diff --git a/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json b/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json index 7a4b3ccb54a..5e5fbff792d 100644 --- a/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json +++ b/advisories/unreviewed/2023/06/GHSA-3jff-v2mx-4rwr/GHSA-3jff-v2mx-4rwr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-613" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-hgcx-83q6-569g/GHSA-hgcx-83q6-569g.json b/advisories/unreviewed/2023/06/GHSA-hgcx-83q6-569g/GHSA-hgcx-83q6-569g.json index c582af16e18..4adc4d9e0dc 100644 --- a/advisories/unreviewed/2023/06/GHSA-hgcx-83q6-569g/GHSA-hgcx-83q6-569g.json +++ b/advisories/unreviewed/2023/06/GHSA-hgcx-83q6-569g/GHSA-hgcx-83q6-569g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-rx3v-c929-952g/GHSA-rx3v-c929-952g.json b/advisories/unreviewed/2023/06/GHSA-rx3v-c929-952g/GHSA-rx3v-c929-952g.json index 3fd4b6c58ed..358f5231357 100644 --- a/advisories/unreviewed/2023/06/GHSA-rx3v-c929-952g/GHSA-rx3v-c929-952g.json +++ b/advisories/unreviewed/2023/06/GHSA-rx3v-c929-952g/GHSA-rx3v-c929-952g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-427" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json b/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json index cd384e63856..fc573db30ab 100644 --- a/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json +++ b/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json b/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json index 15cdacca8f6..a2cbde5f8bb 100644 --- a/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json +++ b/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c537-pf3w-23p5", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-12-03T21:31:20Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42939" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private browsing activity may be unexpectedly saved in the App Privacy Report.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:50Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json b/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json index b11d4f764c2..a36dfdd09af 100644 --- a/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json +++ b/advisories/unreviewed/2024/02/GHSA-gqvf-8g7j-7gh5/GHSA-gqvf-8g7j-7gh5.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -48,7 +46,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json b/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json index 6c90e2aba71..f5e5f396a02 100644 --- a/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json +++ b/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-284" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json b/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json index 5439fe62168..8bef83b081f 100644 --- a/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json +++ b/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", diff --git a/advisories/unreviewed/2024/02/GHSA-wpxj-r4vx-g93m/GHSA-wpxj-r4vx-g93m.json b/advisories/unreviewed/2024/02/GHSA-wpxj-r4vx-g93m/GHSA-wpxj-r4vx-g93m.json index 730f5f1b5d3..8526cadff54 100644 --- a/advisories/unreviewed/2024/02/GHSA-wpxj-r4vx-g93m/GHSA-wpxj-r4vx-g93m.json +++ b/advisories/unreviewed/2024/02/GHSA-wpxj-r4vx-g93m/GHSA-wpxj-r4vx-g93m.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -36,7 +34,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-7jpm-7cvw-x3ph/GHSA-7jpm-7cvw-x3ph.json b/advisories/unreviewed/2024/04/GHSA-7jpm-7cvw-x3ph/GHSA-7jpm-7cvw-x3ph.json index 118ff29270a..011b5e098c4 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jpm-7cvw-x3ph/GHSA-7jpm-7cvw-x3ph.json +++ b/advisories/unreviewed/2024/04/GHSA-7jpm-7cvw-x3ph/GHSA-7jpm-7cvw-x3ph.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h9f9-5v63-95r8/GHSA-h9f9-5v63-95r8.json b/advisories/unreviewed/2024/04/GHSA-h9f9-5v63-95r8/GHSA-h9f9-5v63-95r8.json index f7e50c43a62..1e0320e9195 100644 --- a/advisories/unreviewed/2024/04/GHSA-h9f9-5v63-95r8/GHSA-h9f9-5v63-95r8.json +++ b/advisories/unreviewed/2024/04/GHSA-h9f9-5v63-95r8/GHSA-h9f9-5v63-95r8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-601" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json b/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json index 4c965290b4e..277a28ae76f 100644 --- a/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json +++ b/advisories/unreviewed/2024/04/GHSA-wjjj-mh65-98qx/GHSA-wjjj-mh65-98qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjjj-mh65-98qx", - "modified": "2024-04-30T00:30:35Z", + "modified": "2024-12-03T21:31:20Z", "published": "2024-04-30T00:30:35Z", "aliases": [ "CVE-2023-52727" ], "details": "Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T00:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f839-3vrj-wvgw/GHSA-f839-3vrj-wvgw.json b/advisories/unreviewed/2024/05/GHSA-f839-3vrj-wvgw/GHSA-f839-3vrj-wvgw.json index 31e728d8aac..2849eb18935 100644 --- a/advisories/unreviewed/2024/05/GHSA-f839-3vrj-wvgw/GHSA-f839-3vrj-wvgw.json +++ b/advisories/unreviewed/2024/05/GHSA-f839-3vrj-wvgw/GHSA-f839-3vrj-wvgw.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-f839-3vrj-wvgw", - "modified": "2024-05-06T18:30:36Z", + "modified": "2024-12-03T21:31:20Z", "published": "2024-05-06T18:30:36Z", "aliases": [ "CVE-2024-33409" ], "details": "SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the name parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33409" }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%201.pdf" + }, { "type": "WEB", "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%208.pdf" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T18:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-35m7-cqfx-w4jw/GHSA-35m7-cqfx-w4jw.json b/advisories/unreviewed/2024/07/GHSA-35m7-cqfx-w4jw/GHSA-35m7-cqfx-w4jw.json index f6244a7ee61..7572902bded 100644 --- a/advisories/unreviewed/2024/07/GHSA-35m7-cqfx-w4jw/GHSA-35m7-cqfx-w4jw.json +++ b/advisories/unreviewed/2024/07/GHSA-35m7-cqfx-w4jw/GHSA-35m7-cqfx-w4jw.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,7 +26,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-mrhp-8chw-79jf/GHSA-mrhp-8chw-79jf.json b/advisories/unreviewed/2024/07/GHSA-mrhp-8chw-79jf/GHSA-mrhp-8chw-79jf.json index 18f42a85a0d..2f68e7b9f84 100644 --- a/advisories/unreviewed/2024/07/GHSA-mrhp-8chw-79jf/GHSA-mrhp-8chw-79jf.json +++ b/advisories/unreviewed/2024/07/GHSA-mrhp-8chw-79jf/GHSA-mrhp-8chw-79jf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-3xmv-hrq3-4vc5/GHSA-3xmv-hrq3-4vc5.json b/advisories/unreviewed/2024/08/GHSA-3xmv-hrq3-4vc5/GHSA-3xmv-hrq3-4vc5.json index a7b555e20b6..06fb9f42a5f 100644 --- a/advisories/unreviewed/2024/08/GHSA-3xmv-hrq3-4vc5/GHSA-3xmv-hrq3-4vc5.json +++ b/advisories/unreviewed/2024/08/GHSA-3xmv-hrq3-4vc5/GHSA-3xmv-hrq3-4vc5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-613" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json index 593bd30c572..75bfcc7a6c2 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7g-wccp-rrhj", - "modified": "2024-11-21T21:33:31Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-08-05T15:30:53Z", "aliases": [ "CVE-2024-7409" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7409" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10518" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6811" diff --git a/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json b/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json index ed4d57ed1a3..acb5a21aac0 100644 --- a/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json +++ b/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m5w-7xhr-393x", - "modified": "2024-08-14T18:32:37Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2023-31348" @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json b/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json index f78df37fe69..fbcc77937e0 100644 --- a/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json +++ b/advisories/unreviewed/2024/08/GHSA-pwh8-gr2w-8xpq/GHSA-pwh8-gr2w-8xpq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pwh8-gr2w-8xpq", - "modified": "2024-08-14T03:31:07Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2023-31349" diff --git a/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json b/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json index 27b215034b6..3bc506a51ac 100644 --- a/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json +++ b/advisories/unreviewed/2024/10/GHSA-c45f-33wq-x2qc/GHSA-c45f-33wq-x2qc.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json b/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json index 70c7210af19..72c1f24b2e6 100644 --- a/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json +++ b/advisories/unreviewed/2024/11/GHSA-f63f-f9wj-5wjg/GHSA-f63f-f9wj-5wjg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f63f-f9wj-5wjg", - "modified": "2024-11-29T12:31:49Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-11-29T12:31:49Z", "aliases": [ "CVE-2024-47094" ], "details": "Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-hq5q-m98q-77q2/GHSA-hq5q-m98q-77q2.json b/advisories/unreviewed/2024/11/GHSA-hq5q-m98q-77q2/GHSA-hq5q-m98q-77q2.json index 9875ee1a119..cfcad13570f 100644 --- a/advisories/unreviewed/2024/11/GHSA-hq5q-m98q-77q2/GHSA-hq5q-m98q-77q2.json +++ b/advisories/unreviewed/2024/11/GHSA-hq5q-m98q-77q2/GHSA-hq5q-m98q-77q2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json b/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json index 4e649597ec3..7784a2245a5 100644 --- a/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json +++ b/advisories/unreviewed/2024/11/GHSA-j2fh-p4jc-3h97/GHSA-j2fh-p4jc-3h97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j2fh-p4jc-3h97", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-11-19T18:31:07Z", "aliases": [ "CVE-2024-53059" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()\n\n1. The size of the response packet is not validated.\n2. The response buffer is not freed.\n\nResolve these issues by switching to iwl_mvm_send_cmd_status(),\nwhich handles both size validation and frees the buffer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jwg6-mwv7-v5j4/GHSA-jwg6-mwv7-v5j4.json b/advisories/unreviewed/2024/11/GHSA-jwg6-mwv7-v5j4/GHSA-jwg6-mwv7-v5j4.json index 97b08c3f123..b2b44da6020 100644 --- a/advisories/unreviewed/2024/11/GHSA-jwg6-mwv7-v5j4/GHSA-jwg6-mwv7-v5j4.json +++ b/advisories/unreviewed/2024/11/GHSA-jwg6-mwv7-v5j4/GHSA-jwg6-mwv7-v5j4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json b/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json index 8d21a9f54cb..28a6cd8adfa 100644 --- a/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json +++ b/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxg5-mcmp-m3m9", - "modified": "2024-11-13T00:30:48Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2024-11168" @@ -13,9 +13,7 @@ "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -33,10 +31,18 @@ "type": "WEB", "url": "https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e" + }, { "type": "WEB", "url": "https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550" }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132" + }, { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T" diff --git a/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json b/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json index 520795e58ab..87ba1b79265 100644 --- a/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json +++ b/advisories/unreviewed/2024/11/GHSA-r9m7-7gg7-9ppr/GHSA-r9m7-7gg7-9ppr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r9m7-7gg7-9ppr", - "modified": "2024-11-19T18:31:07Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-11-19T18:31:06Z", "aliases": [ "CVE-2024-53060" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: prevent NULL pointer dereference if ATIF is not supported\n\nacpi_evaluate_object() may return AE_NOT_FOUND (failure), which\nwould result in dereferencing buffer.pointer (obj) while being NULL.\n\nAlthough this case may be unrealistic for the current code, it is\nstill better to protect against possible bugs.\n\nBail out also when status is AE_NOT_FOUND.\n\nThis fixes 1 FORWARD_NULL issue reported by Coverity\nReport: CID 1600951: Null pointer dereferences (FORWARD_NULL)\n\n(cherry picked from commit 91c9e221fe2553edf2db71627d8453f083de87a1)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T18:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json b/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json index 85c730c0fa8..584206c69bb 100644 --- a/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json +++ b/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json b/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json index 05fbf9713b9..6735515d911 100644 --- a/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json +++ b/advisories/unreviewed/2024/12/GHSA-23mj-f5f2-4h46/GHSA-23mj-f5f2-4h46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23mj-f5f2-4h46", - "modified": "2024-12-03T00:31:31Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-12-03T00:31:31Z", "aliases": [ "CVE-2024-53939" ], "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T22:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3p32-8vq4-qvph/GHSA-3p32-8vq4-qvph.json b/advisories/unreviewed/2024/12/GHSA-3p32-8vq4-qvph/GHSA-3p32-8vq4-qvph.json new file mode 100644 index 00000000000..ec0299a442e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3p32-8vq4-qvph/GHSA-3p32-8vq4-qvph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p32-8vq4-qvph", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-48080" + ], + "details": "An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48080" + }, + { + "type": "WEB", + "url": "https://gist.github.com/pengwGit/cd3c1701a9e05b424fa6c60d86845de4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-595j-4p24-6jv2/GHSA-595j-4p24-6jv2.json b/advisories/unreviewed/2024/12/GHSA-595j-4p24-6jv2/GHSA-595j-4p24-6jv2.json new file mode 100644 index 00000000000..55ce7eec5d2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-595j-4p24-6jv2/GHSA-595j-4p24-6jv2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-595j-4p24-6jv2", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-50948" + ], + "details": "An issue in mochiMQTT v2.6.3 allows attackers to cause a Denial of Service (DoS) via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50948" + }, + { + "type": "WEB", + "url": "https://gist.github.com/pengwGit/39760ed5ae03171622ca8215dc0d8c60" + }, + { + "type": "WEB", + "url": "https://github.com/mochi-mqtt/server" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-88r2-xrwf-mvhm/GHSA-88r2-xrwf-mvhm.json b/advisories/unreviewed/2024/12/GHSA-88r2-xrwf-mvhm/GHSA-88r2-xrwf-mvhm.json new file mode 100644 index 00000000000..d7d8a4b4fe3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-88r2-xrwf-mvhm/GHSA-88r2-xrwf-mvhm.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88r2-xrwf-mvhm", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-51772" + ], + "details": "An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51772" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json b/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json index 2bc21e7d597..edc80186f79 100644 --- a/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json +++ b/advisories/unreviewed/2024/12/GHSA-99rp-8r7p-prmv/GHSA-99rp-8r7p-prmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99rp-8r7p-prmv", - "modified": "2024-12-03T00:31:31Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-12-03T00:31:31Z", "aliases": [ "CVE-2024-53938" ], "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achieve full control over the router remotely without any authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T22:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-ccg8-9h52-fhg8/GHSA-ccg8-9h52-fhg8.json b/advisories/unreviewed/2024/12/GHSA-ccg8-9h52-fhg8/GHSA-ccg8-9h52-fhg8.json new file mode 100644 index 00000000000..522a70434f0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ccg8-9h52-fhg8/GHSA-ccg8-9h52-fhg8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccg8-9h52-fhg8", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-45757" + ], + "details": "An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45757" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-45757-centreon-bam-high-severity-4123?tid=4123" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json b/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json index 81f331c8be2..ec0c38d0e0d 100644 --- a/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json +++ b/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccwq-3vpf-86cw", - "modified": "2024-12-03T15:31:23Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-12-02T18:31:56Z", "aliases": [ "CVE-2024-53564" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://gist.github.com/hyp164D1/490732de230edf97423f6d95b0d2f903" + }, + { + "type": "WEB", + "url": "https://gist.github.com/hyp164D1/d419bdf3e7e352088a21631d0f452a8c" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-chjv-79m6-ph9c/GHSA-chjv-79m6-ph9c.json b/advisories/unreviewed/2024/12/GHSA-chjv-79m6-ph9c/GHSA-chjv-79m6-ph9c.json new file mode 100644 index 00000000000..36267b09e88 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-chjv-79m6-ph9c/GHSA-chjv-79m6-ph9c.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chjv-79m6-ph9c", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-51773" + ], + "details": "A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including accessing the user's data and altering information within the user's permissions. This could lead to data modification, deletion, or theft, including unauthorized access to files, file deletion, or the theft of session cookies, which an attacker could use to hijack a user's session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51773" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json b/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json index b63af8e7a5e..106d0d29c30 100644 --- a/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json +++ b/advisories/unreviewed/2024/12/GHSA-chvj-r97v-jv3h/GHSA-chvj-r97v-jv3h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chvj-r97v-jv3h", - "modified": "2024-12-03T00:31:32Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T00:31:32Z", "aliases": [ "CVE-2024-53937" ], "details": "An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with root-level permissions. Device setup does not require this password to be changed during setup in order to utilize the device. (However, the TELNET password is dictated by the current GUI password.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T23:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-cmfx-pwgh-63xj/GHSA-cmfx-pwgh-63xj.json b/advisories/unreviewed/2024/12/GHSA-cmfx-pwgh-63xj/GHSA-cmfx-pwgh-63xj.json index d3bc9565455..2637fc8f1ed 100644 --- a/advisories/unreviewed/2024/12/GHSA-cmfx-pwgh-63xj/GHSA-cmfx-pwgh-63xj.json +++ b/advisories/unreviewed/2024/12/GHSA-cmfx-pwgh-63xj/GHSA-cmfx-pwgh-63xj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cmfx-pwgh-63xj", - "modified": "2024-12-02T21:31:20Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-12-02T21:31:20Z", "aliases": [ "CVE-2018-9413" ], "details": "In handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fq6h-wgjw-ffm5/GHSA-fq6h-wgjw-ffm5.json b/advisories/unreviewed/2024/12/GHSA-fq6h-wgjw-ffm5/GHSA-fq6h-wgjw-ffm5.json new file mode 100644 index 00000000000..293374c851a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fq6h-wgjw-ffm5/GHSA-fq6h-wgjw-ffm5.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq6h-wgjw-ffm5", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-53672" + ], + "details": "A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53672" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json b/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json index dd7cd60ad5b..a773ff1438e 100644 --- a/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json +++ b/advisories/unreviewed/2024/12/GHSA-g998-4r58-rr8q/GHSA-g998-4r58-rr8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g998-4r58-rr8q", - "modified": "2024-12-03T18:31:04Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T18:31:04Z", "aliases": [ "CVE-2024-52545" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/sfewer-r7/LorexExploit" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/12/03/lorex-2k-indoor-wi-fi-security-camera-multiple-vulnerabilities-fixed" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json b/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json index c2a351e6c7c..d75a6d7ba08 100644 --- a/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json +++ b/advisories/unreviewed/2024/12/GHSA-gjcw-vmfm-pc8c/GHSA-gjcw-vmfm-pc8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjcw-vmfm-pc8c", - "modified": "2024-12-03T18:31:04Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T18:31:04Z", "aliases": [ "CVE-2024-52546" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/sfewer-r7/LorexExploit" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/12/03/lorex-2k-indoor-wi-fi-security-camera-multiple-vulnerabilities-fixed" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json b/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json index 3a5792be3f9..4919b7a5109 100644 --- a/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json +++ b/advisories/unreviewed/2024/12/GHSA-h4c6-r2qh-5wvm/GHSA-h4c6-r2qh-5wvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h4c6-r2qh-5wvm", - "modified": "2024-12-03T00:31:31Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T00:31:31Z", "aliases": [ "CVE-2024-53941" ], "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T22:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json b/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json index a589d473c08..f055565170f 100644 --- a/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json +++ b/advisories/unreviewed/2024/12/GHSA-mhf4-rfw7-w7pj/GHSA-mhf4-rfw7-w7pj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mhf4-rfw7-w7pj", - "modified": "2024-12-03T00:31:31Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T00:31:31Z", "aliases": [ "CVE-2024-53940" ], "details": "An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the ping utility, enabling arbitrary command execution with root-level permissions on the device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T22:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json b/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json index 6f478c4fe46..68ac50d3bec 100644 --- a/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json +++ b/advisories/unreviewed/2024/12/GHSA-mjgg-cggm-7j9f/GHSA-mjgg-cggm-7j9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjgg-cggm-7j9f", - "modified": "2024-12-03T18:31:04Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T18:31:04Z", "aliases": [ "CVE-2024-52544" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/sfewer-r7/LorexExploit" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/12/03/lorex-2k-indoor-wi-fi-security-camera-multiple-vulnerabilities-fixed" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-mv99-73mv-q4qp/GHSA-mv99-73mv-q4qp.json b/advisories/unreviewed/2024/12/GHSA-mv99-73mv-q4qp/GHSA-mv99-73mv-q4qp.json index 9a8e4c41d59..4da2d1cf464 100644 --- a/advisories/unreviewed/2024/12/GHSA-mv99-73mv-q4qp/GHSA-mv99-73mv-q4qp.json +++ b/advisories/unreviewed/2024/12/GHSA-mv99-73mv-q4qp/GHSA-mv99-73mv-q4qp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mv99-73mv-q4qp", - "modified": "2024-12-02T21:31:20Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-12-02T21:31:20Z", "aliases": [ "CVE-2018-9376" ], "details": "In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p9qr-rxpv-wm86/GHSA-p9qr-rxpv-wm86.json b/advisories/unreviewed/2024/12/GHSA-p9qr-rxpv-wm86/GHSA-p9qr-rxpv-wm86.json new file mode 100644 index 00000000000..cad92ffdc3e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p9qr-rxpv-wm86/GHSA-p9qr-rxpv-wm86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9qr-rxpv-wm86", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-53921" + ], + "details": "An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53921" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json b/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json index 482ec4419e8..05b10d594a3 100644 --- a/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json +++ b/advisories/unreviewed/2024/12/GHSA-qf6v-j5x7-cg97/GHSA-qf6v-j5x7-cg97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf6v-j5x7-cg97", - "modified": "2024-12-03T18:31:04Z", + "modified": "2024-12-03T21:31:22Z", "published": "2024-12-03T18:31:04Z", "aliases": [ "CVE-2024-52547" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/sfewer-r7/LorexExploit" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/12/03/lorex-2k-indoor-wi-fi-security-camera-multiple-vulnerabilities-fixed" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-v28f-h33w-c2vv/GHSA-v28f-h33w-c2vv.json b/advisories/unreviewed/2024/12/GHSA-v28f-h33w-c2vv/GHSA-v28f-h33w-c2vv.json new file mode 100644 index 00000000000..9b02aa36242 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v28f-h33w-c2vv/GHSA-v28f-h33w-c2vv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v28f-h33w-c2vv", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-51771" + ], + "details": "A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51771" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vjgw-3ffm-c33h/GHSA-vjgw-3ffm-c33h.json b/advisories/unreviewed/2024/12/GHSA-vjgw-3ffm-c33h/GHSA-vjgw-3ffm-c33h.json new file mode 100644 index 00000000000..5161c3b5142 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vjgw-3ffm-c33h/GHSA-vjgw-3ffm-c33h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjgw-3ffm-c33h", + "modified": "2024-12-03T21:31:22Z", + "published": "2024-12-03T21:31:22Z", + "aliases": [ + "CVE-2024-51114" + ], + "details": "An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51114" + }, + { + "type": "WEB", + "url": "https://github.com/ZackSecurity/VulnerReport/blob/cve/DCN/2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-03T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json b/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json index fe919a4f73a..36722ce4056 100644 --- a/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json +++ b/advisories/unreviewed/2024/12/GHSA-wx8m-vcrx-w4p5/GHSA-wx8m-vcrx-w4p5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wx8m-vcrx-w4p5", - "modified": "2024-12-03T00:31:31Z", + "modified": "2024-12-03T21:31:21Z", "published": "2024-12-03T00:31:31Z", "aliases": [ "CVE-2024-53375" ], "details": "Authenticated remote code execution (RCE) vulnerabilities affect TP-Link Archer, Deco, and Tapo series routers. A vulnerability exists in the \"tmp_get_sites\" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the installation or activation of the HomeShield functionality.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T22:15:10Z"