From e18db03b349c97e5b65bfa2cb9ef8f8793ecbd0b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 5 Feb 2024 18:32:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-q34c-v76q-8jx6.json | 3 +- .../GHSA-wrh4-6832-wg62.json | 4 ++ .../GHSA-f47p-g3vj-j588.json | 15 +++++-- .../GHSA-x2m3-cgh8-69x5.json | 4 ++ .../GHSA-3r5f-38cp-r8x3.json | 12 +++++- .../GHSA-j6jf-4ffc-g9xf.json | 8 +++- .../GHSA-25g8-7mhh-fm84.json | 11 +++-- .../GHSA-5q2h-m2hm-4r3w.json | 11 +++-- .../GHSA-663j-9vv5-mmf4.json | 11 +++-- .../GHSA-89c9-2mcj-c9gr.json | 2 +- .../GHSA-8h9j-pxfp-9p97.json | 11 +++-- .../GHSA-crgw-m82j-jv5c.json | 3 +- .../GHSA-f3p3-3pq5-xp8x.json | 11 +++-- .../GHSA-hpcp-jfj7-rjww.json | 11 +++-- .../GHSA-j3rg-72x7-gm5r.json | 2 +- .../GHSA-m653-22c6-v2w8.json | 11 +++-- .../GHSA-rq2f-mxxc-3hv5.json | 11 +++-- .../GHSA-2cmm-m4c8-c4wp.json | 35 +++++++++++++++ .../GHSA-2qm8-4j25-v4w6.json | 35 +++++++++++++++ .../GHSA-34rx-mprw-whv5.json | 43 +++++++++++++++++++ .../GHSA-4v2m-666w-ffm3.json | 38 ++++++++++++++++ .../GHSA-6h6q-fm45-w3hv.json | 35 +++++++++++++++ .../GHSA-9cgf-pxwq-2cpw.json | 43 +++++++++++++++++++ .../GHSA-gw24-882g-rww6.json | 35 +++++++++++++++ .../GHSA-gwp7-vjfg-ffh8.json | 38 ++++++++++++++++ .../GHSA-h8jm-hh42-2j69.json | 35 +++++++++++++++ .../GHSA-mf92-wvmg-38g9.json | 39 +++++++++++++++++ .../GHSA-mmrc-cc78-9f9w.json | 35 +++++++++++++++ .../GHSA-vh8x-63x5-57cx.json | 35 +++++++++++++++ .../GHSA-vj6f-c5mv-86jm.json | 35 +++++++++++++++ .../GHSA-vm59-55f6-4qp9.json | 42 ++++++++++++++++++ .../GHSA-vrhp-w2wh-93c3.json | 35 +++++++++++++++ .../GHSA-whq9-vwxq-6f23.json | 35 +++++++++++++++ .../GHSA-xwmx-qhv2-jx64.json | 35 +++++++++++++++ 34 files changed, 725 insertions(+), 44 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-2cmm-m4c8-c4wp/GHSA-2cmm-m4c8-c4wp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-2qm8-4j25-v4w6/GHSA-2qm8-4j25-v4w6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4v2m-666w-ffm3/GHSA-4v2m-666w-ffm3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9cgf-pxwq-2cpw/GHSA-9cgf-pxwq-2cpw.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gw24-882g-rww6/GHSA-gw24-882g-rww6.json create mode 100644 advisories/unreviewed/2024/02/GHSA-gwp7-vjfg-ffh8/GHSA-gwp7-vjfg-ffh8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-h8jm-hh42-2j69/GHSA-h8jm-hh42-2j69.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vh8x-63x5-57cx/GHSA-vh8x-63x5-57cx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vj6f-c5mv-86jm/GHSA-vj6f-c5mv-86jm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json create mode 100644 advisories/unreviewed/2024/02/GHSA-xwmx-qhv2-jx64/GHSA-xwmx-qhv2-jx64.json diff --git a/advisories/unreviewed/2022/05/GHSA-q34c-v76q-8jx6/GHSA-q34c-v76q-8jx6.json b/advisories/unreviewed/2022/05/GHSA-q34c-v76q-8jx6/GHSA-q34c-v76q-8jx6.json index 530eeb435ef..0417037d2ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-q34c-v76q-8jx6/GHSA-q34c-v76q-8jx6.json +++ b/advisories/unreviewed/2022/05/GHSA-q34c-v76q-8jx6/GHSA-q34c-v76q-8jx6.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-614" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-wrh4-6832-wg62/GHSA-wrh4-6832-wg62.json b/advisories/unreviewed/2023/02/GHSA-wrh4-6832-wg62/GHSA-wrh4-6832-wg62.json index 53ef55f3757..2cfc95a3eda 100644 --- a/advisories/unreviewed/2023/02/GHSA-wrh4-6832-wg62/GHSA-wrh4-6832-wg62.json +++ b/advisories/unreviewed/2023/02/GHSA-wrh4-6832-wg62/GHSA-wrh4-6832-wg62.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://wpscan.com/vulnerability/fd50f2d6-e420-4220-b485-73f33227e8f8" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176983/WordPress-Simple-URLs-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-f47p-g3vj-j588/GHSA-f47p-g3vj-j588.json b/advisories/unreviewed/2023/06/GHSA-f47p-g3vj-j588/GHSA-f47p-g3vj-j588.json index 30d3bc6dacd..0cfd5f4dec4 100644 --- a/advisories/unreviewed/2023/06/GHSA-f47p-g3vj-j588/GHSA-f47p-g3vj-j588.json +++ b/advisories/unreviewed/2023/06/GHSA-f47p-g3vj-j588/GHSA-f47p-g3vj-j588.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f47p-g3vj-j588", - "modified": "2023-06-23T21:30:33Z", + "modified": "2024-02-05T18:31:35Z", "published": "2023-06-23T21:30:33Z", "aliases": [ "CVE-2023-35759" ], "details": "In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -21,13 +24,17 @@ { "type": "WEB", "url": "https://community.progress.com/s/article/Product-Alert-Bulletin-June-2023" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176978/WhatsUp-Gold-2022-22.1.0-Build-39-Cross-Site-Scripting.html" } ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-23T20:15:09Z" diff --git a/advisories/unreviewed/2023/06/GHSA-x2m3-cgh8-69x5/GHSA-x2m3-cgh8-69x5.json b/advisories/unreviewed/2023/06/GHSA-x2m3-cgh8-69x5/GHSA-x2m3-cgh8-69x5.json index 9ed11de9fb1..5e28cb54ec6 100644 --- a/advisories/unreviewed/2023/06/GHSA-x2m3-cgh8-69x5/GHSA-x2m3-cgh8-69x5.json +++ b/advisories/unreviewed/2023/06/GHSA-x2m3-cgh8-69x5/GHSA-x2m3-cgh8-69x5.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://zigrin.com/advisories/misp-stored-xss/" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176975/MISP-2.4.171-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-3r5f-38cp-r8x3/GHSA-3r5f-38cp-r8x3.json b/advisories/unreviewed/2023/10/GHSA-3r5f-38cp-r8x3/GHSA-3r5f-38cp-r8x3.json index 76df28c930d..901f6730d99 100644 --- a/advisories/unreviewed/2023/10/GHSA-3r5f-38cp-r8x3/GHSA-3r5f-38cp-r8x3.json +++ b/advisories/unreviewed/2023/10/GHSA-3r5f-38cp-r8x3/GHSA-3r5f-38cp-r8x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r5f-38cp-r8x3", - "modified": "2023-10-11T18:30:27Z", + "modified": "2024-02-05T18:31:36Z", "published": "2023-10-04T12:30:14Z", "aliases": [ "CVE-2023-43261" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/win3zz/CVE-2023-43261" }, + { + "type": "WEB", + "url": "https://medium.com/%40win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf" + }, { "type": "WEB", "url": "https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf" @@ -37,6 +41,10 @@ "type": "WEB", "url": "http://milesight.com" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html" + }, { "type": "WEB", "url": "http://ur5x.com" @@ -46,7 +54,7 @@ "cwe_ids": [ "CWE-532" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-04T12:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-j6jf-4ffc-g9xf/GHSA-j6jf-4ffc-g9xf.json b/advisories/unreviewed/2023/10/GHSA-j6jf-4ffc-g9xf/GHSA-j6jf-4ffc-g9xf.json index 6f530930b2c..4a14d9e967c 100644 --- a/advisories/unreviewed/2023/10/GHSA-j6jf-4ffc-g9xf/GHSA-j6jf-4ffc-g9xf.json +++ b/advisories/unreviewed/2023/10/GHSA-j6jf-4ffc-g9xf/GHSA-j6jf-4ffc-g9xf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6jf-4ffc-g9xf", - "modified": "2023-10-31T15:30:20Z", + "modified": "2024-02-05T18:31:36Z", "published": "2023-10-25T18:32:21Z", "aliases": [ "CVE-2023-36085" @@ -24,13 +24,17 @@ { "type": "WEB", "url": "https://github.com/omershaik0/Handmade_Exploits/tree/main/SISQUALWFM-Host-Header-Injection-CVE-2023-36085" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176991/SISQUAL-WFM-7.1.319.103-Host-Header-Injection.html" } ], "database_specific": { "cwe_ids": [ "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-25T18:17:28Z" diff --git a/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json b/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json index 4038fee7b10..10f3a4095f2 100644 --- a/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json +++ b/advisories/unreviewed/2024/01/GHSA-25g8-7mhh-fm84/GHSA-25g8-7mhh-fm84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25g8-7mhh-fm84", - "modified": "2024-01-29T15:30:30Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-29T15:30:30Z", "aliases": [ "CVE-2023-7200" ], "details": "The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-29T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json b/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json index 350bbcb0548..2c2c73e818e 100644 --- a/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json +++ b/advisories/unreviewed/2024/01/GHSA-5q2h-m2hm-4r3w/GHSA-5q2h-m2hm-4r3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q2h-m2hm-4r3w", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-51886" ], "details": "Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \\convertpath.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json b/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json index fa94cc2576f..5b845ffa5bc 100644 --- a/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json +++ b/advisories/unreviewed/2024/01/GHSA-663j-9vv5-mmf4/GHSA-663j-9vv5-mmf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-663j-9vv5-mmf4", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-51887" ], "details": "Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-89c9-2mcj-c9gr/GHSA-89c9-2mcj-c9gr.json b/advisories/unreviewed/2024/01/GHSA-89c9-2mcj-c9gr/GHSA-89c9-2mcj-c9gr.json index b0184c95f52..ffe5295c159 100644 --- a/advisories/unreviewed/2024/01/GHSA-89c9-2mcj-c9gr/GHSA-89c9-2mcj-c9gr.json +++ b/advisories/unreviewed/2024/01/GHSA-89c9-2mcj-c9gr/GHSA-89c9-2mcj-c9gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89c9-2mcj-c9gr", - "modified": "2024-01-30T09:30:34Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-30T09:30:34Z", "aliases": [ "CVE-2024-1061" diff --git a/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json b/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json index 8d93964d7f8..cbe20707762 100644 --- a/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json +++ b/advisories/unreviewed/2024/01/GHSA-8h9j-pxfp-9p97/GHSA-8h9j-pxfp-9p97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8h9j-pxfp-9p97", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2023-51885" ], "details": "Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T17:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json b/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json index 8b816cb6283..1dbc98c93dd 100644 --- a/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json +++ b/advisories/unreviewed/2024/01/GHSA-crgw-m82j-jv5c/GHSA-crgw-m82j-jv5c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-552" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json b/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json index 02ca1f17920..16c6ad32a17 100644 --- a/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json +++ b/advisories/unreviewed/2024/01/GHSA-f3p3-3pq5-xp8x/GHSA-f3p3-3pq5-xp8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3p3-3pq5-xp8x", - "modified": "2024-01-29T21:30:27Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-29T21:30:27Z", "aliases": [ "CVE-2024-24135" ], "details": "Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-29T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json b/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json index 63475ad93c0..6ded70bfaf2 100644 --- a/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json +++ b/advisories/unreviewed/2024/01/GHSA-hpcp-jfj7-rjww/GHSA-hpcp-jfj7-rjww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hpcp-jfj7-rjww", - "modified": "2024-01-29T15:30:29Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-29T15:30:29Z", "aliases": [ "CVE-2023-5124" ], "details": "The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-29T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json b/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json index dda92213d8e..49525645560 100644 --- a/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json +++ b/advisories/unreviewed/2024/01/GHSA-j3rg-72x7-gm5r/GHSA-j3rg-72x7-gm5r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json b/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json index 873c6c7fb88..3e4ea425106 100644 --- a/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json +++ b/advisories/unreviewed/2024/01/GHSA-m653-22c6-v2w8/GHSA-m653-22c6-v2w8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m653-22c6-v2w8", - "modified": "2024-01-29T15:30:30Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-29T15:30:30Z", "aliases": [ "CVE-2023-7204" ], "details": "The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-29T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rq2f-mxxc-3hv5/GHSA-rq2f-mxxc-3hv5.json b/advisories/unreviewed/2024/01/GHSA-rq2f-mxxc-3hv5/GHSA-rq2f-mxxc-3hv5.json index e582e466512..080556b9f75 100644 --- a/advisories/unreviewed/2024/01/GHSA-rq2f-mxxc-3hv5/GHSA-rq2f-mxxc-3hv5.json +++ b/advisories/unreviewed/2024/01/GHSA-rq2f-mxxc-3hv5/GHSA-rq2f-mxxc-3hv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rq2f-mxxc-3hv5", - "modified": "2024-01-30T03:30:30Z", + "modified": "2024-02-05T18:31:36Z", "published": "2024-01-30T03:30:30Z", "aliases": [ "CVE-2023-37571" ], "details": "Softing TH SCOPE through 3.70 allows XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-30T01:15:58Z" diff --git a/advisories/unreviewed/2024/02/GHSA-2cmm-m4c8-c4wp/GHSA-2cmm-m4c8-c4wp.json b/advisories/unreviewed/2024/02/GHSA-2cmm-m4c8-c4wp/GHSA-2cmm-m4c8-c4wp.json new file mode 100644 index 00000000000..14995c13473 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2cmm-m4c8-c4wp/GHSA-2cmm-m4c8-c4wp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cmm-m4c8-c4wp", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24263" + ], + "details": "Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24263" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/lotos_detects/blob/main/lotos_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-2qm8-4j25-v4w6/GHSA-2qm8-4j25-v4w6.json b/advisories/unreviewed/2024/02/GHSA-2qm8-4j25-v4w6/GHSA-2qm8-4j25-v4w6.json new file mode 100644 index 00000000000..11a84e19dc9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2qm8-4j25-v4w6/GHSA-2qm8-4j25-v4w6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qm8-4j25-v4w6", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24265" + ], + "details": "gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24265" + }, + { + "type": "WEB", + "url": "https://github.com/yinluming13579/gpac_defects/blob/main/gpac_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json b/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json new file mode 100644 index 00000000000..308b50b06f2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-34rx-mprw-whv5/GHSA-34rx-mprw-whv5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34rx-mprw-whv5", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-23054" + ], + "details": "An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23054" + }, + { + "type": "WEB", + "url": "https://github.com/c0d3x27/CVEs/blob/main/CVE-2024-23054/README.md" + }, + { + "type": "WEB", + "url": "http://plone.com" + }, + { + "type": "WEB", + "url": "http://ploneorg.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4v2m-666w-ffm3/GHSA-4v2m-666w-ffm3.json b/advisories/unreviewed/2024/02/GHSA-4v2m-666w-ffm3/GHSA-4v2m-666w-ffm3.json new file mode 100644 index 00000000000..37cbf96cdff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4v2m-666w-ffm3/GHSA-4v2m-666w-ffm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v2m-666w-ffm3", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-0323" + ], + "details": "Use of a Broken or Risky Cryptographic Algorithm vulnerability in B&R Industrial Automation Automation Runtime (SDM modules).\n\n\n\nThe FTP server used on the B&R\nAutomation Runtime supports unsecure encryption mechanisms, such as SSLv3,\nTLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct\nman-in-the-middle attacks or to decrypt communications between the affected product\nclients.  \n\nThis issue affects Automation Runtime: from 14.0 before 14.93.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0323" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA23P004_FTP_uses_unsecure_encryption_mechanisms-f57c147c.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json b/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json new file mode 100644 index 00000000000..1715004f18d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6h6q-fm45-w3hv/GHSA-6h6q-fm45-w3hv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h6q-fm45-w3hv", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24259" + ], + "details": "mupdf v1.23.9 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24259" + }, + { + "type": "WEB", + "url": "https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9cgf-pxwq-2cpw/GHSA-9cgf-pxwq-2cpw.json b/advisories/unreviewed/2024/02/GHSA-9cgf-pxwq-2cpw/GHSA-9cgf-pxwq-2cpw.json new file mode 100644 index 00000000000..7ad72507408 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9cgf-pxwq-2cpw/GHSA-9cgf-pxwq-2cpw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cgf-pxwq-2cpw", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24397" + ], + "details": "Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24397" + }, + { + "type": "WEB", + "url": "https://cloud-trustit.spp.at/s/Pi78FFazHamJQ5R" + }, + { + "type": "WEB", + "url": "https://cves.at/posts/cve-2024-24397/writeup/" + }, + { + "type": "WEB", + "url": "http://stimulsoft.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gw24-882g-rww6/GHSA-gw24-882g-rww6.json b/advisories/unreviewed/2024/02/GHSA-gw24-882g-rww6/GHSA-gw24-882g-rww6.json new file mode 100644 index 00000000000..f86fcf27b67 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gw24-882g-rww6/GHSA-gw24-882g-rww6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw24-882g-rww6", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24468" + ], + "details": "Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24468" + }, + { + "type": "WEB", + "url": "https://github.com/tang-0717/cms/blob/main/3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gwp7-vjfg-ffh8/GHSA-gwp7-vjfg-ffh8.json b/advisories/unreviewed/2024/02/GHSA-gwp7-vjfg-ffh8/GHSA-gwp7-vjfg-ffh8.json new file mode 100644 index 00000000000..6fd34e583bb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gwp7-vjfg-ffh8/GHSA-gwp7-vjfg-ffh8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwp7-vjfg-ffh8", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2023-6028" + ], + "details": "A reflected\ncross-site scripting (XSS) vulnerability exists in the SVG version of System\nDiagnostics Manager of B&R Automation Runtime versions <= G4.93 that\nenables a remote attacker to execute arbitrary JavaScript code in the context\nof the attacked user’s browser session.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6028" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA23P018_SDM_Web_interface_vulnerable_to_XSS-1d75bee8.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-h8jm-hh42-2j69/GHSA-h8jm-hh42-2j69.json b/advisories/unreviewed/2024/02/GHSA-h8jm-hh42-2j69/GHSA-h8jm-hh42-2j69.json new file mode 100644 index 00000000000..abfaa3a9aa1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-h8jm-hh42-2j69/GHSA-h8jm-hh42-2j69.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8jm-hh42-2j69", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24260" + ], + "details": "media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24260" + }, + { + "type": "WEB", + "url": "https://github.com/yinluming13579/media-server_defects/blob/main/media-server_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json b/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json new file mode 100644 index 00000000000..e1684d4388c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mf92-wvmg-38g9/GHSA-mf92-wvmg-38g9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf92-wvmg-38g9", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2023-47355" + ], + "details": "The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47355" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.eypcnnapps.quickreboot/blob/main/CWE-925.md" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.eypcnnapps.quickreboot" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json b/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json new file mode 100644 index 00000000000..5f37639ca80 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmrc-cc78-9f9w", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24469" + ], + "details": "Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24469" + }, + { + "type": "WEB", + "url": "https://github.com/tang-0717/cms/blob/main/2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vh8x-63x5-57cx/GHSA-vh8x-63x5-57cx.json b/advisories/unreviewed/2024/02/GHSA-vh8x-63x5-57cx/GHSA-vh8x-63x5-57cx.json new file mode 100644 index 00000000000..bc979c5b461 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vh8x-63x5-57cx/GHSA-vh8x-63x5-57cx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh8x-63x5-57cx", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24262" + ], + "details": "media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24262" + }, + { + "type": "WEB", + "url": "https://github.com/LuMingYinDetect/media-server_detect/blob/main/media_server_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vj6f-c5mv-86jm/GHSA-vj6f-c5mv-86jm.json b/advisories/unreviewed/2024/02/GHSA-vj6f-c5mv-86jm/GHSA-vj6f-c5mv-86jm.json new file mode 100644 index 00000000000..809066b7d79 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vj6f-c5mv-86jm/GHSA-vj6f-c5mv-86jm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj6f-c5mv-86jm", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24266" + ], + "details": "gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24266" + }, + { + "type": "WEB", + "url": "https://github.com/yinluming13579/gpac_defects/blob/main/gpac_2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json b/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json new file mode 100644 index 00000000000..c04a4f7df1d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm59-55f6-4qp9", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2023-6874" + ], + "details": "Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6874" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/069Vm000000WXaOIAW" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/gecko_sdk" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json b/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json new file mode 100644 index 00000000000..76a8a46751e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vrhp-w2wh-93c3/GHSA-vrhp-w2wh-93c3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrhp-w2wh-93c3", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24258" + ], + "details": "mupdf v1.23.9 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24258" + }, + { + "type": "WEB", + "url": "https://github.com/yinluming13579/mupdf_defects/blob/main/mupdf_detect_1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json b/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json new file mode 100644 index 00000000000..095dbc18d68 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-whq9-vwxq-6f23/GHSA-whq9-vwxq-6f23.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whq9-vwxq-6f23", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-0953" + ], + "details": "When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0953" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1837916" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xwmx-qhv2-jx64/GHSA-xwmx-qhv2-jx64.json b/advisories/unreviewed/2024/02/GHSA-xwmx-qhv2-jx64/GHSA-xwmx-qhv2-jx64.json new file mode 100644 index 00000000000..f646738989f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xwmx-qhv2-jx64/GHSA-xwmx-qhv2-jx64.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwmx-qhv2-jx64", + "modified": "2024-02-05T18:31:37Z", + "published": "2024-02-05T18:31:37Z", + "aliases": [ + "CVE-2024-24267" + ], + "details": "gpac v2.2.1 was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24267" + }, + { + "type": "WEB", + "url": "https://github.com/yinluming13579/gpac_defects/blob/main/gpac_3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-05T18:15:52Z" + } +} \ No newline at end of file