From f8acf8f3855e4b2e6886daef4dd38247d08b1770 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 12 Nov 2024 21:31:26 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pgrc-8wp5-5mvq.json | 39 ++++++++++++----- .../GHSA-4x8h-5jjw-88xr.json | 11 +++-- .../GHSA-qv2c-ppf9-8pcg.json | 2 +- .../GHSA-wp8h-p32h-fwvc.json | 11 +++-- .../GHSA-xc5j-3rmm-qh4c.json | 11 +++-- .../GHSA-5pvw-wf9w-xx8v.json | 9 ++-- .../GHSA-62m6-hw85-vr62.json | 11 +++-- .../GHSA-95wf-ppr8-fpf4.json | 2 +- .../GHSA-vr4m-r8hq-rpgr.json | 11 +++-- .../GHSA-29xc-2rhm-5f2q.json | 9 ++-- .../GHSA-7hpg-wrjj-gghq.json | 9 ++-- .../GHSA-c4ch-cv96-r58v.json | 12 ++++-- .../GHSA-cxxf-mf68-j85v.json | 2 +- .../GHSA-xc8j-mr73-m6wv.json | 11 +++-- .../GHSA-84g5-5pmf-46fw.json | 9 ++-- .../GHSA-8qrf-6p9x-7w92.json | 11 +++-- .../GHSA-g545-rmg6-689p.json | 11 +++-- .../GHSA-rf2p-c3v5-v8fm.json | 4 +- .../GHSA-jc4p-8qhr-mrv4.json | 11 +++-- .../GHSA-mwxq-5h59-mwf9.json | 2 +- .../GHSA-4x74-8q36-fc3h.json | 11 +++-- .../GHSA-hrvv-3gc2-4cqx.json | 6 ++- .../GHSA-m5m5-6fc4-ph6r.json | 9 ++-- .../GHSA-rxhv-mw63-w89c.json | 9 ++-- .../GHSA-x652-w4xg-69jh.json | 9 ++-- .../GHSA-2mfp-xhwj-f686.json | 38 ++++++++++++++++ .../GHSA-2r34-6f9h-2rxg.json | 11 +++-- .../GHSA-2v5j-9r37-9h2j.json | 38 ++++++++++++++++ .../GHSA-337j-fwm7-hphr.json | 39 +++++++++++++++++ .../GHSA-33mv-fjxj-2mx6.json | 38 ++++++++++++++++ .../GHSA-362g-36hp-r4hp.json | 38 ++++++++++++++++ .../GHSA-3638-r263-v9hp.json | 3 +- .../GHSA-3763-g33m-vwcj.json | 38 ++++++++++++++++ .../GHSA-37r8-854r-595c.json | 11 +++-- .../GHSA-3g8q-mgqw-7ch3.json | 38 ++++++++++++++++ .../GHSA-3r4j-6h5p-7vp5.json | 38 ++++++++++++++++ .../GHSA-3rc9-f2pv-xp95.json | 38 ++++++++++++++++ .../GHSA-3vq2-5g7p-fgf2.json | 38 ++++++++++++++++ .../GHSA-3x8x-wg7p-5gq4.json | 38 ++++++++++++++++ .../GHSA-4225-4fvr-rghw.json | 39 +++++++++++++++++ .../GHSA-4492-8ffc-chrg.json | 38 ++++++++++++++++ .../GHSA-45pj-9676-3wwq.json | 38 ++++++++++++++++ .../GHSA-4jqw-mwqp-mhq2.json | 38 ++++++++++++++++ .../GHSA-4mww-gp9h-h59m.json | 39 +++++++++++++++++ .../GHSA-4r4c-x4gq-3pcw.json | 38 ++++++++++++++++ .../GHSA-4rh4-3933-r7hw.json | 38 ++++++++++++++++ .../GHSA-52xg-258x-mphm.json | 38 ++++++++++++++++ .../GHSA-55v3-94wx-73hc.json | 38 ++++++++++++++++ .../GHSA-595x-6cv8-fp75.json | 39 +++++++++++++++++ .../GHSA-5mc3-gwcr-mgc3.json | 11 +++-- .../GHSA-5w9j-5925-2f4j.json | 11 +++-- .../GHSA-68w3-69rv-qrr7.json | 6 ++- .../GHSA-696r-w2gc-3fgf.json | 11 +++-- .../GHSA-6f8g-mwg3-32f9.json | 38 ++++++++++++++++ .../GHSA-6r2c-554q-5q54.json | 11 +++-- .../GHSA-6vf9-7q6p-x646.json | 4 +- .../GHSA-78hg-5fhj-7wpc.json | 38 ++++++++++++++++ .../GHSA-7cmm-93p5-5x7r.json | 38 ++++++++++++++++ .../GHSA-7wfj-8r7h-pw34.json | 11 +++-- .../GHSA-82hw-xj4r-36wq.json | 38 ++++++++++++++++ .../GHSA-8f3r-v34g-85rw.json | 38 ++++++++++++++++ .../GHSA-8g5x-cxhr-gr43.json | 39 +++++++++++++++++ .../GHSA-8xqq-wrhg-93q9.json | 38 ++++++++++++++++ .../GHSA-935g-fc8j-74rf.json | 9 ++-- .../GHSA-9683-fxjw-gg57.json | 38 ++++++++++++++++ .../GHSA-9gmw-9qg6-35hm.json | 38 ++++++++++++++++ .../GHSA-9m47-c93j-4784.json | 38 ++++++++++++++++ .../GHSA-9m68-hrx9-5wfc.json | 38 ++++++++++++++++ .../GHSA-9mc2-495f-848q.json | 38 ++++++++++++++++ .../GHSA-cfhv-h3jw-vx5r.json | 38 ++++++++++++++++ .../GHSA-cgpx-r229-qpvj.json | 38 ++++++++++++++++ .../GHSA-cjq9-chqc-g9rx.json | 38 ++++++++++++++++ .../GHSA-cmm4-x589-xjmx.json | 38 ++++++++++++++++ .../GHSA-cq44-4c86-v79x.json | 38 ++++++++++++++++ .../GHSA-f6qg-rg6j-cxgf.json | 11 +++-- .../GHSA-f8vw-rrq3-q7q9.json | 39 +++++++++++++++++ .../GHSA-f8xh-22hr-98pr.json | 38 ++++++++++++++++ .../GHSA-ffgw-jxv7-9vp7.json | 38 ++++++++++++++++ .../GHSA-fhc9-mwwq-6p67.json | 38 ++++++++++++++++ .../GHSA-g38m-3gr9-p86q.json | 38 ++++++++++++++++ .../GHSA-g7xw-3x5x-249w.json | 38 ++++++++++++++++ .../GHSA-g838-64mm-fjv7.json | 38 ++++++++++++++++ .../GHSA-g9wf-hxjw-97mq.json | 38 ++++++++++++++++ .../GHSA-gcg5-h35m-25rv.json | 38 ++++++++++++++++ .../GHSA-ggrr-222r-c74p.json | 38 ++++++++++++++++ .../GHSA-gm6q-h79g-j9pf.json | 38 ++++++++++++++++ .../GHSA-gr86-frw6-7wp2.json | 38 ++++++++++++++++ .../GHSA-h2xv-hq2x-rvxq.json | 11 +++-- .../GHSA-hw9x-8m75-4vjq.json | 35 +++++++++++++++ .../GHSA-hwrr-qggh-2777.json | 2 +- .../GHSA-j3qc-mp9w-wcwv.json | 38 ++++++++++++++++ .../GHSA-jcvj-p2rg-4rpw.json | 38 ++++++++++++++++ .../GHSA-jfx4-p2cg-248g.json | 38 ++++++++++++++++ .../GHSA-jrvf-vccr-mvp6.json | 11 +++-- .../GHSA-jwm4-jq46-9g26.json | 38 ++++++++++++++++ .../GHSA-jwp7-wvcp-qc35.json | 38 ++++++++++++++++ .../GHSA-jxg2-g8jw-r8cj.json | 43 +++++++++++++++++++ .../GHSA-m84v-65mj-hw78.json | 39 +++++++++++++++++ .../GHSA-mg99-9h93-rq3m.json | 38 ++++++++++++++++ .../GHSA-mj4p-7pw5-mh9m.json | 38 ++++++++++++++++ .../GHSA-mp4j-j99g-pqwf.json | 38 ++++++++++++++++ .../GHSA-mpwh-m8v4-4v78.json | 38 ++++++++++++++++ .../GHSA-mx2x-7r9x-jj3v.json | 38 ++++++++++++++++ .../GHSA-p3r5-57j4-gq4x.json | 38 ++++++++++++++++ .../GHSA-p8w2-9cmv-c9gc.json | 38 ++++++++++++++++ .../GHSA-pgmr-p79v-f7mc.json | 38 ++++++++++++++++ .../GHSA-pjmr-ff79-h6xp.json | 38 ++++++++++++++++ .../GHSA-pq96-5jf7-gxjh.json | 38 ++++++++++++++++ .../GHSA-q6mf-q7m8-gw96.json | 2 +- .../GHSA-q6p7-p3cc-vcf9.json | 38 ++++++++++++++++ .../GHSA-q7j7-7r72-9h66.json | 38 ++++++++++++++++ .../GHSA-q9h5-v87h-3hhr.json | 38 ++++++++++++++++ .../GHSA-qc3r-qr6p-cwr5.json | 38 ++++++++++++++++ .../GHSA-qq58-pf2w-c658.json | 38 ++++++++++++++++ .../GHSA-r9m4-7h5v-g8h8.json | 38 ++++++++++++++++ .../GHSA-rf9w-7f29-2cx2.json | 38 ++++++++++++++++ .../GHSA-rh9f-c55m-vh5v.json | 38 ++++++++++++++++ .../GHSA-rmcg-5mh4-47x7.json | 35 +++++++++++++++ .../GHSA-rmph-8gw6-8rhx.json | 38 ++++++++++++++++ .../GHSA-rp64-jc8m-27wc.json | 38 ++++++++++++++++ .../GHSA-v428-c7m6-vqcx.json | 38 ++++++++++++++++ .../GHSA-v482-hq83-hpfg.json | 38 ++++++++++++++++ .../GHSA-w9j2-h8vr-446x.json | 11 +++-- .../GHSA-wq79-mjg7-48hq.json | 39 +++++++++++++++++ .../GHSA-wr74-rqfg-9299.json | 11 +++-- .../GHSA-x6qj-75g5-46wg.json | 2 +- .../GHSA-x74x-9w6r-75c3.json | 38 ++++++++++++++++ .../GHSA-xcwx-v8f8-hq62.json | 38 ++++++++++++++++ .../GHSA-xwr3-f5gh-9v6w.json | 11 +++-- 129 files changed, 3468 insertions(+), 144 deletions(-) rename advisories/{unreviewed => github-reviewed}/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json (61%) create mode 100644 advisories/unreviewed/2024/11/GHSA-2mfp-xhwj-f686/GHSA-2mfp-xhwj-f686.json create mode 100644 advisories/unreviewed/2024/11/GHSA-2v5j-9r37-9h2j/GHSA-2v5j-9r37-9h2j.json create mode 100644 advisories/unreviewed/2024/11/GHSA-337j-fwm7-hphr/GHSA-337j-fwm7-hphr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-33mv-fjxj-2mx6/GHSA-33mv-fjxj-2mx6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-362g-36hp-r4hp/GHSA-362g-36hp-r4hp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3763-g33m-vwcj/GHSA-3763-g33m-vwcj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3g8q-mgqw-7ch3/GHSA-3g8q-mgqw-7ch3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3r4j-6h5p-7vp5/GHSA-3r4j-6h5p-7vp5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3rc9-f2pv-xp95/GHSA-3rc9-f2pv-xp95.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3vq2-5g7p-fgf2/GHSA-3vq2-5g7p-fgf2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-3x8x-wg7p-5gq4/GHSA-3x8x-wg7p-5gq4.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4225-4fvr-rghw/GHSA-4225-4fvr-rghw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4492-8ffc-chrg/GHSA-4492-8ffc-chrg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-45pj-9676-3wwq/GHSA-45pj-9676-3wwq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4jqw-mwqp-mhq2/GHSA-4jqw-mwqp-mhq2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4mww-gp9h-h59m/GHSA-4mww-gp9h-h59m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4r4c-x4gq-3pcw/GHSA-4r4c-x4gq-3pcw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4rh4-3933-r7hw/GHSA-4rh4-3933-r7hw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-52xg-258x-mphm/GHSA-52xg-258x-mphm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-55v3-94wx-73hc/GHSA-55v3-94wx-73hc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-595x-6cv8-fp75/GHSA-595x-6cv8-fp75.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6f8g-mwg3-32f9/GHSA-6f8g-mwg3-32f9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-78hg-5fhj-7wpc/GHSA-78hg-5fhj-7wpc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7cmm-93p5-5x7r/GHSA-7cmm-93p5-5x7r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-82hw-xj4r-36wq/GHSA-82hw-xj4r-36wq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8f3r-v34g-85rw/GHSA-8f3r-v34g-85rw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8g5x-cxhr-gr43/GHSA-8g5x-cxhr-gr43.json create mode 100644 advisories/unreviewed/2024/11/GHSA-8xqq-wrhg-93q9/GHSA-8xqq-wrhg-93q9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9683-fxjw-gg57/GHSA-9683-fxjw-gg57.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9gmw-9qg6-35hm/GHSA-9gmw-9qg6-35hm.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9m47-c93j-4784/GHSA-9m47-c93j-4784.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9m68-hrx9-5wfc/GHSA-9m68-hrx9-5wfc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9mc2-495f-848q/GHSA-9mc2-495f-848q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cfhv-h3jw-vx5r/GHSA-cfhv-h3jw-vx5r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cgpx-r229-qpvj/GHSA-cgpx-r229-qpvj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cjq9-chqc-g9rx/GHSA-cjq9-chqc-g9rx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cmm4-x589-xjmx/GHSA-cmm4-x589-xjmx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cq44-4c86-v79x/GHSA-cq44-4c86-v79x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f8vw-rrq3-q7q9/GHSA-f8vw-rrq3-q7q9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f8xh-22hr-98pr/GHSA-f8xh-22hr-98pr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ffgw-jxv7-9vp7/GHSA-ffgw-jxv7-9vp7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-fhc9-mwwq-6p67/GHSA-fhc9-mwwq-6p67.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g38m-3gr9-p86q/GHSA-g38m-3gr9-p86q.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g7xw-3x5x-249w/GHSA-g7xw-3x5x-249w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g838-64mm-fjv7/GHSA-g838-64mm-fjv7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-g9wf-hxjw-97mq/GHSA-g9wf-hxjw-97mq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gcg5-h35m-25rv/GHSA-gcg5-h35m-25rv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-ggrr-222r-c74p/GHSA-ggrr-222r-c74p.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gm6q-h79g-j9pf/GHSA-gm6q-h79g-j9pf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gr86-frw6-7wp2/GHSA-gr86-frw6-7wp2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j3qc-mp9w-wcwv/GHSA-j3qc-mp9w-wcwv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jcvj-p2rg-4rpw/GHSA-jcvj-p2rg-4rpw.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jfx4-p2cg-248g/GHSA-jfx4-p2cg-248g.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jwm4-jq46-9g26/GHSA-jwm4-jq46-9g26.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jwp7-wvcp-qc35/GHSA-jwp7-wvcp-qc35.json create mode 100644 advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json create mode 100644 advisories/unreviewed/2024/11/GHSA-m84v-65mj-hw78/GHSA-m84v-65mj-hw78.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mg99-9h93-rq3m/GHSA-mg99-9h93-rq3m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mj4p-7pw5-mh9m/GHSA-mj4p-7pw5-mh9m.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mp4j-j99g-pqwf/GHSA-mp4j-j99g-pqwf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mpwh-m8v4-4v78/GHSA-mpwh-m8v4-4v78.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mx2x-7r9x-jj3v/GHSA-mx2x-7r9x-jj3v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p3r5-57j4-gq4x/GHSA-p3r5-57j4-gq4x.json create mode 100644 advisories/unreviewed/2024/11/GHSA-p8w2-9cmv-c9gc/GHSA-p8w2-9cmv-c9gc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pgmr-p79v-f7mc/GHSA-pgmr-p79v-f7mc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json create mode 100644 advisories/unreviewed/2024/11/GHSA-pq96-5jf7-gxjh/GHSA-pq96-5jf7-gxjh.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q6p7-p3cc-vcf9/GHSA-q6p7-p3cc-vcf9.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q7j7-7r72-9h66/GHSA-q7j7-7r72-9h66.json create mode 100644 advisories/unreviewed/2024/11/GHSA-q9h5-v87h-3hhr/GHSA-q9h5-v87h-3hhr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qc3r-qr6p-cwr5/GHSA-qc3r-qr6p-cwr5.json create mode 100644 advisories/unreviewed/2024/11/GHSA-qq58-pf2w-c658/GHSA-qq58-pf2w-c658.json create mode 100644 advisories/unreviewed/2024/11/GHSA-r9m4-7h5v-g8h8/GHSA-r9m4-7h5v-g8h8.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rf9w-7f29-2cx2/GHSA-rf9w-7f29-2cx2.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rh9f-c55m-vh5v/GHSA-rh9f-c55m-vh5v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rmph-8gw6-8rhx/GHSA-rmph-8gw6-8rhx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rp64-jc8m-27wc/GHSA-rp64-jc8m-27wc.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v428-c7m6-vqcx/GHSA-v428-c7m6-vqcx.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v482-hq83-hpfg/GHSA-v482-hq83-hpfg.json create mode 100644 advisories/unreviewed/2024/11/GHSA-wq79-mjg7-48hq/GHSA-wq79-mjg7-48hq.json create mode 100644 advisories/unreviewed/2024/11/GHSA-x74x-9w6r-75c3/GHSA-x74x-9w6r-75c3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-xcwx-v8f8-hq62/GHSA-xcwx-v8f8-hq62.json diff --git a/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json b/advisories/github-reviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json similarity index 61% rename from advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json rename to advisories/github-reviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json index ced3f75455f..1a005400ac2 100644 --- a/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json +++ b/advisories/github-reviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json @@ -1,20 +1,43 @@ { "schema_version": "1.4.0", "id": "GHSA-pgrc-8wp5-5mvq", - "modified": "2024-11-12T18:30:51Z", + "modified": "2024-11-12T21:30:21Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-51135" ], + "summary": "powertac-server XML External Entity vulnerability", "details": "An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.powertac:server-interface" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.9.0" + } + ] + } + ] + } ], "references": [ { @@ -26,25 +49,21 @@ "url": "https://github.com/powertac/powertac-server/issues/1166" }, { - "type": "WEB", + "type": "PACKAGE", "url": "https://github.com/powertac/powertac-server" }, { "type": "WEB", "url": "https://mvnrepository.com/artifact/org.powertac/server-interface" - }, - { - "type": "WEB", - "url": "http://www.powertac.org" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-11-12T21:30:21Z", "nvd_published_at": "2024-11-11T19:15:04Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json b/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json index c1f3a4ccd49..39259ec9354 100644 --- a/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json +++ b/advisories/unreviewed/2024/02/GHSA-4x8h-5jjw-88xr/GHSA-4x8h-5jjw-88xr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x8h-5jjw-88xr", - "modified": "2024-02-22T21:30:33Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-02-22T21:30:33Z", "aliases": [ "CVE-2024-25369" ], "details": "A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T20:15:56Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qv2c-ppf9-8pcg/GHSA-qv2c-ppf9-8pcg.json b/advisories/unreviewed/2024/02/GHSA-qv2c-ppf9-8pcg/GHSA-qv2c-ppf9-8pcg.json index 4f96e596dee..a6f3f6a7c5f 100644 --- a/advisories/unreviewed/2024/02/GHSA-qv2c-ppf9-8pcg/GHSA-qv2c-ppf9-8pcg.json +++ b/advisories/unreviewed/2024/02/GHSA-qv2c-ppf9-8pcg/GHSA-qv2c-ppf9-8pcg.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json b/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json index 2a94d61eb91..224f73f1926 100644 --- a/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json +++ b/advisories/unreviewed/2024/02/GHSA-wp8h-p32h-fwvc/GHSA-wp8h-p32h-fwvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp8h-p32h-fwvc", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1556" ], "details": "The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xc5j-3rmm-qh4c/GHSA-xc5j-3rmm-qh4c.json b/advisories/unreviewed/2024/02/GHSA-xc5j-3rmm-qh4c/GHSA-xc5j-3rmm-qh4c.json index 3052d6b9390..7cf73fa21a1 100644 --- a/advisories/unreviewed/2024/02/GHSA-xc5j-3rmm-qh4c/GHSA-xc5j-3rmm-qh4c.json +++ b/advisories/unreviewed/2024/02/GHSA-xc5j-3rmm-qh4c/GHSA-xc5j-3rmm-qh4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc5j-3rmm-qh4c", - "modified": "2024-02-15T21:31:27Z", + "modified": "2024-11-12T21:30:48Z", "published": "2024-02-15T21:31:27Z", "aliases": [ "CVE-2024-25373" ], "details": "Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T19:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5pvw-wf9w-xx8v/GHSA-5pvw-wf9w-xx8v.json b/advisories/unreviewed/2024/03/GHSA-5pvw-wf9w-xx8v/GHSA-5pvw-wf9w-xx8v.json index 2b3a68205e6..9b73bca0a97 100644 --- a/advisories/unreviewed/2024/03/GHSA-5pvw-wf9w-xx8v/GHSA-5pvw-wf9w-xx8v.json +++ b/advisories/unreviewed/2024/03/GHSA-5pvw-wf9w-xx8v/GHSA-5pvw-wf9w-xx8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pvw-wf9w-xx8v", - "modified": "2024-03-27T06:30:30Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-03-27T06:30:30Z", "aliases": [ "CVE-2023-39804" ], "details": "In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-62m6-hw85-vr62/GHSA-62m6-hw85-vr62.json b/advisories/unreviewed/2024/03/GHSA-62m6-hw85-vr62/GHSA-62m6-hw85-vr62.json index e8e39d34f87..e5bb3e48772 100644 --- a/advisories/unreviewed/2024/03/GHSA-62m6-hw85-vr62/GHSA-62m6-hw85-vr62.json +++ b/advisories/unreviewed/2024/03/GHSA-62m6-hw85-vr62/GHSA-62m6-hw85-vr62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62m6-hw85-vr62", - "modified": "2024-03-05T15:32:41Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-03-05T15:32:41Z", "aliases": [ "CVE-2024-27625" ], "details": "CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the \"New directory\" field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T14:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-95wf-ppr8-fpf4/GHSA-95wf-ppr8-fpf4.json b/advisories/unreviewed/2024/03/GHSA-95wf-ppr8-fpf4/GHSA-95wf-ppr8-fpf4.json index a2f84f12627..7da532a3b5c 100644 --- a/advisories/unreviewed/2024/03/GHSA-95wf-ppr8-fpf4/GHSA-95wf-ppr8-fpf4.json +++ b/advisories/unreviewed/2024/03/GHSA-95wf-ppr8-fpf4/GHSA-95wf-ppr8-fpf4.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vr4m-r8hq-rpgr/GHSA-vr4m-r8hq-rpgr.json b/advisories/unreviewed/2024/03/GHSA-vr4m-r8hq-rpgr/GHSA-vr4m-r8hq-rpgr.json index 4541192ac8d..98d3004d313 100644 --- a/advisories/unreviewed/2024/03/GHSA-vr4m-r8hq-rpgr/GHSA-vr4m-r8hq-rpgr.json +++ b/advisories/unreviewed/2024/03/GHSA-vr4m-r8hq-rpgr/GHSA-vr4m-r8hq-rpgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vr4m-r8hq-rpgr", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-03-06T09:30:28Z", "aliases": [ "CVE-2023-52601" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in dbAdjTree\n\nCurrently there is a bound check missing in the dbAdjTree while\naccessing the dmt_stree. To add the required check added the bool is_ctl\nwhich is required to determine the size as suggest in the following\ncommit.\nhttps://lore.kernel.org/linux-kernel-mentees/f9475918-2186-49b8-b801-6f0f9e75f4fa@oracle.com/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json b/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json index 22e7af419f7..57afb448987 100644 --- a/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json +++ b/advisories/unreviewed/2024/04/GHSA-29xc-2rhm-5f2q/GHSA-29xc-2rhm-5f2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29xc-2rhm-5f2q", - "modified": "2024-04-04T09:30:34Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-04-04T09:30:34Z", "aliases": [ "CVE-2024-29007" ], "details": "The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T08:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json b/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json index 0d799396b9a..6fcbe3b7a48 100644 --- a/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json +++ b/advisories/unreviewed/2024/04/GHSA-7hpg-wrjj-gghq/GHSA-7hpg-wrjj-gghq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hpg-wrjj-gghq", - "modified": "2024-05-01T18:30:40Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-04-10T15:30:40Z", "aliases": [ "CVE-2024-31309" ], "details": "HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.\n\nUsers can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute.  ATS does have a fixed amount of memory a request can use and ATS adheres to these limits in previous releases.\nUsers are recommended to upgrade to versions 8.1.10 or 9.2.4 which fixes the issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T12:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json b/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json index 767d7c45bd3..02484a258b1 100644 --- a/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json +++ b/advisories/unreviewed/2024/04/GHSA-c4ch-cv96-r58v/GHSA-c4ch-cv96-r58v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4ch-cv96-r58v", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-04-04T21:30:31Z", "aliases": [ "CVE-2024-24795" ], "details": "HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.\n\nUsers are recommended to upgrade to version 2.4.59, which fixes this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -61,9 +64,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-113" + "CWE-113", + "CWE-444" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cxxf-mf68-j85v/GHSA-cxxf-mf68-j85v.json b/advisories/unreviewed/2024/04/GHSA-cxxf-mf68-j85v/GHSA-cxxf-mf68-j85v.json index 4e5394936a2..b5a7ab17bc8 100644 --- a/advisories/unreviewed/2024/04/GHSA-cxxf-mf68-j85v/GHSA-cxxf-mf68-j85v.json +++ b/advisories/unreviewed/2024/04/GHSA-cxxf-mf68-j85v/GHSA-cxxf-mf68-j85v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json b/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json index a0deef2dfe4..481a039976b 100644 --- a/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json +++ b/advisories/unreviewed/2024/04/GHSA-xc8j-mr73-m6wv/GHSA-xc8j-mr73-m6wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc8j-mr73-m6wv", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3855" ], "details": "In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json b/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json index a6644f9134e..cf9a4bad586 100644 --- a/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json +++ b/advisories/unreviewed/2024/06/GHSA-84g5-5pmf-46fw/GHSA-84g5-5pmf-46fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84g5-5pmf-46fw", - "modified": "2024-06-25T03:31:07Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-06-25T03:31:07Z", "aliases": [ "CVE-2024-23149" ], "details": "A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T03:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8qrf-6p9x-7w92/GHSA-8qrf-6p9x-7w92.json b/advisories/unreviewed/2024/06/GHSA-8qrf-6p9x-7w92/GHSA-8qrf-6p9x-7w92.json index 40ebf316d6b..fe8a2fce489 100644 --- a/advisories/unreviewed/2024/06/GHSA-8qrf-6p9x-7w92/GHSA-8qrf-6p9x-7w92.json +++ b/advisories/unreviewed/2024/06/GHSA-8qrf-6p9x-7w92/GHSA-8qrf-6p9x-7w92.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qrf-6p9x-7w92", - "modified": "2024-06-03T21:30:43Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-06-03T21:30:43Z", "aliases": [ "CVE-2024-31684" ], "details": "Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a deprecated API.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T19:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g545-rmg6-689p/GHSA-g545-rmg6-689p.json b/advisories/unreviewed/2024/06/GHSA-g545-rmg6-689p/GHSA-g545-rmg6-689p.json index b6c6a3c06dd..d8d9ba19869 100644 --- a/advisories/unreviewed/2024/06/GHSA-g545-rmg6-689p/GHSA-g545-rmg6-689p.json +++ b/advisories/unreviewed/2024/06/GHSA-g545-rmg6-689p/GHSA-g545-rmg6-689p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g545-rmg6-689p", - "modified": "2024-06-25T21:31:13Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-06-03T21:30:44Z", "aliases": [ "CVE-2023-51219" ], "details": "A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controller JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to takeover another user's account and read her/his chat messages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T20:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rf2p-c3v5-v8fm/GHSA-rf2p-c3v5-v8fm.json b/advisories/unreviewed/2024/06/GHSA-rf2p-c3v5-v8fm/GHSA-rf2p-c3v5-v8fm.json index 74e8142b052..63ab56a7766 100644 --- a/advisories/unreviewed/2024/06/GHSA-rf2p-c3v5-v8fm/GHSA-rf2p-c3v5-v8fm.json +++ b/advisories/unreviewed/2024/06/GHSA-rf2p-c3v5-v8fm/GHSA-rf2p-c3v5-v8fm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rf2p-c3v5-v8fm", - "modified": "2024-06-25T15:31:09Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-37086" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-jc4p-8qhr-mrv4/GHSA-jc4p-8qhr-mrv4.json b/advisories/unreviewed/2024/07/GHSA-jc4p-8qhr-mrv4/GHSA-jc4p-8qhr-mrv4.json index 0fb0773468c..205b7d44453 100644 --- a/advisories/unreviewed/2024/07/GHSA-jc4p-8qhr-mrv4/GHSA-jc4p-8qhr-mrv4.json +++ b/advisories/unreviewed/2024/07/GHSA-jc4p-8qhr-mrv4/GHSA-jc4p-8qhr-mrv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc4p-8qhr-mrv4", - "modified": "2024-07-01T06:31:17Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-07-01T06:31:17Z", "aliases": [ "CVE-2024-38480" ], "details": "\"Piccoma\" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T05:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mwxq-5h59-mwf9/GHSA-mwxq-5h59-mwf9.json b/advisories/unreviewed/2024/07/GHSA-mwxq-5h59-mwf9/GHSA-mwxq-5h59-mwf9.json index b37cb8a89cd..13a5d9537ab 100644 --- a/advisories/unreviewed/2024/07/GHSA-mwxq-5h59-mwf9/GHSA-mwxq-5h59-mwf9.json +++ b/advisories/unreviewed/2024/07/GHSA-mwxq-5h59-mwf9/GHSA-mwxq-5h59-mwf9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json b/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json index abaaf25146b..f09689f65e6 100644 --- a/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json +++ b/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x74-8q36-fc3h", - "modified": "2024-11-08T18:30:45Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-10-21T18:30:58Z", "aliases": [ "CVE-2024-49949" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: avoid potential underflow in qdisc_pkt_len_init() with UFO\n\nAfter commit 7c6d2ecbda83 (\"net: be more gentle about silly gso\nrequests coming from user\") virtio_net_hdr_to_skb() had sanity check\nto detect malicious attempts from user space to cook a bad GSO packet.\n\nThen commit cf9acc90c80ec (\"net: virtio_net_hdr_to_skb: count\ntransport header in UFO\") while fixing one issue, allowed user space\nto cook a GSO packet with the following characteristic :\n\nIPv4 SKB_GSO_UDP, gso_size=3, skb->len = 28.\n\nWhen this packet arrives in qdisc_pkt_len_init(), we end up\nwith hdr_len = 28 (IPv4 header + UDP header), matching skb->len\n\nThen the following sets gso_segs to 0 :\n\ngso_segs = DIV_ROUND_UP(skb->len - hdr_len,\n shinfo->gso_size);\n\nThen later we set qdisc_skb_cb(skb)->pkt_len to back to zero :/\n\nqdisc_skb_cb(skb)->pkt_len += (gso_segs - 1) * hdr_len;\n\nThis leads to the following crash in fq_codel [1]\n\nqdisc_pkt_len_init() is best effort, we only want an estimation\nof the bytes sent on the wire, not crashing the kernel.\n\nThis patch is fixing this particular issue, a following one\nadds more sanity checks for another potential bug.\n\n[1]\n[ 70.724101] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 70.724561] #PF: supervisor read access in kernel mode\n[ 70.724561] #PF: error_code(0x0000) - not-present page\n[ 70.724561] PGD 10ac61067 P4D 10ac61067 PUD 107ee2067 PMD 0\n[ 70.724561] Oops: Oops: 0000 [#1] SMP NOPTI\n[ 70.724561] CPU: 11 UID: 0 PID: 2163 Comm: b358537762 Not tainted 6.11.0-virtme #991\n[ 70.724561] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 70.724561] RIP: 0010:fq_codel_enqueue (net/sched/sch_fq_codel.c:120 net/sched/sch_fq_codel.c:168 net/sched/sch_fq_codel.c:230) sch_fq_codel\n[ 70.724561] Code: 24 08 49 c1 e1 06 44 89 7c 24 18 45 31 ed 45 31 c0 31 ff 89 44 24 14 4c 03 8b 90 01 00 00 eb 04 39 ca 73 37 4d 8b 39 83 c7 01 <49> 8b 17 49 89 11 41 8b 57 28 45 8b 5f 34 49 c7 07 00 00 00 00 49\nAll code\n========\n 0:\t24 08 \tand $0x8,%al\n 2:\t49 c1 e1 06 \tshl $0x6,%r9\n 6:\t44 89 7c 24 18 \tmov %r15d,0x18(%rsp)\n b:\t45 31 ed \txor %r13d,%r13d\n e:\t45 31 c0 \txor %r8d,%r8d\n 11:\t31 ff \txor %edi,%edi\n 13:\t89 44 24 14 \tmov %eax,0x14(%rsp)\n 17:\t4c 03 8b 90 01 00 00 \tadd 0x190(%rbx),%r9\n 1e:\teb 04 \tjmp 0x24\n 20:\t39 ca \tcmp %ecx,%edx\n 22:\t73 37 \tjae 0x5b\n 24:\t4d 8b 39 \tmov (%r9),%r15\n 27:\t83 c7 01 \tadd $0x1,%edi\n 2a:*\t49 8b 17 \tmov (%r15),%rdx\t\t<-- trapping instruction\n 2d:\t49 89 11 \tmov %rdx,(%r9)\n 30:\t41 8b 57 28 \tmov 0x28(%r15),%edx\n 34:\t45 8b 5f 34 \tmov 0x34(%r15),%r11d\n 38:\t49 c7 07 00 00 00 00 \tmovq $0x0,(%r15)\n 3f:\t49 \trex.WB\n\nCode starting with the faulting instruction\n===========================================\n 0:\t49 8b 17 \tmov (%r15),%rdx\n 3:\t49 89 11 \tmov %rdx,(%r9)\n 6:\t41 8b 57 28 \tmov 0x28(%r15),%edx\n a:\t45 8b 5f 34 \tmov 0x34(%r15),%r11d\n e:\t49 c7 07 00 00 00 00 \tmovq $0x0,(%r15)\n 15:\t49 \trex.WB\n[ 70.724561] RSP: 0018:ffff95ae85e6fb90 EFLAGS: 00000202\n[ 70.724561] RAX: 0000000002000000 RBX: ffff95ae841de000 RCX: 0000000000000000\n[ 70.724561] RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000001\n[ 70.724561] RBP: ffff95ae85e6fbf8 R08: 0000000000000000 R09: ffff95b710a30000\n[ 70.724561] R10: 0000000000000000 R11: bdf289445ce31881 R12: ffff95ae85e6fc58\n[ 70.724561] R13: 0000000000000000 R14: 0000000000000040 R15: 0000000000000000\n[ 70.724561] FS: 000000002c5c1380(0000) GS:ffff95bd7fcc0000(0000) knlGS:0000000000000000\n[ 70.724561] CS: 0010 DS: 0000 ES: 0000 C\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hrvv-3gc2-4cqx/GHSA-hrvv-3gc2-4cqx.json b/advisories/unreviewed/2024/10/GHSA-hrvv-3gc2-4cqx/GHSA-hrvv-3gc2-4cqx.json index bb1da2a80cb..16f2e3717c2 100644 --- a/advisories/unreviewed/2024/10/GHSA-hrvv-3gc2-4cqx/GHSA-hrvv-3gc2-4cqx.json +++ b/advisories/unreviewed/2024/10/GHSA-hrvv-3gc2-4cqx/GHSA-hrvv-3gc2-4cqx.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrvv-3gc2-4cqx", - "modified": "2024-10-04T12:31:02Z", + "modified": "2024-11-12T21:30:49Z", "published": "2024-10-04T12:31:02Z", "aliases": [ "CVE-2024-6400" ], "details": "Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json b/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json index b1604bb942f..c999f4578e7 100644 --- a/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json +++ b/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5m5-6fc4-ph6r", - "modified": "2024-10-21T18:30:58Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-10-21T18:30:58Z", "aliases": [ "CVE-2024-49947" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: test for not too small csum_start in virtio_net_hdr_to_skb()\n\nsyzbot was able to trigger this warning [1], after injecting a\nmalicious packet through af_packet, setting skb->csum_start and thus\nthe transport header to an incorrect value.\n\nWe can at least make sure the transport header is after\nthe end of the network header (with a estimated minimal size).\n\n[1]\n[ 67.873027] skb len=4096 headroom=16 headlen=14 tailroom=0\nmac=(-1,-1) mac_len=0 net=(16,-6) trans=10\nshinfo(txflags=0 nr_frags=1 gso(size=0 type=0 segs=0))\ncsum(0xa start=10 offset=0 ip_summed=3 complete_sw=0 valid=0 level=0)\nhash(0x0 sw=0 l4=0) proto=0x0800 pkttype=0 iif=0\npriority=0x0 mark=0x0 alloc_cpu=10 vlan_all=0x0\nencapsulation=0 inner(proto=0x0000, mac=0, net=0, trans=0)\n[ 67.877172] dev name=veth0_vlan feat=0x000061164fdd09e9\n[ 67.877764] sk family=17 type=3 proto=0\n[ 67.878279] skb linear: 00000000: 00 00 10 00 00 00 00 00 0f 00 00 00 08 00\n[ 67.879128] skb frag: 00000000: 0e 00 07 00 00 00 28 00 08 80 1c 00 04 00 00 02\n[ 67.879877] skb frag: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.880647] skb frag: 00000020: 00 00 02 00 00 00 08 00 1b 00 00 00 00 00 00 00\n[ 67.881156] skb frag: 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.881753] skb frag: 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.882173] skb frag: 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.882790] skb frag: 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.883171] skb frag: 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.883733] skb frag: 00000080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.884206] skb frag: 00000090: 00 00 00 00 00 00 00 00 00 00 69 70 76 6c 61 6e\n[ 67.884704] skb frag: 000000a0: 31 00 00 00 00 00 00 00 00 00 2b 00 00 00 00 00\n[ 67.885139] skb frag: 000000b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.885677] skb frag: 000000c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.886042] skb frag: 000000d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.886408] skb frag: 000000e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.887020] skb frag: 000000f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.887384] skb frag: 00000100: 00 00\n[ 67.887878] ------------[ cut here ]------------\n[ 67.887908] offset (-6) >= skb_headlen() (14)\n[ 67.888445] WARNING: CPU: 10 PID: 2088 at net/core/dev.c:3332 skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.889353] Modules linked in: macsec macvtap macvlan hsr wireguard curve25519_x86_64 libcurve25519_generic libchacha20poly1305 chacha_x86_64 libchacha poly1305_x86_64 dummy bridge sr_mod cdrom evdev pcspkr i2c_piix4 9pnet_virtio 9p 9pnet netfs\n[ 67.890111] CPU: 10 UID: 0 PID: 2088 Comm: b363492833 Not tainted 6.11.0-virtme #1011\n[ 67.890183] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 67.890309] RIP: 0010:skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891043] Call Trace:\n[ 67.891173] \n[ 67.891274] ? __warn (kernel/panic.c:741)\n[ 67.891320] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891333] ? report_bug (lib/bug.c:180 lib/bug.c:219)\n[ 67.891348] ? handle_bug (arch/x86/kernel/traps.c:239)\n[ 67.891363] ? exc_invalid_op (arch/x86/kernel/traps.c:260 (discriminator 1))\n[ 67.891372] ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621)\n[ 67.891388] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891399] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891416] ip_do_fragment (net/ipv4/ip_output.c:777 (discriminator 1))\n[ 67.891448] ? __ip_local_out (./include/linux/skbuff.h:1146 ./include/net/l3mdev.h:196 ./include/net/l3mdev.h:213 ne\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json b/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json index 931f43d21fe..e3a1b4936d2 100644 --- a/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json +++ b/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxhv-mw63-w89c", - "modified": "2024-11-08T18:30:45Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-10-21T18:30:58Z", "aliases": [ "CVE-2024-49948" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add more sanity checks to qdisc_pkt_len_init()\n\nOne path takes care of SKB_GSO_DODGY, assuming\nskb->len is bigger than hdr_len.\n\nvirtio_net_hdr_to_skb() does not fully dissect TCP headers,\nit only make sure it is at least 20 bytes.\n\nIt is possible for an user to provide a malicious 'GSO' packet,\ntotal length of 80 bytes.\n\n- 20 bytes of IPv4 header\n- 60 bytes TCP header\n- a small gso_size like 8\n\nvirtio_net_hdr_to_skb() would declare this packet as a normal\nGSO packet, because it would see 40 bytes of payload,\nbigger than gso_size.\n\nWe need to make detect this case to not underflow\nqdisc_skb_cb(skb)->pkt_len.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -59,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json b/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json index 975a92ab071..6e536853090 100644 --- a/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json +++ b/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x652-w4xg-69jh", - "modified": "2024-10-21T18:30:58Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-10-21T18:30:58Z", "aliases": [ "CVE-2024-49951" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix possible crash on mgmt_index_removed\n\nIf mgmt_index_removed is called while there are commands queued on\ncmd_sync it could lead to crashes like the bellow trace:\n\n0x0000053D: __list_del_entry_valid_or_report+0x98/0xdc\n0x0000053D: mgmt_pending_remove+0x18/0x58 [bluetooth]\n0x0000053E: mgmt_remove_adv_monitor_complete+0x80/0x108 [bluetooth]\n0x0000053E: hci_cmd_sync_work+0xbc/0x164 [bluetooth]\n\nSo while handling mgmt_index_removed this attempts to dequeue\ncommands passed as user_data to cmd_sync.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2mfp-xhwj-f686/GHSA-2mfp-xhwj-f686.json b/advisories/unreviewed/2024/11/GHSA-2mfp-xhwj-f686/GHSA-2mfp-xhwj-f686.json new file mode 100644 index 00000000000..1ff2ca5b6d2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2mfp-xhwj-f686/GHSA-2mfp-xhwj-f686.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mfp-xhwj-f686", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47440" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47440" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2r34-6f9h-2rxg/GHSA-2r34-6f9h-2rxg.json b/advisories/unreviewed/2024/11/GHSA-2r34-6f9h-2rxg/GHSA-2r34-6f9h-2rxg.json index be947a86917..aad70dd20b1 100644 --- a/advisories/unreviewed/2024/11/GHSA-2r34-6f9h-2rxg/GHSA-2r34-6f9h-2rxg.json +++ b/advisories/unreviewed/2024/11/GHSA-2r34-6f9h-2rxg/GHSA-2r34-6f9h-2rxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2r34-6f9h-2rxg", - "modified": "2024-11-12T00:30:36Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-12T00:30:36Z", "aliases": [ "CVE-2024-51213" ], "details": "Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T23:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2v5j-9r37-9h2j/GHSA-2v5j-9r37-9h2j.json b/advisories/unreviewed/2024/11/GHSA-2v5j-9r37-9h2j/GHSA-2v5j-9r37-9h2j.json new file mode 100644 index 00000000000..bf0a556d4ae --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2v5j-9r37-9h2j/GHSA-2v5j-9r37-9h2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v5j-9r37-9h2j", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47427" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47427" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-337j-fwm7-hphr/GHSA-337j-fwm7-hphr.json b/advisories/unreviewed/2024/11/GHSA-337j-fwm7-hphr/GHSA-337j-fwm7-hphr.json new file mode 100644 index 00000000000..78925e80541 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-337j-fwm7-hphr/GHSA-337j-fwm7-hphr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-337j-fwm7-hphr", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11112" + ], + "details": "Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11112" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/354824998" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-33mv-fjxj-2mx6/GHSA-33mv-fjxj-2mx6.json b/advisories/unreviewed/2024/11/GHSA-33mv-fjxj-2mx6/GHSA-33mv-fjxj-2mx6.json new file mode 100644 index 00000000000..c4fde532933 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-33mv-fjxj-2mx6/GHSA-33mv-fjxj-2mx6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33mv-fjxj-2mx6", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-8534" + ], + "details": "Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8534" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-362g-36hp-r4hp/GHSA-362g-36hp-r4hp.json b/advisories/unreviewed/2024/11/GHSA-362g-36hp-r4hp/GHSA-362g-36hp-r4hp.json new file mode 100644 index 00000000000..f8bfef45850 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-362g-36hp-r4hp/GHSA-362g-36hp-r4hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-362g-36hp-r4hp", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49509" + ], + "details": "InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49509" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-88.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json b/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json index 068b7dc508a..251b3eca43a 100644 --- a/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json +++ b/advisories/unreviewed/2024/11/GHSA-3638-r263-v9hp/GHSA-3638-r263-v9hp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-3763-g33m-vwcj/GHSA-3763-g33m-vwcj.json b/advisories/unreviewed/2024/11/GHSA-3763-g33m-vwcj/GHSA-3763-g33m-vwcj.json new file mode 100644 index 00000000000..e21de040a00 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3763-g33m-vwcj/GHSA-3763-g33m-vwcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3763-g33m-vwcj", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47450" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47450" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json b/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json index 524e320aa1e..6b14fcfebaa 100644 --- a/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json +++ b/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37r8-854r-595c", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-52530" ], "details": "GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\\0' characters at the end of header names are ignored, i.e., a \"Transfer-Encoding\\0: chunked\" header is treated the same as a \"Transfer-Encoding: chunked\" header.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-3g8q-mgqw-7ch3/GHSA-3g8q-mgqw-7ch3.json b/advisories/unreviewed/2024/11/GHSA-3g8q-mgqw-7ch3/GHSA-3g8q-mgqw-7ch3.json new file mode 100644 index 00000000000..32a56f80d58 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3g8q-mgqw-7ch3/GHSA-3g8q-mgqw-7ch3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g8q-mgqw-7ch3", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47455" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47455" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3r4j-6h5p-7vp5/GHSA-3r4j-6h5p-7vp5.json b/advisories/unreviewed/2024/11/GHSA-3r4j-6h5p-7vp5/GHSA-3r4j-6h5p-7vp5.json new file mode 100644 index 00000000000..316f68d7b73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3r4j-6h5p-7vp5/GHSA-3r4j-6h5p-7vp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r4j-6h5p-7vp5", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47457" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47457" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3rc9-f2pv-xp95/GHSA-3rc9-f2pv-xp95.json b/advisories/unreviewed/2024/11/GHSA-3rc9-f2pv-xp95/GHSA-3rc9-f2pv-xp95.json new file mode 100644 index 00000000000..27aaaea5a22 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3rc9-f2pv-xp95/GHSA-3rc9-f2pv-xp95.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rc9-f2pv-xp95", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-47442" + ], + "details": "After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47442" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-85.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3vq2-5g7p-fgf2/GHSA-3vq2-5g7p-fgf2.json b/advisories/unreviewed/2024/11/GHSA-3vq2-5g7p-fgf2/GHSA-3vq2-5g7p-fgf2.json new file mode 100644 index 00000000000..a31ff16b440 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3vq2-5g7p-fgf2/GHSA-3vq2-5g7p-fgf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vq2-5g7p-fgf2", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-40592" + ], + "details": "An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40592" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-3x8x-wg7p-5gq4/GHSA-3x8x-wg7p-5gq4.json b/advisories/unreviewed/2024/11/GHSA-3x8x-wg7p-5gq4/GHSA-3x8x-wg7p-5gq4.json new file mode 100644 index 00000000000..f41b389234f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3x8x-wg7p-5gq4/GHSA-3x8x-wg7p-5gq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x8x-wg7p-5gq4", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49517" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49517" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4225-4fvr-rghw/GHSA-4225-4fvr-rghw.json b/advisories/unreviewed/2024/11/GHSA-4225-4fvr-rghw/GHSA-4225-4fvr-rghw.json new file mode 100644 index 00000000000..a37e2067207 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4225-4fvr-rghw/GHSA-4225-4fvr-rghw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4225-4fvr-rghw", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11111" + ], + "details": "Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11111" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/360520331" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4492-8ffc-chrg/GHSA-4492-8ffc-chrg.json b/advisories/unreviewed/2024/11/GHSA-4492-8ffc-chrg/GHSA-4492-8ffc-chrg.json new file mode 100644 index 00000000000..6fd986ea545 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4492-8ffc-chrg/GHSA-4492-8ffc-chrg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4492-8ffc-chrg", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49510" + ], + "details": "InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49510" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-88.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-45pj-9676-3wwq/GHSA-45pj-9676-3wwq.json b/advisories/unreviewed/2024/11/GHSA-45pj-9676-3wwq/GHSA-45pj-9676-3wwq.json new file mode 100644 index 00000000000..ceeda030bac --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-45pj-9676-3wwq/GHSA-45pj-9676-3wwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45pj-9676-3wwq", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47444" + ], + "details": "After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47444" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-85.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4jqw-mwqp-mhq2/GHSA-4jqw-mwqp-mhq2.json b/advisories/unreviewed/2024/11/GHSA-4jqw-mwqp-mhq2/GHSA-4jqw-mwqp-mhq2.json new file mode 100644 index 00000000000..c9ab40109ea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4jqw-mwqp-mhq2/GHSA-4jqw-mwqp-mhq2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jqw-mwqp-mhq2", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47438" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an attacker to write a controlled value at a controlled memory location, which could result in the disclosure of sensitive memory content. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47438" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-123" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4mww-gp9h-h59m/GHSA-4mww-gp9h-h59m.json b/advisories/unreviewed/2024/11/GHSA-4mww-gp9h-h59m/GHSA-4mww-gp9h-h59m.json new file mode 100644 index 00000000000..533c99bfc7e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4mww-gp9h-h59m/GHSA-4mww-gp9h-h59m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mww-gp9h-h59m", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11110" + ], + "details": "Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11110" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/373263969" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4r4c-x4gq-3pcw/GHSA-4r4c-x4gq-3pcw.json b/advisories/unreviewed/2024/11/GHSA-4r4c-x4gq-3pcw/GHSA-4r4c-x4gq-3pcw.json new file mode 100644 index 00000000000..a5d1f4a44d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4r4c-x4gq-3pcw/GHSA-4r4c-x4gq-3pcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r4c-x4gq-3pcw", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47458" + ], + "details": "Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47458" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb24-77.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4rh4-3933-r7hw/GHSA-4rh4-3933-r7hw.json b/advisories/unreviewed/2024/11/GHSA-4rh4-3933-r7hw/GHSA-4rh4-3933-r7hw.json new file mode 100644 index 00000000000..dc2c46750d0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4rh4-3933-r7hw/GHSA-4rh4-3933-r7hw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rh4-3933-r7hw", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-2208" + ], + "details": "Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2208" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11567250-11567490-16/hpsbhf03987" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-52xg-258x-mphm/GHSA-52xg-258x-mphm.json b/advisories/unreviewed/2024/11/GHSA-52xg-258x-mphm/GHSA-52xg-258x-mphm.json new file mode 100644 index 00000000000..6406e387e45 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-52xg-258x-mphm/GHSA-52xg-258x-mphm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52xg-258x-mphm", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49518" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49518" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-55v3-94wx-73hc/GHSA-55v3-94wx-73hc.json b/advisories/unreviewed/2024/11/GHSA-55v3-94wx-73hc/GHSA-55v3-94wx-73hc.json new file mode 100644 index 00000000000..e44143af1d5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-55v3-94wx-73hc/GHSA-55v3-94wx-73hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55v3-94wx-73hc", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47453" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47453" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-595x-6cv8-fp75/GHSA-595x-6cv8-fp75.json b/advisories/unreviewed/2024/11/GHSA-595x-6cv8-fp75/GHSA-595x-6cv8-fp75.json new file mode 100644 index 00000000000..bf771e9a8c6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-595x-6cv8-fp75/GHSA-595x-6cv8-fp75.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-595x-6cv8-fp75", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11113" + ], + "details": "Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11113" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/360274917" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json b/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json index 92bd0bd1c48..d1c10404d93 100644 --- a/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json +++ b/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mc3-gwcr-mgc3", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-52531" ], "details": "GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. Input received over the network cannot trigger this.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5w9j-5925-2f4j/GHSA-5w9j-5925-2f4j.json b/advisories/unreviewed/2024/11/GHSA-5w9j-5925-2f4j/GHSA-5w9j-5925-2f4j.json index 7c4b08671d0..16f93e4149a 100644 --- a/advisories/unreviewed/2024/11/GHSA-5w9j-5925-2f4j/GHSA-5w9j-5925-2f4j.json +++ b/advisories/unreviewed/2024/11/GHSA-5w9j-5925-2f4j/GHSA-5w9j-5925-2f4j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5w9j-5925-2f4j", - "modified": "2024-11-11T15:31:02Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T15:31:02Z", "aliases": [ "CVE-2024-50991" ], "details": "A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via the \"fname\" POST request parameter", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T15:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-68w3-69rv-qrr7/GHSA-68w3-69rv-qrr7.json b/advisories/unreviewed/2024/11/GHSA-68w3-69rv-qrr7/GHSA-68w3-69rv-qrr7.json index 94ac05f381b..8ebab20fd6a 100644 --- a/advisories/unreviewed/2024/11/GHSA-68w3-69rv-qrr7/GHSA-68w3-69rv-qrr7.json +++ b/advisories/unreviewed/2024/11/GHSA-68w3-69rv-qrr7/GHSA-68w3-69rv-qrr7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68w3-69rv-qrr7", - "modified": "2024-11-12T15:30:44Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-12T15:30:44Z", "aliases": [ "CVE-2024-8074" ], "details": "Improper Privilege Management vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users.This issue affects Nomysem: before 13.10.2024.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/11/GHSA-696r-w2gc-3fgf/GHSA-696r-w2gc-3fgf.json b/advisories/unreviewed/2024/11/GHSA-696r-w2gc-3fgf/GHSA-696r-w2gc-3fgf.json index 3fb422c9529..c0ad06ec82d 100644 --- a/advisories/unreviewed/2024/11/GHSA-696r-w2gc-3fgf/GHSA-696r-w2gc-3fgf.json +++ b/advisories/unreviewed/2024/11/GHSA-696r-w2gc-3fgf/GHSA-696r-w2gc-3fgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-696r-w2gc-3fgf", - "modified": "2024-11-11T15:31:02Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T15:31:02Z", "aliases": [ "CVE-2024-51054" ], "details": "A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the \"searchdata\" POST request parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T15:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6f8g-mwg3-32f9/GHSA-6f8g-mwg3-32f9.json b/advisories/unreviewed/2024/11/GHSA-6f8g-mwg3-32f9/GHSA-6f8g-mwg3-32f9.json new file mode 100644 index 00000000000..f384ded241a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6f8g-mwg3-32f9/GHSA-6f8g-mwg3-32f9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f8g-mwg3-32f9", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-32117" + ], + "details": "An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32117" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json b/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json index d35bfaa7f02..bac17160862 100644 --- a/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json +++ b/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6r2c-554q-5q54", - "modified": "2024-11-11T21:31:48Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T21:31:48Z", "aliases": [ "CVE-2024-51186" ], "details": "D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json b/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json index e2dd6f55fb1..2791d8ef257 100644 --- a/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json +++ b/advisories/unreviewed/2024/11/GHSA-6vf9-7q6p-x646/GHSA-6vf9-7q6p-x646.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6vf9-7q6p-x646", - "modified": "2024-11-12T18:31:00Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-12T18:31:00Z", "aliases": [ "CVE-2024-51720" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-78hg-5fhj-7wpc/GHSA-78hg-5fhj-7wpc.json b/advisories/unreviewed/2024/11/GHSA-78hg-5fhj-7wpc/GHSA-78hg-5fhj-7wpc.json new file mode 100644 index 00000000000..3b6074c95b9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-78hg-5fhj-7wpc/GHSA-78hg-5fhj-7wpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78hg-5fhj-7wpc", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47456" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47456" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7cmm-93p5-5x7r/GHSA-7cmm-93p5-5x7r.json b/advisories/unreviewed/2024/11/GHSA-7cmm-93p5-5x7r/GHSA-7cmm-93p5-5x7r.json new file mode 100644 index 00000000000..e90c3150d62 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7cmm-93p5-5x7r/GHSA-7cmm-93p5-5x7r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cmm-93p5-5x7r", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-45147" + ], + "details": "Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45147" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/bridge/apsb24-77.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7wfj-8r7h-pw34/GHSA-7wfj-8r7h-pw34.json b/advisories/unreviewed/2024/11/GHSA-7wfj-8r7h-pw34/GHSA-7wfj-8r7h-pw34.json index 59a500955ce..e4eefd9c207 100644 --- a/advisories/unreviewed/2024/11/GHSA-7wfj-8r7h-pw34/GHSA-7wfj-8r7h-pw34.json +++ b/advisories/unreviewed/2024/11/GHSA-7wfj-8r7h-pw34/GHSA-7wfj-8r7h-pw34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7wfj-8r7h-pw34", - "modified": "2024-11-11T15:31:02Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T15:31:02Z", "aliases": [ "CVE-2024-50990" ], "details": "A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the \"searchdata\" POST request parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T15:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-82hw-xj4r-36wq/GHSA-82hw-xj4r-36wq.json b/advisories/unreviewed/2024/11/GHSA-82hw-xj4r-36wq/GHSA-82hw-xj4r-36wq.json new file mode 100644 index 00000000000..accbf1dedd6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-82hw-xj4r-36wq/GHSA-82hw-xj4r-36wq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82hw-xj4r-36wq", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47449" + ], + "details": "Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47449" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/audition/apsb24-83.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8f3r-v34g-85rw/GHSA-8f3r-v34g-85rw.json b/advisories/unreviewed/2024/11/GHSA-8f3r-v34g-85rw/GHSA-8f3r-v34g-85rw.json new file mode 100644 index 00000000000..7ca842491fe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8f3r-v34g-85rw/GHSA-8f3r-v34g-85rw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f3r-v34g-85rw", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47437" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47437" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8g5x-cxhr-gr43/GHSA-8g5x-cxhr-gr43.json b/advisories/unreviewed/2024/11/GHSA-8g5x-cxhr-gr43/GHSA-8g5x-cxhr-gr43.json new file mode 100644 index 00000000000..a16f249414f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8g5x-cxhr-gr43/GHSA-8g5x-cxhr-gr43.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g5x-cxhr-gr43", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11116" + ], + "details": "Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11116" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40942531" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8xqq-wrhg-93q9/GHSA-8xqq-wrhg-93q9.json b/advisories/unreviewed/2024/11/GHSA-8xqq-wrhg-93q9/GHSA-8xqq-wrhg-93q9.json new file mode 100644 index 00000000000..35e07117562 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8xqq-wrhg-93q9/GHSA-8xqq-wrhg-93q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xqq-wrhg-93q9", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-8535" + ], + "details": "Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8535" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json b/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json index c038c59699f..b4b9d21f71c 100644 --- a/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json +++ b/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-935g-fc8j-74rf", - "modified": "2024-11-05T18:32:11Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-11-05T18:32:11Z", "aliases": [ "CVE-2024-50095" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mad: Improve handling of timed out WRs of mad agent\n\nCurrent timeout handler of mad agent acquires/releases mad_agent_priv\nlock for every timed out WRs. This causes heavy locking contention\nwhen higher no. of WRs are to be handled inside timeout handler.\n\nThis leads to softlockup with below trace in some use cases where\nrdma-cm path is used to establish connection between peer nodes\n\nTrace:\n-----\n BUG: soft lockup - CPU#4 stuck for 26s! [kworker/u128:3:19767]\n CPU: 4 PID: 19767 Comm: kworker/u128:3 Kdump: loaded Tainted: G OE\n ------- --- 5.14.0-427.13.1.el9_4.x86_64 #1\n Hardware name: Dell Inc. PowerEdge R740/01YM03, BIOS 2.4.8 11/26/2019\n Workqueue: ib_mad1 timeout_sends [ib_core]\n RIP: 0010:__do_softirq+0x78/0x2ac\n RSP: 0018:ffffb253449e4f98 EFLAGS: 00000246\n RAX: 00000000ffffffff RBX: 0000000000000000 RCX: 000000000000001f\n RDX: 000000000000001d RSI: 000000003d1879ab RDI: fff363b66fd3a86b\n RBP: ffffb253604cbcd8 R08: 0000009065635f3b R09: 0000000000000000\n R10: 0000000000000040 R11: ffffb253449e4ff8 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000040\n FS: 0000000000000000(0000) GS:ffff8caa1fc80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fd9ec9db900 CR3: 0000000891934006 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? show_trace_log_lvl+0x1c4/0x2df\n ? show_trace_log_lvl+0x1c4/0x2df\n ? __irq_exit_rcu+0xa1/0xc0\n ? watchdog_timer_fn+0x1b2/0x210\n ? __pfx_watchdog_timer_fn+0x10/0x10\n ? __hrtimer_run_queues+0x127/0x2c0\n ? hrtimer_interrupt+0xfc/0x210\n ? __sysvec_apic_timer_interrupt+0x5c/0x110\n ? sysvec_apic_timer_interrupt+0x37/0x90\n ? asm_sysvec_apic_timer_interrupt+0x16/0x20\n ? __do_softirq+0x78/0x2ac\n ? __do_softirq+0x60/0x2ac\n __irq_exit_rcu+0xa1/0xc0\n sysvec_call_function_single+0x72/0x90\n \n \n asm_sysvec_call_function_single+0x16/0x20\n RIP: 0010:_raw_spin_unlock_irq+0x14/0x30\n RSP: 0018:ffffb253604cbd88 EFLAGS: 00000247\n RAX: 000000000001960d RBX: 0000000000000002 RCX: ffff8cad2a064800\n RDX: 000000008020001b RSI: 0000000000000001 RDI: ffff8cad5d39f66c\n RBP: ffff8cad5d39f600 R08: 0000000000000001 R09: 0000000000000000\n R10: ffff8caa443e0c00 R11: ffffb253604cbcd8 R12: ffff8cacb8682538\n R13: 0000000000000005 R14: ffffb253604cbd90 R15: ffff8cad5d39f66c\n cm_process_send_error+0x122/0x1d0 [ib_cm]\n timeout_sends+0x1dd/0x270 [ib_core]\n process_one_work+0x1e2/0x3b0\n ? __pfx_worker_thread+0x10/0x10\n worker_thread+0x50/0x3a0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xdd/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x29/0x50\n \n\nSimplified timeout handler by creating local list of timed out WRs\nand invoke send handler post creating the list. The new method acquires/\nreleases lock once to fetch the list and hence helps to reduce locking\ncontetiong when processing higher no. of WRs", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T17:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9683-fxjw-gg57/GHSA-9683-fxjw-gg57.json b/advisories/unreviewed/2024/11/GHSA-9683-fxjw-gg57/GHSA-9683-fxjw-gg57.json new file mode 100644 index 00000000000..3a15cdff0b5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9683-fxjw-gg57/GHSA-9683-fxjw-gg57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9683-fxjw-gg57", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-31496" + ], + "details": "A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31496" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-098" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9gmw-9qg6-35hm/GHSA-9gmw-9qg6-35hm.json b/advisories/unreviewed/2024/11/GHSA-9gmw-9qg6-35hm/GHSA-9gmw-9qg6-35hm.json new file mode 100644 index 00000000000..c84ad051ce1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9gmw-9qg6-35hm/GHSA-9gmw-9qg6-35hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gmw-9qg6-35hm", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-33510" + ], + "details": "An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33510" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-358" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9m47-c93j-4784/GHSA-9m47-c93j-4784.json b/advisories/unreviewed/2024/11/GHSA-9m47-c93j-4784/GHSA-9m47-c93j-4784.json new file mode 100644 index 00000000000..d22a17778b0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9m47-c93j-4784/GHSA-9m47-c93j-4784.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m47-c93j-4784", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47433" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47433" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9m68-hrx9-5wfc/GHSA-9m68-hrx9-5wfc.json b/advisories/unreviewed/2024/11/GHSA-9m68-hrx9-5wfc/GHSA-9m68-hrx9-5wfc.json new file mode 100644 index 00000000000..62b81bedff3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9m68-hrx9-5wfc/GHSA-9m68-hrx9-5wfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m68-hrx9-5wfc", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-36513" + ], + "details": "A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36513" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-144" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-270" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9mc2-495f-848q/GHSA-9mc2-495f-848q.json b/advisories/unreviewed/2024/11/GHSA-9mc2-495f-848q/GHSA-9mc2-495f-848q.json new file mode 100644 index 00000000000..759e640dee5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9mc2-495f-848q/GHSA-9mc2-495f-848q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mc2-495f-848q", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47436" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47436" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cfhv-h3jw-vx5r/GHSA-cfhv-h3jw-vx5r.json b/advisories/unreviewed/2024/11/GHSA-cfhv-h3jw-vx5r/GHSA-cfhv-h3jw-vx5r.json new file mode 100644 index 00000000000..57c2587a455 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cfhv-h3jw-vx5r/GHSA-cfhv-h3jw-vx5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfhv-h3jw-vx5r", + "modified": "2024-11-12T21:30:51Z", + "published": "2024-11-12T21:30:51Z", + "aliases": [ + "CVE-2023-50176" + ], + "details": "A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50176" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cgpx-r229-qpvj/GHSA-cgpx-r229-qpvj.json b/advisories/unreviewed/2024/11/GHSA-cgpx-r229-qpvj/GHSA-cgpx-r229-qpvj.json new file mode 100644 index 00000000000..a7268156a78 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cgpx-r229-qpvj/GHSA-cgpx-r229-qpvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgpx-r229-qpvj", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-36509" + ], + "details": "An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticated attacker to access the encrypted passwords of other administrators via the \"Log Access Event\" logs page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36509" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cjq9-chqc-g9rx/GHSA-cjq9-chqc-g9rx.json b/advisories/unreviewed/2024/11/GHSA-cjq9-chqc-g9rx/GHSA-cjq9-chqc-g9rx.json new file mode 100644 index 00000000000..5cecde04669 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cjq9-chqc-g9rx/GHSA-cjq9-chqc-g9rx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjq9-chqc-g9rx", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47426" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47426" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cmm4-x589-xjmx/GHSA-cmm4-x589-xjmx.json b/advisories/unreviewed/2024/11/GHSA-cmm4-x589-xjmx/GHSA-cmm4-x589-xjmx.json new file mode 100644 index 00000000000..34cd5d6d6ca --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cmm4-x589-xjmx/GHSA-cmm4-x589-xjmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmm4-x589-xjmx", + "modified": "2024-11-12T21:30:51Z", + "published": "2024-11-12T21:30:51Z", + "aliases": [ + "CVE-2023-44255" + ], + "details": "An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44255" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-267" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cq44-4c86-v79x/GHSA-cq44-4c86-v79x.json b/advisories/unreviewed/2024/11/GHSA-cq44-4c86-v79x/GHSA-cq44-4c86-v79x.json new file mode 100644 index 00000000000..bc42c82666c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cq44-4c86-v79x/GHSA-cq44-4c86-v79x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq44-4c86-v79x", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49512" + ], + "details": "InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49512" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-88.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json b/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json index 185b4ca2c39..5e1ada563e2 100644 --- a/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json +++ b/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6qg-rg6j-cxgf", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-52532" ], "details": "GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T20:15:20Z" diff --git a/advisories/unreviewed/2024/11/GHSA-f8vw-rrq3-q7q9/GHSA-f8vw-rrq3-q7q9.json b/advisories/unreviewed/2024/11/GHSA-f8vw-rrq3-q7q9/GHSA-f8vw-rrq3-q7q9.json new file mode 100644 index 00000000000..897eb78b3f2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f8vw-rrq3-q7q9/GHSA-f8vw-rrq3-q7q9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8vw-rrq3-q7q9", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11114" + ], + "details": "Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11114" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/370856871" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f8xh-22hr-98pr/GHSA-f8xh-22hr-98pr.json b/advisories/unreviewed/2024/11/GHSA-f8xh-22hr-98pr/GHSA-f8xh-22hr-98pr.json new file mode 100644 index 00000000000..136b7d19e29 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f8xh-22hr-98pr/GHSA-f8xh-22hr-98pr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8xh-22hr-98pr", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47445" + ], + "details": "After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47445" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-85.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ffgw-jxv7-9vp7/GHSA-ffgw-jxv7-9vp7.json b/advisories/unreviewed/2024/11/GHSA-ffgw-jxv7-9vp7/GHSA-ffgw-jxv7-9vp7.json new file mode 100644 index 00000000000..c8d4f9c6ee5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ffgw-jxv7-9vp7/GHSA-ffgw-jxv7-9vp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffgw-jxv7-9vp7", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-45114" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45114" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fhc9-mwwq-6p67/GHSA-fhc9-mwwq-6p67.json b/advisories/unreviewed/2024/11/GHSA-fhc9-mwwq-6p67/GHSA-fhc9-mwwq-6p67.json new file mode 100644 index 00000000000..1bd85a5f624 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fhc9-mwwq-6p67/GHSA-fhc9-mwwq-6p67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhc9-mwwq-6p67", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47451" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47451" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g38m-3gr9-p86q/GHSA-g38m-3gr9-p86q.json b/advisories/unreviewed/2024/11/GHSA-g38m-3gr9-p86q/GHSA-g38m-3gr9-p86q.json new file mode 100644 index 00000000000..77842ec8b28 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g38m-3gr9-p86q/GHSA-g38m-3gr9-p86q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g38m-3gr9-p86q", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47430" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47430" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g7xw-3x5x-249w/GHSA-g7xw-3x5x-249w.json b/advisories/unreviewed/2024/11/GHSA-g7xw-3x5x-249w/GHSA-g7xw-3x5x-249w.json new file mode 100644 index 00000000000..acb2d3ceaa0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g7xw-3x5x-249w/GHSA-g7xw-3x5x-249w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7xw-3x5x-249w", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49508" + ], + "details": "InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49508" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-88.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g838-64mm-fjv7/GHSA-g838-64mm-fjv7.json b/advisories/unreviewed/2024/11/GHSA-g838-64mm-fjv7/GHSA-g838-64mm-fjv7.json new file mode 100644 index 00000000000..0b7c6196a39 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g838-64mm-fjv7/GHSA-g838-64mm-fjv7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g838-64mm-fjv7", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47432" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47432" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g9wf-hxjw-97mq/GHSA-g9wf-hxjw-97mq.json b/advisories/unreviewed/2024/11/GHSA-g9wf-hxjw-97mq/GHSA-g9wf-hxjw-97mq.json new file mode 100644 index 00000000000..b1bbb05f430 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g9wf-hxjw-97mq/GHSA-g9wf-hxjw-97mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9wf-hxjw-97mq", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-10217" + ], + "details": "XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10217" + }, + { + "type": "WEB", + "url": "https://community.tibco.com/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gcg5-h35m-25rv/GHSA-gcg5-h35m-25rv.json b/advisories/unreviewed/2024/11/GHSA-gcg5-h35m-25rv/GHSA-gcg5-h35m-25rv.json new file mode 100644 index 00000000000..9e7714cf614 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gcg5-h35m-25rv/GHSA-gcg5-h35m-25rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcg5-h35m-25rv", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-10218" + ], + "details": "XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10218" + }, + { + "type": "WEB", + "url": "https://community.tibco.com/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ggrr-222r-c74p/GHSA-ggrr-222r-c74p.json b/advisories/unreviewed/2024/11/GHSA-ggrr-222r-c74p/GHSA-ggrr-222r-c74p.json new file mode 100644 index 00000000000..db220f2dde1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ggrr-222r-c74p/GHSA-ggrr-222r-c74p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggrr-222r-c74p", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-51722" + ], + "details": "A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained control of code running under one of the system accounts listed in the configuration file to potentially issue privileged script commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51722" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gm6q-h79g-j9pf/GHSA-gm6q-h79g-j9pf.json b/advisories/unreviewed/2024/11/GHSA-gm6q-h79g-j9pf/GHSA-gm6q-h79g-j9pf.json new file mode 100644 index 00000000000..12ad760a62a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gm6q-h79g-j9pf/GHSA-gm6q-h79g-j9pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm6q-h79g-j9pf", + "modified": "2024-11-12T21:30:51Z", + "published": "2024-11-12T21:30:51Z", + "aliases": [ + "CVE-2024-26011" + ], + "details": "A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26011" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gr86-frw6-7wp2/GHSA-gr86-frw6-7wp2.json b/advisories/unreviewed/2024/11/GHSA-gr86-frw6-7wp2/GHSA-gr86-frw6-7wp2.json new file mode 100644 index 00000000000..1a463a2e2ea --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gr86-frw6-7wp2/GHSA-gr86-frw6-7wp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr86-frw6-7wp2", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47434" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47434" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json b/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json index 68453a3f056..0320322bef2 100644 --- a/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json +++ b/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2xv-hq2x-rvxq", - "modified": "2024-11-11T21:31:49Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T21:31:49Z", "aliases": [ "CVE-2024-51026" ], "details": "The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T21:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json b/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json new file mode 100644 index 00000000000..1f052ccfcf9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hw9x-8m75-4vjq/GHSA-hw9x-8m75-4vjq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw9x-8m75-4vjq", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-51093" + ], + "details": "Cross Site Scripting vulnerability in Snipe-IT v.7.0.13 allows a remote attacker to escalate privileges via an unknown part of the file /users/{{user-id}}/#files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51093" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/Tommywarren/ca70f1c43f4ec34dc19cd13459535780/raw/d13192ae50bc7c024b922412dfa3f530faa8d5db/CVE-2024-51093" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json b/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json index 9fbe6cbb260..8d7e36cf1d5 100644 --- a/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json +++ b/advisories/unreviewed/2024/11/GHSA-hwrr-qggh-2777/GHSA-hwrr-qggh-2777.json @@ -33,7 +33,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-209" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-j3qc-mp9w-wcwv/GHSA-j3qc-mp9w-wcwv.json b/advisories/unreviewed/2024/11/GHSA-j3qc-mp9w-wcwv/GHSA-j3qc-mp9w-wcwv.json new file mode 100644 index 00000000000..2a7c3a2f220 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j3qc-mp9w-wcwv/GHSA-j3qc-mp9w-wcwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3qc-mp9w-wcwv", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49520" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49520" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jcvj-p2rg-4rpw/GHSA-jcvj-p2rg-4rpw.json b/advisories/unreviewed/2024/11/GHSA-jcvj-p2rg-4rpw/GHSA-jcvj-p2rg-4rpw.json new file mode 100644 index 00000000000..2f6531022f6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jcvj-p2rg-4rpw/GHSA-jcvj-p2rg-4rpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcvj-p2rg-4rpw", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47435" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47435" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jfx4-p2cg-248g/GHSA-jfx4-p2cg-248g.json b/advisories/unreviewed/2024/11/GHSA-jfx4-p2cg-248g/GHSA-jfx4-p2cg-248g.json new file mode 100644 index 00000000000..7099d958334 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jfx4-p2cg-248g/GHSA-jfx4-p2cg-248g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfx4-p2cg-248g", + "modified": "2024-11-12T21:30:51Z", + "published": "2024-11-12T21:30:51Z", + "aliases": [ + "CVE-2023-47543" + ], + "details": "An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47543" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-448" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json b/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json index 2b7cdc4627e..2f81f4181a4 100644 --- a/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json +++ b/advisories/unreviewed/2024/11/GHSA-jrvf-vccr-mvp6/GHSA-jrvf-vccr-mvp6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrvf-vccr-mvp6", - "modified": "2024-11-11T00:30:44Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-11-11T00:30:44Z", "aliases": [ "CVE-2024-46956" ], "details": "An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-10T22:15:12Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jwm4-jq46-9g26/GHSA-jwm4-jq46-9g26.json b/advisories/unreviewed/2024/11/GHSA-jwm4-jq46-9g26/GHSA-jwm4-jq46-9g26.json new file mode 100644 index 00000000000..f81709dbe13 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jwm4-jq46-9g26/GHSA-jwm4-jq46-9g26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwm4-jq46-9g26", + "modified": "2024-11-12T21:30:51Z", + "published": "2024-11-12T21:30:51Z", + "aliases": [ + "CVE-2024-23666" + ], + "details": "A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData \nat least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23666" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jwp7-wvcp-qc35/GHSA-jwp7-wvcp-qc35.json b/advisories/unreviewed/2024/11/GHSA-jwp7-wvcp-qc35/GHSA-jwp7-wvcp-qc35.json new file mode 100644 index 00000000000..19bcd972c36 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jwp7-wvcp-qc35/GHSA-jwp7-wvcp-qc35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwp7-wvcp-qc35", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-32118" + ], + "details": "Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32118" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json b/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json new file mode 100644 index 00000000000..8a15519c23d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jxg2-g8jw-r8cj/GHSA-jxg2-g8jw-r8cj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxg2-g8jw-r8cj", + "modified": "2024-11-12T21:30:51Z", + "published": "2024-11-12T21:30:51Z", + "aliases": [ + "CVE-2023-52268" + ], + "details": "The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52268" + }, + { + "type": "WEB", + "url": "https://freescout.net/module/end-user-portal" + }, + { + "type": "WEB", + "url": "https://freescout.net/modules-faq" + }, + { + "type": "WEB", + "url": "https://github.com/squ1dw3rm/CVE-2023-52268" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m84v-65mj-hw78/GHSA-m84v-65mj-hw78.json b/advisories/unreviewed/2024/11/GHSA-m84v-65mj-hw78/GHSA-m84v-65mj-hw78.json new file mode 100644 index 00000000000..afd80e1c0c8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m84v-65mj-hw78/GHSA-m84v-65mj-hw78.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m84v-65mj-hw78", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11115" + ], + "details": "Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11115" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/371929521" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mg99-9h93-rq3m/GHSA-mg99-9h93-rq3m.json b/advisories/unreviewed/2024/11/GHSA-mg99-9h93-rq3m/GHSA-mg99-9h93-rq3m.json new file mode 100644 index 00000000000..19fc6a785a7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mg99-9h93-rq3m/GHSA-mg99-9h93-rq3m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg99-9h93-rq3m", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47452" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47452" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mj4p-7pw5-mh9m/GHSA-mj4p-7pw5-mh9m.json b/advisories/unreviewed/2024/11/GHSA-mj4p-7pw5-mh9m/GHSA-mj4p-7pw5-mh9m.json new file mode 100644 index 00000000000..8914caeccb2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mj4p-7pw5-mh9m/GHSA-mj4p-7pw5-mh9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj4p-7pw5-mh9m", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-32116" + ], + "details": "Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32116" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mp4j-j99g-pqwf/GHSA-mp4j-j99g-pqwf.json b/advisories/unreviewed/2024/11/GHSA-mp4j-j99g-pqwf/GHSA-mp4j-j99g-pqwf.json new file mode 100644 index 00000000000..35dd109a67b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mp4j-j99g-pqwf/GHSA-mp4j-j99g-pqwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp4j-j99g-pqwf", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-43613" + ], + "details": "Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43613" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43613" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mpwh-m8v4-4v78/GHSA-mpwh-m8v4-4v78.json b/advisories/unreviewed/2024/11/GHSA-mpwh-m8v4-4v78/GHSA-mpwh-m8v4-4v78.json new file mode 100644 index 00000000000..50d80d08d2d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mpwh-m8v4-4v78/GHSA-mpwh-m8v4-4v78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpwh-m8v4-4v78", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47443" + ], + "details": "After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47443" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-85.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mx2x-7r9x-jj3v/GHSA-mx2x-7r9x-jj3v.json b/advisories/unreviewed/2024/11/GHSA-mx2x-7r9x-jj3v/GHSA-mx2x-7r9x-jj3v.json new file mode 100644 index 00000000000..1cbaec28a39 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mx2x-7r9x-jj3v/GHSA-mx2x-7r9x-jj3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx2x-7r9x-jj3v", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47446" + ], + "details": "After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47446" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-85.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p3r5-57j4-gq4x/GHSA-p3r5-57j4-gq4x.json b/advisories/unreviewed/2024/11/GHSA-p3r5-57j4-gq4x/GHSA-p3r5-57j4-gq4x.json new file mode 100644 index 00000000000..eb733b772d6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p3r5-57j4-gq4x/GHSA-p3r5-57j4-gq4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3r5-57j4-gq4x", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49516" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49516" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p8w2-9cmv-c9gc/GHSA-p8w2-9cmv-c9gc.json b/advisories/unreviewed/2024/11/GHSA-p8w2-9cmv-c9gc/GHSA-p8w2-9cmv-c9gc.json new file mode 100644 index 00000000000..bad947cc625 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p8w2-9cmv-c9gc/GHSA-p8w2-9cmv-c9gc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8w2-9cmv-c9gc", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49507" + ], + "details": "InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49507" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-88.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pgmr-p79v-f7mc/GHSA-pgmr-p79v-f7mc.json b/advisories/unreviewed/2024/11/GHSA-pgmr-p79v-f7mc/GHSA-pgmr-p79v-f7mc.json new file mode 100644 index 00000000000..2d57a21f178 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pgmr-p79v-f7mc/GHSA-pgmr-p79v-f7mc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgmr-p79v-f7mc", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-33505" + ], + "details": "A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33505" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json b/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json new file mode 100644 index 00000000000..4daa321af9e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjmr-ff79-h6xp", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-35274" + ], + "details": "An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write administrative privileges to create non-arbitrary files on a chosen directory via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35274" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pq96-5jf7-gxjh/GHSA-pq96-5jf7-gxjh.json b/advisories/unreviewed/2024/11/GHSA-pq96-5jf7-gxjh/GHSA-pq96-5jf7-gxjh.json new file mode 100644 index 00000000000..d5cb9240185 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pq96-5jf7-gxjh/GHSA-pq96-5jf7-gxjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq96-5jf7-gxjh", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49519" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49519" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q6mf-q7m8-gw96/GHSA-q6mf-q7m8-gw96.json b/advisories/unreviewed/2024/11/GHSA-q6mf-q7m8-gw96/GHSA-q6mf-q7m8-gw96.json index 0bd3120d91f..a05494a920c 100644 --- a/advisories/unreviewed/2024/11/GHSA-q6mf-q7m8-gw96/GHSA-q6mf-q7m8-gw96.json +++ b/advisories/unreviewed/2024/11/GHSA-q6mf-q7m8-gw96/GHSA-q6mf-q7m8-gw96.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q6mf-q7m8-gw96", - "modified": "2024-11-01T15:32:00Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-11-01T15:32:00Z", "aliases": [ "CVE-2024-47317" diff --git a/advisories/unreviewed/2024/11/GHSA-q6p7-p3cc-vcf9/GHSA-q6p7-p3cc-vcf9.json b/advisories/unreviewed/2024/11/GHSA-q6p7-p3cc-vcf9/GHSA-q6p7-p3cc-vcf9.json new file mode 100644 index 00000000000..dcc7b5038b2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q6p7-p3cc-vcf9/GHSA-q6p7-p3cc-vcf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6p7-p3cc-vcf9", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-2207" + ], + "details": "Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2207" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11567250-11567490-16/hpsbhf03987" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q7j7-7r72-9h66/GHSA-q7j7-7r72-9h66.json b/advisories/unreviewed/2024/11/GHSA-q7j7-7r72-9h66/GHSA-q7j7-7r72-9h66.json new file mode 100644 index 00000000000..ede10b34ff6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q7j7-7r72-9h66/GHSA-q7j7-7r72-9h66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7j7-7r72-9h66", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-7516" + ], + "details": "A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7516" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-322" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q9h5-v87h-3hhr/GHSA-q9h5-v87h-3hhr.json b/advisories/unreviewed/2024/11/GHSA-q9h5-v87h-3hhr/GHSA-q9h5-v87h-3hhr.json new file mode 100644 index 00000000000..2cf07a65cb0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q9h5-v87h-3hhr/GHSA-q9h5-v87h-3hhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9h5-v87h-3hhr", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47431" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47431" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qc3r-qr6p-cwr5/GHSA-qc3r-qr6p-cwr5.json b/advisories/unreviewed/2024/11/GHSA-qc3r-qr6p-cwr5/GHSA-qc3r-qr6p-cwr5.json new file mode 100644 index 00000000000..83ef04d2c47 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qc3r-qr6p-cwr5/GHSA-qc3r-qr6p-cwr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc3r-qr6p-cwr5", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49525" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49525" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qq58-pf2w-c658/GHSA-qq58-pf2w-c658.json b/advisories/unreviewed/2024/11/GHSA-qq58-pf2w-c658/GHSA-qq58-pf2w-c658.json new file mode 100644 index 00000000000..92661c43ba0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qq58-pf2w-c658/GHSA-qq58-pf2w-c658.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq58-pf2w-c658", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-47441" + ], + "details": "After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47441" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/after_effects/apsb24-85.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r9m4-7h5v-g8h8/GHSA-r9m4-7h5v-g8h8.json b/advisories/unreviewed/2024/11/GHSA-r9m4-7h5v-g8h8/GHSA-r9m4-7h5v-g8h8.json new file mode 100644 index 00000000000..9a7161b256b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r9m4-7h5v-g8h8/GHSA-r9m4-7h5v-g8h8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9m4-7h5v-g8h8", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47439" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47439" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rf9w-7f29-2cx2/GHSA-rf9w-7f29-2cx2.json b/advisories/unreviewed/2024/11/GHSA-rf9w-7f29-2cx2/GHSA-rf9w-7f29-2cx2.json new file mode 100644 index 00000000000..27412a33667 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rf9w-7f29-2cx2/GHSA-rf9w-7f29-2cx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf9w-7f29-2cx2", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-49042" + ], + "details": "Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49042" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rh9f-c55m-vh5v/GHSA-rh9f-c55m-vh5v.json b/advisories/unreviewed/2024/11/GHSA-rh9f-c55m-vh5v/GHSA-rh9f-c55m-vh5v.json new file mode 100644 index 00000000000..d712316d025 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rh9f-c55m-vh5v/GHSA-rh9f-c55m-vh5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh9f-c55m-vh5v", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47428" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47428" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json b/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json new file mode 100644 index 00000000000..caa96bc0b36 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmcg-5mh4-47x7/GHSA-rmcg-5mh4-47x7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmcg-5mh4-47x7", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-51094" + ], + "details": "An issue in Snipe-IT v.7.0.13 build 15514 allows a remote attacker to escalate privileges via the file /account/profile of the component \"Name\" field value under \"Edit Your Profile\".", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51094" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/Tommywarren/b3a6c6ae5a93dd67c863313f71f53a76/raw/ddff8cbbab5179f680ba3f5e94fc080575ad8913/CVE-2024-51094" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rmph-8gw6-8rhx/GHSA-rmph-8gw6-8rhx.json b/advisories/unreviewed/2024/11/GHSA-rmph-8gw6-8rhx/GHSA-rmph-8gw6-8rhx.json new file mode 100644 index 00000000000..75af9ef0909 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rmph-8gw6-8rhx/GHSA-rmph-8gw6-8rhx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmph-8gw6-8rhx", + "modified": "2024-11-12T21:30:52Z", + "published": "2024-11-12T21:30:52Z", + "aliases": [ + "CVE-2024-36507" + ], + "details": "A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36507" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-205" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rp64-jc8m-27wc/GHSA-rp64-jc8m-27wc.json b/advisories/unreviewed/2024/11/GHSA-rp64-jc8m-27wc/GHSA-rp64-jc8m-27wc.json new file mode 100644 index 00000000000..a411601bec4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rp64-jc8m-27wc/GHSA-rp64-jc8m-27wc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp64-jc8m-27wc", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-51721" + ], + "details": "A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would run with root privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51721" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v428-c7m6-vqcx/GHSA-v428-c7m6-vqcx.json b/advisories/unreviewed/2024/11/GHSA-v428-c7m6-vqcx/GHSA-v428-c7m6-vqcx.json new file mode 100644 index 00000000000..a5e4395396c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v428-c7m6-vqcx/GHSA-v428-c7m6-vqcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v428-c7m6-vqcx", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-49515" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. The problem extends to any type of critical resource that the application trusts. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49515" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v482-hq83-hpfg/GHSA-v482-hq83-hpfg.json b/advisories/unreviewed/2024/11/GHSA-v482-hq83-hpfg/GHSA-v482-hq83-hpfg.json new file mode 100644 index 00000000000..c577a304b7a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v482-hq83-hpfg/GHSA-v482-hq83-hpfg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v482-hq83-hpfg", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-49511" + ], + "details": "InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49511" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/indesign/apsb24-88.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json b/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json index c7550b2424f..9aa5208f574 100644 --- a/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json +++ b/advisories/unreviewed/2024/11/GHSA-w9j2-h8vr-446x/GHSA-w9j2-h8vr-446x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9j2-h8vr-446x", - "modified": "2024-11-11T00:30:43Z", + "modified": "2024-11-12T21:30:50Z", "published": "2024-11-11T00:30:43Z", "aliases": [ "CVE-2024-46955" ], "details": "An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-10T22:15:12Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wq79-mjg7-48hq/GHSA-wq79-mjg7-48hq.json b/advisories/unreviewed/2024/11/GHSA-wq79-mjg7-48hq/GHSA-wq79-mjg7-48hq.json new file mode 100644 index 00000000000..e60e91b9293 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wq79-mjg7-48hq/GHSA-wq79-mjg7-48hq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq79-mjg7-48hq", + "modified": "2024-11-12T21:30:55Z", + "published": "2024-11-12T21:30:55Z", + "aliases": [ + "CVE-2024-11117" + ], + "details": "Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11117" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40062534" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wr74-rqfg-9299/GHSA-wr74-rqfg-9299.json b/advisories/unreviewed/2024/11/GHSA-wr74-rqfg-9299/GHSA-wr74-rqfg-9299.json index 2e6ccf10b66..575dd833e3a 100644 --- a/advisories/unreviewed/2024/11/GHSA-wr74-rqfg-9299/GHSA-wr74-rqfg-9299.json +++ b/advisories/unreviewed/2024/11/GHSA-wr74-rqfg-9299/GHSA-wr74-rqfg-9299.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr74-rqfg-9299", - "modified": "2024-11-11T15:31:02Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T15:31:02Z", "aliases": [ "CVE-2024-50989" ], "details": "A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the \"searchdata \" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T15:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json b/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json index e7b69a69ab5..779bf9ba216 100644 --- a/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json +++ b/advisories/unreviewed/2024/11/GHSA-x6qj-75g5-46wg/GHSA-x6qj-75g5-46wg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-670" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-x74x-9w6r-75c3/GHSA-x74x-9w6r-75c3.json b/advisories/unreviewed/2024/11/GHSA-x74x-9w6r-75c3/GHSA-x74x-9w6r-75c3.json new file mode 100644 index 00000000000..ae19960a5e5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x74x-9w6r-75c3/GHSA-x74x-9w6r-75c3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74x-9w6r-75c3", + "modified": "2024-11-12T21:30:53Z", + "published": "2024-11-12T21:30:53Z", + "aliases": [ + "CVE-2024-47454" + ], + "details": "Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47454" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/illustrator/apsb24-87.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xcwx-v8f8-hq62/GHSA-xcwx-v8f8-hq62.json b/advisories/unreviewed/2024/11/GHSA-xcwx-v8f8-hq62/GHSA-xcwx-v8f8-hq62.json new file mode 100644 index 00000000000..d2679e3db0a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xcwx-v8f8-hq62/GHSA-xcwx-v8f8-hq62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcwx-v8f8-hq62", + "modified": "2024-11-12T21:30:54Z", + "published": "2024-11-12T21:30:54Z", + "aliases": [ + "CVE-2024-47429" + ], + "details": "Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47429" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-12T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xwr3-f5gh-9v6w/GHSA-xwr3-f5gh-9v6w.json b/advisories/unreviewed/2024/11/GHSA-xwr3-f5gh-9v6w/GHSA-xwr3-f5gh-9v6w.json index e7d6db0ecf7..cc5230f0562 100644 --- a/advisories/unreviewed/2024/11/GHSA-xwr3-f5gh-9v6w/GHSA-xwr3-f5gh-9v6w.json +++ b/advisories/unreviewed/2024/11/GHSA-xwr3-f5gh-9v6w/GHSA-xwr3-f5gh-9v6w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xwr3-f5gh-9v6w", - "modified": "2024-11-11T03:30:45Z", + "modified": "2024-11-12T21:30:51Z", "published": "2024-11-11T03:30:45Z", "aliases": [ "CVE-2024-41992" ], "details": "Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-11T01:15:04Z"