diff --git a/advisories/unreviewed/2023/05/GHSA-4794-756c-cx7v/GHSA-4794-756c-cx7v.json b/advisories/unreviewed/2023/05/GHSA-4794-756c-cx7v/GHSA-4794-756c-cx7v.json new file mode 100644 index 00000000000..b4140bfd6c9 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-4794-756c-cx7v/GHSA-4794-756c-cx7v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4794-756c-cx7v", + "modified": "2023-05-22T12:30:25Z", + "published": "2023-05-22T12:30:25Z", + "aliases": [ + "CVE-2023-2597" + ], + "details": "In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2597" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-openj9/openj9/pull/17259" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-cr44-jj23-rv3c/GHSA-cr44-jj23-rv3c.json b/advisories/unreviewed/2023/05/GHSA-cr44-jj23-rv3c/GHSA-cr44-jj23-rv3c.json new file mode 100644 index 00000000000..a2af295b955 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-cr44-jj23-rv3c/GHSA-cr44-jj23-rv3c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr44-jj23-rv3c", + "modified": "2023-05-22T12:30:25Z", + "published": "2023-05-22T12:30:25Z", + "aliases": [ + "CVE-2023-2832" + ], + "details": " SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2832" + }, + { + "type": "WEB", + "url": "https://github.com/unilogies/bumsys/commit/1b426f58a513194206d0ea8ab58baf1461e54978" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/37b80402-0edf-4f26-a668-b6f8b48dcdfb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-f88f-9mmf-7xm6/GHSA-f88f-9mmf-7xm6.json b/advisories/unreviewed/2023/05/GHSA-f88f-9mmf-7xm6/GHSA-f88f-9mmf-7xm6.json new file mode 100644 index 00000000000..cf81260784e --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-f88f-9mmf-7xm6/GHSA-f88f-9mmf-7xm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f88f-9mmf-7xm6", + "modified": "2023-05-22T12:30:25Z", + "published": "2023-05-22T12:30:25Z", + "aliases": [ + "CVE-2023-25537" + ], + "details": "\nDell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25537" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000213550/dsa-2023-098-security-update-for-dell-poweredge-14g-server-bios-for-an-out-of-bounds-write-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file