From e88c91cfcd503d18c20d6c2bb25f61dd176939c1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jan 2024 09:31:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gpcj-wh2f-rr23.json | 4 ++ .../GHSA-275c-w5mq-v5m2.json | 38 +++++++++++++++ .../GHSA-2wcj-qr76-9768.json | 38 +++++++++++++++ .../GHSA-3cr5-2446-8pg3.json | 38 +++++++++++++++ .../GHSA-4rrv-8gcp-24v8.json | 38 +++++++++++++++ .../GHSA-547m-23x7-cxg5.json | 38 +++++++++++++++ .../GHSA-55rm-p79h-88wj.json | 46 +++++++++++++++++++ .../GHSA-5qqv-6f97-m7hw.json | 42 +++++++++++++++++ .../GHSA-74fr-23m6-mhjw.json | 39 ++++++++++++++++ .../GHSA-74p2-cxrg-rcxq.json | 35 ++++++++++++++ .../GHSA-8fp7-jwv2-49x9.json | 38 +++++++++++++++ .../GHSA-93mm-6jq8-8cgj.json | 42 +++++++++++++++++ .../GHSA-c6ph-m8cw-rfqh.json | 38 +++++++++++++++ .../GHSA-g57v-2687-jx33.json | 38 +++++++++++++++ .../GHSA-gr9g-7x3w-8vjj.json | 35 ++++++++++++++ .../GHSA-j5h9-9r39-43q5.json | 38 +++++++++++++++ .../GHSA-j7h9-fx4j-q5vr.json | 35 ++++++++++++++ .../GHSA-jccx-fvx2-cqjj.json | 42 +++++++++++++++++ .../GHSA-jm68-fpmr-8j2g.json | 38 +++++++++++++++ .../GHSA-mr78-v55p-7777.json | 38 +++++++++++++++ .../GHSA-phw4-gv7f-mc27.json | 42 +++++++++++++++++ .../GHSA-qppw-c37g-xwcc.json | 38 +++++++++++++++ .../GHSA-rf7p-79xq-8xwm.json | 38 +++++++++++++++ .../GHSA-rg9q-m8hv-xxr6.json | 38 +++++++++++++++ .../GHSA-rj85-r62x-rwp3.json | 42 +++++++++++++++++ .../GHSA-rx2r-q96c-w5cc.json | 38 +++++++++++++++ .../GHSA-v4r8-6m3f-gvv4.json | 42 +++++++++++++++++ .../GHSA-v9pg-qw6x-w5r2.json | 38 +++++++++++++++ .../GHSA-w5mm-9ffh-gjvj.json | 42 +++++++++++++++++ .../GHSA-x3q9-c788-j7c8.json | 38 +++++++++++++++ .../GHSA-xf55-65pg-x58p.json | 42 +++++++++++++++++ .../GHSA-xjpw-hx47-rccv.json | 38 +++++++++++++++ 32 files changed, 1214 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-275c-w5mq-v5m2/GHSA-275c-w5mq-v5m2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-2wcj-qr76-9768/GHSA-2wcj-qr76-9768.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3cr5-2446-8pg3/GHSA-3cr5-2446-8pg3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4rrv-8gcp-24v8/GHSA-4rrv-8gcp-24v8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-547m-23x7-cxg5/GHSA-547m-23x7-cxg5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5qqv-6f97-m7hw/GHSA-5qqv-6f97-m7hw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-74fr-23m6-mhjw/GHSA-74fr-23m6-mhjw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-74p2-cxrg-rcxq/GHSA-74p2-cxrg-rcxq.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8fp7-jwv2-49x9/GHSA-8fp7-jwv2-49x9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-93mm-6jq8-8cgj/GHSA-93mm-6jq8-8cgj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-c6ph-m8cw-rfqh/GHSA-c6ph-m8cw-rfqh.json create mode 100644 advisories/unreviewed/2024/01/GHSA-g57v-2687-jx33/GHSA-g57v-2687-jx33.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gr9g-7x3w-8vjj/GHSA-gr9g-7x3w-8vjj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-j5h9-9r39-43q5/GHSA-j5h9-9r39-43q5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-j7h9-fx4j-q5vr/GHSA-j7h9-fx4j-q5vr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jccx-fvx2-cqjj/GHSA-jccx-fvx2-cqjj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jm68-fpmr-8j2g/GHSA-jm68-fpmr-8j2g.json create mode 100644 advisories/unreviewed/2024/01/GHSA-mr78-v55p-7777/GHSA-mr78-v55p-7777.json create mode 100644 advisories/unreviewed/2024/01/GHSA-phw4-gv7f-mc27/GHSA-phw4-gv7f-mc27.json create mode 100644 advisories/unreviewed/2024/01/GHSA-qppw-c37g-xwcc/GHSA-qppw-c37g-xwcc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rf7p-79xq-8xwm/GHSA-rf7p-79xq-8xwm.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rg9q-m8hv-xxr6/GHSA-rg9q-m8hv-xxr6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rj85-r62x-rwp3/GHSA-rj85-r62x-rwp3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rx2r-q96c-w5cc/GHSA-rx2r-q96c-w5cc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v9pg-qw6x-w5r2/GHSA-v9pg-qw6x-w5r2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w5mm-9ffh-gjvj/GHSA-w5mm-9ffh-gjvj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-x3q9-c788-j7c8/GHSA-x3q9-c788-j7c8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xf55-65pg-x58p/GHSA-xf55-65pg-x58p.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xjpw-hx47-rccv/GHSA-xjpw-hx47-rccv.json diff --git a/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json b/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json index ad37cf076af..49ee95aab93 100644 --- a/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json +++ b/advisories/unreviewed/2023/12/GHSA-gpcj-wh2f-rr23/GHSA-gpcj-wh2f-rr23.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases/" + }, + { + "type": "WEB", + "url": "https://www.libssh.org/security/advisories/CVE-2023-6918.txt" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-275c-w5mq-v5m2/GHSA-275c-w5mq-v5m2.json b/advisories/unreviewed/2024/01/GHSA-275c-w5mq-v5m2/GHSA-275c-w5mq-v5m2.json new file mode 100644 index 00000000000..fbdb1d8800d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-275c-w5mq-v5m2/GHSA-275c-w5mq-v5m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-275c-w5mq-v5m2", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52313" + ], + "details": "FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52313" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-022.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2wcj-qr76-9768/GHSA-2wcj-qr76-9768.json b/advisories/unreviewed/2024/01/GHSA-2wcj-qr76-9768/GHSA-2wcj-qr76-9768.json new file mode 100644 index 00000000000..55de383e97b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2wcj-qr76-9768/GHSA-2wcj-qr76-9768.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wcj-qr76-9768", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-52303" + ], + "details": "Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52303" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-012.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3cr5-2446-8pg3/GHSA-3cr5-2446-8pg3.json b/advisories/unreviewed/2024/01/GHSA-3cr5-2446-8pg3/GHSA-3cr5-2446-8pg3.json new file mode 100644 index 00000000000..426f188a5ff --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3cr5-2446-8pg3/GHSA-3cr5-2446-8pg3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cr5-2446-8pg3", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52314" + ], + "details": "PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52314" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-023.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4rrv-8gcp-24v8/GHSA-4rrv-8gcp-24v8.json b/advisories/unreviewed/2024/01/GHSA-4rrv-8gcp-24v8/GHSA-4rrv-8gcp-24v8.json new file mode 100644 index 00000000000..c6d8ae6ac43 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4rrv-8gcp-24v8/GHSA-4rrv-8gcp-24v8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rrv-8gcp-24v8", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52304" + ], + "details": "Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52304" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-013.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-547m-23x7-cxg5/GHSA-547m-23x7-cxg5.json b/advisories/unreviewed/2024/01/GHSA-547m-23x7-cxg5/GHSA-547m-23x7-cxg5.json new file mode 100644 index 00000000000..4c9435cb13b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-547m-23x7-cxg5/GHSA-547m-23x7-cxg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-547m-23x7-cxg5", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-52302" + ], + "details": "Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52302" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-011.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json b/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json new file mode 100644 index 00000000000..cbfef7b7228 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55rm-p79h-88wj", + "modified": "2024-01-03T09:30:29Z", + "published": "2024-01-03T09:30:29Z", + "aliases": [ + "CVE-2023-6986" + ], + "details": "The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versions up to 3.9.5 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6986" + }, + { + "type": "WEB", + "url": "https://plugins.svn.wordpress.org/embedpress/trunk/EmbedPress/Shortcode.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3014595%40embedpress&new=3014595%40embedpress&sfp_email=&sfph_mail=#file11" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ceae0115-268c-401b-876b-3477d10c10e6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5qqv-6f97-m7hw/GHSA-5qqv-6f97-m7hw.json b/advisories/unreviewed/2024/01/GHSA-5qqv-6f97-m7hw/GHSA-5qqv-6f97-m7hw.json new file mode 100644 index 00000000000..6f5c3a031e8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5qqv-6f97-m7hw/GHSA-5qqv-6f97-m7hw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qqv-6f97-m7hw", + "modified": "2024-01-03T09:30:30Z", + "published": "2024-01-03T09:30:30Z", + "aliases": [ + "CVE-2024-0207" + ], + "details": "HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0207" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19502" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2024-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-74fr-23m6-mhjw/GHSA-74fr-23m6-mhjw.json b/advisories/unreviewed/2024/01/GHSA-74fr-23m6-mhjw/GHSA-74fr-23m6-mhjw.json new file mode 100644 index 00000000000..438e89604e7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-74fr-23m6-mhjw/GHSA-74fr-23m6-mhjw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74fr-23m6-mhjw", + "modified": "2024-01-03T09:30:29Z", + "published": "2024-01-03T09:30:29Z", + "aliases": [ + "CVE-2023-47473" + ], + "details": "Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted script.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47473" + }, + { + "type": "WEB", + "url": "https://github.com/THMOAS0/SSR123/blob/main/%E4%BC%81%E8%AF%ADiFair%20Any%20file%20read.pdf" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/ssr123/gxhh8t/xv5oxd5i5pxmxd1a?singleDoc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-74p2-cxrg-rcxq/GHSA-74p2-cxrg-rcxq.json b/advisories/unreviewed/2024/01/GHSA-74p2-cxrg-rcxq/GHSA-74p2-cxrg-rcxq.json new file mode 100644 index 00000000000..1aeec39828a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-74p2-cxrg-rcxq/GHSA-74p2-cxrg-rcxq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74p2-cxrg-rcxq", + "modified": "2024-01-03T09:30:29Z", + "published": "2024-01-03T09:30:29Z", + "aliases": [ + "CVE-2023-50922" + ], + "details": "An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory and waiting for its execution. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50922" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Remote%20code%20execution%20due%20to%20gl_crontabs.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8fp7-jwv2-49x9/GHSA-8fp7-jwv2-49x9.json b/advisories/unreviewed/2024/01/GHSA-8fp7-jwv2-49x9/GHSA-8fp7-jwv2-49x9.json new file mode 100644 index 00000000000..8853c85e6ad --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8fp7-jwv2-49x9/GHSA-8fp7-jwv2-49x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fp7-jwv2-49x9", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52309" + ], + "details": "Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52309" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-018.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-93mm-6jq8-8cgj/GHSA-93mm-6jq8-8cgj.json b/advisories/unreviewed/2024/01/GHSA-93mm-6jq8-8cgj/GHSA-93mm-6jq8-8cgj.json new file mode 100644 index 00000000000..685fd36818a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-93mm-6jq8-8cgj/GHSA-93mm-6jq8-8cgj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93mm-6jq8-8cgj", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-7068" + ], + "details": "The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to export orders which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7068" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3014977%40print-invoices-packing-slip-labels-for-woocommerce&new=3014977%40print-invoices-packing-slip-labels-for-woocommerce&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5abc282d-68c9-423c-a15c-d4d3f7035661?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c6ph-m8cw-rfqh/GHSA-c6ph-m8cw-rfqh.json b/advisories/unreviewed/2024/01/GHSA-c6ph-m8cw-rfqh/GHSA-c6ph-m8cw-rfqh.json new file mode 100644 index 00000000000..112bc18c3ed --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c6ph-m8cw-rfqh/GHSA-c6ph-m8cw-rfqh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6ph-m8cw-rfqh", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-38677" + ], + "details": "FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38677" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-009.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g57v-2687-jx33/GHSA-g57v-2687-jx33.json b/advisories/unreviewed/2024/01/GHSA-g57v-2687-jx33/GHSA-g57v-2687-jx33.json new file mode 100644 index 00000000000..d61f059a849 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g57v-2687-jx33/GHSA-g57v-2687-jx33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g57v-2687-jx33", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52307" + ], + "details": "Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52307" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-016.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gr9g-7x3w-8vjj/GHSA-gr9g-7x3w-8vjj.json b/advisories/unreviewed/2024/01/GHSA-gr9g-7x3w-8vjj/GHSA-gr9g-7x3w-8vjj.json new file mode 100644 index 00000000000..3c9a18383c7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gr9g-7x3w-8vjj/GHSA-gr9g-7x3w-8vjj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr9g-7x3w-8vjj", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-6621" + ], + "details": "The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6621" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b49ca336-5bc2-4d72-a9a5-b8c020057928" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-j5h9-9r39-43q5/GHSA-j5h9-9r39-43q5.json b/advisories/unreviewed/2024/01/GHSA-j5h9-9r39-43q5/GHSA-j5h9-9r39-43q5.json new file mode 100644 index 00000000000..b39ac393dcb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j5h9-9r39-43q5/GHSA-j5h9-9r39-43q5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5h9-9r39-43q5", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52310" + ], + "details": "PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52310" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-019.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-j7h9-fx4j-q5vr/GHSA-j7h9-fx4j-q5vr.json b/advisories/unreviewed/2024/01/GHSA-j7h9-fx4j-q5vr/GHSA-j7h9-fx4j-q5vr.json new file mode 100644 index 00000000000..5cf4c4a438c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j7h9-fx4j-q5vr/GHSA-j7h9-fx4j-q5vr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7h9-fx4j-q5vr", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-50921" + ], + "details": "An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50921" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Add_user_vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jccx-fvx2-cqjj/GHSA-jccx-fvx2-cqjj.json b/advisories/unreviewed/2024/01/GHSA-jccx-fvx2-cqjj/GHSA-jccx-fvx2-cqjj.json new file mode 100644 index 00000000000..e33c2b5e423 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jccx-fvx2-cqjj/GHSA-jccx-fvx2-cqjj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jccx-fvx2-cqjj", + "modified": "2024-01-03T09:30:30Z", + "published": "2024-01-03T09:30:30Z", + "aliases": [ + "CVE-2024-0209" + ], + "details": "IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0209" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19501" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2024-02.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jm68-fpmr-8j2g/GHSA-jm68-fpmr-8j2g.json b/advisories/unreviewed/2024/01/GHSA-jm68-fpmr-8j2g/GHSA-jm68-fpmr-8j2g.json new file mode 100644 index 00000000000..2fe1e74dda1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jm68-fpmr-8j2g/GHSA-jm68-fpmr-8j2g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm68-fpmr-8j2g", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-38675" + ], + "details": "FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38675" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-007.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mr78-v55p-7777/GHSA-mr78-v55p-7777.json b/advisories/unreviewed/2024/01/GHSA-mr78-v55p-7777/GHSA-mr78-v55p-7777.json new file mode 100644 index 00000000000..1be6cce8368 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mr78-v55p-7777/GHSA-mr78-v55p-7777.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr78-v55p-7777", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-38678" + ], + "details": "OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38678" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-010.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-phw4-gv7f-mc27/GHSA-phw4-gv7f-mc27.json b/advisories/unreviewed/2024/01/GHSA-phw4-gv7f-mc27/GHSA-phw4-gv7f-mc27.json new file mode 100644 index 00000000000..e38512f3215 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-phw4-gv7f-mc27/GHSA-phw4-gv7f-mc27.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phw4-gv7f-mc27", + "modified": "2024-01-03T09:30:30Z", + "published": "2024-01-03T09:30:30Z", + "aliases": [ + "CVE-2024-0208" + ], + "details": "GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0208" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19496" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2024-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qppw-c37g-xwcc/GHSA-qppw-c37g-xwcc.json b/advisories/unreviewed/2024/01/GHSA-qppw-c37g-xwcc/GHSA-qppw-c37g-xwcc.json new file mode 100644 index 00000000000..6a1b40df63c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qppw-c37g-xwcc/GHSA-qppw-c37g-xwcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qppw-c37g-xwcc", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52312" + ], + "details": "Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52312" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-021.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rf7p-79xq-8xwm/GHSA-rf7p-79xq-8xwm.json b/advisories/unreviewed/2024/01/GHSA-rf7p-79xq-8xwm/GHSA-rf7p-79xq-8xwm.json new file mode 100644 index 00000000000..995fa0fa87b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rf7p-79xq-8xwm/GHSA-rf7p-79xq-8xwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf7p-79xq-8xwm", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52311" + ], + "details": "PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52311" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-020.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rg9q-m8hv-xxr6/GHSA-rg9q-m8hv-xxr6.json b/advisories/unreviewed/2024/01/GHSA-rg9q-m8hv-xxr6/GHSA-rg9q-m8hv-xxr6.json new file mode 100644 index 00000000000..7b569887758 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rg9q-m8hv-xxr6/GHSA-rg9q-m8hv-xxr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg9q-m8hv-xxr6", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52306" + ], + "details": "FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52306" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-015.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rj85-r62x-rwp3/GHSA-rj85-r62x-rwp3.json b/advisories/unreviewed/2024/01/GHSA-rj85-r62x-rwp3/GHSA-rj85-r62x-rwp3.json new file mode 100644 index 00000000000..94b376eaa88 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rj85-r62x-rwp3/GHSA-rj85-r62x-rwp3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj85-r62x-rwp3", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-6984" + ], + "details": "The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.13. This is due to missing or incorrect nonce validation in the powerpack-lite-for-elementor/classes/class-pp-admin-settings.php file. This makes it possible for unauthenticated attackers to modify and reset plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6984" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3015474%40powerpack-lite-for-elementor&new=3015474%40powerpack-lite-for-elementor&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fe2cfc96-63f4-4e4b-bf49-6031594a4805?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rx2r-q96c-w5cc/GHSA-rx2r-q96c-w5cc.json b/advisories/unreviewed/2024/01/GHSA-rx2r-q96c-w5cc/GHSA-rx2r-q96c-w5cc.json new file mode 100644 index 00000000000..150012cd788 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rx2r-q96c-w5cc/GHSA-rx2r-q96c-w5cc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx2r-q96c-w5cc", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52305" + ], + "details": "FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52305" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-014.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json b/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json new file mode 100644 index 00000000000..1c34ad0b41d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4r8-6m3f-gvv4", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-6747" + ], + "details": "The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for contributors and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6747" + }, + { + "type": "WEB", + "url": "https://fooplugins.com/foogallery-wordpress-gallery-plugin/pricing/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dce8ac32-cab8-4e05-bf6f-cc348d0c9472?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v9pg-qw6x-w5r2/GHSA-v9pg-qw6x-w5r2.json b/advisories/unreviewed/2024/01/GHSA-v9pg-qw6x-w5r2/GHSA-v9pg-qw6x-w5r2.json new file mode 100644 index 00000000000..d441a233a72 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v9pg-qw6x-w5r2/GHSA-v9pg-qw6x-w5r2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9pg-qw6x-w5r2", + "modified": "2024-01-03T09:30:33Z", + "published": "2024-01-03T09:30:33Z", + "aliases": [ + "CVE-2023-52308" + ], + "details": "FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52308" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-017.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w5mm-9ffh-gjvj/GHSA-w5mm-9ffh-gjvj.json b/advisories/unreviewed/2024/01/GHSA-w5mm-9ffh-gjvj/GHSA-w5mm-9ffh-gjvj.json new file mode 100644 index 00000000000..aa5c64184a2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w5mm-9ffh-gjvj/GHSA-w5mm-9ffh-gjvj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5mm-9ffh-gjvj", + "modified": "2024-01-03T09:30:30Z", + "published": "2024-01-03T09:30:30Z", + "aliases": [ + "CVE-2024-0210" + ], + "details": "Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0210" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19504" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2024-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x3q9-c788-j7c8/GHSA-x3q9-c788-j7c8.json b/advisories/unreviewed/2024/01/GHSA-x3q9-c788-j7c8/GHSA-x3q9-c788-j7c8.json new file mode 100644 index 00000000000..48cdc268b66 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x3q9-c788-j7c8/GHSA-x3q9-c788-j7c8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3q9-c788-j7c8", + "modified": "2024-01-03T09:30:32Z", + "published": "2024-01-03T09:30:32Z", + "aliases": [ + "CVE-2023-38676" + ], + "details": "Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38676" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-008.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xf55-65pg-x58p/GHSA-xf55-65pg-x58p.json b/advisories/unreviewed/2024/01/GHSA-xf55-65pg-x58p/GHSA-xf55-65pg-x58p.json new file mode 100644 index 00000000000..c3f8cbb5bbf --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xf55-65pg-x58p/GHSA-xf55-65pg-x58p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf55-65pg-x58p", + "modified": "2024-01-03T09:30:30Z", + "published": "2024-01-03T09:30:30Z", + "aliases": [ + "CVE-2024-0211" + ], + "details": "DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0211" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19557" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2024-05.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-674" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xjpw-hx47-rccv/GHSA-xjpw-hx47-rccv.json b/advisories/unreviewed/2024/01/GHSA-xjpw-hx47-rccv/GHSA-xjpw-hx47-rccv.json new file mode 100644 index 00000000000..5260af32781 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xjpw-hx47-rccv/GHSA-xjpw-hx47-rccv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjpw-hx47-rccv", + "modified": "2024-01-03T09:30:31Z", + "published": "2024-01-03T09:30:31Z", + "aliases": [ + "CVE-2023-38674" + ], + "details": "FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38674" + }, + { + "type": "WEB", + "url": "https://github.com/PaddlePaddle/Paddle/blob/develop/security/advisory/pdsa-2023-006.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T09:15:08Z" + } +} \ No newline at end of file