From febba11b4fd599019f37647ece4ec0fe002d40f0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Sep 2024 18:32:50 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-ch89-vv2m-5q5h.json | 9 ++-- .../GHSA-8c88-9jmc-phqr.json | 3 +- .../GHSA-gmvw-h9hf-3rxv.json | 3 +- .../GHSA-h9x5-2vrm-ww3f.json | 3 +- .../GHSA-pq98-r2rc-hr54.json | 3 +- .../GHSA-xgxr-3384-47xm.json | 3 +- .../GHSA-5g25-5pfp-fm6c.json | 2 +- .../GHSA-5x9h-55x2-p265.json | 3 +- .../GHSA-8r7q-hphg-9wxh.json | 2 +- .../GHSA-jh9v-7fvr-mmpq.json | 2 +- .../GHSA-vq2c-8m6j-g4vh.json | 2 +- .../GHSA-f9qj-7ww3-qw2m.json | 3 +- .../GHSA-gvm4-mpc7-wjpq.json | 3 +- .../GHSA-2cr6-32m2-cxhc.json | 1 + .../GHSA-48gx-pf5r-9pp3.json | 1 + .../GHSA-r2ff-rrfq-r548.json | 3 +- .../GHSA-vm59-55f6-4qp9.json | 1 + .../GHSA-x2cq-7whj-pv8w.json | 3 +- .../GHSA-cfjm-h64g-9m86.json | 3 +- .../GHSA-368c-6qh8-76fj.json | 6 ++- .../GHSA-qw32-4rhp-3985.json | 6 ++- .../GHSA-xh4q-h4wh-8q8p.json | 6 ++- .../GHSA-7c7g-wccp-rrhj.json | 6 ++- .../GHSA-2g8x-wxp8-jhpg.json | 38 +++++++++++++++ .../GHSA-3273-8cp5-whhv.json | 39 ++++++++++++++++ .../GHSA-3hwv-fr9j-3wjq.json | 11 +++-- .../GHSA-3phf-8x93-jmv2.json | 38 +++++++++++++++ .../GHSA-3qf3-f6f4-6993.json | 9 ++-- .../GHSA-3vh6-2h2q-2g33.json | 38 +++++++++++++++ .../GHSA-4fw3-822r-pqw6.json | 9 ++-- .../GHSA-4g2v-4q6g-26v9.json | 38 +++++++++++++++ .../GHSA-5cxp-2w3f-wh6m.json | 6 ++- .../GHSA-5mqf-9q34-g8c2.json | 39 ++++++++++++++++ .../GHSA-5q3p-266j-pj8x.json | 38 +++++++++++++++ .../GHSA-6cm4-chj3-vwmx.json | 2 +- .../GHSA-79gx-p4g6-75qp.json | 39 ++++++++++++++++ .../GHSA-cc36-87rj-xmc4.json | 35 ++++++++++++++ .../GHSA-chqx-36rm-rf8h.json | 46 +++++++++++++++++++ .../GHSA-fc2q-mrvj-fwmp.json | 38 +++++++++++++++ .../GHSA-fg4m-w584-q5x8.json | 38 +++++++++++++++ .../GHSA-fmxj-97w3-xq3m.json | 38 +++++++++++++++ .../GHSA-gq6r-xfpw-cg3w.json | 39 ++++++++++++++++ .../GHSA-hqfh-qjr5-xcfm.json | 38 +++++++++++++++ .../GHSA-hwxp-6qf7-q3rc.json | 35 ++++++++++++++ .../GHSA-j9wc-h525-rvc7.json | 38 +++++++++++++++ .../GHSA-m5gv-m5f9-wgv4.json | 46 +++++++++++++++++++ .../GHSA-m6pw-mqxx-frjv.json | 39 ++++++++++++++++ .../GHSA-m9jx-f6w8-8hj9.json | 38 +++++++++++++++ .../GHSA-mm34-xr6q-46qf.json | 38 +++++++++++++++ .../GHSA-p5fp-56mj-rxm3.json | 35 ++++++++++++++ .../GHSA-pffp-cxqq-7pcw.json | 38 +++++++++++++++ .../GHSA-pp73-8587-cg75.json | 38 +++++++++++++++ .../GHSA-q2mj-f3x9-hwgq.json | 38 +++++++++++++++ .../GHSA-q728-88fr-65v3.json | 38 +++++++++++++++ .../GHSA-qcr8-x9j3-5j62.json | 11 +++-- .../GHSA-qfwm-8mwc-483j.json | 35 ++++++++++++++ .../GHSA-qhg2-622w-f7v7.json | 38 +++++++++++++++ .../GHSA-qmm7-r8jx-cj5h.json | 3 +- .../GHSA-r7m5-wp9g-ph5q.json | 38 +++++++++++++++ .../GHSA-v68p-xrrj-h959.json | 35 ++++++++++++++ .../GHSA-vrcx-gx3g-j3h8.json | 35 ++++++++++++++ .../GHSA-xh87-v57g-jhpw.json | 9 ++-- 62 files changed, 1276 insertions(+), 42 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3273-8cp5-whhv/GHSA-3273-8cp5-whhv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3phf-8x93-jmv2/GHSA-3phf-8x93-jmv2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3vh6-2h2q-2g33/GHSA-3vh6-2h2q-2g33.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4g2v-4q6g-26v9/GHSA-4g2v-4q6g-26v9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5q3p-266j-pj8x/GHSA-5q3p-266j-pj8x.json create mode 100644 advisories/unreviewed/2024/09/GHSA-79gx-p4g6-75qp/GHSA-79gx-p4g6-75qp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fc2q-mrvj-fwmp/GHSA-fc2q-mrvj-fwmp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hqfh-qjr5-xcfm/GHSA-hqfh-qjr5-xcfm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j9wc-h525-rvc7/GHSA-j9wc-h525-rvc7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m9jx-f6w8-8hj9/GHSA-m9jx-f6w8-8hj9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mm34-xr6q-46qf/GHSA-mm34-xr6q-46qf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pffp-cxqq-7pcw/GHSA-pffp-cxqq-7pcw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pp73-8587-cg75/GHSA-pp73-8587-cg75.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q2mj-f3x9-hwgq/GHSA-q2mj-f3x9-hwgq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-q728-88fr-65v3/GHSA-q728-88fr-65v3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qfwm-8mwc-483j/GHSA-qfwm-8mwc-483j.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qhg2-622w-f7v7/GHSA-qhg2-622w-f7v7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r7m5-wp9g-ph5q/GHSA-r7m5-wp9g-ph5q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v68p-xrrj-h959/GHSA-v68p-xrrj-h959.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vrcx-gx3g-j3h8/GHSA-vrcx-gx3g-j3h8.json diff --git a/advisories/unreviewed/2022/05/GHSA-ch89-vv2m-5q5h/GHSA-ch89-vv2m-5q5h.json b/advisories/unreviewed/2022/05/GHSA-ch89-vv2m-5q5h/GHSA-ch89-vv2m-5q5h.json index ebacd6406ca..3f27e773235 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch89-vv2m-5q5h/GHSA-ch89-vv2m-5q5h.json +++ b/advisories/unreviewed/2022/05/GHSA-ch89-vv2m-5q5h/GHSA-ch89-vv2m-5q5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch89-vv2m-5q5h", - "modified": "2022-05-01T18:04:28Z", + "modified": "2024-09-25T18:31:17Z", "published": "2022-05-01T18:04:28Z", "aliases": [ "CVE-2007-2534" ], "details": "** DISPUTED ** Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands via the (1) ADMIN_USER (USER) and (2) ADMIN_PASS (PASS) parameters during a login. NOTE: CVE disputes this vulnerability, since ADMIN_USER/ADMIN_PASS are initialized before use.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json b/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json index d3806056b82..7792933c767 100644 --- a/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json +++ b/advisories/unreviewed/2023/06/GHSA-8c88-9jmc-phqr/GHSA-8c88-9jmc-phqr.json @@ -29,7 +29,8 @@ "database_specific": { "cwe_ids": [ "CWE-119", - "CWE-120" + "CWE-120", + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json b/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json index 7bc5df950a7..5c2e9b3249e 100644 --- a/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json +++ b/advisories/unreviewed/2023/06/GHSA-gmvw-h9hf-3rxv/GHSA-gmvw-h9hf-3rxv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json b/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json index 19a49825f92..b24c73c5ead 100644 --- a/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json +++ b/advisories/unreviewed/2023/06/GHSA-h9x5-2vrm-ww3f/GHSA-h9x5-2vrm-ww3f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json b/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json index 266fec0285c..4a31aad4a7a 100644 --- a/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json +++ b/advisories/unreviewed/2023/06/GHSA-pq98-r2rc-hr54/GHSA-pq98-r2rc-hr54.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-xgxr-3384-47xm/GHSA-xgxr-3384-47xm.json b/advisories/unreviewed/2023/06/GHSA-xgxr-3384-47xm/GHSA-xgxr-3384-47xm.json index 963008ed305..241b9c58dbd 100644 --- a/advisories/unreviewed/2023/06/GHSA-xgxr-3384-47xm/GHSA-xgxr-3384-47xm.json +++ b/advisories/unreviewed/2023/06/GHSA-xgxr-3384-47xm/GHSA-xgxr-3384-47xm.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-401" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-5g25-5pfp-fm6c/GHSA-5g25-5pfp-fm6c.json b/advisories/unreviewed/2023/09/GHSA-5g25-5pfp-fm6c/GHSA-5g25-5pfp-fm6c.json index 91aab5a70a4..b9d972deb00 100644 --- a/advisories/unreviewed/2023/09/GHSA-5g25-5pfp-fm6c/GHSA-5g25-5pfp-fm6c.json +++ b/advisories/unreviewed/2023/09/GHSA-5g25-5pfp-fm6c/GHSA-5g25-5pfp-fm6c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-5x9h-55x2-p265/GHSA-5x9h-55x2-p265.json b/advisories/unreviewed/2023/09/GHSA-5x9h-55x2-p265/GHSA-5x9h-55x2-p265.json index 9b711f67a86..f73110ccec5 100644 --- a/advisories/unreviewed/2023/09/GHSA-5x9h-55x2-p265/GHSA-5x9h-55x2-p265.json +++ b/advisories/unreviewed/2023/09/GHSA-5x9h-55x2-p265/GHSA-5x9h-55x2-p265.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-8r7q-hphg-9wxh/GHSA-8r7q-hphg-9wxh.json b/advisories/unreviewed/2023/09/GHSA-8r7q-hphg-9wxh/GHSA-8r7q-hphg-9wxh.json index d8990e41f7a..2e52100cec2 100644 --- a/advisories/unreviewed/2023/09/GHSA-8r7q-hphg-9wxh/GHSA-8r7q-hphg-9wxh.json +++ b/advisories/unreviewed/2023/09/GHSA-8r7q-hphg-9wxh/GHSA-8r7q-hphg-9wxh.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-jh9v-7fvr-mmpq/GHSA-jh9v-7fvr-mmpq.json b/advisories/unreviewed/2023/09/GHSA-jh9v-7fvr-mmpq/GHSA-jh9v-7fvr-mmpq.json index a19428284d0..1f410e72643 100644 --- a/advisories/unreviewed/2023/09/GHSA-jh9v-7fvr-mmpq/GHSA-jh9v-7fvr-mmpq.json +++ b/advisories/unreviewed/2023/09/GHSA-jh9v-7fvr-mmpq/GHSA-jh9v-7fvr-mmpq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json b/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json index 31e55797147..cdde60d48c8 100644 --- a/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json +++ b/advisories/unreviewed/2023/09/GHSA-vq2c-8m6j-g4vh/GHSA-vq2c-8m6j-g4vh.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-f9qj-7ww3-qw2m/GHSA-f9qj-7ww3-qw2m.json b/advisories/unreviewed/2023/10/GHSA-f9qj-7ww3-qw2m/GHSA-f9qj-7ww3-qw2m.json index 32a486f418c..c0c87acbfde 100644 --- a/advisories/unreviewed/2023/10/GHSA-f9qj-7ww3-qw2m/GHSA-f9qj-7ww3-qw2m.json +++ b/advisories/unreviewed/2023/10/GHSA-f9qj-7ww3-qw2m/GHSA-f9qj-7ww3-qw2m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-312" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-gvm4-mpc7-wjpq/GHSA-gvm4-mpc7-wjpq.json b/advisories/unreviewed/2023/10/GHSA-gvm4-mpc7-wjpq/GHSA-gvm4-mpc7-wjpq.json index c80a870ea8b..ceb91dbfa25 100644 --- a/advisories/unreviewed/2023/10/GHSA-gvm4-mpc7-wjpq/GHSA-gvm4-mpc7-wjpq.json +++ b/advisories/unreviewed/2023/10/GHSA-gvm4-mpc7-wjpq/GHSA-gvm4-mpc7-wjpq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-311" + "CWE-311", + "CWE-312" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-2cr6-32m2-cxhc/GHSA-2cr6-32m2-cxhc.json b/advisories/unreviewed/2023/12/GHSA-2cr6-32m2-cxhc/GHSA-2cr6-32m2-cxhc.json index 031fb9df335..9091036b310 100644 --- a/advisories/unreviewed/2023/12/GHSA-2cr6-32m2-cxhc/GHSA-2cr6-32m2-cxhc.json +++ b/advisories/unreviewed/2023/12/GHSA-2cr6-32m2-cxhc/GHSA-2cr6-32m2-cxhc.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-48gx-pf5r-9pp3/GHSA-48gx-pf5r-9pp3.json b/advisories/unreviewed/2024/02/GHSA-48gx-pf5r-9pp3/GHSA-48gx-pf5r-9pp3.json index 73006af0b8f..c7d3c78a5c2 100644 --- a/advisories/unreviewed/2024/02/GHSA-48gx-pf5r-9pp3/GHSA-48gx-pf5r-9pp3.json +++ b/advisories/unreviewed/2024/02/GHSA-48gx-pf5r-9pp3/GHSA-48gx-pf5r-9pp3.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-131" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-r2ff-rrfq-r548/GHSA-r2ff-rrfq-r548.json b/advisories/unreviewed/2024/02/GHSA-r2ff-rrfq-r548/GHSA-r2ff-rrfq-r548.json index 48cb483c961..e7511bc21c1 100644 --- a/advisories/unreviewed/2024/02/GHSA-r2ff-rrfq-r548/GHSA-r2ff-rrfq-r548.json +++ b/advisories/unreviewed/2024/02/GHSA-r2ff-rrfq-r548/GHSA-r2ff-rrfq-r548.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json b/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json index c04a4f7df1d..988e5661132 100644 --- a/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json +++ b/advisories/unreviewed/2024/02/GHSA-vm59-55f6-4qp9/GHSA-vm59-55f6-4qp9.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-754" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-x2cq-7whj-pv8w/GHSA-x2cq-7whj-pv8w.json b/advisories/unreviewed/2024/02/GHSA-x2cq-7whj-pv8w/GHSA-x2cq-7whj-pv8w.json index 6b8f899564b..0db8ca7a799 100644 --- a/advisories/unreviewed/2024/02/GHSA-x2cq-7whj-pv8w/GHSA-x2cq-7whj-pv8w.json +++ b/advisories/unreviewed/2024/02/GHSA-x2cq-7whj-pv8w/GHSA-x2cq-7whj-pv8w.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-401" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-cfjm-h64g-9m86/GHSA-cfjm-h64g-9m86.json b/advisories/unreviewed/2024/03/GHSA-cfjm-h64g-9m86/GHSA-cfjm-h64g-9m86.json index 6252b83d670..f508a5d73e2 100644 --- a/advisories/unreviewed/2024/03/GHSA-cfjm-h64g-9m86/GHSA-cfjm-h64g-9m86.json +++ b/advisories/unreviewed/2024/03/GHSA-cfjm-h64g-9m86/GHSA-cfjm-h64g-9m86.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-368c-6qh8-76fj/GHSA-368c-6qh8-76fj.json b/advisories/unreviewed/2024/06/GHSA-368c-6qh8-76fj/GHSA-368c-6qh8-76fj.json index e42bb4db1ee..7e1d06dc1cb 100644 --- a/advisories/unreviewed/2024/06/GHSA-368c-6qh8-76fj/GHSA-368c-6qh8-76fj.json +++ b/advisories/unreviewed/2024/06/GHSA-368c-6qh8-76fj/GHSA-368c-6qh8-76fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-368c-6qh8-76fj", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-09-25T18:31:19Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2024-6061" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-qw32-4rhp-3985/GHSA-qw32-4rhp-3985.json b/advisories/unreviewed/2024/06/GHSA-qw32-4rhp-3985/GHSA-qw32-4rhp-3985.json index 20135c6f7b7..9fb4d829ef1 100644 --- a/advisories/unreviewed/2024/06/GHSA-qw32-4rhp-3985/GHSA-qw32-4rhp-3985.json +++ b/advisories/unreviewed/2024/06/GHSA-qw32-4rhp-3985/GHSA-qw32-4rhp-3985.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw32-4rhp-3985", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-09-25T18:31:19Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2024-6062" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-xh4q-h4wh-8q8p/GHSA-xh4q-h4wh-8q8p.json b/advisories/unreviewed/2024/06/GHSA-xh4q-h4wh-8q8p/GHSA-xh4q-h4wh-8q8p.json index ccb872684a9..6afb25d52c6 100644 --- a/advisories/unreviewed/2024/06/GHSA-xh4q-h4wh-8q8p/GHSA-xh4q-h4wh-8q8p.json +++ b/advisories/unreviewed/2024/06/GHSA-xh4q-h4wh-8q8p/GHSA-xh4q-h4wh-8q8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh4q-h4wh-8q8p", - "modified": "2024-06-17T21:31:11Z", + "modified": "2024-09-25T18:31:19Z", "published": "2024-06-17T21:31:11Z", "aliases": [ "CVE-2024-6063" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json index c70a678b45d..e7d2481eec4 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7g-wccp-rrhj", - "modified": "2024-09-25T06:30:42Z", + "modified": "2024-09-25T18:31:19Z", "published": "2024-08-05T15:30:53Z", "aliases": [ "CVE-2024-7409" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6811" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6818" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6964" diff --git a/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json b/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json new file mode 100644 index 00000000000..db55a5ee629 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2g8x-wxp8-jhpg/GHSA-2g8x-wxp8-jhpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g8x-wxp8-jhpg", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20480" + ], + "details": "A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. \n\n This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20480" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-sda-edge-dos-MBcbG9k" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-783" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3273-8cp5-whhv/GHSA-3273-8cp5-whhv.json b/advisories/unreviewed/2024/09/GHSA-3273-8cp5-whhv/GHSA-3273-8cp5-whhv.json new file mode 100644 index 00000000000..cf5e363e135 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3273-8cp5-whhv/GHSA-3273-8cp5-whhv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3273-8cp5-whhv", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-46655" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46655" + }, + { + "type": "WEB", + "url": "https://csflabs.github.io/cve/2024/09/24/cve-2024-46655-Cross-Site-Scripting-%28XSS%29-%28Reflected%29-in-Ellevo-application.html" + }, + { + "type": "WEB", + "url": "https://ellevo.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json b/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json index b027b985dc0..ab7015875ff 100644 --- a/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json +++ b/advisories/unreviewed/2024/09/GHSA-3hwv-fr9j-3wjq/GHSA-3hwv-fr9j-3wjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3hwv-fr9j-3wjq", - "modified": "2024-09-25T15:31:13Z", + "modified": "2024-09-25T18:31:20Z", "published": "2024-09-25T15:31:13Z", "aliases": [ "CVE-2024-46461" ], "details": "VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3phf-8x93-jmv2/GHSA-3phf-8x93-jmv2.json b/advisories/unreviewed/2024/09/GHSA-3phf-8x93-jmv2/GHSA-3phf-8x93-jmv2.json new file mode 100644 index 00000000000..5ba1f5919e9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3phf-8x93-jmv2/GHSA-3phf-8x93-jmv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3phf-8x93-jmv2", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20496" + ], + "details": "A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system.\n\nThis vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20496" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdw-vedos-KqFfhps3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3qf3-f6f4-6993/GHSA-3qf3-f6f4-6993.json b/advisories/unreviewed/2024/09/GHSA-3qf3-f6f4-6993/GHSA-3qf3-f6f4-6993.json index b6e17cf40fe..58357b0a90f 100644 --- a/advisories/unreviewed/2024/09/GHSA-3qf3-f6f4-6993/GHSA-3qf3-f6f4-6993.json +++ b/advisories/unreviewed/2024/09/GHSA-3qf3-f6f4-6993/GHSA-3qf3-f6f4-6993.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qf3-f6f4-6993", - "modified": "2024-09-17T00:31:04Z", + "modified": "2024-09-25T18:31:19Z", "published": "2024-09-17T00:31:04Z", "aliases": [ "CVE-2024-40838" ], "details": "A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app may be able to access notifications from the user's device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-17T00:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-3vh6-2h2q-2g33/GHSA-3vh6-2h2q-2g33.json b/advisories/unreviewed/2024/09/GHSA-3vh6-2h2q-2g33/GHSA-3vh6-2h2q-2g33.json new file mode 100644 index 00000000000..511a71bdea4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3vh6-2h2q-2g33/GHSA-3vh6-2h2q-2g33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vh6-2h2q-2g33", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2023-25189" + ], + "details": "BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25189" + }, + { + "type": "WEB", + "url": "https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2023-25189" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json b/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json index fbfb76d9bd7..39b278a9d33 100644 --- a/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json +++ b/advisories/unreviewed/2024/09/GHSA-4fw3-822r-pqw6/GHSA-4fw3-822r-pqw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fw3-822r-pqw6", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-25T18:31:20Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-9122" ], "details": "Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T01:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-4g2v-4q6g-26v9/GHSA-4g2v-4q6g-26v9.json b/advisories/unreviewed/2024/09/GHSA-4g2v-4q6g-26v9/GHSA-4g2v-4q6g-26v9.json new file mode 100644 index 00000000000..53e3f4d8d99 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4g2v-4q6g-26v9/GHSA-4g2v-4q6g-26v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g2v-4q6g-26v9", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-20434" + ], + "details": "A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device.\n\n This vulnerability is due to improper handling of frames with VLAN tag information. An attacker could exploit this vulnerability by sending crafted frames to an affected device. A successful exploit could allow the attacker to render the control plane of the affected device unresponsive. The device would not be accessible through the console or CLI, and it would not respond to ping requests, SNMP requests, or requests from other control plane protocols. Traffic that is traversing the device through the data plane is not affected. A reload of the device is required to restore control plane services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20434" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vlan-dos-27Pur5RT" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json b/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json index aae88f2fd3b..917932fc3de 100644 --- a/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json +++ b/advisories/unreviewed/2024/09/GHSA-5cxp-2w3f-wh6m/GHSA-5cxp-2w3f-wh6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cxp-2w3f-wh6m", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-25T18:31:20Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-7386" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/wpdm-premium-packages/trunk/wpdm-premium-packages.php?rev=3102989#L1148" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3156970%40wpdm-premium-packages&new=3156970%40wpdm-premium-packages&sfp_email=&sfph_mail=" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0a714536-c6fd-495b-b774-104657329a74?source=cve" diff --git a/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json b/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json new file mode 100644 index 00000000000..202fe77afc8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5mqf-9q34-g8c2/GHSA-5mqf-9q34-g8c2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mqf-9q34-g8c2", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-44825" + ], + "details": "Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44825" + }, + { + "type": "WEB", + "url": "https://github.com/invesalius/invesalius3" + }, + { + "type": "WEB", + "url": "https://github.com/partywavesec/invesalius3_vulnerabilities/tree/main/CVE-2024-44825" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5q3p-266j-pj8x/GHSA-5q3p-266j-pj8x.json b/advisories/unreviewed/2024/09/GHSA-5q3p-266j-pj8x/GHSA-5q3p-266j-pj8x.json new file mode 100644 index 00000000000..f0968af8502 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5q3p-266j-pj8x/GHSA-5q3p-266j-pj8x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q3p-266j-pj8x", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20467" + ], + "details": "A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerability by sending specific sizes of fragmented packets to an affected device or through a Virtual Fragmentation Reassembly (VFR)-enabled interface on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.\n\n Note: This vulnerability affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers if they are running Cisco IOS XE Software Release 17.12.1 or 17.12.1a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20467" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cpp-vfr-dos-nhHKGgO" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json b/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json index 7df33d7d2a1..89d8cd8aadf 100644 --- a/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json +++ b/advisories/unreviewed/2024/09/GHSA-6cm4-chj3-vwmx/GHSA-6cm4-chj3-vwmx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-441" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-79gx-p4g6-75qp/GHSA-79gx-p4g6-75qp.json b/advisories/unreviewed/2024/09/GHSA-79gx-p4g6-75qp/GHSA-79gx-p4g6-75qp.json new file mode 100644 index 00000000000..fb21cccd29c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-79gx-p4g6-75qp/GHSA-79gx-p4g6-75qp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79gx-p4g6-75qp", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-45750" + ], + "details": "An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote attacker to execute arbitrary code via the IKEv2 Authentication phase, it accepts malformed ECDSA signatures and establishes the tunnel.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45750" + }, + { + "type": "WEB", + "url": "https://thegreenbow.com" + }, + { + "type": "WEB", + "url": "https://www.thegreenbow.com/en/support/security-alerts/#deeplink-17024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json b/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json new file mode 100644 index 00000000000..809441ae911 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cc36-87rj-xmc4/GHSA-cc36-87rj-xmc4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc36-87rj-xmc4", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-41445" + ], + "details": "Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the ReadData function", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41445" + }, + { + "type": "WEB", + "url": "https://github.com/g0ku704/vulnerabilities/tree/main/CVE-2024-41445" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json b/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json new file mode 100644 index 00000000000..3689becbf2a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-chqx-36rm-rf8h/GHSA-chqx-36rm-rf8h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chqx-36rm-rf8h", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-8975" + ], + "details": "Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM\nThis issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8975" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/alloy/releases/tag/v1.4.0" + }, + { + "type": "WEB", + "url": "https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2024-8975" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fc2q-mrvj-fwmp/GHSA-fc2q-mrvj-fwmp.json b/advisories/unreviewed/2024/09/GHSA-fc2q-mrvj-fwmp/GHSA-fc2q-mrvj-fwmp.json new file mode 100644 index 00000000000..38297b618c8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fc2q-mrvj-fwmp/GHSA-fc2q-mrvj-fwmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc2q-mrvj-fwmp", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20475" + ], + "details": "A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20475" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-xss-zQ4KPvYd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json b/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json new file mode 100644 index 00000000000..83ed5f8b6f3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fg4m-w584-q5x8/GHSA-fg4m-w584-q5x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg4m-w584-q5x8", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-20433" + ], + "details": "A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.\n\n This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An attacker could exploit this vulnerability by sending RSVP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20433" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rsvp-dos-OypvgVZf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json b/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json new file mode 100644 index 00000000000..6654e15e788 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fmxj-97w3-xq3m/GHSA-fmxj-97w3-xq3m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmxj-97w3-xq3m", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20508" + ], + "details": "A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device.\n\nThis vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort IPS Engine failure is set to the default, fail-open, successful exploitation of this vulnerability could allow the attacker to bypass configured security policies. If the action in case of Cisco UTD Snort IPS Engine failure is set to fail-close, successful exploitation of this vulnerability could cause traffic that is configured to be inspected by Cisco UTD Snort IPS Engine to be dropped.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20508" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-utd-snort3-dos-bypas-b4OUEwxD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json b/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json new file mode 100644 index 00000000000..a0e112778f4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gq6r-xfpw-cg3w/GHSA-gq6r-xfpw-cg3w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq6r-xfpw-cg3w", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-41708" + ], + "details": "An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41708" + }, + { + "type": "WEB", + "url": "https://docs.adacore.com/corp/security-advisories/SEC.AWS-0040-v2.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/AdaCore/aws" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hqfh-qjr5-xcfm/GHSA-hqfh-qjr5-xcfm.json b/advisories/unreviewed/2024/09/GHSA-hqfh-qjr5-xcfm/GHSA-hqfh-qjr5-xcfm.json new file mode 100644 index 00000000000..009be5304e0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hqfh-qjr5-xcfm/GHSA-hqfh-qjr5-xcfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqfh-qjr5-xcfm", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-47305" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font allows Cross Site Request Forgery.This issue affects Use Any Font: from n/a through 6.3.08.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/use-any-font/wordpress-use-any-font-plugin-6-3-08-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json b/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json new file mode 100644 index 00000000000..c1011b13829 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hwxp-6qf7-q3rc/GHSA-hwxp-6qf7-q3rc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwxp-6qf7-q3rc", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-46489" + ], + "details": "A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46489" + }, + { + "type": "WEB", + "url": "https://github.com/VulnSphere/LLMVulnSphere/blob/main/Prompt/promptr/RCE_FC_6.0.7.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j9wc-h525-rvc7/GHSA-j9wc-h525-rvc7.json b/advisories/unreviewed/2024/09/GHSA-j9wc-h525-rvc7/GHSA-j9wc-h525-rvc7.json new file mode 100644 index 00000000000..246fa127d19 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j9wc-h525-rvc7/GHSA-j9wc-h525-rvc7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9wc-h525-rvc7", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20455" + ], + "details": "A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability exists because UTD improperly handles certain packets as those packets egress an SD-WAN IPsec tunnel. An attacker could exploit this vulnerability by sending crafted traffic through an SD-WAN IPsec tunnel that is configured on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.\n\n Note: SD-WAN tunnels that are configured with Generic Routing Encapsulation (GRE) are not affected by this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20455" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-utd-dos-hDATqxs" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json b/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json new file mode 100644 index 00000000000..dd9059cb183 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m5gv-m5f9-wgv4/GHSA-m5gv-m5f9-wgv4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5gv-m5f9-wgv4", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-8996" + ], + "details": "Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM\nThis issue affects Agent Flow: before 0.43.2", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8996" + }, + { + "type": "WEB", + "url": "https://github.com/grafana/agent/releases/tag/v0.43.2" + }, + { + "type": "WEB", + "url": "https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2024-8996" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json b/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json new file mode 100644 index 00000000000..446f7d27413 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m6pw-mqxx-frjv/GHSA-m6pw-mqxx-frjv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6pw-mqxx-frjv", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-44678" + ], + "details": "Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44678" + }, + { + "type": "WEB", + "url": "https://www.bridewell.com/insights/blogs/detail/cve-2024-44678-identified-vulnerability-in-gigastone-wi-fi-range-extenders" + }, + { + "type": "WEB", + "url": "https://www.newegg.com/gigastone-tr1/p/0E6-008K-00004" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m9jx-f6w8-8hj9/GHSA-m9jx-f6w8-8hj9.json b/advisories/unreviewed/2024/09/GHSA-m9jx-f6w8-8hj9/GHSA-m9jx-f6w8-8hj9.json new file mode 100644 index 00000000000..c43b1413f38 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m9jx-f6w8-8hj9/GHSA-m9jx-f6w8-8hj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9jx-f6w8-8hj9", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-20414" + ], + "details": "A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.\n\n This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20414" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-webui-HfwnRgk" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mm34-xr6q-46qf/GHSA-mm34-xr6q-46qf.json b/advisories/unreviewed/2024/09/GHSA-mm34-xr6q-46qf/GHSA-mm34-xr6q-46qf.json new file mode 100644 index 00000000000..d816cf9df69 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mm34-xr6q-46qf/GHSA-mm34-xr6q-46qf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm34-xr6q-46qf", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-20436" + ], + "details": "A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20436" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-httpsrvr-dos-yOZThut" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json b/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json new file mode 100644 index 00000000000..a14c2f323f0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p5fp-56mj-rxm3/GHSA-p5fp-56mj-rxm3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5fp-56mj-rxm3", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-7421" + ], + "details": "An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7421" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2024-0014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pffp-cxqq-7pcw/GHSA-pffp-cxqq-7pcw.json b/advisories/unreviewed/2024/09/GHSA-pffp-cxqq-7pcw/GHSA-pffp-cxqq-7pcw.json new file mode 100644 index 00000000000..03eb7110b17 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pffp-cxqq-7pcw/GHSA-pffp-cxqq-7pcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pffp-cxqq-7pcw", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20464" + ], + "details": "A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\n This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a crafted PIMv2 packet to a PIM-enabled interface on an affected device. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition.\n\n Note: This vulnerability can be exploited with either an IPv4 multicast or unicast packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20464" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pim-APbVfySJ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pp73-8587-cg75/GHSA-pp73-8587-cg75.json b/advisories/unreviewed/2024/09/GHSA-pp73-8587-cg75/GHSA-pp73-8587-cg75.json new file mode 100644 index 00000000000..24c83f2be72 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pp73-8587-cg75/GHSA-pp73-8587-cg75.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp73-8587-cg75", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20510" + ], + "details": "A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication.\n\n This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this vulnerability by connecting to a wireless network that is configured for CWA and sending traffic through an affected device that should be denied by the configured ACL before user authentication. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device before the user authentication is completed, allowing the attacker to access trusted networks that the device might be protecting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20510" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-c9800-cwa-acl-nPSbHSnA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q2mj-f3x9-hwgq/GHSA-q2mj-f3x9-hwgq.json b/advisories/unreviewed/2024/09/GHSA-q2mj-f3x9-hwgq/GHSA-q2mj-f3x9-hwgq.json new file mode 100644 index 00000000000..fdbcfe6cdf8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q2mj-f3x9-hwgq/GHSA-q2mj-f3x9-hwgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2mj-f3x9-hwgq", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-20437" + ], + "details": "A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device.\n\n This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an already authenticated user to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20437" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-csrf-ycUYxkKO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q728-88fr-65v3/GHSA-q728-88fr-65v3.json b/advisories/unreviewed/2024/09/GHSA-q728-88fr-65v3/GHSA-q728-88fr-65v3.json new file mode 100644 index 00000000000..33212247c0a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q728-88fr-65v3/GHSA-q728-88fr-65v3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q728-88fr-65v3", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-20465" + ], + "details": "A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL.\n\n This vulnerability is due to the incorrect handling of IPv4 ACLs on switched virtual interfaces when an administrator enables and disables Resilient Ethernet Protocol (REP). An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20465" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-repacl-9eXgnBpD" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json b/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json index 5823ecca06c..a9160a021e9 100644 --- a/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json +++ b/advisories/unreviewed/2024/09/GHSA-qcr8-x9j3-5j62/GHSA-qcr8-x9j3-5j62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcr8-x9j3-5j62", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-25T18:31:20Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-9121" ], "details": "Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T01:15:48Z" diff --git a/advisories/unreviewed/2024/09/GHSA-qfwm-8mwc-483j/GHSA-qfwm-8mwc-483j.json b/advisories/unreviewed/2024/09/GHSA-qfwm-8mwc-483j/GHSA-qfwm-8mwc-483j.json new file mode 100644 index 00000000000..99e0b623582 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qfwm-8mwc-483j/GHSA-qfwm-8mwc-483j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfwm-8mwc-483j", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-46600" + ], + "details": "dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46600" + }, + { + "type": "WEB", + "url": "https://github.com/loading15678/cms/tree/main/3/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qhg2-622w-f7v7/GHSA-qhg2-622w-f7v7.json b/advisories/unreviewed/2024/09/GHSA-qhg2-622w-f7v7/GHSA-qhg2-622w-f7v7.json new file mode 100644 index 00000000000..6128a2efd4a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qhg2-622w-f7v7/GHSA-qhg2-622w-f7v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhg2-622w-f7v7", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-47315" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.15.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47315" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/give/wordpress-givewp-donation-plugin-and-fundraising-platform-plugin-3-15-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qmm7-r8jx-cj5h/GHSA-qmm7-r8jx-cj5h.json b/advisories/unreviewed/2024/09/GHSA-qmm7-r8jx-cj5h/GHSA-qmm7-r8jx-cj5h.json index def94c6fe3e..f5c6bab3939 100644 --- a/advisories/unreviewed/2024/09/GHSA-qmm7-r8jx-cj5h/GHSA-qmm7-r8jx-cj5h.json +++ b/advisories/unreviewed/2024/09/GHSA-qmm7-r8jx-cj5h/GHSA-qmm7-r8jx-cj5h.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r7m5-wp9g-ph5q/GHSA-r7m5-wp9g-ph5q.json b/advisories/unreviewed/2024/09/GHSA-r7m5-wp9g-ph5q/GHSA-r7m5-wp9g-ph5q.json new file mode 100644 index 00000000000..1007d0ad4b5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r7m5-wp9g-ph5q/GHSA-r7m5-wp9g-ph5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7m5-wp9g-ph5q", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-20350" + ], + "details": "A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance.\n\nThis vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections, which could allow the attacker to intercept traffic between SSH clients and a Cisco Catalyst Center appliance. A successful exploit could allow the attacker to impersonate the affected appliance, inject commands into the terminal session, and steal valid user credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20350" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-ssh-e4uOdASj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v68p-xrrj-h959/GHSA-v68p-xrrj-h959.json b/advisories/unreviewed/2024/09/GHSA-v68p-xrrj-h959/GHSA-v68p-xrrj-h959.json new file mode 100644 index 00000000000..a1847c6c2d9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v68p-xrrj-h959/GHSA-v68p-xrrj-h959.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v68p-xrrj-h959", + "modified": "2024-09-25T18:31:20Z", + "published": "2024-09-25T18:31:20Z", + "aliases": [ + "CVE-2024-46485" + ], + "details": "dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46485" + }, + { + "type": "WEB", + "url": "https://github.com/kikaku-ship/cms/tree/main/1/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vrcx-gx3g-j3h8/GHSA-vrcx-gx3g-j3h8.json b/advisories/unreviewed/2024/09/GHSA-vrcx-gx3g-j3h8/GHSA-vrcx-gx3g-j3h8.json new file mode 100644 index 00000000000..8cca1889f76 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vrcx-gx3g-j3h8/GHSA-vrcx-gx3g-j3h8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrcx-gx3g-j3h8", + "modified": "2024-09-25T18:31:21Z", + "published": "2024-09-25T18:31:21Z", + "aliases": [ + "CVE-2024-46488" + ], + "details": "sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46488" + }, + { + "type": "WEB", + "url": "https://github.com/VulnSphere/LLMVulnSphere/blob/main/VectorDB/sqlite-vec/OOBR_2.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json b/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json index 92f180bd39a..7228bd29f8c 100644 --- a/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json +++ b/advisories/unreviewed/2024/09/GHSA-xh87-v57g-jhpw/GHSA-xh87-v57g-jhpw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xh87-v57g-jhpw", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-25T18:31:20Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-9120" ], "details": "Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T01:15:48Z"