From ffba6dd8f670f12eabf11946bea1208c6c5672c1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Oct 2024 21:31:58 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-mc76-5925-c5p6.json | 6 ++- .../GHSA-3r4p-wv9v-57xw.json | 2 +- .../GHSA-92f7-f2c6-vjr8.json | 7 ++- .../GHSA-hjmx-gcwh-p66v.json | 3 +- .../GHSA-pp6p-gh63-62xr.json | 2 +- .../GHSA-q868-g69p-72cw.json | 2 +- .../GHSA-cch8-vp96-g53m.json | 2 +- .../GHSA-h5gp-9w8f-f2p2.json | 2 +- .../GHSA-r39w-v7w4-p94f.json | 2 +- .../GHSA-m4mp-v249-x3mh.json | 2 +- .../GHSA-79q7-m98p-qvhp.json | 2 +- .../GHSA-gq45-c76q-q33j.json | 4 +- .../GHSA-54jg-mrhp-6457.json | 11 +++-- .../GHSA-5p62-ppjr-4c45.json | 1 + .../GHSA-8v8c-vvrq-xph7.json | 11 +++-- .../GHSA-rq57-8pjv-c6r7.json | 2 +- .../GHSA-v4wq-4595-gr53.json | 9 ++-- .../GHSA-xv8j-86xh-qr5w.json | 11 +++-- .../GHSA-q9mv-48mg-vv6w.json | 2 +- .../GHSA-24jq-7r79-4823.json | 39 +++++++++++++++ .../GHSA-2grc-rqmm-2cj8.json | 38 +++++++++++++++ .../GHSA-2hcc-cvcm-gcc5.json | 38 +++++++++++++++ .../GHSA-2hwf-hm8p-fc5c.json | 38 +++++++++++++++ .../GHSA-2rhg-4865-8qfj.json | 38 +++++++++++++++ .../GHSA-2v35-wwj6-wx66.json | 38 +++++++++++++++ .../GHSA-3256-qjh9-28j9.json | 35 ++++++++++++++ .../GHSA-35j4-qh5f-vwv5.json | 38 +++++++++++++++ .../GHSA-36gq-2499-pq9x.json | 38 +++++++++++++++ .../GHSA-38cv-f4xg-5272.json | 38 +++++++++++++++ .../GHSA-3hqc-72mc-jjr3.json | 35 ++++++++++++++ .../GHSA-3j36-mj45-fgp4.json | 39 +++++++++++++++ .../GHSA-4p7w-7m44-gvj9.json | 11 +++-- .../GHSA-4wvc-3vgh-543q.json | 35 ++++++++++++++ .../GHSA-526v-fwq8-9pgv.json | 38 +++++++++++++++ .../GHSA-528v-jf9w-58xh.json | 11 +++-- .../GHSA-545v-m4hv-f5f2.json | 11 +++-- .../GHSA-5579-pjqg-g858.json | 38 +++++++++++++++ .../GHSA-5624-47cx-2qwc.json | 11 +++-- .../GHSA-586r-qxpv-m44q.json | 11 +++-- .../GHSA-5h9p-4mfg-hmh4.json | 11 +++-- .../GHSA-625p-xh6m-38mc.json | 38 +++++++++++++++ .../GHSA-62q5-36cp-484h.json | 11 +++-- .../GHSA-62xv-gxq8-gpgw.json | 38 +++++++++++++++ .../GHSA-6477-mq9q-6867.json | 38 +++++++++++++++ .../GHSA-6pjm-6xcx-c94q.json | 38 +++++++++++++++ .../GHSA-6qgf-rh7g-g5v9.json | 38 +++++++++++++++ .../GHSA-6vrv-p2wx-g2fg.json | 38 +++++++++++++++ .../GHSA-78hg-6jfm-9v5w.json | 38 +++++++++++++++ .../GHSA-7c7g-86f2-3w2x.json | 39 +++++++++++++++ .../GHSA-7ppc-7q95-ccw3.json | 39 +++++++++++++++ .../GHSA-7v2q-xf3f-pfhp.json | 11 +++-- .../GHSA-7x8f-79rh-qg88.json | 38 +++++++++++++++ .../GHSA-85c7-pjjf-rphq.json | 38 +++++++++++++++ .../GHSA-894f-wmfc-4vj2.json | 38 +++++++++++++++ .../GHSA-89v2-8rj2-3464.json | 39 +++++++++++++++ .../GHSA-8gw4-4gr2-h2mr.json | 38 +++++++++++++++ .../GHSA-8h4j-cm33-q84h.json | 38 +++++++++++++++ .../GHSA-8jpg-62jc-hwhr.json | 46 ++++++++++++++++++ .../GHSA-8qjp-f639-q7hx.json | 39 +++++++++++++++ .../GHSA-9224-ggvw-wh7v.json | 46 ++++++++++++++++++ .../GHSA-945q-vj74-93vc.json | 38 +++++++++++++++ .../GHSA-985w-h5mh-4mgr.json | 38 +++++++++++++++ .../GHSA-99cw-3x24-r8wh.json | 11 +++-- .../GHSA-99gw-cq6g-rhmm.json | 38 +++++++++++++++ .../GHSA-9mwp-24h8-4c8f.json | 11 +++-- .../GHSA-9pq2-vmj6-97q4.json | 39 +++++++++++++++ .../GHSA-9w49-jqr4-2979.json | 35 ++++++++++++++ .../GHSA-c2h4-jx6m-jp2q.json | 39 +++++++++++++++ .../GHSA-c2r9-g2wq-7mfp.json | 38 +++++++++++++++ .../GHSA-c494-hg27-rg85.json | 38 +++++++++++++++ .../GHSA-c5xj-vg6h-cc3w.json | 38 +++++++++++++++ .../GHSA-c72q-9j4p-2mp4.json | 38 +++++++++++++++ .../GHSA-c949-x39f-qgxh.json | 38 +++++++++++++++ .../GHSA-cgw6-mmr2-9474.json | 38 +++++++++++++++ .../GHSA-cj7p-fg4w-qrvh.json | 38 +++++++++++++++ .../GHSA-f5r3-qx7g-cx6v.json | 11 +++-- .../GHSA-f8jx-5r24-p453.json | 39 +++++++++++++++ .../GHSA-fjvg-5x2f-67rq.json | 38 +++++++++++++++ .../GHSA-fv75-hjwp-hmcm.json | 38 +++++++++++++++ .../GHSA-g2c9-54g5-q442.json | 38 +++++++++++++++ .../GHSA-gcf7-xv2h-qvv7.json | 11 +++-- .../GHSA-ggjq-q4p4-jmg6.json | 38 +++++++++++++++ .../GHSA-gj3r-7jjv-636h.json | 39 +++++++++++++++ .../GHSA-gp4x-q6rm-qp9m.json | 38 +++++++++++++++ .../GHSA-h3ph-4h6g-xqfq.json | 38 +++++++++++++++ .../GHSA-h5h2-jj79-rjrp.json | 39 +++++++++++++++ .../GHSA-h83f-w3v7-qh8v.json | 11 +++-- .../GHSA-hf48-3p5r-fp4x.json | 38 +++++++++++++++ .../GHSA-hgjp-83m4-h4fj.json | 38 +++++++++++++++ .../GHSA-hj6p-xwh2-fc4f.json | 38 +++++++++++++++ .../GHSA-hq46-pffv-g6wr.json | 11 +++-- .../GHSA-hvmp-w9jw-p62g.json | 38 +++++++++++++++ .../GHSA-hxx7-vhm6-3427.json | 2 +- .../GHSA-j4c2-c778-c3qh.json | 38 +++++++++++++++ .../GHSA-j5r3-hxmp-cxpr.json | 38 +++++++++++++++ .../GHSA-j6j9-m952-pp68.json | 39 +++++++++++++++ .../GHSA-j8c9-3ff4-h2r8.json | 38 +++++++++++++++ .../GHSA-j8x2-fpjj-2hvp.json | 9 ++-- .../GHSA-j9pm-88v7-rvp8.json | 38 +++++++++++++++ .../GHSA-jp5h-88vf-2qp5.json | 38 +++++++++++++++ .../GHSA-jr6g-h572-57hf.json | 38 +++++++++++++++ .../GHSA-jv2x-g26c-46cq.json | 38 +++++++++++++++ .../GHSA-m2x9-pvwq-m49p.json | 38 +++++++++++++++ .../GHSA-m3rx-w78v-9p56.json | 38 +++++++++++++++ .../GHSA-m5cv-jfxj-8vmh.json | 38 +++++++++++++++ .../GHSA-m6rg-98pc-7rxm.json | 38 +++++++++++++++ .../GHSA-m7m4-4xr8-g97p.json | 38 +++++++++++++++ .../GHSA-m7rw-p49v-xvr4.json | 38 +++++++++++++++ .../GHSA-mffh-p59m-fv66.json | 38 +++++++++++++++ .../GHSA-mph2-q2f9-pccr.json | 38 +++++++++++++++ .../GHSA-mq75-p9mg-fj7f.json | 38 +++++++++++++++ .../GHSA-mrwv-hx59-25f7.json | 35 ++++++++++++++ .../GHSA-mv25-xprv-qhqh.json | 38 +++++++++++++++ .../GHSA-mw6x-r32h-w49v.json | 38 +++++++++++++++ .../GHSA-mwf7-wfvq-vc32.json | 47 +++++++++++++++++++ .../GHSA-mwrg-g727-8qpv.json | 38 +++++++++++++++ .../GHSA-mx69-86h6-r53c.json | 38 +++++++++++++++ .../GHSA-pg57-jx9m-63x8.json | 38 +++++++++++++++ .../GHSA-pgqq-75j6-62mw.json | 38 +++++++++++++++ .../GHSA-phgw-9rj7-xgp6.json | 38 +++++++++++++++ .../GHSA-pm45-f424-qf9f.json | 38 +++++++++++++++ .../GHSA-pxc7-gxxv-7pxc.json | 35 ++++++++++++++ .../GHSA-q5rv-w3vj-5jjx.json | 38 +++++++++++++++ .../GHSA-q77p-j5gj-rmw2.json | 35 ++++++++++++++ .../GHSA-q7mg-8rwj-gmwq.json | 35 ++++++++++++++ .../GHSA-q8jf-j34w-q74g.json | 39 +++++++++++++++ .../GHSA-qfc4-qvg8-vmjr.json | 35 ++++++++++++++ .../GHSA-qg3h-rf5x-68cv.json | 43 +++++++++++++++++ .../GHSA-qq87-cr9r-6pj4.json | 38 +++++++++++++++ .../GHSA-r389-865g-hcg3.json | 38 +++++++++++++++ .../GHSA-r97q-xhcv-9xx9.json | 38 +++++++++++++++ .../GHSA-rfgc-w4c4-wfq8.json | 11 +++-- .../GHSA-rv92-jf3g-p8qp.json | 38 +++++++++++++++ .../GHSA-v2h4-8467-fm2m.json | 38 +++++++++++++++ .../GHSA-v3cc-4rr8-r8xv.json | 38 +++++++++++++++ .../GHSA-v84m-m2mf-cxcm.json | 35 ++++++++++++++ .../GHSA-v85r-m9wc-pprx.json | 38 +++++++++++++++ .../GHSA-vchj-ggm5-9rcm.json | 38 +++++++++++++++ .../GHSA-vggh-55p7-p625.json | 38 +++++++++++++++ .../GHSA-vhqv-fr8v-3cwq.json | 38 +++++++++++++++ .../GHSA-vqmm-339w-hc7c.json | 38 +++++++++++++++ .../GHSA-w2p9-j475-2wp5.json | 39 +++++++++++++++ .../GHSA-w326-rf25-93cq.json | 38 +++++++++++++++ .../GHSA-w475-fv8v-qxrm.json | 11 +++-- .../GHSA-w47r-whp2-pxw8.json | 6 ++- .../GHSA-w5f9-2p82-v83j.json | 38 +++++++++++++++ .../GHSA-w76f-wfx3-5qjq.json | 38 +++++++++++++++ .../GHSA-w8wj-7hcm-8qpr.json | 11 +++-- .../GHSA-wc4w-3525-x87q.json | 38 +++++++++++++++ .../GHSA-wp8c-mcg4-hh47.json | 38 +++++++++++++++ .../GHSA-wq2p-5pc6-wpgf.json | 6 ++- .../GHSA-xcwx-vhj6-p7m7.json | 38 +++++++++++++++ .../GHSA-xfqq-7659-m6jq.json | 38 +++++++++++++++ .../GHSA-xhf9-m56c-xh6w.json | 38 +++++++++++++++ .../GHSA-xhr3-wf7j-h255.json | 39 +++++++++++++++ .../GHSA-xmw4-wxv9-hm5g.json | 38 +++++++++++++++ 156 files changed, 4611 insertions(+), 105 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-24jq-7r79-4823/GHSA-24jq-7r79-4823.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2grc-rqmm-2cj8/GHSA-2grc-rqmm-2cj8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2hcc-cvcm-gcc5/GHSA-2hcc-cvcm-gcc5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2hwf-hm8p-fc5c/GHSA-2hwf-hm8p-fc5c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2rhg-4865-8qfj/GHSA-2rhg-4865-8qfj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2v35-wwj6-wx66/GHSA-2v35-wwj6-wx66.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3256-qjh9-28j9/GHSA-3256-qjh9-28j9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-35j4-qh5f-vwv5/GHSA-35j4-qh5f-vwv5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-36gq-2499-pq9x/GHSA-36gq-2499-pq9x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-38cv-f4xg-5272/GHSA-38cv-f4xg-5272.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4wvc-3vgh-543q/GHSA-4wvc-3vgh-543q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-526v-fwq8-9pgv/GHSA-526v-fwq8-9pgv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5579-pjqg-g858/GHSA-5579-pjqg-g858.json create mode 100644 advisories/unreviewed/2024/10/GHSA-625p-xh6m-38mc/GHSA-625p-xh6m-38mc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-62xv-gxq8-gpgw/GHSA-62xv-gxq8-gpgw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6477-mq9q-6867/GHSA-6477-mq9q-6867.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6pjm-6xcx-c94q/GHSA-6pjm-6xcx-c94q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6qgf-rh7g-g5v9/GHSA-6qgf-rh7g-g5v9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6vrv-p2wx-g2fg/GHSA-6vrv-p2wx-g2fg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-78hg-6jfm-9v5w/GHSA-78hg-6jfm-9v5w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7c7g-86f2-3w2x/GHSA-7c7g-86f2-3w2x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7ppc-7q95-ccw3/GHSA-7ppc-7q95-ccw3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7x8f-79rh-qg88/GHSA-7x8f-79rh-qg88.json create mode 100644 advisories/unreviewed/2024/10/GHSA-85c7-pjjf-rphq/GHSA-85c7-pjjf-rphq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-894f-wmfc-4vj2/GHSA-894f-wmfc-4vj2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8gw4-4gr2-h2mr/GHSA-8gw4-4gr2-h2mr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8jpg-62jc-hwhr/GHSA-8jpg-62jc-hwhr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8qjp-f639-q7hx/GHSA-8qjp-f639-q7hx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9224-ggvw-wh7v/GHSA-9224-ggvw-wh7v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-99gw-cq6g-rhmm/GHSA-99gw-cq6g-rhmm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9pq2-vmj6-97q4/GHSA-9pq2-vmj6-97q4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c2r9-g2wq-7mfp/GHSA-c2r9-g2wq-7mfp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c494-hg27-rg85/GHSA-c494-hg27-rg85.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c72q-9j4p-2mp4/GHSA-c72q-9j4p-2mp4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cgw6-mmr2-9474/GHSA-cgw6-mmr2-9474.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cj7p-fg4w-qrvh/GHSA-cj7p-fg4w-qrvh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f8jx-5r24-p453/GHSA-f8jx-5r24-p453.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fv75-hjwp-hmcm/GHSA-fv75-hjwp-hmcm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g2c9-54g5-q442/GHSA-g2c9-54g5-q442.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ggjq-q4p4-jmg6/GHSA-ggjq-q4p4-jmg6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gp4x-q6rm-qp9m/GHSA-gp4x-q6rm-qp9m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h3ph-4h6g-xqfq/GHSA-h3ph-4h6g-xqfq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hgjp-83m4-h4fj/GHSA-hgjp-83m4-h4fj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hj6p-xwh2-fc4f/GHSA-hj6p-xwh2-fc4f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hvmp-w9jw-p62g/GHSA-hvmp-w9jw-p62g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j4c2-c778-c3qh/GHSA-j4c2-c778-c3qh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j5r3-hxmp-cxpr/GHSA-j5r3-hxmp-cxpr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j6j9-m952-pp68/GHSA-j6j9-m952-pp68.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j8c9-3ff4-h2r8/GHSA-j8c9-3ff4-h2r8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jp5h-88vf-2qp5/GHSA-jp5h-88vf-2qp5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jv2x-g26c-46cq/GHSA-jv2x-g26c-46cq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m2x9-pvwq-m49p/GHSA-m2x9-pvwq-m49p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m3rx-w78v-9p56/GHSA-m3rx-w78v-9p56.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m5cv-jfxj-8vmh/GHSA-m5cv-jfxj-8vmh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m6rg-98pc-7rxm/GHSA-m6rg-98pc-7rxm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m7m4-4xr8-g97p/GHSA-m7m4-4xr8-g97p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m7rw-p49v-xvr4/GHSA-m7rw-p49v-xvr4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mffh-p59m-fv66/GHSA-mffh-p59m-fv66.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mph2-q2f9-pccr/GHSA-mph2-q2f9-pccr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mq75-p9mg-fj7f/GHSA-mq75-p9mg-fj7f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mv25-xprv-qhqh/GHSA-mv25-xprv-qhqh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mx69-86h6-r53c/GHSA-mx69-86h6-r53c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pg57-jx9m-63x8/GHSA-pg57-jx9m-63x8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pgqq-75j6-62mw/GHSA-pgqq-75j6-62mw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-phgw-9rj7-xgp6/GHSA-phgw-9rj7-xgp6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pm45-f424-qf9f/GHSA-pm45-f424-qf9f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pxc7-gxxv-7pxc/GHSA-pxc7-gxxv-7pxc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q5rv-w3vj-5jjx/GHSA-q5rv-w3vj-5jjx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q7mg-8rwj-gmwq/GHSA-q7mg-8rwj-gmwq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r97q-xhcv-9xx9/GHSA-r97q-xhcv-9xx9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rv92-jf3g-p8qp/GHSA-rv92-jf3g-p8qp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v2h4-8467-fm2m/GHSA-v2h4-8467-fm2m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v3cc-4rr8-r8xv/GHSA-v3cc-4rr8-r8xv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v84m-m2mf-cxcm/GHSA-v84m-m2mf-cxcm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v85r-m9wc-pprx/GHSA-v85r-m9wc-pprx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vchj-ggm5-9rcm/GHSA-vchj-ggm5-9rcm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vggh-55p7-p625/GHSA-vggh-55p7-p625.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vqmm-339w-hc7c/GHSA-vqmm-339w-hc7c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w326-rf25-93cq/GHSA-w326-rf25-93cq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w5f9-2p82-v83j/GHSA-w5f9-2p82-v83j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w76f-wfx3-5qjq/GHSA-w76f-wfx3-5qjq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wp8c-mcg4-hh47/GHSA-wp8c-mcg4-hh47.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xcwx-vhj6-p7m7/GHSA-xcwx-vhj6-p7m7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xhf9-m56c-xh6w/GHSA-xhf9-m56c-xh6w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xmw4-wxv9-hm5g/GHSA-xmw4-wxv9-hm5g.json diff --git a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json index 353997fc56a..8ab521111c2 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json +++ b/advisories/github-reviewed/2024/10/GHSA-mc76-5925-c5p6/GHSA-mc76-5925-c5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mc76-5925-c5p6", - "modified": "2024-10-14T22:24:12Z", + "modified": "2024-10-15T21:30:36Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-9341" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:8039" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8112" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9341" diff --git a/advisories/unreviewed/2022/05/GHSA-3r4p-wv9v-57xw/GHSA-3r4p-wv9v-57xw.json b/advisories/unreviewed/2022/05/GHSA-3r4p-wv9v-57xw/GHSA-3r4p-wv9v-57xw.json index 61e187c178b..fd9d13611f6 100644 --- a/advisories/unreviewed/2022/05/GHSA-3r4p-wv9v-57xw/GHSA-3r4p-wv9v-57xw.json +++ b/advisories/unreviewed/2022/05/GHSA-3r4p-wv9v-57xw/GHSA-3r4p-wv9v-57xw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r4p-wv9v-57xw", - "modified": "2023-12-08T21:30:27Z", + "modified": "2024-10-15T21:30:31Z", "published": "2022-05-24T17:00:47Z", "aliases": [ "CVE-2019-18279" diff --git a/advisories/unreviewed/2022/05/GHSA-92f7-f2c6-vjr8/GHSA-92f7-f2c6-vjr8.json b/advisories/unreviewed/2022/05/GHSA-92f7-f2c6-vjr8/GHSA-92f7-f2c6-vjr8.json index d889f982042..c63a2a5da9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-92f7-f2c6-vjr8/GHSA-92f7-f2c6-vjr8.json +++ b/advisories/unreviewed/2022/05/GHSA-92f7-f2c6-vjr8/GHSA-92f7-f2c6-vjr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92f7-f2c6-vjr8", - "modified": "2022-05-02T06:09:48Z", + "modified": "2024-10-15T21:30:31Z", "published": "2022-05-02T06:09:48Z", "aliases": [ "CVE-2010-0036" ], "details": "Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-hjmx-gcwh-p66v/GHSA-hjmx-gcwh-p66v.json b/advisories/unreviewed/2022/05/GHSA-hjmx-gcwh-p66v/GHSA-hjmx-gcwh-p66v.json index 98897bc7aeb..ead2ce13309 100644 --- a/advisories/unreviewed/2022/05/GHSA-hjmx-gcwh-p66v/GHSA-hjmx-gcwh-p66v.json +++ b/advisories/unreviewed/2022/05/GHSA-hjmx-gcwh-p66v/GHSA-hjmx-gcwh-p66v.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-pp6p-gh63-62xr/GHSA-pp6p-gh63-62xr.json b/advisories/unreviewed/2022/05/GHSA-pp6p-gh63-62xr/GHSA-pp6p-gh63-62xr.json index 13329da9f9a..772d85552c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-pp6p-gh63-62xr/GHSA-pp6p-gh63-62xr.json +++ b/advisories/unreviewed/2022/05/GHSA-pp6p-gh63-62xr/GHSA-pp6p-gh63-62xr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pp6p-gh63-62xr", - "modified": "2022-11-07T19:00:18Z", + "modified": "2024-10-15T21:30:32Z", "published": "2022-05-24T19:07:07Z", "aliases": [ "CVE-2021-34620" diff --git a/advisories/unreviewed/2022/05/GHSA-q868-g69p-72cw/GHSA-q868-g69p-72cw.json b/advisories/unreviewed/2022/05/GHSA-q868-g69p-72cw/GHSA-q868-g69p-72cw.json index fff129fb480..41a68608d64 100644 --- a/advisories/unreviewed/2022/05/GHSA-q868-g69p-72cw/GHSA-q868-g69p-72cw.json +++ b/advisories/unreviewed/2022/05/GHSA-q868-g69p-72cw/GHSA-q868-g69p-72cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q868-g69p-72cw", - "modified": "2024-02-03T09:30:16Z", + "modified": "2024-10-15T21:30:31Z", "published": "2022-05-24T17:33:09Z", "aliases": [ "CVE-2020-28049" diff --git a/advisories/unreviewed/2022/07/GHSA-cch8-vp96-g53m/GHSA-cch8-vp96-g53m.json b/advisories/unreviewed/2022/07/GHSA-cch8-vp96-g53m/GHSA-cch8-vp96-g53m.json index 77d4325eb9b..bb0757cbb20 100644 --- a/advisories/unreviewed/2022/07/GHSA-cch8-vp96-g53m/GHSA-cch8-vp96-g53m.json +++ b/advisories/unreviewed/2022/07/GHSA-cch8-vp96-g53m/GHSA-cch8-vp96-g53m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cch8-vp96-g53m", - "modified": "2022-07-26T00:00:27Z", + "modified": "2024-10-15T21:30:32Z", "published": "2022-07-18T00:00:32Z", "aliases": [ "CVE-2022-30550" diff --git a/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json b/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json index 17e97829f2a..b53a24b5982 100644 --- a/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json +++ b/advisories/unreviewed/2023/07/GHSA-h5gp-9w8f-f2p2/GHSA-h5gp-9w8f-f2p2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5gp-9w8f-f2p2", - "modified": "2023-12-15T18:30:27Z", + "modified": "2024-10-15T21:30:32Z", "published": "2023-07-18T00:31:08Z", "aliases": [ "CVE-2023-38428" diff --git a/advisories/unreviewed/2023/07/GHSA-r39w-v7w4-p94f/GHSA-r39w-v7w4-p94f.json b/advisories/unreviewed/2023/07/GHSA-r39w-v7w4-p94f/GHSA-r39w-v7w4-p94f.json index 2d42b2d2c1c..6692de0c19e 100644 --- a/advisories/unreviewed/2023/07/GHSA-r39w-v7w4-p94f/GHSA-r39w-v7w4-p94f.json +++ b/advisories/unreviewed/2023/07/GHSA-r39w-v7w4-p94f/GHSA-r39w-v7w4-p94f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r39w-v7w4-p94f", - "modified": "2024-01-07T12:30:29Z", + "modified": "2024-10-15T21:30:32Z", "published": "2023-07-05T12:30:15Z", "aliases": [ "CVE-2023-37203" diff --git a/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json b/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json index 29bdc8c5051..bb6bdf1617a 100644 --- a/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json +++ b/advisories/unreviewed/2023/10/GHSA-m4mp-v249-x3mh/GHSA-m4mp-v249-x3mh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4mp-v249-x3mh", - "modified": "2024-10-14T09:30:52Z", + "modified": "2024-10-15T21:30:33Z", "published": "2023-10-23T09:30:18Z", "aliases": [ "CVE-2023-45802" diff --git a/advisories/unreviewed/2023/11/GHSA-79q7-m98p-qvhp/GHSA-79q7-m98p-qvhp.json b/advisories/unreviewed/2023/11/GHSA-79q7-m98p-qvhp/GHSA-79q7-m98p-qvhp.json index a4a3200911d..ded070751ff 100644 --- a/advisories/unreviewed/2023/11/GHSA-79q7-m98p-qvhp/GHSA-79q7-m98p-qvhp.json +++ b/advisories/unreviewed/2023/11/GHSA-79q7-m98p-qvhp/GHSA-79q7-m98p-qvhp.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-gq45-c76q-q33j/GHSA-gq45-c76q-q33j.json b/advisories/unreviewed/2023/11/GHSA-gq45-c76q-q33j/GHSA-gq45-c76q-q33j.json index e3c5e1dde05..15d76906a31 100644 --- a/advisories/unreviewed/2023/11/GHSA-gq45-c76q-q33j/GHSA-gq45-c76q-q33j.json +++ b/advisories/unreviewed/2023/11/GHSA-gq45-c76q-q33j/GHSA-gq45-c76q-q33j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gq45-c76q-q33j", - "modified": "2023-11-22T18:30:54Z", + "modified": "2024-10-15T21:30:33Z", "published": "2023-11-17T06:31:21Z", "aliases": [ "CVE-2023-48655" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-116" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-54jg-mrhp-6457/GHSA-54jg-mrhp-6457.json b/advisories/unreviewed/2024/06/GHSA-54jg-mrhp-6457/GHSA-54jg-mrhp-6457.json index 0078558c8c8..821a7e02540 100644 --- a/advisories/unreviewed/2024/06/GHSA-54jg-mrhp-6457/GHSA-54jg-mrhp-6457.json +++ b/advisories/unreviewed/2024/06/GHSA-54jg-mrhp-6457/GHSA-54jg-mrhp-6457.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54jg-mrhp-6457", - "modified": "2024-06-07T00:30:36Z", + "modified": "2024-10-15T21:30:35Z", "published": "2024-06-07T00:30:36Z", "aliases": [ "CVE-2024-22525" ], "details": "dnspod-sr 0dfbd37 contains a SEGV.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5p62-ppjr-4c45/GHSA-5p62-ppjr-4c45.json b/advisories/unreviewed/2024/06/GHSA-5p62-ppjr-4c45/GHSA-5p62-ppjr-4c45.json index bbd4efbf81f..37aea65f78c 100644 --- a/advisories/unreviewed/2024/06/GHSA-5p62-ppjr-4c45/GHSA-5p62-ppjr-4c45.json +++ b/advisories/unreviewed/2024/06/GHSA-5p62-ppjr-4c45/GHSA-5p62-ppjr-4c45.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-29" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/06/GHSA-8v8c-vvrq-xph7/GHSA-8v8c-vvrq-xph7.json b/advisories/unreviewed/2024/06/GHSA-8v8c-vvrq-xph7/GHSA-8v8c-vvrq-xph7.json index 94836fc012d..2f919867860 100644 --- a/advisories/unreviewed/2024/06/GHSA-8v8c-vvrq-xph7/GHSA-8v8c-vvrq-xph7.json +++ b/advisories/unreviewed/2024/06/GHSA-8v8c-vvrq-xph7/GHSA-8v8c-vvrq-xph7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v8c-vvrq-xph7", - "modified": "2024-06-07T00:30:36Z", + "modified": "2024-10-15T21:30:35Z", "published": "2024-06-07T00:30:36Z", "aliases": [ "CVE-2024-22524" ], "details": "dnspod-sr 0dfbd37 is vulnerable to buffer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-rq57-8pjv-c6r7/GHSA-rq57-8pjv-c6r7.json b/advisories/unreviewed/2024/06/GHSA-rq57-8pjv-c6r7/GHSA-rq57-8pjv-c6r7.json index 2835ba4aec1..9ae91d2fddf 100644 --- a/advisories/unreviewed/2024/06/GHSA-rq57-8pjv-c6r7/GHSA-rq57-8pjv-c6r7.json +++ b/advisories/unreviewed/2024/06/GHSA-rq57-8pjv-c6r7/GHSA-rq57-8pjv-c6r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rq57-8pjv-c6r7", - "modified": "2024-06-06T21:30:36Z", + "modified": "2024-10-15T21:30:34Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-22326" diff --git a/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json b/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json index 104f1a90cdf..d725b6c0096 100644 --- a/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json +++ b/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4wq-4595-gr53", - "modified": "2024-06-06T21:30:36Z", + "modified": "2024-10-15T21:30:34Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-36735" ], "details": "OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T19:15:58Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xv8j-86xh-qr5w/GHSA-xv8j-86xh-qr5w.json b/advisories/unreviewed/2024/06/GHSA-xv8j-86xh-qr5w/GHSA-xv8j-86xh-qr5w.json index e57341c958c..a4719764a5d 100644 --- a/advisories/unreviewed/2024/06/GHSA-xv8j-86xh-qr5w/GHSA-xv8j-86xh-qr5w.json +++ b/advisories/unreviewed/2024/06/GHSA-xv8j-86xh-qr5w/GHSA-xv8j-86xh-qr5w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv8j-86xh-qr5w", - "modified": "2024-06-06T21:30:36Z", + "modified": "2024-10-15T21:30:34Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-36730" ], "details": "Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T19:15:57Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json b/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json index a4574ee2690..2cf3f0b2f5e 100644 --- a/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json +++ b/advisories/unreviewed/2024/07/GHSA-q9mv-48mg-vv6w/GHSA-q9mv-48mg-vv6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9mv-48mg-vv6w", - "modified": "2024-07-08T15:31:55Z", + "modified": "2024-10-15T21:30:36Z", "published": "2024-07-01T18:32:40Z", "aliases": [ "CVE-2024-36985" diff --git a/advisories/unreviewed/2024/10/GHSA-24jq-7r79-4823/GHSA-24jq-7r79-4823.json b/advisories/unreviewed/2024/10/GHSA-24jq-7r79-4823/GHSA-24jq-7r79-4823.json new file mode 100644 index 00000000000..fb2bae7b7df --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-24jq-7r79-4823/GHSA-24jq-7r79-4823.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24jq-7r79-4823", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-49195" + ], + "details": "Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49195" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-10-1" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/tech-updates/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2grc-rqmm-2cj8/GHSA-2grc-rqmm-2cj8.json b/advisories/unreviewed/2024/10/GHSA-2grc-rqmm-2cj8/GHSA-2grc-rqmm-2cj8.json new file mode 100644 index 00000000000..5d38ddae9ee --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2grc-rqmm-2cj8/GHSA-2grc-rqmm-2cj8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2grc-rqmm-2cj8", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21263" + ], + "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21263" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2hcc-cvcm-gcc5/GHSA-2hcc-cvcm-gcc5.json b/advisories/unreviewed/2024/10/GHSA-2hcc-cvcm-gcc5/GHSA-2hcc-cvcm-gcc5.json new file mode 100644 index 00000000000..0c755edc0df --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2hcc-cvcm-gcc5/GHSA-2hcc-cvcm-gcc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hcc-cvcm-gcc5", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21202" + ], + "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21202" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2hwf-hm8p-fc5c/GHSA-2hwf-hm8p-fc5c.json b/advisories/unreviewed/2024/10/GHSA-2hwf-hm8p-fc5c/GHSA-2hwf-hm8p-fc5c.json new file mode 100644 index 00000000000..d88babc0b84 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2hwf-hm8p-fc5c/GHSA-2hwf-hm8p-fc5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hwf-hm8p-fc5c", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-41344" + ], + "details": "A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41344" + }, + { + "type": "WEB", + "url": "https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/issues/264" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2rhg-4865-8qfj/GHSA-2rhg-4865-8qfj.json b/advisories/unreviewed/2024/10/GHSA-2rhg-4865-8qfj/GHSA-2rhg-4865-8qfj.json new file mode 100644 index 00000000000..2482920f4c0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2rhg-4865-8qfj/GHSA-2rhg-4865-8qfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rhg-4865-8qfj", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21236" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21236" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2v35-wwj6-wx66/GHSA-2v35-wwj6-wx66.json b/advisories/unreviewed/2024/10/GHSA-2v35-wwj6-wx66/GHSA-2v35-wwj6-wx66.json new file mode 100644 index 00000000000..7af69fe8414 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2v35-wwj6-wx66/GHSA-2v35-wwj6-wx66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v35-wwj6-wx66", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21284" + ], + "details": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21284" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3256-qjh9-28j9/GHSA-3256-qjh9-28j9.json b/advisories/unreviewed/2024/10/GHSA-3256-qjh9-28j9/GHSA-3256-qjh9-28j9.json new file mode 100644 index 00000000000..0b456cc6a2b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3256-qjh9-28j9/GHSA-3256-qjh9-28j9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3256-qjh9-28j9", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48713" + ], + "details": "In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48713" + }, + { + "type": "WEB", + "url": "https://github.com/sezangel/IOT-vul/blob/main/TPlink/TL-WDR7660/4/read.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-35j4-qh5f-vwv5/GHSA-35j4-qh5f-vwv5.json b/advisories/unreviewed/2024/10/GHSA-35j4-qh5f-vwv5/GHSA-35j4-qh5f-vwv5.json new file mode 100644 index 00000000000..acb7a8cd24b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-35j4-qh5f-vwv5/GHSA-35j4-qh5f-vwv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35j4-qh5f-vwv5", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21195" + ], + "details": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21195" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-36gq-2499-pq9x/GHSA-36gq-2499-pq9x.json b/advisories/unreviewed/2024/10/GHSA-36gq-2499-pq9x/GHSA-36gq-2499-pq9x.json new file mode 100644 index 00000000000..6a226cef34b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-36gq-2499-pq9x/GHSA-36gq-2499-pq9x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36gq-2499-pq9x", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21244" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21244" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-38cv-f4xg-5272/GHSA-38cv-f4xg-5272.json b/advisories/unreviewed/2024/10/GHSA-38cv-f4xg-5272/GHSA-38cv-f4xg-5272.json new file mode 100644 index 00000000000..88577da163d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-38cv-f4xg-5272/GHSA-38cv-f4xg-5272.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38cv-f4xg-5272", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21273" + ], + "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21273" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json b/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json new file mode 100644 index 00000000000..29692e28d65 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3hqc-72mc-jjr3/GHSA-3hqc-72mc-jjr3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hqc-72mc-jjr3", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48779" + ], + "details": "An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48779" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zty-1995/3fcdf702017ad6721e5011f74c1f6cee" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json b/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json new file mode 100644 index 00000000000..5fe5bd4bbcb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j36-mj45-fgp4", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9960" + ], + "details": "Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9960" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/354748063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json b/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json index 5a2ee416d99..184ce008ef5 100644 --- a/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json +++ b/advisories/unreviewed/2024/10/GHSA-4p7w-7m44-gvj9/GHSA-4p7w-7m44-gvj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4p7w-7m44-gvj9", - "modified": "2024-10-11T21:31:34Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:34Z", "aliases": [ "CVE-2024-48775" ], "details": "An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4wvc-3vgh-543q/GHSA-4wvc-3vgh-543q.json b/advisories/unreviewed/2024/10/GHSA-4wvc-3vgh-543q/GHSA-4wvc-3vgh-543q.json new file mode 100644 index 00000000000..dbe6e502601 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4wvc-3vgh-543q/GHSA-4wvc-3vgh-543q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wvc-3vgh-543q", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48712" + ], + "details": "In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48712" + }, + { + "type": "WEB", + "url": "https://github.com/sezangel/IOT-vul/blob/main/TPlink/TL-WDR7660/3/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-526v-fwq8-9pgv/GHSA-526v-fwq8-9pgv.json b/advisories/unreviewed/2024/10/GHSA-526v-fwq8-9pgv/GHSA-526v-fwq8-9pgv.json new file mode 100644 index 00000000000..7c15fb4b8c0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-526v-fwq8-9pgv/GHSA-526v-fwq8-9pgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-526v-fwq8-9pgv", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21255" + ], + "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21255" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json b/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json index 2792022394a..526bb32f40f 100644 --- a/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json +++ b/advisories/unreviewed/2024/10/GHSA-528v-jf9w-58xh/GHSA-528v-jf9w-58xh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-528v-jf9w-58xh", - "modified": "2024-10-14T15:30:46Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-14T15:30:46Z", "aliases": [ "CVE-2024-48257" ], "details": "Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T15:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json b/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json index 337370439c1..e38f842edd3 100644 --- a/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json +++ b/advisories/unreviewed/2024/10/GHSA-545v-m4hv-f5f2/GHSA-545v-m4hv-f5f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-545v-m4hv-f5f2", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48777" ], "details": "LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5579-pjqg-g858/GHSA-5579-pjqg-g858.json b/advisories/unreviewed/2024/10/GHSA-5579-pjqg-g858/GHSA-5579-pjqg-g858.json new file mode 100644 index 00000000000..3a6a207d214 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5579-pjqg-g858/GHSA-5579-pjqg-g858.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5579-pjqg-g858", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21205" + ], + "details": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21205" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json b/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json index be8f6f7bcb1..8bf94e7a530 100644 --- a/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json +++ b/advisories/unreviewed/2024/10/GHSA-5624-47cx-2qwc/GHSA-5624-47cx-2qwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5624-47cx-2qwc", - "modified": "2024-10-14T15:30:45Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-14T15:30:45Z", "aliases": [ "CVE-2024-48253" ], "details": "Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T14:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json b/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json index 4f14ff1ea8d..fa80555fdbf 100644 --- a/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json +++ b/advisories/unreviewed/2024/10/GHSA-586r-qxpv-m44q/GHSA-586r-qxpv-m44q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-586r-qxpv-m44q", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-46468" ], "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json b/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json index 898c2941302..8601e72c870 100644 --- a/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json +++ b/advisories/unreviewed/2024/10/GHSA-5h9p-4mfg-hmh4/GHSA-5h9p-4mfg-hmh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h9p-4mfg-hmh4", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48786" ], "details": "An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-625p-xh6m-38mc/GHSA-625p-xh6m-38mc.json b/advisories/unreviewed/2024/10/GHSA-625p-xh6m-38mc/GHSA-625p-xh6m-38mc.json new file mode 100644 index 00000000000..c13bcd8c451 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-625p-xh6m-38mc/GHSA-625p-xh6m-38mc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-625p-xh6m-38mc", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21259" + ], + "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21259" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json b/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json index 9ad837e8bfe..ded9b7e0284 100644 --- a/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json +++ b/advisories/unreviewed/2024/10/GHSA-62q5-36cp-484h/GHSA-62q5-36cp-484h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-62q5-36cp-484h", - "modified": "2024-10-11T21:31:34Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:34Z", "aliases": [ "CVE-2024-48773" ], "details": "An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-62xv-gxq8-gpgw/GHSA-62xv-gxq8-gpgw.json b/advisories/unreviewed/2024/10/GHSA-62xv-gxq8-gpgw/GHSA-62xv-gxq8-gpgw.json new file mode 100644 index 00000000000..601175fcfe8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-62xv-gxq8-gpgw/GHSA-62xv-gxq8-gpgw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62xv-gxq8-gpgw", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21260" + ], + "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21260" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6477-mq9q-6867/GHSA-6477-mq9q-6867.json b/advisories/unreviewed/2024/10/GHSA-6477-mq9q-6867/GHSA-6477-mq9q-6867.json new file mode 100644 index 00000000000..04ba11018b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6477-mq9q-6867/GHSA-6477-mq9q-6867.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6477-mq9q-6867", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21209" + ], + "details": "Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 2.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21209" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6pjm-6xcx-c94q/GHSA-6pjm-6xcx-c94q.json b/advisories/unreviewed/2024/10/GHSA-6pjm-6xcx-c94q/GHSA-6pjm-6xcx-c94q.json new file mode 100644 index 00000000000..6fb9c57448f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6pjm-6xcx-c94q/GHSA-6pjm-6xcx-c94q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pjm-6xcx-c94q", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21243" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21243" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6qgf-rh7g-g5v9/GHSA-6qgf-rh7g-g5v9.json b/advisories/unreviewed/2024/10/GHSA-6qgf-rh7g-g5v9/GHSA-6qgf-rh7g-g5v9.json new file mode 100644 index 00000000000..e3ff71922f9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6qgf-rh7g-g5v9/GHSA-6qgf-rh7g-g5v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qgf-rh7g-g5v9", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21274" + ], + "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21274" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6vrv-p2wx-g2fg/GHSA-6vrv-p2wx-g2fg.json b/advisories/unreviewed/2024/10/GHSA-6vrv-p2wx-g2fg/GHSA-6vrv-p2wx-g2fg.json new file mode 100644 index 00000000000..454a462b5ff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6vrv-p2wx-g2fg/GHSA-6vrv-p2wx-g2fg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vrv-p2wx-g2fg", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21232" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21232" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-78hg-6jfm-9v5w/GHSA-78hg-6jfm-9v5w.json b/advisories/unreviewed/2024/10/GHSA-78hg-6jfm-9v5w/GHSA-78hg-6jfm-9v5w.json new file mode 100644 index 00000000000..34b59e71475 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-78hg-6jfm-9v5w/GHSA-78hg-6jfm-9v5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78hg-6jfm-9v5w", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21262" + ], + "details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21262" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7c7g-86f2-3w2x/GHSA-7c7g-86f2-3w2x.json b/advisories/unreviewed/2024/10/GHSA-7c7g-86f2-3w2x/GHSA-7c7g-86f2-3w2x.json new file mode 100644 index 00000000000..8ba6b32ee22 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7c7g-86f2-3w2x/GHSA-7c7g-86f2-3w2x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c7g-86f2-3w2x", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9965" + ], + "details": "Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9965" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/352651673" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7ppc-7q95-ccw3/GHSA-7ppc-7q95-ccw3.json b/advisories/unreviewed/2024/10/GHSA-7ppc-7q95-ccw3/GHSA-7ppc-7q95-ccw3.json new file mode 100644 index 00000000000..609b28e69cc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7ppc-7q95-ccw3/GHSA-7ppc-7q95-ccw3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ppc-7q95-ccw3", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9966" + ], + "details": "Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9966" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/364773822" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json b/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json index 6907b61d649..ca6789ce75f 100644 --- a/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json +++ b/advisories/unreviewed/2024/10/GHSA-7v2q-xf3f-pfhp/GHSA-7v2q-xf3f-pfhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7v2q-xf3f-pfhp", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48784" ], "details": "An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7x8f-79rh-qg88/GHSA-7x8f-79rh-qg88.json b/advisories/unreviewed/2024/10/GHSA-7x8f-79rh-qg88/GHSA-7x8f-79rh-qg88.json new file mode 100644 index 00000000000..717cf98ed89 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7x8f-79rh-qg88/GHSA-7x8f-79rh-qg88.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x8f-79rh-qg88", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21190" + ], + "details": "Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP to compromise Oracle Global Lifecycle Management FMW Installer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management FMW Installer accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21190" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-85c7-pjjf-rphq/GHSA-85c7-pjjf-rphq.json b/advisories/unreviewed/2024/10/GHSA-85c7-pjjf-rphq/GHSA-85c7-pjjf-rphq.json new file mode 100644 index 00000000000..32f9887ca0d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-85c7-pjjf-rphq/GHSA-85c7-pjjf-rphq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85c7-pjjf-rphq", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21192" + ], + "details": "Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Fusion Middleware (component: WebLogic Mgmt). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for Fusion Middleware executes to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Fusion Middleware accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21192" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-894f-wmfc-4vj2/GHSA-894f-wmfc-4vj2.json b/advisories/unreviewed/2024/10/GHSA-894f-wmfc-4vj2/GHSA-894f-wmfc-4vj2.json new file mode 100644 index 00000000000..b81620e7428 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-894f-wmfc-4vj2/GHSA-894f-wmfc-4vj2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-894f-wmfc-4vj2", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21214" + ], + "details": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21214" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json b/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json new file mode 100644 index 00000000000..b1a601be9a8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89v2-8rj2-3464", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9961" + ], + "details": "Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9961" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/357776197" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8gw4-4gr2-h2mr/GHSA-8gw4-4gr2-h2mr.json b/advisories/unreviewed/2024/10/GHSA-8gw4-4gr2-h2mr/GHSA-8gw4-4gr2-h2mr.json new file mode 100644 index 00000000000..6e2d502fbee --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8gw4-4gr2-h2mr/GHSA-8gw4-4gr2-h2mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gw4-4gr2-h2mr", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21217" + ], + "details": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21217" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json b/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json new file mode 100644 index 00000000000..e806b70a892 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8h4j-cm33-q84h/GHSA-8h4j-cm33-q84h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h4j-cm33-q84h", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-31955" + ], + "details": "An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31955" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8jpg-62jc-hwhr/GHSA-8jpg-62jc-hwhr.json b/advisories/unreviewed/2024/10/GHSA-8jpg-62jc-hwhr/GHSA-8jpg-62jc-hwhr.json new file mode 100644 index 00000000000..46c5d1a9687 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8jpg-62jc-hwhr/GHSA-8jpg-62jc-hwhr.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jpg-62jc-hwhr", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9594" + ], + "details": "A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9594" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes/kubernetes/issues/128007" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes-sigs/image-builder/pull/1596" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8qjp-f639-q7hx/GHSA-8qjp-f639-q7hx.json b/advisories/unreviewed/2024/10/GHSA-8qjp-f639-q7hx/GHSA-8qjp-f639-q7hx.json new file mode 100644 index 00000000000..e73e8d3a842 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8qjp-f639-q7hx/GHSA-8qjp-f639-q7hx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qjp-f639-q7hx", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9964" + ], + "details": "Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9964" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/361711121" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9224-ggvw-wh7v/GHSA-9224-ggvw-wh7v.json b/advisories/unreviewed/2024/10/GHSA-9224-ggvw-wh7v/GHSA-9224-ggvw-wh7v.json new file mode 100644 index 00000000000..977f909ecd0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9224-ggvw-wh7v/GHSA-9224-ggvw-wh7v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9224-ggvw-wh7v", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9486" + ], + "details": "A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9486" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes/kubernetes/issues/128006" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes-sigs/image-builder/pull/1595" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json b/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json new file mode 100644 index 00000000000..eeb7699bb6d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-945q-vj74-93vc", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21211" + ], + "details": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21211" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json b/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json new file mode 100644 index 00000000000..f9b9ec9334a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-985w-h5mh-4mgr/GHSA-985w-h5mh-4mgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-985w-h5mh-4mgr", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21250" + ], + "details": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Product Development accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Product Development accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21250" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json b/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json index 4645689d76b..ad75102266f 100644 --- a/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json +++ b/advisories/unreviewed/2024/10/GHSA-99cw-3x24-r8wh/GHSA-99cw-3x24-r8wh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-99cw-3x24-r8wh", - "modified": "2024-10-14T15:30:46Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-14T15:30:46Z", "aliases": [ "CVE-2024-48259" ], "details": "Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T15:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-99gw-cq6g-rhmm/GHSA-99gw-cq6g-rhmm.json b/advisories/unreviewed/2024/10/GHSA-99gw-cq6g-rhmm/GHSA-99gw-cq6g-rhmm.json new file mode 100644 index 00000000000..14eadb42618 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-99gw-cq6g-rhmm/GHSA-99gw-cq6g-rhmm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99gw-cq6g-rhmm", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21204" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.4.0 and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21204" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json b/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json index b75545e328c..f032a1bcb11 100644 --- a/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json +++ b/advisories/unreviewed/2024/10/GHSA-9mwp-24h8-4c8f/GHSA-9mwp-24h8-4c8f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9mwp-24h8-4c8f", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:34Z", "aliases": [ "CVE-2024-48776" ], "details": "An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9pq2-vmj6-97q4/GHSA-9pq2-vmj6-97q4.json b/advisories/unreviewed/2024/10/GHSA-9pq2-vmj6-97q4/GHSA-9pq2-vmj6-97q4.json new file mode 100644 index 00000000000..569c503559b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9pq2-vmj6-97q4/GHSA-9pq2-vmj6-97q4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pq2-vmj6-97q4", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9962" + ], + "details": "Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9962" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/364508693" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json b/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json new file mode 100644 index 00000000000..e161e6e5efb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w49-jqr4-2979", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48782" + ], + "details": "File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48782" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zty-1995/7750a2ea1231971f973f02dc4c893b46" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json b/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json new file mode 100644 index 00000000000..87523c3d6a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2h4-jx6m-jp2q", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9957" + ], + "details": "Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9957" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/358151317" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c2r9-g2wq-7mfp/GHSA-c2r9-g2wq-7mfp.json b/advisories/unreviewed/2024/10/GHSA-c2r9-g2wq-7mfp/GHSA-c2r9-g2wq-7mfp.json new file mode 100644 index 00000000000..89ef7bf7566 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c2r9-g2wq-7mfp/GHSA-c2r9-g2wq-7mfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2r9-g2wq-7mfp", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21258" + ], + "details": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Installed Base accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21258" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c494-hg27-rg85/GHSA-c494-hg27-rg85.json b/advisories/unreviewed/2024/10/GHSA-c494-hg27-rg85/GHSA-c494-hg27-rg85.json new file mode 100644 index 00000000000..527e49e95d2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c494-hg27-rg85/GHSA-c494-hg27-rg85.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c494-hg27-rg85", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21241" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21241" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json b/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json new file mode 100644 index 00000000000..47be651bb34 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5xj-vg6h-cc3w", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21233" + ], + "details": "Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Core. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database Core accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21233" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c72q-9j4p-2mp4/GHSA-c72q-9j4p-2mp4.json b/advisories/unreviewed/2024/10/GHSA-c72q-9j4p-2mp4/GHSA-c72q-9j4p-2mp4.json new file mode 100644 index 00000000000..2f5ac335f4c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c72q-9j4p-2mp4/GHSA-c72q-9j4p-2mp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c72q-9j4p-2mp4", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21219" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21219" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json b/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json new file mode 100644 index 00000000000..74d5db721cb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c949-x39f-qgxh/GHSA-c949-x39f-qgxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c949-x39f-qgxh", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21234" + ], + "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21234" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cgw6-mmr2-9474/GHSA-cgw6-mmr2-9474.json b/advisories/unreviewed/2024/10/GHSA-cgw6-mmr2-9474/GHSA-cgw6-mmr2-9474.json new file mode 100644 index 00000000000..ce5532a0389 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cgw6-mmr2-9474/GHSA-cgw6-mmr2-9474.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgw6-mmr2-9474", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21238" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.1 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21238" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cj7p-fg4w-qrvh/GHSA-cj7p-fg4w-qrvh.json b/advisories/unreviewed/2024/10/GHSA-cj7p-fg4w-qrvh/GHSA-cj7p-fg4w-qrvh.json new file mode 100644 index 00000000000..8c9400fed3e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cj7p-fg4w-qrvh/GHSA-cj7p-fg4w-qrvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj7p-fg4w-qrvh", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21203" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21203" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json b/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json index 8cd7a7d7bbf..4324528b56c 100644 --- a/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json +++ b/advisories/unreviewed/2024/10/GHSA-f5r3-qx7g-cx6v/GHSA-f5r3-qx7g-cx6v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5r3-qx7g-cx6v", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48772" ], "details": "An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f8jx-5r24-p453/GHSA-f8jx-5r24-p453.json b/advisories/unreviewed/2024/10/GHSA-f8jx-5r24-p453/GHSA-f8jx-5r24-p453.json new file mode 100644 index 00000000000..3bb2c6ffd99 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f8jx-5r24-p453/GHSA-f8jx-5r24-p453.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8jx-5r24-p453", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9958" + ], + "details": "Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9958" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/40076120" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json b/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json new file mode 100644 index 00000000000..a4114920c51 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjvg-5x2f-67rq", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21210" + ], + "details": "Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21210" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fv75-hjwp-hmcm/GHSA-fv75-hjwp-hmcm.json b/advisories/unreviewed/2024/10/GHSA-fv75-hjwp-hmcm/GHSA-fv75-hjwp-hmcm.json new file mode 100644 index 00000000000..9d4cc626a60 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fv75-hjwp-hmcm/GHSA-fv75-hjwp-hmcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv75-hjwp-hmcm", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21197" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21197" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g2c9-54g5-q442/GHSA-g2c9-54g5-q442.json b/advisories/unreviewed/2024/10/GHSA-g2c9-54g5-q442/GHSA-g2c9-54g5-q442.json new file mode 100644 index 00000000000..bcb1d018bef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g2c9-54g5-q442/GHSA-g2c9-54g5-q442.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2c9-54g5-q442", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21261" + ], + "details": "Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. While the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21261" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json b/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json index ce1b2dbff03..75345d9fcc9 100644 --- a/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json +++ b/advisories/unreviewed/2024/10/GHSA-gcf7-xv2h-qvv7/GHSA-gcf7-xv2h-qvv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gcf7-xv2h-qvv7", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48778" ], "details": "An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-ggjq-q4p4-jmg6/GHSA-ggjq-q4p4-jmg6.json b/advisories/unreviewed/2024/10/GHSA-ggjq-q4p4-jmg6/GHSA-ggjq-q4p4-jmg6.json new file mode 100644 index 00000000000..06280a6061a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ggjq-q4p4-jmg6/GHSA-ggjq-q4p4-jmg6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggjq-q4p4-jmg6", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21278" + ], + "details": "Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award Processes). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contract Lifecycle Management for Public Sector accessible data as well as unauthorized access to critical data or complete access to all Oracle Contract Lifecycle Management for Public Sector accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21278" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json b/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json new file mode 100644 index 00000000000..1346d275039 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj3r-7jjv-636h", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9955" + ], + "details": "Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9955" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/370133761" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gp4x-q6rm-qp9m/GHSA-gp4x-q6rm-qp9m.json b/advisories/unreviewed/2024/10/GHSA-gp4x-q6rm-qp9m/GHSA-gp4x-q6rm-qp9m.json new file mode 100644 index 00000000000..b0ccf460dad --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gp4x-q6rm-qp9m/GHSA-gp4x-q6rm-qp9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp4x-q6rm-qp9m", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21285" + ], + "details": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21285" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h3ph-4h6g-xqfq/GHSA-h3ph-4h6g-xqfq.json b/advisories/unreviewed/2024/10/GHSA-h3ph-4h6g-xqfq/GHSA-h3ph-4h6g-xqfq.json new file mode 100644 index 00000000000..b07bf4d083b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h3ph-4h6g-xqfq/GHSA-h3ph-4h6g-xqfq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3ph-4h6g-xqfq", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21212" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Health Monitor). Supported versions that are affected are 8.0.39 and prior and 8.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21212" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json b/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json new file mode 100644 index 00000000000..cfb00ba0ead --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5h2-jj79-rjrp", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9959" + ], + "details": "Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9959" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/368672129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json b/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json index 8347320d55d..5d2a9901c3d 100644 --- a/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json +++ b/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h83f-w3v7-qh8v", - "modified": "2024-10-15T18:30:50Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-15T18:30:50Z", "aliases": [ "CVE-2024-48624" ], "details": "In segments\\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T16:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json b/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json new file mode 100644 index 00000000000..7c55b4e6917 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hf48-3p5r-fp4x/GHSA-hf48-3p5r-fp4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf48-3p5r-fp4x", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21249" + ], + "details": "Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN Expenses accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21249" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hgjp-83m4-h4fj/GHSA-hgjp-83m4-h4fj.json b/advisories/unreviewed/2024/10/GHSA-hgjp-83m4-h4fj/GHSA-hgjp-83m4-h4fj.json new file mode 100644 index 00000000000..22f5fed1c37 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hgjp-83m4-h4fj/GHSA-hgjp-83m4-h4fj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgjp-83m4-h4fj", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21272" + ], + "details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21272" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hj6p-xwh2-fc4f/GHSA-hj6p-xwh2-fc4f.json b/advisories/unreviewed/2024/10/GHSA-hj6p-xwh2-fc4f/GHSA-hj6p-xwh2-fc4f.json new file mode 100644 index 00000000000..f3d4f158037 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hj6p-xwh2-fc4f/GHSA-hj6p-xwh2-fc4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj6p-xwh2-fc4f", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21253" + ], + "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 2.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21253" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json b/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json index 4ddb2cb1a7a..75670eb0f91 100644 --- a/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json +++ b/advisories/unreviewed/2024/10/GHSA-hq46-pffv-g6wr/GHSA-hq46-pffv-g6wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq46-pffv-g6wr", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48788" ], "details": "An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-319" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T21:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hvmp-w9jw-p62g/GHSA-hvmp-w9jw-p62g.json b/advisories/unreviewed/2024/10/GHSA-hvmp-w9jw-p62g/GHSA-hvmp-w9jw-p62g.json new file mode 100644 index 00000000000..9583e85cdbe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hvmp-w9jw-p62g/GHSA-hvmp-w9jw-p62g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvmp-w9jw-p62g", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21276" + ], + "details": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21276" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hxx7-vhm6-3427/GHSA-hxx7-vhm6-3427.json b/advisories/unreviewed/2024/10/GHSA-hxx7-vhm6-3427/GHSA-hxx7-vhm6-3427.json index 1700a3a9ab4..6795ca1141e 100644 --- a/advisories/unreviewed/2024/10/GHSA-hxx7-vhm6-3427/GHSA-hxx7-vhm6-3427.json +++ b/advisories/unreviewed/2024/10/GHSA-hxx7-vhm6-3427/GHSA-hxx7-vhm6-3427.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-j4c2-c778-c3qh/GHSA-j4c2-c778-c3qh.json b/advisories/unreviewed/2024/10/GHSA-j4c2-c778-c3qh/GHSA-j4c2-c778-c3qh.json new file mode 100644 index 00000000000..65ab5cf984b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j4c2-c778-c3qh/GHSA-j4c2-c778-c3qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4c2-c778-c3qh", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21172" + ], + "details": "Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. While the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21172" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j5r3-hxmp-cxpr/GHSA-j5r3-hxmp-cxpr.json b/advisories/unreviewed/2024/10/GHSA-j5r3-hxmp-cxpr/GHSA-j5r3-hxmp-cxpr.json new file mode 100644 index 00000000000..2079e3e44da --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j5r3-hxmp-cxpr/GHSA-j5r3-hxmp-cxpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r3-hxmp-cxpr", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21198" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21198" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j6j9-m952-pp68/GHSA-j6j9-m952-pp68.json b/advisories/unreviewed/2024/10/GHSA-j6j9-m952-pp68/GHSA-j6j9-m952-pp68.json new file mode 100644 index 00000000000..bbee09b31f3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j6j9-m952-pp68/GHSA-j6j9-m952-pp68.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6j9-m952-pp68", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9963" + ], + "details": "Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9963" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/328278718" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j8c9-3ff4-h2r8/GHSA-j8c9-3ff4-h2r8.json b/advisories/unreviewed/2024/10/GHSA-j8c9-3ff4-h2r8/GHSA-j8c9-3ff4-h2r8.json new file mode 100644 index 00000000000..a5bd7697ef5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j8c9-3ff4-h2r8/GHSA-j8c9-3ff4-h2r8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8c9-3ff4-h2r8", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21280" + ], + "details": "Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21280" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j8x2-fpjj-2hvp/GHSA-j8x2-fpjj-2hvp.json b/advisories/unreviewed/2024/10/GHSA-j8x2-fpjj-2hvp/GHSA-j8x2-fpjj-2hvp.json index 14a3d0ed285..d718a921dd1 100644 --- a/advisories/unreviewed/2024/10/GHSA-j8x2-fpjj-2hvp/GHSA-j8x2-fpjj-2hvp.json +++ b/advisories/unreviewed/2024/10/GHSA-j8x2-fpjj-2hvp/GHSA-j8x2-fpjj-2hvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j8x2-fpjj-2hvp", - "modified": "2024-10-11T18:32:50Z", + "modified": "2024-10-15T21:30:36Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-9859" ], "details": "Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T17:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json b/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json new file mode 100644 index 00000000000..9453c05a28b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9pm-88v7-rvp8", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21251" + ], + "details": "Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java VM accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21251" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jp5h-88vf-2qp5/GHSA-jp5h-88vf-2qp5.json b/advisories/unreviewed/2024/10/GHSA-jp5h-88vf-2qp5/GHSA-jp5h-88vf-2qp5.json new file mode 100644 index 00000000000..42b2734b27a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jp5h-88vf-2qp5/GHSA-jp5h-88vf-2qp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp5h-88vf-2qp5", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21277" + ], + "details": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle MES for Process Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21277" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json b/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json new file mode 100644 index 00000000000..7da88028128 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jr6g-h572-57hf/GHSA-jr6g-h572-57hf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr6g-h572-57hf", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21252" + ], + "details": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21252" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jv2x-g26c-46cq/GHSA-jv2x-g26c-46cq.json b/advisories/unreviewed/2024/10/GHSA-jv2x-g26c-46cq/GHSA-jv2x-g26c-46cq.json new file mode 100644 index 00000000000..22c4d36e457 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jv2x-g26c-46cq/GHSA-jv2x-g26c-46cq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv2x-g26c-46cq", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21231" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21231" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m2x9-pvwq-m49p/GHSA-m2x9-pvwq-m49p.json b/advisories/unreviewed/2024/10/GHSA-m2x9-pvwq-m49p/GHSA-m2x9-pvwq-m49p.json new file mode 100644 index 00000000000..eab46164345 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m2x9-pvwq-m49p/GHSA-m2x9-pvwq-m49p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2x9-pvwq-m49p", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21194" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21194" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m3rx-w78v-9p56/GHSA-m3rx-w78v-9p56.json b/advisories/unreviewed/2024/10/GHSA-m3rx-w78v-9p56/GHSA-m3rx-w78v-9p56.json new file mode 100644 index 00000000000..b9177c54917 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m3rx-w78v-9p56/GHSA-m3rx-w78v-9p56.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3rx-w78v-9p56", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21191" + ], + "details": "Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Fusion Middleware Control. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Fusion Middleware Control, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Fusion Middleware Control accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Manager Fusion Middleware Control accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21191" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m5cv-jfxj-8vmh/GHSA-m5cv-jfxj-8vmh.json b/advisories/unreviewed/2024/10/GHSA-m5cv-jfxj-8vmh/GHSA-m5cv-jfxj-8vmh.json new file mode 100644 index 00000000000..c31cdd5993b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m5cv-jfxj-8vmh/GHSA-m5cv-jfxj-8vmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5cv-jfxj-8vmh", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21248" + ], + "details": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21248" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m6rg-98pc-7rxm/GHSA-m6rg-98pc-7rxm.json b/advisories/unreviewed/2024/10/GHSA-m6rg-98pc-7rxm/GHSA-m6rg-98pc-7rxm.json new file mode 100644 index 00000000000..c84d870962c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m6rg-98pc-7rxm/GHSA-m6rg-98pc-7rxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6rg-98pc-7rxm", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21230" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21230" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m7m4-4xr8-g97p/GHSA-m7m4-4xr8-g97p.json b/advisories/unreviewed/2024/10/GHSA-m7m4-4xr8-g97p/GHSA-m7m4-4xr8-g97p.json new file mode 100644 index 00000000000..01071132ef9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m7m4-4xr8-g97p/GHSA-m7m4-4xr8-g97p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7m4-4xr8-g97p", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21270" + ], + "details": "Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21270" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m7rw-p49v-xvr4/GHSA-m7rw-p49v-xvr4.json b/advisories/unreviewed/2024/10/GHSA-m7rw-p49v-xvr4/GHSA-m7rw-p49v-xvr4.json new file mode 100644 index 00000000000..2d87a15fe70 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m7rw-p49v-xvr4/GHSA-m7rw-p49v-xvr4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7rw-p49v-xvr4", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21196" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21196" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mffh-p59m-fv66/GHSA-mffh-p59m-fv66.json b/advisories/unreviewed/2024/10/GHSA-mffh-p59m-fv66/GHSA-mffh-p59m-fv66.json new file mode 100644 index 00000000000..39e0b56df3e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mffh-p59m-fv66/GHSA-mffh-p59m-fv66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mffh-p59m-fv66", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21213" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21213" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mph2-q2f9-pccr/GHSA-mph2-q2f9-pccr.json b/advisories/unreviewed/2024/10/GHSA-mph2-q2f9-pccr/GHSA-mph2-q2f9-pccr.json new file mode 100644 index 00000000000..43b3d77d45b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mph2-q2f9-pccr/GHSA-mph2-q2f9-pccr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mph2-q2f9-pccr", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21282" + ], + "details": "Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21282" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mq75-p9mg-fj7f/GHSA-mq75-p9mg-fj7f.json b/advisories/unreviewed/2024/10/GHSA-mq75-p9mg-fj7f/GHSA-mq75-p9mg-fj7f.json new file mode 100644 index 00000000000..978203b6bb9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mq75-p9mg-fj7f/GHSA-mq75-p9mg-fj7f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq75-p9mg-fj7f", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21267" + ], + "details": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21267" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json b/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json new file mode 100644 index 00000000000..44bf278ce7f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrwv-hx59-25f7", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48781" + ], + "details": "An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48781" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zty-1995/a7948be24b3411759a6afa3cc616dc12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mv25-xprv-qhqh/GHSA-mv25-xprv-qhqh.json b/advisories/unreviewed/2024/10/GHSA-mv25-xprv-qhqh/GHSA-mv25-xprv-qhqh.json new file mode 100644 index 00000000000..bf8499ac3e9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mv25-xprv-qhqh/GHSA-mv25-xprv-qhqh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv25-xprv-qhqh", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21264" + ], + "details": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise CC Common Application Objects accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21264" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json b/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json new file mode 100644 index 00000000000..bef40aa7e6d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mw6x-r32h-w49v/GHSA-mw6x-r32h-w49v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw6x-r32h-w49v", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21254" + ], + "details": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21254" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json b/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json new file mode 100644 index 00000000000..0a9e821f6a6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwf7-wfvq-vc32", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-41311" + ], + "details": "In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41311" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libheif/issues/1226" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libheif/pull/1227" + }, + { + "type": "WEB", + "url": "https://github.com/strukturag/libheif/commit/a3ed1b1eb178c5d651d6ac619c8da3d71ac2be36" + }, + { + "type": "WEB", + "url": "https://gist.github.com/flyyee/79f1b224069842ee320115cafa5c35c0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json b/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json new file mode 100644 index 00000000000..5937971455a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwrg-g727-8qpv", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21206" + ], + "details": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21206" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mx69-86h6-r53c/GHSA-mx69-86h6-r53c.json b/advisories/unreviewed/2024/10/GHSA-mx69-86h6-r53c/GHSA-mx69-86h6-r53c.json new file mode 100644 index 00000000000..28571d74f49 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mx69-86h6-r53c/GHSA-mx69-86h6-r53c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx69-86h6-r53c", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21275" + ], + "details": "Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.7-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quoting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Quoting accessible data as well as unauthorized access to critical data or complete access to all Oracle Quoting accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21275" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pg57-jx9m-63x8/GHSA-pg57-jx9m-63x8.json b/advisories/unreviewed/2024/10/GHSA-pg57-jx9m-63x8/GHSA-pg57-jx9m-63x8.json new file mode 100644 index 00000000000..2335bf486d9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pg57-jx9m-63x8/GHSA-pg57-jx9m-63x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg57-jx9m-63x8", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21269" + ], + "details": "Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Incentive Compensation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Incentive Compensation accessible data as well as unauthorized access to critical data or complete access to all Oracle Incentive Compensation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21269" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pgqq-75j6-62mw/GHSA-pgqq-75j6-62mw.json b/advisories/unreviewed/2024/10/GHSA-pgqq-75j6-62mw/GHSA-pgqq-75j6-62mw.json new file mode 100644 index 00000000000..799ea279cb3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pgqq-75j6-62mw/GHSA-pgqq-75j6-62mw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgqq-75j6-62mw", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21286" + ], + "details": "Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM Enterprise Learning Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise ELM Enterprise Learning Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM Enterprise Learning Management accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise ELM Enterprise Learning Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21286" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-phgw-9rj7-xgp6/GHSA-phgw-9rj7-xgp6.json b/advisories/unreviewed/2024/10/GHSA-phgw-9rj7-xgp6/GHSA-phgw-9rj7-xgp6.json new file mode 100644 index 00000000000..1e4f778a086 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-phgw-9rj7-xgp6/GHSA-phgw-9rj7-xgp6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phgw-9rj7-xgp6", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21207" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38 and prior, 8.4.1 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21207" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pm45-f424-qf9f/GHSA-pm45-f424-qf9f.json b/advisories/unreviewed/2024/10/GHSA-pm45-f424-qf9f/GHSA-pm45-f424-qf9f.json new file mode 100644 index 00000000000..b252ecd8f4e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pm45-f424-qf9f/GHSA-pm45-f424-qf9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm45-f424-qf9f", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21268" + ], + "details": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21268" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pxc7-gxxv-7pxc/GHSA-pxc7-gxxv-7pxc.json b/advisories/unreviewed/2024/10/GHSA-pxc7-gxxv-7pxc/GHSA-pxc7-gxxv-7pxc.json new file mode 100644 index 00000000000..78f2b736986 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pxc7-gxxv-7pxc/GHSA-pxc7-gxxv-7pxc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxc7-gxxv-7pxc", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48714" + ], + "details": "In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48714" + }, + { + "type": "WEB", + "url": "https://github.com/sezangel/IOT-vul/tree/main/TPlink/TL-WDR7660/2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q5rv-w3vj-5jjx/GHSA-q5rv-w3vj-5jjx.json b/advisories/unreviewed/2024/10/GHSA-q5rv-w3vj-5jjx/GHSA-q5rv-w3vj-5jjx.json new file mode 100644 index 00000000000..1512b12f457 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q5rv-w3vj-5jjx/GHSA-q5rv-w3vj-5jjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5rv-w3vj-5jjx", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21200" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21200" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json b/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json new file mode 100644 index 00000000000..5af723e6408 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q77p-j5gj-rmw2", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-44775" + ], + "details": "An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service(DoS) via a crafted request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44775" + }, + { + "type": "WEB", + "url": "https://gist.github.com/pengwGit/26fd8630392af5d8829c2e220091ac4f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q7mg-8rwj-gmwq/GHSA-q7mg-8rwj-gmwq.json b/advisories/unreviewed/2024/10/GHSA-q7mg-8rwj-gmwq/GHSA-q7mg-8rwj-gmwq.json new file mode 100644 index 00000000000..8aca977d99d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q7mg-8rwj-gmwq/GHSA-q7mg-8rwj-gmwq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7mg-8rwj-gmwq", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48783" + ], + "details": "An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48783" + }, + { + "type": "WEB", + "url": "https://gist.github.com/zty-1995/8495b81e8d257e8f6df102a32ec3c583" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json b/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json new file mode 100644 index 00000000000..a54a52d2b55 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q8jf-j34w-q74g/GHSA-q8jf-j34w-q74g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8jf-j34w-q74g", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9954" + ], + "details": "Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9954" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/367755363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json b/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json new file mode 100644 index 00000000000..4284fe88559 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfc4-qvg8-vmjr", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48411" + ], + "details": "itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48411" + }, + { + "type": "WEB", + "url": "https://github.com/Comitora/CVEs/blob/main/CVE-2024-48411" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json b/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json new file mode 100644 index 00000000000..aba268649c0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg3h-rf5x-68cv", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-35584" + ], + "details": "SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from \"X-Forwarded-For\" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35584" + }, + { + "type": "WEB", + "url": "https://github.com/whwhwh96/CVE-2024-35584" + }, + { + "type": "WEB", + "url": "http://opensis.com" + }, + { + "type": "WEB", + "url": "http://os4ed.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json b/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json new file mode 100644 index 00000000000..19f8a9c546d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq87-cr9r-6pj4", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21281" + ], + "details": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data as well as unauthorized read access to a subset of Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21281" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json b/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json new file mode 100644 index 00000000000..6dbfeaea8cb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r389-865g-hcg3/GHSA-r389-865g-hcg3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r389-865g-hcg3", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21216" + ], + "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21216" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r97q-xhcv-9xx9/GHSA-r97q-xhcv-9xx9.json b/advisories/unreviewed/2024/10/GHSA-r97q-xhcv-9xx9/GHSA-r97q-xhcv-9xx9.json new file mode 100644 index 00000000000..705fcf92e00 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r97q-xhcv-9xx9/GHSA-r97q-xhcv-9xx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r97q-xhcv-9xx9", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21193" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21193" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json b/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json index 03a7d9225e7..16a24ddb607 100644 --- a/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json +++ b/advisories/unreviewed/2024/10/GHSA-rfgc-w4c4-wfq8/GHSA-rfgc-w4c4-wfq8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfgc-w4c4-wfq8", - "modified": "2024-10-11T21:31:35Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:35Z", "aliases": [ "CVE-2024-48787" ], "details": "An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rv92-jf3g-p8qp/GHSA-rv92-jf3g-p8qp.json b/advisories/unreviewed/2024/10/GHSA-rv92-jf3g-p8qp/GHSA-rv92-jf3g-p8qp.json new file mode 100644 index 00000000000..f5c9bab665c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rv92-jf3g-p8qp/GHSA-rv92-jf3g-p8qp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv92-jf3g-p8qp", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21235" + ], + "details": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21235" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v2h4-8467-fm2m/GHSA-v2h4-8467-fm2m.json b/advisories/unreviewed/2024/10/GHSA-v2h4-8467-fm2m/GHSA-v2h4-8467-fm2m.json new file mode 100644 index 00000000000..3b9654ce868 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v2h4-8467-fm2m/GHSA-v2h4-8467-fm2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2h4-8467-fm2m", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21279" + ], + "details": "Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sourcing accessible data as well as unauthorized access to critical data or complete access to all Oracle Sourcing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21279" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v3cc-4rr8-r8xv/GHSA-v3cc-4rr8-r8xv.json b/advisories/unreviewed/2024/10/GHSA-v3cc-4rr8-r8xv/GHSA-v3cc-4rr8-r8xv.json new file mode 100644 index 00000000000..ae5badceaf9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v3cc-4rr8-r8xv/GHSA-v3cc-4rr8-r8xv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3cc-4rr8-r8xv", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21257" + ], + "details": "Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21257" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v84m-m2mf-cxcm/GHSA-v84m-m2mf-cxcm.json b/advisories/unreviewed/2024/10/GHSA-v84m-m2mf-cxcm/GHSA-v84m-m2mf-cxcm.json new file mode 100644 index 00000000000..fd6ff2a8255 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v84m-m2mf-cxcm/GHSA-v84m-m2mf-cxcm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v84m-m2mf-cxcm", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-48710" + ], + "details": "In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48710" + }, + { + "type": "WEB", + "url": "https://github.com/sezangel/IOT-vul/blob/main/TPlink/TL-WDR7660/1/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v85r-m9wc-pprx/GHSA-v85r-m9wc-pprx.json b/advisories/unreviewed/2024/10/GHSA-v85r-m9wc-pprx/GHSA-v85r-m9wc-pprx.json new file mode 100644 index 00000000000..c4dd624d824 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v85r-m9wc-pprx/GHSA-v85r-m9wc-pprx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v85r-m9wc-pprx", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21265" + ], + "details": "Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Site Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Site Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21265" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vchj-ggm5-9rcm/GHSA-vchj-ggm5-9rcm.json b/advisories/unreviewed/2024/10/GHSA-vchj-ggm5-9rcm/GHSA-vchj-ggm5-9rcm.json new file mode 100644 index 00000000000..8318e479604 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vchj-ggm5-9rcm/GHSA-vchj-ggm5-9rcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vchj-ggm5-9rcm", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21247" + ], + "details": "Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21247" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vggh-55p7-p625/GHSA-vggh-55p7-p625.json b/advisories/unreviewed/2024/10/GHSA-vggh-55p7-p625/GHSA-vggh-55p7-p625.json new file mode 100644 index 00000000000..3b2ada3a098 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vggh-55p7-p625/GHSA-vggh-55p7-p625.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vggh-55p7-p625", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21239" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21239" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json b/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json new file mode 100644 index 00000000000..c060dd297d2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhqv-fr8v-3cwq", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21208" + ], + "details": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and 21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21208" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vqmm-339w-hc7c/GHSA-vqmm-339w-hc7c.json b/advisories/unreviewed/2024/10/GHSA-vqmm-339w-hc7c/GHSA-vqmm-339w-hc7c.json new file mode 100644 index 00000000000..af8377a59c3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vqmm-339w-hc7c/GHSA-vqmm-339w-hc7c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqmm-339w-hc7c", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21218" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21218" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json new file mode 100644 index 00000000000..5c8e84fdaf8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2p9-j475-2wp5", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-9956" + ], + "details": "Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9956" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/370482421" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w326-rf25-93cq/GHSA-w326-rf25-93cq.json b/advisories/unreviewed/2024/10/GHSA-w326-rf25-93cq/GHSA-w326-rf25-93cq.json new file mode 100644 index 00000000000..c8974625946 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w326-rf25-93cq/GHSA-w326-rf25-93cq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w326-rf25-93cq", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21283" + ], + "details": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Core. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Core accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Global Payroll Core accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21283" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json b/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json index c9b7ca43cc4..7d9abd9357f 100644 --- a/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json +++ b/advisories/unreviewed/2024/10/GHSA-w475-fv8v-qxrm/GHSA-w475-fv8v-qxrm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w475-fv8v-qxrm", - "modified": "2024-10-14T15:30:46Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-14T15:30:46Z", "aliases": [ "CVE-2024-48249" ], "details": "Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T15:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json b/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json index afe5affd918..42e7f7b23e7 100644 --- a/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json +++ b/advisories/unreviewed/2024/10/GHSA-w47r-whp2-pxw8/GHSA-w47r-whp2-pxw8.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w47r-whp2-pxw8", - "modified": "2024-10-09T18:31:44Z", + "modified": "2024-10-15T21:30:36Z", "published": "2024-10-09T18:31:44Z", "aliases": [ "CVE-2024-9473" ], "details": "A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/10/GHSA-w5f9-2p82-v83j/GHSA-w5f9-2p82-v83j.json b/advisories/unreviewed/2024/10/GHSA-w5f9-2p82-v83j/GHSA-w5f9-2p82-v83j.json new file mode 100644 index 00000000000..d065f4962a1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w5f9-2p82-v83j/GHSA-w5f9-2p82-v83j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5f9-2p82-v83j", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21266" + ], + "details": "Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21266" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w76f-wfx3-5qjq/GHSA-w76f-wfx3-5qjq.json b/advisories/unreviewed/2024/10/GHSA-w76f-wfx3-5qjq/GHSA-w76f-wfx3-5qjq.json new file mode 100644 index 00000000000..dceec4e7242 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w76f-wfx3-5qjq/GHSA-w76f-wfx3-5qjq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w76f-wfx3-5qjq", + "modified": "2024-10-15T21:30:37Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21199" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21199" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json b/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json index 5174f8367b1..188afe14b69 100644 --- a/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json +++ b/advisories/unreviewed/2024/10/GHSA-w8wj-7hcm-8qpr/GHSA-w8wj-7hcm-8qpr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8wj-7hcm-8qpr", - "modified": "2024-10-11T21:31:34Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-11T21:31:34Z", "aliases": [ "CVE-2024-48769" ], "details": "An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json b/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json new file mode 100644 index 00000000000..76282f94679 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wc4w-3525-x87q/GHSA-wc4w-3525-x87q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc4w-3525-x87q", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21246" + ], + "details": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21246" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wp8c-mcg4-hh47/GHSA-wp8c-mcg4-hh47.json b/advisories/unreviewed/2024/10/GHSA-wp8c-mcg4-hh47/GHSA-wp8c-mcg4-hh47.json new file mode 100644 index 00000000000..9e8c67b74de --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wp8c-mcg4-hh47/GHSA-wp8c-mcg4-hh47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp8c-mcg4-hh47", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-21271" + ], + "details": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Field Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21271" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json index 2f0a7fe6a1a..675cb0cd6be 100644 --- a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json +++ b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq2p-5pc6-wpgf", - "modified": "2024-10-15T18:30:50Z", + "modified": "2024-10-15T21:30:37Z", "published": "2024-10-15T18:30:50Z", "aliases": [ "CVE-2024-9676" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317467" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-wq2p-5pc6-wpgf" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-xcwx-vhj6-p7m7/GHSA-xcwx-vhj6-p7m7.json b/advisories/unreviewed/2024/10/GHSA-xcwx-vhj6-p7m7/GHSA-xcwx-vhj6-p7m7.json new file mode 100644 index 00000000000..b7f6a26dc6e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xcwx-vhj6-p7m7/GHSA-xcwx-vhj6-p7m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcwx-vhj6-p7m7", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21237" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21237" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json b/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json new file mode 100644 index 00000000000..b056807b151 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xfqq-7659-m6jq/GHSA-xfqq-7659-m6jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfqq-7659-m6jq", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21215" + ], + "details": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21215" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xhf9-m56c-xh6w/GHSA-xhf9-m56c-xh6w.json b/advisories/unreviewed/2024/10/GHSA-xhf9-m56c-xh6w/GHSA-xhf9-m56c-xh6w.json new file mode 100644 index 00000000000..2db31d5dff0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xhf9-m56c-xh6w/GHSA-xhf9-m56c-xh6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhf9-m56c-xh6w", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:37Z", + "aliases": [ + "CVE-2024-21201" + ], + "details": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21201" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json b/advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json new file mode 100644 index 00000000000..66332f25c0a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xhr3-wf7j-h255/GHSA-xhr3-wf7j-h255.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhr3-wf7j-h255", + "modified": "2024-10-15T21:30:39Z", + "published": "2024-10-15T21:30:39Z", + "aliases": [ + "CVE-2024-44337" + ], + "details": "The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44337" + }, + { + "type": "WEB", + "url": "https://github.com/gomarkdown/markdown/commit/a2a9c4f76ef5a5c32108e36f7c47f8d310322252" + }, + { + "type": "WEB", + "url": "https://github.com/Brinmon/CVE-2024-44337" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xmw4-wxv9-hm5g/GHSA-xmw4-wxv9-hm5g.json b/advisories/unreviewed/2024/10/GHSA-xmw4-wxv9-hm5g/GHSA-xmw4-wxv9-hm5g.json new file mode 100644 index 00000000000..470d8c49616 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xmw4-wxv9-hm5g/GHSA-xmw4-wxv9-hm5g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmw4-wxv9-hm5g", + "modified": "2024-10-15T21:30:38Z", + "published": "2024-10-15T21:30:38Z", + "aliases": [ + "CVE-2024-21242" + ], + "details": "Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21242" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2024.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T20:15:13Z" + } +} \ No newline at end of file