From f7a9c1ffee7c9fa593bbf047ab54c6ab61ba7319 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 2 Dec 2024 18:32:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-33cf-32gf-rq6j.json | 4 +- .../GHSA-4vgv-pwv7-ff8j.json | 4 +- .../GHSA-775x-pffr-hqmc.json | 4 +- .../GHSA-96m3-m78r-2xq9.json | 4 +- .../GHSA-99j5-xj2q-86w3.json | 4 +- .../GHSA-mpff-353q-5493.json | 4 +- .../GHSA-xxxp-8x92-f69v.json | 4 +- .../GHSA-whm2-8r5j-rj8q.json | 13 +++--- .../GHSA-289g-wh2w-9hg2.json | 6 +-- .../GHSA-8cxh-wxvq-9jgw.json | 15 +++++-- .../GHSA-fpq9-w5cw-5hf8.json | 6 ++- .../GHSA-2gx6-qrpp-c4p3.json | 15 +++++-- .../GHSA-44gv-75g5-gcm5.json | 15 +++++-- .../GHSA-6wff-g5m3-3vrq.json | 15 +++++-- .../GHSA-8737-h7fg-9xgj.json | 15 +++++-- .../GHSA-cg28-v4wq-whv5.json | 15 +++++-- .../GHSA-crqc-m66h-cvr4.json | 15 +++++-- .../GHSA-f9m5-926v-fxw4.json | 15 +++++-- .../GHSA-g5wv-cvf4-2r98.json | 15 +++---- .../GHSA-gq96-59xw-28wj.json | 15 +++++-- .../GHSA-j4r5-m4h2-m93g.json | 15 +++++-- .../GHSA-pw36-wp35-2rw6.json | 15 +++++-- .../GHSA-qq65-5wvg-p275.json | 15 +++---- .../GHSA-rhx4-chf7-v77c.json | 15 +++++-- .../GHSA-v456-9683-gpmq.json | 15 +++++-- .../GHSA-w5f2-gvhw-r7q6.json | 15 +++++-- .../GHSA-wjq6-6xvc-xr82.json | 15 +++---- .../GHSA-xjm8-v6p6-5c3j.json | 15 +++++-- .../GHSA-289c-grq2-86fp.json | 11 +++-- .../GHSA-2c5p-v6r6-q8xj.json | 11 +++-- .../GHSA-2fr9-xph3-mm3j.json | 40 +++++++++++++++++++ .../GHSA-2hhm-535h-jfpf.json | 11 +++-- .../GHSA-2q9j-fxww-vw94.json | 11 +++-- .../GHSA-2qv3-7vvv-5c37.json | 11 +++-- .../GHSA-3crx-72mc-vg28.json | 11 +++-- .../GHSA-3hxq-37g6-vgvh.json | 4 +- .../GHSA-6cmw-42pp-vrv8.json | 11 +++-- .../GHSA-ccwq-3vpf-86cw.json | 29 ++++++++++++++ .../GHSA-fgp4-7fm6-8pxh.json | 15 +++++-- .../GHSA-h3pq-wm2x-37wm.json | 11 +++-- .../GHSA-hxr2-47r8-rr3v.json | 11 +++-- .../GHSA-j7qp-74vm-wr32.json | 11 +++-- .../GHSA-m396-rwgp-jw45.json | 11 +++-- .../GHSA-mgww-wpg8-7gmj.json | 11 +++-- .../GHSA-pmp6-g6pf-49wc.json | 11 +++-- .../GHSA-qq74-3r8j-w4c9.json | 33 +++++++++++++++ .../GHSA-rgfw-9xmc-3h72.json | 36 +++++++++++++++++ .../GHSA-vgr3-gmw5-qgp2.json | 36 +++++++++++++++++ .../GHSA-w2w8-wf8j-grh4.json | 36 +++++++++++++++++ .../GHSA-wr8w-653v-34g8.json | 11 +++-- 50 files changed, 560 insertions(+), 146 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-2fr9-xph3-mm3j/GHSA-2fr9-xph3-mm3j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qq74-3r8j-w4c9/GHSA-qq74-3r8j-w4c9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rgfw-9xmc-3h72/GHSA-rgfw-9xmc-3h72.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vgr3-gmw5-qgp2/GHSA-vgr3-gmw5-qgp2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w2w8-wf8j-grh4/GHSA-w2w8-wf8j-grh4.json diff --git a/advisories/unreviewed/2023/06/GHSA-33cf-32gf-rq6j/GHSA-33cf-32gf-rq6j.json b/advisories/unreviewed/2023/06/GHSA-33cf-32gf-rq6j/GHSA-33cf-32gf-rq6j.json index e850b9d95bc..ccd85dd83b4 100644 --- a/advisories/unreviewed/2023/06/GHSA-33cf-32gf-rq6j/GHSA-33cf-32gf-rq6j.json +++ b/advisories/unreviewed/2023/06/GHSA-33cf-32gf-rq6j/GHSA-33cf-32gf-rq6j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-4vgv-pwv7-ff8j/GHSA-4vgv-pwv7-ff8j.json b/advisories/unreviewed/2023/06/GHSA-4vgv-pwv7-ff8j/GHSA-4vgv-pwv7-ff8j.json index 492246f660d..cfa509a2464 100644 --- a/advisories/unreviewed/2023/06/GHSA-4vgv-pwv7-ff8j/GHSA-4vgv-pwv7-ff8j.json +++ b/advisories/unreviewed/2023/06/GHSA-4vgv-pwv7-ff8j/GHSA-4vgv-pwv7-ff8j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-775x-pffr-hqmc/GHSA-775x-pffr-hqmc.json b/advisories/unreviewed/2023/06/GHSA-775x-pffr-hqmc/GHSA-775x-pffr-hqmc.json index 7510198b092..fcd39acc89d 100644 --- a/advisories/unreviewed/2023/06/GHSA-775x-pffr-hqmc/GHSA-775x-pffr-hqmc.json +++ b/advisories/unreviewed/2023/06/GHSA-775x-pffr-hqmc/GHSA-775x-pffr-hqmc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-96m3-m78r-2xq9/GHSA-96m3-m78r-2xq9.json b/advisories/unreviewed/2023/06/GHSA-96m3-m78r-2xq9/GHSA-96m3-m78r-2xq9.json index 4df42f59b5d..d89424c2923 100644 --- a/advisories/unreviewed/2023/06/GHSA-96m3-m78r-2xq9/GHSA-96m3-m78r-2xq9.json +++ b/advisories/unreviewed/2023/06/GHSA-96m3-m78r-2xq9/GHSA-96m3-m78r-2xq9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-99j5-xj2q-86w3/GHSA-99j5-xj2q-86w3.json b/advisories/unreviewed/2023/06/GHSA-99j5-xj2q-86w3/GHSA-99j5-xj2q-86w3.json index d5ed04487f0..f97944e3b70 100644 --- a/advisories/unreviewed/2023/06/GHSA-99j5-xj2q-86w3/GHSA-99j5-xj2q-86w3.json +++ b/advisories/unreviewed/2023/06/GHSA-99j5-xj2q-86w3/GHSA-99j5-xj2q-86w3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-mpff-353q-5493/GHSA-mpff-353q-5493.json b/advisories/unreviewed/2023/06/GHSA-mpff-353q-5493/GHSA-mpff-353q-5493.json index 3fceb827625..d4b81a75516 100644 --- a/advisories/unreviewed/2023/06/GHSA-mpff-353q-5493/GHSA-mpff-353q-5493.json +++ b/advisories/unreviewed/2023/06/GHSA-mpff-353q-5493/GHSA-mpff-353q-5493.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-xxxp-8x92-f69v/GHSA-xxxp-8x92-f69v.json b/advisories/unreviewed/2023/06/GHSA-xxxp-8x92-f69v/GHSA-xxxp-8x92-f69v.json index 006c1d8acc2..a1d7c4ca747 100644 --- a/advisories/unreviewed/2023/06/GHSA-xxxp-8x92-f69v/GHSA-xxxp-8x92-f69v.json +++ b/advisories/unreviewed/2023/06/GHSA-xxxp-8x92-f69v/GHSA-xxxp-8x92-f69v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-whm2-8r5j-rj8q/GHSA-whm2-8r5j-rj8q.json b/advisories/unreviewed/2024/02/GHSA-whm2-8r5j-rj8q/GHSA-whm2-8r5j-rj8q.json index 618ea679554..1319925a438 100644 --- a/advisories/unreviewed/2024/02/GHSA-whm2-8r5j-rj8q/GHSA-whm2-8r5j-rj8q.json +++ b/advisories/unreviewed/2024/02/GHSA-whm2-8r5j-rj8q/GHSA-whm2-8r5j-rj8q.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-whm2-8r5j-rj8q", - "modified": "2024-02-29T03:33:17Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-21723" ], "details": "Inadequate parsing of URLs could result into an open redirect.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -27,7 +28,7 @@ "cwe_ids": [ "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:03Z" diff --git a/advisories/unreviewed/2024/06/GHSA-289g-wh2w-9hg2/GHSA-289g-wh2w-9hg2.json b/advisories/unreviewed/2024/06/GHSA-289g-wh2w-9hg2/GHSA-289g-wh2w-9hg2.json index 2dc71b4d3a1..6806d81b2d4 100644 --- a/advisories/unreviewed/2024/06/GHSA-289g-wh2w-9hg2/GHSA-289g-wh2w-9hg2.json +++ b/advisories/unreviewed/2024/06/GHSA-289g-wh2w-9hg2/GHSA-289g-wh2w-9hg2.json @@ -13,9 +13,7 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [ - - ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -28,7 +26,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8cxh-wxvq-9jgw/GHSA-8cxh-wxvq-9jgw.json b/advisories/unreviewed/2024/07/GHSA-8cxh-wxvq-9jgw/GHSA-8cxh-wxvq-9jgw.json index d4eba660496..a0073844cbe 100644 --- a/advisories/unreviewed/2024/07/GHSA-8cxh-wxvq-9jgw/GHSA-8cxh-wxvq-9jgw.json +++ b/advisories/unreviewed/2024/07/GHSA-8cxh-wxvq-9jgw/GHSA-8cxh-wxvq-9jgw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8cxh-wxvq-9jgw", - "modified": "2024-07-22T21:30:39Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-07-22T21:30:39Z", "aliases": [ "CVE-2024-40075" ], "details": "Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-22T19:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json b/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json index aab7e1e2814..207d159a755 100644 --- a/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json +++ b/advisories/unreviewed/2024/07/GHSA-fpq9-w5cw-5hf8/GHSA-fpq9-w5cw-5hf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fpq9-w5cw-5hf8", - "modified": "2024-08-21T15:30:49Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-07-01T21:31:14Z", "aliases": [ "CVE-2024-38476" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240712-0001" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/01/9" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json b/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json index 5d757873409..bf452cacd60 100644 --- a/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json +++ b/advisories/unreviewed/2024/11/GHSA-2gx6-qrpp-c4p3/GHSA-2gx6-qrpp-c4p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gx6-qrpp-c4p3", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-35371" ], "details": "Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-44gv-75g5-gcm5/GHSA-44gv-75g5-gcm5.json b/advisories/unreviewed/2024/11/GHSA-44gv-75g5-gcm5/GHSA-44gv-75g5-gcm5.json index 9a68fdddcdb..5b2553992f3 100644 --- a/advisories/unreviewed/2024/11/GHSA-44gv-75g5-gcm5/GHSA-44gv-75g5-gcm5.json +++ b/advisories/unreviewed/2024/11/GHSA-44gv-75g5-gcm5/GHSA-44gv-75g5-gcm5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-44gv-75g5-gcm5", - "modified": "2024-11-29T18:34:03Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-11-29T18:34:03Z", "aliases": [ "CVE-2024-36617" ], "details": "FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T18:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json b/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json index 6cdaa8b2145..3e1e0f59b2e 100644 --- a/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json +++ b/advisories/unreviewed/2024/11/GHSA-6wff-g5m3-3vrq/GHSA-6wff-g5m3-3vrq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wff-g5m3-3vrq", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-35367" ], "details": "FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json b/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json index 8125188f092..84b4d17e431 100644 --- a/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json +++ b/advisories/unreviewed/2024/11/GHSA-8737-h7fg-9xgj/GHSA-8737-h7fg-9xgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8737-h7fg-9xgj", - "modified": "2024-11-27T18:34:04Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-11-27T15:31:46Z", "aliases": [ "CVE-2024-53920" ], "details": "In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json b/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json index e930abe8bb5..9951943414c 100644 --- a/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json +++ b/advisories/unreviewed/2024/11/GHSA-cg28-v4wq-whv5/GHSA-cg28-v4wq-whv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cg28-v4wq-whv5", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-36610" ], "details": "A deserialization vulnerability exists in the Stub class of the VarDumper module in Symfony v7.0.3. The vulnerability stems from deficiencies in the original implementation when handling properties with null or uninitialized values. An attacker could construct specific serialized data and use this vulnerability to execute unauthorized code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json b/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json index ac678248195..0283464ee06 100644 --- a/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json +++ b/advisories/unreviewed/2024/11/GHSA-crqc-m66h-cvr4/GHSA-crqc-m66h-cvr4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crqc-m66h-cvr4", - "modified": "2024-11-29T21:31:03Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:03Z", "aliases": [ "CVE-2024-36616" ], "details": "An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T19:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-f9m5-926v-fxw4/GHSA-f9m5-926v-fxw4.json b/advisories/unreviewed/2024/11/GHSA-f9m5-926v-fxw4/GHSA-f9m5-926v-fxw4.json index 75021151cdf..2fcc6d94dcc 100644 --- a/advisories/unreviewed/2024/11/GHSA-f9m5-926v-fxw4/GHSA-f9m5-926v-fxw4.json +++ b/advisories/unreviewed/2024/11/GHSA-f9m5-926v-fxw4/GHSA-f9m5-926v-fxw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9m5-926v-fxw4", - "modified": "2024-11-29T18:34:03Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-11-29T18:34:03Z", "aliases": [ "CVE-2024-36618" ], "details": "FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T18:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json b/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json index 762ac3c3082..e7b9d6ff18a 100644 --- a/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json +++ b/advisories/unreviewed/2024/11/GHSA-g5wv-cvf4-2r98/GHSA-g5wv-cvf4-2r98.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-g5wv-cvf4-2r98", - "modified": "2024-11-26T15:31:02Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-11-26T15:31:02Z", "aliases": [ "CVE-2024-11696" ], "details": "The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed. Signature validation in this context is used to ensure that third-party applications on the user's computer have not tampered with the user's extensions, limiting the impact of this issue. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -41,9 +42,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T14:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json b/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json index 46bc2e3217a..4f22bb9de7c 100644 --- a/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json +++ b/advisories/unreviewed/2024/11/GHSA-gq96-59xw-28wj/GHSA-gq96-59xw-28wj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gq96-59xw-28wj", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-35366" ], "details": "FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json b/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json index ef9b7252db4..e04537c7884 100644 --- a/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json +++ b/advisories/unreviewed/2024/11/GHSA-j4r5-m4h2-m93g/GHSA-j4r5-m4h2-m93g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j4r5-m4h2-m93g", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-53507" ], "details": "A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:21Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json b/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json index f9ced6c0689..b92a07d1363 100644 --- a/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json +++ b/advisories/unreviewed/2024/11/GHSA-pw36-wp35-2rw6/GHSA-pw36-wp35-2rw6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pw36-wp35-2rw6", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-35368" ], "details": "FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json b/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json index a34c414dd9f..942b3c6237d 100644 --- a/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json +++ b/advisories/unreviewed/2024/11/GHSA-qq65-5wvg-p275/GHSA-qq65-5wvg-p275.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-qq65-5wvg-p275", - "modified": "2024-11-27T15:31:45Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-11-27T15:31:45Z", "aliases": [ "CVE-2024-46054" ], "details": "OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -33,9 +34,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json b/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json index c63c3d2252d..626b2c2433f 100644 --- a/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json +++ b/advisories/unreviewed/2024/11/GHSA-rhx4-chf7-v77c/GHSA-rhx4-chf7-v77c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rhx4-chf7-v77c", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-53504" ], "details": "A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json b/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json index 133ebda15c4..9834a44f6ae 100644 --- a/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json +++ b/advisories/unreviewed/2024/11/GHSA-v456-9683-gpmq/GHSA-v456-9683-gpmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v456-9683-gpmq", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-36612" ], "details": "Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json b/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json index 583adb54e82..a8bea4b9928 100644 --- a/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json +++ b/advisories/unreviewed/2024/11/GHSA-w5f2-gvhw-r7q6/GHSA-w5f2-gvhw-r7q6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5f2-gvhw-r7q6", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-53506" ], "details": "A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json b/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json index 7cad1dc711a..2bf4c46a0ab 100644 --- a/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json +++ b/advisories/unreviewed/2024/11/GHSA-wjq6-6xvc-xr82/GHSA-wjq6-6xvc-xr82.json @@ -1,18 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-wjq6-6xvc-xr82", - "modified": "2024-11-26T15:31:02Z", + "modified": "2024-12-02T18:31:54Z", "published": "2024-11-26T15:31:02Z", "aliases": [ "CVE-2024-11703" ], "details": "On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.", "severity": [ - - ], - "affected": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], + "affected": [], "references": [ { "type": "ADVISORY", @@ -29,9 +30,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-26T14:15:19Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json b/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json index e743c21e936..0616a26561d 100644 --- a/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json +++ b/advisories/unreviewed/2024/11/GHSA-xjm8-v6p6-5c3j/GHSA-xjm8-v6p6-5c3j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjm8-v6p6-5c3j", - "modified": "2024-11-29T21:31:04Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-11-29T21:31:04Z", "aliases": [ "CVE-2024-53505" ], "details": "A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-29T20:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-289c-grq2-86fp/GHSA-289c-grq2-86fp.json b/advisories/unreviewed/2024/12/GHSA-289c-grq2-86fp/GHSA-289c-grq2-86fp.json index 13b58e260ca..71000329918 100644 --- a/advisories/unreviewed/2024/12/GHSA-289c-grq2-86fp/GHSA-289c-grq2-86fp.json +++ b/advisories/unreviewed/2024/12/GHSA-289c-grq2-86fp/GHSA-289c-grq2-86fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-289c-grq2-86fp", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20136" ], "details": "In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2c5p-v6r6-q8xj/GHSA-2c5p-v6r6-q8xj.json b/advisories/unreviewed/2024/12/GHSA-2c5p-v6r6-q8xj/GHSA-2c5p-v6r6-q8xj.json index 50dc8ff2a5a..72156b30ab4 100644 --- a/advisories/unreviewed/2024/12/GHSA-2c5p-v6r6-q8xj/GHSA-2c5p-v6r6-q8xj.json +++ b/advisories/unreviewed/2024/12/GHSA-2c5p-v6r6-q8xj/GHSA-2c5p-v6r6-q8xj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2c5p-v6r6-q8xj", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20138" ], "details": "In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2fr9-xph3-mm3j/GHSA-2fr9-xph3-mm3j.json b/advisories/unreviewed/2024/12/GHSA-2fr9-xph3-mm3j/GHSA-2fr9-xph3-mm3j.json new file mode 100644 index 00000000000..e7801f9a8c2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2fr9-xph3-mm3j/GHSA-2fr9-xph3-mm3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fr9-xph3-mm3j", + "modified": "2024-12-02T18:31:56Z", + "published": "2024-12-02T18:31:56Z", + "aliases": [ + "CVE-2024-53566" + ], + "details": "An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53566" + }, + { + "type": "WEB", + "url": "https://gist.github.com/hyp164D1/e7c0f44ffb38c00320aa1a6d98bee616" + }, + { + "type": "WEB", + "url": "https://github.com/asterisk/asterisk/blob/22/main/manager.c#L2556" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2hhm-535h-jfpf/GHSA-2hhm-535h-jfpf.json b/advisories/unreviewed/2024/12/GHSA-2hhm-535h-jfpf/GHSA-2hhm-535h-jfpf.json index 84aebcf42ce..0694d5d289e 100644 --- a/advisories/unreviewed/2024/12/GHSA-2hhm-535h-jfpf/GHSA-2hhm-535h-jfpf.json +++ b/advisories/unreviewed/2024/12/GHSA-2hhm-535h-jfpf/GHSA-2hhm-535h-jfpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2hhm-535h-jfpf", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20133" ], "details": "In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2q9j-fxww-vw94/GHSA-2q9j-fxww-vw94.json b/advisories/unreviewed/2024/12/GHSA-2q9j-fxww-vw94/GHSA-2q9j-fxww-vw94.json index 942e62599ac..74e999531fa 100644 --- a/advisories/unreviewed/2024/12/GHSA-2q9j-fxww-vw94/GHSA-2q9j-fxww-vw94.json +++ b/advisories/unreviewed/2024/12/GHSA-2q9j-fxww-vw94/GHSA-2q9j-fxww-vw94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2q9j-fxww-vw94", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20134" ], "details": "In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09154589; Issue ID: MSV-1866.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2qv3-7vvv-5c37/GHSA-2qv3-7vvv-5c37.json b/advisories/unreviewed/2024/12/GHSA-2qv3-7vvv-5c37/GHSA-2qv3-7vvv-5c37.json index 30827865d87..c82f59dd98e 100644 --- a/advisories/unreviewed/2024/12/GHSA-2qv3-7vvv-5c37/GHSA-2qv3-7vvv-5c37.json +++ b/advisories/unreviewed/2024/12/GHSA-2qv3-7vvv-5c37/GHSA-2qv3-7vvv-5c37.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qv3-7vvv-5c37", - "modified": "2024-12-02T06:31:46Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:46Z", "aliases": [ "CVE-2024-20116" ], "details": "In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:03Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3crx-72mc-vg28/GHSA-3crx-72mc-vg28.json b/advisories/unreviewed/2024/12/GHSA-3crx-72mc-vg28/GHSA-3crx-72mc-vg28.json index 14fc6f4722b..7c500c23890 100644 --- a/advisories/unreviewed/2024/12/GHSA-3crx-72mc-vg28/GHSA-3crx-72mc-vg28.json +++ b/advisories/unreviewed/2024/12/GHSA-3crx-72mc-vg28/GHSA-3crx-72mc-vg28.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3crx-72mc-vg28", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20132" ], "details": "In Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00957388; Issue ID: MSV-1872.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json b/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json index 76edaf02988..fc0d0eaf21e 100644 --- a/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json +++ b/advisories/unreviewed/2024/12/GHSA-3hxq-37g6-vgvh/GHSA-3hxq-37g6-vgvh.json @@ -28,7 +28,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json b/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json index a0c1a781b5c..9ddd70b8ddd 100644 --- a/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json +++ b/advisories/unreviewed/2024/12/GHSA-6cmw-42pp-vrv8/GHSA-6cmw-42pp-vrv8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6cmw-42pp-vrv8", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20130" ], "details": "In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09193374; Issue ID: MSV-1982.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json b/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json new file mode 100644 index 00000000000..eccba66beef --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccwq-3vpf-86cw", + "modified": "2024-12-02T18:31:56Z", + "published": "2024-12-02T18:31:56Z", + "aliases": [ + "CVE-2024-53564" + ], + "details": "An authenticated arbitrary file upload vulnerability in the component /module_admin/upload.php of freepbx v17.0.19.17 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53564" + }, + { + "type": "WEB", + "url": "https://gist.github.com/hyp164D1/490732de230edf97423f6d95b0d2f903" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fgp4-7fm6-8pxh/GHSA-fgp4-7fm6-8pxh.json b/advisories/unreviewed/2024/12/GHSA-fgp4-7fm6-8pxh/GHSA-fgp4-7fm6-8pxh.json index 110b0a8717b..283a80ff029 100644 --- a/advisories/unreviewed/2024/12/GHSA-fgp4-7fm6-8pxh/GHSA-fgp4-7fm6-8pxh.json +++ b/advisories/unreviewed/2024/12/GHSA-fgp4-7fm6-8pxh/GHSA-fgp4-7fm6-8pxh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fgp4-7fm6-8pxh", - "modified": "2024-12-01T21:30:33Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-01T21:30:33Z", "aliases": [ "CVE-2024-45520" ], "details": "WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE32 file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-01T21:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-h3pq-wm2x-37wm/GHSA-h3pq-wm2x-37wm.json b/advisories/unreviewed/2024/12/GHSA-h3pq-wm2x-37wm/GHSA-h3pq-wm2x-37wm.json index b6a982347a5..82b84d50a36 100644 --- a/advisories/unreviewed/2024/12/GHSA-h3pq-wm2x-37wm/GHSA-h3pq-wm2x-37wm.json +++ b/advisories/unreviewed/2024/12/GHSA-h3pq-wm2x-37wm/GHSA-h3pq-wm2x-37wm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3pq-wm2x-37wm", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20137" ], "details": "In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-248" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hxr2-47r8-rr3v/GHSA-hxr2-47r8-rr3v.json b/advisories/unreviewed/2024/12/GHSA-hxr2-47r8-rr3v/GHSA-hxr2-47r8-rr3v.json index 8d089354fee..ecb89d63297 100644 --- a/advisories/unreviewed/2024/12/GHSA-hxr2-47r8-rr3v/GHSA-hxr2-47r8-rr3v.json +++ b/advisories/unreviewed/2024/12/GHSA-hxr2-47r8-rr3v/GHSA-hxr2-47r8-rr3v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hxr2-47r8-rr3v", - "modified": "2024-12-02T06:31:48Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:48Z", "aliases": [ "CVE-2024-20125" ], "details": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09046782; Issue ID: MSV-1728.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j7qp-74vm-wr32/GHSA-j7qp-74vm-wr32.json b/advisories/unreviewed/2024/12/GHSA-j7qp-74vm-wr32/GHSA-j7qp-74vm-wr32.json index 62410864796..e4445bbfa40 100644 --- a/advisories/unreviewed/2024/12/GHSA-j7qp-74vm-wr32/GHSA-j7qp-74vm-wr32.json +++ b/advisories/unreviewed/2024/12/GHSA-j7qp-74vm-wr32/GHSA-j7qp-74vm-wr32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j7qp-74vm-wr32", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20128" ], "details": "In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2024.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-m396-rwgp-jw45/GHSA-m396-rwgp-jw45.json b/advisories/unreviewed/2024/12/GHSA-m396-rwgp-jw45/GHSA-m396-rwgp-jw45.json index cc57bae666c..1c22ad20313 100644 --- a/advisories/unreviewed/2024/12/GHSA-m396-rwgp-jw45/GHSA-m396-rwgp-jw45.json +++ b/advisories/unreviewed/2024/12/GHSA-m396-rwgp-jw45/GHSA-m396-rwgp-jw45.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m396-rwgp-jw45", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20131" ], "details": "In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1873.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mgww-wpg8-7gmj/GHSA-mgww-wpg8-7gmj.json b/advisories/unreviewed/2024/12/GHSA-mgww-wpg8-7gmj/GHSA-mgww-wpg8-7gmj.json index ae6927c7385..5d653f63440 100644 --- a/advisories/unreviewed/2024/12/GHSA-mgww-wpg8-7gmj/GHSA-mgww-wpg8-7gmj.json +++ b/advisories/unreviewed/2024/12/GHSA-mgww-wpg8-7gmj/GHSA-mgww-wpg8-7gmj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgww-wpg8-7gmj", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20139" ], "details": "In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-617" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pmp6-g6pf-49wc/GHSA-pmp6-g6pf-49wc.json b/advisories/unreviewed/2024/12/GHSA-pmp6-g6pf-49wc/GHSA-pmp6-g6pf-49wc.json index 0079486840d..59a9aeb2b5c 100644 --- a/advisories/unreviewed/2024/12/GHSA-pmp6-g6pf-49wc/GHSA-pmp6-g6pf-49wc.json +++ b/advisories/unreviewed/2024/12/GHSA-pmp6-g6pf-49wc/GHSA-pmp6-g6pf-49wc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pmp6-g6pf-49wc", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20127" ], "details": "In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2023.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qq74-3r8j-w4c9/GHSA-qq74-3r8j-w4c9.json b/advisories/unreviewed/2024/12/GHSA-qq74-3r8j-w4c9/GHSA-qq74-3r8j-w4c9.json new file mode 100644 index 00000000000..02a417be2e8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qq74-3r8j-w4c9/GHSA-qq74-3r8j-w4c9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq74-3r8j-w4c9", + "modified": "2024-12-02T18:31:56Z", + "published": "2024-12-02T18:31:56Z", + "aliases": [ + "CVE-2024-53364" + ], + "details": "A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53364" + }, + { + "type": "WEB", + "url": "https://github.com/SCR-athif/CVE/tree/main/CVE-2024-53364" + }, + { + "type": "WEB", + "url": "http://phpgurukul.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rgfw-9xmc-3h72/GHSA-rgfw-9xmc-3h72.json b/advisories/unreviewed/2024/12/GHSA-rgfw-9xmc-3h72/GHSA-rgfw-9xmc-3h72.json new file mode 100644 index 00000000000..437802c03da --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rgfw-9xmc-3h72/GHSA-rgfw-9xmc-3h72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgfw-9xmc-3h72", + "modified": "2024-12-02T18:31:55Z", + "published": "2024-12-02T18:31:55Z", + "aliases": [ + "CVE-2024-50381" + ], + "details": "A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50381" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vgr3-gmw5-qgp2/GHSA-vgr3-gmw5-qgp2.json b/advisories/unreviewed/2024/12/GHSA-vgr3-gmw5-qgp2/GHSA-vgr3-gmw5-qgp2.json new file mode 100644 index 00000000000..254690cc771 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vgr3-gmw5-qgp2/GHSA-vgr3-gmw5-qgp2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgr3-gmw5-qgp2", + "modified": "2024-12-02T18:31:55Z", + "published": "2024-12-02T18:31:55Z", + "aliases": [ + "CVE-2024-50380" + ], + "details": "Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can impersonate other devices by supplying enumerated MAC addresses and receive sensitive information about the device.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50380" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w2w8-wf8j-grh4/GHSA-w2w8-wf8j-grh4.json b/advisories/unreviewed/2024/12/GHSA-w2w8-wf8j-grh4/GHSA-w2w8-wf8j-grh4.json new file mode 100644 index 00000000000..8410760fb4c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w2w8-wf8j-grh4/GHSA-w2w8-wf8j-grh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2w8-wf8j-grh4", + "modified": "2024-12-02T18:31:55Z", + "published": "2024-12-02T18:31:55Z", + "aliases": [ + "CVE-2024-53459" + ], + "details": "Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53459" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/182467/Sysax-Multi-Server-6.99-Cross-Site-Scripting.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-02T16:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wr8w-653v-34g8/GHSA-wr8w-653v-34g8.json b/advisories/unreviewed/2024/12/GHSA-wr8w-653v-34g8/GHSA-wr8w-653v-34g8.json index eff6d71ee14..3885b2f717a 100644 --- a/advisories/unreviewed/2024/12/GHSA-wr8w-653v-34g8/GHSA-wr8w-653v-34g8.json +++ b/advisories/unreviewed/2024/12/GHSA-wr8w-653v-34g8/GHSA-wr8w-653v-34g8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr8w-653v-34g8", - "modified": "2024-12-02T06:31:49Z", + "modified": "2024-12-02T18:31:55Z", "published": "2024-12-02T06:31:49Z", "aliases": [ "CVE-2024-20135" ], "details": "In soundtrigger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09142526; Issue ID: MSV-1841.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T04:15:05Z"