diff --git a/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json b/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json index 7d50ac3868d..a1534f2649d 100644 --- a/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json +++ b/advisories/unreviewed/2023/10/GHSA-2fcg-hwv9-g767/GHSA-2fcg-hwv9-g767.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2fcg-hwv9-g767", - "modified": "2023-10-19T15:31:06Z", + "modified": "2023-10-28T00:30:29Z", "published": "2023-10-19T15:31:06Z", "aliases": [ "CVE-2023-45883" ], "details": "A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json b/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json index 021f55d042d..208dd575a79 100644 --- a/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json +++ b/advisories/unreviewed/2023/10/GHSA-3g9h-f994-3h4c/GHSA-3g9h-f994-3h4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g9h-f994-3h4c", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46562" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-47xw-vw6m-w9fq/GHSA-47xw-vw6m-w9fq.json b/advisories/unreviewed/2023/10/GHSA-47xw-vw6m-w9fq/GHSA-47xw-vw6m-w9fq.json new file mode 100644 index 00000000000..847085dc426 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-47xw-vw6m-w9fq/GHSA-47xw-vw6m-w9fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47xw-vw6m-w9fq", + "modified": "2023-10-28T00:30:31Z", + "published": "2023-10-28T00:30:31Z", + "aliases": [ + "CVE-2023-5834" + ], + "details": "HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5834" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2023-31-vagrant-s-windows-installer-allowed-directory-junction-write/59568" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1386" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json b/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json index b6f0b580dcd..caadab1f314 100644 --- a/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json +++ b/advisories/unreviewed/2023/10/GHSA-4pm7-5852-9cj6/GHSA-4pm7-5852-9cj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pm7-5852-9cj6", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46556" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formFilter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json b/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json index ec2322d18b4..5d5b787a8a7 100644 --- a/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json +++ b/advisories/unreviewed/2023/10/GHSA-4xxx-xjp2-284m/GHSA-4xxx-xjp2-284m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4xxx-xjp2-284m", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:29Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45554" ], "details": "File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json b/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json index 667beb3bd9b..233fa93f5ea 100644 --- a/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json +++ b/advisories/unreviewed/2023/10/GHSA-5xgm-7mgw-vcg3/GHSA-5xgm-7mgw-vcg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5xgm-7mgw-vcg3", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46574" ], "details": "An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-6xmf-7cqj-2h8m/GHSA-6xmf-7cqj-2h8m.json b/advisories/unreviewed/2023/10/GHSA-6xmf-7cqj-2h8m/GHSA-6xmf-7cqj-2h8m.json new file mode 100644 index 00000000000..3f2cec0602b --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-6xmf-7cqj-2h8m/GHSA-6xmf-7cqj-2h8m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xmf-7cqj-2h8m", + "modified": "2023-10-28T00:30:31Z", + "published": "2023-10-28T00:30:31Z", + "aliases": [ + "CVE-2023-46490" + ], + "details": "SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/Cacti/cacti/security/advisories/GHSA-f4r3-53jr-654c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46490" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ISHGARD-2/a95632111138fcd7ccf7432ccb145b53" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json b/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json new file mode 100644 index 00000000000..07510147fe9 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-8j8g-9794-h995/GHSA-8j8g-9794-h995.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j8g-9794-h995", + "modified": "2023-10-28T00:30:31Z", + "published": "2023-10-28T00:30:31Z", + "aliases": [ + "CVE-2023-46587" + ], + "details": "Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46587" + }, + { + "type": "WEB", + "url": "https://github.com/nasroabd/vulns/tree/main/XnView/2.51.5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json b/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json index 7d16849caaf..4fc9d287de4 100644 --- a/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json +++ b/advisories/unreviewed/2023/10/GHSA-97jg-3m56-w8ph/GHSA-97jg-3m56-w8ph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97jg-3m56-w8ph", - "modified": "2023-10-19T18:30:30Z", + "modified": "2023-10-28T00:30:29Z", "published": "2023-10-19T18:30:30Z", "aliases": [ "CVE-2023-46033" ], "details": "** UNSUPPORTED WHEN ASSIGNED ** D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json b/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json index 6356e92b216..3318664cc80 100644 --- a/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json +++ b/advisories/unreviewed/2023/10/GHSA-9rvp-jg33-mp8v/GHSA-9rvp-jg33-mp8v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9rvp-jg33-mp8v", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45754" diff --git a/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json b/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json index 1ce8f891c20..38d5a1fe6d3 100644 --- a/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json +++ b/advisories/unreviewed/2023/10/GHSA-cj2w-wj5h-c44x/GHSA-cj2w-wj5h-c44x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-338" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json b/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json index 7db834f4e9a..90118b468fc 100644 --- a/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json +++ b/advisories/unreviewed/2023/10/GHSA-cjjx-jw4j-6587/GHSA-cjjx-jw4j-6587.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjjx-jw4j-6587", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46554" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json b/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json index cdae0299a52..cb179619715 100644 --- a/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json +++ b/advisories/unreviewed/2023/10/GHSA-g7rr-rj9q-jfww/GHSA-g7rr-rj9q-jfww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7rr-rj9q-jfww", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45555" ], "details": "File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json b/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json index 6051cb3b5ed..df53a51d2e4 100644 --- a/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json +++ b/advisories/unreviewed/2023/10/GHSA-h43q-h523-j594/GHSA-h43q-h523-j594.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h43q-h523-j594", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46560" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json b/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json index 5fd751e8824..308ef41d64d 100644 --- a/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json +++ b/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42406" }, + { + "type": "WEB", + "url": "https://github.com/1dreamGN/CVE/blob/main/CVE-2023-42406.md" + }, { "type": "WEB", "url": "https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_:sysmanage:editrole.php.md" diff --git a/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json b/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json index b61155ef4ff..56c2fd988cd 100644 --- a/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json +++ b/advisories/unreviewed/2023/10/GHSA-j2q7-6q2x-2q9p/GHSA-j2q7-6q2x-2q9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2q7-6q2x-2q9p", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46564" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json b/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json index d5bf8475d81..2d58c4c8540 100644 --- a/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json +++ b/advisories/unreviewed/2023/10/GHSA-j38r-mq7j-wgvr/GHSA-j38r-mq7j-wgvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j38r-mq7j-wgvr", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45747" diff --git a/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json b/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json index 543ad192883..4e6edd9840d 100644 --- a/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json +++ b/advisories/unreviewed/2023/10/GHSA-j7gf-5v9f-v496/GHSA-j7gf-5v9f-v496.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j7gf-5v9f-v496", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46559" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json b/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json index ad82e8535c9..2a78db526eb 100644 --- a/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json +++ b/advisories/unreviewed/2023/10/GHSA-m2cg-wrh8-h3xx/GHSA-m2cg-wrh8-h3xx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2cg-wrh8-h3xx", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46558" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json b/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json index 10311503c61..9acbac5d340 100644 --- a/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json +++ b/advisories/unreviewed/2023/10/GHSA-m7jf-8pgq-2mqc/GHSA-m7jf-8pgq-2mqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7jf-8pgq-2mqc", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45646" diff --git a/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json b/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json index f45d6ba5433..4288b47e1cc 100644 --- a/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json +++ b/advisories/unreviewed/2023/10/GHSA-p28p-p2pv-wq98/GHSA-p28p-p2pv-wq98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p28p-p2pv-wq98", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45634" diff --git a/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json b/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json index 45f19523e3b..a50a68ac60d 100644 --- a/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json +++ b/advisories/unreviewed/2023/10/GHSA-p4f9-fq6j-5cff/GHSA-p4f9-fq6j-5cff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4f9-fq6j-5cff", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45755" diff --git a/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json b/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json index b708bb696a6..43d15f77fd4 100644 --- a/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json +++ b/advisories/unreviewed/2023/10/GHSA-p678-r7cm-66fh/GHSA-p678-r7cm-66fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p678-r7cm-66fh", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46563" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json b/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json index 1880eb528f1..1c66bdc1a0c 100644 --- a/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json +++ b/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfwv-624m-h3m9", - "modified": "2023-10-21T00:30:47Z", + "modified": "2023-10-28T00:30:29Z", "published": "2023-10-21T00:30:47Z", "aliases": [ "CVE-2023-38191" ], "details": "An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json b/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json index a108ac9e493..199f1c42a77 100644 --- a/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json +++ b/advisories/unreviewed/2023/10/GHSA-q5qf-qc2j-h64w/GHSA-q5qf-qc2j-h64w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q5qf-qc2j-h64w", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45750" diff --git a/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json b/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json index 422827619d2..5c56195e607 100644 --- a/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json +++ b/advisories/unreviewed/2023/10/GHSA-qg2v-xqqh-rxvv/GHSA-qg2v-xqqh-rxvv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qg2v-xqqh-rxvv", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:31Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46557" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json b/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json index 83248c89f10..086e4d8e2c9 100644 --- a/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json +++ b/advisories/unreviewed/2023/10/GHSA-qxjh-36c6-ww4r/GHSA-qxjh-36c6-ww4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxjh-36c6-ww4r", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45756" diff --git a/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json b/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json index fcf0efb5174..0e3000c3158 100644 --- a/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json +++ b/advisories/unreviewed/2023/10/GHSA-rff8-hf8p-29h7/GHSA-rff8-hf8p-29h7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rff8-hf8p-29h7", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46555" ], "details": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPortFw.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json b/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json index 4a8234d3d63..9616879928c 100644 --- a/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json +++ b/advisories/unreviewed/2023/10/GHSA-wfjp-4mpm-mr6x/GHSA-wfjp-4mpm-mr6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfjp-4mpm-mr6x", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45644" diff --git a/advisories/unreviewed/2023/10/GHSA-xh5x-756j-vhq8/GHSA-xh5x-756j-vhq8.json b/advisories/unreviewed/2023/10/GHSA-xh5x-756j-vhq8/GHSA-xh5x-756j-vhq8.json index b701f668beb..f8349e31bc7 100644 --- a/advisories/unreviewed/2023/10/GHSA-xh5x-756j-vhq8/GHSA-xh5x-756j-vhq8.json +++ b/advisories/unreviewed/2023/10/GHSA-xh5x-756j-vhq8/GHSA-xh5x-756j-vhq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5x-756j-vhq8", - "modified": "2023-10-25T18:32:23Z", + "modified": "2023-10-28T00:30:30Z", "published": "2023-10-25T18:32:23Z", "aliases": [ "CVE-2023-45637"