Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-10-28 00:31:39 +00:00
parent db82e8fd83
commit df414c7801
30 changed files with 220 additions and 56 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fcg-hwv9-g767",
"modified": "2023-10-19T15:31:06Z",
"modified": "2023-10-28T00:30:29Z",
"published": "2023-10-19T15:31:06Z",
"aliases": [
"CVE-2023-45883"
],
"details": "A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g9h-f994-3h4c",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46562"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47xw-vw6m-w9fq",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-28T00:30:31Z",
"aliases": [
"CVE-2023-5834"
],
"details": "HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5834"
},
{
"type": "WEB",
"url": "https://discuss.hashicorp.com/t/hcsec-2023-31-vagrant-s-windows-installer-allowed-directory-junction-write/59568"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1386"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pm7-5852-9cj6",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:30Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46556"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formFilter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xxx-xjp2-284m",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T00:30:29Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45554"
],
"details": "File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xgm-7mgw-vcg3",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46574"
],
"details": "An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xmf-7cqj-2h8m",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-28T00:30:31Z",
"aliases": [
"CVE-2023-46490"
],
"details": "SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "WEB",
"url": "https://github.com/Cacti/cacti/security/advisories/GHSA-f4r3-53jr-654c"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46490"
},
{
"type": "WEB",
"url": "https://gist.github.com/ISHGARD-2/a95632111138fcd7ccf7432ccb145b53"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8j8g-9794-h995",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-28T00:30:31Z",
"aliases": [
"CVE-2023-46587"
],
"details": "Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46587"
},
{
"type": "WEB",
"url": "https://github.com/nasroabd/vulns/tree/main/XnView/2.51.5"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97jg-3m56-w8ph",
"modified": "2023-10-19T18:30:30Z",
"modified": "2023-10-28T00:30:29Z",
"published": "2023-10-19T18:30:30Z",
"aliases": [
"CVE-2023-46033"
],
"details": "** UNSUPPORTED WHEN ASSIGNED ** D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9rvp-jg33-mp8v",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T00:30:30Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45754"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-338"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cjjx-jw4j-6587",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:30Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46554"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7rr-rj9q-jfww",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T00:30:30Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45555"
],
"details": "File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h43q-h523-j594",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46560"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -18,6 +18,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42406"
},
{
"type": "WEB",
"url": "https://github.com/1dreamGN/CVE/blob/main/CVE-2023-42406.md"
},
{
"type": "WEB",
"url": "https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_:sysmanage:editrole.php.md"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2q7-6q2x-2q9p",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46564"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j38r-mq7j-wgvr",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T00:30:30Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45747"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j7gf-5v9f-v496",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46559"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2cg-wrh8-h3xx",
"modified": "2023-10-25T18:32:25Z",
"modified": "2023-10-28T00:30:31Z",
"published": "2023-10-25T18:32:25Z",
"aliases": [
"CVE-2023-46558"
],
"details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7jf-8pgq-2mqc",
"modified": "2023-10-25T18:32:23Z",
"modified": "2023-10-28T00:30:30Z",
"published": "2023-10-25T18:32:23Z",
"aliases": [
"CVE-2023-45646"

Some files were not shown because too many files have changed in this diff Show More