diff --git a/advisories/unreviewed/2022/05/GHSA-jwrr-gwxm-fxhv/GHSA-jwrr-gwxm-fxhv.json b/advisories/unreviewed/2022/05/GHSA-jwrr-gwxm-fxhv/GHSA-jwrr-gwxm-fxhv.json index 9a66de2f68a..89dfe00890a 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwrr-gwxm-fxhv/GHSA-jwrr-gwxm-fxhv.json +++ b/advisories/unreviewed/2022/05/GHSA-jwrr-gwxm-fxhv/GHSA-jwrr-gwxm-fxhv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-r7j5-v5jg-987g/GHSA-r7j5-v5jg-987g.json b/advisories/unreviewed/2022/05/GHSA-r7j5-v5jg-987g/GHSA-r7j5-v5jg-987g.json index 7bc880cd8ea..1c39ed69541 100644 --- a/advisories/unreviewed/2022/05/GHSA-r7j5-v5jg-987g/GHSA-r7j5-v5jg-987g.json +++ b/advisories/unreviewed/2022/05/GHSA-r7j5-v5jg-987g/GHSA-r7j5-v5jg-987g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7j5-v5jg-987g", - "modified": "2022-05-24T17:34:31Z", + "modified": "2024-10-17T15:31:05Z", "published": "2022-05-24T17:34:31Z", "aliases": [ "CVE-2020-28129" ], "details": "Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rf6r-8jqg-grhq/GHSA-rf6r-8jqg-grhq.json b/advisories/unreviewed/2022/05/GHSA-rf6r-8jqg-grhq/GHSA-rf6r-8jqg-grhq.json index 3b30160ecf4..599b6c9ff16 100644 --- a/advisories/unreviewed/2022/05/GHSA-rf6r-8jqg-grhq/GHSA-rf6r-8jqg-grhq.json +++ b/advisories/unreviewed/2022/05/GHSA-rf6r-8jqg-grhq/GHSA-rf6r-8jqg-grhq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rf6r-8jqg-grhq", - "modified": "2022-05-24T17:35:16Z", + "modified": "2024-10-17T15:31:05Z", "published": "2022-05-24T17:35:16Z", "aliases": [ "CVE-2020-29288" ], "details": "An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vwrr-q8r4-3hgf/GHSA-vwrr-q8r4-3hgf.json b/advisories/unreviewed/2022/05/GHSA-vwrr-q8r4-3hgf/GHSA-vwrr-q8r4-3hgf.json index 8ae01a33b12..53a554bef37 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwrr-q8r4-3hgf/GHSA-vwrr-q8r4-3hgf.json +++ b/advisories/unreviewed/2022/05/GHSA-vwrr-q8r4-3hgf/GHSA-vwrr-q8r4-3hgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwrr-q8r4-3hgf", - "modified": "2022-05-14T01:35:48Z", + "modified": "2024-10-17T15:31:05Z", "published": "2022-05-14T01:35:48Z", "aliases": [ "CVE-2017-18356" diff --git a/advisories/unreviewed/2023/06/GHSA-frc9-g2r4-48w5/GHSA-frc9-g2r4-48w5.json b/advisories/unreviewed/2023/06/GHSA-frc9-g2r4-48w5/GHSA-frc9-g2r4-48w5.json index b5c3584e43d..edeb997ccee 100644 --- a/advisories/unreviewed/2023/06/GHSA-frc9-g2r4-48w5/GHSA-frc9-g2r4-48w5.json +++ b/advisories/unreviewed/2023/06/GHSA-frc9-g2r4-48w5/GHSA-frc9-g2r4-48w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frc9-g2r4-48w5", - "modified": "2024-04-04T05:01:28Z", + "modified": "2024-10-17T15:31:06Z", "published": "2023-06-22T21:30:48Z", "aliases": [ "CVE-2023-28799" @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1287", "CWE-20", "CWE-601" ], diff --git a/advisories/unreviewed/2023/08/GHSA-6p5j-fmww-gq26/GHSA-6p5j-fmww-gq26.json b/advisories/unreviewed/2023/08/GHSA-6p5j-fmww-gq26/GHSA-6p5j-fmww-gq26.json index b065f74f45c..714821cf882 100644 --- a/advisories/unreviewed/2023/08/GHSA-6p5j-fmww-gq26/GHSA-6p5j-fmww-gq26.json +++ b/advisories/unreviewed/2023/08/GHSA-6p5j-fmww-gq26/GHSA-6p5j-fmww-gq26.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-9jjw-9r7v-2x3g/GHSA-9jjw-9r7v-2x3g.json b/advisories/unreviewed/2023/08/GHSA-9jjw-9r7v-2x3g/GHSA-9jjw-9r7v-2x3g.json index b671ded66e6..5dc6c9091c7 100644 --- a/advisories/unreviewed/2023/08/GHSA-9jjw-9r7v-2x3g/GHSA-9jjw-9r7v-2x3g.json +++ b/advisories/unreviewed/2023/08/GHSA-9jjw-9r7v-2x3g/GHSA-9jjw-9r7v-2x3g.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json b/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json index 7ef16b4293b..4eb17beb01b 100644 --- a/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json +++ b/advisories/unreviewed/2023/10/GHSA-4pxq-qc65-2pqq/GHSA-4pxq-qc65-2pqq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-347" + "CWE-347", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json b/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json index 383212e5bbf..f5aead8291a 100644 --- a/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json +++ b/advisories/unreviewed/2023/10/GHSA-g99m-655w-j95w/GHSA-g99m-655w-j95w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json b/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json index 2e4c6fc18ab..5a5527c7787 100644 --- a/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json +++ b/advisories/unreviewed/2024/02/GHSA-4p3v-h475-6j2m/GHSA-4p3v-h475-6j2m.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json b/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json index c6ff4501673..de949eaf1b3 100644 --- a/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json +++ b/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvwm-qh2r-q68h", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-10-17T15:31:06Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2023-20570" ], "details": "Insufficient verification of data authenticity in\nthe configuration state machine may allow a local attacker to potentially load\narbitrary bitstreams.\n\n\n\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T18:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jr25-xhw2-xwv9/GHSA-jr25-xhw2-xwv9.json b/advisories/unreviewed/2024/02/GHSA-jr25-xhw2-xwv9/GHSA-jr25-xhw2-xwv9.json index 9f3abb01bfc..489c9e69013 100644 --- a/advisories/unreviewed/2024/02/GHSA-jr25-xhw2-xwv9/GHSA-jr25-xhw2-xwv9.json +++ b/advisories/unreviewed/2024/02/GHSA-jr25-xhw2-xwv9/GHSA-jr25-xhw2-xwv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jr25-xhw2-xwv9", - "modified": "2024-02-13T15:31:12Z", + "modified": "2024-10-17T15:31:06Z", "published": "2024-02-13T15:31:12Z", "aliases": [ "CVE-2024-23440" diff --git a/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json b/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json index 71d7ca998bc..39399c868f9 100644 --- a/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json +++ b/advisories/unreviewed/2024/02/GHSA-xvvw-m6mf-m9hw/GHSA-xvvw-m6mf-m9hw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xvvw-m6mf-m9hw", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-10-17T15:31:06Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2023-48432" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T16:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json b/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json index 69de12f0550..713561fb438 100644 --- a/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json +++ b/advisories/unreviewed/2024/03/GHSA-vrpp-jrqv-4gj2/GHSA-vrpp-jrqv-4gj2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-59" + "CWE-59", + "CWE-61" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-4vg2-58j7-gmw7/GHSA-4vg2-58j7-gmw7.json b/advisories/unreviewed/2024/04/GHSA-4vg2-58j7-gmw7/GHSA-4vg2-58j7-gmw7.json index c2fb68fb5f8..b3b92d493db 100644 --- a/advisories/unreviewed/2024/04/GHSA-4vg2-58j7-gmw7/GHSA-4vg2-58j7-gmw7.json +++ b/advisories/unreviewed/2024/04/GHSA-4vg2-58j7-gmw7/GHSA-4vg2-58j7-gmw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vg2-58j7-gmw7", - "modified": "2024-04-18T12:30:29Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-04-18T12:30:29Z", "aliases": [ "CVE-2024-26921" @@ -22,10 +22,18 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/18685451fc4e546fc0e718580d32df3c0e5c8272" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4318608dc28ef184158b4045896740716bea23f0" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/7d0567842b78390dd9b60f00f1d8f838d540e325" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9705f447bf9a6cd088300ad2c407b5e1c6591091" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/e09cbe017311508c21e0739e97198a8388b98981" diff --git a/advisories/unreviewed/2024/04/GHSA-5rcv-qpv8-9248/GHSA-5rcv-qpv8-9248.json b/advisories/unreviewed/2024/04/GHSA-5rcv-qpv8-9248/GHSA-5rcv-qpv8-9248.json index 602693dfd96..24ac5f0d34e 100644 --- a/advisories/unreviewed/2024/04/GHSA-5rcv-qpv8-9248/GHSA-5rcv-qpv8-9248.json +++ b/advisories/unreviewed/2024/04/GHSA-5rcv-qpv8-9248/GHSA-5rcv-qpv8-9248.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rcv-qpv8-9248", - "modified": "2024-06-26T00:31:37Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26885" @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/281d464a34f540de166cee74b723e97ac2515ec3" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b81a9f92b3676cb74b907a7a209b3d15bd9a7f9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c826502bed93970f2fd488918a7b8d5f1d30e2e3" diff --git a/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json b/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json index c380d66a874..68aaf2374e7 100644 --- a/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json +++ b/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx5c-hrvr-85gj", - "modified": "2024-10-10T12:31:11Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27072" @@ -22,10 +22,22 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3e7d82ebb86e94643bdb30b0b5b077ed27dce1c2" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ec4641df57cbdfdc51bb4959afcdbcf5003ddb9" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/65e6a2773d655172143cc0b927cdc89549842895" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bdd82c47b22a8befd617b723098b2a41b77373c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5ed208d04acf06781d63d30f9fa991e8d609ebd" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/dea46e246ef0f98d89d59a4229157cd9ffb636bf" diff --git a/advisories/unreviewed/2024/05/GHSA-g582-9mpv-vv22/GHSA-g582-9mpv-vv22.json b/advisories/unreviewed/2024/05/GHSA-g582-9mpv-vv22/GHSA-g582-9mpv-vv22.json index b716a288055..6f39ac7c2ed 100644 --- a/advisories/unreviewed/2024/05/GHSA-g582-9mpv-vv22/GHSA-g582-9mpv-vv22.json +++ b/advisories/unreviewed/2024/05/GHSA-g582-9mpv-vv22/GHSA-g582-9mpv-vv22.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g582-9mpv-vv22", - "modified": "2024-05-21T18:31:20Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52759" @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/4c6a08125f2249531ec01783a5f4317d7342add5" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50e33567bc4a1c4ed79a1d289fe93c9a26491848" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/53fc16c1ad84f5467ec24341670b63aa759335d3" diff --git a/advisories/unreviewed/2024/05/GHSA-qhh4-wrfh-w5pg/GHSA-qhh4-wrfh-w5pg.json b/advisories/unreviewed/2024/05/GHSA-qhh4-wrfh-w5pg/GHSA-qhh4-wrfh-w5pg.json index c7bb7eb1242..a98d9839bba 100644 --- a/advisories/unreviewed/2024/05/GHSA-qhh4-wrfh-w5pg/GHSA-qhh4-wrfh-w5pg.json +++ b/advisories/unreviewed/2024/05/GHSA-qhh4-wrfh-w5pg/GHSA-qhh4-wrfh-w5pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhh4-wrfh-w5pg", - "modified": "2024-09-30T15:30:43Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-05-01T06:31:43Z", "aliases": [ "CVE-2024-27017" @@ -33,10 +33,18 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/721715655c72640567e8742567520c99801148ed" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce9fef54c5ec9912a0c9a47bac3195cc41b14679" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f24d8abc2bb8cbf31ec713336e402eafa8f42f60" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff89db14c63a827066446460e39226c0688ef786" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53" diff --git a/advisories/unreviewed/2024/05/GHSA-qv2f-765q-7wrf/GHSA-qv2f-765q-7wrf.json b/advisories/unreviewed/2024/05/GHSA-qv2f-765q-7wrf/GHSA-qv2f-765q-7wrf.json index bdb222b4705..379dcff5667 100644 --- a/advisories/unreviewed/2024/05/GHSA-qv2f-765q-7wrf/GHSA-qv2f-765q-7wrf.json +++ b/advisories/unreviewed/2024/05/GHSA-qv2f-765q-7wrf/GHSA-qv2f-765q-7wrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qv2f-765q-7wrf", - "modified": "2024-10-10T12:31:11Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-05-20T12:30:28Z", "aliases": [ "CVE-2024-35963" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/50173882bb187e70e37bac01385b9b114019bee2" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/781f3a97a38a338bc893b6db7f9f9670bf1a9e37" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b2186061d6043d6345a97100460363e990af0d46" diff --git a/advisories/unreviewed/2024/05/GHSA-w79p-phhc-5r23/GHSA-w79p-phhc-5r23.json b/advisories/unreviewed/2024/05/GHSA-w79p-phhc-5r23/GHSA-w79p-phhc-5r23.json index a00ba67e04c..af47fd42f66 100644 --- a/advisories/unreviewed/2024/05/GHSA-w79p-phhc-5r23/GHSA-w79p-phhc-5r23.json +++ b/advisories/unreviewed/2024/05/GHSA-w79p-phhc-5r23/GHSA-w79p-phhc-5r23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w79p-phhc-5r23", - "modified": "2024-10-10T12:31:11Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-05-20T12:30:28Z", "aliases": [ "CVE-2024-35965" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/9d42f373391211c7c8af66a3a316533a32b8a607" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f13b04cf65a86507ff15a9bbf37969d25be3e2a0" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json b/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json index 1879d267561..e94b8677036 100644 --- a/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json +++ b/advisories/unreviewed/2024/06/GHSA-27fg-vf5m-qmjj/GHSA-27fg-vf5m-qmjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27fg-vf5m-qmjj", - "modified": "2024-09-09T15:30:37Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-06-21T12:31:21Z", "aliases": [ "CVE-2024-38632" @@ -32,6 +32,14 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/82b951e6fbd31d85ae7f4feb5f00ddd4c5d256e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91ced077db2062604ec270b1046f8337e9090079" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6d810554d7d9d07041f14c5fcd453f3d3fed594" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json b/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json index ac144535e45..f81f4f15105 100644 --- a/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json +++ b/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v6g-vfrc-9w8p", - "modified": "2024-09-10T09:31:11Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-39463" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39463" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3bb6763a8319170c2d41c4232c8e7e4c37dcacfb" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c898afdc15645efb555acb6d85b484eb40a45409" diff --git a/advisories/unreviewed/2024/06/GHSA-9fpr-g62f-647w/GHSA-9fpr-g62f-647w.json b/advisories/unreviewed/2024/06/GHSA-9fpr-g62f-647w/GHSA-9fpr-g62f-647w.json index 4ffdfd4a0d6..706f2500628 100644 --- a/advisories/unreviewed/2024/06/GHSA-9fpr-g62f-647w/GHSA-9fpr-g62f-647w.json +++ b/advisories/unreviewed/2024/06/GHSA-9fpr-g62f-647w/GHSA-9fpr-g62f-647w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fpr-g62f-647w", - "modified": "2024-09-19T15:30:48Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38588" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38588" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1880a324af1c95940a7c954b6b937e86844a33bd" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/31310e373f4c8c74e029d4326b283e757edabc0b" diff --git a/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json b/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json index 9aa973b21d6..2b317d94267 100644 --- a/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json +++ b/advisories/unreviewed/2024/06/GHSA-mqxf-7jx4-2h8p/GHSA-mqxf-7jx4-2h8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqxf-7jx4-2h8p", - "modified": "2024-06-19T15:30:52Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38544" @@ -34,6 +34,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/bbad88f111a1829f366c189aa48e7e58e57553fc" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de5a059e36657442b5637cc16df5163e435b9cb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0e14dd35d4242340c7346aac60c7ff8fbf87ffc" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/faa8d0ecf6c9c7c2ace3ca3e552180ada6f75e19" diff --git a/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json b/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json index fbc34653cec..129bd9a93ff 100644 --- a/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json +++ b/advisories/unreviewed/2024/06/GHSA-w738-qp3q-hrfg/GHSA-w738-qp3q-hrfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w738-qp3q-hrfg", - "modified": "2024-08-27T21:31:12Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-06-19T15:30:52Z", "aliases": [ "CVE-2024-38545" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38545" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/330c825e66ef65278e4ebe57fd49c1d6f3f4e34e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/37a7559dc1358a8d300437e99ed8ecdab0671507" diff --git a/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json b/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json index a81922a7ffd..02fa2b7433d 100644 --- a/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json +++ b/advisories/unreviewed/2024/07/GHSA-m487-w7jq-5grr/GHSA-m487-w7jq-5grr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m487-w7jq-5grr", - "modified": "2024-08-26T15:31:14Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-07-29T15:30:46Z", "aliases": [ "CVE-2024-41071" @@ -25,9 +25,17 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/2663d0462eb32ae7c9b035300ab6b1523886c718" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26b177ecdd311f20de4c379f0630858a675dfc0c" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/4f43a614b1b84f0d1e3c48cc541c3bfdf414a6d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2bb0c5d0086be5ab5054465dfaa381a1144905c" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json b/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json index 72b365cd7b7..32fbc24b4e8 100644 --- a/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json +++ b/advisories/unreviewed/2024/07/GHSA-r7gc-73mm-jqxm/GHSA-r7gc-73mm-jqxm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7gc-73mm-jqxm", - "modified": "2024-09-30T15:30:43Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-07-29T09:36:14Z", "aliases": [ "CVE-2024-41016" @@ -18,10 +18,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41016" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57a3d89831fcaa2cdbe024b47c7c36d5a56c3637" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/af77c4fc1871847b528d58b7fdafb4aa1f6a9262" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c031d286eceb82f72f8623b7f4abd2aa491bfb5e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c726dea9d0c806d64c26fcef483b1fb9474d8c5e" diff --git a/advisories/unreviewed/2024/08/GHSA-3xr6-pm2j-p9qj/GHSA-3xr6-pm2j-p9qj.json b/advisories/unreviewed/2024/08/GHSA-3xr6-pm2j-p9qj/GHSA-3xr6-pm2j-p9qj.json index 1a5911293f8..695f9b1510a 100644 --- a/advisories/unreviewed/2024/08/GHSA-3xr6-pm2j-p9qj/GHSA-3xr6-pm2j-p9qj.json +++ b/advisories/unreviewed/2024/08/GHSA-3xr6-pm2j-p9qj/GHSA-3xr6-pm2j-p9qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xr6-pm2j-p9qj", - "modified": "2024-08-21T00:30:30Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-08-21T00:30:30Z", "aliases": [ "CVE-2024-43866" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/1b75da22ed1e6171e261bc9265370162553d5393" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5005e2e159b300c1b8c6820a1e13a62eb0127b9b" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/6048dec754554a1303d632be6042d3feb3295285" diff --git a/advisories/unreviewed/2024/08/GHSA-5gj8-wg34-rgv9/GHSA-5gj8-wg34-rgv9.json b/advisories/unreviewed/2024/08/GHSA-5gj8-wg34-rgv9/GHSA-5gj8-wg34-rgv9.json index e331d692135..583ab9f90c4 100644 --- a/advisories/unreviewed/2024/08/GHSA-5gj8-wg34-rgv9/GHSA-5gj8-wg34-rgv9.json +++ b/advisories/unreviewed/2024/08/GHSA-5gj8-wg34-rgv9/GHSA-5gj8-wg34-rgv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gj8-wg34-rgv9", - "modified": "2024-09-12T18:31:39Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-08-21T09:31:32Z", "aliases": [ "CVE-2023-52904" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/a474d4ad59cd4642d1b7e3a6c08cef9eca0992c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f57204edc10760c935d8d36ea999dc8acf018030" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json b/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json index fda28395dac..b5eb507b99b 100644 --- a/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json +++ b/advisories/unreviewed/2024/08/GHSA-cxw8-j5f9-53mh/GHSA-cxw8-j5f9-53mh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxw8-j5f9-53mh", - "modified": "2024-09-30T15:30:43Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44931" @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/672c19165fc96dfad531a5458e0b3cdab414aae4" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d682e89c44bd5819b01f3fbb45a8e3681a4b6d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c65ab97efcd438cb4e9f299400f2ea55251f3a67" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/d776c0486b03a5c4afca65b8ff44573592bf93bb" diff --git a/advisories/unreviewed/2024/09/GHSA-2r8q-2j9h-3chh/GHSA-2r8q-2j9h-3chh.json b/advisories/unreviewed/2024/09/GHSA-2r8q-2j9h-3chh/GHSA-2r8q-2j9h-3chh.json index 7764ff5cc10..a8c803ffa19 100644 --- a/advisories/unreviewed/2024/09/GHSA-2r8q-2j9h-3chh/GHSA-2r8q-2j9h-3chh.json +++ b/advisories/unreviewed/2024/09/GHSA-2r8q-2j9h-3chh/GHSA-2r8q-2j9h-3chh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r8q-2j9h-3chh", - "modified": "2024-10-04T18:31:10Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46854" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46854" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f31f51bfc8214a6deaac2920e6342cb9d019133" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/34fcac26216ce17886af3eb392355b459367af1a" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38f5db5587c0ee53546b28c50ba128253181ac83" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0" diff --git a/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json b/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json index 5d6fe2d0240..8834254dbfd 100644 --- a/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json +++ b/advisories/unreviewed/2024/09/GHSA-4mm4-rvx3-h58h/GHSA-4mm4-rvx3-h58h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mm4-rvx3-h58h", - "modified": "2024-10-01T18:31:17Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46858" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46858" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e7814b028cd50b3ff79659d23dfa9da6a1e75e1" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/12134a652b0a10064844ea235173e70246eba6dc" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3554482f4691571fc4b5490c17ae26896e62171c" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/6452b162549c7f9ef54655d3fb9977b9192e6e5b" diff --git a/advisories/unreviewed/2024/09/GHSA-5793-wfxr-j725/GHSA-5793-wfxr-j725.json b/advisories/unreviewed/2024/09/GHSA-5793-wfxr-j725/GHSA-5793-wfxr-j725.json index 58767de289d..7a5d4810e2d 100644 --- a/advisories/unreviewed/2024/09/GHSA-5793-wfxr-j725/GHSA-5793-wfxr-j725.json +++ b/advisories/unreviewed/2024/09/GHSA-5793-wfxr-j725/GHSA-5793-wfxr-j725.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5793-wfxr-j725", - "modified": "2024-10-02T15:30:37Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46852" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46852" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/007180fcb6cc4a93211d4cc45fef3f5ccccd56ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79cce5e81d20fa9ad553be439d665ac3302d3c95" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/84175dc5b2c932266a50c04e5ce342c30f817a2f" diff --git a/advisories/unreviewed/2024/09/GHSA-7xv9-cqv7-wcpr/GHSA-7xv9-cqv7-wcpr.json b/advisories/unreviewed/2024/09/GHSA-7xv9-cqv7-wcpr/GHSA-7xv9-cqv7-wcpr.json index 922fb2e3fdc..5ac2b4bc325 100644 --- a/advisories/unreviewed/2024/09/GHSA-7xv9-cqv7-wcpr/GHSA-7xv9-cqv7-wcpr.json +++ b/advisories/unreviewed/2024/09/GHSA-7xv9-cqv7-wcpr/GHSA-7xv9-cqv7-wcpr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7xv9-cqv7-wcpr", - "modified": "2024-09-11T18:31:08Z", + "modified": "2024-10-17T15:31:07Z", "published": "2024-09-11T18:31:08Z", "aliases": [ "CVE-2024-8691" ], "details": "A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/09/GHSA-g97f-rj22-c2c5/GHSA-g97f-rj22-c2c5.json b/advisories/unreviewed/2024/09/GHSA-g97f-rj22-c2c5/GHSA-g97f-rj22-c2c5.json index eac21214cbc..de35344442e 100644 --- a/advisories/unreviewed/2024/09/GHSA-g97f-rj22-c2c5/GHSA-g97f-rj22-c2c5.json +++ b/advisories/unreviewed/2024/09/GHSA-g97f-rj22-c2c5/GHSA-g97f-rj22-c2c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g97f-rj22-c2c5", - "modified": "2024-10-02T15:30:37Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46849" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/4f9a71435953f941969a4f017e2357db62d85a86" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a2cc2bb81399e9ebc72560541137eb04d61dc3d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/7d318166bf55e9029d56997c3b134f4ac2ae2607" @@ -36,6 +40,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/e43364f578cdc2f8083abbc0cb743ea55e827c29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb0530025d502cb79d2b2801b14a9d5261833f1a" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-gjv7-5cpp-hqgw/GHSA-gjv7-5cpp-hqgw.json b/advisories/unreviewed/2024/09/GHSA-gjv7-5cpp-hqgw/GHSA-gjv7-5cpp-hqgw.json index 2a391599224..ae7611dcef5 100644 --- a/advisories/unreviewed/2024/09/GHSA-gjv7-5cpp-hqgw/GHSA-gjv7-5cpp-hqgw.json +++ b/advisories/unreviewed/2024/09/GHSA-gjv7-5cpp-hqgw/GHSA-gjv7-5cpp-hqgw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjv7-5cpp-hqgw", - "modified": "2024-10-04T18:31:09Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-13T09:30:32Z", "aliases": [ "CVE-2024-46710" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/0851b1ec650adadcaa23ec96daad95a55bf966f0" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58a3714db4d9dcaeb9fc4905141e17b9f536c0a5" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/aba07b9a0587f50e5d3346eaa19019cf3f86c0ea" diff --git a/advisories/unreviewed/2024/09/GHSA-jc8x-x899-862j/GHSA-jc8x-x899-862j.json b/advisories/unreviewed/2024/09/GHSA-jc8x-x899-862j/GHSA-jc8x-x899-862j.json index 92e475c0d01..c19c81c511a 100644 --- a/advisories/unreviewed/2024/09/GHSA-jc8x-x899-862j/GHSA-jc8x-x899-862j.json +++ b/advisories/unreviewed/2024/09/GHSA-jc8x-x899-862j/GHSA-jc8x-x899-862j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jc8x-x899-862j", - "modified": "2024-10-02T15:30:37Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46855" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/8b26ff7af8c32cb4148b3e147c52f9e4c695209c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddc7c423c4a5386bf865474c694b48178efd311a" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json b/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json index 452a8db6188..3e36af01a37 100644 --- a/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json +++ b/advisories/unreviewed/2024/09/GHSA-p594-vh26-gh4w/GHSA-p594-vh26-gh4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p594-vh26-gh4w", - "modified": "2024-09-19T18:30:51Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-13T06:30:43Z", "aliases": [ "CVE-2024-46695" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46695" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2dbc4b7bac60b02cc6e70d05bf6a7dfd551f9dda" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/459584258d47ec3cc6245a82e8a49c9d08eb8b57" @@ -29,9 +33,17 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/76a0e79bc84f466999fa501fce5bf7a07641b8a7" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eebec98791d0137e455cc006411bb92a54250924" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f71ec019257ba4f7ab198bd948c5902a207bad96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe0cd53791119f6287b6532af8ce41576d664930" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json b/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json index 840bd2eb695..37d14270088 100644 --- a/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json +++ b/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r56c-c546-6wvj", - "modified": "2024-10-03T18:30:35Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46859" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/b38c19783286a71693c2194ed1b36665168c09c4" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7c2f692307fe704be87ea80d7328782b33c3cef" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f52e98d16e9bd7dd2b3aef8e38db5cbc9899d6a4" diff --git a/advisories/unreviewed/2024/09/GHSA-whxc-gjg6-88q9/GHSA-whxc-gjg6-88q9.json b/advisories/unreviewed/2024/09/GHSA-whxc-gjg6-88q9/GHSA-whxc-gjg6-88q9.json index bb7cfc35615..0562d5c48c5 100644 --- a/advisories/unreviewed/2024/09/GHSA-whxc-gjg6-88q9/GHSA-whxc-gjg6-88q9.json +++ b/advisories/unreviewed/2024/09/GHSA-whxc-gjg6-88q9/GHSA-whxc-gjg6-88q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whxc-gjg6-88q9", - "modified": "2024-10-04T18:31:10Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46853" @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/2a8787c1cdc7be24fdd8953ecd1a8743a1006235" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/491f9646f7ac31af5fca71be1a3e5eb8aa7663ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/609260542cf86b459c57618b8cdec8020394b7ad" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/af9ca9ca3e44f48b2a191e100d452fbf850c3d87" diff --git a/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json b/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json index 9935d1773c3..d232e1d4582 100644 --- a/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json +++ b/advisories/unreviewed/2024/09/GHSA-x8x2-w2mg-gx8m/GHSA-x8x2-w2mg-gx8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8x2-w2mg-gx8m", - "modified": "2024-10-01T18:31:17Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46865" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46865" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16ff0895283058b0f96d4fe277aa25ee096f0ea8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/392f6a97fcbecc64f0c00058b2db5bb0e4b8cc3e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/4c8002277167125078e6b9b90137bdf443ebaa08" diff --git a/advisories/unreviewed/2024/10/GHSA-2822-72rm-gg4h/GHSA-2822-72rm-gg4h.json b/advisories/unreviewed/2024/10/GHSA-2822-72rm-gg4h/GHSA-2822-72rm-gg4h.json new file mode 100644 index 00000000000..64ee21e1edf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2822-72rm-gg4h/GHSA-2822-72rm-gg4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2822-72rm-gg4h", + "modified": "2024-10-17T15:31:09Z", + "published": "2024-10-17T15:31:09Z", + "aliases": [ + "CVE-2024-47459" + ], + "details": "Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47459" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-sampler/apsb24-65.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2cfj-58rp-82cv/GHSA-2cfj-58rp-82cv.json b/advisories/unreviewed/2024/10/GHSA-2cfj-58rp-82cv/GHSA-2cfj-58rp-82cv.json index 1f36bd39e02..8cf89de5df2 100644 --- a/advisories/unreviewed/2024/10/GHSA-2cfj-58rp-82cv/GHSA-2cfj-58rp-82cv.json +++ b/advisories/unreviewed/2024/10/GHSA-2cfj-58rp-82cv/GHSA-2cfj-58rp-82cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cfj-58rp-82cv", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-47673" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/5948a191906b54e10f02f6b7a7670243a39f99f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a15df5f37fa3a8b7a8ec7a339d1e897bc524e28f" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-2jrg-m6qw-2x74/GHSA-2jrg-m6qw-2x74.json b/advisories/unreviewed/2024/10/GHSA-2jrg-m6qw-2x74/GHSA-2jrg-m6qw-2x74.json new file mode 100644 index 00000000000..e08185dde26 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2jrg-m6qw-2x74/GHSA-2jrg-m6qw-2x74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jrg-m6qw-2x74", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-49579" + ], + "details": "In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49579" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-940" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3325-j24p-9883/GHSA-3325-j24p-9883.json b/advisories/unreviewed/2024/10/GHSA-3325-j24p-9883/GHSA-3325-j24p-9883.json new file mode 100644 index 00000000000..bd77a18a2c7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3325-j24p-9883/GHSA-3325-j24p-9883.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3325-j24p-9883", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2023-44283" + ], + "details": "\nIn Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code, in the Windows system context, and confined to that specific local PC.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44283" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000219086/dsa-2023-401-security-update-for-dell-supportassist-for-home-pcs-and-dell-supportassist-for-business-pcs-user-interface-component" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-36rg-c62m-gwmx/GHSA-36rg-c62m-gwmx.json b/advisories/unreviewed/2024/10/GHSA-36rg-c62m-gwmx/GHSA-36rg-c62m-gwmx.json new file mode 100644 index 00000000000..c1f668c9aa6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-36rg-c62m-gwmx/GHSA-36rg-c62m-gwmx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36rg-c62m-gwmx", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2024-23783" + ], + "details": "Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23783" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3832-qfwh-78wc/GHSA-3832-qfwh-78wc.json b/advisories/unreviewed/2024/10/GHSA-3832-qfwh-78wc/GHSA-3832-qfwh-78wc.json new file mode 100644 index 00000000000..a377fa3b952 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3832-qfwh-78wc/GHSA-3832-qfwh-78wc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3832-qfwh-78wc", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48032" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48032" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/featured-posts-with-multiple-custom-groups-fpmcg/wordpress-featured-posts-with-multiple-custom-groups-fpmcg-plugin-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3gwg-p922-8p2m/GHSA-3gwg-p922-8p2m.json b/advisories/unreviewed/2024/10/GHSA-3gwg-p922-8p2m/GHSA-3gwg-p922-8p2m.json index 3eabe3e0fcc..7342d0becca 100644 --- a/advisories/unreviewed/2024/10/GHSA-3gwg-p922-8p2m/GHSA-3gwg-p922-8p2m.json +++ b/advisories/unreviewed/2024/10/GHSA-3gwg-p922-8p2m/GHSA-3gwg-p922-8p2m.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3gwg-p922-8p2m", - "modified": "2024-10-10T18:31:09Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-10T18:31:08Z", "aliases": [ "CVE-2024-47963" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-3qw9-56c9-wgjp/GHSA-3qw9-56c9-wgjp.json b/advisories/unreviewed/2024/10/GHSA-3qw9-56c9-wgjp/GHSA-3qw9-56c9-wgjp.json new file mode 100644 index 00000000000..a8f760702cf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3qw9-56c9-wgjp/GHSA-3qw9-56c9-wgjp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qw9-56c9-wgjp", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2023-44294" + ], + "details": "\nIn Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API. \nThis issue may potentially lead to unintentional information disclosure from the product database.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44294" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000219372/dsa-2023-403-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T09:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3w4c-53gw-r9pv/GHSA-3w4c-53gw-r9pv.json b/advisories/unreviewed/2024/10/GHSA-3w4c-53gw-r9pv/GHSA-3w4c-53gw-r9pv.json index 1fedbf9a0da..827149386db 100644 --- a/advisories/unreviewed/2024/10/GHSA-3w4c-53gw-r9pv/GHSA-3w4c-53gw-r9pv.json +++ b/advisories/unreviewed/2024/10/GHSA-3w4c-53gw-r9pv/GHSA-3w4c-53gw-r9pv.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w4c-53gw-r9pv", - "modified": "2024-10-10T18:31:09Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-10T18:31:09Z", "aliases": [ "CVE-2024-47966" ], "details": "Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-4qgw-h7j9-pwq4/GHSA-4qgw-h7j9-pwq4.json b/advisories/unreviewed/2024/10/GHSA-4qgw-h7j9-pwq4/GHSA-4qgw-h7j9-pwq4.json new file mode 100644 index 00000000000..e045950547f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4qgw-h7j9-pwq4/GHSA-4qgw-h7j9-pwq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qgw-h7j9-pwq4", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2023-25535" + ], + "details": "\nDell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25535" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000211410/dell-supportassist-for-home-pcs-security-update-for-installer-executable-file-for-local-privilege-escalation-lpe-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4rf2-7phj-4vwq/GHSA-4rf2-7phj-4vwq.json b/advisories/unreviewed/2024/10/GHSA-4rf2-7phj-4vwq/GHSA-4rf2-7phj-4vwq.json index b6ed51b1df2..33af654e98f 100644 --- a/advisories/unreviewed/2024/10/GHSA-4rf2-7phj-4vwq/GHSA-4rf2-7phj-4vwq.json +++ b/advisories/unreviewed/2024/10/GHSA-4rf2-7phj-4vwq/GHSA-4rf2-7phj-4vwq.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-456" + "CWE-456", + "CWE-909" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json b/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json index 802df133bd2..ad5fc2d6dd1 100644 --- a/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json +++ b/advisories/unreviewed/2024/10/GHSA-587p-xc7x-rjh8/GHSA-587p-xc7x-rjh8.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5hrh-4r6p-g563/GHSA-5hrh-4r6p-g563.json b/advisories/unreviewed/2024/10/GHSA-5hrh-4r6p-g563/GHSA-5hrh-4r6p-g563.json new file mode 100644 index 00000000000..31701261efd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5hrh-4r6p-g563/GHSA-5hrh-4r6p-g563.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hrh-4r6p-g563", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-49315" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49315" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/free-download-manager/wordpress-free-download-manager-plugin-1-0-0-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5pp3-77xw-wmg5/GHSA-5pp3-77xw-wmg5.json b/advisories/unreviewed/2024/10/GHSA-5pp3-77xw-wmg5/GHSA-5pp3-77xw-wmg5.json new file mode 100644 index 00000000000..157d45090ef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5pp3-77xw-wmg5/GHSA-5pp3-77xw-wmg5.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pp3-77xw-wmg5", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2005-10003" + ], + "details": "A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.3 is able to address this issue. The patch is named 6ed8e3cc336e29f09c7e791863d0559939da98bf. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-10003" + }, + { + "type": "WEB", + "url": "https://github.com/mikexstudios/xcomic/commit/6ed8e3cc336e29f09c7e791863d0559939da98bf" + }, + { + "type": "WEB", + "url": "https://github.com/mikexstudios/xcomic/releases/tag/v0.8.3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280359" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280359" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20071218144304/http://xcomic.mikexstudios.com/forum/viewtopic.php?id=130" + }, + { + "type": "WEB", + "url": "http://xcomic.mikexstudios.com/forum/viewtopic.php?id=130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T14:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8p54-hh75-4mh9/GHSA-8p54-hh75-4mh9.json b/advisories/unreviewed/2024/10/GHSA-8p54-hh75-4mh9/GHSA-8p54-hh75-4mh9.json index bab88c77aa2..83c62f50842 100644 --- a/advisories/unreviewed/2024/10/GHSA-8p54-hh75-4mh9/GHSA-8p54-hh75-4mh9.json +++ b/advisories/unreviewed/2024/10/GHSA-8p54-hh75-4mh9/GHSA-8p54-hh75-4mh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8p54-hh75-4mh9", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-47672" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47672" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1afed66cb271b3e65fe9df1c9fba2bf4b1f55669" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/1b0cd832c9607f41f84053b818e0b7908510a3b9" @@ -33,6 +37,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/7188b7a72320367554b76d8f298417b070b05dd3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de46b1d24f5f752b3bd8b46673c2ea4239661244" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-8qv4-773j-c979/GHSA-8qv4-773j-c979.json b/advisories/unreviewed/2024/10/GHSA-8qv4-773j-c979/GHSA-8qv4-773j-c979.json new file mode 100644 index 00000000000..b474d20db12 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8qv4-773j-c979/GHSA-8qv4-773j-c979.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qv4-773j-c979", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-49580" + ], + "details": "In JetBrains Ktor before 3.0.0 improper caching in HttpCache Plugin could lead to response information disclosure", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49580" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-524" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8xf6-75qf-44g2/GHSA-8xf6-75qf-44g2.json b/advisories/unreviewed/2024/10/GHSA-8xf6-75qf-44g2/GHSA-8xf6-75qf-44g2.json new file mode 100644 index 00000000000..6552a9e41b3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8xf6-75qf-44g2/GHSA-8xf6-75qf-44g2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xf6-75qf-44g2", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-6333" + ], + "details": "Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6333" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2024/10/Xerox-Security-Bulletin-XRX24-015-for-Altalink-Versalink-and-WorkCentre-%E2%80%93-CVE-2024-6333-.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json b/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json index f9b9ec9334a..b55dcd631d1 100644 --- a/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json +++ b/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-9qmh-x5w7-v2h6/GHSA-9qmh-x5w7-v2h6.json b/advisories/unreviewed/2024/10/GHSA-9qmh-x5w7-v2h6/GHSA-9qmh-x5w7-v2h6.json new file mode 100644 index 00000000000..d5caa1b0b5a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9qmh-x5w7-v2h6/GHSA-9qmh-x5w7-v2h6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qmh-x5w7-v2h6", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48022" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics Shortcode For Elementor Templates allows Stored XSS.This issue affects Shortcode For Elementor Templates: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48022" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-support-for-elementor-templates/wordpress-shortcode-for-elementor-templates-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json b/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json index 74d5db721cb..53c62e5ecca 100644 --- a/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json +++ b/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-c9g5-fph2-vp88/GHSA-c9g5-fph2-vp88.json b/advisories/unreviewed/2024/10/GHSA-c9g5-fph2-vp88/GHSA-c9g5-fph2-vp88.json new file mode 100644 index 00000000000..6f672a0211e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c9g5-fph2-vp88/GHSA-c9g5-fph2-vp88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9g5-fph2-vp88", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48037" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48037" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/new-contact-form-widget/wordpress-contact-form-widget-contact-query-contact-page-form-maker-query-table-plugin-1-4-2-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json b/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json new file mode 100644 index 00000000000..dd2fe3f83a8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cj3p-4jrq-mg7x/GHSA-cj3p-4jrq-mg7x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj3p-4jrq-mg7x", + "modified": "2024-10-17T15:31:09Z", + "published": "2024-10-17T15:31:09Z", + "aliases": [ + "CVE-2024-9683" + ], + "details": "A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement.  While the risk is relatively low due to the typical length of the passwords used (73 characters), this vulnerability can still be exploited to reduce the complexity of brute-force or password-guessing attacks. The truncation of passwords weakens the overall authentication process, thereby reducing the effectiveness of password policies and potentially increasing the risk of unauthorized access in the future.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9683" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9683" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317559" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f6rr-r6cw-c7wh/GHSA-f6rr-r6cw-c7wh.json b/advisories/unreviewed/2024/10/GHSA-f6rr-r6cw-c7wh/GHSA-f6rr-r6cw-c7wh.json index adf0aeb69b2..3dd0bd98ee6 100644 --- a/advisories/unreviewed/2024/10/GHSA-f6rr-r6cw-c7wh/GHSA-f6rr-r6cw-c7wh.json +++ b/advisories/unreviewed/2024/10/GHSA-f6rr-r6cw-c7wh/GHSA-f6rr-r6cw-c7wh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6rr-r6cw-c7wh", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-47671" @@ -18,6 +18,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47671" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c927dfc0b9bd177f7ab6ee59ef0c4ea06c110a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16e0ab9ed3ae7d19ca8ee718ba4e09d5c0f909ca" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/51297ef7ad7824ad577337f273cd092e81a9fa08" diff --git a/advisories/unreviewed/2024/10/GHSA-frhx-fj3p-cwfc/GHSA-frhx-fj3p-cwfc.json b/advisories/unreviewed/2024/10/GHSA-frhx-fj3p-cwfc/GHSA-frhx-fj3p-cwfc.json new file mode 100644 index 00000000000..fb37ba5f1ae --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-frhx-fj3p-cwfc/GHSA-frhx-fj3p-cwfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frhx-fj3p-cwfc", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48046" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Supsystic Contact Form by Supsystic allows Stored XSS.This issue affects Contact Form by Supsystic: from n/a through 1.7.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48046" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-by-supsystic/wordpress-contact-form-by-supsystic-plugin-1-7-28-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fw32-766m-2448/GHSA-fw32-766m-2448.json b/advisories/unreviewed/2024/10/GHSA-fw32-766m-2448/GHSA-fw32-766m-2448.json new file mode 100644 index 00000000000..960cf83a05d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fw32-766m-2448/GHSA-fw32-766m-2448.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw32-766m-2448", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2024-23784" + ], + "details": "Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page of the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23784" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g6jf-r72q-jg8c/GHSA-g6jf-r72q-jg8c.json b/advisories/unreviewed/2024/10/GHSA-g6jf-r72q-jg8c/GHSA-g6jf-r72q-jg8c.json new file mode 100644 index 00000000000..0a426441e2c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g6jf-r72q-jg8c/GHSA-g6jf-r72q-jg8c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6jf-r72q-jg8c", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2023-39249" + ], + "details": "\nDell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System Administrators to perform driver scans and Dell-recommended driver installations without requiring them to log out of the local non-admin user session. However, the granted privilege is limited solely to the SupportAssist User Interface and automatically expires after 15 minutes.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39249" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000216574/security-update-for-dell-supportassist-for-business-pcs-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h54j-5f6g-862r/GHSA-h54j-5f6g-862r.json b/advisories/unreviewed/2024/10/GHSA-h54j-5f6g-862r/GHSA-h54j-5f6g-862r.json new file mode 100644 index 00000000000..30fef240e14 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h54j-5f6g-862r/GHSA-h54j-5f6g-862r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h54j-5f6g-862r", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48031" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Cross Site Request Forgery.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48031" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/featured-posts-with-multiple-custom-groups-fpmcg/wordpress-featured-posts-with-multiple-custom-groups-fpmcg-plugin-4-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hw37-q237-42x3/GHSA-hw37-q237-42x3.json b/advisories/unreviewed/2024/10/GHSA-hw37-q237-42x3/GHSA-hw37-q237-42x3.json index 54c02e17355..51a71cba7e8 100644 --- a/advisories/unreviewed/2024/10/GHSA-hw37-q237-42x3/GHSA-hw37-q237-42x3.json +++ b/advisories/unreviewed/2024/10/GHSA-hw37-q237-42x3/GHSA-hw37-q237-42x3.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hw37-q237-42x3", - "modified": "2024-10-10T18:31:08Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-10T18:31:08Z", "aliases": [ "CVE-2024-47962" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-j4rw-pwh3-9p7x/GHSA-j4rw-pwh3-9p7x.json b/advisories/unreviewed/2024/10/GHSA-j4rw-pwh3-9p7x/GHSA-j4rw-pwh3-9p7x.json new file mode 100644 index 00000000000..69941834716 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j4rw-pwh3-9p7x/GHSA-j4rw-pwh3-9p7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4rw-pwh3-9p7x", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48021" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48021" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-7-paypal-add-on/wordpress-contact-form-7-paypal-stripe-add-on-plugin-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json b/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json index ea6303d4cbd..926cf5040b6 100644 --- a/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json +++ b/advisories/unreviewed/2024/10/GHSA-j6xh-hx47-7x23/GHSA-j6xh-hx47-7x23.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-jj89-j5vx-25mf/GHSA-jj89-j5vx-25mf.json b/advisories/unreviewed/2024/10/GHSA-jj89-j5vx-25mf/GHSA-jj89-j5vx-25mf.json new file mode 100644 index 00000000000..4a3b4eed83f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jj89-j5vx-25mf/GHSA-jj89-j5vx-25mf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj89-j5vx-25mf", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48048" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WSIFY – Sales can fly Wsify Widget allows Stored XSS.This issue affects Wsify Widget: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48048" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wsify-widget/wordpress-wsify-widget-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json b/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json index 7da88028128..3a80da2e1af 100644 --- a/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json +++ b/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-mgxj-q65h-43hg/GHSA-mgxj-q65h-43hg.json b/advisories/unreviewed/2024/10/GHSA-mgxj-q65h-43hg/GHSA-mgxj-q65h-43hg.json new file mode 100644 index 00000000000..d71c9472d1f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mgxj-q65h-43hg/GHSA-mgxj-q65h-43hg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgxj-q65h-43hg", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2024-23785" + ], + "details": "Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23785" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mj6q-w4f8-2m48/GHSA-mj6q-w4f8-2m48.json b/advisories/unreviewed/2024/10/GHSA-mj6q-w4f8-2m48/GHSA-mj6q-w4f8-2m48.json index 170a8284534..e5094dc89a4 100644 --- a/advisories/unreviewed/2024/10/GHSA-mj6q-w4f8-2m48/GHSA-mj6q-w4f8-2m48.json +++ b/advisories/unreviewed/2024/10/GHSA-mj6q-w4f8-2m48/GHSA-mj6q-w4f8-2m48.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj6q-w4f8-2m48", - "modified": "2024-10-10T18:31:08Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-10T18:31:08Z", "aliases": [ "CVE-2024-47965" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json b/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json index bef40aa7e6d..20255ca1e9f 100644 --- a/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json +++ b/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json b/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json index 51efc15b303..a29cfd3bda5 100644 --- a/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json +++ b/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwp3-45p3-xq9x", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-43685" ], "details": "Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json b/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json index 81551526607..5690c929a3b 100644 --- a/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json +++ b/advisories/unreviewed/2024/10/GHSA-p8rh-8mh7-w4xh/GHSA-p8rh-8mh7-w4xh.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-q7mw-gxpm-rgh5/GHSA-q7mw-gxpm-rgh5.json b/advisories/unreviewed/2024/10/GHSA-q7mw-gxpm-rgh5/GHSA-q7mw-gxpm-rgh5.json index b2c36e56ea9..3a9827b0326 100644 --- a/advisories/unreviewed/2024/10/GHSA-q7mw-gxpm-rgh5/GHSA-q7mw-gxpm-rgh5.json +++ b/advisories/unreviewed/2024/10/GHSA-q7mw-gxpm-rgh5/GHSA-q7mw-gxpm-rgh5.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7mw-gxpm-rgh5", - "modified": "2024-10-10T18:31:09Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-10T18:31:09Z", "aliases": [ "CVE-2024-47964" ], "details": "Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json b/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json new file mode 100644 index 00000000000..776c85e4177 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q7v6-v4wg-h8m2/GHSA-q7v6-v4wg-h8m2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7v6-v4wg-h8m2", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2023-6728" + ], + "details": "Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6728" + }, + { + "type": "WEB", + "url": "https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2023-6728" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json b/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json index e858f436276..5a688bd8033 100644 --- a/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json +++ b/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjwp-794r-6x7v", - "modified": "2024-10-15T12:30:37Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-15T12:30:37Z", "aliases": [ "CVE-2024-47674" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47674" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b2c8b34f6d76bfbd1dd4936eb8a0fbfb9af3959" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/65d0db500d7c07f0f76fc24a4d837791c4862cd2" diff --git a/advisories/unreviewed/2024/10/GHSA-qvvj-m5ww-3hcj/GHSA-qvvj-m5ww-3hcj.json b/advisories/unreviewed/2024/10/GHSA-qvvj-m5ww-3hcj/GHSA-qvvj-m5ww-3hcj.json index 4b54a171f24..3ca150b7905 100644 --- a/advisories/unreviewed/2024/10/GHSA-qvvj-m5ww-3hcj/GHSA-qvvj-m5ww-3hcj.json +++ b/advisories/unreviewed/2024/10/GHSA-qvvj-m5ww-3hcj/GHSA-qvvj-m5ww-3hcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvvj-m5ww-3hcj", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-47670" @@ -22,6 +22,14 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/1f6e167d6753fe3ea493cdc7f7de8d03147a4d39" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34759b7e4493d7337cbc414c132cef378c492a2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5bbe51eaf01a5dd6fb3f0dea81791e5dbc6dc6dd" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8e7bef408261746c160853fc27df3139659f5f77" diff --git a/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json b/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json index 6dbfeaea8cb..ad03d7a869e 100644 --- a/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json +++ b/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-r3fh-rp7c-vq3c/GHSA-r3fh-rp7c-vq3c.json b/advisories/unreviewed/2024/10/GHSA-r3fh-rp7c-vq3c/GHSA-r3fh-rp7c-vq3c.json new file mode 100644 index 00000000000..817f5b51e3c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r3fh-rp7c-vq3c/GHSA-r3fh-rp7c-vq3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3fh-rp7c-vq3c", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48025" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DOGROW.NET Simple Baseball Scoreboard allows Stored XSS.This issue affects Simple Baseball Scoreboard: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48025" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-baseball-scoreboard/wordpress-simple-baseball-scoreboard-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rj4v-9qwv-36p2/GHSA-rj4v-9qwv-36p2.json b/advisories/unreviewed/2024/10/GHSA-rj4v-9qwv-36p2/GHSA-rj4v-9qwv-36p2.json index a6954fcabf0..e8c08155d1e 100644 --- a/advisories/unreviewed/2024/10/GHSA-rj4v-9qwv-36p2/GHSA-rj4v-9qwv-36p2.json +++ b/advisories/unreviewed/2024/10/GHSA-rj4v-9qwv-36p2/GHSA-rj4v-9qwv-36p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rj4v-9qwv-36p2", - "modified": "2024-10-16T18:31:47Z", + "modified": "2024-10-17T15:31:08Z", "published": "2024-10-16T18:31:47Z", "aliases": [ "CVE-2024-46606" ], "details": "A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json b/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json new file mode 100644 index 00000000000..e08292a1c5d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vfh3-c3xr-qw22/GHSA-vfh3-c3xr-qw22.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfh3-c3xr-qw22", + "modified": "2024-10-17T15:31:09Z", + "published": "2024-10-17T15:31:09Z", + "aliases": [ + "CVE-2024-10069" + ], + "details": "A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actionPassMainApplication of the file /com/esafenet/servlet/client/MailDecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10069" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/20a4440e-1268-4df1-ab95-8583b450b7c4?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280718" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280718" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.419869" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vgxw-m868-jgjx/GHSA-vgxw-m868-jgjx.json b/advisories/unreviewed/2024/10/GHSA-vgxw-m868-jgjx/GHSA-vgxw-m868-jgjx.json new file mode 100644 index 00000000000..89753906837 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vgxw-m868-jgjx/GHSA-vgxw-m868-jgjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgxw-m868-jgjx", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48023" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RestaurantConnect, Inc Restaurant Reservations Widget allows Reflected XSS.This issue affects Restaurant Reservations Widget: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48023" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/restaurantconnect-reswidget/wordpress-restaurant-reservations-widget-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w34f-v8wf-pvqj/GHSA-w34f-v8wf-pvqj.json b/advisories/unreviewed/2024/10/GHSA-w34f-v8wf-pvqj/GHSA-w34f-v8wf-pvqj.json new file mode 100644 index 00000000000..3df4d7fefc6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w34f-v8wf-pvqj/GHSA-w34f-v8wf-pvqj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w34f-v8wf-pvqj", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2024-23786" + ], + "details": "Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23786" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w9wx-g7f2-2m32/GHSA-w9wx-g7f2-2m32.json b/advisories/unreviewed/2024/10/GHSA-w9wx-g7f2-2m32/GHSA-w9wx-g7f2-2m32.json new file mode 100644 index 00000000000..9586832ea98 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w9wx-g7f2-2m32/GHSA-w9wx-g7f2-2m32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9wx-g7f2-2m32", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2024-48036" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48036" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/skt-blocks/wordpress-skt-blocks-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json b/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json index 76282f94679..b04a1dde0e3 100644 --- a/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json +++ b/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json b/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json new file mode 100644 index 00000000000..dee43ce6135 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wmqp-549h-p884/GHSA-wmqp-549h-p884.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmqp-549h-p884", + "modified": "2024-10-17T15:31:08Z", + "published": "2024-10-17T15:31:08Z", + "aliases": [ + "CVE-2023-6729" + ], + "details": "Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with \"access console.\" Consequently, a low privilege authenticated user with \"access console\" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of service of the router after the system is rebooted.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6729" + }, + { + "type": "WEB", + "url": "https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2023-6729" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json b/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json index b056807b151..3cdb9e4f4be 100644 --- a/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json +++ b/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-xrcr-vp89-pv9v/GHSA-xrcr-vp89-pv9v.json b/advisories/unreviewed/2024/10/GHSA-xrcr-vp89-pv9v/GHSA-xrcr-vp89-pv9v.json new file mode 100644 index 00000000000..c0d6594cb3b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xrcr-vp89-pv9v/GHSA-xrcr-vp89-pv9v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrcr-vp89-pv9v", + "modified": "2024-10-17T15:31:07Z", + "published": "2024-10-17T15:31:07Z", + "aliases": [ + "CVE-2023-44293" + ], + "details": "\nIn Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44293" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000219372/dsa-2023-403-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json b/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json new file mode 100644 index 00000000000..500269ece40 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xw6g-7x68-mrj2/GHSA-xw6g-7x68-mrj2.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw6g-7x68-mrj2", + "modified": "2024-10-17T15:31:09Z", + "published": "2024-10-17T15:31:09Z", + "aliases": [ + "CVE-2024-10070" + ], + "details": "A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10070" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/b2afb61c-cdbe-4303-b799-f7c82a9643fb?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280719" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280719" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.419870" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-17T15:15:13Z" + } +} \ No newline at end of file