSA-v4c3-qgm8-jh35/GHSA-v4c3-qgm8-jh35.json new file mode 100644 index 00000000000..388ecf59c9c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v4c3-qgm8-jh35/GHSA-v4c3-qgm8-jh35.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4c3-qgm8-jh35", + "modified": "2024-08-21T21:30:47Z", + "published": "2024-08-21T21:30:47Z", + "aliases": [ + "CVE-2024-7977" + ], + "details": "Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7977" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/324770940" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wg2h-7567-vcrf/GHSA-wg2h-7567-vcrf.json b/advisories/unreviewed/2024/08/GHSA-wg2h-7567-vcrf/GHSA-wg2h-7567-vcrf.json index 7e6655af781..161e70103c9 100644 --- a/advisories/unreviewed/2024/08/GHSA-wg2h-7567-vcrf/GHSA-wg2h-7567-vcrf.json +++ b/advisories/unreviewed/2024/08/GHSA-wg2h-7567-vcrf/GHSA-wg2h-7567-vcrf.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json b/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json new file mode 100644 index 00000000000..4ce46001f37 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x38q-hvmx-rwhg", + "modified": "2024-08-21T21:30:46Z", + "published": "2024-08-21T21:30:46Z", + "aliases": [ + "CVE-2024-7965" + ], + "details": "Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7965" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/356196918" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-21T21:15:08Z" + } +} \ No newline at end of file