From ec92b1069680e1da3fd9aed5e9121f1e7a4489b0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 4 Mar 2024 12:32:32 +0000 Subject: [PATCH] Publish Advisories GHSA-3w2j-mvmp-4vx3 GHSA-4crg-cmgg-hmf6 GHSA-6299-m9xc-vxvj GHSA-82gf-5hq2-6g45 GHSA-88qq-vr7f-76wp GHSA-9fv2-j4fg-6v4w GHSA-f279-w6jr-7xxj GHSA-f2j2-g4wg-mxr5 GHSA-f3xr-vc85-7grj GHSA-fvc8-q78j-c743 GHSA-hfr9-gm39-p2g7 GHSA-j5r8-f5xj-3h83 GHSA-jghx-2c7v-jjmc GHSA-p8vw-h7rx-fgxr GHSA-p9qx-8g2v-c964 GHSA-prf2-664f-fphr GHSA-qr2g-hvxr-c357 GHSA-r456-h7vj-7pm5 GHSA-v532-947m-m96r GHSA-v5wh-r46x-75cp GHSA-v6r4-6v6m-8669 GHSA-xcr6-9x44-6hpq GHSA-xjcp-9jxf-mc93 --- .../GHSA-3w2j-mvmp-4vx3.json | 38 +++++++++++++++++++ .../GHSA-4crg-cmgg-hmf6.json | 38 +++++++++++++++++++ .../GHSA-6299-m9xc-vxvj.json | 38 +++++++++++++++++++ .../GHSA-82gf-5hq2-6g45.json | 38 +++++++++++++++++++ .../GHSA-88qq-vr7f-76wp.json | 38 +++++++++++++++++++ .../GHSA-9fv2-j4fg-6v4w.json | 38 +++++++++++++++++++ .../GHSA-f279-w6jr-7xxj.json | 35 +++++++++++++++++ .../GHSA-f2j2-g4wg-mxr5.json | 38 +++++++++++++++++++ .../GHSA-f3xr-vc85-7grj.json | 38 +++++++++++++++++++ .../GHSA-fvc8-q78j-c743.json | 38 +++++++++++++++++++ .../GHSA-hfr9-gm39-p2g7.json | 38 +++++++++++++++++++ .../GHSA-j5r8-f5xj-3h83.json | 38 +++++++++++++++++++ .../GHSA-jghx-2c7v-jjmc.json | 38 +++++++++++++++++++ .../GHSA-p8vw-h7rx-fgxr.json | 38 +++++++++++++++++++ .../GHSA-p9qx-8g2v-c964.json | 38 +++++++++++++++++++ .../GHSA-prf2-664f-fphr.json | 38 +++++++++++++++++++ .../GHSA-qr2g-hvxr-c357.json | 38 +++++++++++++++++++ .../GHSA-r456-h7vj-7pm5.json | 38 +++++++++++++++++++ .../GHSA-v532-947m-m96r.json | 38 +++++++++++++++++++ .../GHSA-v5wh-r46x-75cp.json | 38 +++++++++++++++++++ .../GHSA-v6r4-6v6m-8669.json | 38 +++++++++++++++++++ .../GHSA-xcr6-9x44-6hpq.json | 38 +++++++++++++++++++ .../GHSA-xjcp-9jxf-mc93.json | 38 +++++++++++++++++++ 23 files changed, 871 insertions(+) create mode 100644 advisories/unreviewed/2024/03/GHSA-3w2j-mvmp-4vx3/GHSA-3w2j-mvmp-4vx3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4crg-cmgg-hmf6/GHSA-4crg-cmgg-hmf6.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-82gf-5hq2-6g45/GHSA-82gf-5hq2-6g45.json create mode 100644 advisories/unreviewed/2024/03/GHSA-88qq-vr7f-76wp/GHSA-88qq-vr7f-76wp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f2j2-g4wg-mxr5/GHSA-f2j2-g4wg-mxr5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f3xr-vc85-7grj/GHSA-f3xr-vc85-7grj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fvc8-q78j-c743/GHSA-fvc8-q78j-c743.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hfr9-gm39-p2g7/GHSA-hfr9-gm39-p2g7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jghx-2c7v-jjmc/GHSA-jghx-2c7v-jjmc.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p8vw-h7rx-fgxr/GHSA-p8vw-h7rx-fgxr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p9qx-8g2v-c964/GHSA-p9qx-8g2v-c964.json create mode 100644 advisories/unreviewed/2024/03/GHSA-prf2-664f-fphr/GHSA-prf2-664f-fphr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qr2g-hvxr-c357/GHSA-qr2g-hvxr-c357.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-v5wh-r46x-75cp/GHSA-v5wh-r46x-75cp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-v6r4-6v6m-8669/GHSA-v6r4-6v6m-8669.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json diff --git a/advisories/unreviewed/2024/03/GHSA-3w2j-mvmp-4vx3/GHSA-3w2j-mvmp-4vx3.json b/advisories/unreviewed/2024/03/GHSA-3w2j-mvmp-4vx3/GHSA-3w2j-mvmp-4vx3.json new file mode 100644 index 00000000000..94c1dfc610c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3w2j-mvmp-4vx3/GHSA-3w2j-mvmp-4vx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w2j-mvmp-4vx3", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33096" + ], + "details": "Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33096" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4crg-cmgg-hmf6/GHSA-4crg-cmgg-hmf6.json b/advisories/unreviewed/2024/03/GHSA-4crg-cmgg-hmf6/GHSA-4crg-cmgg-hmf6.json new file mode 100644 index 00000000000..0e073a5183f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4crg-cmgg-hmf6/GHSA-4crg-cmgg-hmf6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4crg-cmgg-hmf6", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43550" + ], + "details": "Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43550" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json b/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json new file mode 100644 index 00000000000..a25b6732c2b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6299-m9xc-vxvj", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-43540" + ], + "details": "Memory corruption while processing the IOCTL FM HCI WRITE request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43540" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-82gf-5hq2-6g45/GHSA-82gf-5hq2-6g45.json b/advisories/unreviewed/2024/03/GHSA-82gf-5hq2-6g45/GHSA-82gf-5hq2-6g45.json new file mode 100644 index 00000000000..2a6d54d7284 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-82gf-5hq2-6g45/GHSA-82gf-5hq2-6g45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82gf-5hq2-6g45", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43546" + ], + "details": "Memory corruption while invoking HGSL IOCTL context create.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43546" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-88qq-vr7f-76wp/GHSA-88qq-vr7f-76wp.json b/advisories/unreviewed/2024/03/GHSA-88qq-vr7f-76wp/GHSA-88qq-vr7f-76wp.json new file mode 100644 index 00000000000..7ce93430300 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-88qq-vr7f-76wp/GHSA-88qq-vr7f-76wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88qq-vr7f-76wp", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43548" + ], + "details": "Memory corruption while parsing qcp clip with invalid chunk data size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43548" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json b/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json new file mode 100644 index 00000000000..5dd51848b03 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fv2-j4fg-6v4w", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-28578" + ], + "details": "Memory corruption in Core Services while executing the command for removing a single event listener.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28578" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json b/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json new file mode 100644 index 00000000000..418fbe77b86 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f279-w6jr-7xxj", + "modified": "2024-03-04T12:31:09Z", + "published": "2024-03-04T12:31:09Z", + "aliases": [ + "CVE-2023-6143" + ], + "details": "Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r1p0 through r18p0; Valhall GPU Kernel Driver: from r37p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6143" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f2j2-g4wg-mxr5/GHSA-f2j2-g4wg-mxr5.json b/advisories/unreviewed/2024/03/GHSA-f2j2-g4wg-mxr5/GHSA-f2j2-g4wg-mxr5.json new file mode 100644 index 00000000000..ad672a8d0db --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f2j2-g4wg-mxr5/GHSA-f2j2-g4wg-mxr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2j2-g4wg-mxr5", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43552" + ], + "details": "Memory corruption while processing MBSSID beacon containing several subelement IE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43552" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f3xr-vc85-7grj/GHSA-f3xr-vc85-7grj.json b/advisories/unreviewed/2024/03/GHSA-f3xr-vc85-7grj/GHSA-f3xr-vc85-7grj.json new file mode 100644 index 00000000000..2e8faba933d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f3xr-vc85-7grj/GHSA-f3xr-vc85-7grj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3xr-vc85-7grj", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43547" + ], + "details": "Memory corruption while invoking IOCTLs calls in Automotive Multimedia.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43547" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fvc8-q78j-c743/GHSA-fvc8-q78j-c743.json b/advisories/unreviewed/2024/03/GHSA-fvc8-q78j-c743/GHSA-fvc8-q78j-c743.json new file mode 100644 index 00000000000..9496a80e474 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fvc8-q78j-c743/GHSA-fvc8-q78j-c743.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvc8-q78j-c743", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33095" + ], + "details": "Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33095" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hfr9-gm39-p2g7/GHSA-hfr9-gm39-p2g7.json b/advisories/unreviewed/2024/03/GHSA-hfr9-gm39-p2g7/GHSA-hfr9-gm39-p2g7.json new file mode 100644 index 00000000000..e5e756cef4c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hfr9-gm39-p2g7/GHSA-hfr9-gm39-p2g7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfr9-gm39-p2g7", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33105" + ], + "details": "Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33105" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json b/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json new file mode 100644 index 00000000000..b22c3c9d04c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r8-f5xj-3h83", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33090" + ], + "details": "Transient DOS while processing channel information for speaker protection v2 module in ADSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33090" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jghx-2c7v-jjmc/GHSA-jghx-2c7v-jjmc.json b/advisories/unreviewed/2024/03/GHSA-jghx-2c7v-jjmc/GHSA-jghx-2c7v-jjmc.json new file mode 100644 index 00000000000..aab5fe8e9bd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jghx-2c7v-jjmc/GHSA-jghx-2c7v-jjmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jghx-2c7v-jjmc", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33084" + ], + "details": "Transient DOS while processing IE fragments from server during DTLS handshake.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33084" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p8vw-h7rx-fgxr/GHSA-p8vw-h7rx-fgxr.json b/advisories/unreviewed/2024/03/GHSA-p8vw-h7rx-fgxr/GHSA-p8vw-h7rx-fgxr.json new file mode 100644 index 00000000000..c4dafa9dc87 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p8vw-h7rx-fgxr/GHSA-p8vw-h7rx-fgxr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8vw-h7rx-fgxr", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43553" + ], + "details": "Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43553" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p9qx-8g2v-c964/GHSA-p9qx-8g2v-c964.json b/advisories/unreviewed/2024/03/GHSA-p9qx-8g2v-c964/GHSA-p9qx-8g2v-c964.json new file mode 100644 index 00000000000..c74cea04453 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p9qx-8g2v-c964/GHSA-p9qx-8g2v-c964.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9qx-8g2v-c964", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33104" + ], + "details": "Transient DOS while processing PDU Release command with a parameter PDU ID out of range.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33104" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-prf2-664f-fphr/GHSA-prf2-664f-fphr.json b/advisories/unreviewed/2024/03/GHSA-prf2-664f-fphr/GHSA-prf2-664f-fphr.json new file mode 100644 index 00000000000..a173c6bcba8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-prf2-664f-fphr/GHSA-prf2-664f-fphr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prf2-664f-fphr", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33086" + ], + "details": "Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33086" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qr2g-hvxr-c357/GHSA-qr2g-hvxr-c357.json b/advisories/unreviewed/2024/03/GHSA-qr2g-hvxr-c357/GHSA-qr2g-hvxr-c357.json new file mode 100644 index 00000000000..345fdc1399a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qr2g-hvxr-c357/GHSA-qr2g-hvxr-c357.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr2g-hvxr-c357", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33103" + ], + "details": "Transient DOS while processing CAG info IE received from NW.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33103" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json b/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json new file mode 100644 index 00000000000..d54b66fea5e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r456-h7vj-7pm5", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-43539" + ], + "details": "Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43539" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json b/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json new file mode 100644 index 00000000000..cadd1aa70a4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v532-947m-m96r", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-28582" + ], + "details": "Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28582" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v5wh-r46x-75cp/GHSA-v5wh-r46x-75cp.json b/advisories/unreviewed/2024/03/GHSA-v5wh-r46x-75cp/GHSA-v5wh-r46x-75cp.json new file mode 100644 index 00000000000..e2e2c736068 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v5wh-r46x-75cp/GHSA-v5wh-r46x-75cp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5wh-r46x-75cp", + "modified": "2024-03-04T12:31:11Z", + "published": "2024-03-04T12:31:11Z", + "aliases": [ + "CVE-2023-43549" + ], + "details": "Memory corruption while processing TPC target power table in FTM TPC.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43549" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v6r4-6v6m-8669/GHSA-v6r4-6v6m-8669.json b/advisories/unreviewed/2024/03/GHSA-v6r4-6v6m-8669/GHSA-v6r4-6v6m-8669.json new file mode 100644 index 00000000000..3a3f10de947 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v6r4-6v6m-8669/GHSA-v6r4-6v6m-8669.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6r4-6v6m-8669", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-43541" + ], + "details": "Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43541" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json b/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json new file mode 100644 index 00000000000..5faee29ad20 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcr6-9x44-6hpq", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33066" + ], + "details": "Memory corruption in Audio while processing RT proxy port register driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33066" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json b/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json new file mode 100644 index 00000000000..fef4c27b17f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjcp-9jxf-mc93", + "modified": "2024-03-04T12:31:10Z", + "published": "2024-03-04T12:31:10Z", + "aliases": [ + "CVE-2023-33078" + ], + "details": "Information Disclosure while processing IOCTL request in FastRPC.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33078" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/march-2024-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-04T11:15:09Z" + } +} \ No newline at end of file