From fecd23cc3a6e0e2a28462cda4afcd233f590abbe Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 7 Oct 2024 15:33:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-42p7-pcvv-9gm5.json | 11 ++-- .../GHSA-52p3-42f9-q8gp.json | 2 +- .../GHSA-6jxj-6j73-7fgm.json | 11 ++-- .../GHSA-75xr-xx5q-8h3v.json | 11 ++-- .../GHSA-7vpc-649w-qqpr.json | 11 ++-- .../GHSA-7vrc-hc62-3f49.json | 6 +- .../GHSA-8hrr-r493-96vh.json | 3 +- .../GHSA-8mgj-fhf8-9275.json | 3 +- .../GHSA-8x7j-q7w2-6pxg.json | 11 ++-- .../GHSA-c8ff-57f4-9r7c.json | 11 ++-- .../GHSA-f5v6-6qcg-mrg8.json | 2 +- .../GHSA-fg6p-6vjg-95r5.json | 9 ++- .../GHSA-vjjf-x2fh-7rqj.json | 2 +- .../GHSA-w45p-45qw-q65m.json | 2 +- .../GHSA-w9j6-gpc8-w3w8.json | 11 ++-- .../GHSA-2g22-jf64-pvrp.json | 58 +++++++++++++++++++ .../GHSA-2v26-h6g3-vrgj.json | 38 ++++++++++++ .../GHSA-36wv-6w83-xmqr.json | 38 ++++++++++++ .../GHSA-46p9-g8f2-qj87.json | 38 ++++++++++++ .../GHSA-4vvw-xxg7-3qfj.json | 38 ++++++++++++ .../GHSA-5gm8-rjrv-q6hj.json | 38 ++++++++++++ .../GHSA-5mch-6pwv-9qcv.json | 38 ++++++++++++ .../GHSA-5vgv-f6wh-xq94.json | 38 ++++++++++++ .../GHSA-72r8-34hv-3qjh.json | 38 ++++++++++++ .../GHSA-7ch4-4cx7-v494.json | 38 ++++++++++++ .../GHSA-7r96-5299-pqgj.json | 38 ++++++++++++ .../GHSA-7wh7-988c-gqfj.json | 38 ++++++++++++ .../GHSA-8p55-c2p4-c8hp.json | 38 ++++++++++++ .../GHSA-923r-gp72-rmm4.json | 38 ++++++++++++ .../GHSA-9377-p242-8m6p.json | 38 ++++++++++++ .../GHSA-9ghg-wm2v-725p.json | 38 ++++++++++++ .../GHSA-f44g-3fvc-36q4.json | 58 +++++++++++++++++++ .../GHSA-f7vv-q49x-rvww.json | 38 ++++++++++++ .../GHSA-g5mr-5gcc-mgfx.json | 38 ++++++++++++ .../GHSA-g9xx-vqxv-3gjm.json | 38 ++++++++++++ .../GHSA-gxgq-8g7h-rw9j.json | 38 ++++++++++++ .../GHSA-h8cp-m3hw-6297.json | 38 ++++++++++++ .../GHSA-jpg5-hv6p-pxvv.json | 38 ++++++++++++ .../GHSA-jxm2-p482-6hqq.json | 58 +++++++++++++++++++ .../GHSA-m52g-xcvx-ppv2.json | 35 +++++++++++ .../GHSA-mg96-4cjg-fvrq.json | 38 ++++++++++++ .../GHSA-mvx6-xfx7-r23g.json | 10 +++- .../GHSA-p4vj-j2w3-773m.json | 38 ++++++++++++ .../GHSA-pgfh-74x2-2w43.json | 39 +++++++++++++ .../GHSA-ppw7-rj8j-p8c2.json | 38 ++++++++++++ .../GHSA-qcr4-m6wf-h33w.json | 58 +++++++++++++++++++ .../GHSA-qgvh-3gr3-j9ph.json | 38 ++++++++++++ .../GHSA-qj96-v6mr-fxhc.json | 38 ++++++++++++ .../GHSA-rjwx-3ghx-2cr8.json | 38 ++++++++++++ .../GHSA-rqp6-8mfq-gp8w.json | 38 ++++++++++++ .../GHSA-x9gf-8wx8-vgh8.json | 38 ++++++++++++ 51 files changed, 1486 insertions(+), 38 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-2g22-jf64-pvrp/GHSA-2g22-jf64-pvrp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2v26-h6g3-vrgj/GHSA-2v26-h6g3-vrgj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-36wv-6w83-xmqr/GHSA-36wv-6w83-xmqr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4vvw-xxg7-3qfj/GHSA-4vvw-xxg7-3qfj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5mch-6pwv-9qcv/GHSA-5mch-6pwv-9qcv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json create mode 100644 advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7ch4-4cx7-v494/GHSA-7ch4-4cx7-v494.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7r96-5299-pqgj/GHSA-7r96-5299-pqgj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7wh7-988c-gqfj/GHSA-7wh7-988c-gqfj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8p55-c2p4-c8hp/GHSA-8p55-c2p4-c8hp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9377-p242-8m6p/GHSA-9377-p242-8m6p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9ghg-wm2v-725p/GHSA-9ghg-wm2v-725p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f44g-3fvc-36q4/GHSA-f44g-3fvc-36q4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g5mr-5gcc-mgfx/GHSA-g5mr-5gcc-mgfx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g9xx-vqxv-3gjm/GHSA-g9xx-vqxv-3gjm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gxgq-8g7h-rw9j/GHSA-gxgq-8g7h-rw9j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h8cp-m3hw-6297/GHSA-h8cp-m3hw-6297.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jpg5-hv6p-pxvv/GHSA-jpg5-hv6p-pxvv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jxm2-p482-6hqq/GHSA-jxm2-p482-6hqq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m52g-xcvx-ppv2/GHSA-m52g-xcvx-ppv2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mg96-4cjg-fvrq/GHSA-mg96-4cjg-fvrq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p4vj-j2w3-773m/GHSA-p4vj-j2w3-773m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pgfh-74x2-2w43/GHSA-pgfh-74x2-2w43.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ppw7-rj8j-p8c2/GHSA-ppw7-rj8j-p8c2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qcr4-m6wf-h33w/GHSA-qcr4-m6wf-h33w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qj96-v6mr-fxhc/GHSA-qj96-v6mr-fxhc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rjwx-3ghx-2cr8/GHSA-rjwx-3ghx-2cr8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rqp6-8mfq-gp8w/GHSA-rqp6-8mfq-gp8w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x9gf-8wx8-vgh8/GHSA-x9gf-8wx8-vgh8.json diff --git a/advisories/unreviewed/2024/09/GHSA-42p7-pcvv-9gm5/GHSA-42p7-pcvv-9gm5.json b/advisories/unreviewed/2024/09/GHSA-42p7-pcvv-9gm5/GHSA-42p7-pcvv-9gm5.json index a88099596f7..7e8c7dea9c6 100644 --- a/advisories/unreviewed/2024/09/GHSA-42p7-pcvv-9gm5/GHSA-42p7-pcvv-9gm5.json +++ b/advisories/unreviewed/2024/09/GHSA-42p7-pcvv-9gm5/GHSA-42p7-pcvv-9gm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42p7-pcvv-9gm5", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-44912" ], "details": "NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:15Z" diff --git a/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json b/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json index c4d77377efb..1e1a459cd8d 100644 --- a/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json +++ b/advisories/unreviewed/2024/09/GHSA-52p3-42f9-q8gp/GHSA-52p3-42f9-q8gp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-52p3-42f9-q8gp", - "modified": "2024-09-04T06:30:42Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-8325" diff --git a/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json b/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json index 8aaf7fb5204..ca7b40c834b 100644 --- a/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json +++ b/advisories/unreviewed/2024/09/GHSA-6jxj-6j73-7fgm/GHSA-6jxj-6j73-7fgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6jxj-6j73-7fgm", - "modified": "2024-09-27T18:32:26Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T18:32:26Z", "aliases": [ "CVE-2024-25412" ], "details": "A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T18:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-75xr-xx5q-8h3v/GHSA-75xr-xx5q-8h3v.json b/advisories/unreviewed/2024/09/GHSA-75xr-xx5q-8h3v/GHSA-75xr-xx5q-8h3v.json index b79ad144a9d..b1074956950 100644 --- a/advisories/unreviewed/2024/09/GHSA-75xr-xx5q-8h3v/GHSA-75xr-xx5q-8h3v.json +++ b/advisories/unreviewed/2024/09/GHSA-75xr-xx5q-8h3v/GHSA-75xr-xx5q-8h3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75xr-xx5q-8h3v", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46802" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: added NULL check at start of dc_validate_stream\n\n[Why]\nprevent invalid memory access\n\n[How]\ncheck if dc and stream are NULL", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7vpc-649w-qqpr/GHSA-7vpc-649w-qqpr.json b/advisories/unreviewed/2024/09/GHSA-7vpc-649w-qqpr/GHSA-7vpc-649w-qqpr.json index e22a70c14f8..a06c04abf3f 100644 --- a/advisories/unreviewed/2024/09/GHSA-7vpc-649w-qqpr/GHSA-7vpc-649w-qqpr.json +++ b/advisories/unreviewed/2024/09/GHSA-7vpc-649w-qqpr/GHSA-7vpc-649w-qqpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vpc-649w-qqpr", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-44910" ], "details": "NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json b/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json index 70e38ade820..8c9675abf43 100644 --- a/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json +++ b/advisories/unreviewed/2024/09/GHSA-7vrc-hc62-3f49/GHSA-7vrc-hc62-3f49.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vrc-hc62-3f49", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47126" ], "details": "The goTenna Pro series does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json b/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json index 7e87204d3af..d1f211390e2 100644 --- a/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json +++ b/advisories/unreviewed/2024/09/GHSA-8hrr-r493-96vh/GHSA-8hrr-r493-96vh.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json b/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json index 5ab299d14d6..ca9222aaa06 100644 --- a/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json +++ b/advisories/unreviewed/2024/09/GHSA-8mgj-fhf8-9275/GHSA-8mgj-fhf8-9275.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-8x7j-q7w2-6pxg/GHSA-8x7j-q7w2-6pxg.json b/advisories/unreviewed/2024/09/GHSA-8x7j-q7w2-6pxg/GHSA-8x7j-q7w2-6pxg.json index 9ff02302486..a4bbe494515 100644 --- a/advisories/unreviewed/2024/09/GHSA-8x7j-q7w2-6pxg/GHSA-8x7j-q7w2-6pxg.json +++ b/advisories/unreviewed/2024/09/GHSA-8x7j-q7w2-6pxg/GHSA-8x7j-q7w2-6pxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8x7j-q7w2-6pxg", - "modified": "2024-09-27T15:30:35Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T15:30:35Z", "aliases": [ "CVE-2024-44911" ], "details": "NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_aos.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json b/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json index aa180b4690f..cc2e633c940 100644 --- a/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json +++ b/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8ff-57f4-9r7c", - "modified": "2024-09-27T21:31:50Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T21:31:50Z", "aliases": [ "CVE-2024-46453" ], "details": "A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T21:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json b/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json index bc2bf3ff04f..f6b50729691 100644 --- a/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json +++ b/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json b/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json index 2025a3db34e..e21527f07dc 100644 --- a/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json +++ b/advisories/unreviewed/2024/09/GHSA-fg6p-6vjg-95r5/GHSA-fg6p-6vjg-95r5.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fg6p-6vjg-95r5", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47127" ], "details": "In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This vulnerability can be exploited if the device is being used in a unencrypted environment or if the cryptography has already been compromised.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1390" + "CWE-1390", + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json b/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json index b2bf09124a6..210f016a153 100644 --- a/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json +++ b/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-w45p-45qw-q65m/GHSA-w45p-45qw-q65m.json b/advisories/unreviewed/2024/09/GHSA-w45p-45qw-q65m/GHSA-w45p-45qw-q65m.json index 964c21f54c8..c962fb67f4a 100644 --- a/advisories/unreviewed/2024/09/GHSA-w45p-45qw-q65m/GHSA-w45p-45qw-q65m.json +++ b/advisories/unreviewed/2024/09/GHSA-w45p-45qw-q65m/GHSA-w45p-45qw-q65m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w45p-45qw-q65m", - "modified": "2024-09-28T00:30:49Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-28T00:30:49Z", "aliases": [ "CVE-2024-23586" diff --git a/advisories/unreviewed/2024/09/GHSA-w9j6-gpc8-w3w8/GHSA-w9j6-gpc8-w3w8.json b/advisories/unreviewed/2024/09/GHSA-w9j6-gpc8-w3w8/GHSA-w9j6-gpc8-w3w8.json index 84f7f89f2fb..1feddd2d911 100644 --- a/advisories/unreviewed/2024/09/GHSA-w9j6-gpc8-w3w8/GHSA-w9j6-gpc8-w3w8.json +++ b/advisories/unreviewed/2024/09/GHSA-w9j6-gpc8-w3w8/GHSA-w9j6-gpc8-w3w8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w9j6-gpc8-w3w8", - "modified": "2024-09-27T15:30:33Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-09-27T15:30:33Z", "aliases": [ "CVE-2024-46811" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box\n\n[Why]\nCoverity reports OVERRUN warning. soc.num_states could\nbe 40. But array range of bw_params->clk_table.entries is 8.\n\n[How]\nAssert if soc.num_states greater than 8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T13:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-2g22-jf64-pvrp/GHSA-2g22-jf64-pvrp.json b/advisories/unreviewed/2024/10/GHSA-2g22-jf64-pvrp/GHSA-2g22-jf64-pvrp.json new file mode 100644 index 00000000000..b408ded1287 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2g22-jf64-pvrp/GHSA-2g22-jf64-pvrp.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g22-jf64-pvrp", + "modified": "2024-10-07T15:31:40Z", + "published": "2024-10-07T15:31:40Z", + "aliases": [ + "CVE-2024-9568" + ], + "details": "A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9568" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formAdvNetwork.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279462" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279462" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.414545" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2v26-h6g3-vrgj/GHSA-2v26-h6g3-vrgj.json b/advisories/unreviewed/2024/10/GHSA-2v26-h6g3-vrgj/GHSA-2v26-h6g3-vrgj.json new file mode 100644 index 00000000000..383d16d0690 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2v26-h6g3-vrgj/GHSA-2v26-h6g3-vrgj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v26-h6g3-vrgj", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-38425" + ], + "details": "Information disclosure while sending implicit broadcast containing APP launch information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38425" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-36wv-6w83-xmqr/GHSA-36wv-6w83-xmqr.json b/advisories/unreviewed/2024/10/GHSA-36wv-6w83-xmqr/GHSA-36wv-6w83-xmqr.json new file mode 100644 index 00000000000..72b2cfe8f4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-36wv-6w83-xmqr/GHSA-36wv-6w83-xmqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36wv-6w83-xmqr", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-43047" + ], + "details": "Memory corruption while maintaining memory maps of HLOS memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43047" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json b/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json new file mode 100644 index 00000000000..89af8ea317d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46p9-g8f2-qj87", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33071" + ], + "details": "Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33071" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4vvw-xxg7-3qfj/GHSA-4vvw-xxg7-3qfj.json b/advisories/unreviewed/2024/10/GHSA-4vvw-xxg7-3qfj/GHSA-4vvw-xxg7-3qfj.json new file mode 100644 index 00000000000..9ef5c510ad0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4vvw-xxg7-3qfj/GHSA-4vvw-xxg7-3qfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vvw-xxg7-3qfj", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-23379" + ], + "details": "Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23379" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json b/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json new file mode 100644 index 00000000000..abbc13193b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gm8-rjrv-q6hj", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33049" + ], + "details": "Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33049" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5mch-6pwv-9qcv/GHSA-5mch-6pwv-9qcv.json b/advisories/unreviewed/2024/10/GHSA-5mch-6pwv-9qcv/GHSA-5mch-6pwv-9qcv.json new file mode 100644 index 00000000000..04a7e4737b3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5mch-6pwv-9qcv/GHSA-5mch-6pwv-9qcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mch-6pwv-9qcv", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9574" + ], + "details": "SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9574" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-soplanning" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json b/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json new file mode 100644 index 00000000000..082a6cb5676 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vgv-f6wh-xq94", + "modified": "2024-10-07T15:31:38Z", + "published": "2024-10-07T15:31:38Z", + "aliases": [ + "CVE-2024-21455" + ], + "details": "Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21455" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json b/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json new file mode 100644 index 00000000000..da7321fb89b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72r8-34hv-3qjh", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33064" + ], + "details": "Information disclosure while parsing the multiple MBSSID IEs from the beacon.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33064" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7ch4-4cx7-v494/GHSA-7ch4-4cx7-v494.json b/advisories/unreviewed/2024/10/GHSA-7ch4-4cx7-v494/GHSA-7ch4-4cx7-v494.json new file mode 100644 index 00000000000..21b6e4d294e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7ch4-4cx7-v494/GHSA-7ch4-4cx7-v494.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ch4-4cx7-v494", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33073" + ], + "details": "Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33073" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7r96-5299-pqgj/GHSA-7r96-5299-pqgj.json b/advisories/unreviewed/2024/10/GHSA-7r96-5299-pqgj/GHSA-7r96-5299-pqgj.json new file mode 100644 index 00000000000..177e170e59c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7r96-5299-pqgj/GHSA-7r96-5299-pqgj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r96-5299-pqgj", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:38Z", + "aliases": [ + "CVE-2024-23375" + ], + "details": "Memory corruption during the network scan request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23375" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7wh7-988c-gqfj/GHSA-7wh7-988c-gqfj.json b/advisories/unreviewed/2024/10/GHSA-7wh7-988c-gqfj/GHSA-7wh7-988c-gqfj.json new file mode 100644 index 00000000000..7a24f26eeb7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7wh7-988c-gqfj/GHSA-7wh7-988c-gqfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wh7-988c-gqfj", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-23378" + ], + "details": "Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23378" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8p55-c2p4-c8hp/GHSA-8p55-c2p4-c8hp.json b/advisories/unreviewed/2024/10/GHSA-8p55-c2p4-c8hp/GHSA-8p55-c2p4-c8hp.json new file mode 100644 index 00000000000..d81554daa0c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8p55-c2p4-c8hp/GHSA-8p55-c2p4-c8hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p55-c2p4-c8hp", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-38399" + ], + "details": "Memory corruption while processing user packets to generate page faults.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38399" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json b/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json new file mode 100644 index 00000000000..eecd846f2ee --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-923r-gp72-rmm4", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-23374" + ], + "details": "Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23374" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9377-p242-8m6p/GHSA-9377-p242-8m6p.json b/advisories/unreviewed/2024/10/GHSA-9377-p242-8m6p/GHSA-9377-p242-8m6p.json new file mode 100644 index 00000000000..f114b41927f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9377-p242-8m6p/GHSA-9377-p242-8m6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9377-p242-8m6p", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9572" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow a remote user to send a specially crafted query to an authenticated user and steal their session details.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9572" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-soplanning" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9ghg-wm2v-725p/GHSA-9ghg-wm2v-725p.json b/advisories/unreviewed/2024/10/GHSA-9ghg-wm2v-725p/GHSA-9ghg-wm2v-725p.json new file mode 100644 index 00000000000..8c19dd1f3c5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9ghg-wm2v-725p/GHSA-9ghg-wm2v-725p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ghg-wm2v-725p", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-23370" + ], + "details": "Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23370" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f44g-3fvc-36q4/GHSA-f44g-3fvc-36q4.json b/advisories/unreviewed/2024/10/GHSA-f44g-3fvc-36q4/GHSA-f44g-3fvc-36q4.json new file mode 100644 index 00000000000..f9d160add5e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f44g-3fvc-36q4/GHSA-f44g-3fvc-36q4.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f44g-3fvc-36q4", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9569" + ], + "details": "A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file /goform/formEasySetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9569" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formEasySetPassword.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279463" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279463" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.414547" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json b/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json new file mode 100644 index 00000000000..08ba79e5849 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7vv-q49x-rvww", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-42027" + ], + "details": "The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42027" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2546437" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g5mr-5gcc-mgfx/GHSA-g5mr-5gcc-mgfx.json b/advisories/unreviewed/2024/10/GHSA-g5mr-5gcc-mgfx/GHSA-g5mr-5gcc-mgfx.json new file mode 100644 index 00000000000..0b5468a4630 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g5mr-5gcc-mgfx/GHSA-g5mr-5gcc-mgfx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5mr-5gcc-mgfx", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-23376" + ], + "details": "Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23376" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g9xx-vqxv-3gjm/GHSA-g9xx-vqxv-3gjm.json b/advisories/unreviewed/2024/10/GHSA-g9xx-vqxv-3gjm/GHSA-g9xx-vqxv-3gjm.json new file mode 100644 index 00000000000..22b38b68e24 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g9xx-vqxv-3gjm/GHSA-g9xx-vqxv-3gjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9xx-vqxv-3gjm", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:38Z", + "aliases": [ + "CVE-2024-23369" + ], + "details": "Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23369" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gxgq-8g7h-rw9j/GHSA-gxgq-8g7h-rw9j.json b/advisories/unreviewed/2024/10/GHSA-gxgq-8g7h-rw9j/GHSA-gxgq-8g7h-rw9j.json new file mode 100644 index 00000000000..d8a0153bc20 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gxgq-8g7h-rw9j/GHSA-gxgq-8g7h-rw9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxgq-8g7h-rw9j", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9571" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a remote user to send a specially crafted query to an authenticated user and partially take control of their browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9571" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-soplanning" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h8cp-m3hw-6297/GHSA-h8cp-m3hw-6297.json b/advisories/unreviewed/2024/10/GHSA-h8cp-m3hw-6297/GHSA-h8cp-m3hw-6297.json new file mode 100644 index 00000000000..919bbfe4b83 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h8cp-m3hw-6297/GHSA-h8cp-m3hw-6297.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8cp-m3hw-6297", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9576" + ], + "details": "Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9576" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/improper-access-control-linux-workbooth-distro" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jpg5-hv6p-pxvv/GHSA-jpg5-hv6p-pxvv.json b/advisories/unreviewed/2024/10/GHSA-jpg5-hv6p-pxvv/GHSA-jpg5-hv6p-pxvv.json new file mode 100644 index 00000000000..e9a6c9b3eda --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jpg5-hv6p-pxvv/GHSA-jpg5-hv6p-pxvv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpg5-hv6p-pxvv", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33065" + ], + "details": "Memory corruption while taking snapshot when an offset variable is set by camera driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33065" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jxm2-p482-6hqq/GHSA-jxm2-p482-6hqq.json b/advisories/unreviewed/2024/10/GHSA-jxm2-p482-6hqq/GHSA-jxm2-p482-6hqq.json new file mode 100644 index 00000000000..7dec11ea9b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jxm2-p482-6hqq/GHSA-jxm2-p482-6hqq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxm2-p482-6hqq", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9566" + ], + "details": "A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9566" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formDeviceReboot.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279460" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279460" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.414541" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m52g-xcvx-ppv2/GHSA-m52g-xcvx-ppv2.json b/advisories/unreviewed/2024/10/GHSA-m52g-xcvx-ppv2/GHSA-m52g-xcvx-ppv2.json new file mode 100644 index 00000000000..8378ea3936b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m52g-xcvx-ppv2/GHSA-m52g-xcvx-ppv2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m52g-xcvx-ppv2", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-46325" + ], + "details": "TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46325" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TP-LINK/WR740N/popupSiteSurveyRpm.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mg96-4cjg-fvrq/GHSA-mg96-4cjg-fvrq.json b/advisories/unreviewed/2024/10/GHSA-mg96-4cjg-fvrq/GHSA-mg96-4cjg-fvrq.json new file mode 100644 index 00000000000..6e448cd96cf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mg96-4cjg-fvrq/GHSA-mg96-4cjg-fvrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg96-4cjg-fvrq", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2023-6362" + ], + "details": "A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6362" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-winhex" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json b/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json index 561faa79cab..054442d8abf 100644 --- a/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json +++ b/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvx6-xfx7-r23g", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-07T15:31:38Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41511" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick" + }, + { + "type": "WEB", + "url": "http://cadclick.de" + }, + { + "type": "WEB", + "url": "http://kimweb.de" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-p4vj-j2w3-773m/GHSA-p4vj-j2w3-773m.json b/advisories/unreviewed/2024/10/GHSA-p4vj-j2w3-773m/GHSA-p4vj-j2w3-773m.json new file mode 100644 index 00000000000..f2fb80ccb1f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p4vj-j2w3-773m/GHSA-p4vj-j2w3-773m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4vj-j2w3-773m", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33069" + ], + "details": "Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33069" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pgfh-74x2-2w43/GHSA-pgfh-74x2-2w43.json b/advisories/unreviewed/2024/10/GHSA-pgfh-74x2-2w43/GHSA-pgfh-74x2-2w43.json new file mode 100644 index 00000000000..8c89865ccc7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pgfh-74x2-2w43/GHSA-pgfh-74x2-2w43.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgfh-74x2-2w43", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-45933" + ], + "details": "OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45933" + }, + { + "type": "WEB", + "url": "https://github.com/AslamMahi/CVE-Aslam-Mahi/blob/main/MobinaJafarian-OnlineNewsSite%20v%201.0/CVE-2024-45933.md" + }, + { + "type": "WEB", + "url": "http://TobeReleased.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ppw7-rj8j-p8c2/GHSA-ppw7-rj8j-p8c2.json b/advisories/unreviewed/2024/10/GHSA-ppw7-rj8j-p8c2/GHSA-ppw7-rj8j-p8c2.json new file mode 100644 index 00000000000..0620ccd6054 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ppw7-rj8j-p8c2/GHSA-ppw7-rj8j-p8c2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppw7-rj8j-p8c2", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-45153" + ], + "details": "Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45153" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qcr4-m6wf-h33w/GHSA-qcr4-m6wf-h33w.json b/advisories/unreviewed/2024/10/GHSA-qcr4-m6wf-h33w/GHSA-qcr4-m6wf-h33w.json new file mode 100644 index 00000000000..be77b423ce7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qcr4-m6wf-h33w/GHSA-qcr4-m6wf-h33w.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcr4-m6wf-h33w", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9567" + ], + "details": "A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the function formAdvFirewall of the file /goform/formAdvFirewall. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9567" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formAdvFirewall.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279461" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279461" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.414544" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json b/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json new file mode 100644 index 00000000000..ad8896f782b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgvh-3gr3-j9ph", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33070" + ], + "details": "Transient DOS while parsing ESP IE from beacon/probe response frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33070" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qj96-v6mr-fxhc/GHSA-qj96-v6mr-fxhc.json b/advisories/unreviewed/2024/10/GHSA-qj96-v6mr-fxhc/GHSA-qj96-v6mr-fxhc.json new file mode 100644 index 00000000000..156b40d74b5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qj96-v6mr-fxhc/GHSA-qj96-v6mr-fxhc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj96-v6mr-fxhc", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-33066" + ], + "details": "Memory corruption while redirecting log file to any file location with any file name.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33066" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rjwx-3ghx-2cr8/GHSA-rjwx-3ghx-2cr8.json b/advisories/unreviewed/2024/10/GHSA-rjwx-3ghx-2cr8/GHSA-rjwx-3ghx-2cr8.json new file mode 100644 index 00000000000..9804063468e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rjwx-3ghx-2cr8/GHSA-rjwx-3ghx-2cr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjwx-3ghx-2cr8", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-38397" + ], + "details": "Transient DOS while parsing probe response and assoc response frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38397" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rqp6-8mfq-gp8w/GHSA-rqp6-8mfq-gp8w.json b/advisories/unreviewed/2024/10/GHSA-rqp6-8mfq-gp8w/GHSA-rqp6-8mfq-gp8w.json new file mode 100644 index 00000000000..5c8dfa45750 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rqp6-8mfq-gp8w/GHSA-rqp6-8mfq-gp8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqp6-8mfq-gp8w", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2023-6361" + ], + "details": "A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6361" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-winhex" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x9gf-8wx8-vgh8/GHSA-x9gf-8wx8-vgh8.json b/advisories/unreviewed/2024/10/GHSA-x9gf-8wx8-vgh8/GHSA-x9gf-8wx8-vgh8.json new file mode 100644 index 00000000000..27985885f81 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x9gf-8wx8-vgh8/GHSA-x9gf-8wx8-vgh8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9gf-8wx8-vgh8", + "modified": "2024-10-07T15:31:39Z", + "published": "2024-10-07T15:31:39Z", + "aliases": [ + "CVE-2024-9573" + ], + "details": "SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9573" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-soplanning" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T15:15:10Z" + } +} \ No newline at end of file