From f32e65203a6e9aa733d896297098a607bb21cc74 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jan 2024 00:31:39 +0000 Subject: [PATCH] Publish Advisories GHSA-3pfj-g4wr-qj3j GHSA-3vm6-qcr3-wwv3 GHSA-4vf6-2rmx-fgqx GHSA-4x52-4p76-xv6v GHSA-56gq-fgx7-r88g GHSA-5mfr-vx4f-m7q7 GHSA-7hrg-3c44-45cg GHSA-8g65-3569-fx34 GHSA-92hj-6r7m-gqhh GHSA-9gfv-m6hh-94gq GHSA-9m9h-jcjj-xjvx GHSA-f6jr-7pgg-f497 GHSA-fh95-g988-p9j3 GHSA-pf33-q9qc-h48r GHSA-q795-pwf5-9r9x GHSA-rm58-g3gh-gqf5 GHSA-rpjw-97p8-p2xp GHSA-w3p5-6w9w-p383 GHSA-wqmr-cp8m-946m --- .../GHSA-3pfj-g4wr-qj3j.json | 47 +++++++++++++++++++ .../GHSA-3vm6-qcr3-wwv3.json | 35 ++++++++++++++ .../GHSA-4vf6-2rmx-fgqx.json | 47 +++++++++++++++++++ .../GHSA-4x52-4p76-xv6v.json | 35 ++++++++++++++ .../GHSA-56gq-fgx7-r88g.json | 39 +++++++++++++++ .../GHSA-5mfr-vx4f-m7q7.json | 35 ++++++++++++++ .../GHSA-7hrg-3c44-45cg.json | 35 ++++++++++++++ .../GHSA-8g65-3569-fx34.json | 38 +++++++++++++++ .../GHSA-92hj-6r7m-gqhh.json | 35 ++++++++++++++ .../GHSA-9gfv-m6hh-94gq.json | 35 ++++++++++++++ .../GHSA-9m9h-jcjj-xjvx.json | 39 +++++++++++++++ .../GHSA-f6jr-7pgg-f497.json | 35 ++++++++++++++ .../GHSA-fh95-g988-p9j3.json | 35 ++++++++++++++ .../GHSA-pf33-q9qc-h48r.json | 46 ++++++++++++++++++ .../GHSA-q795-pwf5-9r9x.json | 35 ++++++++++++++ .../GHSA-rm58-g3gh-gqf5.json | 38 +++++++++++++++ .../GHSA-rpjw-97p8-p2xp.json | 47 +++++++++++++++++++ .../GHSA-w3p5-6w9w-p383.json | 35 ++++++++++++++ .../GHSA-wqmr-cp8m-946m.json | 38 +++++++++++++++ 19 files changed, 729 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4vf6-2rmx-fgqx/GHSA-4vf6-2rmx-fgqx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json create mode 100644 advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json create mode 100644 advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pf33-q9qc-h48r/GHSA-pf33-q9qc-h48r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rpjw-97p8-p2xp/GHSA-rpjw-97p8-p2xp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json diff --git a/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json b/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json new file mode 100644 index 00000000000..912f1947c72 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3pfj-g4wr-qj3j/GHSA-3pfj-g4wr-qj3j.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pfj-g4wr-qj3j", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2020-26625" + ], + "details": "A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26625" + }, + { + "type": "WEB", + "url": "https://github.com/GilaCMS/gila" + }, + { + "type": "WEB", + "url": "https://github.com/GilaCMS/gila/security/policy" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/176301/GilaCMS-1.15.4-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "http://gilacms.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json b/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json new file mode 100644 index 00000000000..6b83ede0406 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3vm6-qcr3-wwv3/GHSA-3vm6-qcr3-wwv3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vm6-qcr3-wwv3", + "modified": "2024-01-03T00:30:24Z", + "published": "2024-01-03T00:30:24Z", + "aliases": [ + "CVE-2023-49555" + ], + "details": "An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49555" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/248" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4vf6-2rmx-fgqx/GHSA-4vf6-2rmx-fgqx.json b/advisories/unreviewed/2024/01/GHSA-4vf6-2rmx-fgqx/GHSA-4vf6-2rmx-fgqx.json new file mode 100644 index 00000000000..0a4cffc330e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4vf6-2rmx-fgqx/GHSA-4vf6-2rmx-fgqx.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vf6-2rmx-fgqx", + "modified": "2024-01-03T00:30:22Z", + "published": "2024-01-03T00:30:22Z", + "aliases": [ + "CVE-2020-26624" + ], + "details": "A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26624" + }, + { + "type": "WEB", + "url": "https://github.com/GilaCMS/gila" + }, + { + "type": "WEB", + "url": "https://github.com/GilaCMS/gila/security/policy" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/176301/GilaCMS-1.15.4-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "http://gilacms.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json b/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json new file mode 100644 index 00000000000..a08a9becc22 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4x52-4p76-xv6v/GHSA-4x52-4p76-xv6v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x52-4p76-xv6v", + "modified": "2024-01-03T00:30:24Z", + "published": "2024-01-03T00:30:24Z", + "aliases": [ + "CVE-2023-49554" + ], + "details": "Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49554" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/249" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json b/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json new file mode 100644 index 00000000000..581e84ff955 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-56gq-fgx7-r88g/GHSA-56gq-fgx7-r88g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56gq-fgx7-r88g", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-50020" + ], + "details": "An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50020" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/2734" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/commit/1aba814938e3a1b2eec7014bf6ce132d34622e08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json b/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json new file mode 100644 index 00000000000..81cf011a178 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mfr-vx4f-m7q7", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-49550" + ], + "details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49550" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/252" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json b/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json new file mode 100644 index 00000000000..4ad7e85b9af --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7hrg-3c44-45cg/GHSA-7hrg-3c44-45cg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hrg-3c44-45cg", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-49551" + ], + "details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49551" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/257" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json b/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json new file mode 100644 index 00000000000..069fababc13 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8g65-3569-fx34/GHSA-8g65-3569-fx34.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g65-3569-fx34", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-4164" + ], + "details": "There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4164" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel-watch/2023/2023-12-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json b/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json new file mode 100644 index 00000000000..bca75f99b10 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-92hj-6r7m-gqhh/GHSA-92hj-6r7m-gqhh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92hj-6r7m-gqhh", + "modified": "2024-01-03T00:30:24Z", + "published": "2024-01-03T00:30:24Z", + "aliases": [ + "CVE-2023-49557" + ], + "details": "An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49557" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/253" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json b/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json new file mode 100644 index 00000000000..4446ecc5e93 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9gfv-m6hh-94gq/GHSA-9gfv-m6hh-94gq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gfv-m6hh-94gq", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-49553" + ], + "details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49553" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/253" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json b/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json new file mode 100644 index 00000000000..b750accecca --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9m9h-jcjj-xjvx/GHSA-9m9h-jcjj-xjvx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m9h-jcjj-xjvx", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-50019" + ], + "details": "An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50019" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/issues/2733" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/commit/7278714133422cee46c32c7523f81ec2cecad9e2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json b/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json new file mode 100644 index 00000000000..a1bba1e02dc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f6jr-7pgg-f497/GHSA-f6jr-7pgg-f497.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6jr-7pgg-f497", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-49552" + ], + "details": "An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49552" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/256" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json b/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json new file mode 100644 index 00000000000..a759e950c77 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fh95-g988-p9j3/GHSA-fh95-g988-p9j3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh95-g988-p9j3", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-49549" + ], + "details": "An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49549" + }, + { + "type": "WEB", + "url": "https://github.com/cesanta/mjs/issues/251" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pf33-q9qc-h48r/GHSA-pf33-q9qc-h48r.json b/advisories/unreviewed/2024/01/GHSA-pf33-q9qc-h48r/GHSA-pf33-q9qc-h48r.json new file mode 100644 index 00000000000..6457efd74e9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pf33-q9qc-h48r/GHSA-pf33-q9qc-h48r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf33-q9qc-h48r", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2024-0196" + ], + "details": "A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resource/file/api/save?auto=1. The manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249511.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0196" + }, + { + "type": "WEB", + "url": "https://github.com/laoquanshi/puppy/blob/main/Magic-Api%20Code%20Execution%20Vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249511" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249511" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json b/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json new file mode 100644 index 00000000000..f3bae60b8a0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q795-pwf5-9r9x/GHSA-q795-pwf5-9r9x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q795-pwf5-9r9x", + "modified": "2024-01-03T00:30:24Z", + "published": "2024-01-03T00:30:24Z", + "aliases": [ + "CVE-2023-49556" + ], + "details": "Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49556" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/250" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json b/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json new file mode 100644 index 00000000000..e50484418fd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rm58-g3gh-gqf5/GHSA-rm58-g3gh-gqf5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm58-g3gh-gqf5", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-6339" + ], + "details": "Google Nest WiFi Pro root code-execution & user-data compromise", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6339" + }, + { + "type": "WEB", + "url": "https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rpjw-97p8-p2xp/GHSA-rpjw-97p8-p2xp.json b/advisories/unreviewed/2024/01/GHSA-rpjw-97p8-p2xp/GHSA-rpjw-97p8-p2xp.json new file mode 100644 index 00000000000..3558194da5e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rpjw-97p8-p2xp/GHSA-rpjw-97p8-p2xp.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpjw-97p8-p2xp", + "modified": "2024-01-03T00:30:22Z", + "published": "2024-01-03T00:30:22Z", + "aliases": [ + "CVE-2020-26623" + ], + "details": "SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26623" + }, + { + "type": "WEB", + "url": "https://github.com/GilaCMS/gila" + }, + { + "type": "WEB", + "url": "https://github.com/GilaCMS/gila/security/policy" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/176301/GilaCMS-1.15.4-SQL-Injection.html" + }, + { + "type": "WEB", + "url": "http://gilacms.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json b/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json new file mode 100644 index 00000000000..b8ae22d453c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w3p5-6w9w-p383/GHSA-w3p5-6w9w-p383.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3p5-6w9w-p383", + "modified": "2024-01-03T00:30:24Z", + "published": "2024-01-03T00:30:24Z", + "aliases": [ + "CVE-2023-49558" + ], + "details": "An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49558" + }, + { + "type": "WEB", + "url": "https://github.com/yasm/yasm/issues/252" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-03T00:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json b/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json new file mode 100644 index 00000000000..b357a7f1b7c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wqmr-cp8m-946m/GHSA-wqmr-cp8m-946m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqmr-cp8m-946m", + "modified": "2024-01-03T00:30:23Z", + "published": "2024-01-03T00:30:23Z", + "aliases": [ + "CVE-2023-48418" + ], + "details": " In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a\n    possible way to access adb before SUW completion due to an insecure default\n    value. This could lead to local escalation of privilege with no additional\n    execution privileges needed. User interaction is not needed for\n    exploitation\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48418" + }, + { + "type": "WEB", + "url": "https://source.android.com/docs/security/bulletin/pixel-watch/2023/2023-12-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T23:15:11Z" + } +} \ No newline at end of file