Publish Advisories

GHSA-8q4v-68hv-v55c
GHSA-7mqh-9jjg-r8c8
GHSA-f2jm-rw3h-6phg
GHSA-hh55-xqjj-vxv4
GHSA-jf5x-p6mg-vvp7
This commit is contained in:
advisory-database[bot]
2024-09-17 12:32:05 +00:00
parent f68ad3ed64
commit fa88f75b69
5 changed files with 69 additions and 15 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q4v-68hv-v55c",
"modified": "2024-08-31T09:30:43Z",
"modified": "2024-09-17T12:30:32Z",
"published": "2024-08-31T09:30:43Z",
"aliases": [
"CVE-2024-44945"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink: Initialise extack before use in ACKs\n\nAdd missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-31T07:15:03Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mqh-9jjg-r8c8",
"modified": "2024-09-16T14:37:28Z",
"modified": "2024-09-17T12:30:32Z",
"published": "2024-09-16T14:37:28Z",
"aliases": [
"CVE-2024-46451"
],
"details": "TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T13:15:10Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2jm-rw3h-6phg",
"modified": "2024-09-17T12:30:32Z",
"published": "2024-09-17T12:30:32Z",
"aliases": [
"CVE-2024-5998"
],
"details": "A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998"
},
{
"type": "WEB",
"url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-17T12:15:02Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hh55-xqjj-vxv4",
"modified": "2024-09-16T14:37:28Z",
"modified": "2024-09-17T12:30:32Z",
"published": "2024-09-16T14:37:28Z",
"aliases": [
"CVE-2024-46424"
],
"details": "TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T13:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf5x-p6mg-vvp7",
"modified": "2024-09-16T14:37:29Z",
"modified": "2024-09-17T12:30:32Z",
"published": "2024-09-16T14:37:28Z",
"aliases": [
"CVE-2024-46419"
],
"details": "TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T14:15:13Z"