diff --git a/advisories/unreviewed/2023/12/GHSA-w6ww-869j-cgm6/GHSA-w6ww-869j-cgm6.json b/advisories/unreviewed/2023/12/GHSA-w6ww-869j-cgm6/GHSA-w6ww-869j-cgm6.json index a63fa92d5fd..cd71602e9d7 100644 --- a/advisories/unreviewed/2023/12/GHSA-w6ww-869j-cgm6/GHSA-w6ww-869j-cgm6.json +++ b/advisories/unreviewed/2023/12/GHSA-w6ww-869j-cgm6/GHSA-w6ww-869j-cgm6.json @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://git.exim.org/exim.git/commit/cf1376206284f2a4f11e32d931d4aade34c206c5" }, + { + "type": "WEB", + "url": "https://github.com/Exim/exim/blob/master/doc/doc-txt/cve-2023-51766" + }, { "type": "WEB", "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/" @@ -61,6 +65,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/12/29/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/01/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-fqfx-v8f6-cc7c/GHSA-fqfx-v8f6-cc7c.json b/advisories/unreviewed/2024/01/GHSA-fqfx-v8f6-cc7c/GHSA-fqfx-v8f6-cc7c.json new file mode 100644 index 00000000000..8fc1c0ae443 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fqfx-v8f6-cc7c/GHSA-fqfx-v8f6-cc7c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqfx-v8f6-cc7c", + "modified": "2024-01-01T18:30:25Z", + "published": "2024-01-01T18:30:25Z", + "aliases": [ + "CVE-2024-0181" + ], + "details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin_user.php of the component Admin Panel. The manipulation of the argument Firstname/Lastname/Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249433 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0181" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/3Yc2iRzY#Uv7ECzLwUvff__JXEcyPG9oxJ0A1fsBIFGVaS35pvtA" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249433" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249433" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-01T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json b/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json new file mode 100644 index 00000000000..e214c2a2f7a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pjh6-2v65-x4fj/GHSA-pjh6-2v65-x4fj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjh6-2v65-x4fj", + "modified": "2024-01-01T18:30:25Z", + "published": "2024-01-01T18:30:25Z", + "aliases": [ + "CVE-2023-50096" + ], + "details": "STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50096" + }, + { + "type": "WEB", + "url": "https://github.com/elttam/publications/blob/master/writeups/CVE-2023-50096.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-01T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json b/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json new file mode 100644 index 00000000000..ed426bf1179 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfhc-4q79-wvf9", + "modified": "2024-01-01T18:30:25Z", + "published": "2024-01-01T18:30:25Z", + "aliases": [ + "CVE-2023-50094" + ], + "details": "reNgine through 2.0.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50094" + }, + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/blob/5e120bd5f9dfbd1da82a193e8c9702e483d38d22/web/api/views.py#L195" + }, + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/releases" + }, + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/security" + }, + { + "type": "WEB", + "url": "https://www.mattz.io/posts/cve-2023-50094/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-01T18:15:09Z" + } +} \ No newline at end of file