diff --git a/advisories/unreviewed/2024/04/GHSA-4262-7rxm-xfp7/GHSA-4262-7rxm-xfp7.json b/advisories/unreviewed/2024/04/GHSA-4262-7rxm-xfp7/GHSA-4262-7rxm-xfp7.json new file mode 100644 index 00000000000..dbd6e2523ef --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4262-7rxm-xfp7/GHSA-4262-7rxm-xfp7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4262-7rxm-xfp7", + "modified": "2024-04-03T09:30:32Z", + "published": "2024-04-03T09:30:32Z", + "aliases": [ + "CVE-2024-28515" + ], + "details": "Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28515" + }, + { + "type": "WEB", + "url": "https://gist.github.com/heshi906/090b647a76981b8aa621e99fd6e1795d" + }, + { + "type": "WEB", + "url": "https://github.com/heshi906/CVE-2024-28515" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T07:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json b/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json new file mode 100644 index 00000000000..625de665740 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-597x-4hfr-67c4/GHSA-597x-4hfr-67c4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-597x-4hfr-67c4", + "modified": "2024-04-03T09:30:32Z", + "published": "2024-04-03T09:30:32Z", + "aliases": [ + "CVE-2024-24506" + ], + "details": "Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24506" + }, + { + "type": "WEB", + "url": "https://bugs.limesurvey.org/bug_relationship_graph.php?bug_id=19364&graph=relation" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/51926" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T07:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6xj8-67w9-54rv/GHSA-6xj8-67w9-54rv.json b/advisories/unreviewed/2024/04/GHSA-6xj8-67w9-54rv/GHSA-6xj8-67w9-54rv.json new file mode 100644 index 00000000000..84f9e308842 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6xj8-67w9-54rv/GHSA-6xj8-67w9-54rv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xj8-67w9-54rv", + "modified": "2024-04-03T09:30:33Z", + "published": "2024-04-03T09:30:33Z", + "aliases": [ + "CVE-2024-28589" + ], + "details": "An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28589" + }, + { + "type": "WEB", + "url": "https://www.axigen.com/knowledgebase/Local-Privilege-Escalation-Vulnerability-on-Axigen-for-Windows-CVE-2024-28589-_402.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T08:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json b/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json new file mode 100644 index 00000000000..daa04430aa8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjfc-48h7-67x9", + "modified": "2024-04-03T09:30:33Z", + "published": "2024-04-03T09:30:33Z", + "aliases": [ + "CVE-2024-29734" + ], + "details": "Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29734" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN40367518" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T08:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json b/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json new file mode 100644 index 00000000000..af500f60dad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfh5-9vgh-ffpg", + "modified": "2024-04-03T09:30:32Z", + "published": "2024-04-03T09:30:32Z", + "aliases": [ + "CVE-2023-35764" + ], + "details": "Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35764" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN51098626" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/survey-maker" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T08:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json b/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json new file mode 100644 index 00000000000..971deac8060 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-ph95-6589-h2hv/GHSA-ph95-6589-h2hv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph95-6589-h2hv", + "modified": "2024-04-03T09:30:32Z", + "published": "2024-04-03T09:30:32Z", + "aliases": [ + "CVE-2023-34423" + ], + "details": "Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34423" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN51098626" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/survey-maker" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T08:15:48Z" + } +} \ No newline at end of file