From e4b259481439d22a635ef6b0a19e7cabd9e34d63 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 6 Jul 2023 03:32:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3vjj-f6mx-v6mf.json | 7 +++- .../GHSA-82j3-37rp-v59p.json | 9 ++-- .../GHSA-8q9j-479x-6g5g.json | 9 ++-- .../GHSA-cx5j-85rf-rq2m.json | 9 ++-- .../GHSA-jh4x-45p8-48r4.json | 9 ++-- .../GHSA-phhq-j3pr-xv78.json | 9 ++-- .../GHSA-r74p-fm7h-v58h.json | 9 ++-- .../GHSA-x5v3-9hgf-599q.json | 2 +- .../GHSA-xwcr-4pfv-3qm8.json | 9 ++-- .../GHSA-2jjp-c35x-v2v9.json | 38 +++++++++++++++++ .../GHSA-2xph-w2r8-f9pw.json | 38 +++++++++++++++++ .../GHSA-36wc-2jgf-p9gp.json | 38 +++++++++++++++++ .../GHSA-48cv-xv53-cgjf.json | 38 +++++++++++++++++ .../GHSA-49vx-vwj9-q95m.json | 35 ++++++++++++++++ .../GHSA-4c89-hmqm-65h7.json | 38 +++++++++++++++++ .../GHSA-4h27-fj22-482r.json | 38 +++++++++++++++++ .../GHSA-5jxc-mmv9-x77x.json | 38 +++++++++++++++++ .../GHSA-6g4h-q5wf-4cv7.json | 38 +++++++++++++++++ .../GHSA-6p4h-xvj3-j477.json | 38 +++++++++++++++++ .../GHSA-83q5-ph4f-qx3w.json | 39 +++++++++++++++++ .../GHSA-8hgr-jwwc-6m87.json | 38 +++++++++++++++++ .../GHSA-8xqj-8wq5-jx5x.json | 38 +++++++++++++++++ .../GHSA-93v2-v964-8v32.json | 38 +++++++++++++++++ .../GHSA-9r79-345x-hmrj.json | 38 +++++++++++++++++ .../GHSA-c55m-42jr-9f58.json | 38 +++++++++++++++++ .../GHSA-c9gx-wmcv-6c99.json | 38 +++++++++++++++++ .../GHSA-cpj5-6hc9-4243.json | 38 +++++++++++++++++ .../GHSA-f2hf-p7mp-7x9v.json | 42 +++++++++++++++++++ .../GHSA-f2jq-xx6w-7wgv.json | 38 +++++++++++++++++ .../GHSA-f995-m52f-mjhx.json | 38 +++++++++++++++++ .../GHSA-f9fp-mv38-gcjq.json | 39 +++++++++++++++++ .../GHSA-fcmh-mv68-957w.json | 38 +++++++++++++++++ .../GHSA-fgh3-6cc5-g9mv.json | 42 +++++++++++++++++++ .../GHSA-gc2m-85qp-g4q2.json | 38 +++++++++++++++++ .../GHSA-gqcm-hxx4-3hrp.json | 38 +++++++++++++++++ .../GHSA-gqq5-v4cw-9926.json | 38 +++++++++++++++++ .../GHSA-h9j7-xfpf-9qqc.json | 38 +++++++++++++++++ .../GHSA-hgq6-hc58-6h88.json | 38 +++++++++++++++++ .../GHSA-j5fh-8vfx-pf9m.json | 38 +++++++++++++++++ .../GHSA-jrxr-fwjr-rghr.json | 38 +++++++++++++++++ .../GHSA-mjxq-qjq6-94vh.json | 38 +++++++++++++++++ .../GHSA-mwv4-686j-f844.json | 38 +++++++++++++++++ .../GHSA-pgwp-hxrw-pr48.json | 38 +++++++++++++++++ .../GHSA-phgv-c466-pqj8.json | 38 +++++++++++++++++ .../GHSA-phv9-h86h-pf49.json | 38 +++++++++++++++++ .../GHSA-qm74-hw29-p8vj.json | 38 +++++++++++++++++ .../GHSA-qrr4-p6rr-3pjr.json | 38 +++++++++++++++++ .../GHSA-rc7j-3cmg-8cww.json | 38 +++++++++++++++++ .../GHSA-rq9c-g2c8-gm2q.json | 38 +++++++++++++++++ .../GHSA-vgxr-5gfw-xp36.json | 38 +++++++++++++++++ .../GHSA-w6m8-3jxg-4g55.json | 39 +++++++++++++++++ .../GHSA-wc2x-c474-wcwr.json | 38 +++++++++++++++++ .../GHSA-x7r6-hgxq-528p.json | 38 +++++++++++++++++ 53 files changed, 1728 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2023/07/GHSA-2jjp-c35x-v2v9/GHSA-2jjp-c35x-v2v9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2xph-w2r8-f9pw/GHSA-2xph-w2r8-f9pw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-36wc-2jgf-p9gp/GHSA-36wc-2jgf-p9gp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-48cv-xv53-cgjf/GHSA-48cv-xv53-cgjf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-49vx-vwj9-q95m/GHSA-49vx-vwj9-q95m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4c89-hmqm-65h7/GHSA-4c89-hmqm-65h7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4h27-fj22-482r/GHSA-4h27-fj22-482r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5jxc-mmv9-x77x/GHSA-5jxc-mmv9-x77x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6g4h-q5wf-4cv7/GHSA-6g4h-q5wf-4cv7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6p4h-xvj3-j477/GHSA-6p4h-xvj3-j477.json create mode 100644 advisories/unreviewed/2023/07/GHSA-83q5-ph4f-qx3w/GHSA-83q5-ph4f-qx3w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8hgr-jwwc-6m87/GHSA-8hgr-jwwc-6m87.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8xqj-8wq5-jx5x/GHSA-8xqj-8wq5-jx5x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-93v2-v964-8v32/GHSA-93v2-v964-8v32.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9r79-345x-hmrj/GHSA-9r79-345x-hmrj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c55m-42jr-9f58/GHSA-c55m-42jr-9f58.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c9gx-wmcv-6c99/GHSA-c9gx-wmcv-6c99.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cpj5-6hc9-4243/GHSA-cpj5-6hc9-4243.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f2hf-p7mp-7x9v/GHSA-f2hf-p7mp-7x9v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f2jq-xx6w-7wgv/GHSA-f2jq-xx6w-7wgv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f995-m52f-mjhx/GHSA-f995-m52f-mjhx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f9fp-mv38-gcjq/GHSA-f9fp-mv38-gcjq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fcmh-mv68-957w/GHSA-fcmh-mv68-957w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fgh3-6cc5-g9mv/GHSA-fgh3-6cc5-g9mv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gc2m-85qp-g4q2/GHSA-gc2m-85qp-g4q2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gqcm-hxx4-3hrp/GHSA-gqcm-hxx4-3hrp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gqq5-v4cw-9926/GHSA-gqq5-v4cw-9926.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h9j7-xfpf-9qqc/GHSA-h9j7-xfpf-9qqc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hgq6-hc58-6h88/GHSA-hgq6-hc58-6h88.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j5fh-8vfx-pf9m/GHSA-j5fh-8vfx-pf9m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jrxr-fwjr-rghr/GHSA-jrxr-fwjr-rghr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mjxq-qjq6-94vh/GHSA-mjxq-qjq6-94vh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mwv4-686j-f844/GHSA-mwv4-686j-f844.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pgwp-hxrw-pr48/GHSA-pgwp-hxrw-pr48.json create mode 100644 advisories/unreviewed/2023/07/GHSA-phgv-c466-pqj8/GHSA-phgv-c466-pqj8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-phv9-h86h-pf49/GHSA-phv9-h86h-pf49.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qm74-hw29-p8vj/GHSA-qm74-hw29-p8vj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qrr4-p6rr-3pjr/GHSA-qrr4-p6rr-3pjr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rc7j-3cmg-8cww/GHSA-rc7j-3cmg-8cww.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rq9c-g2c8-gm2q/GHSA-rq9c-g2c8-gm2q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vgxr-5gfw-xp36/GHSA-vgxr-5gfw-xp36.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w6m8-3jxg-4g55/GHSA-w6m8-3jxg-4g55.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wc2x-c474-wcwr/GHSA-wc2x-c474-wcwr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x7r6-hgxq-528p/GHSA-x7r6-hgxq-528p.json diff --git a/advisories/unreviewed/2023/06/GHSA-3vjj-f6mx-v6mf/GHSA-3vjj-f6mx-v6mf.json b/advisories/unreviewed/2023/06/GHSA-3vjj-f6mx-v6mf/GHSA-3vjj-f6mx-v6mf.json index 0ffc8dee221..a7896144f67 100644 --- a/advisories/unreviewed/2023/06/GHSA-3vjj-f6mx-v6mf/GHSA-3vjj-f6mx-v6mf.json +++ b/advisories/unreviewed/2023/06/GHSA-3vjj-f6mx-v6mf/GHSA-3vjj-f6mx-v6mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vjj-f6mx-v6mf", - "modified": "2023-06-28T18:30:26Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:26Z", "aliases": [ "CVE-2023-21183" ], "details": "In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235863754", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-82j3-37rp-v59p/GHSA-82j3-37rp-v59p.json b/advisories/unreviewed/2023/06/GHSA-82j3-37rp-v59p/GHSA-82j3-37rp-v59p.json index 1b6ac85e87c..7a2b37527d6 100644 --- a/advisories/unreviewed/2023/06/GHSA-82j3-37rp-v59p/GHSA-82j3-37rp-v59p.json +++ b/advisories/unreviewed/2023/06/GHSA-82j3-37rp-v59p/GHSA-82j3-37rp-v59p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82j3-37rp-v59p", - "modified": "2023-06-28T18:30:26Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:26Z", "aliases": [ "CVE-2023-21181" ], "details": "In btm_ble_update_inq_result of btm_ble_gap.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-264880969", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-8q9j-479x-6g5g/GHSA-8q9j-479x-6g5g.json b/advisories/unreviewed/2023/06/GHSA-8q9j-479x-6g5g/GHSA-8q9j-479x-6g5g.json index c41659fe6b2..a1c09ae2002 100644 --- a/advisories/unreviewed/2023/06/GHSA-8q9j-479x-6g5g/GHSA-8q9j-479x-6g5g.json +++ b/advisories/unreviewed/2023/06/GHSA-8q9j-479x-6g5g/GHSA-8q9j-479x-6g5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8q9j-479x-6g5g", - "modified": "2023-06-28T18:30:26Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:26Z", "aliases": [ "CVE-2023-21210" ], "details": "In initiateHs20IconQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236331", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-cx5j-85rf-rq2m/GHSA-cx5j-85rf-rq2m.json b/advisories/unreviewed/2023/06/GHSA-cx5j-85rf-rq2m/GHSA-cx5j-85rf-rq2m.json index ea41afebef6..fdfffe20177 100644 --- a/advisories/unreviewed/2023/06/GHSA-cx5j-85rf-rq2m/GHSA-cx5j-85rf-rq2m.json +++ b/advisories/unreviewed/2023/06/GHSA-cx5j-85rf-rq2m/GHSA-cx5j-85rf-rq2m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx5j-85rf-rq2m", - "modified": "2023-06-28T18:30:25Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:25Z", "aliases": [ "CVE-2023-21167" ], "details": "In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259942964", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-jh4x-45p8-48r4/GHSA-jh4x-45p8-48r4.json b/advisories/unreviewed/2023/06/GHSA-jh4x-45p8-48r4/GHSA-jh4x-45p8-48r4.json index 5c6468c03ad..afe68b15ab7 100644 --- a/advisories/unreviewed/2023/06/GHSA-jh4x-45p8-48r4/GHSA-jh4x-45p8-48r4.json +++ b/advisories/unreviewed/2023/06/GHSA-jh4x-45p8-48r4/GHSA-jh4x-45p8-48r4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jh4x-45p8-48r4", - "modified": "2023-06-28T18:30:25Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:25Z", "aliases": [ "CVE-2023-21161" ], "details": "In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-263783702References: N/A", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-phhq-j3pr-xv78/GHSA-phhq-j3pr-xv78.json b/advisories/unreviewed/2023/06/GHSA-phhq-j3pr-xv78/GHSA-phhq-j3pr-xv78.json index 851f0a6d222..652391ab9a2 100644 --- a/advisories/unreviewed/2023/06/GHSA-phhq-j3pr-xv78/GHSA-phhq-j3pr-xv78.json +++ b/advisories/unreviewed/2023/06/GHSA-phhq-j3pr-xv78/GHSA-phhq-j3pr-xv78.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-phhq-j3pr-xv78", - "modified": "2023-06-28T18:30:26Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:26Z", "aliases": [ "CVE-2023-21211" ], "details": "In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235998", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-r74p-fm7h-v58h/GHSA-r74p-fm7h-v58h.json b/advisories/unreviewed/2023/06/GHSA-r74p-fm7h-v58h/GHSA-r74p-fm7h-v58h.json index fca88d4c450..63b0cda21e7 100644 --- a/advisories/unreviewed/2023/06/GHSA-r74p-fm7h-v58h/GHSA-r74p-fm7h-v58h.json +++ b/advisories/unreviewed/2023/06/GHSA-r74p-fm7h-v58h/GHSA-r74p-fm7h-v58h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r74p-fm7h-v58h", - "modified": "2023-06-28T18:30:26Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:26Z", "aliases": [ "CVE-2023-21180" ], "details": "In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261365944", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-x5v3-9hgf-599q/GHSA-x5v3-9hgf-599q.json b/advisories/unreviewed/2023/06/GHSA-x5v3-9hgf-599q/GHSA-x5v3-9hgf-599q.json index d97607f6fd4..07374a5b6fd 100644 --- a/advisories/unreviewed/2023/06/GHSA-x5v3-9hgf-599q/GHSA-x5v3-9hgf-599q.json +++ b/advisories/unreviewed/2023/06/GHSA-x5v3-9hgf-599q/GHSA-x5v3-9hgf-599q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5v3-9hgf-599q", - "modified": "2023-06-27T06:30:43Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-27T06:30:43Z", "aliases": [ "CVE-2023-3411" diff --git a/advisories/unreviewed/2023/06/GHSA-xwcr-4pfv-3qm8/GHSA-xwcr-4pfv-3qm8.json b/advisories/unreviewed/2023/06/GHSA-xwcr-4pfv-3qm8/GHSA-xwcr-4pfv-3qm8.json index 9af82619dc1..9c39753ced6 100644 --- a/advisories/unreviewed/2023/06/GHSA-xwcr-4pfv-3qm8/GHSA-xwcr-4pfv-3qm8.json +++ b/advisories/unreviewed/2023/06/GHSA-xwcr-4pfv-3qm8/GHSA-xwcr-4pfv-3qm8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwcr-4pfv-3qm8", - "modified": "2023-06-28T18:30:26Z", + "modified": "2023-07-06T03:30:43Z", "published": "2023-06-28T18:30:26Z", "aliases": [ "CVE-2023-21182" ], "details": "In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252764175", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-2jjp-c35x-v2v9/GHSA-2jjp-c35x-v2v9.json b/advisories/unreviewed/2023/07/GHSA-2jjp-c35x-v2v9/GHSA-2jjp-c35x-v2v9.json new file mode 100644 index 00000000000..048620da595 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2jjp-c35x-v2v9/GHSA-2jjp-c35x-v2v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jjp-c35x-v2v9", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30670" + ], + "details": "Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30670" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2xph-w2r8-f9pw/GHSA-2xph-w2r8-f9pw.json b/advisories/unreviewed/2023/07/GHSA-2xph-w2r8-f9pw/GHSA-2xph-w2r8-f9pw.json new file mode 100644 index 00000000000..43c7c702021 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2xph-w2r8-f9pw/GHSA-2xph-w2r8-f9pw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xph-w2r8-f9pw", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30642" + ], + "details": "Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30642" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-36wc-2jgf-p9gp/GHSA-36wc-2jgf-p9gp.json b/advisories/unreviewed/2023/07/GHSA-36wc-2jgf-p9gp/GHSA-36wc-2jgf-p9gp.json new file mode 100644 index 00000000000..3eb4ca31f91 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-36wc-2jgf-p9gp/GHSA-36wc-2jgf-p9gp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36wc-2jgf-p9gp", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30677" + ], + "details": "Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30677" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-48cv-xv53-cgjf/GHSA-48cv-xv53-cgjf.json b/advisories/unreviewed/2023/07/GHSA-48cv-xv53-cgjf/GHSA-48cv-xv53-cgjf.json new file mode 100644 index 00000000000..52a5c41ce0e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-48cv-xv53-cgjf/GHSA-48cv-xv53-cgjf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48cv-xv53-cgjf", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30673" + ], + "details": "Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30673" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-354" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-49vx-vwj9-q95m/GHSA-49vx-vwj9-q95m.json b/advisories/unreviewed/2023/07/GHSA-49vx-vwj9-q95m/GHSA-49vx-vwj9-q95m.json new file mode 100644 index 00000000000..f134befc435 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-49vx-vwj9-q95m/GHSA-49vx-vwj9-q95m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49vx-vwj9-q95m", + "modified": "2023-07-06T03:30:43Z", + "published": "2023-07-06T03:30:43Z", + "aliases": [ + "CVE-2023-24256" + ], + "details": "An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24256" + }, + { + "type": "WEB", + "url": "https://github.com/hhj4ck/JailBreakEC6/blob/main/BugReport.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4c89-hmqm-65h7/GHSA-4c89-hmqm-65h7.json b/advisories/unreviewed/2023/07/GHSA-4c89-hmqm-65h7/GHSA-4c89-hmqm-65h7.json new file mode 100644 index 00000000000..bb4ea6ccd42 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4c89-hmqm-65h7/GHSA-4c89-hmqm-65h7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c89-hmqm-65h7", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30672" + ], + "details": "Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30672" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4h27-fj22-482r/GHSA-4h27-fj22-482r.json b/advisories/unreviewed/2023/07/GHSA-4h27-fj22-482r/GHSA-4h27-fj22-482r.json new file mode 100644 index 00000000000..67e8c1d7a7b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4h27-fj22-482r/GHSA-4h27-fj22-482r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h27-fj22-482r", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30661" + ], + "details": "Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30661" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5jxc-mmv9-x77x/GHSA-5jxc-mmv9-x77x.json b/advisories/unreviewed/2023/07/GHSA-5jxc-mmv9-x77x/GHSA-5jxc-mmv9-x77x.json new file mode 100644 index 00000000000..d2db06a4340 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5jxc-mmv9-x77x/GHSA-5jxc-mmv9-x77x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jxc-mmv9-x77x", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30645" + ], + "details": "Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30645" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6g4h-q5wf-4cv7/GHSA-6g4h-q5wf-4cv7.json b/advisories/unreviewed/2023/07/GHSA-6g4h-q5wf-4cv7/GHSA-6g4h-q5wf-4cv7.json new file mode 100644 index 00000000000..9bbfdda9de1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6g4h-q5wf-4cv7/GHSA-6g4h-q5wf-4cv7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g4h-q5wf-4cv7", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30666" + ], + "details": "Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30666" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6p4h-xvj3-j477/GHSA-6p4h-xvj3-j477.json b/advisories/unreviewed/2023/07/GHSA-6p4h-xvj3-j477/GHSA-6p4h-xvj3-j477.json new file mode 100644 index 00000000000..f462a54f161 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6p4h-xvj3-j477/GHSA-6p4h-xvj3-j477.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p4h-xvj3-j477", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30678" + ], + "details": "Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30678" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-83q5-ph4f-qx3w/GHSA-83q5-ph4f-qx3w.json b/advisories/unreviewed/2023/07/GHSA-83q5-ph4f-qx3w/GHSA-83q5-ph4f-qx3w.json new file mode 100644 index 00000000000..5604e4f8492 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-83q5-ph4f-qx3w/GHSA-83q5-ph4f-qx3w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83q5-ph4f-qx3w", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-29656" + ], + "details": "An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control \"antigena\" actions(block/unblock traffic) from the mobile application. This vulnerability could create a \"shutdown\", blocking all ingress or egress traffic in the entire infrastructure where darktrace agents are deployed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29656" + }, + { + "type": "WEB", + "url": "https://darktrace.com" + }, + { + "type": "WEB", + "url": "https://ramihub.github.io/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8hgr-jwwc-6m87/GHSA-8hgr-jwwc-6m87.json b/advisories/unreviewed/2023/07/GHSA-8hgr-jwwc-6m87/GHSA-8hgr-jwwc-6m87.json new file mode 100644 index 00000000000..409a899d046 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8hgr-jwwc-6m87/GHSA-8hgr-jwwc-6m87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hgr-jwwc-6m87", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30650" + ], + "details": "Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30650" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8xqj-8wq5-jx5x/GHSA-8xqj-8wq5-jx5x.json b/advisories/unreviewed/2023/07/GHSA-8xqj-8wq5-jx5x/GHSA-8xqj-8wq5-jx5x.json new file mode 100644 index 00000000000..08a8cbe74f5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8xqj-8wq5-jx5x/GHSA-8xqj-8wq5-jx5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xqj-8wq5-jx5x", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30651" + ], + "details": "Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30651" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-93v2-v964-8v32/GHSA-93v2-v964-8v32.json b/advisories/unreviewed/2023/07/GHSA-93v2-v964-8v32/GHSA-93v2-v964-8v32.json new file mode 100644 index 00000000000..450585d9c47 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-93v2-v964-8v32/GHSA-93v2-v964-8v32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93v2-v964-8v32", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30644" + ], + "details": "Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30644" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9r79-345x-hmrj/GHSA-9r79-345x-hmrj.json b/advisories/unreviewed/2023/07/GHSA-9r79-345x-hmrj/GHSA-9r79-345x-hmrj.json new file mode 100644 index 00000000000..124fa8c4b58 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9r79-345x-hmrj/GHSA-9r79-345x-hmrj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r79-345x-hmrj", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30656" + ], + "details": "Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30656" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c55m-42jr-9f58/GHSA-c55m-42jr-9f58.json b/advisories/unreviewed/2023/07/GHSA-c55m-42jr-9f58/GHSA-c55m-42jr-9f58.json new file mode 100644 index 00000000000..8149d01d944 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c55m-42jr-9f58/GHSA-c55m-42jr-9f58.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c55m-42jr-9f58", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30665" + ], + "details": "Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30665" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c9gx-wmcv-6c99/GHSA-c9gx-wmcv-6c99.json b/advisories/unreviewed/2023/07/GHSA-c9gx-wmcv-6c99/GHSA-c9gx-wmcv-6c99.json new file mode 100644 index 00000000000..08ef9ae2085 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c9gx-wmcv-6c99/GHSA-c9gx-wmcv-6c99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9gx-wmcv-6c99", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30648" + ], + "details": "Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30648" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cpj5-6hc9-4243/GHSA-cpj5-6hc9-4243.json b/advisories/unreviewed/2023/07/GHSA-cpj5-6hc9-4243/GHSA-cpj5-6hc9-4243.json new file mode 100644 index 00000000000..55aff3bd163 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cpj5-6hc9-4243/GHSA-cpj5-6hc9-4243.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpj5-6hc9-4243", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30647" + ], + "details": "Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30647" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f2hf-p7mp-7x9v/GHSA-f2hf-p7mp-7x9v.json b/advisories/unreviewed/2023/07/GHSA-f2hf-p7mp-7x9v/GHSA-f2hf-p7mp-7x9v.json new file mode 100644 index 00000000000..431f7cba703 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f2hf-p7mp-7x9v/GHSA-f2hf-p7mp-7x9v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2hf-p7mp-7x9v", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-3521" + ], + "details": "Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3521" + }, + { + "type": "WEB", + "url": "https://github.com/fossbilling/fossbilling/commit/5eb516d4ebcb764db1b2edf9c8d0539e76ebde52" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/76a3441d-7f75-4a8d-a7a0-95a7f5456eb0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f2jq-xx6w-7wgv/GHSA-f2jq-xx6w-7wgv.json b/advisories/unreviewed/2023/07/GHSA-f2jq-xx6w-7wgv/GHSA-f2jq-xx6w-7wgv.json new file mode 100644 index 00000000000..0df6ce1859a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f2jq-xx6w-7wgv/GHSA-f2jq-xx6w-7wgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2jq-xx6w-7wgv", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30655" + ], + "details": "Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30655" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f995-m52f-mjhx/GHSA-f995-m52f-mjhx.json b/advisories/unreviewed/2023/07/GHSA-f995-m52f-mjhx/GHSA-f995-m52f-mjhx.json new file mode 100644 index 00000000000..b89819796be --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f995-m52f-mjhx/GHSA-f995-m52f-mjhx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f995-m52f-mjhx", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30653" + ], + "details": "Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30653" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f9fp-mv38-gcjq/GHSA-f9fp-mv38-gcjq.json b/advisories/unreviewed/2023/07/GHSA-f9fp-mv38-gcjq/GHSA-f9fp-mv38-gcjq.json new file mode 100644 index 00000000000..de6f86192cb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f9fp-mv38-gcjq/GHSA-f9fp-mv38-gcjq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9fp-mv38-gcjq", + "modified": "2023-07-06T03:30:43Z", + "published": "2023-07-06T03:30:43Z", + "aliases": [ + "CVE-2022-46080" + ], + "details": "Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46080" + }, + { + "type": "WEB", + "url": "https://github.com/yerodin/CVE-2022-46080" + }, + { + "type": "WEB", + "url": "https://nexxtsolutions.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fcmh-mv68-957w/GHSA-fcmh-mv68-957w.json b/advisories/unreviewed/2023/07/GHSA-fcmh-mv68-957w/GHSA-fcmh-mv68-957w.json new file mode 100644 index 00000000000..488bdabfa00 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fcmh-mv68-957w/GHSA-fcmh-mv68-957w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcmh-mv68-957w", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30658" + ], + "details": "Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30658" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fgh3-6cc5-g9mv/GHSA-fgh3-6cc5-g9mv.json b/advisories/unreviewed/2023/07/GHSA-fgh3-6cc5-g9mv/GHSA-fgh3-6cc5-g9mv.json new file mode 100644 index 00000000000..c829a09b302 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fgh3-6cc5-g9mv/GHSA-fgh3-6cc5-g9mv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgh3-6cc5-g9mv", + "modified": "2023-07-06T03:30:43Z", + "published": "2023-07-06T03:30:43Z", + "aliases": [ + "CVE-2023-3520" + ], + "details": "Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3520" + }, + { + "type": "WEB", + "url": "https://github.com/it-novum/openitcockpit/commit/6c717f3c352e55257fc3fef2c5dec111f7d2ee6b" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/f3b277bb-91db-419e-bcc4-fe0b055d2551" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-614" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gc2m-85qp-g4q2/GHSA-gc2m-85qp-g4q2.json b/advisories/unreviewed/2023/07/GHSA-gc2m-85qp-g4q2/GHSA-gc2m-85qp-g4q2.json new file mode 100644 index 00000000000..4d1d93fe284 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gc2m-85qp-g4q2/GHSA-gc2m-85qp-g4q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc2m-85qp-g4q2", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30662" + ], + "details": "Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30662" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gqcm-hxx4-3hrp/GHSA-gqcm-hxx4-3hrp.json b/advisories/unreviewed/2023/07/GHSA-gqcm-hxx4-3hrp/GHSA-gqcm-hxx4-3hrp.json new file mode 100644 index 00000000000..2e3468d80e3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gqcm-hxx4-3hrp/GHSA-gqcm-hxx4-3hrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqcm-hxx4-3hrp", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30664" + ], + "details": "Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30664" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gqq5-v4cw-9926/GHSA-gqq5-v4cw-9926.json b/advisories/unreviewed/2023/07/GHSA-gqq5-v4cw-9926/GHSA-gqq5-v4cw-9926.json new file mode 100644 index 00000000000..d8fb3aa8dd5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gqq5-v4cw-9926/GHSA-gqq5-v4cw-9926.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqq5-v4cw-9926", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30674" + ], + "details": "Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30674" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1275" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h9j7-xfpf-9qqc/GHSA-h9j7-xfpf-9qqc.json b/advisories/unreviewed/2023/07/GHSA-h9j7-xfpf-9qqc/GHSA-h9j7-xfpf-9qqc.json new file mode 100644 index 00000000000..9b6a2f1fe83 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h9j7-xfpf-9qqc/GHSA-h9j7-xfpf-9qqc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9j7-xfpf-9qqc", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30646" + ], + "details": "Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30646" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hgq6-hc58-6h88/GHSA-hgq6-hc58-6h88.json b/advisories/unreviewed/2023/07/GHSA-hgq6-hc58-6h88/GHSA-hgq6-hc58-6h88.json new file mode 100644 index 00000000000..e5a54de1b5b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hgq6-hc58-6h88/GHSA-hgq6-hc58-6h88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgq6-hc58-6h88", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30659" + ], + "details": "Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30659" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j5fh-8vfx-pf9m/GHSA-j5fh-8vfx-pf9m.json b/advisories/unreviewed/2023/07/GHSA-j5fh-8vfx-pf9m/GHSA-j5fh-8vfx-pf9m.json new file mode 100644 index 00000000000..12ec1974363 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j5fh-8vfx-pf9m/GHSA-j5fh-8vfx-pf9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5fh-8vfx-pf9m", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30676" + ], + "details": "Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30676" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jrxr-fwjr-rghr/GHSA-jrxr-fwjr-rghr.json b/advisories/unreviewed/2023/07/GHSA-jrxr-fwjr-rghr/GHSA-jrxr-fwjr-rghr.json new file mode 100644 index 00000000000..f1f25e60491 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jrxr-fwjr-rghr/GHSA-jrxr-fwjr-rghr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrxr-fwjr-rghr", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30660" + ], + "details": "Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30660" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mjxq-qjq6-94vh/GHSA-mjxq-qjq6-94vh.json b/advisories/unreviewed/2023/07/GHSA-mjxq-qjq6-94vh/GHSA-mjxq-qjq6-94vh.json new file mode 100644 index 00000000000..bf6773d629a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mjxq-qjq6-94vh/GHSA-mjxq-qjq6-94vh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjxq-qjq6-94vh", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30667" + ], + "details": "Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30667" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mwv4-686j-f844/GHSA-mwv4-686j-f844.json b/advisories/unreviewed/2023/07/GHSA-mwv4-686j-f844/GHSA-mwv4-686j-f844.json new file mode 100644 index 00000000000..7b608d23ed9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mwv4-686j-f844/GHSA-mwv4-686j-f844.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwv4-686j-f844", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30668" + ], + "details": "Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30668" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pgwp-hxrw-pr48/GHSA-pgwp-hxrw-pr48.json b/advisories/unreviewed/2023/07/GHSA-pgwp-hxrw-pr48/GHSA-pgwp-hxrw-pr48.json new file mode 100644 index 00000000000..a61063cafbb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pgwp-hxrw-pr48/GHSA-pgwp-hxrw-pr48.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgwp-hxrw-pr48", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30641" + ], + "details": "Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30641" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-phgv-c466-pqj8/GHSA-phgv-c466-pqj8.json b/advisories/unreviewed/2023/07/GHSA-phgv-c466-pqj8/GHSA-phgv-c466-pqj8.json new file mode 100644 index 00000000000..4b73de940f1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-phgv-c466-pqj8/GHSA-phgv-c466-pqj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phgv-c466-pqj8", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30669" + ], + "details": "Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30669" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-phv9-h86h-pf49/GHSA-phv9-h86h-pf49.json b/advisories/unreviewed/2023/07/GHSA-phv9-h86h-pf49/GHSA-phv9-h86h-pf49.json new file mode 100644 index 00000000000..48e7facc0ce --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-phv9-h86h-pf49/GHSA-phv9-h86h-pf49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phv9-h86h-pf49", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30671" + ], + "details": "Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30671" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qm74-hw29-p8vj/GHSA-qm74-hw29-p8vj.json b/advisories/unreviewed/2023/07/GHSA-qm74-hw29-p8vj/GHSA-qm74-hw29-p8vj.json new file mode 100644 index 00000000000..c01c8889e41 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qm74-hw29-p8vj/GHSA-qm74-hw29-p8vj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm74-hw29-p8vj", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30657" + ], + "details": "Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30657" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qrr4-p6rr-3pjr/GHSA-qrr4-p6rr-3pjr.json b/advisories/unreviewed/2023/07/GHSA-qrr4-p6rr-3pjr/GHSA-qrr4-p6rr-3pjr.json new file mode 100644 index 00000000000..892daaa3c11 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qrr4-p6rr-3pjr/GHSA-qrr4-p6rr-3pjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrr4-p6rr-3pjr", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30649" + ], + "details": "Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30649" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rc7j-3cmg-8cww/GHSA-rc7j-3cmg-8cww.json b/advisories/unreviewed/2023/07/GHSA-rc7j-3cmg-8cww/GHSA-rc7j-3cmg-8cww.json new file mode 100644 index 00000000000..10966b41f9f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rc7j-3cmg-8cww/GHSA-rc7j-3cmg-8cww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc7j-3cmg-8cww", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30652" + ], + "details": "Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30652" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rq9c-g2c8-gm2q/GHSA-rq9c-g2c8-gm2q.json b/advisories/unreviewed/2023/07/GHSA-rq9c-g2c8-gm2q/GHSA-rq9c-g2c8-gm2q.json new file mode 100644 index 00000000000..56c275533d9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rq9c-g2c8-gm2q/GHSA-rq9c-g2c8-gm2q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq9c-g2c8-gm2q", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30640" + ], + "details": "Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30640" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vgxr-5gfw-xp36/GHSA-vgxr-5gfw-xp36.json b/advisories/unreviewed/2023/07/GHSA-vgxr-5gfw-xp36/GHSA-vgxr-5gfw-xp36.json new file mode 100644 index 00000000000..4387c2d0886 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vgxr-5gfw-xp36/GHSA-vgxr-5gfw-xp36.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgxr-5gfw-xp36", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30675" + ], + "details": "Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30675" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w6m8-3jxg-4g55/GHSA-w6m8-3jxg-4g55.json b/advisories/unreviewed/2023/07/GHSA-w6m8-3jxg-4g55/GHSA-w6m8-3jxg-4g55.json new file mode 100644 index 00000000000..5a4825c3292 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w6m8-3jxg-4g55/GHSA-w6m8-3jxg-4g55.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6m8-3jxg-4g55", + "modified": "2023-07-06T03:30:43Z", + "published": "2023-07-06T03:30:43Z", + "aliases": [ + "CVE-2023-27225" + ], + "details": "A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27225" + }, + { + "type": "WEB", + "url": "https://medium.com/@ridheshgohil1092/my-first-cve-2023-27225-f232650f6cde" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wc2x-c474-wcwr/GHSA-wc2x-c474-wcwr.json b/advisories/unreviewed/2023/07/GHSA-wc2x-c474-wcwr/GHSA-wc2x-c474-wcwr.json new file mode 100644 index 00000000000..db053f09fb8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wc2x-c474-wcwr/GHSA-wc2x-c474-wcwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc2x-c474-wcwr", + "modified": "2023-07-06T03:30:45Z", + "published": "2023-07-06T03:30:45Z", + "aliases": [ + "CVE-2023-30663" + ], + "details": "Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30663" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x7r6-hgxq-528p/GHSA-x7r6-hgxq-528p.json b/advisories/unreviewed/2023/07/GHSA-x7r6-hgxq-528p/GHSA-x7r6-hgxq-528p.json new file mode 100644 index 00000000000..96b3b77d5ac --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x7r6-hgxq-528p/GHSA-x7r6-hgxq-528p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7r6-hgxq-528p", + "modified": "2023-07-06T03:30:44Z", + "published": "2023-07-06T03:30:44Z", + "aliases": [ + "CVE-2023-30643" + ], + "details": "Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30643" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file