Publish Advisories

GHSA-75f9-xr67-g7hj
GHSA-hjc5-g972-rc2j
GHSA-vggm-vvxj-ggq4
GHSA-2vfh-6ppw-453g
GHSA-69p4-mgmf-pphx
GHSA-f7wp-vx7r-p4vf
GHSA-gm9c-2h9v-jgp5
GHSA-w6wr-vw8p-992f
GHSA-2mjg-798r-mxwh
GHSA-2qqq-gmvr-p2rw
GHSA-3q68-hm47-94vg
GHSA-4c4w-77f9-v9mq
GHSA-66rc-q43x-8675
GHSA-7m4m-pwhv-49c5
GHSA-89wc-q5f7-75f4
GHSA-9c2g-6v5v-57qg
GHSA-9vxw-3j77-cj78
GHSA-cf2w-h975-2fpg
GHSA-f2v6-mw6x-qmwc
GHSA-hp6f-5xgc-789p
GHSA-j3v3-2jrv-w8cx
GHSA-rw7g-4966-p363
This commit is contained in:
advisory-database[bot]
2024-09-04 00:32:41 +00:00
parent a6d2ec2a8e
commit fde0bd0e28
22 changed files with 416 additions and 28 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-75f9-xr67-g7hj",
"modified": "2023-11-14T21:30:54Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2023-11-08T12:30:33Z",
"aliases": [
"CVE-2023-46755"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vfh-6ppw-453g",
"modified": "2024-07-24T03:32:20Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-07-24T03:32:20Z",
"aliases": [
"CVE-2024-6753"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-69p4-mgmf-pphx",
"modified": "2024-07-25T18:32:35Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-07-24T15:31:28Z",
"aliases": [
"CVE-2024-39345"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://github.com/actuator/cve/blob/main/AdTran/TBA"
},
{
"type": "WEB",
"url": "https://supportcommunity.adtran.com/t5/Security-Advisories/ADTSA-2024001-Multiple-vulnerabilities-in-Service-Delivery-Gateway-products/ta-p/39332"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f7wp-vx7r-p4vf",
"modified": "2024-07-24T03:32:20Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-07-24T03:32:20Z",
"aliases": [
"CVE-2024-6755"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gm9c-2h9v-jgp5",
"modified": "2024-07-24T03:32:20Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-07-24T03:32:20Z",
"aliases": [
"CVE-2024-6754"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w6wr-vw8p-992f",
"modified": "2024-07-24T03:32:20Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-07-24T03:32:20Z",
"aliases": [
"CVE-2024-6752"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mjg-798r-mxwh",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-04T00:31:15Z",
"aliases": [
"CVE-2024-45616"
],
"details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45616"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45616"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309290"
}
],
"database_specific": {
"cwe_ids": [
"CWE-457"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:04Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qqq-gmvr-p2rw",
"modified": "2024-09-03T21:31:12Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-09-03T21:31:12Z",
"aliases": [
"CVE-2024-41435"
],
"details": "YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the \"insert into\" parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T19:15:14Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q68-hm47-94vg",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-04T00:31:15Z",
"aliases": [
"CVE-2024-45615"
],
"details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45615"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45615"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309285"
}
],
"database_specific": {
"cwe_ids": [
"CWE-457"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:04Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4c4w-77f9-v9mq",
"modified": "2024-09-04T00:31:16Z",
"published": "2024-09-04T00:31:16Z",
"aliases": [
"CVE-2024-7970"
],
"details": "Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7970"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/358485426"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T23:15:23Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66rc-q43x-8675",
"modified": "2024-09-03T21:31:12Z",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-03T21:31:12Z",
"aliases": [
"CVE-2024-41434"
],
"details": "PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T20:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m4m-pwhv-49c5",
"modified": "2024-09-03T18:31:32Z",
"modified": "2024-09-04T00:31:14Z",
"published": "2024-09-03T18:31:32Z",
"aliases": [
"CVE-2024-6119"
],
"details": "Issue summary: Applications performing certificate name checks (e.g., TLS\nclients checking server certificates) may attempt to read an invalid memory\naddress resulting in abnormal termination of the application process.\n\nImpact summary: Abnormal termination of an application can a cause a denial of\nservice.\n\nApplications performing certificate name checks (e.g., TLS clients checking\nserver certificates) may attempt to read an invalid memory address when\ncomparing the expected name with an `otherName` subject alternative name of an\nX.509 certificate. This may result in an exception that terminates the\napplication program.\n\nNote that basic certificate chain validation (signatures, dates, ...) is not\naffected, the denial of service can occur only when the application also\nspecifies an expected DNS name, Email address or IP address.\n\nTLS servers rarely solicit client certificates, and even when they do, they\ngenerally don't perform a name check against a reference identifier (expected\nidentity), but rather extract the presented identity after checking the\ncertificate chain. So TLS servers are generally not affected and the severity\nof the issue is Moderate.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -43,7 +46,7 @@
"cwe_ids": [
"CWE-843"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T16:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-89wc-q5f7-75f4",
"modified": "2024-09-03T21:31:12Z",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-03T21:31:12Z",
"aliases": [
"CVE-2024-41433"
],
"details": "PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T21:15:16Z"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c2g-6v5v-57qg",
"modified": "2024-09-04T00:31:16Z",
"published": "2024-09-04T00:31:16Z",
"aliases": [
"CVE-2024-45620"
],
"details": "A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45620"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45620"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309289"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vxw-3j77-cj78",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-04T00:31:15Z",
"aliases": [
"CVE-2024-45619"
],
"details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45619"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45619"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309288"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cf2w-h975-2fpg",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-04T00:31:15Z",
"aliases": [
"CVE-2024-45617"
],
"details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45617"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45617"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309286"
}
],
"database_specific": {
"cwe_ids": [
"CWE-457"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:05Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2v6-mw6x-qmwc",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-04T00:31:15Z",
"aliases": [
"CVE-2024-45618"
],
"details": "A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45618"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-45618"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309287"
}
],
"database_specific": {
"cwe_ids": [
"CWE-457"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:05Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hp6f-5xgc-789p",
"modified": "2024-09-04T00:31:15Z",
"published": "2024-09-04T00:31:15Z",
"aliases": [
"CVE-2024-44809"
],
"details": "A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user input passed to the \"position\" GET parameter in the tilt.php script. An attacker can exploit this by sending crafted input data that includes malicious command sequences, allowing arbitrary commands to be executed on the server with the privileges of the web server user. This vulnerability is exploitable remotely and poses significant risk if the application is exposed to untrusted networks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44809"
},
{
"type": "WEB",
"url": "https://github.com/recantha/camera-pi/blob/ef018d212288cb16404f0b050593d20f0dc0467b/www/tilt.php#L4"
},
{
"type": "WEB",
"url": "https://jacobmasse.medium.com/cve-2024-44809-remote-code-execution-in-raspberry-pi-camera-project-4b8e3486a628"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-03T22:15:04Z"
}
}

Some files were not shown because too many files have changed in this diff Show More