Publish Advisories

GHSA-394m-vxwj-363j
GHSA-38h4-hmr8-8c7q
GHSA-4fvr-c9qm-r85w
GHSA-4q6j-vwqc-gp8r
GHSA-7q27-3v2r-ccj9
GHSA-cf88-f3cc-2r22
GHSA-g9w9-pqmh-3hm7
GHSA-h6qx-c9g7-659w
GHSA-hmch-8qfm-f6mp
GHSA-hvg8-7678-v53j
GHSA-hwhf-72f8-crgh
GHSA-jj76-44fx-5g9w
GHSA-mqh3-w8fw-j85c
GHSA-p6wf-f62f-3j43
GHSA-p762-67q5-3hrq
GHSA-p93q-wj5g-6w29
GHSA-r4m8-fhqx-9796
GHSA-rjpg-qpwf-xp3r
GHSA-vpg3-wxv6-fm2j
GHSA-wmhm-48vh-qjwg
GHSA-x7f5-x9wp-mgqw
This commit is contained in:
advisory-database[bot]
2025-01-06 12:31:36 +00:00
parent 417420434e
commit f27014e7fb
21 changed files with 729 additions and 4 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-394m-vxwj-363j",
"modified": "2024-02-16T09:30:25Z",
"modified": "2025-01-06T12:30:31Z",
"published": "2024-02-16T09:30:25Z",
"aliases": [
"CVE-2023-49508"
],
"details": "Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-16T08:15:39Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38h4-hmr8-8c7q",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45541"
],
"details": "Memory corruption when IOCTL call is invoked from user-space to read board data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45541"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:09Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4fvr-c9qm-r85w",
"modified": "2025-01-06T12:30:32Z",
"published": "2025-01-06T12:30:32Z",
"aliases": [
"CVE-2024-33055"
],
"details": "Memory corruption while invoking IOCTL calls to unmap the DMA buffers.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33055"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:08Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q6j-vwqc-gp8r",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45542"
],
"details": "Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45542"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:09Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q27-3v2r-ccj9",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-33067"
],
"details": "Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33067"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:08Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cf88-f3cc-2r22",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45559"
],
"details": "Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45559"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:10Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9w9-pqmh-3hm7",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45553"
],
"details": "Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45553"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:10Z"
}
}
@@ -0,0 +1,34 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6qx-c9g7-659w",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-43064"
],
"details": "Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43064"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:09Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmch-8qfm-f6mp",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-12970"
],
"details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus OS My Computer: before 0.7.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12970"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-24-1900"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T12:15:06Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvg8-7678-v53j",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45548"
],
"details": "Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45548"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:09Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hwhf-72f8-crgh",
"modified": "2025-01-06T12:30:32Z",
"published": "2025-01-06T12:30:32Z",
"aliases": [
"CVE-2024-23366"
],
"details": "Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23366"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:07Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj76-44fx-5g9w",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45558"
],
"details": "Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45558"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:10Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqh3-w8fw-j85c",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45550"
],
"details": "Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45550"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-129"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:10Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6wf-f62f-3j43",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45547"
],
"details": "Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45547"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:09Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p762-67q5-3hrq",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45546"
],
"details": "Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45546"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:09Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p93q-wj5g-6w29",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-33059"
],
"details": "Memory corruption while processing frame command IOCTL calls.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33059"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:08Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4m8-fhqx-9796",
"modified": "2025-01-06T12:30:32Z",
"published": "2025-01-06T12:30:32Z",
"aliases": [
"CVE-2024-21464"
],
"details": "Memory corruption while processing IPA statistics, when there are no active clients registered.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21464"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:06Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjpg-qpwf-xp3r",
"modified": "2025-01-06T12:30:32Z",
"published": "2025-01-06T12:30:32Z",
"aliases": [
"CVE-2024-33041"
],
"details": "Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33041"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-823"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:08Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpg3-wxv6-fm2j",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-43063"
],
"details": "information disclosure while invoking the mailbox read API.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43063"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:08Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmhm-48vh-qjwg",
"modified": "2025-01-06T12:30:33Z",
"published": "2025-01-06T12:30:33Z",
"aliases": [
"CVE-2024-45555"
],
"details": "Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45555"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T11:15:10Z"
}
}

Some files were not shown because too many files have changed in this diff Show More