From efe7a6d8bb83e8ab63ea28078b8a03d860e07477 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 19 Dec 2024 18:33:01 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-22c5-cpvr-cfvq.json | 10 +++- .../GHSA-6j7w-pxhr-g4pr.json | 9 ++- .../GHSA-f5c7-c9q4-9h6j.json | 12 +++- .../GHSA-fmc6-x6ww-78h8.json | 9 ++- .../GHSA-m6wc-h767-27c3.json | 12 +++- .../GHSA-pvcc-qqxr-p978.json | 13 ++++- .../GHSA-q4f6-24ph-r6rm.json | 12 +++- .../GHSA-qrqx-wqch-hjh4.json | 12 +++- .../GHSA-qw37-hh98-8g3j.json | 9 ++- .../GHSA-rv25-qx26-27xv.json | 13 ++++- .../GHSA-wx6p-35hf-vhhj.json | 10 +++- .../GHSA-xjr9-phw2-2wjx.json | 12 +++- .../GHSA-f8gg-fh4p-4795.json | 3 +- .../GHSA-5pj4-f8gh-j3mr.json | 4 +- .../GHSA-gg9c-7j6m-3qq2.json | 4 +- .../GHSA-qccw-wmvp-8pv9.json | 4 +- .../GHSA-4m4g-p795-cmq7.json | 4 +- .../GHSA-c47q-h9w3-rcwg.json | 3 +- .../GHSA-jj65-jvhx-4h6p.json | 15 +++-- .../GHSA-22mx-7hxm-5fcw.json | 36 ++++++++++++ .../GHSA-28pp-6j97-mmc8.json | 36 ++++++++++++ .../GHSA-2p6g-86q5-vxxh.json | 36 ++++++++++++ .../GHSA-494w-gq5c-m2qq.json | 52 +++++++++++++++++ .../GHSA-4x4p-57gw-fhrv.json | 3 +- .../GHSA-55mr-49mr-xcvc.json | 29 ++++++++++ .../GHSA-57cm-p9q8-qfqp.json | 52 +++++++++++++++++ .../GHSA-673v-f97j-c5vj.json | 56 +++++++++++++++++++ .../GHSA-6rhp-5prw-7252.json | 36 ++++++++++++ .../GHSA-6rp7-x538-xh3v.json | 1 + .../GHSA-6v67-2wr5-gvf4.json | 36 ++++++++++++ .../GHSA-6wm7-jp97-x8j3.json | 52 +++++++++++++++++ .../GHSA-8jjx-px56-3jpp.json | 3 +- .../GHSA-9p9q-mq5f-p69m.json | 3 +- .../GHSA-fmwg-695f-mrjx.json | 52 +++++++++++++++++ .../GHSA-fx37-r27p-w9f7.json | 36 ++++++++++++ .../GHSA-g378-8vq5-m8fm.json | 33 +++++++++++ .../GHSA-g5vr-rgqm-vf78.json | 36 ++++++++++++ .../GHSA-g853-3v2c-5mcr.json | 52 +++++++++++++++++ .../GHSA-h62v-f3rv-rqwf.json | 56 +++++++++++++++++++ .../GHSA-j3gf-gcj2-hmm5.json | 36 ++++++++++++ .../GHSA-j5p5-v7rm-vgw7.json | 36 ++++++++++++ .../GHSA-p3g7-98ff-92pp.json | 33 +++++++++++ .../GHSA-pr98-23f8-jwxv.json | 36 ++++++++++++ .../GHSA-qf32-jmjm-hhgw.json | 15 +++-- .../GHSA-rj72-g79c-g69m.json | 52 +++++++++++++++++ .../GHSA-x7qc-9ccg-fgv7.json | 1 + 46 files changed, 1028 insertions(+), 47 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2p6g-86q5-vxxh/GHSA-2p6g-86q5-vxxh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-494w-gq5c-m2qq/GHSA-494w-gq5c-m2qq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-55mr-49mr-xcvc/GHSA-55mr-49mr-xcvc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-57cm-p9q8-qfqp/GHSA-57cm-p9q8-qfqp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-673v-f97j-c5vj/GHSA-673v-f97j-c5vj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6rhp-5prw-7252/GHSA-6rhp-5prw-7252.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6v67-2wr5-gvf4/GHSA-6v67-2wr5-gvf4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fmwg-695f-mrjx/GHSA-fmwg-695f-mrjx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fx37-r27p-w9f7/GHSA-fx37-r27p-w9f7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g378-8vq5-m8fm/GHSA-g378-8vq5-m8fm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h62v-f3rv-rqwf/GHSA-h62v-f3rv-rqwf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j3gf-gcj2-hmm5/GHSA-j3gf-gcj2-hmm5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j5p5-v7rm-vgw7/GHSA-j5p5-v7rm-vgw7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p3g7-98ff-92pp/GHSA-p3g7-98ff-92pp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pr98-23f8-jwxv/GHSA-pr98-23f8-jwxv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json diff --git a/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json b/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json index b0ea25c5856..cac0c9b7970 100644 --- a/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json +++ b/advisories/github-reviewed/2024/12/GHSA-22c5-cpvr-cfvq/GHSA-22c5-cpvr-cfvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22c5-cpvr-cfvq", - "modified": "2024-12-19T15:31:11Z", + "modified": "2024-12-19T18:31:36Z", "published": "2024-12-12T09:31:36Z", "aliases": [ "CVE-2024-4109" @@ -60,6 +60,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:11559" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:11560" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:11570" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-4109" diff --git a/advisories/unreviewed/2022/05/GHSA-6j7w-pxhr-g4pr/GHSA-6j7w-pxhr-g4pr.json b/advisories/unreviewed/2022/05/GHSA-6j7w-pxhr-g4pr/GHSA-6j7w-pxhr-g4pr.json index 6eb7c820b2f..30eae80f3ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-6j7w-pxhr-g4pr/GHSA-6j7w-pxhr-g4pr.json +++ b/advisories/unreviewed/2022/05/GHSA-6j7w-pxhr-g4pr/GHSA-6j7w-pxhr-g4pr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6j7w-pxhr-g4pr", - "modified": "2022-05-14T01:31:44Z", + "modified": "2024-12-19T18:31:34Z", "published": "2022-05-14T01:31:44Z", "aliases": [ "CVE-2010-2568" ], "details": "Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json b/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json index 7d50dcea26f..8de7d4b0e48 100644 --- a/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json +++ b/advisories/unreviewed/2022/05/GHSA-f5c7-c9q4-9h6j/GHSA-f5c7-c9q4-9h6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f5c7-c9q4-9h6j", - "modified": "2022-05-02T03:16:36Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-02T03:16:36Z", "aliases": [ "CVE-2009-0563" ], "details": "Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka \"Word Buffer Overflow Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -53,7 +58,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json b/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json index 388d1d88692..98df4a1f60c 100644 --- a/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json +++ b/advisories/unreviewed/2022/05/GHSA-fmc6-x6ww-78h8/GHSA-fmc6-x6ww-78h8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fmc6-x6ww-78h8", - "modified": "2022-05-02T03:16:36Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-02T03:16:36Z", "aliases": [ "CVE-2009-0557" ], "details": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka \"Object Record Corruption Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-m6wc-h767-27c3/GHSA-m6wc-h767-27c3.json b/advisories/unreviewed/2022/05/GHSA-m6wc-h767-27c3/GHSA-m6wc-h767-27c3.json index dfa6fe6fc8c..907b4af9f42 100644 --- a/advisories/unreviewed/2022/05/GHSA-m6wc-h767-27c3/GHSA-m6wc-h767-27c3.json +++ b/advisories/unreviewed/2022/05/GHSA-m6wc-h767-27c3/GHSA-m6wc-h767-27c3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m6wc-h767-27c3", - "modified": "2022-05-14T02:18:00Z", + "modified": "2024-12-19T18:31:34Z", "published": "2022-05-14T02:18:00Z", "aliases": [ "CVE-2010-2883" ], "details": "Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -93,7 +98,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-pvcc-qqxr-p978/GHSA-pvcc-qqxr-p978.json b/advisories/unreviewed/2022/05/GHSA-pvcc-qqxr-p978/GHSA-pvcc-qqxr-p978.json index 43e5bd2cce1..2c8dab59e8b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pvcc-qqxr-p978/GHSA-pvcc-qqxr-p978.json +++ b/advisories/unreviewed/2022/05/GHSA-pvcc-qqxr-p978/GHSA-pvcc-qqxr-p978.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvcc-qqxr-p978", - "modified": "2022-05-01T06:59:35Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-01T06:59:35Z", "aliases": [ "CVE-2006-2492" ], "details": "Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -84,7 +89,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-q4f6-24ph-r6rm/GHSA-q4f6-24ph-r6rm.json b/advisories/unreviewed/2022/05/GHSA-q4f6-24ph-r6rm/GHSA-q4f6-24ph-r6rm.json index 173b6097fd7..cf6eb28c2f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q4f6-24ph-r6rm/GHSA-q4f6-24ph-r6rm.json +++ b/advisories/unreviewed/2022/05/GHSA-q4f6-24ph-r6rm/GHSA-q4f6-24ph-r6rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4f6-24ph-r6rm", - "modified": "2022-05-02T03:50:11Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-02T03:50:11Z", "aliases": [ "CVE-2009-3953" ], "details": "The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -73,7 +78,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qrqx-wqch-hjh4/GHSA-qrqx-wqch-hjh4.json b/advisories/unreviewed/2022/05/GHSA-qrqx-wqch-hjh4/GHSA-qrqx-wqch-hjh4.json index 9368eb389e1..0c452e956ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-qrqx-wqch-hjh4/GHSA-qrqx-wqch-hjh4.json +++ b/advisories/unreviewed/2022/05/GHSA-qrqx-wqch-hjh4/GHSA-qrqx-wqch-hjh4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrqx-wqch-hjh4", - "modified": "2022-05-14T02:36:43Z", + "modified": "2024-12-19T18:31:34Z", "published": "2022-05-14T02:36:43Z", "aliases": [ "CVE-2010-2572" ], "details": "Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka \"PowerPoint Parsing Buffer Overflow Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json b/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json index 823f0a45be1..b5fd13bc67b 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json +++ b/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qw37-hh98-8g3j", - "modified": "2022-05-01T23:32:10Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-01T23:32:10Z", "aliases": [ "CVE-2008-0655" ], "details": "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-rv25-qx26-27xv/GHSA-rv25-qx26-27xv.json b/advisories/unreviewed/2022/05/GHSA-rv25-qx26-27xv/GHSA-rv25-qx26-27xv.json index 1f92287dfac..be30bfde8e0 100644 --- a/advisories/unreviewed/2022/05/GHSA-rv25-qx26-27xv/GHSA-rv25-qx26-27xv.json +++ b/advisories/unreviewed/2022/05/GHSA-rv25-qx26-27xv/GHSA-rv25-qx26-27xv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rv25-qx26-27xv", - "modified": "2022-05-02T03:53:42Z", + "modified": "2024-12-19T18:31:34Z", "published": "2022-05-02T03:53:42Z", "aliases": [ "CVE-2009-4324" ], "details": "Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -100,7 +105,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wx6p-35hf-vhhj/GHSA-wx6p-35hf-vhhj.json b/advisories/unreviewed/2022/05/GHSA-wx6p-35hf-vhhj/GHSA-wx6p-35hf-vhhj.json index 8ff7ed0e9b7..e25c0a671b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-wx6p-35hf-vhhj/GHSA-wx6p-35hf-vhhj.json +++ b/advisories/unreviewed/2022/05/GHSA-wx6p-35hf-vhhj/GHSA-wx6p-35hf-vhhj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wx6p-35hf-vhhj", - "modified": "2022-05-02T03:29:27Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-02T03:29:27Z", "aliases": [ "CVE-2009-1862" ], "details": "Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -97,6 +102,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-xjr9-phw2-2wjx/GHSA-xjr9-phw2-2wjx.json b/advisories/unreviewed/2022/05/GHSA-xjr9-phw2-2wjx/GHSA-xjr9-phw2-2wjx.json index 0413e1edfd7..995d60aa29a 100644 --- a/advisories/unreviewed/2022/05/GHSA-xjr9-phw2-2wjx/GHSA-xjr9-phw2-2wjx.json +++ b/advisories/unreviewed/2022/05/GHSA-xjr9-phw2-2wjx/GHSA-xjr9-phw2-2wjx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjr9-phw2-2wjx", - "modified": "2022-05-01T18:35:41Z", + "modified": "2024-12-19T18:31:33Z", "published": "2022-05-01T18:35:41Z", "aliases": [ "CVE-2007-5659" ], "details": "Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -69,7 +74,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json index 747bdf10f6c..c8bc962904f 100644 --- a/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json +++ b/advisories/unreviewed/2024/02/GHSA-f8gg-fh4p-4795/GHSA-f8gg-fh4p-4795.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json b/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json index fefe869ca26..e76f9cce3c5 100644 --- a/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json +++ b/advisories/unreviewed/2024/03/GHSA-5pj4-f8gh-j3mr/GHSA-5pj4-f8gh-j3mr.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json b/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json index 30404966172..5614864ced9 100644 --- a/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json +++ b/advisories/unreviewed/2024/03/GHSA-gg9c-7j6m-3qq2/GHSA-gg9c-7j6m-3qq2.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json b/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json index e8b07c9289f..cbaad003707 100644 --- a/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json +++ b/advisories/unreviewed/2024/03/GHSA-qccw-wmvp-8pv9/GHSA-qccw-wmvp-8pv9.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json b/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json index b25cb0bf44f..4a9c50e884e 100644 --- a/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json +++ b/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json b/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json index 30727c43584..1f93e6ada24 100644 --- a/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json +++ b/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1068" + "CWE-1068", + "CWE-358" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json b/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json index fa6a6ec9e55..82ed9683479 100644 --- a/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json +++ b/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jj65-jvhx-4h6p", - "modified": "2024-11-26T00:33:31Z", + "modified": "2024-12-19T18:31:36Z", "published": "2024-11-26T00:33:31Z", "aliases": [ "CVE-2024-53101" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Fix uninitialized value issue in from_kuid and from_kgid\n\nocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in\na trace point even though ATTR_MODE, ATTR_UID and ATTR_GID aren't set.\n\nInitialize all fields of newattrs to avoid uninitialized variables, by\nchecking if ATTR_MODE, ATTR_UID, ATTR_GID are initialized, otherwise 0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-25T22:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json b/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json new file mode 100644 index 00000000000..b66f2232065 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-22mx-7hxm-5fcw/GHSA-22mx-7hxm-5fcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22mx-7hxm-5fcw", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-52897" + ], + "details": "IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52897" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178086" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json b/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json new file mode 100644 index 00000000000..f5c334b14a8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-28pp-6j97-mmc8/GHSA-28pp-6j97-mmc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28pp-6j97-mmc8", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-52896" + ], + "details": "IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52896" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2p6g-86q5-vxxh/GHSA-2p6g-86q5-vxxh.json b/advisories/unreviewed/2024/12/GHSA-2p6g-86q5-vxxh/GHSA-2p6g-86q5-vxxh.json new file mode 100644 index 00000000000..0ba46d113c5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2p6g-86q5-vxxh/GHSA-2p6g-86q5-vxxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p6g-86q5-vxxh", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-51471" + ], + "details": "IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51471" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178243" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-494w-gq5c-m2qq/GHSA-494w-gq5c-m2qq.json b/advisories/unreviewed/2024/12/GHSA-494w-gq5c-m2qq/GHSA-494w-gq5c-m2qq.json new file mode 100644 index 00000000000..09d13c59d4c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-494w-gq5c-m2qq/GHSA-494w-gq5c-m2qq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-494w-gq5c-m2qq", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-12793" + ], + "details": "A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.2.4 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12793" + }, + { + "type": "WEB", + "url": "https://gist.github.com/J1rrY-learn/b939899001b2c6b59632d82df11da001" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288974" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288974" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465779" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json b/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json index f97591f93fc..7347510aa8b 100644 --- a/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json +++ b/advisories/unreviewed/2024/12/GHSA-4x4p-57gw-fhrv/GHSA-4x4p-57gw-fhrv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-55mr-49mr-xcvc/GHSA-55mr-49mr-xcvc.json b/advisories/unreviewed/2024/12/GHSA-55mr-49mr-xcvc/GHSA-55mr-49mr-xcvc.json new file mode 100644 index 00000000000..8011bac74ef --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-55mr-49mr-xcvc/GHSA-55mr-49mr-xcvc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55mr-49mr-xcvc", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2023-7005" + ], + "details": "A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7005" + }, + { + "type": "WEB", + "url": "https://alephsecurity.com/2024/03/07/kontrol-lux-lock-2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-57cm-p9q8-qfqp/GHSA-57cm-p9q8-qfqp.json b/advisories/unreviewed/2024/12/GHSA-57cm-p9q8-qfqp/GHSA-57cm-p9q8-qfqp.json new file mode 100644 index 00000000000..3e20ae5cd4c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-57cm-p9q8-qfqp/GHSA-57cm-p9q8-qfqp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57cm-p9q8-qfqp", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12789" + ], + "details": "A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.4 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12789" + }, + { + "type": "WEB", + "url": "https://gist.github.com/J1rrY-learn/8e52bf055fd1806ada81ae1ff25dd817" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288969" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288969" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-673v-f97j-c5vj/GHSA-673v-f97j-c5vj.json b/advisories/unreviewed/2024/12/GHSA-673v-f97j-c5vj/GHSA-673v-f97j-c5vj.json new file mode 100644 index 00000000000..2c202c5a378 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-673v-f97j-c5vj/GHSA-673v-f97j-c5vj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-673v-f97j-c5vj", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12787" + ], + "details": "A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/check_student_login.php. The manipulation of the argument student_emailid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12787" + }, + { + "type": "WEB", + "url": "https://github.com/AFK-cmd/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288967" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465082" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6rhp-5prw-7252/GHSA-6rhp-5prw-7252.json b/advisories/unreviewed/2024/12/GHSA-6rhp-5prw-7252/GHSA-6rhp-5prw-7252.json new file mode 100644 index 00000000000..02f86472961 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6rhp-5prw-7252/GHSA-6rhp-5prw-7252.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rhp-5prw-7252", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-38864" + ], + "details": "Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38864" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17098" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6rp7-x538-xh3v/GHSA-6rp7-x538-xh3v.json b/advisories/unreviewed/2024/12/GHSA-6rp7-x538-xh3v/GHSA-6rp7-x538-xh3v.json index 583a189420c..5f9756bedae 100644 --- a/advisories/unreviewed/2024/12/GHSA-6rp7-x538-xh3v/GHSA-6rp7-x538-xh3v.json +++ b/advisories/unreviewed/2024/12/GHSA-6rp7-x538-xh3v/GHSA-6rp7-x538-xh3v.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-191", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-6v67-2wr5-gvf4/GHSA-6v67-2wr5-gvf4.json b/advisories/unreviewed/2024/12/GHSA-6v67-2wr5-gvf4/GHSA-6v67-2wr5-gvf4.json new file mode 100644 index 00000000000..cc3e4c5c03e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6v67-2wr5-gvf4/GHSA-6v67-2wr5-gvf4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v67-2wr5-gvf4", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12801" + ], + "details": "Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to \nforge requests by compromising logback configuration files in XML.\n\n\n\nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:X/U:Clear" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12801" + }, + { + "type": "WEB", + "url": "https://logback.qos.ch/news.html#1.5.13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json b/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json new file mode 100644 index 00000000000..32faca945f2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wm7-jp97-x8j3", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12791" + ], + "details": "A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file signin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12791" + }, + { + "type": "WEB", + "url": "https://github.com/laowuzi/cve/blob/main/E-commerce/E-commerce-signin.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288971" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288971" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465711" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8jjx-px56-3jpp/GHSA-8jjx-px56-3jpp.json b/advisories/unreviewed/2024/12/GHSA-8jjx-px56-3jpp/GHSA-8jjx-px56-3jpp.json index 285f765f09a..450147359d9 100644 --- a/advisories/unreviewed/2024/12/GHSA-8jjx-px56-3jpp/GHSA-8jjx-px56-3jpp.json +++ b/advisories/unreviewed/2024/12/GHSA-8jjx-px56-3jpp/GHSA-8jjx-px56-3jpp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json b/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json index 3be05b16e27..7fa59f6f731 100644 --- a/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json +++ b/advisories/unreviewed/2024/12/GHSA-9p9q-mq5f-p69m/GHSA-9p9q-mq5f-p69m.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-fmwg-695f-mrjx/GHSA-fmwg-695f-mrjx.json b/advisories/unreviewed/2024/12/GHSA-fmwg-695f-mrjx/GHSA-fmwg-695f-mrjx.json new file mode 100644 index 00000000000..de33e7927de --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fmwg-695f-mrjx/GHSA-fmwg-695f-mrjx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmwg-695f-mrjx", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12788" + ], + "details": "A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file signinpost.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12788" + }, + { + "type": "WEB", + "url": "https://github.com/laowuzi/cve/tree/main/Technical_Discussion_Forum" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288968" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288968" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fx37-r27p-w9f7/GHSA-fx37-r27p-w9f7.json b/advisories/unreviewed/2024/12/GHSA-fx37-r27p-w9f7/GHSA-fx37-r27p-w9f7.json new file mode 100644 index 00000000000..f8749424d94 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fx37-r27p-w9f7/GHSA-fx37-r27p-w9f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx37-r27p-w9f7", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-9154" + ], + "details": "A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9154" + }, + { + "type": "WEB", + "url": "https://cyberdanube.com/security-research/authenticated-remote-code-execution-in-ewon-flexy-205" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g378-8vq5-m8fm/GHSA-g378-8vq5-m8fm.json b/advisories/unreviewed/2024/12/GHSA-g378-8vq5-m8fm/GHSA-g378-8vq5-m8fm.json new file mode 100644 index 00000000000..182883f5946 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g378-8vq5-m8fm/GHSA-g378-8vq5-m8fm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g378-8vq5-m8fm", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-55082" + ], + "details": "A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attackers to access sensitive information via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55082" + }, + { + "type": "WEB", + "url": "https://gist.github.com/summerxxoo/f98033dbf1ab81a045c1196c3a1ab3ef" + }, + { + "type": "WEB", + "url": "https://github.com/summerxxoo/VulnPoc/blob/main/Stirling-PDF-%20Server-Side%20Request%20Forgery%28SSRF%29%20vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json b/advisories/unreviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json new file mode 100644 index 00000000000..488d1688e9f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g5vr-rgqm-vf78/GHSA-g5vr-rgqm-vf78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5vr-rgqm-vf78", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-38819" + ], + "details": "Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38819" + }, + { + "type": "WEB", + "url": "https://spring.io/security/cve-2024-38819" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json b/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json new file mode 100644 index 00000000000..222f619000f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g853-3v2c-5mcr/GHSA-g853-3v2c-5mcr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g853-3v2c-5mcr", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-12794" + ], + "details": "A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown part of the file /admin/editorder.php. The manipulation of the argument dstatus/quantity/ddate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12794" + }, + { + "type": "WEB", + "url": "https://github.com/laowuzi/cve/blob/main/E-commerce/E-commerce_editorder.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288975" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288975" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.466241" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h62v-f3rv-rqwf/GHSA-h62v-f3rv-rqwf.json b/advisories/unreviewed/2024/12/GHSA-h62v-f3rv-rqwf/GHSA-h62v-f3rv-rqwf.json new file mode 100644 index 00000000000..0e0150c2846 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h62v-f3rv-rqwf/GHSA-h62v-f3rv-rqwf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h62v-f3rv-rqwf", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12790" + ], + "details": "A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file room-details.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12790" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/asd1238525/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288970" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288970" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j3gf-gcj2-hmm5/GHSA-j3gf-gcj2-hmm5.json b/advisories/unreviewed/2024/12/GHSA-j3gf-gcj2-hmm5/GHSA-j3gf-gcj2-hmm5.json new file mode 100644 index 00000000000..9a6fb44be8a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j3gf-gcj2-hmm5/GHSA-j3gf-gcj2-hmm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3gf-gcj2-hmm5", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2021-22501" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation. \n\nThe vulnerability could be exploited to confidential information\n\nThis issue affects Operations Bridge Manager: 2017.05, 2017.11, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22501" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000037407?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j5p5-v7rm-vgw7/GHSA-j5p5-v7rm-vgw7.json b/advisories/unreviewed/2024/12/GHSA-j5p5-v7rm-vgw7/GHSA-j5p5-v7rm-vgw7.json new file mode 100644 index 00000000000..f30df78e6f1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j5p5-v7rm-vgw7/GHSA-j5p5-v7rm-vgw7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5p5-v7rm-vgw7", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-49336" + ], + "details": "IBM Security Guardium 11.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49336" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7179369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p3g7-98ff-92pp/GHSA-p3g7-98ff-92pp.json b/advisories/unreviewed/2024/12/GHSA-p3g7-98ff-92pp/GHSA-p3g7-98ff-92pp.json new file mode 100644 index 00000000000..95d6d239921 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p3g7-98ff-92pp/GHSA-p3g7-98ff-92pp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3g7-98ff-92pp", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-55081" + ], + "details": "An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55081" + }, + { + "type": "WEB", + "url": "https://gist.github.com/summerxxoo/18b3ccc91aacd606aa4d48a02029e9e7" + }, + { + "type": "WEB", + "url": "https://github.com/summerxxoo/VulnPoc/blob/main/chat2DB_XXE.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pr98-23f8-jwxv/GHSA-pr98-23f8-jwxv.json b/advisories/unreviewed/2024/12/GHSA-pr98-23f8-jwxv/GHSA-pr98-23f8-jwxv.json new file mode 100644 index 00000000000..9228059370b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pr98-23f8-jwxv/GHSA-pr98-23f8-jwxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr98-23f8-jwxv", + "modified": "2024-12-19T18:31:37Z", + "published": "2024-12-19T18:31:37Z", + "aliases": [ + "CVE-2024-12798" + ], + "details": "ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core\n upto and including version 1.5.12 in Java applications allows\n attacker to execute arbitrary code by compromising an existing\n logback configuration file or by injecting an environment variable\n before program execution.\n\n\n\n\n\nMalicious logback configuration files can allow the attacker to execute \narbitrary code using the JaninoEventEvaluator extension.\n\n\n\nA successful attack requires the user to have write access to a \nconfiguration file. Alternatively, the attacker could inject a malicious \nenvironment variable pointing to a malicious configuration file. In both \ncases, the attack requires existing privilege.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Clear" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12798" + }, + { + "type": "WEB", + "url": "https://logback.qos.ch/news.html#1.5.13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-917" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json b/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json index 5464fc130f9..37b8f398fb0 100644 --- a/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json +++ b/advisories/unreviewed/2024/12/GHSA-qf32-jmjm-hhgw/GHSA-qf32-jmjm-hhgw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qf32-jmjm-hhgw", - "modified": "2024-12-19T15:31:11Z", + "modified": "2024-12-19T18:31:36Z", "published": "2024-12-19T15:31:11Z", "aliases": [ "CVE-2024-54790" ], "details": "A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-19T15:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json b/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json new file mode 100644 index 00000000000..ba075f8e6ba --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rj72-g79c-g69m/GHSA-rj72-g79c-g69m.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj72-g79c-g69m", + "modified": "2024-12-19T18:31:38Z", + "published": "2024-12-19T18:31:38Z", + "aliases": [ + "CVE-2024-12792" + ], + "details": "A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12792" + }, + { + "type": "WEB", + "url": "https://github.com/laowuzi/cve/blob/main/E-commerce/E-commerce-newadmin.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288973" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288973" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.465715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json b/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json index acc8a776faf..65da1f2329c 100644 --- a/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json +++ b/advisories/unreviewed/2024/12/GHSA-x7qc-9ccg-fgv7/GHSA-x7qc-9ccg-fgv7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "HIGH",