From e310b583b92b94a40b1aa637b69a71fdca063f95 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Oct 2024 21:32:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8q59-q68h-6hv4.json | 20 ++++++---- .../GHSA-hrj7-f62f-j7x7.json | 6 ++- .../GHSA-qq29-5vjh-vxwr.json | 8 +++- .../GHSA-4rw9-59ch-c9mh.json | 3 +- .../GHSA-66c8-9r5r-35hf.json | 3 +- .../GHSA-h9hg-q2g5-9w43.json | 3 +- .../GHSA-h9vv-8q8m-v6m6.json | 3 +- .../GHSA-ww3h-6rx6-947h.json | 3 +- .../GHSA-9g7g-rfw9-5xff.json | 3 +- .../GHSA-qmp7-vwf7-6g2g.json | 3 +- .../GHSA-xw97-mfvw-wc3w.json | 3 +- .../GHSA-8m9p-998m-hx59.json | 3 +- .../GHSA-8wxx-35qc-vp6r.json | 3 +- .../GHSA-r3xf-v29w-fxc6.json | 1 + .../GHSA-fqh3-x4m8-54qw.json | 9 +++-- .../GHSA-pqp2-hjwx-f6qp.json | 11 ++++-- .../GHSA-rqp9-2crf-qjg9.json | 9 +++-- .../GHSA-x8hg-ghpc-gxw6.json | 9 +++-- .../GHSA-24vf-v4v3-xgmr.json | 11 ++++-- .../GHSA-2645-7hqp-7qr7.json | 11 ++++-- .../GHSA-276c-3gx4-x9pr.json | 11 ++++-- .../GHSA-2jf4-28jv-3rg7.json | 39 +++++++++++++++++++ .../GHSA-2mv8-jjm5-f3hr.json | 35 +++++++++++++++++ .../GHSA-2pm2-9wvh-w2w9.json | 11 ++++-- .../GHSA-2q3j-fpjf-8xrm.json | 11 ++++-- .../GHSA-33jj-pgpw-2mqq.json | 9 +++-- .../GHSA-36m8-cp45-7q2q.json | 11 ++++-- .../GHSA-3cmg-5p27-qj6j.json | 11 ++++-- .../GHSA-3fj9-rv52-g5r6.json | 9 +++-- .../GHSA-3p5c-4j36-fmjf.json | 6 ++- .../GHSA-3v5r-242w-7766.json | 9 +++-- .../GHSA-4h38-c385-vwjx.json | 11 ++++-- .../GHSA-4j29-45vf-qcg5.json | 39 +++++++++++++++++++ .../GHSA-4vhm-95hf-qf25.json | 11 ++++-- .../GHSA-5828-hc43-9j7x.json | 11 ++++-- .../GHSA-5g66-93qv-565j.json | 35 +++++++++++++++++ .../GHSA-5g6f-mmx7-rp64.json | 11 ++++-- .../GHSA-5g9h-w8cm-q83h.json | 2 +- .../GHSA-5h35-qf38-2835.json | 11 ++++-- .../GHSA-5qpx-jr89-72gw.json | 11 ++++-- .../GHSA-5rmx-h57x-xq29.json | 11 ++++-- .../GHSA-67hh-63jq-82xv.json | 11 ++++-- .../GHSA-69pq-86fm-3gg5.json | 11 ++++-- .../GHSA-6j8f-88mh-r9vq.json | 35 +++++++++++++++++ .../GHSA-6m58-669r-3v4p.json | 11 ++++-- .../GHSA-7m83-4f94-8qqr.json | 35 +++++++++++++++++ .../GHSA-8cpm-hmp4-fcm6.json | 11 ++++-- .../GHSA-8hm3-x962-r5c7.json | 11 ++++-- .../GHSA-8j4x-47rq-vf32.json | 11 ++++-- .../GHSA-8j66-8f4j-h263.json | 11 ++++-- .../GHSA-8r3f-gpmm-xph8.json | 38 ++++++++++++++++++ .../GHSA-97r4-38mp-rc64.json | 11 ++++-- .../GHSA-9gw3-qr2f-3vg5.json | 35 +++++++++++++++++ .../GHSA-9r3v-4452-42x7.json | 11 ++++-- .../GHSA-9vq5-h4gw-g3q3.json | 11 ++++-- .../GHSA-c44c-v227-hv3q.json | 11 ++++-- .../GHSA-c9v4-5376-3jjw.json | 39 +++++++++++++++++++ .../GHSA-cpjr-vp64-xf74.json | 38 ++++++++++++++++++ .../GHSA-f754-p36j-5c6r.json | 11 ++++-- .../GHSA-gp53-q766-mxq2.json | 11 ++++-- .../GHSA-h345-r48x-g68f.json | 35 +++++++++++++++++ .../GHSA-h4px-9vmp-p7pv.json | 35 +++++++++++++++++ .../GHSA-h4qj-qcw9-2w6h.json | 11 ++++-- .../GHSA-h8wp-xf43-pm3w.json | 9 +++-- .../GHSA-hf8q-jfj5-c238.json | 11 ++++-- .../GHSA-hxxw-vvrc-qrx3.json | 11 ++++-- .../GHSA-j8vf-qmcj-wv9f.json | 2 +- .../GHSA-jc3p-f86q-23rh.json | 11 ++++-- .../GHSA-jjq3-cw48-pqmx.json | 11 ++++-- .../GHSA-jmxw-f4w9-294j.json | 11 ++++-- .../GHSA-jp89-qg38-336v.json | 2 +- .../GHSA-jxjm-crgh-jq3f.json | 39 +++++++++++++++++++ .../GHSA-m584-rmpj-6q5p.json | 11 ++++-- .../GHSA-mcg9-4p62-w7x9.json | 38 ++++++++++++++++++ .../GHSA-p25v-3q9m-p32x.json | 3 +- .../GHSA-p7hf-43g5-xhvw.json | 39 +++++++++++++++++++ .../GHSA-p9jh-f6vr-wxj3.json | 11 ++++-- .../GHSA-phfx-3hch-p62r.json | 11 ++++-- .../GHSA-px64-cpgr-654p.json | 11 ++++-- .../GHSA-qq67-99wj-86rm.json | 9 +++-- .../GHSA-qr7m-wmg3-5x2f.json | 9 +++-- .../GHSA-qw38-ppmm-fjpw.json | 11 ++++-- .../GHSA-r39h-f84x-g77w.json | 35 +++++++++++++++++ .../GHSA-r9v5-q97m-rj5g.json | 35 +++++++++++++++++ .../GHSA-rwfh-mmmq-96x7.json | 9 +++-- .../GHSA-rxqx-qqq2-7xfj.json | 6 ++- .../GHSA-vj24-j7x3-73cw.json | 11 ++++-- .../GHSA-vw6x-c5rg-jmjp.json | 35 +++++++++++++++++ .../GHSA-vwjf-jh23-hhpx.json | 11 ++++-- .../GHSA-w3m7-7f4v-5jvh.json | 11 ++++-- .../GHSA-w3m8-3fj2-8h9p.json | 11 ++++-- .../GHSA-w7fm-hm77-gq28.json | 38 ++++++++++++++++++ .../GHSA-w7vv-chh5-rjfj.json | 11 ++++-- .../GHSA-w8r5-25wc-2c5m.json | 11 ++++-- .../GHSA-wh9r-qhjq-2hg4.json | 35 +++++++++++++++++ .../GHSA-x2fr-vj74-5h35.json | 35 +++++++++++++++++ 96 files changed, 1202 insertions(+), 236 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-2jf4-28jv-3rg7/GHSA-2jf4-28jv-3rg7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2mv8-jjm5-f3hr/GHSA-2mv8-jjm5-f3hr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5g66-93qv-565j/GHSA-5g66-93qv-565j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6j8f-88mh-r9vq/GHSA-6j8f-88mh-r9vq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8r3f-gpmm-xph8/GHSA-8r3f-gpmm-xph8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9gw3-qr2f-3vg5/GHSA-9gw3-qr2f-3vg5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c9v4-5376-3jjw/GHSA-c9v4-5376-3jjw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cpjr-vp64-xf74/GHSA-cpjr-vp64-xf74.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h345-r48x-g68f/GHSA-h345-r48x-g68f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h4px-9vmp-p7pv/GHSA-h4px-9vmp-p7pv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mcg9-4p62-w7x9/GHSA-mcg9-4p62-w7x9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p7hf-43g5-xhvw/GHSA-p7hf-43g5-xhvw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r9v5-q97m-rj5g/GHSA-r9v5-q97m-rj5g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vw6x-c5rg-jmjp/GHSA-vw6x-c5rg-jmjp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w7fm-hm77-gq28/GHSA-w7fm-hm77-gq28.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wh9r-qhjq-2hg4/GHSA-wh9r-qhjq-2hg4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x2fr-vj74-5h35/GHSA-x2fr-vj74-5h35.json diff --git a/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json b/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json index 76af9165463..7c97634ae73 100644 --- a/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json +++ b/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8q59-q68h-6hv4", - "modified": "2021-09-28T19:04:49Z", + "modified": "2024-10-25T21:31:44Z", "published": "2021-03-25T21:26:26Z", "aliases": [ "CVE-2020-14343" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -20,12 +24,6 @@ "ecosystem": "PyPI", "name": "PyYAML" }, - "ecosystem_specific": { - "affected_functions": [ - "yaml.constructor.FullConstructor", - "yaml.constructor.UnsafeConstructor" - ] - }, "ranges": [ { "type": "ECOSYSTEM", @@ -66,6 +64,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860466" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-8q59-q68h-6hv4" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2021-142.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/yaml/pyyaml" diff --git a/advisories/github-reviewed/2022/09/GHSA-hrj7-f62f-j7x7/GHSA-hrj7-f62f-j7x7.json b/advisories/github-reviewed/2022/09/GHSA-hrj7-f62f-j7x7/GHSA-hrj7-f62f-j7x7.json index 14c200462fd..2f67b1c087a 100644 --- a/advisories/github-reviewed/2022/09/GHSA-hrj7-f62f-j7x7/GHSA-hrj7-f62f-j7x7.json +++ b/advisories/github-reviewed/2022/09/GHSA-hrj7-f62f-j7x7/GHSA-hrj7-f62f-j7x7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrj7-f62f-j7x7", - "modified": "2022-09-30T04:41:04Z", + "modified": "2024-10-25T21:29:32Z", "published": "2022-09-27T00:00:22Z", "aliases": [ "CVE-2022-3295" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ diff --git a/advisories/github-reviewed/2022/09/GHSA-qq29-5vjh-vxwr/GHSA-qq29-5vjh-vxwr.json b/advisories/github-reviewed/2022/09/GHSA-qq29-5vjh-vxwr/GHSA-qq29-5vjh-vxwr.json index ede8b8385e7..23415a99ca3 100644 --- a/advisories/github-reviewed/2022/09/GHSA-qq29-5vjh-vxwr/GHSA-qq29-5vjh-vxwr.json +++ b/advisories/github-reviewed/2022/09/GHSA-qq29-5vjh-vxwr/GHSA-qq29-5vjh-vxwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq29-5vjh-vxwr", - "modified": "2022-09-30T04:44:55Z", + "modified": "2024-10-25T21:29:58Z", "published": "2022-09-27T00:00:22Z", "aliases": [ "CVE-2022-3301" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -61,7 +65,7 @@ "cwe_ids": [ "CWE-460" ], - "severity": "LOW", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-09-30T04:44:55Z", "nvd_published_at": "2022-09-26T11:15:00Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json b/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json index 5d7d7ab7479..16af149a30a 100644 --- a/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json +++ b/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-66c8-9r5r-35hf/GHSA-66c8-9r5r-35hf.json b/advisories/unreviewed/2024/04/GHSA-66c8-9r5r-35hf/GHSA-66c8-9r5r-35hf.json index f14ec200a67..de9ff7ff010 100644 --- a/advisories/unreviewed/2024/04/GHSA-66c8-9r5r-35hf/GHSA-66c8-9r5r-35hf.json +++ b/advisories/unreviewed/2024/04/GHSA-66c8-9r5r-35hf/GHSA-66c8-9r5r-35hf.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-918" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json b/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json index ce9dd8f8f70..849e5fe02a9 100644 --- a/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json +++ b/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json b/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json index ccaecc16d77..a7ccda486dc 100644 --- a/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json +++ b/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json b/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json index 9a56464aece..10e98907d85 100644 --- a/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json +++ b/advisories/unreviewed/2024/04/GHSA-ww3h-6rx6-947h/GHSA-ww3h-6rx6-947h.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-300" + "CWE-300", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json b/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json index 144002ac5d7..6f59c90ca13 100644 --- a/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json +++ b/advisories/unreviewed/2024/05/GHSA-9g7g-rfw9-5xff/GHSA-9g7g-rfw9-5xff.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json b/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json index 90748a8bdd2..ecebe27a6b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json +++ b/advisories/unreviewed/2024/05/GHSA-qmp7-vwf7-6g2g/GHSA-qmp7-vwf7-6g2g.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json b/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json index 00e71e1b490..4f6044e3658 100644 --- a/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json +++ b/advisories/unreviewed/2024/05/GHSA-xw97-mfvw-wc3w/GHSA-xw97-mfvw-wc3w.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8m9p-998m-hx59/GHSA-8m9p-998m-hx59.json b/advisories/unreviewed/2024/07/GHSA-8m9p-998m-hx59/GHSA-8m9p-998m-hx59.json index 623ac194467..594701fe27e 100644 --- a/advisories/unreviewed/2024/07/GHSA-8m9p-998m-hx59/GHSA-8m9p-998m-hx59.json +++ b/advisories/unreviewed/2024/07/GHSA-8m9p-998m-hx59/GHSA-8m9p-998m-hx59.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json b/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json index 4a186c79a3c..b3ea1d9ece6 100644 --- a/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json +++ b/advisories/unreviewed/2024/07/GHSA-8wxx-35qc-vp6r/GHSA-8wxx-35qc-vp6r.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-289" + "CWE-289", + "CWE-639" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-r3xf-v29w-fxc6/GHSA-r3xf-v29w-fxc6.json b/advisories/unreviewed/2024/07/GHSA-r3xf-v29w-fxc6/GHSA-r3xf-v29w-fxc6.json index 208c5d5193f..399f5b4c3a6 100644 --- a/advisories/unreviewed/2024/07/GHSA-r3xf-v29w-fxc6/GHSA-r3xf-v29w-fxc6.json +++ b/advisories/unreviewed/2024/07/GHSA-r3xf-v29w-fxc6/GHSA-r3xf-v29w-fxc6.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-368" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-fqh3-x4m8-54qw/GHSA-fqh3-x4m8-54qw.json b/advisories/unreviewed/2024/08/GHSA-fqh3-x4m8-54qw/GHSA-fqh3-x4m8-54qw.json index bb11d19093a..49bc79ccdb1 100644 --- a/advisories/unreviewed/2024/08/GHSA-fqh3-x4m8-54qw/GHSA-fqh3-x4m8-54qw.json +++ b/advisories/unreviewed/2024/08/GHSA-fqh3-x4m8-54qw/GHSA-fqh3-x4m8-54qw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqh3-x4m8-54qw", - "modified": "2024-08-17T12:30:33Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-08-17T12:30:32Z", "aliases": [ "CVE-2024-43844" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: wow: fix GTK offload H2C skbuff issue\n\nWe mistakenly put skb too large and that may exceed skb->end.\nTherefore, we fix it.\n\nskbuff: skb_over_panic: text:ffffffffc09e9a9d len:416 put:204 head:ffff8fba04eca780 data:ffff8fba04eca7e0 tail:0x200 end:0x140 dev:\n------------[ cut here ]------------\nkernel BUG at net/core/skbuff.c:192!\ninvalid opcode: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 4747 Comm: kworker/u4:44 Tainted: G O 6.6.30-02659-gc18865c4dfbd #1 86547039b47e46935493f615ee31d0b2d711d35e\nHardware name: HP Meep/Meep, BIOS Google_Meep.11297.262.0 03/18/2021\nWorkqueue: events_unbound async_run_entry_fn\nRIP: 0010:skb_panic+0x5d/0x60\nCode: c6 63 8b 8f bb 4c 0f 45 f6 48 c7 c7 4d 89 8b bb 48 89 ce 44 89 d1 41 56 53 41 53 ff b0 c8 00 00 00 e8 27 5f 23 00 48 83 c4 20 <0f> 0b 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44\nRSP: 0018:ffffaa700144bad0 EFLAGS: 00010282\nRAX: 0000000000000089 RBX: 0000000000000140 RCX: 14432c5aad26c900\nRDX: 0000000000000000 RSI: 00000000ffffdfff RDI: 0000000000000001\nRBP: ffffaa700144bae0 R08: 0000000000000000 R09: ffffaa700144b920\nR10: 00000000ffffdfff R11: ffffffffbc28fbc0 R12: ffff8fba4e57a010\nR13: 0000000000000000 R14: ffffffffbb8f8b63 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff8fba7bd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007999c4ad1000 CR3: 000000015503a000 CR4: 0000000000350ee0\nCall Trace:\n \n ? __die_body+0x1f/0x70\n ? die+0x3d/0x60\n ? do_trap+0xa4/0x110\n ? skb_panic+0x5d/0x60\n ? do_error_trap+0x6d/0x90\n ? skb_panic+0x5d/0x60\n ? handle_invalid_op+0x30/0x40\n ? skb_panic+0x5d/0x60\n ? exc_invalid_op+0x3c/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_panic+0x5d/0x60\n skb_put+0x49/0x50\n rtw89_fw_h2c_wow_gtk_ofld+0xbd/0x220 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_wow_resume+0x31f/0x540 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n rtw89_ops_resume+0x2b/0xa0 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a83636fa5]\n ieee80211_reconfig+0x84/0x13e0 [mac80211 818a894e3b77da6298269c59ed7cdff065a4ed52]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? dev_printk_emit+0x51/0x70\n ? _dev_info+0x6e/0x90\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n wiphy_resume+0x89/0x180 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d]\n dpm_run_callback+0x3c/0x140\n device_resume+0x1f9/0x3c0\n ? __pfx_dpm_watchdog_handler+0x10/0x10\n async_resume+0x1d/0x30\n async_run_entry_fn+0x29/0xd0\n process_scheduled_works+0x1d8/0x3d0\n worker_thread+0x1fc/0x2f0\n kthread+0xed/0x110\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x38/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \nModules linked in: ccm 8021q r8153_ecm cdc_ether usbnet r8152 mii dm_integrity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmalloc uinput rfcomm cmac algif_hash rtw89_8922ae(O) algif_skcipher rtw89_8922a(O) af_alg rtw89_pci(O) rtw89_core(O) btusb(O) snd_soc_sst_bxt_da7219_max98357a btbcm(O) snd_soc_hdac_hdmi btintel(O) snd_soc_intel_hda_dsp_common snd_sof_probes btrtl(O) btmtk(O) snd_hda_codec_hdmi snd_soc_dmic uvcvideo videobuf2_vmalloc uvc videobuf2_memops videobuf2_v4l2 videobuf2_common snd_sof_pci_intel_apl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda soundwire_intel soundwire_generic_allocation snd_sof_intel_hda_mlink soundwire_cadence snd_sof_pci snd_sof_xtensa_dsp mac80211 snd_soc_acpi_intel_match snd_soc_acpi snd_sof snd_sof_utils soundwire_bus snd_soc_max98357a snd_soc_avs snd_soc_hda_codec snd_hda_ext_core snd_intel_dspcfg snd_intel_sdw_acpi snd_soc_da7219 snd_hda_codec snd_hwdep snd_hda_core veth ip6table_nat xt_MASQUERADE xt_cgroup fuse bluetooth ecdh_generic\n cfg80211 ecc\ngsmi: Log Shutdown \n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json b/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json index d9a21034002..51507d8d39d 100644 --- a/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json +++ b/advisories/unreviewed/2024/08/GHSA-pqp2-hjwx-f6qp/GHSA-pqp2-hjwx-f6qp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqp2-hjwx-f6qp", - "modified": "2024-10-22T18:32:04Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43845" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix bogus checksum computation in udf_rename()\n\nSyzbot reports uninitialized memory access in udf_rename() when updating\nchecksum of '..' directory entry of a moved directory. This is indeed\ntrue as we pass on-stack diriter.fi to the udf_update_tag() and because\nthat has only struct fileIdentDesc included in it and not the impUse or\nname fields, the checksumming function is going to checksum random stack\ncontents beyond the end of the structure. This is actually harmless\nbecause the following udf_fiiter_write_fi() will recompute the checksum\nfrom on-disk buffers where everything is properly included. So all that\nis needed is just removing the bogus calculation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rqp9-2crf-qjg9/GHSA-rqp9-2crf-qjg9.json b/advisories/unreviewed/2024/08/GHSA-rqp9-2crf-qjg9/GHSA-rqp9-2crf-qjg9.json index 60e4e468b3a..341950a275f 100644 --- a/advisories/unreviewed/2024/08/GHSA-rqp9-2crf-qjg9/GHSA-rqp9-2crf-qjg9.json +++ b/advisories/unreviewed/2024/08/GHSA-rqp9-2crf-qjg9/GHSA-rqp9-2crf-qjg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqp9-2crf-qjg9", - "modified": "2024-08-19T06:30:54Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43846" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib: objagg: Fix general protection fault\n\nThe library supports aggregation of objects into other objects only if\nthe parent object does not have a parent itself. That is, nesting is not\nsupported.\n\nAggregation happens in two cases: Without and with hints, where hints\nare a pre-computed recommendation on how to aggregate the provided\nobjects.\n\nNesting is not possible in the first case due to a check that prevents\nit, but in the second case there is no check because the assumption is\nthat nesting cannot happen when creating objects based on hints. The\nviolation of this assumption leads to various warnings and eventually to\na general protection fault [1].\n\nBefore fixing the root cause, error out when nesting happens and warn.\n\n[1]\ngeneral protection fault, probably for non-canonical address 0xdead000000000d90: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 1083 Comm: kworker/1:9 Tainted: G W 6.9.0-rc6-custom-gd9b4f1cca7fb #7\nHardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019\nWorkqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work\nRIP: 0010:mlxsw_sp_acl_erp_bf_insert+0x25/0x80\n[...]\nCall Trace:\n \n mlxsw_sp_acl_atcam_entry_add+0x256/0x3c0\n mlxsw_sp_acl_tcam_entry_create+0x5e/0xa0\n mlxsw_sp_acl_tcam_vchunk_migrate_one+0x16b/0x270\n mlxsw_sp_acl_tcam_vregion_rehash_work+0xbe/0x510\n process_one_work+0x151/0x370\n worker_thread+0x2cb/0x3e0\n kthread+0xd0/0x100\n ret_from_fork+0x34/0x50\n ret_from_fork_asm+0x1a/0x30\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x8hg-ghpc-gxw6/GHSA-x8hg-ghpc-gxw6.json b/advisories/unreviewed/2024/08/GHSA-x8hg-ghpc-gxw6/GHSA-x8hg-ghpc-gxw6.json index b6e6da020da..7abe0a4a3b8 100644 --- a/advisories/unreviewed/2024/08/GHSA-x8hg-ghpc-gxw6/GHSA-x8hg-ghpc-gxw6.json +++ b/advisories/unreviewed/2024/08/GHSA-x8hg-ghpc-gxw6/GHSA-x8hg-ghpc-gxw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8hg-ghpc-gxw6", - "modified": "2024-08-17T12:30:33Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-08-17T12:30:33Z", "aliases": [ "CVE-2024-43847" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix invalid memory access while processing fragmented packets\n\nThe monitor ring and the reo reinject ring share the same ring mask index.\nWhen the driver receives an interrupt for the reo reinject ring, the\nmonitor ring is also processed, leading to invalid memory access. Since\nmonitor support is not yet enabled in ath12k, the ring mask for the monitor\nring should be removed.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00209-QCAHKSWPL_SILICONZ-1", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json b/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json index 848ccdd9d30..9815dfadad1 100644 --- a/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json +++ b/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24vf-v4v3-xgmr", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49975" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes: fix kernel info leak via \"[uprobes]\" vma\n\nxol_add_vma() maps the uninitialized page allocated by __create_xol_area()\ninto userspace. On some architectures (x86) this memory is readable even\nwithout VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ,\nalthough this doesn't really matter, debugger can read this memory anyway.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2645-7hqp-7qr7/GHSA-2645-7hqp-7qr7.json b/advisories/unreviewed/2024/10/GHSA-2645-7hqp-7qr7/GHSA-2645-7hqp-7qr7.json index d09e9c851ec..c12223e01e5 100644 --- a/advisories/unreviewed/2024/10/GHSA-2645-7hqp-7qr7/GHSA-2645-7hqp-7qr7.json +++ b/advisories/unreviewed/2024/10/GHSA-2645-7hqp-7qr7/GHSA-2645-7hqp-7qr7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2645-7hqp-7qr7", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48967" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: nci: Bounds check struct nfc_target arrays\n\nWhile running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:\n\n memcpy: detected field-spanning write (size 129) of single field \"target->sensf_res\" at net/nfc/nci/ntf.c:260 (size 18)\n\nThis appears to be a legitimate lack of bounds checking in\nnci_add_new_protocol(). Add the missing checks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json b/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json index 9850f23706e..75c46eedcd2 100644 --- a/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json +++ b/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-276c-3gx4-x9pr", - "modified": "2024-10-21T18:31:00Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49996" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix buffer overflow when parsing NFS reparse points\n\nReparseDataLength is sum of the InodeType size and DataBuffer size.\nSo to get DataBuffer size it is needed to subtract InodeType's size from\nReparseDataLength.\n\nFunction cifs_strndup_from_utf16() is currentlly accessing buf->DataBuffer\nat position after the end of the buffer because it does not subtract\nInodeType size from the length. Fix this problem and correctly subtract\nvariable len.\n\nMember InodeType is present only when reparse buffer is large enough. Check\nfor ReparseDataLength before accessing InodeType to prevent another invalid\nmemory access.\n\nMajor and minor rdev values are present also only when reparse buffer is\nlarge enough. Check for reparse buffer size before calling reparse_mkdev().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2jf4-28jv-3rg7/GHSA-2jf4-28jv-3rg7.json b/advisories/unreviewed/2024/10/GHSA-2jf4-28jv-3rg7/GHSA-2jf4-28jv-3rg7.json new file mode 100644 index 00000000000..3899aec8de3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2jf4-28jv-3rg7/GHSA-2jf4-28jv-3rg7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jf4-28jv-3rg7", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-37846" + ], + "details": "MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37846" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/blob/main/CVE-2024-37846-CSTI.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2mv8-jjm5-f3hr/GHSA-2mv8-jjm5-f3hr.json b/advisories/unreviewed/2024/10/GHSA-2mv8-jjm5-f3hr/GHSA-2mv8-jjm5-f3hr.json new file mode 100644 index 00000000000..6f7b1ff9a73 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2mv8-jjm5-f3hr/GHSA-2mv8-jjm5-f3hr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mv8-jjm5-f3hr", + "modified": "2024-10-25T21:31:28Z", + "published": "2024-10-25T21:31:28Z", + "aliases": [ + "CVE-2024-48230" + ], + "details": "funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \\backend\\controller\\auth\\Auth.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48230" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/30" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json b/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json index 83e649ac873..de32c81cb9d 100644 --- a/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json +++ b/advisories/unreviewed/2024/10/GHSA-2pm2-9wvh-w2w9/GHSA-2pm2-9wvh-w2w9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pm2-9wvh-w2w9", - "modified": "2024-10-25T12:31:32Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T12:31:32Z", "aliases": [ "CVE-2024-47013" ], "details": "In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2q3j-fpjf-8xrm/GHSA-2q3j-fpjf-8xrm.json b/advisories/unreviewed/2024/10/GHSA-2q3j-fpjf-8xrm/GHSA-2q3j-fpjf-8xrm.json index 7be0cd86e50..8f8d80752b0 100644 --- a/advisories/unreviewed/2024/10/GHSA-2q3j-fpjf-8xrm/GHSA-2q3j-fpjf-8xrm.json +++ b/advisories/unreviewed/2024/10/GHSA-2q3j-fpjf-8xrm/GHSA-2q3j-fpjf-8xrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2q3j-fpjf-8xrm", - "modified": "2024-10-24T18:30:44Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T18:30:44Z", "aliases": [ "CVE-2024-48441" ], "details": "Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T18:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-33jj-pgpw-2mqq/GHSA-33jj-pgpw-2mqq.json b/advisories/unreviewed/2024/10/GHSA-33jj-pgpw-2mqq/GHSA-33jj-pgpw-2mqq.json index cd02b1a5a74..913160c7f64 100644 --- a/advisories/unreviewed/2024/10/GHSA-33jj-pgpw-2mqq/GHSA-33jj-pgpw-2mqq.json +++ b/advisories/unreviewed/2024/10/GHSA-33jj-pgpw-2mqq/GHSA-33jj-pgpw-2mqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-33jj-pgpw-2mqq", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48952" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: mt7621: Add sentinel to quirks table\n\nCurrent driver is missing a sentinel in the struct soc_device_attribute\narray, which causes an oops when assessed by the\nsoc_device_match(mt7621_pcie_quirks_match) call.\n\nThis was only exposed once the CONFIG_SOC_MT7621 mt7621 soc_dev_attr\nwas fixed to register the SOC as a device, in:\n\ncommit 7c18b64bba3b (\"mips: ralink: mt7621: do not use kzalloc too early\")\n\nFix it by adding the required sentinel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json b/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json index fa6db62238c..7e4bdc67060 100644 --- a/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json +++ b/advisories/unreviewed/2024/10/GHSA-36m8-cp45-7q2q/GHSA-36m8-cp45-7q2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36m8-cp45-7q2q", - "modified": "2024-10-25T12:31:32Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T12:31:32Z", "aliases": [ "CVE-2024-44100" ], "details": "N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json b/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json index db38b0789aa..69bd8c6acb4 100644 --- a/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json +++ b/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cmg-5p27-qj6j", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49986" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors\n\nx86_android_tablet_remove() frees the pdevs[] array, so it should not\nbe used after calling x86_android_tablet_remove().\n\nWhen platform_device_register() fails, store the pdevs[x] PTR_ERR() value\ninto the local ret variable before calling x86_android_tablet_remove()\nto avoid using pdevs[] after it has been freed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3fj9-rv52-g5r6/GHSA-3fj9-rv52-g5r6.json b/advisories/unreviewed/2024/10/GHSA-3fj9-rv52-g5r6/GHSA-3fj9-rv52-g5r6.json index e9ca2c2bdee..dc6fff3ccc5 100644 --- a/advisories/unreviewed/2024/10/GHSA-3fj9-rv52-g5r6/GHSA-3fj9-rv52-g5r6.json +++ b/advisories/unreviewed/2024/10/GHSA-3fj9-rv52-g5r6/GHSA-3fj9-rv52-g5r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3fj9-rv52-g5r6", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48946" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix preallocation discarding at indirect extent boundary\n\nWhen preallocation extent is the first one in the extent block, the\ncode would corrupt extent tree header instead. Fix the problem and use\nudf_delete_aext() for deleting extent to avoid some code duplication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3p5c-4j36-fmjf/GHSA-3p5c-4j36-fmjf.json b/advisories/unreviewed/2024/10/GHSA-3p5c-4j36-fmjf/GHSA-3p5c-4j36-fmjf.json index 44a5d7d52f1..98b1bafb05a 100644 --- a/advisories/unreviewed/2024/10/GHSA-3p5c-4j36-fmjf/GHSA-3p5c-4j36-fmjf.json +++ b/advisories/unreviewed/2024/10/GHSA-3p5c-4j36-fmjf/GHSA-3p5c-4j36-fmjf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p5c-4j36-fmjf", - "modified": "2024-10-22T09:33:54Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-22T09:33:54Z", "aliases": [ "CVE-2024-35308" ], "details": "A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red" diff --git a/advisories/unreviewed/2024/10/GHSA-3v5r-242w-7766/GHSA-3v5r-242w-7766.json b/advisories/unreviewed/2024/10/GHSA-3v5r-242w-7766/GHSA-3v5r-242w-7766.json index be04afdfd73..e2cacf092ad 100644 --- a/advisories/unreviewed/2024/10/GHSA-3v5r-242w-7766/GHSA-3v5r-242w-7766.json +++ b/advisories/unreviewed/2024/10/GHSA-3v5r-242w-7766/GHSA-3v5r-242w-7766.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3v5r-242w-7766", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48976" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable_offload: fix using __this_cpu_add in preemptible\n\nflow_offload_queue_work() can be called in workqueue without\nbh disabled, like the call trace showed in my act_ct testing,\ncalling NF_FLOW_TABLE_STAT_INC() there would cause a call\ntrace:\n\n BUG: using __this_cpu_add() in preemptible [00000000] code: kworker/u4:0/138560\n caller is flow_offload_queue_work+0xec/0x1b0 [nf_flow_table]\n Workqueue: act_ct_workqueue tcf_ct_flow_table_cleanup_work [act_ct]\n Call Trace:\n \n dump_stack_lvl+0x33/0x46\n check_preemption_disabled+0xc3/0xf0\n flow_offload_queue_work+0xec/0x1b0 [nf_flow_table]\n nf_flow_table_iterate+0x138/0x170 [nf_flow_table]\n nf_flow_table_free+0x140/0x1a0 [nf_flow_table]\n tcf_ct_flow_table_cleanup_work+0x2f/0x2b0 [act_ct]\n process_one_work+0x6a3/0x1030\n worker_thread+0x8a/0xdf0\n\nThis patch fixes it by using NF_FLOW_TABLE_STAT_INC_ATOMIC()\ninstead in flow_offload_queue_work().\n\nNote that for FLOW_CLS_REPLACE branch in flow_offload_queue_work(),\nit may not be called in preemptible path, but it's good to use\nNF_FLOW_TABLE_STAT_INC_ATOMIC() for all cases in\nflow_offload_queue_work().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4h38-c385-vwjx/GHSA-4h38-c385-vwjx.json b/advisories/unreviewed/2024/10/GHSA-4h38-c385-vwjx/GHSA-4h38-c385-vwjx.json index 4bd13779a36..05250712546 100644 --- a/advisories/unreviewed/2024/10/GHSA-4h38-c385-vwjx/GHSA-4h38-c385-vwjx.json +++ b/advisories/unreviewed/2024/10/GHSA-4h38-c385-vwjx/GHSA-4h38-c385-vwjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4h38-c385-vwjx", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2024-50018" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: napi: Prevent overflow of napi_defer_hard_irqs\n\nIn commit 6f8b12d661d0 (\"net: napi: add hard irqs deferral feature\")\nnapi_defer_irqs was added to net_device and napi_defer_irqs_count was\nadded to napi_struct, both as type int.\n\nThis value never goes below zero, so there is not reason for it to be a\nsigned int. Change the type for both from int to u32, and add an\noverflow check to sysfs to limit the value to S32_MAX.\n\nThe limit of S32_MAX was chosen because the practical limit before this\npatch was S32_MAX (anything larger was an overflow) and thus there are\nno behavioral changes introduced. If the extra bit is needed in the\nfuture, the limit can be raised.\n\nBefore this patch:\n\n$ sudo bash -c 'echo 2147483649 > /sys/class/net/eth4/napi_defer_hard_irqs'\n$ cat /sys/class/net/eth4/napi_defer_hard_irqs\n-2147483647\n\nAfter this patch:\n\n$ sudo bash -c 'echo 2147483649 > /sys/class/net/eth4/napi_defer_hard_irqs'\nbash: line 0: echo: write error: Numerical result out of range\n\nSimilarly, /sys/class/net/XXXXX/tx_queue_len is defined as unsigned:\n\ninclude/linux/netdevice.h: unsigned int tx_queue_len;\n\nAnd has an overflow check:\n\ndev_change_tx_queue_len(..., unsigned long new_len):\n\n if (new_len != (unsigned int)new_len)\n return -ERANGE;", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json b/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json new file mode 100644 index 00000000000..3cbb2143bc4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4j29-45vf-qcg5/GHSA-4j29-45vf-qcg5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j29-45vf-qcg5", + "modified": "2024-10-25T21:31:28Z", + "published": "2024-10-25T21:31:28Z", + "aliases": [ + "CVE-2024-48396" + ], + "details": "AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48396" + }, + { + "type": "WEB", + "url": "https://github.com/sohelamin/chatbot" + }, + { + "type": "WEB", + "url": "https://jacobmasse.medium.com/reflected-xss-in-popular-ai-chatbot-application-79de74ea0cc8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json b/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json index fb2818c335e..e837cb73b5a 100644 --- a/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json +++ b/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4vhm-95hf-qf25", - "modified": "2024-10-21T18:31:00Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:31:00Z", "aliases": [ "CVE-2024-50000" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()\n\nIn mlx5e_tir_builder_alloc() kvzalloc() may return NULL\nwhich is dereferenced on the next line in a reference\nto the modify field.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:20Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5828-hc43-9j7x/GHSA-5828-hc43-9j7x.json b/advisories/unreviewed/2024/10/GHSA-5828-hc43-9j7x/GHSA-5828-hc43-9j7x.json index e140d17ab04..54cb7445632 100644 --- a/advisories/unreviewed/2024/10/GHSA-5828-hc43-9j7x/GHSA-5828-hc43-9j7x.json +++ b/advisories/unreviewed/2024/10/GHSA-5828-hc43-9j7x/GHSA-5828-hc43-9j7x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5828-hc43-9j7x", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2022-30355" ], "details": "OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T16:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5g66-93qv-565j/GHSA-5g66-93qv-565j.json b/advisories/unreviewed/2024/10/GHSA-5g66-93qv-565j/GHSA-5g66-93qv-565j.json new file mode 100644 index 00000000000..601dc448cfb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5g66-93qv-565j/GHSA-5g66-93qv-565j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g66-93qv-565j", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48222" + ], + "details": "Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48222" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/22" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5g6f-mmx7-rp64/GHSA-5g6f-mmx7-rp64.json b/advisories/unreviewed/2024/10/GHSA-5g6f-mmx7-rp64/GHSA-5g6f-mmx7-rp64.json index 54637f6638a..9482fb1376b 100644 --- a/advisories/unreviewed/2024/10/GHSA-5g6f-mmx7-rp64/GHSA-5g6f-mmx7-rp64.json +++ b/advisories/unreviewed/2024/10/GHSA-5g6f-mmx7-rp64/GHSA-5g6f-mmx7-rp64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5g6f-mmx7-rp64", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2024-50013" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix memory leak in exfat_load_bitmap()\n\nIf the first directory entry in the root directory is not a bitmap\ndirectory entry, 'bh' will not be released and reassigned, which\nwill cause a memory leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5g9h-w8cm-q83h/GHSA-5g9h-w8cm-q83h.json b/advisories/unreviewed/2024/10/GHSA-5g9h-w8cm-q83h/GHSA-5g9h-w8cm-q83h.json index 52dc64fe171..17bca71689e 100644 --- a/advisories/unreviewed/2024/10/GHSA-5g9h-w8cm-q83h/GHSA-5g9h-w8cm-q83h.json +++ b/advisories/unreviewed/2024/10/GHSA-5g9h-w8cm-q83h/GHSA-5g9h-w8cm-q83h.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5h35-qf38-2835/GHSA-5h35-qf38-2835.json b/advisories/unreviewed/2024/10/GHSA-5h35-qf38-2835/GHSA-5h35-qf38-2835.json index e38698e116d..d447dfe4178 100644 --- a/advisories/unreviewed/2024/10/GHSA-5h35-qf38-2835/GHSA-5h35-qf38-2835.json +++ b/advisories/unreviewed/2024/10/GHSA-5h35-qf38-2835/GHSA-5h35-qf38-2835.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h35-qf38-2835", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2022-30357" ], "details": "OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T17:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5qpx-jr89-72gw/GHSA-5qpx-jr89-72gw.json b/advisories/unreviewed/2024/10/GHSA-5qpx-jr89-72gw/GHSA-5qpx-jr89-72gw.json index 3189a5834d5..80a62e8edd9 100644 --- a/advisories/unreviewed/2024/10/GHSA-5qpx-jr89-72gw/GHSA-5qpx-jr89-72gw.json +++ b/advisories/unreviewed/2024/10/GHSA-5qpx-jr89-72gw/GHSA-5qpx-jr89-72gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qpx-jr89-72gw", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2024-48580" ], "details": "SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T16:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5rmx-h57x-xq29/GHSA-5rmx-h57x-xq29.json b/advisories/unreviewed/2024/10/GHSA-5rmx-h57x-xq29/GHSA-5rmx-h57x-xq29.json index 0491086ca6d..61ef540083d 100644 --- a/advisories/unreviewed/2024/10/GHSA-5rmx-h57x-xq29/GHSA-5rmx-h57x-xq29.json +++ b/advisories/unreviewed/2024/10/GHSA-5rmx-h57x-xq29/GHSA-5rmx-h57x-xq29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rmx-h57x-xq29", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48975" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpiolib: fix memory leak in gpiochip_setup_dev()\n\nHere is a backtrace report about memory leak detected in\ngpiochip_setup_dev():\n\nunreferenced object 0xffff88810b406400 (size 512):\n comm \"python3\", pid 1682, jiffies 4295346908 (age 24.090s)\n backtrace:\n kmalloc_trace\n device_add\t\tdevice_private_init at drivers/base/core.c:3361\n\t\t\t(inlined by) device_add at drivers/base/core.c:3411\n cdev_device_add\n gpiolib_cdev_register\n gpiochip_setup_dev\n gpiochip_add_data_with_key\n\ngcdev_register() & gcdev_unregister() would call device_add() &\ndevice_del() (no matter CONFIG_GPIO_CDEV is enabled or not) to\nregister/unregister device.\n\nHowever, if device_add() succeeds, some resource (like\nstruct device_private allocated by device_private_init())\nis not released by device_del().\n\nTherefore, after device_add() succeeds by gcdev_register(), it\nneeds to call put_device() to release resource in the error handle\npath.\n\nHere we move forward the register of release function, and let it\nrelease every piece of resource by put_device() instead of kfree().\n\nWhile at it, fix another subtle issue, i.e. when gc->ngpio is equal\nto 0, we still call kcalloc() and, in case of further error, kfree()\non the ZERO_PTR pointer, which is not NULL. It's not a bug per se,\nbut rather waste of the resources and potentially wrong expectation\nabout contents of the gdev->descs variable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-67hh-63jq-82xv/GHSA-67hh-63jq-82xv.json b/advisories/unreviewed/2024/10/GHSA-67hh-63jq-82xv/GHSA-67hh-63jq-82xv.json index 352e612f1a9..3c3971d3c6a 100644 --- a/advisories/unreviewed/2024/10/GHSA-67hh-63jq-82xv/GHSA-67hh-63jq-82xv.json +++ b/advisories/unreviewed/2024/10/GHSA-67hh-63jq-82xv/GHSA-67hh-63jq-82xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67hh-63jq-82xv", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: af_can: fix NULL pointer dereference in can_rcv_filter\n\nAnalogue to commit 8aa59e355949 (\"can: af_can: fix NULL pointer\ndereference in can_rx_register()\") we need to check for a missing\ninitialization of ml_priv in the receive path of CAN frames.\n\nSince commit 4e096a18867a (\"net: introduce CAN specific pointer in the\nstruct net_device\") the check for dev->type to be ARPHRD_CAN is not\nsufficient anymore since bonding or tun netdevices claim to be CAN\ndevices but do not initialize ml_priv accordingly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-69pq-86fm-3gg5/GHSA-69pq-86fm-3gg5.json b/advisories/unreviewed/2024/10/GHSA-69pq-86fm-3gg5/GHSA-69pq-86fm-3gg5.json index 43c7c531961..b883c77baa4 100644 --- a/advisories/unreviewed/2024/10/GHSA-69pq-86fm-3gg5/GHSA-69pq-86fm-3gg5.json +++ b/advisories/unreviewed/2024/10/GHSA-69pq-86fm-3gg5/GHSA-69pq-86fm-3gg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69pq-86fm-3gg5", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48966" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvneta: Prevent out of bounds read in mvneta_config_rss()\n\nThe pp->indir[0] value comes from the user. It is passed to:\n\n\tif (cpu_online(pp->rxq_def))\n\ninside the mvneta_percpu_elect() function. It needs bounds checkeding\nto ensure that it is not beyond the end of the cpu bitmap.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6j8f-88mh-r9vq/GHSA-6j8f-88mh-r9vq.json b/advisories/unreviewed/2024/10/GHSA-6j8f-88mh-r9vq/GHSA-6j8f-88mh-r9vq.json new file mode 100644 index 00000000000..c460ac7a9cc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6j8f-88mh-r9vq/GHSA-6j8f-88mh-r9vq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j8f-88mh-r9vq", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48224" + ], + "details": "Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48224" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/24" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json b/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json index 7928257386f..baeae2fabc0 100644 --- a/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json +++ b/advisories/unreviewed/2024/10/GHSA-6m58-669r-3v4p/GHSA-6m58-669r-3v4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6m58-669r-3v4p", - "modified": "2024-10-25T12:31:32Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T12:31:32Z", "aliases": [ "CVE-2024-44101" ], "details": "there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json b/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json new file mode 100644 index 00000000000..4ac300aa2ba --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7m83-4f94-8qqr/GHSA-7m83-4f94-8qqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m83-4f94-8qqr", + "modified": "2024-10-25T21:31:28Z", + "published": "2024-10-25T21:31:28Z", + "aliases": [ + "CVE-2024-48232" + ], + "details": "An issue was found in mipjz 5.0.5. In the mipPost method of \\app\\setting\\controller\\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48232" + }, + { + "type": "WEB", + "url": "https://github.com/sansanyun/mipjz/issues/17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json b/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json index 25bb25927f6..a2afaec9c2b 100644 --- a/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json +++ b/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cpm-hmp4-fcm6", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: Fix zero-division error when disabling tc cbs\n\nThe commit b8c43360f6e4 (\"net: stmmac: No need to calculate speed divider\nwhen offload is disabled\") allows the \"port_transmit_rate_kbps\" to be\nset to a value of 0, which is then passed to the \"div_s64\" function when\ntc-cbs is disabled. This leads to a zero-division error.\n\nWhen tc-cbs is disabled, the idleslope, sendslope, and credit values the\ncredit values are not required to be configured. Therefore, adding a return\nstatement after setting the txQ mode to DCB when tc-cbs is disabled would\nprevent a zero-division error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json b/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json index 49d14161cce..bbe29d5cf99 100644 --- a/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json +++ b/advisories/unreviewed/2024/10/GHSA-8hm3-x962-r5c7/GHSA-8hm3-x962-r5c7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hm3-x962-r5c7", - "modified": "2024-10-24T21:31:03Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T21:31:03Z", "aliases": [ "CVE-2024-48143" ], "details": "A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive amount of food orders.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8j4x-47rq-vf32/GHSA-8j4x-47rq-vf32.json b/advisories/unreviewed/2024/10/GHSA-8j4x-47rq-vf32/GHSA-8j4x-47rq-vf32.json index 79c6cbc9a85..673fd1dceb6 100644 --- a/advisories/unreviewed/2024/10/GHSA-8j4x-47rq-vf32/GHSA-8j4x-47rq-vf32.json +++ b/advisories/unreviewed/2024/10/GHSA-8j4x-47rq-vf32/GHSA-8j4x-47rq-vf32.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j4x-47rq-vf32", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48953" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtc: cmos: Fix event handler registration ordering issue\n\nBecause acpi_install_fixed_event_handler() enables the event\nautomatically on success, it is incorrect to call it before the\nhandler routine passed to it is ready to handle events.\n\nUnfortunately, the rtc-cmos driver does exactly the incorrect thing\nby calling cmos_wake_setup(), which passes rtc_handler() to\nacpi_install_fixed_event_handler(), before cmos_do_probe(), because\nrtc_handler() uses dev_get_drvdata() to get to the cmos object\npointer and the driver data pointer is only populated in\ncmos_do_probe().\n\nThis leads to a NULL pointer dereference in rtc_handler() on boot\nif the RTC fixed event happens to be active at the init time.\n\nTo address this issue, change the initialization ordering of the\ndriver so that cmos_wake_setup() is always called after a successful\ncmos_do_probe() call.\n\nWhile at it, change cmos_pnp_probe() to call cmos_do_probe() after\nthe initial if () statement used for computing the IRQ argument to\nbe passed to cmos_do_probe() which is cleaner than calling it in\neach branch of that if () (local variable \"irq\" can be of type int,\nbecause it is passed to that function as an argument of type int).\n\nNote that commit 6492fed7d8c9 (\"rtc: rtc-cmos: Do not check\nACPI_FADT_LOW_POWER_S0\") caused this issue to affect a larger number\nof systems, because previously it only affected systems with\nACPI_FADT_LOW_POWER_S0 set, but it is present regardless of that\ncommit.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json b/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json index 6d295ca29d7..cea463fd22a 100644 --- a/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json +++ b/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j66-8f4j-h263", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49976" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Drop interface_lock in stop_kthread()\n\nstop_kthread() is the offline callback for \"trace/osnoise:online\", since\ncommit 5bfbcd1ee57b (\"tracing/timerlat: Add interface_lock around clearing\nof kthread in stop_kthread()\"), the following ABBA deadlock scenario is\nintroduced:\n\nT1 | T2 [BP] | T3 [AP]\nosnoise_hotplug_workfn() | work_for_cpu_fn() | cpuhp_thread_fun()\n | _cpu_down() | osnoise_cpu_die()\n mutex_lock(&interface_lock) | | stop_kthread()\n | cpus_write_lock() | mutex_lock(&interface_lock)\n cpus_read_lock() | cpuhp_kick_ap() |\n\nAs the interface_lock here in just for protecting the \"kthread\" field of\nthe osn_var, use xchg() instead to fix this issue. Also use\nfor_each_online_cpu() back in stop_per_cpu_kthreads() as it can take\ncpu_read_lock() again.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8r3f-gpmm-xph8/GHSA-8r3f-gpmm-xph8.json b/advisories/unreviewed/2024/10/GHSA-8r3f-gpmm-xph8/GHSA-8r3f-gpmm-xph8.json new file mode 100644 index 00000000000..edf9f3dfd4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8r3f-gpmm-xph8/GHSA-8r3f-gpmm-xph8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r3f-gpmm-xph8", + "modified": "2024-10-25T21:31:25Z", + "published": "2024-10-25T21:31:25Z", + "aliases": [ + "CVE-2023-36490" + ], + "details": "Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36490" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00967.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-97r4-38mp-rc64/GHSA-97r4-38mp-rc64.json b/advisories/unreviewed/2024/10/GHSA-97r4-38mp-rc64/GHSA-97r4-38mp-rc64.json index a6f164a5ac9..c64c08081b1 100644 --- a/advisories/unreviewed/2024/10/GHSA-97r4-38mp-rc64/GHSA-97r4-38mp-rc64.json +++ b/advisories/unreviewed/2024/10/GHSA-97r4-38mp-rc64/GHSA-97r4-38mp-rc64.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97r4-38mp-rc64", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48979" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix array index out of bound error in DCN32 DML\n\n[Why&How]\nLinkCapacitySupport array is indexed with the number of voltage states and\nnot the number of max DPPs. Fix the error by changing the array\ndeclaration to use the correct (larger) array size of total number of\nvoltage states.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9gw3-qr2f-3vg5/GHSA-9gw3-qr2f-3vg5.json b/advisories/unreviewed/2024/10/GHSA-9gw3-qr2f-3vg5/GHSA-9gw3-qr2f-3vg5.json new file mode 100644 index 00000000000..9bbc01a4a2f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9gw3-qr2f-3vg5/GHSA-9gw3-qr2f-3vg5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gw3-qr2f-3vg5", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48226" + ], + "details": "Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48226" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json b/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json index aa1d3f80991..e5949a95b02 100644 --- a/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json +++ b/advisories/unreviewed/2024/10/GHSA-9r3v-4452-42x7/GHSA-9r3v-4452-42x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9r3v-4452-42x7", - "modified": "2024-10-24T21:31:03Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T21:31:03Z", "aliases": [ "CVE-2024-48141" ], "details": "A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json b/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json index fc415ca9217..74bc41003f4 100644 --- a/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json +++ b/advisories/unreviewed/2024/10/GHSA-9vq5-h4gw-g3q3/GHSA-9vq5-h4gw-g3q3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vq5-h4gw-g3q3", - "modified": "2024-10-25T12:31:32Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T12:31:32Z", "aliases": [ "CVE-2024-47014" ], "details": "N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c44c-v227-hv3q/GHSA-c44c-v227-hv3q.json b/advisories/unreviewed/2024/10/GHSA-c44c-v227-hv3q/GHSA-c44c-v227-hv3q.json index 5e0f271715d..268448017d9 100644 --- a/advisories/unreviewed/2024/10/GHSA-c44c-v227-hv3q/GHSA-c44c-v227-hv3q.json +++ b/advisories/unreviewed/2024/10/GHSA-c44c-v227-hv3q/GHSA-c44c-v227-hv3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c44c-v227-hv3q", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48968" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: Fix potential memory leak in otx2_init_tc()\n\nIn otx2_init_tc(), if rhashtable_init() failed, it does not free\ntc->tc_entries_bitmap which is allocated in otx2_tc_alloc_ent_bitmap().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c9v4-5376-3jjw/GHSA-c9v4-5376-3jjw.json b/advisories/unreviewed/2024/10/GHSA-c9v4-5376-3jjw/GHSA-c9v4-5376-3jjw.json new file mode 100644 index 00000000000..e90386f4f86 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c9v4-5376-3jjw/GHSA-c9v4-5376-3jjw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9v4-5376-3jjw", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-37847" + ], + "details": "An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37847" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/blob/main/CVE-2024-37847%20File%20Upload%20Path%20Traversal.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cpjr-vp64-xf74/GHSA-cpjr-vp64-xf74.json b/advisories/unreviewed/2024/10/GHSA-cpjr-vp64-xf74/GHSA-cpjr-vp64-xf74.json new file mode 100644 index 00000000000..2404869f501 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cpjr-vp64-xf74/GHSA-cpjr-vp64-xf74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpjr-vp64-xf74", + "modified": "2024-10-25T21:31:25Z", + "published": "2024-10-25T21:31:25Z", + "aliases": [ + "CVE-2023-38135" + ], + "details": "Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38135" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00958.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f754-p36j-5c6r/GHSA-f754-p36j-5c6r.json b/advisories/unreviewed/2024/10/GHSA-f754-p36j-5c6r/GHSA-f754-p36j-5c6r.json index 58713b47f5b..a9c96aa17bf 100644 --- a/advisories/unreviewed/2024/10/GHSA-f754-p36j-5c6r/GHSA-f754-p36j-5c6r.json +++ b/advisories/unreviewed/2024/10/GHSA-f754-p36j-5c6r/GHSA-f754-p36j-5c6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f754-p36j-5c6r", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48981" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/shmem-helper: Remove errant put in error path\n\ndrm_gem_shmem_mmap() doesn't own this reference, resulting in the GEM\nobject getting prematurely freed leading to a later use-after-free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gp53-q766-mxq2/GHSA-gp53-q766-mxq2.json b/advisories/unreviewed/2024/10/GHSA-gp53-q766-mxq2/GHSA-gp53-q766-mxq2.json index 5b419558237..356a8d69bdb 100644 --- a/advisories/unreviewed/2024/10/GHSA-gp53-q766-mxq2/GHSA-gp53-q766-mxq2.json +++ b/advisories/unreviewed/2024/10/GHSA-gp53-q766-mxq2/GHSA-gp53-q766-mxq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp53-q766-mxq2", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48947" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix u8 overflow\n\nBy keep sending L2CAP_CONF_REQ packets, chan->num_conf_rsp increases\nmultiple times and eventually it will wrap around the maximum number\n(i.e., 255).\nThis patch prevents this by adding a boundary check with\nL2CAP_MAX_CONF_RSP\n\nBtmon log:\nBluetooth monitor ver 5.64\n= Note: Linux version 6.1.0-rc2 (x86_64) 0.264594\n= Note: Bluetooth subsystem version 2.22 0.264636\n@ MGMT Open: btmon (privileged) version 1.22 {0x0001} 0.272191\n= New Index: 00:00:00:00:00:00 (Primary,Virtual,hci0) [hci0] 13.877604\n@ RAW Open: 9496 (privileged) version 2.22 {0x0002} 13.890741\n= Open Index: 00:00:00:00:00:00 [hci0] 13.900426\n(...)\n> ACL Data RX: Handle 200 flags 0x00 dlen 1033 #32 [hci0] 14.273106\n invalid packet size (12 != 1033)\n 08 00 01 00 02 01 04 00 01 10 ff ff ............\n> ACL Data RX: Handle 200 flags 0x00 dlen 1547 #33 [hci0] 14.273561\n invalid packet size (14 != 1547)\n 0a 00 01 00 04 01 06 00 40 00 00 00 00 00 ........@.....\n> ACL Data RX: Handle 200 flags 0x00 dlen 2061 #34 [hci0] 14.274390\n invalid packet size (16 != 2061)\n 0c 00 01 00 04 01 08 00 40 00 00 00 00 00 00 04 ........@.......\n> ACL Data RX: Handle 200 flags 0x00 dlen 2061 #35 [hci0] 14.274932\n invalid packet size (16 != 2061)\n 0c 00 01 00 04 01 08 00 40 00 00 00 07 00 03 00 ........@.......\n= bluetoothd: Bluetooth daemon 5.43 14.401828\n> ACL Data RX: Handle 200 flags 0x00 dlen 1033 #36 [hci0] 14.275753\n invalid packet size (12 != 1033)\n 08 00 01 00 04 01 04 00 40 00 00 00 ........@...", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h345-r48x-g68f/GHSA-h345-r48x-g68f.json b/advisories/unreviewed/2024/10/GHSA-h345-r48x-g68f/GHSA-h345-r48x-g68f.json new file mode 100644 index 00000000000..3229cb119dc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h345-r48x-g68f/GHSA-h345-r48x-g68f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h345-r48x-g68f", + "modified": "2024-10-25T21:31:28Z", + "published": "2024-10-25T21:31:28Z", + "aliases": [ + "CVE-2024-48229" + ], + "details": "funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48229" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/28" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h4px-9vmp-p7pv/GHSA-h4px-9vmp-p7pv.json b/advisories/unreviewed/2024/10/GHSA-h4px-9vmp-p7pv/GHSA-h4px-9vmp-p7pv.json new file mode 100644 index 00000000000..dd0cb507081 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h4px-9vmp-p7pv/GHSA-h4px-9vmp-p7pv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4px-9vmp-p7pv", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48218" + ], + "details": "Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48218" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/21" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h4qj-qcw9-2w6h/GHSA-h4qj-qcw9-2w6h.json b/advisories/unreviewed/2024/10/GHSA-h4qj-qcw9-2w6h/GHSA-h4qj-qcw9-2w6h.json index 367f4002b6e..48f67c8c311 100644 --- a/advisories/unreviewed/2024/10/GHSA-h4qj-qcw9-2w6h/GHSA-h4qj-qcw9-2w6h.json +++ b/advisories/unreviewed/2024/10/GHSA-h4qj-qcw9-2w6h/GHSA-h4qj-qcw9-2w6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4qj-qcw9-2w6h", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen-netfront: Fix NULL sring after live migration\n\nA NAPI is setup for each network sring to poll data to kernel\nThe sring with source host is destroyed before live migration and\nnew sring with target host is setup after live migration.\nThe NAPI for the old sring is not deleted until setup new sring\nwith target host after migration. With busy_poll/busy_read enabled,\nthe NAPI can be polled before got deleted when resume VM.\n\nBUG: unable to handle kernel NULL pointer dereference at\n0000000000000008\nIP: xennet_poll+0xae/0xd20\nPGD 0 P4D 0\nOops: 0000 [#1] SMP PTI\nCall Trace:\n finish_task_switch+0x71/0x230\n timerqueue_del+0x1d/0x40\n hrtimer_try_to_cancel+0xb5/0x110\n xennet_alloc_rx_buffers+0x2a0/0x2a0\n napi_busy_loop+0xdb/0x270\n sock_poll+0x87/0x90\n do_sys_poll+0x26f/0x580\n tracing_map_insert+0x1d4/0x2f0\n event_hist_trigger+0x14a/0x260\n\n finish_task_switch+0x71/0x230\n __schedule+0x256/0x890\n recalc_sigpending+0x1b/0x50\n xen_sched_clock+0x15/0x20\n __rb_reserve_next+0x12d/0x140\n ring_buffer_lock_reserve+0x123/0x3d0\n event_triggers_call+0x87/0xb0\n trace_event_buffer_commit+0x1c4/0x210\n xen_clocksource_get_cycles+0x15/0x20\n ktime_get_ts64+0x51/0xf0\n SyS_ppoll+0x160/0x1a0\n SyS_ppoll+0x160/0x1a0\n do_syscall_64+0x73/0x130\n entry_SYSCALL_64_after_hwframe+0x41/0xa6\n...\nRIP: xennet_poll+0xae/0xd20 RSP: ffffb4f041933900\nCR2: 0000000000000008\n---[ end trace f8601785b354351c ]---\n\nxen frontend should remove the NAPIs for the old srings before live\nmigration as the bond srings are destroyed\n\nThere is a tiny window between the srings are set to NULL and\nthe NAPIs are disabled, It is safe as the NAPI threads are still\nfrozen at that time", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h8wp-xf43-pm3w/GHSA-h8wp-xf43-pm3w.json b/advisories/unreviewed/2024/10/GHSA-h8wp-xf43-pm3w/GHSA-h8wp-xf43-pm3w.json index 173922112ff..d5732a223f9 100644 --- a/advisories/unreviewed/2024/10/GHSA-h8wp-xf43-pm3w/GHSA-h8wp-xf43-pm3w.json +++ b/advisories/unreviewed/2024/10/GHSA-h8wp-xf43-pm3w/GHSA-h8wp-xf43-pm3w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8wp-xf43-pm3w", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2024-50017" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/ident_map: Use gbpages only where full GB page should be mapped.\n\nWhen ident_pud_init() uses only GB pages to create identity maps, large\nranges of addresses not actually requested can be included in the resulting\ntable; a 4K request will map a full GB. This can include a lot of extra\naddress space past that requested, including areas marked reserved by the\nBIOS. That allows processor speculation into reserved regions, that on UV\nsystems can cause system halts.\n\nOnly use GB pages when map creation requests include the full GB page of\nspace. Fall back to using smaller 2M pages when only portions of a GB page\nare included in the request.\n\nNo attempt is made to coalesce mapping requests. If a request requires a\nmap entry at the 2M (pmd) level, subsequent mapping requests within the\nsame 1G region will also be at the pmd level, even if adjacent or\noverlapping such requests could have been combined to map a full GB page.\nExisting usage starts with larger regions and then adds smaller regions, so\nthis should not have any great consequence.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hf8q-jfj5-c238/GHSA-hf8q-jfj5-c238.json b/advisories/unreviewed/2024/10/GHSA-hf8q-jfj5-c238/GHSA-hf8q-jfj5-c238.json index fa4cdb64655..b0f99a380b5 100644 --- a/advisories/unreviewed/2024/10/GHSA-hf8q-jfj5-c238/GHSA-hf8q-jfj5-c238.json +++ b/advisories/unreviewed/2024/10/GHSA-hf8q-jfj5-c238/GHSA-hf8q-jfj5-c238.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf8q-jfj5-c238", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2024-48204" ], "details": "SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T16:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json b/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json index b8e49f4b681..2ec30fce3c9 100644 --- a/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json +++ b/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxxw-vvrc-qrx3", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index out of bounds in DCN30 color transformation\n\nThis commit addresses a potential index out of bounds issue in the\n`cm3_helper_translate_curve_to_hw_format` function in the DCN30 color\nmanagement module. The issue could occur when the index 'i' exceeds the\nnumber of transfer function points (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds, the function returns\nfalse to indicate an error.\n\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:180 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:181 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:182 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j8vf-qmcj-wv9f/GHSA-j8vf-qmcj-wv9f.json b/advisories/unreviewed/2024/10/GHSA-j8vf-qmcj-wv9f/GHSA-j8vf-qmcj-wv9f.json index 83e7e9d7b30..c8a459f8d55 100644 --- a/advisories/unreviewed/2024/10/GHSA-j8vf-qmcj-wv9f/GHSA-j8vf-qmcj-wv9f.json +++ b/advisories/unreviewed/2024/10/GHSA-j8vf-qmcj-wv9f/GHSA-j8vf-qmcj-wv9f.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json b/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json index 15bffbe7829..2a805c16ade 100644 --- a/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json +++ b/advisories/unreviewed/2024/10/GHSA-jc3p-f86q-23rh/GHSA-jc3p-f86q-23rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc3p-f86q-23rh", - "modified": "2024-10-25T12:31:32Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T12:31:32Z", "aliases": [ "CVE-2024-47012" ], "details": "In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json b/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json index 89e35a497ee..6f7e7455850 100644 --- a/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json +++ b/advisories/unreviewed/2024/10/GHSA-jjq3-cw48-pqmx/GHSA-jjq3-cw48-pqmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjq3-cw48-pqmx", - "modified": "2024-10-24T21:31:03Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T21:31:03Z", "aliases": [ "CVE-2024-48139" ], "details": "A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json b/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json index 537006072ff..80b927a6c5d 100644 --- a/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json +++ b/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmxw-f4w9-294j", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49989" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix double free issue during amdgpu module unload\n\nFlexible endpoints use DIGs from available inflexible endpoints,\nso only the encoders of inflexible links need to be freed.\nOtherwise, a double free issue may occur when unloading the\namdgpu module.\n\n[ 279.190523] RIP: 0010:__slab_free+0x152/0x2f0\n[ 279.190577] Call Trace:\n[ 279.190580] \n[ 279.190582] ? show_regs+0x69/0x80\n[ 279.190590] ? die+0x3b/0x90\n[ 279.190595] ? do_trap+0xc8/0xe0\n[ 279.190601] ? do_error_trap+0x73/0xa0\n[ 279.190605] ? __slab_free+0x152/0x2f0\n[ 279.190609] ? exc_invalid_op+0x56/0x70\n[ 279.190616] ? __slab_free+0x152/0x2f0\n[ 279.190642] ? asm_exc_invalid_op+0x1f/0x30\n[ 279.190648] ? dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191096] ? __slab_free+0x152/0x2f0\n[ 279.191102] ? dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191469] kfree+0x260/0x2b0\n[ 279.191474] dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191821] link_destroy+0xd7/0x130 [amdgpu]\n[ 279.192248] dc_destruct+0x90/0x270 [amdgpu]\n[ 279.192666] dc_destroy+0x19/0x40 [amdgpu]\n[ 279.193020] amdgpu_dm_fini+0x16e/0x200 [amdgpu]\n[ 279.193432] dm_hw_fini+0x26/0x40 [amdgpu]\n[ 279.193795] amdgpu_device_fini_hw+0x24c/0x400 [amdgpu]\n[ 279.194108] amdgpu_driver_unload_kms+0x4f/0x70 [amdgpu]\n[ 279.194436] amdgpu_pci_remove+0x40/0x80 [amdgpu]\n[ 279.194632] pci_device_remove+0x3a/0xa0\n[ 279.194638] device_remove+0x40/0x70\n[ 279.194642] device_release_driver_internal+0x1ad/0x210\n[ 279.194647] driver_detach+0x4e/0xa0\n[ 279.194650] bus_remove_driver+0x6f/0xf0\n[ 279.194653] driver_unregister+0x33/0x60\n[ 279.194657] pci_unregister_driver+0x44/0x90\n[ 279.194662] amdgpu_exit+0x19/0x1f0 [amdgpu]\n[ 279.194939] __do_sys_delete_module.isra.0+0x198/0x2f0\n[ 279.194946] __x64_sys_delete_module+0x16/0x20\n[ 279.194950] do_syscall_64+0x58/0x120\n[ 279.194954] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[ 279.194980] ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:19Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jp89-qg38-336v/GHSA-jp89-qg38-336v.json b/advisories/unreviewed/2024/10/GHSA-jp89-qg38-336v/GHSA-jp89-qg38-336v.json index 0885763cd27..fc8a2bd82f5 100644 --- a/advisories/unreviewed/2024/10/GHSA-jp89-qg38-336v/GHSA-jp89-qg38-336v.json +++ b/advisories/unreviewed/2024/10/GHSA-jp89-qg38-336v/GHSA-jp89-qg38-336v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json b/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json new file mode 100644 index 00000000000..6deb707b881 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jxjm-crgh-jq3f/GHSA-jxjm-crgh-jq3f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxjm-crgh-jq3f", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-37844" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37844" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/blob/main/CVE-2024-37844%20XSS.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m584-rmpj-6q5p/GHSA-m584-rmpj-6q5p.json b/advisories/unreviewed/2024/10/GHSA-m584-rmpj-6q5p/GHSA-m584-rmpj-6q5p.json index 8c575a5226b..c6d98a65577 100644 --- a/advisories/unreviewed/2024/10/GHSA-m584-rmpj-6q5p/GHSA-m584-rmpj-6q5p.json +++ b/advisories/unreviewed/2024/10/GHSA-m584-rmpj-6q5p/GHSA-m584-rmpj-6q5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m584-rmpj-6q5p", - "modified": "2024-10-24T18:30:44Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T18:30:44Z", "aliases": [ "CVE-2024-48440" ], "details": "Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T18:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mcg9-4p62-w7x9/GHSA-mcg9-4p62-w7x9.json b/advisories/unreviewed/2024/10/GHSA-mcg9-4p62-w7x9/GHSA-mcg9-4p62-w7x9.json new file mode 100644 index 00000000000..f1318bde33b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mcg9-4p62-w7x9/GHSA-mcg9-4p62-w7x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcg9-4p62-w7x9", + "modified": "2024-10-25T21:31:25Z", + "published": "2024-10-25T21:31:25Z", + "aliases": [ + "CVE-2023-32647" + ], + "details": "Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32647" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00955.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p25v-3q9m-p32x/GHSA-p25v-3q9m-p32x.json b/advisories/unreviewed/2024/10/GHSA-p25v-3q9m-p32x/GHSA-p25v-3q9m-p32x.json index e81b48a9fa6..c9357e772e2 100644 --- a/advisories/unreviewed/2024/10/GHSA-p25v-3q9m-p32x/GHSA-p25v-3q9m-p32x.json +++ b/advisories/unreviewed/2024/10/GHSA-p25v-3q9m-p32x/GHSA-p25v-3q9m-p32x.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-p7hf-43g5-xhvw/GHSA-p7hf-43g5-xhvw.json b/advisories/unreviewed/2024/10/GHSA-p7hf-43g5-xhvw/GHSA-p7hf-43g5-xhvw.json new file mode 100644 index 00000000000..251da3b180d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p7hf-43g5-xhvw/GHSA-p7hf-43g5-xhvw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hf-43g5-xhvw", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-37845" + ], + "details": "MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37845" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/blob/main/CVE-2024-37845%20RCE.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/herombey/Disclosures/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p9jh-f6vr-wxj3/GHSA-p9jh-f6vr-wxj3.json b/advisories/unreviewed/2024/10/GHSA-p9jh-f6vr-wxj3/GHSA-p9jh-f6vr-wxj3.json index 453d1fd6eae..b5d6268d16e 100644 --- a/advisories/unreviewed/2024/10/GHSA-p9jh-f6vr-wxj3/GHSA-p9jh-f6vr-wxj3.json +++ b/advisories/unreviewed/2024/10/GHSA-p9jh-f6vr-wxj3/GHSA-p9jh-f6vr-wxj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9jh-f6vr-wxj3", - "modified": "2024-10-24T18:30:44Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T18:30:44Z", "aliases": [ "CVE-2024-46478" ], "details": "HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json b/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json index 1683b7acba0..3574a6367dc 100644 --- a/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json +++ b/advisories/unreviewed/2024/10/GHSA-phfx-3hch-p62r/GHSA-phfx-3hch-p62r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phfx-3hch-p62r", - "modified": "2024-10-25T12:31:32Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T12:31:32Z", "aliases": [ "CVE-2024-44099" ], "details": "There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T11:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-px64-cpgr-654p/GHSA-px64-cpgr-654p.json b/advisories/unreviewed/2024/10/GHSA-px64-cpgr-654p/GHSA-px64-cpgr-654p.json index b4e321b61b6..8719b449438 100644 --- a/advisories/unreviewed/2024/10/GHSA-px64-cpgr-654p/GHSA-px64-cpgr-654p.json +++ b/advisories/unreviewed/2024/10/GHSA-px64-cpgr-654p/GHSA-px64-cpgr-654p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px64-cpgr-654p", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2024-48581" ], "details": "File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T16:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qq67-99wj-86rm/GHSA-qq67-99wj-86rm.json b/advisories/unreviewed/2024/10/GHSA-qq67-99wj-86rm/GHSA-qq67-99wj-86rm.json index e3cade66775..ce5a5670d8c 100644 --- a/advisories/unreviewed/2024/10/GHSA-qq67-99wj-86rm/GHSA-qq67-99wj-86rm.json +++ b/advisories/unreviewed/2024/10/GHSA-qq67-99wj-86rm/GHSA-qq67-99wj-86rm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qq67-99wj-86rm", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2024-50012" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Avoid a bad reference count on CPU node\n\nIn the parse_perf_domain function, if the call to\nof_parse_phandle_with_args returns an error, then the reference to the\nCPU device node that was acquired at the start of the function would not\nbe properly decremented.\n\nAddress this by declaring the variable with the __free(device_node)\ncleanup attribute.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qr7m-wmg3-5x2f/GHSA-qr7m-wmg3-5x2f.json b/advisories/unreviewed/2024/10/GHSA-qr7m-wmg3-5x2f/GHSA-qr7m-wmg3-5x2f.json index 594079871aa..d184e8d1fb3 100644 --- a/advisories/unreviewed/2024/10/GHSA-qr7m-wmg3-5x2f/GHSA-qr7m-wmg3-5x2f.json +++ b/advisories/unreviewed/2024/10/GHSA-qr7m-wmg3-5x2f/GHSA-qr7m-wmg3-5x2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qr7m-wmg3-5x2f", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48978" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix shift-out-of-bounds in hid_report_raw_event\n\nSyzbot reported shift-out-of-bounds in hid_report_raw_event.\n\nmicrosoft 0003:045E:07DA.0001: hid_field_extract() called with n (128) >\n32! (swapper/0)\n======================================================================\nUBSAN: shift-out-of-bounds in drivers/hid/hid-core.c:1323:20\nshift exponent 127 is too large for 32-bit type 'int'\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted\n6.1.0-rc4-syzkaller-00159-g4bbf3422df78 #0\nHardware name: Google Compute Engine/Google Compute Engine, BIOS\nGoogle 10/26/2022\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106\n ubsan_epilogue lib/ubsan.c:151 [inline]\n __ubsan_handle_shift_out_of_bounds+0x3a6/0x420 lib/ubsan.c:322\n snto32 drivers/hid/hid-core.c:1323 [inline]\n hid_input_fetch_field drivers/hid/hid-core.c:1572 [inline]\n hid_process_report drivers/hid/hid-core.c:1665 [inline]\n hid_report_raw_event+0xd56/0x18b0 drivers/hid/hid-core.c:1998\n hid_input_report+0x408/0x4f0 drivers/hid/hid-core.c:2066\n hid_irq_in+0x459/0x690 drivers/hid/usbhid/hid-core.c:284\n __usb_hcd_giveback_urb+0x369/0x530 drivers/usb/core/hcd.c:1671\n dummy_timer+0x86b/0x3110 drivers/usb/gadget/udc/dummy_hcd.c:1988\n call_timer_fn+0xf5/0x210 kernel/time/timer.c:1474\n expire_timers kernel/time/timer.c:1519 [inline]\n __run_timers+0x76a/0x980 kernel/time/timer.c:1790\n run_timer_softirq+0x63/0xf0 kernel/time/timer.c:1803\n __do_softirq+0x277/0x75b kernel/softirq.c:571\n __irq_exit_rcu+0xec/0x170 kernel/softirq.c:650\n irq_exit_rcu+0x5/0x20 kernel/softirq.c:662\n sysvec_apic_timer_interrupt+0x91/0xb0 arch/x86/kernel/apic/apic.c:1107\n======================================================================\n\nIf the size of the integer (unsigned n) is bigger than 32 in snto32(),\nshift exponent will be too large for 32-bit type 'int', resulting in a\nshift-out-of-bounds bug.\nFix this by adding a check on the size of the integer (unsigned n) in\nsnto32(). To add support for n greater than 32 bits, set n to 32, if n\nis greater than 32.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qw38-ppmm-fjpw/GHSA-qw38-ppmm-fjpw.json b/advisories/unreviewed/2024/10/GHSA-qw38-ppmm-fjpw/GHSA-qw38-ppmm-fjpw.json index b94a5d02271..5fcc7a30a68 100644 --- a/advisories/unreviewed/2024/10/GHSA-qw38-ppmm-fjpw/GHSA-qw38-ppmm-fjpw.json +++ b/advisories/unreviewed/2024/10/GHSA-qw38-ppmm-fjpw/GHSA-qw38-ppmm-fjpw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw38-ppmm-fjpw", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48950" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix perf_pending_task() UaF\n\nPer syzbot it is possible for perf_pending_task() to run after the\nevent is free()'d. There are two related but distinct cases:\n\n - the task_work was already queued before destroying the event;\n - destroying the event itself queues the task_work.\n\nThe first cannot be solved using task_work_cancel() since\nperf_release() itself might be called from a task_work (____fput),\nwhich means the current->task_works list is already empty and\ntask_work_cancel() won't be able to find the perf_pending_task()\nentry.\n\nThe simplest alternative is extending the perf_event lifetime to cover\nthe task_work.\n\nThe second is just silly, queueing a task_work while you know the\nevent is going away makes no sense and is easily avoided by\nre-arranging how the event is marked STATE_DEAD and ensuring it goes\nthrough STATE_OFF on the way down.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json b/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json new file mode 100644 index 00000000000..9e146e9df50 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r39h-f84x-g77w/GHSA-r39h-f84x-g77w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r39h-f84x-g77w", + "modified": "2024-10-25T21:31:28Z", + "published": "2024-10-25T21:31:28Z", + "aliases": [ + "CVE-2024-48233" + ], + "details": "mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \\app\\setting\\controller\\ApiAdminSetting.php via the ICP parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48233" + }, + { + "type": "WEB", + "url": "https://github.com/sansanyun/mipjz/issues/16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r9v5-q97m-rj5g/GHSA-r9v5-q97m-rj5g.json b/advisories/unreviewed/2024/10/GHSA-r9v5-q97m-rj5g/GHSA-r9v5-q97m-rj5g.json new file mode 100644 index 00000000000..4fbad6dde15 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r9v5-q97m-rj5g/GHSA-r9v5-q97m-rj5g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9v5-q97m-rj5g", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48227" + ], + "details": "Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48227" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/27" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rwfh-mmmq-96x7/GHSA-rwfh-mmmq-96x7.json b/advisories/unreviewed/2024/10/GHSA-rwfh-mmmq-96x7/GHSA-rwfh-mmmq-96x7.json index dd6fc751357..0f6ebc54b5c 100644 --- a/advisories/unreviewed/2024/10/GHSA-rwfh-mmmq-96x7/GHSA-rwfh-mmmq-96x7.json +++ b/advisories/unreviewed/2024/10/GHSA-rwfh-mmmq-96x7/GHSA-rwfh-mmmq-96x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwfh-mmmq-96x7", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48965" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio/rockchip: fix refcount leak in rockchip_gpiolib_register()\n\nThe node returned by of_get_parent() with refcount incremented,\nof_node_put() needs be called when finish using it. So add it in the\nend of of_pinctrl_get().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rxqx-qqq2-7xfj/GHSA-rxqx-qqq2-7xfj.json b/advisories/unreviewed/2024/10/GHSA-rxqx-qqq2-7xfj/GHSA-rxqx-qqq2-7xfj.json index 99d764c0972..551c858749a 100644 --- a/advisories/unreviewed/2024/10/GHSA-rxqx-qqq2-7xfj/GHSA-rxqx-qqq2-7xfj.json +++ b/advisories/unreviewed/2024/10/GHSA-rxqx-qqq2-7xfj/GHSA-rxqx-qqq2-7xfj.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxqx-qqq2-7xfj", - "modified": "2024-10-22T09:33:54Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-22T09:33:54Z", "aliases": [ "CVE-2024-9987" ], "details": "A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red" diff --git a/advisories/unreviewed/2024/10/GHSA-vj24-j7x3-73cw/GHSA-vj24-j7x3-73cw.json b/advisories/unreviewed/2024/10/GHSA-vj24-j7x3-73cw/GHSA-vj24-j7x3-73cw.json index bc11a3e25b6..b5335be49c6 100644 --- a/advisories/unreviewed/2024/10/GHSA-vj24-j7x3-73cw/GHSA-vj24-j7x3-73cw.json +++ b/advisories/unreviewed/2024/10/GHSA-vj24-j7x3-73cw/GHSA-vj24-j7x3-73cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj24-j7x3-73cw", - "modified": "2024-10-24T18:30:44Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T18:30:44Z", "aliases": [ "CVE-2024-48442" ], "details": "Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T18:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vw6x-c5rg-jmjp/GHSA-vw6x-c5rg-jmjp.json b/advisories/unreviewed/2024/10/GHSA-vw6x-c5rg-jmjp/GHSA-vw6x-c5rg-jmjp.json new file mode 100644 index 00000000000..51fa0d9c511 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vw6x-c5rg-jmjp/GHSA-vw6x-c5rg-jmjp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw6x-c5rg-jmjp", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48225" + ], + "details": "Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48225" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vwjf-jh23-hhpx/GHSA-vwjf-jh23-hhpx.json b/advisories/unreviewed/2024/10/GHSA-vwjf-jh23-hhpx/GHSA-vwjf-jh23-hhpx.json index ca979b95ae0..72d63611972 100644 --- a/advisories/unreviewed/2024/10/GHSA-vwjf-jh23-hhpx/GHSA-vwjf-jh23-hhpx.json +++ b/advisories/unreviewed/2024/10/GHSA-vwjf-jh23-hhpx/GHSA-vwjf-jh23-hhpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwjf-jh23-hhpx", - "modified": "2024-10-21T21:30:50Z", + "modified": "2024-10-25T21:31:26Z", "published": "2024-10-21T21:30:50Z", "aliases": [ "CVE-2022-48951" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()\n\nThe bounds checks in snd_soc_put_volsw_sx() are only being applied to the\nfirst channel, meaning it is possible to write out of bounds values to the\nsecond channel in stereo controls. Add appropriate checks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w3m7-7f4v-5jvh/GHSA-w3m7-7f4v-5jvh.json b/advisories/unreviewed/2024/10/GHSA-w3m7-7f4v-5jvh/GHSA-w3m7-7f4v-5jvh.json index 19b851ca121..38f8f732905 100644 --- a/advisories/unreviewed/2024/10/GHSA-w3m7-7f4v-5jvh/GHSA-w3m7-7f4v-5jvh.json +++ b/advisories/unreviewed/2024/10/GHSA-w3m7-7f4v-5jvh/GHSA-w3m7-7f4v-5jvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3m7-7f4v-5jvh", - "modified": "2024-10-25T18:30:49Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2024-48579" ], "details": "SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-25T16:15:09Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w3m8-3fj2-8h9p/GHSA-w3m8-3fj2-8h9p.json b/advisories/unreviewed/2024/10/GHSA-w3m8-3fj2-8h9p/GHSA-w3m8-3fj2-8h9p.json index 12232e9390c..092e531d07b 100644 --- a/advisories/unreviewed/2024/10/GHSA-w3m8-3fj2-8h9p/GHSA-w3m8-3fj2-8h9p.json +++ b/advisories/unreviewed/2024/10/GHSA-w3m8-3fj2-8h9p/GHSA-w3m8-3fj2-8h9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3m8-3fj2-8h9p", - "modified": "2024-10-21T21:30:51Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-21T21:30:51Z", "aliases": [ "CVE-2022-48980" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: sja1105: avoid out of bounds access in sja1105_init_l2_policing()\n\nThe SJA1105 family has 45 L2 policing table entries\n(SJA1105_MAX_L2_POLICING_COUNT) and SJA1110 has 110\n(SJA1110_MAX_L2_POLICING_COUNT). Keeping the table structure but\naccounting for the difference in port count (5 in SJA1105 vs 10 in\nSJA1110) does not fully explain the difference. Rather, the SJA1110 also\nhas L2 ingress policers for multicast traffic. If a packet is classified\nas multicast, it will be processed by the policer index 99 + SRCPORT.\n\nThe sja1105_init_l2_policing() function initializes all L2 policers such\nthat they don't interfere with normal packet reception by default. To have\na common code between SJA1105 and SJA1110, the index of the multicast\npolicer for the port is calculated because it's an index that is out of\nbounds for SJA1105 but in bounds for SJA1110, and a bounds check is\nperformed.\n\nThe code fails to do the proper thing when determining what to do with the\nmulticast policer of port 0 on SJA1105 (ds->num_ports = 5). The \"mcast\"\nindex will be equal to 45, which is also equal to\ntable->ops->max_entry_count (SJA1105_MAX_L2_POLICING_COUNT). So it passes\nthrough the check. But at the same time, SJA1105 doesn't have multicast\npolicers. So the code programs the SHARINDX field of an out-of-bounds\nelement in the L2 Policing table of the static config.\n\nThe comparison between index 45 and 45 entries should have determined the\ncode to not access this policer index on SJA1105, since its memory wasn't\neven allocated.\n\nWith enough bad luck, the out-of-bounds write could even overwrite other\nvalid kernel data, but in this case, the issue was detected using KASAN.\n\nKernel log:\n\nsja1105 spi5.0: Probed switch chip: SJA1105Q\n==================================================================\nBUG: KASAN: slab-out-of-bounds in sja1105_setup+0x1cbc/0x2340\nWrite of size 8 at addr ffffff880bd57708 by task kworker/u8:0/8\n...\nWorkqueue: events_unbound deferred_probe_work_func\nCall trace:\n...\nsja1105_setup+0x1cbc/0x2340\ndsa_register_switch+0x1284/0x18d0\nsja1105_probe+0x748/0x840\n...\nAllocated by task 8:\n...\nsja1105_setup+0x1bcc/0x2340\ndsa_register_switch+0x1284/0x18d0\nsja1105_probe+0x748/0x840\n...", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w7fm-hm77-gq28/GHSA-w7fm-hm77-gq28.json b/advisories/unreviewed/2024/10/GHSA-w7fm-hm77-gq28/GHSA-w7fm-hm77-gq28.json new file mode 100644 index 00000000000..838123f81b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w7fm-hm77-gq28/GHSA-w7fm-hm77-gq28.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7fm-hm77-gq28", + "modified": "2024-10-25T21:31:25Z", + "published": "2024-10-25T21:31:25Z", + "aliases": [ + "CVE-2023-38561" + ], + "details": "Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38561" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00955.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json b/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json index d899a32744d..63a325f4abb 100644 --- a/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json +++ b/advisories/unreviewed/2024/10/GHSA-w7vv-chh5-rjfj/GHSA-w7vv-chh5-rjfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7vv-chh5-rjfj", - "modified": "2024-10-24T21:31:03Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T21:31:03Z", "aliases": [ "CVE-2024-48142" ], "details": "A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json b/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json index c46febe6ba2..3e302b7834f 100644 --- a/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json +++ b/advisories/unreviewed/2024/10/GHSA-w8r5-25wc-2c5m/GHSA-w8r5-25wc-2c5m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8r5-25wc-2c5m", - "modified": "2024-10-24T21:31:03Z", + "modified": "2024-10-25T21:31:27Z", "published": "2024-10-24T21:31:03Z", "aliases": [ "CVE-2024-48140" ], "details": "A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wh9r-qhjq-2hg4/GHSA-wh9r-qhjq-2hg4.json b/advisories/unreviewed/2024/10/GHSA-wh9r-qhjq-2hg4/GHSA-wh9r-qhjq-2hg4.json new file mode 100644 index 00000000000..a3981ec5d31 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wh9r-qhjq-2hg4/GHSA-wh9r-qhjq-2hg4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh9r-qhjq-2hg4", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48450" + ], + "details": "An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48450" + }, + { + "type": "WEB", + "url": "https://github.com/b-hermes/vulnerability-research/tree/main/CVE-2024-48450" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x2fr-vj74-5h35/GHSA-x2fr-vj74-5h35.json b/advisories/unreviewed/2024/10/GHSA-x2fr-vj74-5h35/GHSA-x2fr-vj74-5h35.json new file mode 100644 index 00000000000..de8b75c49b1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x2fr-vj74-5h35/GHSA-x2fr-vj74-5h35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2fr-vj74-5h35", + "modified": "2024-10-25T21:31:27Z", + "published": "2024-10-25T21:31:27Z", + "aliases": [ + "CVE-2024-48223" + ], + "details": "Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48223" + }, + { + "type": "WEB", + "url": "https://github.com/funadmin/funadmin/issues/23" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-25T21:15:03Z" + } +} \ No newline at end of file