Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-19 18:33:01 +00:00
parent 2d33f8fa43
commit efe7a6d8bb
46 changed files with 1028 additions and 47 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22c5-cpvr-cfvq",
"modified": "2024-12-19T15:31:11Z",
"modified": "2024-12-19T18:31:36Z",
"published": "2024-12-12T09:31:36Z",
"aliases": [
"CVE-2024-4109"
@@ -60,6 +60,14 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:11559"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:11560"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:11570"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-4109"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6j7w-pxhr-g4pr",
"modified": "2022-05-14T01:31:44Z",
"modified": "2024-12-19T18:31:34Z",
"published": "2022-05-14T01:31:44Z",
"aliases": [
"CVE-2010-2568"
],
"details": "Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5c7-c9q4-9h6j",
"modified": "2022-05-02T03:16:36Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-02T03:16:36Z",
"aliases": [
"CVE-2009-0563"
],
"details": "Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka \"Word Buffer Overflow Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -53,7 +58,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmc6-x6ww-78h8",
"modified": "2022-05-02T03:16:36Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-02T03:16:36Z",
"aliases": [
"CVE-2009-0557"
],
"details": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"Object Record Corruption Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6wc-h767-27c3",
"modified": "2022-05-14T02:18:00Z",
"modified": "2024-12-19T18:31:34Z",
"published": "2022-05-14T02:18:00Z",
"aliases": [
"CVE-2010-2883"
],
"details": "Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -93,7 +98,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvcc-qqxr-p978",
"modified": "2022-05-01T06:59:35Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-01T06:59:35Z",
"aliases": [
"CVE-2006-2492"
],
"details": "Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -84,7 +89,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q4f6-24ph-r6rm",
"modified": "2022-05-02T03:50:11Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-02T03:50:11Z",
"aliases": [
"CVE-2009-3953"
],
"details": "The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -73,7 +78,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrqx-wqch-hjh4",
"modified": "2022-05-14T02:36:43Z",
"modified": "2024-12-19T18:31:34Z",
"published": "2022-05-14T02:36:43Z",
"aliases": [
"CVE-2010-2572"
],
"details": "Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka \"PowerPoint Parsing Buffer Overflow Vulnerability.\"",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -29,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qw37-hh98-8g3j",
"modified": "2022-05-01T23:32:10Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-01T23:32:10Z",
"aliases": [
"CVE-2008-0655"
],
"details": "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rv25-qx26-27xv",
"modified": "2022-05-02T03:53:42Z",
"modified": "2024-12-19T18:31:34Z",
"published": "2022-05-02T03:53:42Z",
"aliases": [
"CVE-2009-4324"
],
"details": "Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -100,7 +105,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wx6p-35hf-vhhj",
"modified": "2022-05-02T03:29:27Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-02T03:29:27Z",
"aliases": [
"CVE-2009-1862"
],
"details": "Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -97,6 +102,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787",
"CWE-94"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjr9-phw2-2wjx",
"modified": "2022-05-01T18:35:41Z",
"modified": "2024-12-19T18:31:33Z",
"published": "2022-05-01T18:35:41Z",
"aliases": [
"CVE-2007-5659"
],
"details": "Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -69,7 +74,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -38,7 +38,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
"CWE-125",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -41,7 +41,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -41,7 +41,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -41,7 +41,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -41,7 +41,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -54,7 +54,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1068"
"CWE-1068",
"CWE-358"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj65-jvhx-4h6p",
"modified": "2024-11-26T00:33:31Z",
"modified": "2024-12-19T18:31:36Z",
"published": "2024-11-26T00:33:31Z",
"aliases": [
"CVE-2024-53101"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Fix uninitialized value issue in from_kuid and from_kgid\n\nocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in\na trace point even though ATTR_MODE, ATTR_UID and ATTR_GID aren't set.\n\nInitialize all fields of newattrs to avoid uninitialized variables, by\nchecking if ATTR_MODE, ATTR_UID, ATTR_GID are initialized, otherwise 0.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-908"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-25T22:15:17Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22mx-7hxm-5fcw",
"modified": "2024-12-19T18:31:38Z",
"published": "2024-12-19T18:31:38Z",
"aliases": [
"CVE-2024-52897"
],
"details": "IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52897"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7178086"
}
],
"database_specific": {
"cwe_ids": [
"CWE-209"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-19T18:15:23Z"
}
}

Some files were not shown because too many files have changed in this diff Show More