Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-08-20 15:33:40 +00:00
parent e7af16a2ec
commit fdb6c063a1
100 changed files with 2568 additions and 102 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43x4-rqpq-prmp",
"modified": "2022-02-08T00:00:47Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2022-02-08T00:00:47Z",
"aliases": [
"CVE-2021-31617"
],
"details": "In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4p74-9wgm-4fjq",
"modified": "2022-07-13T00:01:15Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2022-02-01T00:00:37Z",
"aliases": [
"CVE-2021-28962"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg96-hc49-whwj",
"modified": "2022-07-13T00:01:14Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2022-05-24T19:01:26Z",
"aliases": [
"CVE-2021-28665"
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-401"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qqfg-vxw9-g865",
"modified": "2022-05-24T17:43:30Z",
"modified": "2024-08-20T15:32:10Z",
"published": "2022-05-24T17:43:30Z",
"aliases": [
"CVE-2021-3384"
],
"details": "A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfvf-cm38-cvx4",
"modified": "2022-07-02T00:00:30Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2022-05-24T17:44:55Z",
"aliases": [
"CVE-2021-27506"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qrj-m697-ww2v",
"modified": "2022-08-29T00:00:32Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2022-08-25T00:00:28Z",
"aliases": [
"CVE-2022-27812"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ch6f-2w93-3p64",
"modified": "2024-01-04T03:30:38Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2023-12-25T09:30:20Z",
"aliases": [
"CVE-2023-47091"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rx3-wxg4-cfw8",
"modified": "2024-04-29T18:30:45Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-04-29T18:30:45Z",
"aliases": [
"CVE-2024-32269"
],
"details": "An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-29T17:15:19Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35h7-49rx-p783",
"modified": "2024-05-14T15:32:54Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T15:32:54Z",
"aliases": [
"CVE-2024-29159"
],
"details": "HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:15:32Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mcf-4rgf-4fx9",
"modified": "2024-05-14T18:30:46Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T18:30:46Z",
"aliases": [
"CVE-2024-32621"
],
"details": "HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:36:47Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g42-4xgf-8mcj",
"modified": "2024-05-14T18:30:46Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T18:30:46Z",
"aliases": [
"CVE-2024-32622"
],
"details": "HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:36:47Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9g4-wrgg-h792",
"modified": "2024-05-14T18:30:46Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T18:30:46Z",
"aliases": [
"CVE-2024-32617"
],
"details": "HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:36:46Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h34r-96vv-vxhc",
"modified": "2024-05-14T18:30:44Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T18:30:44Z",
"aliases": [
"CVE-2022-32506"
],
"details": "An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1263"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T10:43:41Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2m4-x7mj-qfqv",
"modified": "2024-05-14T15:32:50Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T15:32:50Z",
"aliases": [
"CVE-2023-46870"
],
"details": "extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T13:54:34Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvvh-gx47-g435",
"modified": "2024-05-14T18:31:02Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T18:31:02Z",
"aliases": [
"CVE-2024-35010"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T16:17:30Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rv8j-7qfw-8mr3",
"modified": "2024-05-20T18:31:24Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-20T18:31:24Z",
"aliases": [
"CVE-2024-35580"
],
"details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T18:15:10Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x9q5-g839-f63f",
"modified": "2024-05-14T18:30:52Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-05-14T18:30:52Z",
"aliases": [
"CVE-2024-35205"
],
"details": "The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:39:43Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3748-24jp-3mgm",
"modified": "2024-06-06T21:30:36Z",
"modified": "2024-08-20T15:32:11Z",
"published": "2024-06-06T21:30:36Z",
"aliases": [
"CVE-2024-36734"
],
"details": "Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the dim parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-06T19:15:58Z"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g2h-7hrx-ghf6",
"modified": "2024-06-27T15:30:45Z",
"modified": "2024-08-20T15:32:12Z",
"published": "2024-06-27T15:30:45Z",
"aliases": [
"CVE-2024-6372"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [

Some files were not shown because too many files have changed in this diff Show More