diff --git a/advisories/unreviewed/2023/12/GHSA-278h-99f9-m238/GHSA-278h-99f9-m238.json b/advisories/unreviewed/2023/12/GHSA-278h-99f9-m238/GHSA-278h-99f9-m238.json new file mode 100644 index 00000000000..d8a88ef9884 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-278h-99f9-m238/GHSA-278h-99f9-m238.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-278h-99f9-m238", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-50472" + ], + "details": "cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50472" + }, + { + "type": "WEB", + "url": "https://github.com/DaveGamble/cJSON/issues/803" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T20:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-2g42-jgwr-h29g/GHSA-2g42-jgwr-h29g.json b/advisories/unreviewed/2023/12/GHSA-2g42-jgwr-h29g/GHSA-2g42-jgwr-h29g.json index 9caa56fab5b..e3c35909987 100644 --- a/advisories/unreviewed/2023/12/GHSA-2g42-jgwr-h29g/GHSA-2g42-jgwr-h29g.json +++ b/advisories/unreviewed/2023/12/GHSA-2g42-jgwr-h29g/GHSA-2g42-jgwr-h29g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g42-jgwr-h29g", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2023-49992" ], "details": "Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T14:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-2gxf-v2x6-xmcm/GHSA-2gxf-v2x6-xmcm.json b/advisories/unreviewed/2023/12/GHSA-2gxf-v2x6-xmcm/GHSA-2gxf-v2x6-xmcm.json index ca0018750ed..77f2dad72c2 100644 --- a/advisories/unreviewed/2023/12/GHSA-2gxf-v2x6-xmcm/GHSA-2gxf-v2x6-xmcm.json +++ b/advisories/unreviewed/2023/12/GHSA-2gxf-v2x6-xmcm/GHSA-2gxf-v2x6-xmcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2gxf-v2x6-xmcm", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2023-49994" ], "details": "Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-697" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T14:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-2h32-h397-qgv2/GHSA-2h32-h397-qgv2.json b/advisories/unreviewed/2023/12/GHSA-2h32-h397-qgv2/GHSA-2h32-h397-qgv2.json index f0e9b84a252..f2fa63ab5cb 100644 --- a/advisories/unreviewed/2023/12/GHSA-2h32-h397-qgv2/GHSA-2h32-h397-qgv2.json +++ b/advisories/unreviewed/2023/12/GHSA-2h32-h397-qgv2/GHSA-2h32-h397-qgv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2h32-h397-qgv2", - "modified": "2023-12-12T15:30:59Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:59Z", "aliases": [ "CVE-2020-12614" ], "details": "An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is protected by this criteria, it can be leveraged by a malicious actor to achieve Elevation of Privileges from standard user to administrator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-478w-7mxw-36gh/GHSA-478w-7mxw-36gh.json b/advisories/unreviewed/2023/12/GHSA-478w-7mxw-36gh/GHSA-478w-7mxw-36gh.json index 1129f96604d..68cab8ac07f 100644 --- a/advisories/unreviewed/2023/12/GHSA-478w-7mxw-36gh/GHSA-478w-7mxw-36gh.json +++ b/advisories/unreviewed/2023/12/GHSA-478w-7mxw-36gh/GHSA-478w-7mxw-36gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-478w-7mxw-36gh", - "modified": "2023-12-12T09:30:33Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T09:30:33Z", "aliases": [ "CVE-2023-49809" diff --git a/advisories/unreviewed/2023/12/GHSA-47p2-p2p7-c22c/GHSA-47p2-p2p7-c22c.json b/advisories/unreviewed/2023/12/GHSA-47p2-p2p7-c22c/GHSA-47p2-p2p7-c22c.json index 2d84b59468b..8298268cbfd 100644 --- a/advisories/unreviewed/2023/12/GHSA-47p2-p2p7-c22c/GHSA-47p2-p2p7-c22c.json +++ b/advisories/unreviewed/2023/12/GHSA-47p2-p2p7-c22c/GHSA-47p2-p2p7-c22c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-4gj5-jpg2-r4vj/GHSA-4gj5-jpg2-r4vj.json b/advisories/unreviewed/2023/12/GHSA-4gj5-jpg2-r4vj/GHSA-4gj5-jpg2-r4vj.json index 7279e76d0c8..1f0bbb0d107 100644 --- a/advisories/unreviewed/2023/12/GHSA-4gj5-jpg2-r4vj/GHSA-4gj5-jpg2-r4vj.json +++ b/advisories/unreviewed/2023/12/GHSA-4gj5-jpg2-r4vj/GHSA-4gj5-jpg2-r4vj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gj5-jpg2-r4vj", - "modified": "2023-12-12T09:30:33Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T09:30:33Z", "aliases": [ "CVE-2023-6547" diff --git a/advisories/unreviewed/2023/12/GHSA-56fm-mg9v-8c3h/GHSA-56fm-mg9v-8c3h.json b/advisories/unreviewed/2023/12/GHSA-56fm-mg9v-8c3h/GHSA-56fm-mg9v-8c3h.json index 679ecfe4a50..ac988421fbc 100644 --- a/advisories/unreviewed/2023/12/GHSA-56fm-mg9v-8c3h/GHSA-56fm-mg9v-8c3h.json +++ b/advisories/unreviewed/2023/12/GHSA-56fm-mg9v-8c3h/GHSA-56fm-mg9v-8c3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56fm-mg9v-8c3h", - "modified": "2023-12-12T15:30:59Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:59Z", "aliases": [ "CVE-2023-46454" ], "details": "In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-66qm-3q49-g6g2/GHSA-66qm-3q49-g6g2.json b/advisories/unreviewed/2023/12/GHSA-66qm-3q49-g6g2/GHSA-66qm-3q49-g6g2.json index 940f5102e80..7c44868363e 100644 --- a/advisories/unreviewed/2023/12/GHSA-66qm-3q49-g6g2/GHSA-66qm-3q49-g6g2.json +++ b/advisories/unreviewed/2023/12/GHSA-66qm-3q49-g6g2/GHSA-66qm-3q49-g6g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66qm-3q49-g6g2", - "modified": "2023-12-12T09:30:32Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T09:30:32Z", "aliases": [ "CVE-2023-48642" ], "details": "Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T08:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json b/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json new file mode 100644 index 00000000000..5833b70762f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ww3-v82p-jv78", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-0248" + ], + "details": "An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.7.2 in certain circumstances can recover the reader's communication memory between the card and reader.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0248" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-02" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/cyber-solutions/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-756q-cg5p-5457/GHSA-756q-cg5p-5457.json b/advisories/unreviewed/2023/12/GHSA-756q-cg5p-5457/GHSA-756q-cg5p-5457.json new file mode 100644 index 00000000000..0a4b60ffcfe --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-756q-cg5p-5457/GHSA-756q-cg5p-5457.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-756q-cg5p-5457", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-45894" + ], + "details": "The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45894" + }, + { + "type": "WEB", + "url": "https://github.com/Oracle-Security/CVEs/blob/main/Parallels%20Remote%20Server/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T20:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7fw8-2j3x-v679/GHSA-7fw8-2j3x-v679.json b/advisories/unreviewed/2023/12/GHSA-7fw8-2j3x-v679/GHSA-7fw8-2j3x-v679.json index 57f4d5337fe..578a00f9c8f 100644 --- a/advisories/unreviewed/2023/12/GHSA-7fw8-2j3x-v679/GHSA-7fw8-2j3x-v679.json +++ b/advisories/unreviewed/2023/12/GHSA-7fw8-2j3x-v679/GHSA-7fw8-2j3x-v679.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fw8-2j3x-v679", - "modified": "2023-12-12T15:30:59Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:59Z", "aliases": [ "CVE-2020-28369" ], "details": "In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the user-writable location %WINDIR%\\Temp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json b/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json index d4c0a88a317..841aed3510f 100644 --- a/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json +++ b/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8p5h-3mcg-frjf", - "modified": "2023-12-12T15:30:59Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:59Z", "aliases": [ "CVE-2023-50495" ], "details": "NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-8q46-8c27-mjgg/GHSA-8q46-8c27-mjgg.json b/advisories/unreviewed/2023/12/GHSA-8q46-8c27-mjgg/GHSA-8q46-8c27-mjgg.json index 1d2f7feb7eb..8f1d761ed69 100644 --- a/advisories/unreviewed/2023/12/GHSA-8q46-8c27-mjgg/GHSA-8q46-8c27-mjgg.json +++ b/advisories/unreviewed/2023/12/GHSA-8q46-8c27-mjgg/GHSA-8q46-8c27-mjgg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8q46-8c27-mjgg", - "modified": "2023-12-12T12:30:51Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T12:30:51Z", "aliases": [ "CVE-2023-41963" ], "details": "Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T10:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-8x4c-6c7p-x5wp/GHSA-8x4c-6c7p-x5wp.json b/advisories/unreviewed/2023/12/GHSA-8x4c-6c7p-x5wp/GHSA-8x4c-6c7p-x5wp.json new file mode 100644 index 00000000000..35d9f526aef --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8x4c-6c7p-x5wp/GHSA-8x4c-6c7p-x5wp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x4c-6c7p-x5wp", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-50017" + ], + "details": "Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50017" + }, + { + "type": "WEB", + "url": "https://github.com/849200701/cms/blob/main/CSRF%20exists%20in%20the%20backup%20and%20restore%20location.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json b/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json new file mode 100644 index 00000000000..097d004542a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8xqf-3483-8954/GHSA-8xqf-3483-8954.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xqf-3483-8954", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-4694" + ], + "details": "Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4694" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_9823639-9823677-16/hpsbpi03894" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json b/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json index 0aae08a7ca3..703056b7ff0 100644 --- a/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json +++ b/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qvw-gvq6-g569", - "modified": "2023-12-12T12:30:53Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T12:30:53Z", "aliases": [ "CVE-2023-46281" diff --git a/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json b/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json index 12f51a706bf..6dcc000de25 100644 --- a/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json +++ b/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmr5-j3hh-jpg4", - "modified": "2023-12-12T12:30:54Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46282" diff --git a/advisories/unreviewed/2023/12/GHSA-fwfm-f7pg-rq6r/GHSA-fwfm-f7pg-rq6r.json b/advisories/unreviewed/2023/12/GHSA-fwfm-f7pg-rq6r/GHSA-fwfm-f7pg-rq6r.json index f5ad578069f..d77d4d455e1 100644 --- a/advisories/unreviewed/2023/12/GHSA-fwfm-f7pg-rq6r/GHSA-fwfm-f7pg-rq6r.json +++ b/advisories/unreviewed/2023/12/GHSA-fwfm-f7pg-rq6r/GHSA-fwfm-f7pg-rq6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwfm-f7pg-rq6r", - "modified": "2023-12-12T03:31:45Z", + "modified": "2023-12-14T21:31:13Z", "published": "2023-12-12T03:31:45Z", "aliases": [ "CVE-2023-49058" diff --git a/advisories/unreviewed/2023/12/GHSA-gcgw-q47m-prvj/GHSA-gcgw-q47m-prvj.json b/advisories/unreviewed/2023/12/GHSA-gcgw-q47m-prvj/GHSA-gcgw-q47m-prvj.json index db3d638371a..bdf0324a858 100644 --- a/advisories/unreviewed/2023/12/GHSA-gcgw-q47m-prvj/GHSA-gcgw-q47m-prvj.json +++ b/advisories/unreviewed/2023/12/GHSA-gcgw-q47m-prvj/GHSA-gcgw-q47m-prvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcgw-q47m-prvj", - "modified": "2023-12-12T09:30:31Z", + "modified": "2023-12-14T21:31:13Z", "published": "2023-12-12T03:31:45Z", "aliases": [ "CVE-2023-50422" diff --git a/advisories/unreviewed/2023/12/GHSA-hf2c-2hx8-m89f/GHSA-hf2c-2hx8-m89f.json b/advisories/unreviewed/2023/12/GHSA-hf2c-2hx8-m89f/GHSA-hf2c-2hx8-m89f.json index 64f0c8154aa..f6a1a386d0e 100644 --- a/advisories/unreviewed/2023/12/GHSA-hf2c-2hx8-m89f/GHSA-hf2c-2hx8-m89f.json +++ b/advisories/unreviewed/2023/12/GHSA-hf2c-2hx8-m89f/GHSA-hf2c-2hx8-m89f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-394" + "CWE-394", + "CWE-754" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-jc4h-wrcm-fx94/GHSA-jc4h-wrcm-fx94.json b/advisories/unreviewed/2023/12/GHSA-jc4h-wrcm-fx94/GHSA-jc4h-wrcm-fx94.json index 85921bf8bf9..d8c6df8c992 100644 --- a/advisories/unreviewed/2023/12/GHSA-jc4h-wrcm-fx94/GHSA-jc4h-wrcm-fx94.json +++ b/advisories/unreviewed/2023/12/GHSA-jc4h-wrcm-fx94/GHSA-jc4h-wrcm-fx94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc4h-wrcm-fx94", - "modified": "2023-12-12T09:30:33Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T09:30:33Z", "aliases": [ "CVE-2023-49563" ], "details": "Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T09:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jrqw-cwpm-3q7j/GHSA-jrqw-cwpm-3q7j.json b/advisories/unreviewed/2023/12/GHSA-jrqw-cwpm-3q7j/GHSA-jrqw-cwpm-3q7j.json index f4a289d9edb..8136e50be62 100644 --- a/advisories/unreviewed/2023/12/GHSA-jrqw-cwpm-3q7j/GHSA-jrqw-cwpm-3q7j.json +++ b/advisories/unreviewed/2023/12/GHSA-jrqw-cwpm-3q7j/GHSA-jrqw-cwpm-3q7j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-qh3r-8rvv-95xp/GHSA-qh3r-8rvv-95xp.json b/advisories/unreviewed/2023/12/GHSA-qh3r-8rvv-95xp/GHSA-qh3r-8rvv-95xp.json index c4a8603fcc7..0080c80edfb 100644 --- a/advisories/unreviewed/2023/12/GHSA-qh3r-8rvv-95xp/GHSA-qh3r-8rvv-95xp.json +++ b/advisories/unreviewed/2023/12/GHSA-qh3r-8rvv-95xp/GHSA-qh3r-8rvv-95xp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh3r-8rvv-95xp", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2023-49993" ], "details": "Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T14:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vc5p-mv7h-v2mx/GHSA-vc5p-mv7h-v2mx.json b/advisories/unreviewed/2023/12/GHSA-vc5p-mv7h-v2mx/GHSA-vc5p-mv7h-v2mx.json index 28a659f2c97..5be95829c81 100644 --- a/advisories/unreviewed/2023/12/GHSA-vc5p-mv7h-v2mx/GHSA-vc5p-mv7h-v2mx.json +++ b/advisories/unreviewed/2023/12/GHSA-vc5p-mv7h-v2mx/GHSA-vc5p-mv7h-v2mx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vc5p-mv7h-v2mx", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2023-49991" ], "details": "Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T14:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json b/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json index 54993ece749..b2d45e5bf7d 100644 --- a/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json +++ b/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vq7h-4q4f-453x", - "modified": "2023-12-12T15:30:59Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:59Z", "aliases": [ "CVE-2023-46455" ], "details": "In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T15:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json b/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json new file mode 100644 index 00000000000..efc4852b7b5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wchp-7c65-4hqg/GHSA-wchp-7c65-4hqg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wchp-7c65-4hqg", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-41151" + ], + "details": "An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41151" + }, + { + "type": "WEB", + "url": "https://industrial.softing.com/fileadmin/psirt/downloads/2023/syt-2023-3.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wvgw-2rwh-w596/GHSA-wvgw-2rwh-w596.json b/advisories/unreviewed/2023/12/GHSA-wvgw-2rwh-w596/GHSA-wvgw-2rwh-w596.json index 91eae849b40..3356f45db0d 100644 --- a/advisories/unreviewed/2023/12/GHSA-wvgw-2rwh-w596/GHSA-wvgw-2rwh-w596.json +++ b/advisories/unreviewed/2023/12/GHSA-wvgw-2rwh-w596/GHSA-wvgw-2rwh-w596.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvgw-2rwh-w596", - "modified": "2023-12-12T12:30:51Z", + "modified": "2023-12-14T21:31:14Z", "published": "2023-12-12T12:30:51Z", "aliases": [ "CVE-2023-49140" ], "details": "Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T10:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-x7cw-5x7j-jx35/GHSA-x7cw-5x7j-jx35.json b/advisories/unreviewed/2023/12/GHSA-x7cw-5x7j-jx35/GHSA-x7cw-5x7j-jx35.json index bb9ebada571..003188d8c0e 100644 --- a/advisories/unreviewed/2023/12/GHSA-x7cw-5x7j-jx35/GHSA-x7cw-5x7j-jx35.json +++ b/advisories/unreviewed/2023/12/GHSA-x7cw-5x7j-jx35/GHSA-x7cw-5x7j-jx35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7cw-5x7j-jx35", - "modified": "2023-12-12T15:30:58Z", + "modified": "2023-12-14T21:31:15Z", "published": "2023-12-12T15:30:58Z", "aliases": [ "CVE-2023-49990" ], "details": "Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-12T14:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-xgc4-4vwx-6v94/GHSA-xgc4-4vwx-6v94.json b/advisories/unreviewed/2023/12/GHSA-xgc4-4vwx-6v94/GHSA-xgc4-4vwx-6v94.json new file mode 100644 index 00000000000..ca85cf6243b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-xgc4-4vwx-6v94/GHSA-xgc4-4vwx-6v94.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgc4-4vwx-6v94", + "modified": "2023-12-14T21:31:16Z", + "published": "2023-12-14T21:31:16Z", + "aliases": [ + "CVE-2023-50471" + ], + "details": "cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50471" + }, + { + "type": "WEB", + "url": "https://github.com/DaveGamble/cJSON/issues/802" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-14T20:15:53Z" + } +} \ No newline at end of file