diff --git a/advisories/github-reviewed/2019/11/GHSA-vvwv-h69m-wg6f/GHSA-vvwv-h69m-wg6f.json b/advisories/github-reviewed/2019/11/GHSA-vvwv-h69m-wg6f/GHSA-vvwv-h69m-wg6f.json index f987636ff16..911ab922bf4 100644 --- a/advisories/github-reviewed/2019/11/GHSA-vvwv-h69m-wg6f/GHSA-vvwv-h69m-wg6f.json +++ b/advisories/github-reviewed/2019/11/GHSA-vvwv-h69m-wg6f/GHSA-vvwv-h69m-wg6f.json @@ -40,6 +40,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12331" }, + { + "type": "WEB", + "url": "https://github.com/PHPOffice/PhpSpreadsheet/pull/1041" + }, + { + "type": "WEB", + "url": "https://github.com/PHPOffice/PhpSpreadsheet/commit/0e6238c69e863b58aeece61e48ea032696c6dccd" + }, { "type": "PACKAGE", "url": "https://github.com/PHPOffice/PhpSpreadsheet" diff --git a/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json b/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json index a40d183c683..87ee4e699bb 100644 --- a/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json +++ b/advisories/unreviewed/2023/11/GHSA-35r7-vh9q-xpf7/GHSA-35r7-vh9q-xpf7.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://crbug.com/1499298" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWHRLW3GDNFBFSBHDD4QOPUPX7ORTUEC/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5556" diff --git a/advisories/unreviewed/2023/11/GHSA-4cv2-qh42-x2j4/GHSA-4cv2-qh42-x2j4.json b/advisories/unreviewed/2023/11/GHSA-4cv2-qh42-x2j4/GHSA-4cv2-qh42-x2j4.json index 616fb42a60a..7bdfff7d1d2 100644 --- a/advisories/unreviewed/2023/11/GHSA-4cv2-qh42-x2j4/GHSA-4cv2-qh42-x2j4.json +++ b/advisories/unreviewed/2023/11/GHSA-4cv2-qh42-x2j4/GHSA-4cv2-qh42-x2j4.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1658432%2C1820983%2C1829252%2C1856072%2C1856091%2C1859030%2C1860943%2C1862782" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/" diff --git a/advisories/unreviewed/2023/11/GHSA-68m9-mw54-x3jx/GHSA-68m9-mw54-x3jx.json b/advisories/unreviewed/2023/11/GHSA-68m9-mw54-x3jx/GHSA-68m9-mw54-x3jx.json index 183dd3f582e..1c84625af62 100644 --- a/advisories/unreviewed/2023/11/GHSA-68m9-mw54-x3jx/GHSA-68m9-mw54-x3jx.json +++ b/advisories/unreviewed/2023/11/GHSA-68m9-mw54-x3jx/GHSA-68m9-mw54-x3jx.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1857430" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/" diff --git a/advisories/unreviewed/2023/11/GHSA-85qp-mxrm-pxg7/GHSA-85qp-mxrm-pxg7.json b/advisories/unreviewed/2023/11/GHSA-85qp-mxrm-pxg7/GHSA-85qp-mxrm-pxg7.json index 75b35032637..8c4f7c9a804 100644 --- a/advisories/unreviewed/2023/11/GHSA-85qp-mxrm-pxg7/GHSA-85qp-mxrm-pxg7.json +++ b/advisories/unreviewed/2023/11/GHSA-85qp-mxrm-pxg7/GHSA-85qp-mxrm-pxg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-85qp-mxrm-pxg7", - "modified": "2023-11-10T09:30:30Z", + "modified": "2023-11-23T03:34:08Z", "published": "2023-11-10T09:30:30Z", "aliases": [ "CVE-2023-47800" ], "details": "Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or destroying/disrupting MSSQL services.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-10T07:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-c2fx-6qc9-26x9/GHSA-c2fx-6qc9-26x9.json b/advisories/unreviewed/2023/11/GHSA-c2fx-6qc9-26x9/GHSA-c2fx-6qc9-26x9.json index 78b6c98b09a..ed5ce2d894b 100644 --- a/advisories/unreviewed/2023/11/GHSA-c2fx-6qc9-26x9/GHSA-c2fx-6qc9-26x9.json +++ b/advisories/unreviewed/2023/11/GHSA-c2fx-6qc9-26x9/GHSA-c2fx-6qc9-26x9.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1858570" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/" diff --git a/advisories/unreviewed/2023/11/GHSA-c9gw-j4mh-mj26/GHSA-c9gw-j4mh-mj26.json b/advisories/unreviewed/2023/11/GHSA-c9gw-j4mh-mj26/GHSA-c9gw-j4mh-mj26.json index f024d59095b..c298a7d10e2 100644 --- a/advisories/unreviewed/2023/11/GHSA-c9gw-j4mh-mj26/GHSA-c9gw-j4mh-mj26.json +++ b/advisories/unreviewed/2023/11/GHSA-c9gw-j4mh-mj26/GHSA-c9gw-j4mh-mj26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9gw-j4mh-mj26", - "modified": "2023-11-22T18:30:55Z", + "modified": "2023-11-23T03:34:08Z", "published": "2023-11-21T15:30:20Z", "aliases": [ "CVE-2023-6204" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1841050" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/" diff --git a/advisories/unreviewed/2023/11/GHSA-fggx-frxq-cpx8/GHSA-fggx-frxq-cpx8.json b/advisories/unreviewed/2023/11/GHSA-fggx-frxq-cpx8/GHSA-fggx-frxq-cpx8.json index 3fba4cb3021..d09f87a6307 100644 --- a/advisories/unreviewed/2023/11/GHSA-fggx-frxq-cpx8/GHSA-fggx-frxq-cpx8.json +++ b/advisories/unreviewed/2023/11/GHSA-fggx-frxq-cpx8/GHSA-fggx-frxq-cpx8.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://crbug.com/1497997" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWHRLW3GDNFBFSBHDD4QOPUPX7ORTUEC/" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5556" diff --git a/advisories/unreviewed/2023/11/GHSA-gv4f-48g4-9pqh/GHSA-gv4f-48g4-9pqh.json b/advisories/unreviewed/2023/11/GHSA-gv4f-48g4-9pqh/GHSA-gv4f-48g4-9pqh.json new file mode 100644 index 00000000000..08f564866fc --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gv4f-48g4-9pqh/GHSA-gv4f-48g4-9pqh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv4f-48g4-9pqh", + "modified": "2023-11-23T03:34:08Z", + "published": "2023-11-23T03:34:08Z", + "aliases": [ + "CVE-2023-29073" + ], + "details": "A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29073" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-23T03:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gvr6-g64h-9mj2/GHSA-gvr6-g64h-9mj2.json b/advisories/unreviewed/2023/11/GHSA-gvr6-g64h-9mj2/GHSA-gvr6-g64h-9mj2.json index 7d12883585a..644f9d57f3a 100644 --- a/advisories/unreviewed/2023/11/GHSA-gvr6-g64h-9mj2/GHSA-gvr6-g64h-9mj2.json +++ b/advisories/unreviewed/2023/11/GHSA-gvr6-g64h-9mj2/GHSA-gvr6-g64h-9mj2.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1855345" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/" diff --git a/advisories/unreviewed/2023/11/GHSA-h4m4-6cfw-5q6g/GHSA-h4m4-6cfw-5q6g.json b/advisories/unreviewed/2023/11/GHSA-h4m4-6cfw-5q6g/GHSA-h4m4-6cfw-5q6g.json index bfa1f0fbeb2..e6c21db3764 100644 --- a/advisories/unreviewed/2023/11/GHSA-h4m4-6cfw-5q6g/GHSA-h4m4-6cfw-5q6g.json +++ b/advisories/unreviewed/2023/11/GHSA-h4m4-6cfw-5q6g/GHSA-h4m4-6cfw-5q6g.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1854076" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/" diff --git a/advisories/unreviewed/2023/11/GHSA-jg57-vh55-3g23/GHSA-jg57-vh55-3g23.json b/advisories/unreviewed/2023/11/GHSA-jg57-vh55-3g23/GHSA-jg57-vh55-3g23.json index b0884814cae..4a14a89bdf9 100644 --- a/advisories/unreviewed/2023/11/GHSA-jg57-vh55-3g23/GHSA-jg57-vh55-3g23.json +++ b/advisories/unreviewed/2023/11/GHSA-jg57-vh55-3g23/GHSA-jg57-vh55-3g23.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://community.openvpn.net/openvpn/wiki/CVE-2023-46850" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3FS46ANNTAVLIQY56ZKGM5CBTRVBUNE/" + }, { "type": "WEB", "url": "https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/" diff --git a/advisories/unreviewed/2023/11/GHSA-mwwq-v92j-38xr/GHSA-mwwq-v92j-38xr.json b/advisories/unreviewed/2023/11/GHSA-mwwq-v92j-38xr/GHSA-mwwq-v92j-38xr.json index e137b27db0b..60b2c7af183 100644 --- a/advisories/unreviewed/2023/11/GHSA-mwwq-v92j-38xr/GHSA-mwwq-v92j-38xr.json +++ b/advisories/unreviewed/2023/11/GHSA-mwwq-v92j-38xr/GHSA-mwwq-v92j-38xr.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://advisory.splunk.com/advisories/SVD-2023-1104" }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/6cb7e011-55fb-48e3-a98d-164fa854e37e/" + }, { "type": "WEB", "url": "https://research.splunk.com/application/a053e6a6-2146-483a-9798-2d43652f3299/" diff --git a/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json b/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json index 04199d3c760..1e2419c2356 100644 --- a/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json +++ b/advisories/unreviewed/2023/11/GHSA-p99v-qjfm-8vvq/GHSA-p99v-qjfm-8vvq.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://community.openvpn.net/openvpn/wiki/CVE-2023-46849" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3FS46ANNTAVLIQY56ZKGM5CBTRVBUNE/" + }, { "type": "WEB", "url": "https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/" diff --git a/advisories/unreviewed/2023/11/GHSA-qvr4-hgxw-v9xj/GHSA-qvr4-hgxw-v9xj.json b/advisories/unreviewed/2023/11/GHSA-qvr4-hgxw-v9xj/GHSA-qvr4-hgxw-v9xj.json index 28a1c97ae29..b16e66f44b6 100644 --- a/advisories/unreviewed/2023/11/GHSA-qvr4-hgxw-v9xj/GHSA-qvr4-hgxw-v9xj.json +++ b/advisories/unreviewed/2023/11/GHSA-qvr4-hgxw-v9xj/GHSA-qvr4-hgxw-v9xj.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1861344" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5561" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-49/"