From f0364a662916b94ce905871043d8367bf22202fd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 29 Feb 2024 21:32:17 +0000 Subject: [PATCH] Publish Advisories GHSA-jhw6-rjph-429f GHSA-23c2-hg9m-2pw8 GHSA-26x5-365c-m568 GHSA-4g2w-rjr9-jccg GHSA-58pm-crq9-w2qq GHSA-6733-f273-8q48 GHSA-77jp-g8vw-f6xm GHSA-9vh6-fr62-399g GHSA-c48c-24j9-j745 GHSA-fhq8-7gjm-8jxf GHSA-hx98-5v9p-2p84 GHSA-v9x5-9rj9-j343 GHSA-x5hf-p447-47mj GHSA-x7vm-hc8m-78p7 --- .../GHSA-jhw6-rjph-429f.json | 4 +- .../GHSA-23c2-hg9m-2pw8.json | 35 ++++++++++++++++ .../GHSA-26x5-365c-m568.json | 35 ++++++++++++++++ .../GHSA-4g2w-rjr9-jccg.json | 35 ++++++++++++++++ .../GHSA-58pm-crq9-w2qq.json | 35 ++++++++++++++++ .../GHSA-6733-f273-8q48.json | 35 ++++++++++++++++ .../GHSA-77jp-g8vw-f6xm.json | 35 ++++++++++++++++ .../GHSA-9vh6-fr62-399g.json | 38 +++++++++++++++++ .../GHSA-c48c-24j9-j745.json | 38 +++++++++++++++++ .../GHSA-fhq8-7gjm-8jxf.json | 42 +++++++++++++++++++ .../GHSA-hx98-5v9p-2p84.json | 35 ++++++++++++++++ .../GHSA-v9x5-9rj9-j343.json | 35 ++++++++++++++++ .../GHSA-x5hf-p447-47mj.json | 35 ++++++++++++++++ .../GHSA-x7vm-hc8m-78p7.json | 35 ++++++++++++++++ 14 files changed, 470 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-26x5-365c-m568/GHSA-26x5-365c-m568.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4g2w-rjr9-jccg/GHSA-4g2w-rjr9-jccg.json create mode 100644 advisories/unreviewed/2024/02/GHSA-58pm-crq9-w2qq/GHSA-58pm-crq9-w2qq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json create mode 100644 advisories/unreviewed/2024/02/GHSA-77jp-g8vw-f6xm/GHSA-77jp-g8vw-f6xm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9vh6-fr62-399g/GHSA-9vh6-fr62-399g.json create mode 100644 advisories/unreviewed/2024/02/GHSA-c48c-24j9-j745/GHSA-c48c-24j9-j745.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fhq8-7gjm-8jxf/GHSA-fhq8-7gjm-8jxf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-hx98-5v9p-2p84/GHSA-hx98-5v9p-2p84.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x5hf-p447-47mj/GHSA-x5hf-p447-47mj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x7vm-hc8m-78p7/GHSA-x7vm-hc8m-78p7.json diff --git a/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json b/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json index 17509410f55..100ec0c8b78 100644 --- a/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json +++ b/advisories/unreviewed/2023/04/GHSA-jhw6-rjph-429f/GHSA-jhw6-rjph-429f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhw6-rjph-429f", - "modified": "2023-04-19T21:30:23Z", + "modified": "2024-02-29T21:30:51Z", "published": "2023-04-12T18:30:39Z", "aliases": [ "CVE-2023-1872" @@ -46,7 +46,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-12T16:15:00Z" diff --git a/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json b/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json new file mode 100644 index 00000000000..eae6c85957d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-23c2-hg9m-2pw8/GHSA-23c2-hg9m-2pw8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23c2-hg9m-2pw8", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-27660" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27660" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-NPD-0x41C708-e46f864c48114f45894f4563588d7968?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-26x5-365c-m568/GHSA-26x5-365c-m568.json b/advisories/unreviewed/2024/02/GHSA-26x5-365c-m568/GHSA-26x5-365c-m568.json new file mode 100644 index 00000000000..918d86eb5d3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-26x5-365c-m568/GHSA-26x5-365c-m568.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26x5-365c-m568", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-27658" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27658" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-NPD-0x44900C-8f23082721854117bdea70b6113433fd?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4g2w-rjr9-jccg/GHSA-4g2w-rjr9-jccg.json b/advisories/unreviewed/2024/02/GHSA-4g2w-rjr9-jccg/GHSA-4g2w-rjr9-jccg.json new file mode 100644 index 00000000000..67168c5fc6a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4g2w-rjr9-jccg/GHSA-4g2w-rjr9-jccg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g2w-rjr9-jccg", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-27659" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27659" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-NPD-0x42B4C4-dfeae31d711f414796e1d9eb9cea7d31?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-58pm-crq9-w2qq/GHSA-58pm-crq9-w2qq.json b/advisories/unreviewed/2024/02/GHSA-58pm-crq9-w2qq/GHSA-58pm-crq9-w2qq.json new file mode 100644 index 00000000000..1f6cab2b9f7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-58pm-crq9-w2qq/GHSA-58pm-crq9-w2qq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58pm-crq9-w2qq", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-26548" + ], + "details": "An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26548" + }, + { + "type": "WEB", + "url": "https://github.com/cwh031600/vivotek/blob/main/vivotek-FD8166A-uploadfile-dos/vivotek-FD8166A-uploadfile-analysis.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json b/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json new file mode 100644 index 00000000000..5d616fd0b36 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6733-f273-8q48/GHSA-6733-f273-8q48.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6733-f273-8q48", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-24246" + ], + "details": "Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24246" + }, + { + "type": "WEB", + "url": "https://github.com/qpdf/qpdf/issues/1123" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-77jp-g8vw-f6xm/GHSA-77jp-g8vw-f6xm.json b/advisories/unreviewed/2024/02/GHSA-77jp-g8vw-f6xm/GHSA-77jp-g8vw-f6xm.json new file mode 100644 index 00000000000..c62ba2f170e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-77jp-g8vw-f6xm/GHSA-77jp-g8vw-f6xm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77jp-g8vw-f6xm", + "modified": "2024-02-29T21:30:53Z", + "published": "2024-02-29T21:30:53Z", + "aliases": [ + "CVE-2024-27661" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27661" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-NPD-0x42444C-34458f12482346b291f334eea12e6fd0?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9vh6-fr62-399g/GHSA-9vh6-fr62-399g.json b/advisories/unreviewed/2024/02/GHSA-9vh6-fr62-399g/GHSA-9vh6-fr62-399g.json new file mode 100644 index 00000000000..d41c8cd3b6d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9vh6-fr62-399g/GHSA-9vh6-fr62-399g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vh6-fr62-399g", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-1595" + ], + "details": "Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82\n\n insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1595" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-053-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c48c-24j9-j745/GHSA-c48c-24j9-j745.json b/advisories/unreviewed/2024/02/GHSA-c48c-24j9-j745/GHSA-c48c-24j9-j745.json new file mode 100644 index 00000000000..f5741544ba6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c48c-24j9-j745/GHSA-c48c-24j9-j745.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c48c-24j9-j745", + "modified": "2024-02-29T21:30:51Z", + "published": "2024-02-29T21:30:51Z", + "aliases": [ + "CVE-2024-0068" + ], + "details": "Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0068" + }, + { + "type": "WEB", + "url": "https://www.hypr.com/trust-center/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fhq8-7gjm-8jxf/GHSA-fhq8-7gjm-8jxf.json b/advisories/unreviewed/2024/02/GHSA-fhq8-7gjm-8jxf/GHSA-fhq8-7gjm-8jxf.json new file mode 100644 index 00000000000..1a026198c25 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fhq8-7gjm-8jxf/GHSA-fhq8-7gjm-8jxf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhq8-7gjm-8jxf", + "modified": "2024-02-29T21:30:53Z", + "published": "2024-02-29T21:30:53Z", + "aliases": [ + "CVE-2024-2009" + ], + "details": "A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_login_submit_form of the file login\\index.php of the component Argument Handler. The manipulation of the argument rsargs[] leads to information exposure through error message. The attack may be launched remotely. VDB-255266 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.255266" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.255266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hx98-5v9p-2p84/GHSA-hx98-5v9p-2p84.json b/advisories/unreviewed/2024/02/GHSA-hx98-5v9p-2p84/GHSA-hx98-5v9p-2p84.json new file mode 100644 index 00000000000..d84e9f58b14 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hx98-5v9p-2p84/GHSA-hx98-5v9p-2p84.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx98-5v9p-2p84", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-27657" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27657" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-OOBW-0x41D5B0-462500887ea3464692e3e697cc43838c?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json b/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json new file mode 100644 index 00000000000..83a99fc9daf --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9x5-9rj9-j343", + "modified": "2024-02-29T21:30:53Z", + "published": "2024-02-29T21:30:53Z", + "aliases": [ + "CVE-2024-27662" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27662" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-NPD-0x4116F0-5befc4a65457482c8c4dcb16910ab820?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x5hf-p447-47mj/GHSA-x5hf-p447-47mj.json b/advisories/unreviewed/2024/02/GHSA-x5hf-p447-47mj/GHSA-x5hf-p447-47mj.json new file mode 100644 index 00000000000..547809cf825 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x5hf-p447-47mj/GHSA-x5hf-p447-47mj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5hf-p447-47mj", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-27655" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27655" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-OOBW-0x41E094-f1bd478368644136ad2e3a33e59041b2?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x7vm-hc8m-78p7/GHSA-x7vm-hc8m-78p7.json b/advisories/unreviewed/2024/02/GHSA-x7vm-hc8m-78p7/GHSA-x7vm-hc8m-78p7.json new file mode 100644 index 00000000000..197fbabb2a7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x7vm-hc8m-78p7/GHSA-x7vm-hc8m-78p7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7vm-hc8m-78p7", + "modified": "2024-02-29T21:30:52Z", + "published": "2024-02-29T21:30:52Z", + "aliases": [ + "CVE-2024-27656" + ], + "details": "D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27656" + }, + { + "type": "WEB", + "url": "https://calm-healer-839.notion.site/D-LINK-DIR-823G-OOBW-0x41E2A0-8ea57277c7cd4ea18dbc40bcb41a98f2?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-29T20:15:41Z" + } +} \ No newline at end of file