diff --git a/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json b/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json index 2150aa5dcc6..14e8017ce9a 100644 --- a/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json +++ b/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74h5-c7r2-qfwr", - "modified": "2023-03-28T21:30:20Z", + "modified": "2024-08-16T00:32:02Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20971" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20971" }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/6c22d6c1e69676c5c68d21928aa5486bfd1bd131" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + }, { "type": "WEB", "url": "https://source.android.com/security/bulletin/pixel/2023-03-01" diff --git a/advisories/unreviewed/2023/10/GHSA-jqg7-34mv-rqjm/GHSA-jqg7-34mv-rqjm.json b/advisories/unreviewed/2023/10/GHSA-jqg7-34mv-rqjm/GHSA-jqg7-34mv-rqjm.json index a8f89c1a08a..bcf828cc288 100644 --- a/advisories/unreviewed/2023/10/GHSA-jqg7-34mv-rqjm/GHSA-jqg7-34mv-rqjm.json +++ b/advisories/unreviewed/2023/10/GHSA-jqg7-34mv-rqjm/GHSA-jqg7-34mv-rqjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jqg7-34mv-rqjm", - "modified": "2023-11-04T03:30:19Z", + "modified": "2024-08-16T00:32:04Z", "published": "2023-10-30T18:30:25Z", "aliases": [ "CVE-2023-21351" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21351" }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/26522c0e82fd3a9bcbd01409217291d97dcdabcf" + }, { "type": "WEB", "url": "https://source.android.com/docs/security/bulletin/android-14" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-mj4c-frrv-hprq/GHSA-mj4c-frrv-hprq.json b/advisories/unreviewed/2024/02/GHSA-mj4c-frrv-hprq/GHSA-mj4c-frrv-hprq.json index c5fc29357ad..d0f7e449a13 100644 --- a/advisories/unreviewed/2024/02/GHSA-mj4c-frrv-hprq/GHSA-mj4c-frrv-hprq.json +++ b/advisories/unreviewed/2024/02/GHSA-mj4c-frrv-hprq/GHSA-mj4c-frrv-hprq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj4c-frrv-hprq", - "modified": "2024-02-27T03:31:02Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-02-27T03:31:02Z", "aliases": [ "CVE-2024-22917" ], "details": "SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T02:15:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mmjv-3699-c2q5/GHSA-mmjv-3699-c2q5.json b/advisories/unreviewed/2024/02/GHSA-mmjv-3699-c2q5/GHSA-mmjv-3699-c2q5.json index d529c9865cf..8679c7e3790 100644 --- a/advisories/unreviewed/2024/02/GHSA-mmjv-3699-c2q5/GHSA-mmjv-3699-c2q5.json +++ b/advisories/unreviewed/2024/02/GHSA-mmjv-3699-c2q5/GHSA-mmjv-3699-c2q5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mmjv-3699-c2q5", - "modified": "2024-02-28T00:31:55Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-02-28T00:31:55Z", "aliases": [ "CVE-2024-26542" ], "details": "Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T22:15:15Z" diff --git a/advisories/unreviewed/2024/02/GHSA-v4q2-79g6-j728/GHSA-v4q2-79g6-j728.json b/advisories/unreviewed/2024/02/GHSA-v4q2-79g6-j728/GHSA-v4q2-79g6-j728.json index 9c1cc2f1456..2a2822a660a 100644 --- a/advisories/unreviewed/2024/02/GHSA-v4q2-79g6-j728/GHSA-v4q2-79g6-j728.json +++ b/advisories/unreviewed/2024/02/GHSA-v4q2-79g6-j728/GHSA-v4q2-79g6-j728.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4q2-79g6-j728", - "modified": "2024-06-10T18:30:52Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-02-20T18:30:35Z", "aliases": [ "CVE-2024-24474" ], "details": "Buffer Overflow vulnerability in Qemu before v.8.2.0 allows a remote attacker to execute arbitrary code via the async_len variable to the FIFO buffer component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T18:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json b/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json index 2ec388079e3..57ed112e907 100644 --- a/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json +++ b/advisories/unreviewed/2024/03/GHSA-6fq2-mvcq-gw26/GHSA-6fq2-mvcq-gw26.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6fq2-mvcq-gw26", - "modified": "2024-03-04T15:31:07Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-04T15:31:07Z", "aliases": [ "CVE-2024-27680" ], "details": "Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the \"Contact form.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T15:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7fc6-ggpp-78xq/GHSA-7fc6-ggpp-78xq.json b/advisories/unreviewed/2024/03/GHSA-7fc6-ggpp-78xq/GHSA-7fc6-ggpp-78xq.json index a45e7b4b3a7..eb62e2e20e1 100644 --- a/advisories/unreviewed/2024/03/GHSA-7fc6-ggpp-78xq/GHSA-7fc6-ggpp-78xq.json +++ b/advisories/unreviewed/2024/03/GHSA-7fc6-ggpp-78xq/GHSA-7fc6-ggpp-78xq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fc6-ggpp-78xq", - "modified": "2024-03-07T21:30:21Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-07T21:30:21Z", "aliases": [ "CVE-2024-24035" ], "details": "Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T21:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7ppq-5vxg-mxp7/GHSA-7ppq-5vxg-mxp7.json b/advisories/unreviewed/2024/03/GHSA-7ppq-5vxg-mxp7/GHSA-7ppq-5vxg-mxp7.json index f6ccdbf227b..6604feab54a 100644 --- a/advisories/unreviewed/2024/03/GHSA-7ppq-5vxg-mxp7/GHSA-7ppq-5vxg-mxp7.json +++ b/advisories/unreviewed/2024/03/GHSA-7ppq-5vxg-mxp7/GHSA-7ppq-5vxg-mxp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7ppq-5vxg-mxp7", - "modified": "2024-03-02T00:31:32Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-02T00:31:32Z", "aliases": [ "CVE-2024-24512" ], "details": "Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T23:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json b/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json index 54c5e83e821..db16e424365 100644 --- a/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json +++ b/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-832m-mwp6-jcr3", - "modified": "2024-03-06T03:30:29Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-06T03:30:29Z", "aliases": [ "CVE-2023-49974" ], "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T01:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9ghw-mv5v-jx7g/GHSA-9ghw-mv5v-jx7g.json b/advisories/unreviewed/2024/03/GHSA-9ghw-mv5v-jx7g/GHSA-9ghw-mv5v-jx7g.json index a6887e5a3b8..c6cd7caa53c 100644 --- a/advisories/unreviewed/2024/03/GHSA-9ghw-mv5v-jx7g/GHSA-9ghw-mv5v-jx7g.json +++ b/advisories/unreviewed/2024/03/GHSA-9ghw-mv5v-jx7g/GHSA-9ghw-mv5v-jx7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9ghw-mv5v-jx7g", - "modified": "2024-03-25T15:30:40Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-25T15:30:40Z", "aliases": [ "CVE-2024-25175" ], "details": "An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T15:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cmx2-vf3h-cg9p/GHSA-cmx2-vf3h-cg9p.json b/advisories/unreviewed/2024/03/GHSA-cmx2-vf3h-cg9p/GHSA-cmx2-vf3h-cg9p.json index 98f9be525a3..eaac83e5c57 100644 --- a/advisories/unreviewed/2024/03/GHSA-cmx2-vf3h-cg9p/GHSA-cmx2-vf3h-cg9p.json +++ b/advisories/unreviewed/2024/03/GHSA-cmx2-vf3h-cg9p/GHSA-cmx2-vf3h-cg9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmx2-vf3h-cg9p", - "modified": "2024-03-13T09:31:22Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-13T09:31:22Z", "aliases": [ "CVE-2024-28623" ], "details": "RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T08:15:43Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f738-2p56-xf85/GHSA-f738-2p56-xf85.json b/advisories/unreviewed/2024/03/GHSA-f738-2p56-xf85/GHSA-f738-2p56-xf85.json index c905738ce94..bf49eae6286 100644 --- a/advisories/unreviewed/2024/03/GHSA-f738-2p56-xf85/GHSA-f738-2p56-xf85.json +++ b/advisories/unreviewed/2024/03/GHSA-f738-2p56-xf85/GHSA-f738-2p56-xf85.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f738-2p56-xf85", - "modified": "2024-03-08T00:33:39Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-08T00:33:39Z", "aliases": [ "CVE-2024-25327" ], "details": "Cross Site Scripting (XSS) vulnerability in Justice Systems FullCourt Enterprise v.8.2 allows a remote attacker to execute arbitrary code via the formatCaseNumber parameter of the Citation search function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T00:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g7vc-r5r2-8x6v/GHSA-g7vc-r5r2-8x6v.json b/advisories/unreviewed/2024/03/GHSA-g7vc-r5r2-8x6v/GHSA-g7vc-r5r2-8x6v.json index 25fc4835fc2..cd7ef1250d7 100644 --- a/advisories/unreviewed/2024/03/GHSA-g7vc-r5r2-8x6v/GHSA-g7vc-r5r2-8x6v.json +++ b/advisories/unreviewed/2024/03/GHSA-g7vc-r5r2-8x6v/GHSA-g7vc-r5r2-8x6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7vc-r5r2-8x6v", - "modified": "2024-03-02T00:31:33Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-03-02T00:31:33Z", "aliases": [ "CVE-2024-25438" ], "details": "A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T23:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json b/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json index ce6d7d142f9..cf0d8fd64f9 100644 --- a/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json +++ b/advisories/unreviewed/2024/06/GHSA-94mv-6g8w-jxvx/GHSA-94mv-6g8w-jxvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94mv-6g8w-jxvx", - "modified": "2024-06-11T21:32:17Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-06-11T21:32:17Z", "aliases": [ "CVE-2024-28020" diff --git a/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json b/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json new file mode 100644 index 00000000000..4f2ac4b0f1c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-35gp-5q9f-g9pq/GHSA-35gp-5q9f-g9pq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35gp-5q9f-g9pq", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34737" + ], + "details": "In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34737" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/8b473b3f79642f42eeeffbfe572df6c6cbe9d79e" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json b/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json new file mode 100644 index 00000000000..6b6f0ebab52 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-423g-mrq6-vpvp/GHSA-423g-mrq6-vpvp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-423g-mrq6-vpvp", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34739" + ], + "details": "In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34739" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/50e1f8f36e32928d10e72324c05a203a6db9f7fb" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json b/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json new file mode 100644 index 00000000000..c64c5961731 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4627-mxfh-2ghm/GHSA-4627-mxfh-2ghm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4627-mxfh-2ghm", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34743" + ], + "details": "In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34743" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/native/+/3f85323b27d95a57bfa87cbf68dd4a143f9f88ad" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json b/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json new file mode 100644 index 00000000000..166295082da --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4m4w-x26h-2qjx/GHSA-4m4w-x26h-2qjx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m4w-x26h-2qjx", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34742" + ], + "details": "In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34742" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/688e5c3012eb0a4ea88361588cf5026c10e4a42c" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json b/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json new file mode 100644 index 00000000000..e0477cc3f4b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-598c-cc55-mwv5/GHSA-598c-cc55-mwv5.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-598c-cc55-mwv5", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34731" + ], + "details": "In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34731" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/av/+/4b68b00993849b6a7f0e6d075bc2c8bb2e184e61" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/hardware/interfaces/+/0ff19d1f89614fce9454fb415bcbfcbcf3caf76e" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/hardware/interfaces/+/d63d09261806f7f1aa01406867f2a9e169356fca" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/system/nfc/+/1037992b9abcde1e3560bd895f62644a68563b3d" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/system/security/+/d3805312d73433e34ef69a645b553a2969c5dc93" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json b/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json new file mode 100644 index 00000000000..7fbfc3455b7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-67q8-hw3v-9fj4/GHSA-67q8-hw3v-9fj4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67q8-hw3v-9fj4", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34734" + ], + "details": "In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34734" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/207584fb6f820eba14251251d7e9331bfd57adb8" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7fmw-x593-854j/GHSA-7fmw-x593-854j.json b/advisories/unreviewed/2024/08/GHSA-7fmw-x593-854j/GHSA-7fmw-x593-854j.json new file mode 100644 index 00000000000..bcd4cbeda94 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7fmw-x593-854j/GHSA-7fmw-x593-854j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fmw-x593-854j", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:04Z", + "aliases": [ + "CVE-2024-34736" + ], + "details": "In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabled. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34736" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/av/+/6cfd048292b2cc706811a22c9078208cfa8e6d24" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json b/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json index 64ef06e4c5b..7a235919141 100644 --- a/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json +++ b/advisories/unreviewed/2024/08/GHSA-8jv6-9x2j-w49p/GHSA-8jv6-9x2j-w49p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jv6-9x2j-w49p", - "modified": "2024-08-15T21:31:19Z", + "modified": "2024-08-16T00:32:04Z", "published": "2024-08-15T21:31:19Z", "aliases": [ "CVE-2024-23168" ], "details": "Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1385" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T19:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9j34-x9f3-m95c/GHSA-9j34-x9f3-m95c.json b/advisories/unreviewed/2024/08/GHSA-9j34-x9f3-m95c/GHSA-9j34-x9f3-m95c.json new file mode 100644 index 00000000000..ffa766b0e3c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9j34-x9f3-m95c/GHSA-9j34-x9f3-m95c.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j34-x9f3-m95c", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-7841" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation of the argument user_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7841" + }, + { + "type": "WEB", + "url": "https://github.com/qqlove555/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274744" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274744" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391540" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json b/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json new file mode 100644 index 00000000000..47cbd75d6e5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g8gg-jvrh-m6c2/GHSA-g8gg-jvrh-m6c2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8gg-jvrh-m6c2", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34740" + ], + "details": "In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34740" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/e8b6505647be558ed3a167a1e13c53dfc227d22b" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/libs/modules-utils/+/700c28908051ceb55e1456d2d21229bc17c6895a" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json b/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json new file mode 100644 index 00000000000..0a37a527e82 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h3r8-2pw7-fhc3/GHSA-h3r8-2pw7-fhc3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3r8-2pw7-fhc3", + "modified": "2024-08-16T00:32:04Z", + "published": "2024-08-16T00:32:04Z", + "aliases": [ + "CVE-2024-34727" + ], + "details": "In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34727" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6afad4b377b5bc3f38b28296e746b674173f99d8" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m3q3-8mgh-rp49/GHSA-m3q3-8mgh-rp49.json b/advisories/unreviewed/2024/08/GHSA-m3q3-8mgh-rp49/GHSA-m3q3-8mgh-rp49.json new file mode 100644 index 00000000000..70d2185e293 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m3q3-8mgh-rp49/GHSA-m3q3-8mgh-rp49.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3q3-8mgh-rp49", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-7844" + ], + "details": "A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/admin/add_acc.php. The manipulation of the argument name/user/position leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7844" + }, + { + "type": "WEB", + "url": "https://github.com/Wsstiger/cve/blob/main/Tracer_XSS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274747" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274747" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391566" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p66m-6jrh-qw22/GHSA-p66m-6jrh-qw22.json b/advisories/unreviewed/2024/08/GHSA-p66m-6jrh-qw22/GHSA-p66m-6jrh-qw22.json new file mode 100644 index 00000000000..a5d5874dcf4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p66m-6jrh-qw22/GHSA-p66m-6jrh-qw22.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p66m-6jrh-qw22", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-7843" + ], + "details": "A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7843" + }, + { + "type": "WEB", + "url": "https://github.com/Wsstiger/cve/blob/main/Tracer_info2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274746" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274746" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391563" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json b/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json new file mode 100644 index 00000000000..9449322c2a2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-prxw-7955-hmfm/GHSA-prxw-7955-hmfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prxw-7955-hmfm", + "modified": "2024-08-16T00:32:04Z", + "published": "2024-08-16T00:32:04Z", + "aliases": [ + "CVE-2024-31333" + ], + "details": "In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31333" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json b/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json new file mode 100644 index 00000000000..175ad33712b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rg28-x6g7-wxr5/GHSA-rg28-x6g7-wxr5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg28-x6g7-wxr5", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34738" + ], + "details": "In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34738" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/21d764807b3dcd402d63e2b4c9fbae1c9965400a" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w7f7-5mx6-5cpc/GHSA-w7f7-5mx6-5cpc.json b/advisories/unreviewed/2024/08/GHSA-w7f7-5mx6-5cpc/GHSA-w7f7-5mx6-5cpc.json new file mode 100644 index 00000000000..3364af848b1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w7f7-5mx6-5cpc/GHSA-w7f7-5mx6-5cpc.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7f7-5mx6-5cpc", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-7842" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the file /tracking/admin/export_it.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7842" + }, + { + "type": "WEB", + "url": "https://github.com/Wsstiger/cve/blob/main/Tracer_info.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274745" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274745" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.391562" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json b/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json new file mode 100644 index 00000000000..babae3b7de1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xx83-6gm8-xx8p/GHSA-xx83-6gm8-xx8p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx83-6gm8-xx8p", + "modified": "2024-08-16T00:32:05Z", + "published": "2024-08-16T00:32:05Z", + "aliases": [ + "CVE-2024-34741" + ], + "details": "In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34741" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/abfaf702ef833dc4d374492d45c615c6e6de7f01" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2024-08-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-15T22:15:06Z" + } +} \ No newline at end of file