diff --git a/advisories/unreviewed/2023/07/GHSA-wmv8-5f2q-h9xg/GHSA-wmv8-5f2q-h9xg.json b/advisories/unreviewed/2023/07/GHSA-wmv8-5f2q-h9xg/GHSA-wmv8-5f2q-h9xg.json index 07701f609ae..d684f172359 100644 --- a/advisories/unreviewed/2023/07/GHSA-wmv8-5f2q-h9xg/GHSA-wmv8-5f2q-h9xg.json +++ b/advisories/unreviewed/2023/07/GHSA-wmv8-5f2q-h9xg/GHSA-wmv8-5f2q-h9xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wmv8-5f2q-h9xg", - "modified": "2023-07-11T18:31:27Z", + "modified": "2024-01-12T00:30:16Z", "published": "2023-07-11T18:31:27Z", "aliases": [ "CVE-2023-35356" @@ -32,13 +32,17 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/174118/Microsoft-Windows-Kernel-Security-Descriptor-Use-After-Free.html" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176451/Microsoft-Windows-Registry-Predefined-Keys-Privilege-Escalation.html" } ], "database_specific": { "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-11T18:15:19Z" diff --git a/advisories/unreviewed/2023/12/GHSA-2xc6-pfrf-w5p4/GHSA-2xc6-pfrf-w5p4.json b/advisories/unreviewed/2023/12/GHSA-2xc6-pfrf-w5p4/GHSA-2xc6-pfrf-w5p4.json index 54c915c2b73..7da0c5e5e6e 100644 --- a/advisories/unreviewed/2023/12/GHSA-2xc6-pfrf-w5p4/GHSA-2xc6-pfrf-w5p4.json +++ b/advisories/unreviewed/2023/12/GHSA-2xc6-pfrf-w5p4/GHSA-2xc6-pfrf-w5p4.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35633" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176451/Microsoft-Windows-Registry-Predefined-Keys-Privilege-Escalation.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-2w86-wv37-w7h5/GHSA-2w86-wv37-w7h5.json b/advisories/unreviewed/2024/01/GHSA-2w86-wv37-w7h5/GHSA-2w86-wv37-w7h5.json new file mode 100644 index 00000000000..0a356acfd21 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2w86-wv37-w7h5/GHSA-2w86-wv37-w7h5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w86-wv37-w7h5", + "modified": "2024-01-12T00:30:17Z", + "published": "2024-01-12T00:30:17Z", + "aliases": [ + "CVE-2023-51350" + ], + "details": "A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51350" + }, + { + "type": "WEB", + "url": "https://github.com/ujcms/ujcms/issues/7" + }, + { + "type": "WEB", + "url": "https://github.com/ujcms/ujcms" + }, + { + "type": "WEB", + "url": "https://www.ujcms.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5c29-2r8j-8727/GHSA-5c29-2r8j-8727.json b/advisories/unreviewed/2024/01/GHSA-5c29-2r8j-8727/GHSA-5c29-2r8j-8727.json index 431334b06df..acf02900c1e 100644 --- a/advisories/unreviewed/2024/01/GHSA-5c29-2r8j-8727/GHSA-5c29-2r8j-8727.json +++ b/advisories/unreviewed/2024/01/GHSA-5c29-2r8j-8727/GHSA-5c29-2r8j-8727.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-792w-295c-v45g/GHSA-792w-295c-v45g.json b/advisories/unreviewed/2024/01/GHSA-792w-295c-v45g/GHSA-792w-295c-v45g.json index ffc19a033fe..cc448c25c07 100644 --- a/advisories/unreviewed/2024/01/GHSA-792w-295c-v45g/GHSA-792w-295c-v45g.json +++ b/advisories/unreviewed/2024/01/GHSA-792w-295c-v45g/GHSA-792w-295c-v45g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-94xx-ww3x-xh3v/GHSA-94xx-ww3x-xh3v.json b/advisories/unreviewed/2024/01/GHSA-94xx-ww3x-xh3v/GHSA-94xx-ww3x-xh3v.json new file mode 100644 index 00000000000..a2022346a5c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-94xx-ww3x-xh3v/GHSA-94xx-ww3x-xh3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94xx-ww3x-xh3v", + "modified": "2024-01-12T00:30:16Z", + "published": "2024-01-12T00:30:16Z", + "aliases": [ + "CVE-2024-21337" + ], + "details": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21337" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21337" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T22:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json b/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json index 1bf7333519b..fb6865b0c64 100644 --- a/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json +++ b/advisories/unreviewed/2024/01/GHSA-9cw8-p5p2-35pf/GHSA-9cw8-p5p2-35pf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cw8-p5p2-35pf", - "modified": "2024-01-11T09:30:36Z", + "modified": "2024-01-12T00:30:16Z", "published": "2024-01-11T09:30:36Z", "aliases": [ "CVE-2023-6875" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e675d64c-cbb8-4f24-9b6f-2597a97b49af?source=cve" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176525/WordPress-POST-SMTP-Mailer-2.8.7-Authorization-Bypass-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-ccxm-r356-vpjv/GHSA-ccxm-r356-vpjv.json b/advisories/unreviewed/2024/01/GHSA-ccxm-r356-vpjv/GHSA-ccxm-r356-vpjv.json index 0c126e7a7db..bc0eac7467c 100644 --- a/advisories/unreviewed/2024/01/GHSA-ccxm-r356-vpjv/GHSA-ccxm-r356-vpjv.json +++ b/advisories/unreviewed/2024/01/GHSA-ccxm-r356-vpjv/GHSA-ccxm-r356-vpjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccxm-r356-vpjv", - "modified": "2024-01-09T03:30:22Z", + "modified": "2024-01-12T00:30:16Z", "published": "2024-01-09T03:30:22Z", "aliases": [ "CVE-2024-21738" diff --git a/advisories/unreviewed/2024/01/GHSA-jr5v-4546-4997/GHSA-jr5v-4546-4997.json b/advisories/unreviewed/2024/01/GHSA-jr5v-4546-4997/GHSA-jr5v-4546-4997.json index e315facf10b..f12ae1c8f9e 100644 --- a/advisories/unreviewed/2024/01/GHSA-jr5v-4546-4997/GHSA-jr5v-4546-4997.json +++ b/advisories/unreviewed/2024/01/GHSA-jr5v-4546-4997/GHSA-jr5v-4546-4997.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr5v-4546-4997", - "modified": "2024-01-09T03:30:22Z", + "modified": "2024-01-12T00:30:16Z", "published": "2024-01-09T03:30:22Z", "aliases": [ "CVE-2023-27000" ], "details": "Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-09T02:15:44Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mh49-rqvq-cjxg/GHSA-mh49-rqvq-cjxg.json b/advisories/unreviewed/2024/01/GHSA-mh49-rqvq-cjxg/GHSA-mh49-rqvq-cjxg.json index c0a916f5ad9..18ca8f4ec71 100644 --- a/advisories/unreviewed/2024/01/GHSA-mh49-rqvq-cjxg/GHSA-mh49-rqvq-cjxg.json +++ b/advisories/unreviewed/2024/01/GHSA-mh49-rqvq-cjxg/GHSA-mh49-rqvq-cjxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mh49-rqvq-cjxg", - "modified": "2024-01-09T21:30:34Z", + "modified": "2024-01-12T00:30:16Z", "published": "2024-01-03T06:30:27Z", "aliases": [ "CVE-2023-7027" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e8911a3-ce0f-420c-bf2a-1c2929d01cef?source=cve" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176525/WordPress-POST-SMTP-Mailer-2.8.7-Authorization-Bypass-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-mr7g-4crw-jcpj/GHSA-mr7g-4crw-jcpj.json b/advisories/unreviewed/2024/01/GHSA-mr7g-4crw-jcpj/GHSA-mr7g-4crw-jcpj.json new file mode 100644 index 00000000000..a45951d45ab --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mr7g-4crw-jcpj/GHSA-mr7g-4crw-jcpj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr7g-4crw-jcpj", + "modified": "2024-01-12T00:30:17Z", + "published": "2024-01-12T00:30:17Z", + "aliases": [ + "CVE-2024-21982" + ], + "details": "ONTAP versions 9.4 and higher are susceptible to a vulnerability \nwhich when successfully exploited could lead to disclosure of sensitive \ninformation to unprivileged attackers when the object-store profiler \ncommand is being run by an administrative user.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21982" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240111-0001/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T00:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p29w-9j4h-g34x/GHSA-p29w-9j4h-g34x.json b/advisories/unreviewed/2024/01/GHSA-p29w-9j4h-g34x/GHSA-p29w-9j4h-g34x.json new file mode 100644 index 00000000000..8310aececb8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p29w-9j4h-g34x/GHSA-p29w-9j4h-g34x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p29w-9j4h-g34x", + "modified": "2024-01-12T00:30:16Z", + "published": "2024-01-12T00:30:16Z", + "aliases": [ + "CVE-2023-46474" + ], + "details": "File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46474" + }, + { + "type": "WEB", + "url": "https://github.com/Xn2/CVE-2023-46474" + }, + { + "type": "WEB", + "url": "http://pmb.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-11T22:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rqh4-x2v7-j34g/GHSA-rqh4-x2v7-j34g.json b/advisories/unreviewed/2024/01/GHSA-rqh4-x2v7-j34g/GHSA-rqh4-x2v7-j34g.json new file mode 100644 index 00000000000..ef1d427c108 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rqh4-x2v7-j34g/GHSA-rqh4-x2v7-j34g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqh4-x2v7-j34g", + "modified": "2024-01-12T00:30:17Z", + "published": "2024-01-12T00:30:17Z", + "aliases": [ + "CVE-2024-0443" + ], + "details": "A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0443" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0443" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2257968" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/linux-block/20221215033132.230023-3-longman@redhat.com/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-402" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-12T00:15:45Z" + } +} \ No newline at end of file