From f8c6339267a81a4cf6f331b9d84fe62b49989eb0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 14 Aug 2024 18:34:09 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3w2f-j9r3-9h89.json | 2 +- .../GHSA-vfhc-4q79-wvf9.json | 18 +++++++- .../GHSA-2v9x-x358-276j.json | 11 +++-- .../GHSA-4498-28jp-m89x.json | 11 +++-- .../GHSA-4847-mppj-fwhp.json | 11 +++-- .../GHSA-8cpv-pp42-ppmr.json | 11 +++-- .../GHSA-gm42-r9cp-95fh.json | 11 +++-- .../GHSA-jc8v-q399-gfq9.json | 11 +++-- .../GHSA-m3q9-44rg-xw34.json | 9 ++-- .../GHSA-pr57-r6pp-3h3h.json | 9 ++-- .../GHSA-qmvm-mg94-c39p.json | 11 +++-- .../GHSA-vmh4-jjxc-hgm4.json | 11 +++-- .../GHSA-xq2h-vm9v-fgph.json | 11 +++-- .../GHSA-w9xx-xhpg-c678.json | 3 +- .../GHSA-hwrp-v8fj-7p9x.json | 1 + .../GHSA-pf95-r93p-c3p6.json | 11 +++-- .../GHSA-2mxh-j9g4-gj85.json | 1 + .../GHSA-3xxg-9vrr-9g96.json | 38 +++++++++++++++++ .../GHSA-475c-8mw8-7m88.json | 38 +++++++++++++++++ .../GHSA-4m5j-3mr3-cv42.json | 38 +++++++++++++++++ .../GHSA-5jm2-m5ch-w9xp.json | 38 +++++++++++++++++ .../GHSA-64hf-wv63-57h5.json | 38 +++++++++++++++++ .../GHSA-6r2r-p6rp-m369.json | 38 +++++++++++++++++ .../GHSA-754m-gg4c-75j7.json | 11 +++-- .../GHSA-7867-7x9c-9gr2.json | 42 +++++++++++++++++++ .../GHSA-7p73-rpm9-rwr6.json | 42 +++++++++++++++++++ .../GHSA-8jq9-2rv4-gphv.json | 11 +++-- .../GHSA-97p6-m24q-57p8.json | 42 +++++++++++++++++++ .../GHSA-9jpm-269x-j69q.json | 38 +++++++++++++++++ .../GHSA-9m5w-7xhr-393x.json | 4 +- .../GHSA-ch97-hpq7-jfg9.json | 38 +++++++++++++++++ .../GHSA-cp7r-3r6c-mj6f.json | 38 +++++++++++++++++ .../GHSA-cvjp-23hx-635r.json | 38 +++++++++++++++++ .../GHSA-f245-vq36-rx88.json | 38 +++++++++++++++++ .../GHSA-frj6-38mm-gr73.json | 38 +++++++++++++++++ .../GHSA-g536-h677-2w32.json | 2 +- .../GHSA-g788-m4v3-47c7.json | 42 +++++++++++++++++++ .../GHSA-j78j-h8vv-5m5x.json | 38 +++++++++++++++++ .../GHSA-j8ch-8f2h-7f8f.json | 9 ++-- .../GHSA-jjch-2577-r3c2.json | 42 +++++++++++++++++++ .../GHSA-mjf8-fqvw-qvr7.json | 38 +++++++++++++++++ .../GHSA-pwhp-4qxf-7ff6.json | 42 +++++++++++++++++++ .../GHSA-q7vq-23c3-qm7w.json | 42 +++++++++++++++++++ .../GHSA-qrw6-cmhg-g5p6.json | 42 +++++++++++++++++++ .../GHSA-r979-6ffq-pvxw.json | 3 +- .../GHSA-wrqr-6727-v5vq.json | 11 +++-- .../GHSA-x6mm-hvfx-gxp7.json | 38 +++++++++++++++++ .../GHSA-xr43-cwp6-p6wf.json | 38 +++++++++++++++++ 48 files changed, 1080 insertions(+), 68 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json create mode 100644 advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4m5j-3mr3-cv42/GHSA-4m5j-3mr3-cv42.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-64hf-wv63-57h5/GHSA-64hf-wv63-57h5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6r2r-p6rp-m369/GHSA-6r2r-p6rp-m369.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7867-7x9c-9gr2/GHSA-7867-7x9c-9gr2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7p73-rpm9-rwr6/GHSA-7p73-rpm9-rwr6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-97p6-m24q-57p8/GHSA-97p6-m24q-57p8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9jpm-269x-j69q/GHSA-9jpm-269x-j69q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cp7r-3r6c-mj6f/GHSA-cp7r-3r6c-mj6f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cvjp-23hx-635r/GHSA-cvjp-23hx-635r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f245-vq36-rx88/GHSA-f245-vq36-rx88.json create mode 100644 advisories/unreviewed/2024/08/GHSA-frj6-38mm-gr73/GHSA-frj6-38mm-gr73.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g788-m4v3-47c7/GHSA-g788-m4v3-47c7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jjch-2577-r3c2/GHSA-jjch-2577-r3c2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mjf8-fqvw-qvr7/GHSA-mjf8-fqvw-qvr7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q7vq-23c3-qm7w/GHSA-q7vq-23c3-qm7w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qrw6-cmhg-g5p6/GHSA-qrw6-cmhg-g5p6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x6mm-hvfx-gxp7/GHSA-x6mm-hvfx-gxp7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xr43-cwp6-p6wf/GHSA-xr43-cwp6-p6wf.json diff --git a/advisories/unreviewed/2023/07/GHSA-3w2f-j9r3-9h89/GHSA-3w2f-j9r3-9h89.json b/advisories/unreviewed/2023/07/GHSA-3w2f-j9r3-9h89/GHSA-3w2f-j9r3-9h89.json index 7d4de949b9f..622dc565bc5 100644 --- a/advisories/unreviewed/2023/07/GHSA-3w2f-j9r3-9h89/GHSA-3w2f-j9r3-9h89.json +++ b/advisories/unreviewed/2023/07/GHSA-3w2f-j9r3-9h89/GHSA-3w2f-j9r3-9h89.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json b/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json index 599c4405a44..82ae9031f30 100644 --- a/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json +++ b/advisories/unreviewed/2024/01/GHSA-vfhc-4q79-wvf9/GHSA-vfhc-4q79-wvf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfhc-4q79-wvf9", - "modified": "2024-01-09T21:30:28Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-01-01T18:30:25Z", "aliases": [ "CVE-2023-50094" @@ -17,10 +17,26 @@ ], "references": [ + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/security/advisories/GHSA-fx7f-f735-vgh4" + }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50094" }, + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/commit/3d5f1724dd12cf9861443742e7d7c02ff8c75a6f" + }, + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/commit/edd3c85ee16f93804ad38dac5602549d2d30a93e" + }, + { + "type": "WEB", + "url": "https://github.com/yogeshojha/rengine/blob/53d9f505f04861a5040195ea71f20907ff90577a/web/api/views.py#L268-L275" + }, { "type": "WEB", "url": "https://github.com/yogeshojha/rengine/blob/5e120bd5f9dfbd1da82a193e8c9702e483d38d22/web/api/views.py#L195" diff --git a/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json b/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json index 7fcc3208de3..501af542139 100644 --- a/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json +++ b/advisories/unreviewed/2024/02/GHSA-2v9x-x358-276j/GHSA-2v9x-x358-276j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2v9x-x358-276j", - "modified": "2024-02-22T21:30:32Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-22T21:30:32Z", "aliases": [ "CVE-2024-22547" ], "details": "WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T19:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4498-28jp-m89x/GHSA-4498-28jp-m89x.json b/advisories/unreviewed/2024/02/GHSA-4498-28jp-m89x/GHSA-4498-28jp-m89x.json index 3a5a535c166..85eadd516d9 100644 --- a/advisories/unreviewed/2024/02/GHSA-4498-28jp-m89x/GHSA-4498-28jp-m89x.json +++ b/advisories/unreviewed/2024/02/GHSA-4498-28jp-m89x/GHSA-4498-28jp-m89x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4498-28jp-m89x", - "modified": "2024-02-22T00:31:01Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-22T00:31:01Z", "aliases": [ "CVE-2023-52155" ], "details": "A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T22:15:49Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json b/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json index 08af5141c63..9b06d86010c 100644 --- a/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json +++ b/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4847-mppj-fwhp", - "modified": "2024-02-21T18:31:02Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-21T18:31:02Z", "aliases": [ "CVE-2024-25892" ], "details": "ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T18:15:51Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json b/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json index 78b7e4f2064..d950078bd27 100644 --- a/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json +++ b/advisories/unreviewed/2024/02/GHSA-8cpv-pp42-ppmr/GHSA-8cpv-pp42-ppmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cpv-pp42-ppmr", - "modified": "2024-05-02T18:30:50Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-27T03:31:02Z", "aliases": [ "CVE-2024-24720" ], "details": "An issue was discovered on Innovaphone PBX before 14r1 devices. It provides different responses to incoming requests in a way that reveals information to an attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T01:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gm42-r9cp-95fh/GHSA-gm42-r9cp-95fh.json b/advisories/unreviewed/2024/02/GHSA-gm42-r9cp-95fh/GHSA-gm42-r9cp-95fh.json index ffb13038ed0..84177705153 100644 --- a/advisories/unreviewed/2024/02/GHSA-gm42-r9cp-95fh/GHSA-gm42-r9cp-95fh.json +++ b/advisories/unreviewed/2024/02/GHSA-gm42-r9cp-95fh/GHSA-gm42-r9cp-95fh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm42-r9cp-95fh", - "modified": "2024-02-22T15:30:39Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-22T15:30:39Z", "aliases": [ "CVE-2024-26349" ], "details": "flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_translation.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T14:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jc8v-q399-gfq9/GHSA-jc8v-q399-gfq9.json b/advisories/unreviewed/2024/02/GHSA-jc8v-q399-gfq9/GHSA-jc8v-q399-gfq9.json index 786273bb534..722540576e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-jc8v-q399-gfq9/GHSA-jc8v-q399-gfq9.json +++ b/advisories/unreviewed/2024/02/GHSA-jc8v-q399-gfq9/GHSA-jc8v-q399-gfq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc8v-q399-gfq9", - "modified": "2024-05-14T15:32:40Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-26461" ], "details": "Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:18Z" diff --git a/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json b/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json index 25085c33d6c..450cb72f2dc 100644 --- a/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json +++ b/advisories/unreviewed/2024/02/GHSA-m3q9-44rg-xw34/GHSA-m3q9-44rg-xw34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3q9-44rg-xw34", - "modified": "2024-03-03T03:30:23Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-26T18:30:28Z", "aliases": [ "CVE-2023-49114" ], "details": "A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:27:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pr57-r6pp-3h3h/GHSA-pr57-r6pp-3h3h.json b/advisories/unreviewed/2024/02/GHSA-pr57-r6pp-3h3h/GHSA-pr57-r6pp-3h3h.json index ef5288f538d..dfddf73ce95 100644 --- a/advisories/unreviewed/2024/02/GHSA-pr57-r6pp-3h3h/GHSA-pr57-r6pp-3h3h.json +++ b/advisories/unreviewed/2024/02/GHSA-pr57-r6pp-3h3h/GHSA-pr57-r6pp-3h3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pr57-r6pp-3h3h", - "modified": "2024-02-20T12:31:00Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-20T12:31:00Z", "aliases": [ "CVE-2023-7245" ], "details": "The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-95" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T11:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json b/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json index c037cd59981..a05b6b702cf 100644 --- a/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json +++ b/advisories/unreviewed/2024/02/GHSA-qmvm-mg94-c39p/GHSA-qmvm-mg94-c39p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmvm-mg94-c39p", - "modified": "2024-02-26T18:30:31Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-27455" ], "details": "In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.02.03 and Assetwise Information Integrity Server 23.00.04.04.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-488" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T16:28:00Z" diff --git a/advisories/unreviewed/2024/02/GHSA-vmh4-jjxc-hgm4/GHSA-vmh4-jjxc-hgm4.json b/advisories/unreviewed/2024/02/GHSA-vmh4-jjxc-hgm4/GHSA-vmh4-jjxc-hgm4.json index 74f1e328837..afba7ad5b4d 100644 --- a/advisories/unreviewed/2024/02/GHSA-vmh4-jjxc-hgm4/GHSA-vmh4-jjxc-hgm4.json +++ b/advisories/unreviewed/2024/02/GHSA-vmh4-jjxc-hgm4/GHSA-vmh4-jjxc-hgm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmh4-jjxc-hgm4", - "modified": "2024-02-21T21:30:25Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-21T21:30:25Z", "aliases": [ "CVE-2023-24332" ], "details": "A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T21:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xq2h-vm9v-fgph/GHSA-xq2h-vm9v-fgph.json b/advisories/unreviewed/2024/02/GHSA-xq2h-vm9v-fgph/GHSA-xq2h-vm9v-fgph.json index b6b40c3a504..a083090dcd7 100644 --- a/advisories/unreviewed/2024/02/GHSA-xq2h-vm9v-fgph/GHSA-xq2h-vm9v-fgph.json +++ b/advisories/unreviewed/2024/02/GHSA-xq2h-vm9v-fgph/GHSA-xq2h-vm9v-fgph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq2h-vm9v-fgph", - "modified": "2024-02-23T15:30:37Z", + "modified": "2024-08-14T18:32:36Z", "published": "2024-02-23T15:30:37Z", "aliases": [ "CVE-2024-22776" ], "details": "Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-23T15:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json b/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json index 61f1cfbaa43..4dbeb5c3531 100644 --- a/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json +++ b/advisories/unreviewed/2024/04/GHSA-w9xx-xhpg-c678/GHSA-w9xx-xhpg-c678.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-280" + "CWE-280", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-hwrp-v8fj-7p9x/GHSA-hwrp-v8fj-7p9x.json b/advisories/unreviewed/2024/06/GHSA-hwrp-v8fj-7p9x/GHSA-hwrp-v8fj-7p9x.json index bd59166fa1a..5866f073f53 100644 --- a/advisories/unreviewed/2024/06/GHSA-hwrp-v8fj-7p9x/GHSA-hwrp-v8fj-7p9x.json +++ b/advisories/unreviewed/2024/06/GHSA-hwrp-v8fj-7p9x/GHSA-hwrp-v8fj-7p9x.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-31" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-pf95-r93p-c3p6/GHSA-pf95-r93p-c3p6.json b/advisories/unreviewed/2024/07/GHSA-pf95-r93p-c3p6/GHSA-pf95-r93p-c3p6.json index 32a4bbc2a62..3c66a450e4d 100644 --- a/advisories/unreviewed/2024/07/GHSA-pf95-r93p-c3p6/GHSA-pf95-r93p-c3p6.json +++ b/advisories/unreviewed/2024/07/GHSA-pf95-r93p-c3p6/GHSA-pf95-r93p-c3p6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pf95-r93p-c3p6", - "modified": "2024-07-22T18:31:48Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-07-22T18:31:48Z", "aliases": [ "CVE-2024-40051" ], "details": "IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-22T18:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2mxh-j9g4-gj85/GHSA-2mxh-j9g4-gj85.json b/advisories/unreviewed/2024/08/GHSA-2mxh-j9g4-gj85/GHSA-2mxh-j9g4-gj85.json index 26f8f859b72..22eda67ce55 100644 --- a/advisories/unreviewed/2024/08/GHSA-2mxh-j9g4-gj85/GHSA-2mxh-j9g4-gj85.json +++ b/advisories/unreviewed/2024/08/GHSA-2mxh-j9g4-gj85/GHSA-2mxh-j9g4-gj85.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-665" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json b/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json new file mode 100644 index 00000000000..5b7248ec7ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3xxg-9vrr-9g96/GHSA-3xxg-9vrr-9g96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xxg-9vrr-9g96", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-39825" + ], + "details": "Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39825" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json b/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json new file mode 100644 index 00000000000..470e1a1b18e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-475c-8mw8-7m88/GHSA-475c-8mw8-7m88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-475c-8mw8-7m88", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42437" + ], + "details": "Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42437" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4m5j-3mr3-cv42/GHSA-4m5j-3mr3-cv42.json b/advisories/unreviewed/2024/08/GHSA-4m5j-3mr3-cv42/GHSA-4m5j-3mr3-cv42.json new file mode 100644 index 00000000000..ba60c9235be --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4m5j-3mr3-cv42/GHSA-4m5j-3mr3-cv42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m5j-3mr3-cv42", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42440" + ], + "details": "Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42440" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json b/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json new file mode 100644 index 00000000000..9c50ffa7134 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5jm2-m5ch-w9xp/GHSA-5jm2-m5ch-w9xp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jm2-m5ch-w9xp", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42436" + ], + "details": "Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42436" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-64hf-wv63-57h5/GHSA-64hf-wv63-57h5.json b/advisories/unreviewed/2024/08/GHSA-64hf-wv63-57h5/GHSA-64hf-wv63-57h5.json new file mode 100644 index 00000000000..1b84723337b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-64hf-wv63-57h5/GHSA-64hf-wv63-57h5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64hf-wv63-57h5", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42438" + ], + "details": "Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42438" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6r2r-p6rp-m369/GHSA-6r2r-p6rp-m369.json b/advisories/unreviewed/2024/08/GHSA-6r2r-p6rp-m369/GHSA-6r2r-p6rp-m369.json new file mode 100644 index 00000000000..eb9c8b78bbc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6r2r-p6rp-m369/GHSA-6r2r-p6rp-m369.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r2r-p6rp-m369", + "modified": "2024-08-14T18:32:41Z", + "published": "2024-08-14T18:32:41Z", + "aliases": [ + "CVE-2024-39822" + ], + "details": "Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39822" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json b/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json index c91147fcd0c..4443e488d5e 100644 --- a/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json +++ b/advisories/unreviewed/2024/08/GHSA-754m-gg4c-75j7/GHSA-754m-gg4c-75j7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-754m-gg4c-75j7", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-41711" ], "details": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T17:15:24Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7867-7x9c-9gr2/GHSA-7867-7x9c-9gr2.json b/advisories/unreviewed/2024/08/GHSA-7867-7x9c-9gr2/GHSA-7867-7x9c-9gr2.json new file mode 100644 index 00000000000..f0739fa4c39 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7867-7x9c-9gr2/GHSA-7867-7x9c-9gr2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7867-7x9c-9gr2", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-37529" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 294295.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37529" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/292639" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7p73-rpm9-rwr6/GHSA-7p73-rpm9-rwr6.json b/advisories/unreviewed/2024/08/GHSA-7p73-rpm9-rwr6/GHSA-7p73-rpm9-rwr6.json new file mode 100644 index 00000000000..53e7d2ff796 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7p73-rpm9-rwr6/GHSA-7p73-rpm9-rwr6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p73-rpm9-rwr6", + "modified": "2024-08-14T18:32:41Z", + "published": "2024-08-14T18:32:41Z", + "aliases": [ + "CVE-2024-27267" + ], + "details": "The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads. IBM X-Force ID: 284573.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27267" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/284573" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165421" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-300" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json b/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json index 986abb1a614..507ae885043 100644 --- a/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json +++ b/advisories/unreviewed/2024/08/GHSA-8jq9-2rv4-gphv/GHSA-8jq9-2rv4-gphv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jq9-2rv4-gphv", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-41613" ], "details": "A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T17:15:23Z" diff --git a/advisories/unreviewed/2024/08/GHSA-97p6-m24q-57p8/GHSA-97p6-m24q-57p8.json b/advisories/unreviewed/2024/08/GHSA-97p6-m24q-57p8/GHSA-97p6-m24q-57p8.json new file mode 100644 index 00000000000..4de4b6647b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-97p6-m24q-57p8/GHSA-97p6-m24q-57p8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97p6-m24q-57p8", + "modified": "2024-08-14T18:32:41Z", + "published": "2024-08-14T18:32:41Z", + "aliases": [ + "CVE-2024-28799" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28799" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287173" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165488" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-214" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9jpm-269x-j69q/GHSA-9jpm-269x-j69q.json b/advisories/unreviewed/2024/08/GHSA-9jpm-269x-j69q/GHSA-9jpm-269x-j69q.json new file mode 100644 index 00000000000..4a4bf09917d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9jpm-269x-j69q/GHSA-9jpm-269x-j69q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jpm-269x-j69q", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42439" + ], + "details": "Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42439" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json b/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json index f3e2241dbc0..ed4d57ed1a3 100644 --- a/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json +++ b/advisories/unreviewed/2024/08/GHSA-9m5w-7xhr-393x/GHSA-9m5w-7xhr-393x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m5w-7xhr-393x", - "modified": "2024-08-14T03:31:07Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2023-31348" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json b/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json new file mode 100644 index 00000000000..3b0cdf57efd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch97-hpq7-jfg9", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-5915" + ], + "details": "A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5915" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cp7r-3r6c-mj6f/GHSA-cp7r-3r6c-mj6f.json b/advisories/unreviewed/2024/08/GHSA-cp7r-3r6c-mj6f/GHSA-cp7r-3r6c-mj6f.json new file mode 100644 index 00000000000..d33efdc3038 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cp7r-3r6c-mj6f/GHSA-cp7r-3r6c-mj6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp7r-3r6c-mj6f", + "modified": "2024-08-14T18:32:41Z", + "published": "2024-08-14T18:32:41Z", + "aliases": [ + "CVE-2024-39818" + ], + "details": "Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39818" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cvjp-23hx-635r/GHSA-cvjp-23hx-635r.json b/advisories/unreviewed/2024/08/GHSA-cvjp-23hx-635r/GHSA-cvjp-23hx-635r.json new file mode 100644 index 00000000000..83729c8fff5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cvjp-23hx-635r/GHSA-cvjp-23hx-635r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvjp-23hx-635r", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-5916" + ], + "details": "An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5916" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-313" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f245-vq36-rx88/GHSA-f245-vq36-rx88.json b/advisories/unreviewed/2024/08/GHSA-f245-vq36-rx88/GHSA-f245-vq36-rx88.json new file mode 100644 index 00000000000..6f74d656c23 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f245-vq36-rx88/GHSA-f245-vq36-rx88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f245-vq36-rx88", + "modified": "2024-08-14T18:32:42Z", + "published": "2024-08-14T18:32:42Z", + "aliases": [ + "CVE-2024-39824" + ], + "details": "Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39824" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-frj6-38mm-gr73/GHSA-frj6-38mm-gr73.json b/advisories/unreviewed/2024/08/GHSA-frj6-38mm-gr73/GHSA-frj6-38mm-gr73.json new file mode 100644 index 00000000000..742157e7a4b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-frj6-38mm-gr73/GHSA-frj6-38mm-gr73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frj6-38mm-gr73", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42434" + ], + "details": "Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42434" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g536-h677-2w32/GHSA-g536-h677-2w32.json b/advisories/unreviewed/2024/08/GHSA-g536-h677-2w32/GHSA-g536-h677-2w32.json index 772a14a258d..b618c39a9b6 100644 --- a/advisories/unreviewed/2024/08/GHSA-g536-h677-2w32/GHSA-g536-h677-2w32.json +++ b/advisories/unreviewed/2024/08/GHSA-g536-h677-2w32/GHSA-g536-h677-2w32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g536-h677-2w32", - "modified": "2024-08-14T12:35:01Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-08-14T00:31:02Z", "aliases": [ "CVE-2024-28986" diff --git a/advisories/unreviewed/2024/08/GHSA-g788-m4v3-47c7/GHSA-g788-m4v3-47c7.json b/advisories/unreviewed/2024/08/GHSA-g788-m4v3-47c7/GHSA-g788-m4v3-47c7.json new file mode 100644 index 00000000000..b36a9c4bd6b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g788-m4v3-47c7/GHSA-g788-m4v3-47c7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g788-m4v3-47c7", + "modified": "2024-08-14T18:32:41Z", + "published": "2024-08-14T18:32:41Z", + "aliases": [ + "CVE-2023-50315" + ], + "details": "IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50315" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/274714" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165511" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json b/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json new file mode 100644 index 00000000000..579e9dcce61 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j78j-h8vv-5m5x", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-5914" + ], + "details": "A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5914" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-5914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j8ch-8f2h-7f8f/GHSA-j8ch-8f2h-7f8f.json b/advisories/unreviewed/2024/08/GHSA-j8ch-8f2h-7f8f/GHSA-j8ch-8f2h-7f8f.json index 3f077f48eb5..f70ea9cf53b 100644 --- a/advisories/unreviewed/2024/08/GHSA-j8ch-8f2h-7f8f/GHSA-j8ch-8f2h-7f8f.json +++ b/advisories/unreviewed/2024/08/GHSA-j8ch-8f2h-7f8f/GHSA-j8ch-8f2h-7f8f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8ch-8f2h-7f8f", - "modified": "2024-08-14T03:31:09Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-08-14T03:31:09Z", "aliases": [ "CVE-2024-20082" ], "details": "In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01182594; Issue ID: MSV-1529.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-14T03:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jjch-2577-r3c2/GHSA-jjch-2577-r3c2.json b/advisories/unreviewed/2024/08/GHSA-jjch-2577-r3c2/GHSA-jjch-2577-r3c2.json new file mode 100644 index 00000000000..c4f839c9b79 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jjch-2577-r3c2/GHSA-jjch-2577-r3c2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjch-2577-r3c2", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2023-50314" + ], + "details": "IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50314" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/274713" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165502" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mjf8-fqvw-qvr7/GHSA-mjf8-fqvw-qvr7.json b/advisories/unreviewed/2024/08/GHSA-mjf8-fqvw-qvr7/GHSA-mjf8-fqvw-qvr7.json new file mode 100644 index 00000000000..6e99479130d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mjf8-fqvw-qvr7/GHSA-mjf8-fqvw-qvr7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjf8-fqvw-qvr7", + "modified": "2024-08-14T18:32:42Z", + "published": "2024-08-14T18:32:42Z", + "aliases": [ + "CVE-2024-39823" + ], + "details": "Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39823" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json b/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json new file mode 100644 index 00000000000..7b3173e9237 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pwhp-4qxf-7ff6/GHSA-pwhp-4qxf-7ff6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwhp-4qxf-7ff6", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-31882" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287614.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31882" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/287614" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165338" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-943" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q7vq-23c3-qm7w/GHSA-q7vq-23c3-qm7w.json b/advisories/unreviewed/2024/08/GHSA-q7vq-23c3-qm7w/GHSA-q7vq-23c3-qm7w.json new file mode 100644 index 00000000000..004fcf232c3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q7vq-23c3-qm7w/GHSA-q7vq-23c3-qm7w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7vq-23c3-qm7w", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-35152" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 292639.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35152" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/292639" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qrw6-cmhg-g5p6/GHSA-qrw6-cmhg-g5p6.json b/advisories/unreviewed/2024/08/GHSA-qrw6-cmhg-g5p6/GHSA-qrw6-cmhg-g5p6.json new file mode 100644 index 00000000000..6c06a683dce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qrw6-cmhg-g5p6/GHSA-qrw6-cmhg-g5p6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrw6-cmhg-g5p6", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-35136" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 291307.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35136" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/291307" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165341" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-943" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json b/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json index b156140f624..9daf8113cb5 100644 --- a/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json +++ b/advisories/unreviewed/2024/08/GHSA-r979-6ffq-pvxw/GHSA-r979-6ffq-pvxw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-78" + "CWE-78", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json b/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json index a9c3d8bc96a..69883a2be1d 100644 --- a/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json +++ b/advisories/unreviewed/2024/08/GHSA-wrqr-6727-v5vq/GHSA-wrqr-6727-v5vq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrqr-6727-v5vq", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-14T18:32:37Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-41614" ], "details": "symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T17:15:24Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x6mm-hvfx-gxp7/GHSA-x6mm-hvfx-gxp7.json b/advisories/unreviewed/2024/08/GHSA-x6mm-hvfx-gxp7/GHSA-x6mm-hvfx-gxp7.json new file mode 100644 index 00000000000..c63353727dc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6mm-hvfx-gxp7/GHSA-x6mm-hvfx-gxp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6mm-hvfx-gxp7", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42441" + ], + "details": "Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42441" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xr43-cwp6-p6wf/GHSA-xr43-cwp6-p6wf.json b/advisories/unreviewed/2024/08/GHSA-xr43-cwp6-p6wf/GHSA-xr43-cwp6-p6wf.json new file mode 100644 index 00000000000..0b4e41527a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xr43-cwp6-p6wf/GHSA-xr43-cwp6-p6wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr43-cwp6-p6wf", + "modified": "2024-08-14T18:32:43Z", + "published": "2024-08-14T18:32:43Z", + "aliases": [ + "CVE-2024-42435" + ], + "details": "Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42435" + }, + { + "type": "WEB", + "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-24030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T17:15:16Z" + } +} \ No newline at end of file