From fde0bd0e28aab0ecff99fb56e3edfeadab5673b4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 4 Sep 2024 00:32:41 +0000 Subject: [PATCH] Publish Advisories GHSA-75f9-xr67-g7hj GHSA-hjc5-g972-rc2j GHSA-vggm-vvxj-ggq4 GHSA-2vfh-6ppw-453g GHSA-69p4-mgmf-pphx GHSA-f7wp-vx7r-p4vf GHSA-gm9c-2h9v-jgp5 GHSA-w6wr-vw8p-992f GHSA-2mjg-798r-mxwh GHSA-2qqq-gmvr-p2rw GHSA-3q68-hm47-94vg GHSA-4c4w-77f9-v9mq GHSA-66rc-q43x-8675 GHSA-7m4m-pwhv-49c5 GHSA-89wc-q5f7-75f4 GHSA-9c2g-6v5v-57qg GHSA-9vxw-3j77-cj78 GHSA-cf2w-h975-2fpg GHSA-f2v6-mw6x-qmwc GHSA-hp6f-5xgc-789p GHSA-j3v3-2jrv-w8cx GHSA-rw7g-4966-p363 --- .../GHSA-75f9-xr67-g7hj.json | 4 +- .../GHSA-hjc5-g972-rc2j.json | 2 +- .../GHSA-vggm-vvxj-ggq4.json | 2 +- .../GHSA-2vfh-6ppw-453g.json | 2 +- .../GHSA-69p4-mgmf-pphx.json | 6 ++- .../GHSA-f7wp-vx7r-p4vf.json | 2 +- .../GHSA-gm9c-2h9v-jgp5.json | 2 +- .../GHSA-w6wr-vw8p-992f.json | 2 +- .../GHSA-2mjg-798r-mxwh.json | 42 +++++++++++++++++++ .../GHSA-2qqq-gmvr-p2rw.json | 11 +++-- .../GHSA-3q68-hm47-94vg.json | 42 +++++++++++++++++++ .../GHSA-4c4w-77f9-v9mq.json | 39 +++++++++++++++++ .../GHSA-66rc-q43x-8675.json | 11 +++-- .../GHSA-7m4m-pwhv-49c5.json | 9 ++-- .../GHSA-89wc-q5f7-75f4.json | 11 +++-- .../GHSA-9c2g-6v5v-57qg.json | 42 +++++++++++++++++++ .../GHSA-9vxw-3j77-cj78.json | 42 +++++++++++++++++++ .../GHSA-cf2w-h975-2fpg.json | 42 +++++++++++++++++++ .../GHSA-f2v6-mw6x-qmwc.json | 42 +++++++++++++++++++ .../GHSA-hp6f-5xgc-789p.json | 39 +++++++++++++++++ .../GHSA-j3v3-2jrv-w8cx.json | 11 +++-- .../GHSA-rw7g-4966-p363.json | 39 +++++++++++++++++ 22 files changed, 416 insertions(+), 28 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9c2g-6v5v-57qg/GHSA-9c2g-6v5v-57qg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9vxw-3j77-cj78/GHSA-9vxw-3j77-cj78.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json diff --git a/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json b/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json index 3ccffb311b5..e5c9089df35 100644 --- a/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json +++ b/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-75f9-xr67-g7hj", - "modified": "2023-11-14T21:30:54Z", + "modified": "2024-09-04T00:31:14Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46755" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-hjc5-g972-rc2j/GHSA-hjc5-g972-rc2j.json b/advisories/unreviewed/2024/01/GHSA-hjc5-g972-rc2j/GHSA-hjc5-g972-rc2j.json index 8f3cb9ca5b2..68f91747a11 100644 --- a/advisories/unreviewed/2024/01/GHSA-hjc5-g972-rc2j/GHSA-hjc5-g972-rc2j.json +++ b/advisories/unreviewed/2024/01/GHSA-hjc5-g972-rc2j/GHSA-hjc5-g972-rc2j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-vggm-vvxj-ggq4/GHSA-vggm-vvxj-ggq4.json b/advisories/unreviewed/2024/01/GHSA-vggm-vvxj-ggq4/GHSA-vggm-vvxj-ggq4.json index 1ca02caf912..60f033f03be 100644 --- a/advisories/unreviewed/2024/01/GHSA-vggm-vvxj-ggq4/GHSA-vggm-vvxj-ggq4.json +++ b/advisories/unreviewed/2024/01/GHSA-vggm-vvxj-ggq4/GHSA-vggm-vvxj-ggq4.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2vfh-6ppw-453g/GHSA-2vfh-6ppw-453g.json b/advisories/unreviewed/2024/07/GHSA-2vfh-6ppw-453g/GHSA-2vfh-6ppw-453g.json index b073e166fe4..a90a9bfe83c 100644 --- a/advisories/unreviewed/2024/07/GHSA-2vfh-6ppw-453g/GHSA-2vfh-6ppw-453g.json +++ b/advisories/unreviewed/2024/07/GHSA-2vfh-6ppw-453g/GHSA-2vfh-6ppw-453g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vfh-6ppw-453g", - "modified": "2024-07-24T03:32:20Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-07-24T03:32:20Z", "aliases": [ "CVE-2024-6753" diff --git a/advisories/unreviewed/2024/07/GHSA-69p4-mgmf-pphx/GHSA-69p4-mgmf-pphx.json b/advisories/unreviewed/2024/07/GHSA-69p4-mgmf-pphx/GHSA-69p4-mgmf-pphx.json index b7d5950382c..698d0b13651 100644 --- a/advisories/unreviewed/2024/07/GHSA-69p4-mgmf-pphx/GHSA-69p4-mgmf-pphx.json +++ b/advisories/unreviewed/2024/07/GHSA-69p4-mgmf-pphx/GHSA-69p4-mgmf-pphx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69p4-mgmf-pphx", - "modified": "2024-07-25T18:32:35Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-07-24T15:31:28Z", "aliases": [ "CVE-2024-39345" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/actuator/cve/blob/main/AdTran/TBA" + }, + { + "type": "WEB", + "url": "https://supportcommunity.adtran.com/t5/Security-Advisories/ADTSA-2024001-Multiple-vulnerabilities-in-Service-Delivery-Gateway-products/ta-p/39332" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-f7wp-vx7r-p4vf/GHSA-f7wp-vx7r-p4vf.json b/advisories/unreviewed/2024/07/GHSA-f7wp-vx7r-p4vf/GHSA-f7wp-vx7r-p4vf.json index 76478751118..4d9eeb4f4c7 100644 --- a/advisories/unreviewed/2024/07/GHSA-f7wp-vx7r-p4vf/GHSA-f7wp-vx7r-p4vf.json +++ b/advisories/unreviewed/2024/07/GHSA-f7wp-vx7r-p4vf/GHSA-f7wp-vx7r-p4vf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f7wp-vx7r-p4vf", - "modified": "2024-07-24T03:32:20Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-07-24T03:32:20Z", "aliases": [ "CVE-2024-6755" diff --git a/advisories/unreviewed/2024/07/GHSA-gm9c-2h9v-jgp5/GHSA-gm9c-2h9v-jgp5.json b/advisories/unreviewed/2024/07/GHSA-gm9c-2h9v-jgp5/GHSA-gm9c-2h9v-jgp5.json index 375112f031d..7d975bffdc4 100644 --- a/advisories/unreviewed/2024/07/GHSA-gm9c-2h9v-jgp5/GHSA-gm9c-2h9v-jgp5.json +++ b/advisories/unreviewed/2024/07/GHSA-gm9c-2h9v-jgp5/GHSA-gm9c-2h9v-jgp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gm9c-2h9v-jgp5", - "modified": "2024-07-24T03:32:20Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-07-24T03:32:20Z", "aliases": [ "CVE-2024-6754" diff --git a/advisories/unreviewed/2024/07/GHSA-w6wr-vw8p-992f/GHSA-w6wr-vw8p-992f.json b/advisories/unreviewed/2024/07/GHSA-w6wr-vw8p-992f/GHSA-w6wr-vw8p-992f.json index d119c860a08..cbc3d0656b6 100644 --- a/advisories/unreviewed/2024/07/GHSA-w6wr-vw8p-992f/GHSA-w6wr-vw8p-992f.json +++ b/advisories/unreviewed/2024/07/GHSA-w6wr-vw8p-992f/GHSA-w6wr-vw8p-992f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6wr-vw8p-992f", - "modified": "2024-07-24T03:32:20Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-07-24T03:32:20Z", "aliases": [ "CVE-2024-6752" diff --git a/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json b/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json new file mode 100644 index 00000000000..9e649870653 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2mjg-798r-mxwh/GHSA-2mjg-798r-mxwh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mjg-798r-mxwh", + "modified": "2024-09-04T00:31:15Z", + "published": "2024-09-04T00:31:15Z", + "aliases": [ + "CVE-2024-45616" + ], + "details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45616" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45616" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309290" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-2qqq-gmvr-p2rw/GHSA-2qqq-gmvr-p2rw.json b/advisories/unreviewed/2024/09/GHSA-2qqq-gmvr-p2rw/GHSA-2qqq-gmvr-p2rw.json index 882ca705424..7d2d3261265 100644 --- a/advisories/unreviewed/2024/09/GHSA-2qqq-gmvr-p2rw/GHSA-2qqq-gmvr-p2rw.json +++ b/advisories/unreviewed/2024/09/GHSA-2qqq-gmvr-p2rw/GHSA-2qqq-gmvr-p2rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qqq-gmvr-p2rw", - "modified": "2024-09-03T21:31:12Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-41435" ], "details": "YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the \"insert into\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T19:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json b/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json new file mode 100644 index 00000000000..6d140d8d36f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3q68-hm47-94vg/GHSA-3q68-hm47-94vg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q68-hm47-94vg", + "modified": "2024-09-04T00:31:15Z", + "published": "2024-09-04T00:31:15Z", + "aliases": [ + "CVE-2024-45615" + ], + "details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45615" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45615" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json b/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json new file mode 100644 index 00000000000..87501674f4a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4c4w-77f9-v9mq/GHSA-4c4w-77f9-v9mq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c4w-77f9-v9mq", + "modified": "2024-09-04T00:31:16Z", + "published": "2024-09-04T00:31:16Z", + "aliases": [ + "CVE-2024-7970" + ], + "details": "Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7970" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/358485426" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T23:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-66rc-q43x-8675/GHSA-66rc-q43x-8675.json b/advisories/unreviewed/2024/09/GHSA-66rc-q43x-8675/GHSA-66rc-q43x-8675.json index 1a6bbb4a27a..276f6cf31b8 100644 --- a/advisories/unreviewed/2024/09/GHSA-66rc-q43x-8675/GHSA-66rc-q43x-8675.json +++ b/advisories/unreviewed/2024/09/GHSA-66rc-q43x-8675/GHSA-66rc-q43x-8675.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66rc-q43x-8675", - "modified": "2024-09-03T21:31:12Z", + "modified": "2024-09-04T00:31:15Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-41434" ], "details": "PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T20:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7m4m-pwhv-49c5/GHSA-7m4m-pwhv-49c5.json b/advisories/unreviewed/2024/09/GHSA-7m4m-pwhv-49c5/GHSA-7m4m-pwhv-49c5.json index f2d6fd8e1f0..84dfeb27cce 100644 --- a/advisories/unreviewed/2024/09/GHSA-7m4m-pwhv-49c5/GHSA-7m4m-pwhv-49c5.json +++ b/advisories/unreviewed/2024/09/GHSA-7m4m-pwhv-49c5/GHSA-7m4m-pwhv-49c5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7m4m-pwhv-49c5", - "modified": "2024-09-03T18:31:32Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-09-03T18:31:32Z", "aliases": [ "CVE-2024-6119" ], "details": "Issue summary: Applications performing certificate name checks (e.g., TLS\nclients checking server certificates) may attempt to read an invalid memory\naddress resulting in abnormal termination of the application process.\n\nImpact summary: Abnormal termination of an application can a cause a denial of\nservice.\n\nApplications performing certificate name checks (e.g., TLS clients checking\nserver certificates) may attempt to read an invalid memory address when\ncomparing the expected name with an `otherName` subject alternative name of an\nX.509 certificate. This may result in an exception that terminates the\napplication program.\n\nNote that basic certificate chain validation (signatures, dates, ...) is not\naffected, the denial of service can occur only when the application also\nspecifies an expected DNS name, Email address or IP address.\n\nTLS servers rarely solicit client certificates, and even when they do, they\ngenerally don't perform a name check against a reference identifier (expected\nidentity), but rather extract the presented identity after checking the\ncertificate chain. So TLS servers are generally not affected and the severity\nof the issue is Moderate.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T16:15:07Z" diff --git a/advisories/unreviewed/2024/09/GHSA-89wc-q5f7-75f4/GHSA-89wc-q5f7-75f4.json b/advisories/unreviewed/2024/09/GHSA-89wc-q5f7-75f4/GHSA-89wc-q5f7-75f4.json index e3d26395c28..237fd12899c 100644 --- a/advisories/unreviewed/2024/09/GHSA-89wc-q5f7-75f4/GHSA-89wc-q5f7-75f4.json +++ b/advisories/unreviewed/2024/09/GHSA-89wc-q5f7-75f4/GHSA-89wc-q5f7-75f4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89wc-q5f7-75f4", - "modified": "2024-09-03T21:31:12Z", + "modified": "2024-09-04T00:31:15Z", "published": "2024-09-03T21:31:12Z", "aliases": [ "CVE-2024-41433" ], "details": "PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T21:15:16Z" diff --git a/advisories/unreviewed/2024/09/GHSA-9c2g-6v5v-57qg/GHSA-9c2g-6v5v-57qg.json b/advisories/unreviewed/2024/09/GHSA-9c2g-6v5v-57qg/GHSA-9c2g-6v5v-57qg.json new file mode 100644 index 00000000000..152b3676f8a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9c2g-6v5v-57qg/GHSA-9c2g-6v5v-57qg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c2g-6v5v-57qg", + "modified": "2024-09-04T00:31:16Z", + "published": "2024-09-04T00:31:16Z", + "aliases": [ + "CVE-2024-45620" + ], + "details": "A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45620" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45620" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309289" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9vxw-3j77-cj78/GHSA-9vxw-3j77-cj78.json b/advisories/unreviewed/2024/09/GHSA-9vxw-3j77-cj78/GHSA-9vxw-3j77-cj78.json new file mode 100644 index 00000000000..23b40bf5498 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9vxw-3j77-cj78/GHSA-9vxw-3j77-cj78.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vxw-3j77-cj78", + "modified": "2024-09-04T00:31:15Z", + "published": "2024-09-04T00:31:15Z", + "aliases": [ + "CVE-2024-45619" + ], + "details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45619" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45619" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309288" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json b/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json new file mode 100644 index 00000000000..cb7a2a62e72 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cf2w-h975-2fpg/GHSA-cf2w-h975-2fpg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf2w-h975-2fpg", + "modified": "2024-09-04T00:31:15Z", + "published": "2024-09-04T00:31:15Z", + "aliases": [ + "CVE-2024-45617" + ], + "details": "A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45617" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45617" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309286" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json b/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json new file mode 100644 index 00000000000..7534c520d1d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-f2v6-mw6x-qmwc/GHSA-f2v6-mw6x-qmwc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2v6-mw6x-qmwc", + "modified": "2024-09-04T00:31:15Z", + "published": "2024-09-04T00:31:15Z", + "aliases": [ + "CVE-2024-45618" + ], + "details": "A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45618" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45618" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2309287" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json b/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json new file mode 100644 index 00000000000..5fc97c00a74 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hp6f-5xgc-789p/GHSA-hp6f-5xgc-789p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp6f-5xgc-789p", + "modified": "2024-09-04T00:31:15Z", + "published": "2024-09-04T00:31:15Z", + "aliases": [ + "CVE-2024-44809" + ], + "details": "A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user input passed to the \"position\" GET parameter in the tilt.php script. An attacker can exploit this by sending crafted input data that includes malicious command sequences, allowing arbitrary commands to be executed on the server with the privileges of the web server user. This vulnerability is exploitable remotely and poses significant risk if the application is exposed to untrusted networks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44809" + }, + { + "type": "WEB", + "url": "https://github.com/recantha/camera-pi/blob/ef018d212288cb16404f0b050593d20f0dc0467b/www/tilt.php#L4" + }, + { + "type": "WEB", + "url": "https://jacobmasse.medium.com/cve-2024-44809-remote-code-execution-in-raspberry-pi-camera-project-4b8e3486a628" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json b/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json index 2c226985884..93349ca9434 100644 --- a/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json +++ b/advisories/unreviewed/2024/09/GHSA-j3v3-2jrv-w8cx/GHSA-j3v3-2jrv-w8cx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j3v3-2jrv-w8cx", - "modified": "2024-09-03T18:31:32Z", + "modified": "2024-09-04T00:31:14Z", "published": "2024-09-03T18:31:32Z", "aliases": [ "CVE-2023-49233" ], "details": "Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow attackers to obtain different types of configured credentials and potentially elevate their privileges to administrator level.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T17:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json b/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json new file mode 100644 index 00000000000..2893d2dd740 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rw7g-4966-p363/GHSA-rw7g-4966-p363.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw7g-4966-p363", + "modified": "2024-09-04T00:31:16Z", + "published": "2024-09-04T00:31:16Z", + "aliases": [ + "CVE-2024-8362" + ], + "details": "Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8362" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/357391257" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-03T23:15:23Z" + } +} \ No newline at end of file