From e750d6db133e65e5b7a4e619e4095a03537c747a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 16 Nov 2024 00:33:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-j6qq-7xp7-c5p5.json | 11 ++-- .../GHSA-gpvh-42rv-p6wg.json | 9 ++- .../GHSA-h86r-ff52-49qg.json | 9 ++- .../GHSA-mfgg-7fpx-cp7p.json | 11 ++-- .../GHSA-qc99-r4wh-c8h6.json | 9 ++- .../GHSA-7wqm-436q-gxcm.json | 2 +- .../GHSA-9gxf-r468-r4c5.json | 11 ++-- .../GHSA-247v-cg43-r8xg.json | 9 ++- .../GHSA-prj9-gvpq-vj8x.json | 9 ++- .../GHSA-8g3v-wwhq-2r48.json | 2 +- .../GHSA-f7h9-hrg7-94fg.json | 11 ++-- .../GHSA-3vhp-r544-3wrg.json | 35 +++++++++++ .../GHSA-3x6q-p4ff-j7wv.json | 58 +++++++++++++++++++ .../GHSA-4g32-4h7x-954w.json | 11 ++-- .../GHSA-5gw7-xq3v-7q6c.json | 35 +++++++++++ .../GHSA-5qw6-857j-hf24.json | 35 +++++++++++ .../GHSA-5v3w-3pq2-qhxx.json | 58 +++++++++++++++++++ .../GHSA-62mp-w633-xcfv.json | 11 ++-- .../GHSA-72v3-rgjm-mj6f.json | 11 ++-- .../GHSA-7pj9-85vv-hh5r.json | 11 ++-- .../GHSA-8386-783g-q974.json | 11 ++-- .../GHSA-87wv-cch6-jjh9.json | 38 ++++++++++++ .../GHSA-93r2-p5rq-7xr3.json | 9 ++- .../GHSA-9c7g-8m6v-j7h8.json | 3 +- .../GHSA-9g24-qqwh-54ww.json | 11 ++-- .../GHSA-crhm-9fh5-299j.json | 11 ++-- .../GHSA-cvm8-v9rf-89jw.json | 11 ++-- .../GHSA-h9q9-3g7p-gq9x.json | 35 +++++++++++ .../GHSA-j7jv-w7wp-p2c3.json | 35 +++++++++++ .../GHSA-jfhm-j25g-cc8g.json | 35 +++++++++++ .../GHSA-mcr8-cmcm-2p3c.json | 35 +++++++++++ .../GHSA-mcxg-gq2f-3x39.json | 11 ++-- .../GHSA-mm25-jv7r-42qf.json | 11 ++-- .../GHSA-pvg7-86fr-gvjh.json | 11 ++-- .../GHSA-pww8-r4pc-9m94.json | 39 +++++++++++++ .../GHSA-qf7p-2hmj-48mq.json | 11 ++-- .../GHSA-r29r-jxx6-7ff5.json | 6 +- .../GHSA-r764-fgc6-fqw3.json | 9 ++- .../GHSA-r8vx-grx7-h7xj.json | 9 ++- .../GHSA-w6cj-wqfc-3399.json | 11 ++-- .../GHSA-xmrx-pprf-648j.json | 11 ++-- 41 files changed, 621 insertions(+), 100 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json create mode 100644 advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-87wv-cch6-jjh9/GHSA-87wv-cch6-jjh9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json diff --git a/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json b/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json index e8af3f606d4..87c651cd81e 100644 --- a/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json +++ b/advisories/unreviewed/2024/02/GHSA-j6qq-7xp7-c5p5/GHSA-j6qq-7xp7-c5p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6qq-7xp7-c5p5", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-11-16T00:31:47Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1555" ], "details": "When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gpvh-42rv-p6wg/GHSA-gpvh-42rv-p6wg.json b/advisories/unreviewed/2024/03/GHSA-gpvh-42rv-p6wg/GHSA-gpvh-42rv-p6wg.json index 9d1f42baf7b..f0614992f29 100644 --- a/advisories/unreviewed/2024/03/GHSA-gpvh-42rv-p6wg/GHSA-gpvh-42rv-p6wg.json +++ b/advisories/unreviewed/2024/03/GHSA-gpvh-42rv-p6wg/GHSA-gpvh-42rv-p6wg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpvh-42rv-p6wg", - "modified": "2024-03-23T18:30:41Z", + "modified": "2024-11-16T00:31:48Z", "published": "2024-03-18T06:30:51Z", "aliases": [ "CVE-2021-47154" ], "details": "The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T05:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h86r-ff52-49qg/GHSA-h86r-ff52-49qg.json b/advisories/unreviewed/2024/03/GHSA-h86r-ff52-49qg/GHSA-h86r-ff52-49qg.json index 8ce01c92446..ac4b1e895e0 100644 --- a/advisories/unreviewed/2024/03/GHSA-h86r-ff52-49qg/GHSA-h86r-ff52-49qg.json +++ b/advisories/unreviewed/2024/03/GHSA-h86r-ff52-49qg/GHSA-h86r-ff52-49qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h86r-ff52-49qg", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-11-16T00:31:48Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27223" ], "details": "In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure after authenticating the cell connection with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mfgg-7fpx-cp7p/GHSA-mfgg-7fpx-cp7p.json b/advisories/unreviewed/2024/03/GHSA-mfgg-7fpx-cp7p/GHSA-mfgg-7fpx-cp7p.json index d6b9bca18df..de8b71d77c4 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfgg-7fpx-cp7p/GHSA-mfgg-7fpx-cp7p.json +++ b/advisories/unreviewed/2024/03/GHSA-mfgg-7fpx-cp7p/GHSA-mfgg-7fpx-cp7p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfgg-7fpx-cp7p", - "modified": "2024-03-27T06:30:32Z", + "modified": "2024-11-16T00:31:48Z", "published": "2024-03-27T06:30:32Z", "aliases": [ "CVE-2023-45935" ], "details": "Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T05:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json b/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json index 59dbf89968d..5ed320b24aa 100644 --- a/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json +++ b/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qc99-r4wh-c8h6", - "modified": "2024-03-29T00:30:34Z", + "modified": "2024-11-16T00:31:48Z", "published": "2024-03-29T00:30:34Z", "aliases": [ "CVE-2024-29316" ], "details": "NodeBB 3.6.7 is vulnerable to Incorrect Access Control.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T23:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7wqm-436q-gxcm/GHSA-7wqm-436q-gxcm.json b/advisories/unreviewed/2024/04/GHSA-7wqm-436q-gxcm/GHSA-7wqm-436q-gxcm.json index 40767f5ecaa..778616a331f 100644 --- a/advisories/unreviewed/2024/04/GHSA-7wqm-436q-gxcm/GHSA-7wqm-436q-gxcm.json +++ b/advisories/unreviewed/2024/04/GHSA-7wqm-436q-gxcm/GHSA-7wqm-436q-gxcm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json b/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json index 449d325c708..ceeb460c7a0 100644 --- a/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json +++ b/advisories/unreviewed/2024/05/GHSA-9gxf-r468-r4c5/GHSA-9gxf-r468-r4c5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gxf-r468-r4c5", - "modified": "2024-06-10T21:30:35Z", + "modified": "2024-11-16T00:31:49Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-27789" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Ventura 13.6.7, macOS Sonoma 14.4. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -65,9 +68,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:13:01Z" diff --git a/advisories/unreviewed/2024/06/GHSA-247v-cg43-r8xg/GHSA-247v-cg43-r8xg.json b/advisories/unreviewed/2024/06/GHSA-247v-cg43-r8xg/GHSA-247v-cg43-r8xg.json index c7edfde7a02..813951781c0 100644 --- a/advisories/unreviewed/2024/06/GHSA-247v-cg43-r8xg/GHSA-247v-cg43-r8xg.json +++ b/advisories/unreviewed/2024/06/GHSA-247v-cg43-r8xg/GHSA-247v-cg43-r8xg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-247v-cg43-r8xg", - "modified": "2024-06-03T03:31:04Z", + "modified": "2024-11-16T00:31:49Z", "published": "2024-06-03T03:31:04Z", "aliases": [ "CVE-2024-20070" ], "details": "In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00942482; Issue ID: MSV-1469.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-327" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T02:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-prj9-gvpq-vj8x/GHSA-prj9-gvpq-vj8x.json b/advisories/unreviewed/2024/06/GHSA-prj9-gvpq-vj8x/GHSA-prj9-gvpq-vj8x.json index 844763ecc42..882245d7ffd 100644 --- a/advisories/unreviewed/2024/06/GHSA-prj9-gvpq-vj8x/GHSA-prj9-gvpq-vj8x.json +++ b/advisories/unreviewed/2024/06/GHSA-prj9-gvpq-vj8x/GHSA-prj9-gvpq-vj8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prj9-gvpq-vj8x", - "modified": "2024-06-18T06:30:42Z", + "modified": "2024-11-16T00:31:49Z", "published": "2024-06-18T06:30:42Z", "aliases": [ "CVE-2024-34024" ], "details": "Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-18T06:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8g3v-wwhq-2r48/GHSA-8g3v-wwhq-2r48.json b/advisories/unreviewed/2024/07/GHSA-8g3v-wwhq-2r48/GHSA-8g3v-wwhq-2r48.json index dc7cd79b399..a24c03c963c 100644 --- a/advisories/unreviewed/2024/07/GHSA-8g3v-wwhq-2r48/GHSA-8g3v-wwhq-2r48.json +++ b/advisories/unreviewed/2024/07/GHSA-8g3v-wwhq-2r48/GHSA-8g3v-wwhq-2r48.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json b/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json index 18d5a6b0138..2cc73a13aad 100644 --- a/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json +++ b/advisories/unreviewed/2024/10/GHSA-f7h9-hrg7-94fg/GHSA-f7h9-hrg7-94fg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f7h9-hrg7-94fg", - "modified": "2024-10-01T15:32:08Z", + "modified": "2024-11-16T00:31:49Z", "published": "2024-10-01T15:32:08Z", "aliases": [ "CVE-2021-37577" ], "details": "Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X coordinate as the offered public key and by reflection of the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. This is a related issue to CVE-2020-26558.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T15:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json b/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json new file mode 100644 index 00000000000..b5f7ca1afbb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3vhp-r544-3wrg/GHSA-3vhp-r544-3wrg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vhp-r544-3wrg", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:50Z", + "aliases": [ + "CVE-2017-13310" + ], + "details": "In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13310" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json b/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json new file mode 100644 index 00000000000..51b3df35483 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3x6q-p4ff-j7wv/GHSA-3x6q-p4ff-j7wv.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x6q-p4ff-j7wv", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2024-11261" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Affected is an unknown function of the file StudentRecordManagementSystem.cpp of the component Number of Students Menu. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11261" + }, + { + "type": "WEB", + "url": "https://github.com/Hacker0xone/CVE/issues/12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284718" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284718" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443906" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json b/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json index e7e6f64a55c..490c40b2967 100644 --- a/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json +++ b/advisories/unreviewed/2024/11/GHSA-4g32-4h7x-954w/GHSA-4g32-4h7x-954w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g32-4h7x-954w", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24459" ], "details": "An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json b/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json new file mode 100644 index 00000000000..50eca7e1e3e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5gw7-xq3v-7q6c/GHSA-5gw7-xq3v-7q6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gw7-xq3v-7q6c", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2017-13314" + ], + "details": "In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13314" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json b/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json new file mode 100644 index 00000000000..4da7e2f38ac --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5qw6-857j-hf24/GHSA-5qw6-857j-hf24.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qw6-857j-hf24", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2024-51765" + ], + "details": "A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51765" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbcr04748en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json b/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json new file mode 100644 index 00000000000..d9d3955371e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5v3w-3pq2-qhxx/GHSA-5v3w-3pq2-qhxx.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v3w-3pq2-qhxx", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2024-11262" + ], + "details": "A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of the component View All Student Marks. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11262" + }, + { + "type": "WEB", + "url": "https://github.com/Hacker0xone/CVE/issues/13" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.284719" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.284719" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.443950" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json b/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json index 82fe165e58d..e0d4562e406 100644 --- a/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json +++ b/advisories/unreviewed/2024/11/GHSA-62mp-w633-xcfv/GHSA-62mp-w633-xcfv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62mp-w633-xcfv", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-24450" ], "details": "Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a suffciently large FailedToSetupList IE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-72v3-rgjm-mj6f/GHSA-72v3-rgjm-mj6f.json b/advisories/unreviewed/2024/11/GHSA-72v3-rgjm-mj6f/GHSA-72v3-rgjm-mj6f.json index 6ad1e85ccb7..3ef130fb900 100644 --- a/advisories/unreviewed/2024/11/GHSA-72v3-rgjm-mj6f/GHSA-72v3-rgjm-mj6f.json +++ b/advisories/unreviewed/2024/11/GHSA-72v3-rgjm-mj6f/GHSA-72v3-rgjm-mj6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72v3-rgjm-mj6f", - "modified": "2024-11-13T00:30:48Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2021-27702" ], "details": "Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json b/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json index fd2aa53aacc..27ab3c5106e 100644 --- a/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json +++ b/advisories/unreviewed/2024/11/GHSA-7pj9-85vv-hh5r/GHSA-7pj9-85vv-hh5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pj9-85vv-hh5r", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24454" ], "details": "An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json b/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json index 6db451521cb..9fe7ea3031d 100644 --- a/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json +++ b/advisories/unreviewed/2024/11/GHSA-8386-783g-q974/GHSA-8386-783g-q974.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8386-783g-q974", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24452" ], "details": "An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-87wv-cch6-jjh9/GHSA-87wv-cch6-jjh9.json b/advisories/unreviewed/2024/11/GHSA-87wv-cch6-jjh9/GHSA-87wv-cch6-jjh9.json new file mode 100644 index 00000000000..bf04425eda7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-87wv-cch6-jjh9/GHSA-87wv-cch6-jjh9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87wv-cch6-jjh9", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2024-9500" + ], + "details": "A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9500" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-93r2-p5rq-7xr3/GHSA-93r2-p5rq-7xr3.json b/advisories/unreviewed/2024/11/GHSA-93r2-p5rq-7xr3/GHSA-93r2-p5rq-7xr3.json index f997cfa31c9..fa95f0442b4 100644 --- a/advisories/unreviewed/2024/11/GHSA-93r2-p5rq-7xr3/GHSA-93r2-p5rq-7xr3.json +++ b/advisories/unreviewed/2024/11/GHSA-93r2-p5rq-7xr3/GHSA-93r2-p5rq-7xr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93r2-p5rq-7xr3", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2024-31337" ], "details": "In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9c7g-8m6v-j7h8/GHSA-9c7g-8m6v-j7h8.json b/advisories/unreviewed/2024/11/GHSA-9c7g-8m6v-j7h8/GHSA-9c7g-8m6v-j7h8.json index 08a1a4760df..4aafa7ac478 100644 --- a/advisories/unreviewed/2024/11/GHSA-9c7g-8m6v-j7h8/GHSA-9c7g-8m6v-j7h8.json +++ b/advisories/unreviewed/2024/11/GHSA-9c7g-8m6v-j7h8/GHSA-9c7g-8m6v-j7h8.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-9g24-qqwh-54ww/GHSA-9g24-qqwh-54ww.json b/advisories/unreviewed/2024/11/GHSA-9g24-qqwh-54ww/GHSA-9g24-qqwh-54ww.json index 273151918e9..17f4d21b413 100644 --- a/advisories/unreviewed/2024/11/GHSA-9g24-qqwh-54ww/GHSA-9g24-qqwh-54ww.json +++ b/advisories/unreviewed/2024/11/GHSA-9g24-qqwh-54ww/GHSA-9g24-qqwh-54ww.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g24-qqwh-54ww", - "modified": "2024-11-08T18:30:49Z", + "modified": "2024-11-16T00:31:49Z", "published": "2024-11-07T12:30:34Z", "aliases": [ "CVE-2024-50143" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: fix uninit-value use in udf_get_fileshortad\n\nCheck for overflow when computing alen in udf_current_aext to mitigate\nlater uninit-value use in udf_get_fileshortad KMSAN bug[1].\nAfter applying the patch reproducer did not trigger any issue[2].\n\n[1] https://syzkaller.appspot.com/bug?extid=8901c4560b7ab5c2f9df\n[2] https://syzkaller.appspot.com/x/log.txt?x=10242227980000", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T10:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json b/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json index 0d4972b00b3..9bf7df10861 100644 --- a/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json +++ b/advisories/unreviewed/2024/11/GHSA-crhm-9fh5-299j/GHSA-crhm-9fh5-299j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-crhm-9fh5-299j", - "modified": "2024-11-15T18:30:51Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T18:30:51Z", "aliases": [ "CVE-2024-24447" ], "details": "Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a ResourceFailedToSetupList containing zero elements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T18:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json b/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json index 59f29790358..9cbcc2aa549 100644 --- a/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json +++ b/advisories/unreviewed/2024/11/GHSA-cvm8-v9rf-89jw/GHSA-cvm8-v9rf-89jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvm8-v9rf-89jw", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24455" ], "details": "An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json b/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json new file mode 100644 index 00000000000..e041f864eb1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h9q9-3g7p-gq9x/GHSA-h9q9-3g7p-gq9x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9q9-3g7p-gq9x", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:50Z", + "aliases": [ + "CVE-2017-13313" + ], + "details": "In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13313" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json b/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json new file mode 100644 index 00000000000..d373585d35d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j7jv-w7wp-p2c3/GHSA-j7jv-w7wp-p2c3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7jv-w7wp-p2c3", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2024-51764" + ], + "details": "A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51764" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbcr04747en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json b/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json new file mode 100644 index 00000000000..a99c5783e18 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jfhm-j25g-cc8g/GHSA-jfhm-j25g-cc8g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfhm-j25g-cc8g", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:50Z", + "aliases": [ + "CVE-2017-13311" + ], + "details": "In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13311" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json b/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json new file mode 100644 index 00000000000..eb64bd2a598 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mcr8-cmcm-2p3c/GHSA-mcr8-cmcm-2p3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcr8-cmcm-2p3c", + "modified": "2024-11-16T00:31:50Z", + "published": "2024-11-16T00:31:50Z", + "aliases": [ + "CVE-2017-13312" + ], + "details": "In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-13312" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2018-05-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json b/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json index 2899844cb87..90d5d33e4a9 100644 --- a/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json +++ b/advisories/unreviewed/2024/11/GHSA-mcxg-gq2f-3x39/GHSA-mcxg-gq2f-3x39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mcxg-gq2f-3x39", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24458" ], "details": "An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-mm25-jv7r-42qf/GHSA-mm25-jv7r-42qf.json b/advisories/unreviewed/2024/11/GHSA-mm25-jv7r-42qf/GHSA-mm25-jv7r-42qf.json index 61df5637f42..ad852f7d700 100644 --- a/advisories/unreviewed/2024/11/GHSA-mm25-jv7r-42qf/GHSA-mm25-jv7r-42qf.json +++ b/advisories/unreviewed/2024/11/GHSA-mm25-jv7r-42qf/GHSA-mm25-jv7r-42qf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mm25-jv7r-42qf", - "modified": "2024-11-13T00:30:48Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2021-27703" ], "details": "Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-12T23:15:03Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pvg7-86fr-gvjh/GHSA-pvg7-86fr-gvjh.json b/advisories/unreviewed/2024/11/GHSA-pvg7-86fr-gvjh/GHSA-pvg7-86fr-gvjh.json index 1c216026e85..c3471fbb1b2 100644 --- a/advisories/unreviewed/2024/11/GHSA-pvg7-86fr-gvjh/GHSA-pvg7-86fr-gvjh.json +++ b/advisories/unreviewed/2024/11/GHSA-pvg7-86fr-gvjh/GHSA-pvg7-86fr-gvjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pvg7-86fr-gvjh", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2024-34747" ], "details": "In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json b/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json new file mode 100644 index 00000000000..1eb97ab50a6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pww8-r4pc-9m94/GHSA-pww8-r4pc-9m94.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pww8-r4pc-9m94", + "modified": "2024-11-16T00:31:51Z", + "published": "2024-11-16T00:31:51Z", + "aliases": [ + "CVE-2024-50983" + ], + "details": "FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50983" + }, + { + "type": "WEB", + "url": "https://github.com/redhotchilihacker1/CVE-Hunting/blob/master/CVE-2024-50983/README.md" + }, + { + "type": "WEB", + "url": "https://github.com/swampopus/flightpath/blob/e713acf9f125af22cc68c2f5664c2869cd73616b/flightpath/CHANGELOG.txt#L4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-15T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json b/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json index 3e1197b3b66..ae60f44b559 100644 --- a/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json +++ b/advisories/unreviewed/2024/11/GHSA-qf7p-2hmj-48mq/GHSA-qf7p-2hmj-48mq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qf7p-2hmj-48mq", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24453" ], "details": "An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r29r-jxx6-7ff5/GHSA-r29r-jxx6-7ff5.json b/advisories/unreviewed/2024/11/GHSA-r29r-jxx6-7ff5/GHSA-r29r-jxx6-7ff5.json index df73eadbcf6..896eed2a916 100644 --- a/advisories/unreviewed/2024/11/GHSA-r29r-jxx6-7ff5/GHSA-r29r-jxx6-7ff5.json +++ b/advisories/unreviewed/2024/11/GHSA-r29r-jxx6-7ff5/GHSA-r29r-jxx6-7ff5.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r29r-jxx6-7ff5", - "modified": "2024-11-13T15:31:38Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-13T15:31:38Z", "aliases": [ "CVE-2024-9477" ], "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air4443 Firmware allows Cross-Site Scripting (XSS).This issue affects Air4443 Firmware: through 14102024.\n\n\nNOTE: The vendor was contacted and it was learned that the product classified as End-of-Life and End-of-Support.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-r764-fgc6-fqw3/GHSA-r764-fgc6-fqw3.json b/advisories/unreviewed/2024/11/GHSA-r764-fgc6-fqw3/GHSA-r764-fgc6-fqw3.json index 430c585c1d0..428202027da 100644 --- a/advisories/unreviewed/2024/11/GHSA-r764-fgc6-fqw3/GHSA-r764-fgc6-fqw3.json +++ b/advisories/unreviewed/2024/11/GHSA-r764-fgc6-fqw3/GHSA-r764-fgc6-fqw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r764-fgc6-fqw3", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2017-13309" ], "details": "In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T21:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-r8vx-grx7-h7xj/GHSA-r8vx-grx7-h7xj.json b/advisories/unreviewed/2024/11/GHSA-r8vx-grx7-h7xj/GHSA-r8vx-grx7-h7xj.json index 0010c0bcaca..6b34a57397f 100644 --- a/advisories/unreviewed/2024/11/GHSA-r8vx-grx7-h7xj/GHSA-r8vx-grx7-h7xj.json +++ b/advisories/unreviewed/2024/11/GHSA-r8vx-grx7-h7xj/GHSA-r8vx-grx7-h7xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8vx-grx7-h7xj", - "modified": "2024-11-13T18:32:04Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-13T18:32:04Z", "aliases": [ "CVE-2024-34729" ], "details": "In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-13T18:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w6cj-wqfc-3399/GHSA-w6cj-wqfc-3399.json b/advisories/unreviewed/2024/11/GHSA-w6cj-wqfc-3399/GHSA-w6cj-wqfc-3399.json index 32d6f96d5a8..2c7b36f5966 100644 --- a/advisories/unreviewed/2024/11/GHSA-w6cj-wqfc-3399/GHSA-w6cj-wqfc-3399.json +++ b/advisories/unreviewed/2024/11/GHSA-w6cj-wqfc-3399/GHSA-w6cj-wqfc-3399.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w6cj-wqfc-3399", - "modified": "2024-11-14T18:30:36Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-14T18:30:36Z", "aliases": [ "CVE-2024-50835" ], "details": "A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-14T17:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json b/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json index 64c8dad8bce..a3a8cc4380a 100644 --- a/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json +++ b/advisories/unreviewed/2024/11/GHSA-xmrx-pprf-648j/GHSA-xmrx-pprf-648j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmrx-pprf-648j", - "modified": "2024-11-15T21:30:47Z", + "modified": "2024-11-16T00:31:50Z", "published": "2024-11-15T21:30:47Z", "aliases": [ "CVE-2024-24457" ], "details": "An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-15T20:15:19Z"