Publish Advisories

GHSA-9w3h-593p-q56r
GHSA-jjr8-97p7-vmmg
GHSA-3p7f-4r2q-wxmm
GHSA-4265-ccf5-phj5
GHSA-4g9r-vxhx-9pgx
GHSA-6fvm-72pg-5mvv
GHSA-jg62-3p5c-pg7j
GHSA-qg8q-74vc-qfgq
GHSA-vcv5-7xr7-wf5f
This commit is contained in:
advisory-database[bot]
2024-02-19 12:31:54 +00:00
parent f39c43f27d
commit fd79cc9f0c
9 changed files with 209 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9w3h-593p-q56r",
"modified": "2024-01-29T12:30:20Z",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-01-29T12:30:20Z",
"aliases": [
"CVE-2023-5378"
@@ -31,11 +31,11 @@
},
{
"type": "WEB",
"url": "https://megabip.pl/"
"url": "https://megabip.pl"
},
{
"type": "WEB",
"url": "https://smod.pl/"
"url": "https://smod.pl"
}
],
"database_specific": {
@@ -60,7 +60,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-131"
"CWE-131",
"CWE-190"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p7f-4r2q-wxmm",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T12:30:37Z",
"aliases": [
"CVE-2024-1580"
],
"details": "An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.\n\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1580"
},
{
"type": "WEB",
"url": "https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS"
},
{
"type": "WEB",
"url": "https://code.videolan.org/videolan/dav1d/-/releases/1.4.0"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-19T11:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4265-ccf5-phj5",
"modified": "2024-02-19T09:30:52Z",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T09:30:52Z",
"aliases": [
"CVE-2024-26308"
@@ -21,6 +21,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/ch5yo2d21p7vlqrhll9b17otbyq4npfg"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/02/19/2"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g9r-vxhx-9pgx",
"modified": "2024-02-19T09:30:50Z",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T09:30:50Z",
"aliases": [
"CVE-2024-25710"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/02/19/1"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fvm-72pg-5mvv",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T12:30:37Z",
"aliases": [
"CVE-2024-1346"
],
"details": "Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1346"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-laborofficefree"
}
],
"database_specific": {
"cwe_ids": [
"CWE-521"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-19T12:15:45Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg62-3p5c-pg7j",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T12:30:37Z",
"aliases": [
"CVE-2024-1343"
],
"details": "A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1343"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-laborofficefree"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-19T12:15:44Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qg8q-74vc-qfgq",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T12:30:37Z",
"aliases": [
"CVE-2024-1344"
],
"details": "Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of 'LOF_service.exe' and 'LaborOfficeFree.exe' located in the '%programfiles(x86)%\\LaborOfficeFree\\' directory. This user can log in remotely and has root-like privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1344"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-laborofficefree"
}
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-19T12:15:44Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vcv5-7xr7-wf5f",
"modified": "2024-02-19T12:30:37Z",
"published": "2024-02-19T12:30:37Z",
"aliases": [
"CVE-2024-1345"
],
"details": "Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1345"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-laborofficefree"
}
],
"database_specific": {
"cwe_ids": [
"CWE-521"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-19T12:15:44Z"
}
}