diff --git a/advisories/unreviewed/2024/08/GHSA-8q4v-68hv-v55c/GHSA-8q4v-68hv-v55c.json b/advisories/unreviewed/2024/08/GHSA-8q4v-68hv-v55c/GHSA-8q4v-68hv-v55c.json index 180b38704d0..1bbc0ae56cf 100644 --- a/advisories/unreviewed/2024/08/GHSA-8q4v-68hv-v55c/GHSA-8q4v-68hv-v55c.json +++ b/advisories/unreviewed/2024/08/GHSA-8q4v-68hv-v55c/GHSA-8q4v-68hv-v55c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8q4v-68hv-v55c", - "modified": "2024-08-31T09:30:43Z", + "modified": "2024-09-17T12:30:32Z", "published": "2024-08-31T09:30:43Z", "aliases": [ "CVE-2024-44945" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink: Initialise extack before use in ACKs\n\nAdd missing extack initialisation when ACKing BATCH_BEGIN and BATCH_END.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-31T07:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7mqh-9jjg-r8c8/GHSA-7mqh-9jjg-r8c8.json b/advisories/unreviewed/2024/09/GHSA-7mqh-9jjg-r8c8/GHSA-7mqh-9jjg-r8c8.json index a6e7630b7f9..7a2c8597e7e 100644 --- a/advisories/unreviewed/2024/09/GHSA-7mqh-9jjg-r8c8/GHSA-7mqh-9jjg-r8c8.json +++ b/advisories/unreviewed/2024/09/GHSA-7mqh-9jjg-r8c8/GHSA-7mqh-9jjg-r8c8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7mqh-9jjg-r8c8", - "modified": "2024-09-16T14:37:28Z", + "modified": "2024-09-17T12:30:32Z", "published": "2024-09-16T14:37:28Z", "aliases": [ "CVE-2024-46451" ], "details": "TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-16T13:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json b/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json new file mode 100644 index 00000000000..e234de8beae --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2jm-rw3h-6phg", + "modified": "2024-09-17T12:30:32Z", + "published": "2024-09-17T12:30:32Z", + "aliases": [ + "CVE-2024-5998" + ], + "details": "A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hh55-xqjj-vxv4/GHSA-hh55-xqjj-vxv4.json b/advisories/unreviewed/2024/09/GHSA-hh55-xqjj-vxv4/GHSA-hh55-xqjj-vxv4.json index 96fa273630f..dcf8a5dd068 100644 --- a/advisories/unreviewed/2024/09/GHSA-hh55-xqjj-vxv4/GHSA-hh55-xqjj-vxv4.json +++ b/advisories/unreviewed/2024/09/GHSA-hh55-xqjj-vxv4/GHSA-hh55-xqjj-vxv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hh55-xqjj-vxv4", - "modified": "2024-09-16T14:37:28Z", + "modified": "2024-09-17T12:30:32Z", "published": "2024-09-16T14:37:28Z", "aliases": [ "CVE-2024-46424" ], "details": "TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-16T13:15:10Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jf5x-p6mg-vvp7/GHSA-jf5x-p6mg-vvp7.json b/advisories/unreviewed/2024/09/GHSA-jf5x-p6mg-vvp7/GHSA-jf5x-p6mg-vvp7.json index ba7813fb630..27be5abf85b 100644 --- a/advisories/unreviewed/2024/09/GHSA-jf5x-p6mg-vvp7/GHSA-jf5x-p6mg-vvp7.json +++ b/advisories/unreviewed/2024/09/GHSA-jf5x-p6mg-vvp7/GHSA-jf5x-p6mg-vvp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jf5x-p6mg-vvp7", - "modified": "2024-09-16T14:37:29Z", + "modified": "2024-09-17T12:30:32Z", "published": "2024-09-16T14:37:28Z", "aliases": [ "CVE-2024-46419" ], "details": "TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-16T14:15:13Z"