diff --git a/advisories/unreviewed/2022/05/GHSA-4vmw-hgp9-m43m/GHSA-4vmw-hgp9-m43m.json b/advisories/unreviewed/2022/05/GHSA-4vmw-hgp9-m43m/GHSA-4vmw-hgp9-m43m.json index 005a681f2c5..a7f622ef31d 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vmw-hgp9-m43m/GHSA-4vmw-hgp9-m43m.json +++ b/advisories/unreviewed/2022/05/GHSA-4vmw-hgp9-m43m/GHSA-4vmw-hgp9-m43m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4vmw-hgp9-m43m", - "modified": "2022-05-24T22:28:13Z", + "modified": "2024-10-03T18:30:34Z", "published": "2022-05-24T22:28:13Z", "aliases": [ "CVE-2021-24261" ], "details": "The “HT Mega – Absolute Addons for Elementor Page Builder� WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/07/GHSA-f3mv-w3v5-88qp/GHSA-f3mv-w3v5-88qp.json b/advisories/unreviewed/2022/07/GHSA-f3mv-w3v5-88qp/GHSA-f3mv-w3v5-88qp.json index e6de4978b76..04493ceba63 100644 --- a/advisories/unreviewed/2022/07/GHSA-f3mv-w3v5-88qp/GHSA-f3mv-w3v5-88qp.json +++ b/advisories/unreviewed/2022/07/GHSA-f3mv-w3v5-88qp/GHSA-f3mv-w3v5-88qp.json @@ -56,6 +56,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-180", "CWE-287" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/07/GHSA-fpj5-pcgc-34g7/GHSA-fpj5-pcgc-34g7.json b/advisories/unreviewed/2022/07/GHSA-fpj5-pcgc-34g7/GHSA-fpj5-pcgc-34g7.json index ec27694226e..64ddfda776c 100644 --- a/advisories/unreviewed/2022/07/GHSA-fpj5-pcgc-34g7/GHSA-fpj5-pcgc-34g7.json +++ b/advisories/unreviewed/2022/07/GHSA-fpj5-pcgc-34g7/GHSA-fpj5-pcgc-34g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fpj5-pcgc-34g7", - "modified": "2022-08-05T00:00:29Z", + "modified": "2024-10-03T18:30:34Z", "published": "2022-07-21T00:00:27Z", "aliases": [ "CVE-2022-26137" @@ -56,6 +56,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-180", "CWE-346" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-3wf8-8777-h28j/GHSA-3wf8-8777-h28j.json b/advisories/unreviewed/2023/08/GHSA-3wf8-8777-h28j/GHSA-3wf8-8777-h28j.json index 3c4ddd25e95..b1f5a014029 100644 --- a/advisories/unreviewed/2023/08/GHSA-3wf8-8777-h28j/GHSA-3wf8-8777-h28j.json +++ b/advisories/unreviewed/2023/08/GHSA-3wf8-8777-h28j/GHSA-3wf8-8777-h28j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-cqv8-rcm7-jhxx/GHSA-cqv8-rcm7-jhxx.json b/advisories/unreviewed/2023/08/GHSA-cqv8-rcm7-jhxx/GHSA-cqv8-rcm7-jhxx.json index 5bad143f474..de33dbdf654 100644 --- a/advisories/unreviewed/2023/08/GHSA-cqv8-rcm7-jhxx/GHSA-cqv8-rcm7-jhxx.json +++ b/advisories/unreviewed/2023/08/GHSA-cqv8-rcm7-jhxx/GHSA-cqv8-rcm7-jhxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqv8-rcm7-jhxx", - "modified": "2024-04-04T07:08:54Z", + "modified": "2024-10-03T18:30:35Z", "published": "2023-08-22T21:30:27Z", "aliases": [ "CVE-2023-37427" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-hcj5-gphh-wmp6/GHSA-hcj5-gphh-wmp6.json b/advisories/unreviewed/2023/08/GHSA-hcj5-gphh-wmp6/GHSA-hcj5-gphh-wmp6.json index b297b5004af..7aa9558de02 100644 --- a/advisories/unreviewed/2023/08/GHSA-hcj5-gphh-wmp6/GHSA-hcj5-gphh-wmp6.json +++ b/advisories/unreviewed/2023/08/GHSA-hcj5-gphh-wmp6/GHSA-hcj5-gphh-wmp6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-j536-gfc6-fg37/GHSA-j536-gfc6-fg37.json b/advisories/unreviewed/2023/08/GHSA-j536-gfc6-fg37/GHSA-j536-gfc6-fg37.json index 2935fd86107..2893b13e253 100644 --- a/advisories/unreviewed/2023/08/GHSA-j536-gfc6-fg37/GHSA-j536-gfc6-fg37.json +++ b/advisories/unreviewed/2023/08/GHSA-j536-gfc6-fg37/GHSA-j536-gfc6-fg37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j536-gfc6-fg37", - "modified": "2024-04-04T07:08:48Z", + "modified": "2024-10-03T18:30:34Z", "published": "2023-08-22T21:30:27Z", "aliases": [ "CVE-2023-37424" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-8q8c-8w2c-527x/GHSA-8q8c-8w2c-527x.json b/advisories/unreviewed/2024/02/GHSA-8q8c-8w2c-527x/GHSA-8q8c-8w2c-527x.json index 87a4ab4088c..47c4a29f133 100644 --- a/advisories/unreviewed/2024/02/GHSA-8q8c-8w2c-527x/GHSA-8q8c-8w2c-527x.json +++ b/advisories/unreviewed/2024/02/GHSA-8q8c-8w2c-527x/GHSA-8q8c-8w2c-527x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-2g2h-672j-8vfh/GHSA-2g2h-672j-8vfh.json b/advisories/unreviewed/2024/06/GHSA-2g2h-672j-8vfh/GHSA-2g2h-672j-8vfh.json index 1e45548c669..21eb75f1847 100644 --- a/advisories/unreviewed/2024/06/GHSA-2g2h-672j-8vfh/GHSA-2g2h-672j-8vfh.json +++ b/advisories/unreviewed/2024/06/GHSA-2g2h-672j-8vfh/GHSA-2g2h-672j-8vfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g2h-672j-8vfh", - "modified": "2024-06-13T18:31:59Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-06-13T18:31:59Z", "aliases": [ "CVE-2024-37029" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-6mw6-j92w-4h63/GHSA-6mw6-j92w-4h63.json b/advisories/unreviewed/2024/06/GHSA-6mw6-j92w-4h63/GHSA-6mw6-j92w-4h63.json index e6ee732ec34..6e0c932e570 100644 --- a/advisories/unreviewed/2024/06/GHSA-6mw6-j92w-4h63/GHSA-6mw6-j92w-4h63.json +++ b/advisories/unreviewed/2024/06/GHSA-6mw6-j92w-4h63/GHSA-6mw6-j92w-4h63.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-6mw6-j92w-4h63", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-38281" ], "details": "An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T17:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f8mv-jphx-3r7g/GHSA-f8mv-jphx-3r7g.json b/advisories/unreviewed/2024/06/GHSA-f8mv-jphx-3r7g/GHSA-f8mv-jphx-3r7g.json index c029040849f..15c27d107fa 100644 --- a/advisories/unreviewed/2024/06/GHSA-f8mv-jphx-3r7g/GHSA-f8mv-jphx-3r7g.json +++ b/advisories/unreviewed/2024/06/GHSA-f8mv-jphx-3r7g/GHSA-f8mv-jphx-3r7g.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-qcm6-ww7j-hm8x/GHSA-qcm6-ww7j-hm8x.json b/advisories/unreviewed/2024/06/GHSA-qcm6-ww7j-hm8x/GHSA-qcm6-ww7j-hm8x.json index c56ae3321ca..c77f092d089 100644 --- a/advisories/unreviewed/2024/06/GHSA-qcm6-ww7j-hm8x/GHSA-qcm6-ww7j-hm8x.json +++ b/advisories/unreviewed/2024/06/GHSA-qcm6-ww7j-hm8x/GHSA-qcm6-ww7j-hm8x.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-qcm6-ww7j-hm8x", - "modified": "2024-06-13T18:31:58Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-06-13T18:31:58Z", "aliases": [ "CVE-2024-38279" ], "details": "The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -25,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T17:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vh8w-5wph-86hm/GHSA-vh8w-5wph-86hm.json b/advisories/unreviewed/2024/06/GHSA-vh8w-5wph-86hm/GHSA-vh8w-5wph-86hm.json index c2e079a146f..1ceef879818 100644 --- a/advisories/unreviewed/2024/06/GHSA-vh8w-5wph-86hm/GHSA-vh8w-5wph-86hm.json +++ b/advisories/unreviewed/2024/06/GHSA-vh8w-5wph-86hm/GHSA-vh8w-5wph-86hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vh8w-5wph-86hm", - "modified": "2024-06-13T18:31:59Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-06-13T18:31:59Z", "aliases": [ "CVE-2024-37022" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-wm2w-xpgv-w6v4/GHSA-wm2w-xpgv-w6v4.json b/advisories/unreviewed/2024/06/GHSA-wm2w-xpgv-w6v4/GHSA-wm2w-xpgv-w6v4.json index 58aa7aa31cd..b77e0dc13f8 100644 --- a/advisories/unreviewed/2024/06/GHSA-wm2w-xpgv-w6v4/GHSA-wm2w-xpgv-w6v4.json +++ b/advisories/unreviewed/2024/06/GHSA-wm2w-xpgv-w6v4/GHSA-wm2w-xpgv-w6v4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json b/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json index 7f214e9e717..634b825b7f1 100644 --- a/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json +++ b/advisories/unreviewed/2024/09/GHSA-285g-gc96-4xjh/GHSA-285g-gc96-4xjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-285g-gc96-4xjh", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44968" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntick/broadcast: Move per CPU pointer access into the atomic section\n\nThe recent fix for making the take over of the broadcast timer more\nreliable retrieves a per CPU pointer in preemptible context.\n\nThis went unnoticed as compilers hoist the access into the non-preemptible\nregion where the pointer is actually used. But of course it's valid that\nthe compiler keeps it at the place where the code puts it which rightfully\ntriggers:\n\n BUG: using smp_processor_id() in preemptible [00000000] code:\n caller is hotplug_cpu__broadcast_tick_pull+0x1c/0xc0\n\nMove it to the actual usage site which is in a non-preemptible region.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json b/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json index 41904ef84d0..af82d38d983 100644 --- a/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json +++ b/advisories/unreviewed/2024/09/GHSA-2hcr-rj2w-r9vj/GHSA-2hcr-rj2w-r9vj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hcr-rj2w-r9vj", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44967" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mgag200: Bind I2C lifetime to DRM device\n\nManaged cleanup with devm_add_action_or_reset() will release the I2C\nadapter when the underlying Linux device goes away. But the connector\nstill refers to it, so this cleanup leaves behind a stale pointer\nin struct drm_connector.ddc.\n\nBind the lifetime of the I2C adapter to the connector's lifetime by\nusing DRM's managed release. When the DRM device goes away (after\nthe Linux device) DRM will first clean up the connector and then\nclean up the I2C adapter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json b/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json index 6e514feeea2..71d0b64494f 100644 --- a/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json +++ b/advisories/unreviewed/2024/09/GHSA-4w3q-gj3x-9575/GHSA-4w3q-gj3x-9575.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4w3q-gj3x-9575", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/sclp: Prevent release of buffer in I/O\n\nWhen a task waiting for completion of a Store Data operation is\ninterrupted, an attempt is made to halt this operation. If this attempt\nfails due to a hardware or firmware problem, there is a chance that the\nSCLP facility might store data into buffers referenced by the original\noperation at a later time.\n\nHandle this situation by not releasing the referenced data buffers if\nthe halt attempt fails. For current use cases, this might result in a\nleak of few pages of memory in case of a rare hardware/firmware\nmalfunction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json b/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json index 6e7efc0eb03..1bbd4f74ace 100644 --- a/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json +++ b/advisories/unreviewed/2024/09/GHSA-5rqg-4vpc-fpm2/GHSA-5rqg-4vpc-fpm2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rqg-4vpc-fpm2", - "modified": "2024-09-27T18:32:27Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-27T18:32:27Z", "aliases": [ "CVE-2024-46257" ], "details": "A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c7j9-vm5x-xj32/GHSA-c7j9-vm5x-xj32.json b/advisories/unreviewed/2024/09/GHSA-c7j9-vm5x-xj32/GHSA-c7j9-vm5x-xj32.json index 790fc15002b..4d39d1d7e46 100644 --- a/advisories/unreviewed/2024/09/GHSA-c7j9-vm5x-xj32/GHSA-c7j9-vm5x-xj32.json +++ b/advisories/unreviewed/2024/09/GHSA-c7j9-vm5x-xj32/GHSA-c7j9-vm5x-xj32.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json b/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json index 0463775b386..54f0f335e56 100644 --- a/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json +++ b/advisories/unreviewed/2024/09/GHSA-f3vh-8mjp-cx6c/GHSA-f3vh-8mjp-cx6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3vh-8mjp-cx6c", - "modified": "2024-09-04T21:30:32Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-04T21:30:32Z", "aliases": [ "CVE-2024-44972" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not clear page dirty inside extent_write_locked_range()\n\n[BUG]\nFor subpage + zoned case, the following workload can lead to rsv data\nleak at unmount time:\n\n # mkfs.btrfs -f -s 4k $dev\n # mount $dev $mnt\n # fsstress -w -n 8 -d $mnt -s 1709539240\n 0/0: fiemap - no filename\n 0/1: copyrange read - no filename\n 0/2: write - no filename\n 0/3: rename - no source filename\n 0/4: creat f0 x:0 0 0\n 0/4: creat add id=0,parent=-1\n 0/5: writev f0[259 1 0 0 0 0] [778052,113,965] 0\n 0/6: ioctl(FIEMAP) f0[259 1 0 0 224 887097] [1294220,2291618343991484791,0x10000] -1\n 0/7: dwrite - xfsctl(XFS_IOC_DIOINFO) f0[259 1 0 0 224 887097] return 25, fallback to stat()\n 0/7: dwrite f0[259 1 0 0 224 887097] [696320,102400] 0\n # umount $mnt\n\nThe dmesg includes the following rsv leak detection warning (all call\ntrace skipped):\n\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8653 btrfs_destroy_inode+0x1e0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8654 btrfs_destroy_inode+0x1a8/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 4528 at fs/btrfs/inode.c:8660 btrfs_destroy_inode+0x1a0/0x200 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): last unmount of filesystem 1b4abba9-de34-4f07-9e7f-157cf12a18d6\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info DATA has 268218368 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=204800, pinned=0, reserved=0, may_use=12288, readonly=0 zone_unusable=0\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n ------------[ cut here ]------------\n WARNING: CPU: 3 PID: 4528 at fs/btrfs/block-group.c:4434 btrfs_free_block_groups+0x338/0x500 [btrfs]\n ---[ end trace 0000000000000000 ]---\n BTRFS info (device sda): space_info METADATA has 267796480 free, is not full\n BTRFS info (device sda): space_info total=268435456, used=131072, pinned=0, reserved=0, may_use=262144, readonly=0 zone_unusable=245760\n BTRFS info (device sda): global_block_rsv: size 0 reserved 0\n BTRFS info (device sda): trans_block_rsv: size 0 reserved 0\n BTRFS info (device sda): chunk_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_block_rsv: size 0 reserved 0\n BTRFS info (device sda): delayed_refs_rsv: size 0 reserved 0\n\nAbove $dev is a tcmu-runner emulated zoned HDD, which has a max zone\nappend size of 64K, and the system has 64K page size.\n\n[CAUSE]\nI have added several trace_printk() to show the events (header skipped):\n\n > btrfs_dirty_pages: r/i=5/259 dirty start=774144 len=114688\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=720896 off_in_page=53248 len_in_page=12288\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=786432 off_in_page=0 len_in_page=65536\n > btrfs_dirty_pages: r/i=5/259 dirty part of page=851968 off_in_page=0 len_in_page=36864\n\nThe above lines show our buffered write has dirtied 3 pages of inode\n259 of root 5:\n\n 704K 768K 832K 896K\n I |////I/////////////////I///////////| I\n 756K 868K\n\n |///| is the dirtied range using subpage bitmaps. and 'I' is the page\n boundary.\n\n Meanwhile all three pages (704K, 768K, 832K) have their PageDirty\n flag set.\n\n > btrfs_direct_write: r/i=5/259 start dio filepos=696320 len=102400\n\nThen direct IO writ\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T19:15:31Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jh62-xx57-p239/GHSA-jh62-xx57-p239.json b/advisories/unreviewed/2024/09/GHSA-jh62-xx57-p239/GHSA-jh62-xx57-p239.json index 937e8e6c9fc..1cf4965adea 100644 --- a/advisories/unreviewed/2024/09/GHSA-jh62-xx57-p239/GHSA-jh62-xx57-p239.json +++ b/advisories/unreviewed/2024/09/GHSA-jh62-xx57-p239/GHSA-jh62-xx57-p239.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-m95h-4hjq-w7wv/GHSA-m95h-4hjq-w7wv.json b/advisories/unreviewed/2024/09/GHSA-m95h-4hjq-w7wv/GHSA-m95h-4hjq-w7wv.json index b6570a58095..1defff661dc 100644 --- a/advisories/unreviewed/2024/09/GHSA-m95h-4hjq-w7wv/GHSA-m95h-4hjq-w7wv.json +++ b/advisories/unreviewed/2024/09/GHSA-m95h-4hjq-w7wv/GHSA-m95h-4hjq-w7wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m95h-4hjq-w7wv", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46862" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item\n\nThere is no links_num in struct snd_soc_acpi_mach {}, and we test\n!link->num_adr as a condition to end the loop in hda_sdw_machine_select().\nSo an empty item in struct snd_soc_acpi_link_adr array is required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-mhrv-mcvx-mvx7/GHSA-mhrv-mcvx-mvx7.json b/advisories/unreviewed/2024/09/GHSA-mhrv-mcvx-mvx7/GHSA-mhrv-mcvx-mvx7.json index 5fedb79aa0c..83361621d58 100644 --- a/advisories/unreviewed/2024/09/GHSA-mhrv-mcvx-mvx7/GHSA-mhrv-mcvx-mvx7.json +++ b/advisories/unreviewed/2024/09/GHSA-mhrv-mcvx-mvx7/GHSA-mhrv-mcvx-mvx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhrv-mcvx-mvx7", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46861" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: ipheth: do not stop RX on failing RX callback\n\nRX callbacks can fail for multiple reasons:\n\n* Payload too short\n* Payload formatted incorrecly (e.g. bad NCM framing)\n* Lack of memory\n\nNone of these should cause the driver to seize up.\n\nMake such failures non-critical and continue processing further\nincoming URBs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json b/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json index 11f87e9e657..f24b330f44c 100644 --- a/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json +++ b/advisories/unreviewed/2024/09/GHSA-pwxr-xm9v-qfvh/GHSA-pwxr-xm9v-qfvh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-qc45-54hc-mx8p/GHSA-qc45-54hc-mx8p.json b/advisories/unreviewed/2024/09/GHSA-qc45-54hc-mx8p/GHSA-qc45-54hc-mx8p.json index f0746d3d785..4fe26ed4842 100644 --- a/advisories/unreviewed/2024/09/GHSA-qc45-54hc-mx8p/GHSA-qc45-54hc-mx8p.json +++ b/advisories/unreviewed/2024/09/GHSA-qc45-54hc-mx8p/GHSA-qc45-54hc-mx8p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json b/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json index 9d202561202..840bd2eb695 100644 --- a/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json +++ b/advisories/unreviewed/2024/09/GHSA-r56c-c546-6wvj/GHSA-r56c-c546-6wvj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r56c-c546-6wvj", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46859" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: panasonic-laptop: Fix SINF array out of bounds accesses\n\nThe panasonic laptop code in various places uses the SINF array with index\nvalues of 0 - SINF_CUR_BRIGHT(0x0d) without checking that the SINF array\nis big enough.\n\nNot all panasonic laptops have this many SINF array entries, for example\nthe Toughbook CF-18 model only has 10 SINF array entries. So it only\nsupports the AC+DC brightness entries and mute.\n\nCheck that the SINF array has a minimum size which covers all AC+DC\nbrightness entries and refuse to load if the SINF array is smaller.\n\nFor higher SINF indexes hide the sysfs attributes when the SINF array\ndoes not contain an entry for that attribute, avoiding show()/store()\naccessing the array out of bounds and add bounds checking to the probe()\nand resume() code accessing these.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rm8v-5w66-jm6j/GHSA-rm8v-5w66-jm6j.json b/advisories/unreviewed/2024/09/GHSA-rm8v-5w66-jm6j/GHSA-rm8v-5w66-jm6j.json index 5a215262155..d511b2062ae 100644 --- a/advisories/unreviewed/2024/09/GHSA-rm8v-5w66-jm6j/GHSA-rm8v-5w66-jm6j.json +++ b/advisories/unreviewed/2024/09/GHSA-rm8v-5w66-jm6j/GHSA-rm8v-5w66-jm6j.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x4v7-2qvr-vh9c/GHSA-x4v7-2qvr-vh9c.json b/advisories/unreviewed/2024/09/GHSA-x4v7-2qvr-vh9c/GHSA-x4v7-2qvr-vh9c.json index 5f313f9445c..289e87addcb 100644 --- a/advisories/unreviewed/2024/09/GHSA-x4v7-2qvr-vh9c/GHSA-x4v7-2qvr-vh9c.json +++ b/advisories/unreviewed/2024/09/GHSA-x4v7-2qvr-vh9c/GHSA-x4v7-2qvr-vh9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4v7-2qvr-vh9c", - "modified": "2024-09-27T15:30:34Z", + "modified": "2024-10-03T18:30:35Z", "published": "2024-09-27T15:30:34Z", "aliases": [ "CVE-2024-46863" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item\n\nThere is no links_num in struct snd_soc_acpi_mach {}, and we test\n!link->num_adr as a condition to end the loop in hda_sdw_machine_select().\nSo an empty item in struct snd_soc_acpi_link_adr array is required.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-x63p-f88f-gg9j/GHSA-x63p-f88f-gg9j.json b/advisories/unreviewed/2024/09/GHSA-x63p-f88f-gg9j/GHSA-x63p-f88f-gg9j.json index fd3999f884f..4de43d447d7 100644 --- a/advisories/unreviewed/2024/09/GHSA-x63p-f88f-gg9j/GHSA-x63p-f88f-gg9j.json +++ b/advisories/unreviewed/2024/09/GHSA-x63p-f88f-gg9j/GHSA-x63p-f88f-gg9j.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2f42-mj3m-xhvx/GHSA-2f42-mj3m-xhvx.json b/advisories/unreviewed/2024/10/GHSA-2f42-mj3m-xhvx/GHSA-2f42-mj3m-xhvx.json new file mode 100644 index 00000000000..0ac2abe93a5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2f42-mj3m-xhvx/GHSA-2f42-mj3m-xhvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f42-mj3m-xhvx", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-0124" + ], + "details": "NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0124" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5577" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2jm4-m62p-325r/GHSA-2jm4-m62p-325r.json b/advisories/unreviewed/2024/10/GHSA-2jm4-m62p-325r/GHSA-2jm4-m62p-325r.json new file mode 100644 index 00000000000..b4c62e3a9c4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2jm4-m62p-325r/GHSA-2jm4-m62p-325r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jm4-m62p-325r", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-39755" + ], + "details": "A privilege escalation vulnerability exists in the Veertu Anka Build 1.42.0. The vulnerability occurs during Anka node agent update. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39755" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json b/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json new file mode 100644 index 00000000000..ddda3a2f514 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-46m2-r42j-gr4p/GHSA-46m2-r42j-gr4p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46m2-r42j-gr4p", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-45870" + ], + "details": "Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45870" + }, + { + "type": "WEB", + "url": "https://github.com/Jaecho6053/BandiView_PoC" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5pmr-hjgq-832v/GHSA-5pmr-hjgq-832v.json b/advisories/unreviewed/2024/10/GHSA-5pmr-hjgq-832v/GHSA-5pmr-hjgq-832v.json new file mode 100644 index 00000000000..9aeeda28016 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5pmr-hjgq-832v/GHSA-5pmr-hjgq-832v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pmr-hjgq-832v", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-42415" + ], + "details": "An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42415" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libgsf/-/issues/34" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6jf3-p3mx-v587/GHSA-6jf3-p3mx-v587.json b/advisories/unreviewed/2024/10/GHSA-6jf3-p3mx-v587/GHSA-6jf3-p3mx-v587.json new file mode 100644 index 00000000000..17ccb894c56 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6jf3-p3mx-v587/GHSA-6jf3-p3mx-v587.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jf3-p3mx-v587", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-0125" + ], + "details": "NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0125" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5577" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-75x6-3558-67mc/GHSA-75x6-3558-67mc.json b/advisories/unreviewed/2024/10/GHSA-75x6-3558-67mc/GHSA-75x6-3558-67mc.json new file mode 100644 index 00000000000..21f6ba10631 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-75x6-3558-67mc/GHSA-75x6-3558-67mc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75x6-3558-67mc", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-41987" + ], + "details": "The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41987" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-277-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7m28-hv5x-hp65/GHSA-7m28-hv5x-hp65.json b/advisories/unreviewed/2024/10/GHSA-7m28-hv5x-hp65/GHSA-7m28-hv5x-hp65.json new file mode 100644 index 00000000000..c1f5ab3efb5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7m28-hv5x-hp65/GHSA-7m28-hv5x-hp65.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m28-hv5x-hp65", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-36474" + ], + "details": "An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36474" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libgsf/-/issues/34" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json b/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json new file mode 100644 index 00000000000..0aa4a549da5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8m9g-c3mm-hr68/GHSA-8m9g-c3mm-hr68.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m9g-c3mm-hr68", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-7825" + ], + "details": "Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7825" + }, + { + "type": "WEB", + "url": "https://answers.webroot.com/Webroot/ukp.aspx?pid=12&app=vw&vw=1&login=1&json=1&solutionid=4275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json b/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json new file mode 100644 index 00000000000..3758467ffe2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8mx7-3ccx-q5cq/GHSA-8mx7-3ccx-q5cq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mx7-3ccx-q5cq", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-45871" + ], + "details": "Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45871" + }, + { + "type": "WEB", + "url": "https://github.com/Jaecho6053/BandiView_PoC" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c6mx-ff55-jhcw/GHSA-c6mx-ff55-jhcw.json b/advisories/unreviewed/2024/10/GHSA-c6mx-ff55-jhcw/GHSA-c6mx-ff55-jhcw.json new file mode 100644 index 00000000000..73f6eba4ab2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c6mx-ff55-jhcw/GHSA-c6mx-ff55-jhcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6mx-ff55-jhcw", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-41988" + ], + "details": "TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTTP2 web server module but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41988" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-277-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json b/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json new file mode 100644 index 00000000000..b90a29fcb7f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cr9c-949p-jxvr/GHSA-cr9c-949p-jxvr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr9c-949p-jxvr", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2023-37822" + ], + "details": "Eufy HomeBase 2 model T8010X v3.2.8.3h was discovered to use the deprecated wireless protocol WPA2-PSK.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37822" + }, + { + "type": "WEB", + "url": "https://www.usenix.org/conference/woot24/presentation/goeman" + }, + { + "type": "WEB", + "url": "http://anker.com" + }, + { + "type": "WEB", + "url": "http://eufy.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json b/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json new file mode 100644 index 00000000000..f20e01bcf5d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f9c2-396j-6x9r/GHSA-f9c2-396j-6x9r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9c2-396j-6x9r", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-34535" + ], + "details": "In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/mastodon/mastodon/security/advisories/GHSA-q3rg-xx5v-4mxh" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34535" + }, + { + "type": "WEB", + "url": "https://github.com/mastodon/mastodon/tags" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ff23-px5j-g8qq/GHSA-ff23-px5j-g8qq.json b/advisories/unreviewed/2024/10/GHSA-ff23-px5j-g8qq/GHSA-ff23-px5j-g8qq.json new file mode 100644 index 00000000000..384d9cecb3b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ff23-px5j-g8qq/GHSA-ff23-px5j-g8qq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff23-px5j-g8qq", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-0123" + ], + "details": "NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0123" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5577" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1285" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json b/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json new file mode 100644 index 00000000000..658d36847bc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g5vx-c2fq-6jm8/GHSA-g5vx-c2fq-6jm8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5vx-c2fq-6jm8", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-7826" + ], + "details": "Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7826" + }, + { + "type": "WEB", + "url": "https://answers.webroot.com/Webroot/ukp.aspx?pid=12&app=vw&vw=1&login=1&json=1&solutionid=4275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json b/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json new file mode 100644 index 00000000000..b419c539153 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g7cv-x9wx-38gx/GHSA-g7cv-x9wx-38gx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7cv-x9wx-38gx", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-8508" + ], + "details": "NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. The vulnerability can be exploited by a malicious actor querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations it is willing to do per packet. Packets that need more compression will result in semi-compressed packets or truncated packets, even on TCP for huge messages, to avoid locking the CPU for long. This change should not affect normal DNS traffic.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8508" + }, + { + "type": "WEB", + "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-606" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j24x-x8jj-mv7g/GHSA-j24x-x8jj-mv7g.json b/advisories/unreviewed/2024/10/GHSA-j24x-x8jj-mv7g/GHSA-j24x-x8jj-mv7g.json new file mode 100644 index 00000000000..1ce6acc2a49 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j24x-x8jj-mv7g/GHSA-j24x-x8jj-mv7g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j24x-x8jj-mv7g", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-41163" + ], + "details": "A directory traversal vulnerability exists in the archive download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of arbitrary files. An attacker can make an unauthenticated HTTP request to exploit this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41163" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2059" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json b/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json index abbb17a1df4..04fffcc8bfd 100644 --- a/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json +++ b/advisories/unreviewed/2024/10/GHSA-jq66-g5qg-w7wf/GHSA-jq66-g5qg-w7wf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jq66-g5qg-w7wf", - "modified": "2024-10-01T21:31:34Z", + "modified": "2024-10-03T18:30:36Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-42514" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42514" }, + { + "type": "WEB", + "url": "https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0024-001-v2.pdf" + }, { "type": "WEB", "url": "https://www.mitel.com/support/security-advisories" diff --git a/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json b/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json new file mode 100644 index 00000000000..12e04f7d89e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p4hq-9rw5-2cwc/GHSA-p4hq-9rw5-2cwc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4hq-9rw5-2cwc", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-45872" + ], + "details": "Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45872" + }, + { + "type": "WEB", + "url": "https://github.com/Jaecho6053/BandiView_PoC" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pq4p-r5xh-r7fm/GHSA-pq4p-r5xh-r7fm.json b/advisories/unreviewed/2024/10/GHSA-pq4p-r5xh-r7fm/GHSA-pq4p-r5xh-r7fm.json new file mode 100644 index 00000000000..5890469abf7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pq4p-r5xh-r7fm/GHSA-pq4p-r5xh-r7fm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq4p-r5xh-r7fm", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-41922" + ], + "details": "A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can result in a disclosure of arbitrary files. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41922" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pvmx-j29h-323g/GHSA-pvmx-j29h-323g.json b/advisories/unreviewed/2024/10/GHSA-pvmx-j29h-323g/GHSA-pvmx-j29h-323g.json new file mode 100644 index 00000000000..a53e19885a1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pvmx-j29h-323g/GHSA-pvmx-j29h-323g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvmx-j29h-323g", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-25590" + ], + "details": "An attacker can publish a zone containing specific Resource Record Sets.\n\n Repeatedly processing and caching results for these sets can lead to a \n\ndenial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25590" + }, + { + "type": "WEB", + "url": "https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-04.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v876-7vq8-2gf7/GHSA-v876-7vq8-2gf7.json b/advisories/unreviewed/2024/10/GHSA-v876-7vq8-2gf7/GHSA-v876-7vq8-2gf7.json index 0ba4761fbe1..61cfdd5e5e7 100644 --- a/advisories/unreviewed/2024/10/GHSA-v876-7vq8-2gf7/GHSA-v876-7vq8-2gf7.json +++ b/advisories/unreviewed/2024/10/GHSA-v876-7vq8-2gf7/GHSA-v876-7vq8-2gf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v876-7vq8-2gf7", - "modified": "2024-10-02T21:30:37Z", + "modified": "2024-10-03T18:30:36Z", "published": "2024-10-02T21:30:37Z", "aliases": [ "CVE-2024-28888" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1967" + }, + { + "type": "WEB", + "url": "https://www.foxit.com/support/security-bulletins.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json b/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json new file mode 100644 index 00000000000..51f2fb5bc24 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vmg4-jx97-rmvv/GHSA-vmg4-jx97-rmvv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmg4-jx97-rmvv", + "modified": "2024-10-03T18:30:36Z", + "published": "2024-10-03T18:30:36Z", + "aliases": [ + "CVE-2024-7824" + ], + "details": "Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7824" + }, + { + "type": "WEB", + "url": "https://answers.webroot.com/Webroot/ukp.aspx?pid=12&app=vw&vw=1&login=1&json=1&solutionid=4275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T17:15:14Z" + } +} \ No newline at end of file