diff --git a/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json b/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json index 970e5b7d63b..ac042d49569 100644 --- a/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json +++ b/advisories/unreviewed/2022/11/GHSA-q7gf-qq2r-mhhf/GHSA-q7gf-qq2r-mhhf.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://gitee.com/isoftforce/dreamer_cms/issues/I5U408" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/171585/Dreamer-CMS-4.0.0-SQL-Injection.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-2968-fmvc-r6gw/GHSA-2968-fmvc-r6gw.json b/advisories/unreviewed/2023/04/GHSA-2968-fmvc-r6gw/GHSA-2968-fmvc-r6gw.json index a7b6b13f6d5..c598a47b388 100644 --- a/advisories/unreviewed/2023/04/GHSA-2968-fmvc-r6gw/GHSA-2968-fmvc-r6gw.json +++ b/advisories/unreviewed/2023/04/GHSA-2968-fmvc-r6gw/GHSA-2968-fmvc-r6gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2968-fmvc-r6gw", - "modified": "2023-04-14T03:30:28Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T03:30:28Z", "aliases": [ "CVE-2023-1285" ], "details": "Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are \"16\" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362", + "CWE-364" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-2cvf-r7fr-6p6p/GHSA-2cvf-r7fr-6p6p.json b/advisories/unreviewed/2023/04/GHSA-2cvf-r7fr-6p6p/GHSA-2cvf-r7fr-6p6p.json new file mode 100644 index 00000000000..8a3ee6353cc --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-2cvf-r7fr-6p6p/GHSA-2cvf-r7fr-6p6p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cvf-r7fr-6p6p", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-30371" + ], + "details": "In Tenda AC15 V15.03.05.19, the function \"sub_ED14\" contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30371" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/4.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-3vvp-9ghf-fqvw/GHSA-3vvp-9ghf-fqvw.json b/advisories/unreviewed/2023/04/GHSA-3vvp-9ghf-fqvw/GHSA-3vvp-9ghf-fqvw.json index ffea016bb92..bd81ba846c4 100644 --- a/advisories/unreviewed/2023/04/GHSA-3vvp-9ghf-fqvw/GHSA-3vvp-9ghf-fqvw.json +++ b/advisories/unreviewed/2023/04/GHSA-3vvp-9ghf-fqvw/GHSA-3vvp-9ghf-fqvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vvp-9ghf-fqvw", - "modified": "2023-04-11T21:31:01Z", + "modified": "2023-04-24T15:30:27Z", "published": "2023-04-11T21:31:01Z", "aliases": [ "CVE-2023-26555" ], "details": "praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-44r5-q922-2rc3/GHSA-44r5-q922-2rc3.json b/advisories/unreviewed/2023/04/GHSA-44r5-q922-2rc3/GHSA-44r5-q922-2rc3.json new file mode 100644 index 00000000000..4d894bfa9f1 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-44r5-q922-2rc3/GHSA-44r5-q922-2rc3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44r5-q922-2rc3", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-29848" + ], + "details": "Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29848" + }, + { + "type": "WEB", + "url": "https://github.com/mesinkasir/bangresto/issues/2" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171899/Bang-Resto-1.0-Cross-Site-Scripting.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-47mh-6hjv-3484/GHSA-47mh-6hjv-3484.json b/advisories/unreviewed/2023/04/GHSA-47mh-6hjv-3484/GHSA-47mh-6hjv-3484.json new file mode 100644 index 00000000000..85f05a12154 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-47mh-6hjv-3484/GHSA-47mh-6hjv-3484.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47mh-6hjv-3484", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-30372" + ], + "details": "In Tenda AC15 V15.03.05.19, The function \"xkjs_ver32\" contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30372" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/10.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-747c-jg37-7m9c/GHSA-747c-jg37-7m9c.json b/advisories/unreviewed/2023/04/GHSA-747c-jg37-7m9c/GHSA-747c-jg37-7m9c.json new file mode 100644 index 00000000000..05a2f3d9a25 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-747c-jg37-7m9c/GHSA-747c-jg37-7m9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-747c-jg37-7m9c", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2022-48477" + ], + "details": "In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48477" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-767v-xrqh-x67m/GHSA-767v-xrqh-x67m.json b/advisories/unreviewed/2023/04/GHSA-767v-xrqh-x67m/GHSA-767v-xrqh-x67m.json index 1c12a05bd45..bc37c008e01 100644 --- a/advisories/unreviewed/2023/04/GHSA-767v-xrqh-x67m/GHSA-767v-xrqh-x67m.json +++ b/advisories/unreviewed/2023/04/GHSA-767v-xrqh-x67m/GHSA-767v-xrqh-x67m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-767v-xrqh-x67m", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2022-40532" ], "details": "Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-78m2-q358-37wh/GHSA-78m2-q358-37wh.json b/advisories/unreviewed/2023/04/GHSA-78m2-q358-37wh/GHSA-78m2-q358-37wh.json index 8cc180d13d7..1a9616028f3 100644 --- a/advisories/unreviewed/2023/04/GHSA-78m2-q358-37wh/GHSA-78m2-q358-37wh.json +++ b/advisories/unreviewed/2023/04/GHSA-78m2-q358-37wh/GHSA-78m2-q358-37wh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-78m2-q358-37wh", - "modified": "2023-04-11T21:30:57Z", + "modified": "2023-04-24T15:30:27Z", "published": "2023-04-11T21:30:57Z", "aliases": [ "CVE-2023-28808" ], "details": "Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-7j3x-mrc3-42pg/GHSA-7j3x-mrc3-42pg.json b/advisories/unreviewed/2023/04/GHSA-7j3x-mrc3-42pg/GHSA-7j3x-mrc3-42pg.json new file mode 100644 index 00000000000..1cd8a1aadb5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-7j3x-mrc3-42pg/GHSA-7j3x-mrc3-42pg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j3x-mrc3-42pg", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-1731" + ], + "details": "In LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1731" + }, + { + "type": "WEB", + "url": "https://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-2023-02-lantime-firmware-v7-06-013.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json b/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json index 7741a3fd509..443585dd560 100644 --- a/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json +++ b/advisories/unreviewed/2023/04/GHSA-83w8-56qx-9vq7/GHSA-83w8-56qx-9vq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-83w8-56qx-9vq7", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29090" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Via header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-9hjw-9cqg-v7h7/GHSA-9hjw-9cqg-v7h7.json b/advisories/unreviewed/2023/04/GHSA-9hjw-9cqg-v7h7/GHSA-9hjw-9cqg-v7h7.json new file mode 100644 index 00000000000..ee28800b06f --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-9hjw-9cqg-v7h7/GHSA-9hjw-9cqg-v7h7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hjw-9cqg-v7h7", + "modified": "2023-04-24T15:30:35Z", + "published": "2023-04-24T15:30:35Z", + "aliases": [ + "CVE-2023-30375" + ], + "details": "In Tenda AC15 V15.03.05.19, the function \"getIfIp\" contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30375" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-9rj4-9hjf-7pcg/GHSA-9rj4-9hjf-7pcg.json b/advisories/unreviewed/2023/04/GHSA-9rj4-9hjf-7pcg/GHSA-9rj4-9hjf-7pcg.json new file mode 100644 index 00000000000..ee1f39f712e --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-9rj4-9hjf-7pcg/GHSA-9rj4-9hjf-7pcg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rj4-9hjf-7pcg", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-29579" + ], + "details": "yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29579" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/214" + }, + { + "type": "WEB", + "url": "https://github.com/z1r00/fuzz_vuln/blob/main/yasm/stack-buffer-overflow/yasm/readmd.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json b/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json index d3fa9de537e..44f562f76b4 100644 --- a/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json +++ b/advisories/unreviewed/2023/04/GHSA-9w4w-2cpw-g65c/GHSA-9w4w-2cpw-g65c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w4w-2cpw-g65c", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29089" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding SIP multipart messages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-cw85-fvjr-j5xv/GHSA-cw85-fvjr-j5xv.json b/advisories/unreviewed/2023/04/GHSA-cw85-fvjr-j5xv/GHSA-cw85-fvjr-j5xv.json index 505db5315cd..0ed4a824e8b 100644 --- a/advisories/unreviewed/2023/04/GHSA-cw85-fvjr-j5xv/GHSA-cw85-fvjr-j5xv.json +++ b/advisories/unreviewed/2023/04/GHSA-cw85-fvjr-j5xv/GHSA-cw85-fvjr-j5xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cw85-fvjr-j5xv", - "modified": "2023-04-13T21:30:27Z", + "modified": "2023-04-24T15:30:28Z", "published": "2023-04-13T21:30:27Z", "aliases": [ "CVE-2023-22951" ], "details": "An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-cxvw-qhc5-36vm/GHSA-cxvw-qhc5-36vm.json b/advisories/unreviewed/2023/04/GHSA-cxvw-qhc5-36vm/GHSA-cxvw-qhc5-36vm.json new file mode 100644 index 00000000000..9af9acb8c43 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-cxvw-qhc5-36vm/GHSA-cxvw-qhc5-36vm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxvw-qhc5-36vm", + "modified": "2023-04-24T15:30:35Z", + "published": "2023-04-24T15:30:35Z", + "aliases": [ + "CVE-2023-30378" + ], + "details": "In Tenda AC15 V15.03.05.19, the function \"sub_8EE8\" contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30378" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/5.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-f9xv-q969-pqx4/GHSA-f9xv-q969-pqx4.json b/advisories/unreviewed/2023/04/GHSA-f9xv-q969-pqx4/GHSA-f9xv-q969-pqx4.json new file mode 100644 index 00000000000..a4c94825010 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-f9xv-q969-pqx4/GHSA-f9xv-q969-pqx4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9xv-q969-pqx4", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-2251" + ], + "details": "Uncaught Exception in GitHub repository eemeli/yaml prior to 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2251" + }, + { + "type": "WEB", + "url": "https://github.com/eemeli/yaml/commit/984f5781ffd807e58cad3b5c8da1f940dab75fba" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/4b494e99-5a3e-40d9-8678-277f3060e96c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-fh2p-qw35-q7r4/GHSA-fh2p-qw35-q7r4.json b/advisories/unreviewed/2023/04/GHSA-fh2p-qw35-q7r4/GHSA-fh2p-qw35-q7r4.json index a79e3397c44..7f5558d8e55 100644 --- a/advisories/unreviewed/2023/04/GHSA-fh2p-qw35-q7r4/GHSA-fh2p-qw35-q7r4.json +++ b/advisories/unreviewed/2023/04/GHSA-fh2p-qw35-q7r4/GHSA-fh2p-qw35-q7r4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh2p-qw35-q7r4", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T15:30:27Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-33291" ], "details": "Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json b/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json index 2d0b096ea43..52aa89bee40 100644 --- a/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json +++ b/advisories/unreviewed/2023/04/GHSA-fmcm-3vcv-q39p/GHSA-fmcm-3vcv-q39p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fmcm-3vcv-q39p", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29091" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json b/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json index da5384fb0b9..ce0a0059ec5 100644 --- a/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json +++ b/advisories/unreviewed/2023/04/GHSA-fpx6-4jxg-6422/GHSA-fpx6-4jxg-6422.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpx6-4jxg-6422", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29087" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Retry-After header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-fxv6-3hhp-7g5f/GHSA-fxv6-3hhp-7g5f.json b/advisories/unreviewed/2023/04/GHSA-fxv6-3hhp-7g5f/GHSA-fxv6-3hhp-7g5f.json new file mode 100644 index 00000000000..b5436088924 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-fxv6-3hhp-7g5f/GHSA-fxv6-3hhp-7g5f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxv6-3hhp-7g5f", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-30369" + ], + "details": "Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30369" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/3.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json b/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json index f19e3e2a50c..35f8b0e1b42 100644 --- a/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json +++ b/advisories/unreviewed/2023/04/GHSA-h6pv-hpfp-q558/GHSA-h6pv-hpfp-q558.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6pv-hpfp-q558", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29086" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Min-SE header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-hjpj-ff6x-x57r/GHSA-hjpj-ff6x-x57r.json b/advisories/unreviewed/2023/04/GHSA-hjpj-ff6x-x57r/GHSA-hjpj-ff6x-x57r.json new file mode 100644 index 00000000000..5c04aa854bd --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-hjpj-ff6x-x57r/GHSA-hjpj-ff6x-x57r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjpj-ff6x-x57r", + "modified": "2023-04-24T15:30:35Z", + "published": "2023-04-24T15:30:35Z", + "aliases": [ + "CVE-2023-30376" + ], + "details": "In Tenda AC15 V15.03.05.19, the function \"henan_pppoe_user\" contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30376" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/9.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-j2cj-28m2-5h5j/GHSA-j2cj-28m2-5h5j.json b/advisories/unreviewed/2023/04/GHSA-j2cj-28m2-5h5j/GHSA-j2cj-28m2-5h5j.json new file mode 100644 index 00000000000..47af96a9fd5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-j2cj-28m2-5h5j/GHSA-j2cj-28m2-5h5j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2cj-28m2-5h5j", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-29582" + ], + "details": "yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29582" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/217" + }, + { + "type": "WEB", + "url": "https://github.com/z1r00/fuzz_vuln/blob/main/yasm/stack-overflow/parse_expr1/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-pw38-42w8-qm8m/GHSA-pw38-42w8-qm8m.json b/advisories/unreviewed/2023/04/GHSA-pw38-42w8-qm8m/GHSA-pw38-42w8-qm8m.json new file mode 100644 index 00000000000..c0dfcde67ee --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-pw38-42w8-qm8m/GHSA-pw38-42w8-qm8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw38-42w8-qm8m", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2022-48476" + ], + "details": "In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48476" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-qjvw-vhjr-4r9r/GHSA-qjvw-vhjr-4r9r.json b/advisories/unreviewed/2023/04/GHSA-qjvw-vhjr-4r9r/GHSA-qjvw-vhjr-4r9r.json new file mode 100644 index 00000000000..82311d9bbc5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-qjvw-vhjr-4r9r/GHSA-qjvw-vhjr-4r9r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjvw-vhjr-4r9r", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-29578" + ], + "details": "mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at src/mp4property.cpp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29578" + }, + { + "type": "WEB", + "url": "https://github.com/TechSmith/mp4v2/issues/74" + }, + { + "type": "WEB", + "url": "https://github.com/z1r00/fuzz_vuln/blob/main/mp4v2/heap-buffer-overflow/mp4property.cpp/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json b/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json new file mode 100644 index 00000000000..7b2bd125bd4 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmx9-67mw-5ghq", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-29570" + ], + "details": "Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29570" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/240" + }, + { + "type": "WEB", + "url": "https://github.com/z1r00/fuzz_vuln/blob/main/mjs/SEGV/mjs_fii2/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-r744-phrq-6w44/GHSA-r744-phrq-6w44.json b/advisories/unreviewed/2023/04/GHSA-r744-phrq-6w44/GHSA-r744-phrq-6w44.json index bc8a7228628..b1da6776031 100644 --- a/advisories/unreviewed/2023/04/GHSA-r744-phrq-6w44/GHSA-r744-phrq-6w44.json +++ b/advisories/unreviewed/2023/04/GHSA-r744-phrq-6w44/GHSA-r744-phrq-6w44.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r744-phrq-6w44", - "modified": "2023-04-13T09:30:18Z", + "modified": "2023-04-24T15:30:28Z", "published": "2023-04-13T09:30:18Z", "aliases": [ "CVE-2023-21630" ], "details": "Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-rfj4-7g32-cpqh/GHSA-rfj4-7g32-cpqh.json b/advisories/unreviewed/2023/04/GHSA-rfj4-7g32-cpqh/GHSA-rfj4-7g32-cpqh.json new file mode 100644 index 00000000000..4aa6bafd0e2 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-rfj4-7g32-cpqh/GHSA-rfj4-7g32-cpqh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfj4-7g32-cpqh", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-30373" + ], + "details": "In Tenda AC15 V15.03.05.19, the function \"xian_pppoe_user\" contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30373" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/8.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json b/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json index b9f518ca4fa..39e740eca53 100644 --- a/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json +++ b/advisories/unreviewed/2023/04/GHSA-rfpr-2mwv-6gc8/GHSA-rfpr-2mwv-6gc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfpr-2mwv-6gc8", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29085" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP status line.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-rr9h-qqwq-gm72/GHSA-rr9h-qqwq-gm72.json b/advisories/unreviewed/2023/04/GHSA-rr9h-qqwq-gm72/GHSA-rr9h-qqwq-gm72.json new file mode 100644 index 00000000000..0d7986c17fd --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-rr9h-qqwq-gm72/GHSA-rr9h-qqwq-gm72.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr9h-qqwq-gm72", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-29479" + ], + "details": "Ribose RNP before 0.16.3 may hang when the input is malformed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29479" + }, + { + "type": "WEB", + "url": "https://www.rnpgp.org/blog/2023-04-13-rnp-release-0-16-3/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-rx4q-gwv4-r27p/GHSA-rx4q-gwv4-r27p.json b/advisories/unreviewed/2023/04/GHSA-rx4q-gwv4-r27p/GHSA-rx4q-gwv4-r27p.json index a2613ef8601..8258cfaaf4b 100644 --- a/advisories/unreviewed/2023/04/GHSA-rx4q-gwv4-r27p/GHSA-rx4q-gwv4-r27p.json +++ b/advisories/unreviewed/2023/04/GHSA-rx4q-gwv4-r27p/GHSA-rx4q-gwv4-r27p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rx4q-gwv4-r27p", - "modified": "2023-04-14T03:30:29Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T03:30:29Z", "aliases": [ "CVE-2023-29132" ], "details": "Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json b/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json index d34fd95a5e8..9d47deb3dce 100644 --- a/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json +++ b/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vh2x-5rx6-qqhv", - "modified": "2023-04-14T03:30:29Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T03:30:29Z", "aliases": [ "CVE-2023-29491" ], "details": "ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-vrmf-9x5h-2hr7/GHSA-vrmf-9x5h-2hr7.json b/advisories/unreviewed/2023/04/GHSA-vrmf-9x5h-2hr7/GHSA-vrmf-9x5h-2hr7.json new file mode 100644 index 00000000000..1ede9dad1f8 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-vrmf-9x5h-2hr7/GHSA-vrmf-9x5h-2hr7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrmf-9x5h-2hr7", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-29480" + ], + "details": "Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29480" + }, + { + "type": "WEB", + "url": "https://www.rnpgp.org/blog/2023-04-13-rnp-release-0-16-3/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json b/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json index 15552220bb7..60a7263af5f 100644 --- a/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json +++ b/advisories/unreviewed/2023/04/GHSA-vvgj-r4cg-78rh/GHSA-vvgj-r4cg-78rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvgj-r4cg-78rh", - "modified": "2023-04-14T21:30:23Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T21:30:23Z", "aliases": [ "CVE-2023-29088" ], "details": "An issue was discovered in Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Session-Expires header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/04/GHSA-wg94-qv5w-pwh4/GHSA-wg94-qv5w-pwh4.json b/advisories/unreviewed/2023/04/GHSA-wg94-qv5w-pwh4/GHSA-wg94-qv5w-pwh4.json new file mode 100644 index 00000000000..acc51fe8dd9 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-wg94-qv5w-pwh4/GHSA-wg94-qv5w-pwh4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg94-qv5w-pwh4", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-30370" + ], + "details": "In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30370" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC15/7.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-whqq-vqv6-fmvc/GHSA-whqq-vqv6-fmvc.json b/advisories/unreviewed/2023/04/GHSA-whqq-vqv6-fmvc/GHSA-whqq-vqv6-fmvc.json index c09f04665b7..62db29e0ea8 100644 --- a/advisories/unreviewed/2023/04/GHSA-whqq-vqv6-fmvc/GHSA-whqq-vqv6-fmvc.json +++ b/advisories/unreviewed/2023/04/GHSA-whqq-vqv6-fmvc/GHSA-whqq-vqv6-fmvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-whqq-vqv6-fmvc", - "modified": "2023-04-14T00:31:36Z", + "modified": "2023-04-24T15:30:29Z", "published": "2023-04-14T00:31:36Z", "aliases": [ "CVE-2023-30638" ], "details": "Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-wmfr-hvpj-h75h/GHSA-wmfr-hvpj-h75h.json b/advisories/unreviewed/2023/04/GHSA-wmfr-hvpj-h75h/GHSA-wmfr-hvpj-h75h.json index b5d1a1ecad0..54647e1bfcb 100644 --- a/advisories/unreviewed/2023/04/GHSA-wmfr-hvpj-h75h/GHSA-wmfr-hvpj-h75h.json +++ b/advisories/unreviewed/2023/04/GHSA-wmfr-hvpj-h75h/GHSA-wmfr-hvpj-h75h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmfr-hvpj-h75h", - "modified": "2023-04-13T09:30:19Z", + "modified": "2023-04-24T15:30:28Z", "published": "2023-04-13T09:30:19Z", "aliases": [ "CVE-2022-33296" ], "details": "Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-wp3x-mhc9-hr54/GHSA-wp3x-mhc9-hr54.json b/advisories/unreviewed/2023/04/GHSA-wp3x-mhc9-hr54/GHSA-wp3x-mhc9-hr54.json new file mode 100644 index 00000000000..5c2497788c7 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-wp3x-mhc9-hr54/GHSA-wp3x-mhc9-hr54.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp3x-mhc9-hr54", + "modified": "2023-04-24T15:30:34Z", + "published": "2023-04-24T15:30:34Z", + "aliases": [ + "CVE-2023-29849" + ], + "details": "Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29849" + }, + { + "type": "WEB", + "url": "https://github.com/mesinkasir/bangresto/issues/3" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171900/Bang-Resto-1.0-SQL-Injection.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-x39w-h9m5-w57p/GHSA-x39w-h9m5-w57p.json b/advisories/unreviewed/2023/04/GHSA-x39w-h9m5-w57p/GHSA-x39w-h9m5-w57p.json new file mode 100644 index 00000000000..30a04f8b1e7 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-x39w-h9m5-w57p/GHSA-x39w-h9m5-w57p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x39w-h9m5-w57p", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-29583" + ], + "details": "yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29583" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/218" + }, + { + "type": "WEB", + "url": "https://github.com/z1r00/fuzz_vuln/blob/main/yasm/stack-overflow/parse_expr5/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-xqw2-xw3g-cpj5/GHSA-xqw2-xw3g-cpj5.json b/advisories/unreviewed/2023/04/GHSA-xqw2-xw3g-cpj5/GHSA-xqw2-xw3g-cpj5.json new file mode 100644 index 00000000000..acbb227d2c7 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-xqw2-xw3g-cpj5/GHSA-xqw2-xw3g-cpj5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqw2-xw3g-cpj5", + "modified": "2023-04-24T15:30:33Z", + "published": "2023-04-24T15:30:33Z", + "aliases": [ + "CVE-2023-30368" + ], + "details": "Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30368" + }, + { + "type": "WEB", + "url": "https://github.com/2205794866/Tenda/blob/main/AC5/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file