From 5509808f2fdc8329bed8131b0026618e68285b1a Mon Sep 17 00:00:00 2001 From: cad-safe-bot Date: Mon, 4 Sep 2023 10:00:27 +0000 Subject: [PATCH] Auto-Update: 2023-09-04T10:00:24.262181+00:00 --- CVE-2023/CVE-2023-46xx/CVE-2023-4613.json | 55 +++++++++++++++++++++ CVE-2023/CVE-2023-47xx/CVE-2023-4754.json | 59 +++++++++++++++++++++++ CVE-2023/CVE-2023-47xx/CVE-2023-4756.json | 59 +++++++++++++++++++++++ README.md | 43 +++-------------- 4 files changed, 181 insertions(+), 35 deletions(-) create mode 100644 CVE-2023/CVE-2023-46xx/CVE-2023-4613.json create mode 100644 CVE-2023/CVE-2023-47xx/CVE-2023-4754.json create mode 100644 CVE-2023/CVE-2023-47xx/CVE-2023-4756.json diff --git a/CVE-2023/CVE-2023-46xx/CVE-2023-4613.json b/CVE-2023/CVE-2023-46xx/CVE-2023-4613.json new file mode 100644 index 00000000000..d98ede2c9af --- /dev/null +++ b/CVE-2023/CVE-2023-46xx/CVE-2023-4613.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-4613", + "sourceIdentifier": "product.security@lge.com", + "published": "2023-09-04T09:15:07.510", + "lastModified": "2023-09-04T09:15:07.510", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LG Electronics LG-LED Assistant allows Remote Code Inclusion." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "product.security@lge.com", + "type": "Secondary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "HIGH", + "availabilityImpact": "HIGH", + "baseScore": 9.8, + "baseSeverity": "CRITICAL" + }, + "exploitabilityScore": 3.9, + "impactScore": 5.9 + } + ] + }, + "weaknesses": [ + { + "source": "product.security@lge.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-22" + } + ] + } + ], + "references": [ + { + "url": "https://lgsecurity.lge.com/bulletins/idproducts#updateDetails", + "source": "product.security@lge.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-47xx/CVE-2023-4754.json b/CVE-2023/CVE-2023-47xx/CVE-2023-4754.json new file mode 100644 index 00000000000..29b547cc0cb --- /dev/null +++ b/CVE-2023/CVE-2023-47xx/CVE-2023-4754.json @@ -0,0 +1,59 @@ +{ + "id": "CVE-2023-4754", + "sourceIdentifier": "security@huntr.dev", + "published": "2023-09-04T09:15:07.897", + "lastModified": "2023-09-04T09:15:07.897", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "security@huntr.dev", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "LOCAL", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 5.3, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.8, + "impactScore": 3.4 + } + ] + }, + "weaknesses": [ + { + "source": "security@huntr.dev", + "type": "Primary", + "description": [ + { + "lang": "en", + "value": "CWE-787" + } + ] + } + ], + "references": [ + { + "url": "https://github.com/gpac/gpac/commit/7e2e92feb1b30fac1d659f6620d743b5a188ffe0", + "source": "security@huntr.dev" + }, + { + "url": "https://huntr.dev/bounties/b7ed24ad-7d0b-40b7-8f4d-3c18a906620c", + "source": "security@huntr.dev" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-47xx/CVE-2023-4756.json b/CVE-2023/CVE-2023-47xx/CVE-2023-4756.json new file mode 100644 index 00000000000..783fd08e977 --- /dev/null +++ b/CVE-2023/CVE-2023-47xx/CVE-2023-4756.json @@ -0,0 +1,59 @@ +{ + "id": "CVE-2023-4756", + "sourceIdentifier": "security@huntr.dev", + "published": "2023-09-04T09:15:07.990", + "lastModified": "2023-09-04T09:15:07.990", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "security@huntr.dev", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "LOCAL", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 5.9, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.5, + "impactScore": 3.4 + } + ] + }, + "weaknesses": [ + { + "source": "security@huntr.dev", + "type": "Primary", + "description": [ + { + "lang": "en", + "value": "CWE-121" + } + ] + } + ], + "references": [ + { + "url": "https://github.com/gpac/gpac/commit/6914d016e2b540bac2c471c4aea156ddef8e8e01", + "source": "security@huntr.dev" + }, + { + "url": "https://huntr.dev/bounties/2342da0e-f097-4ce7-bfdc-3ec0ba446e05", + "source": "security@huntr.dev" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index 84f30f961f2..31e823c2bac 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2023-09-04T04:00:24.768953+00:00 +2023-09-04T10:00:24.262181+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2023-09-04T03:51:45.317000+00:00 +2023-09-04T09:15:07.990000+00:00 ``` ### Last Data Feed Release @@ -29,49 +29,22 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -224073 +224076 ``` ### CVEs added in the last Commit -Recently added CVEs: `89` +Recently added CVEs: `3` -* [CVE-2023-20840](CVE-2023/CVE-2023-208xx/CVE-2023-20840.json) (`2023-09-04T03:15:10.827`) -* [CVE-2023-20841](CVE-2023/CVE-2023-208xx/CVE-2023-20841.json) (`2023-09-04T03:15:11.003`) -* [CVE-2023-20842](CVE-2023/CVE-2023-208xx/CVE-2023-20842.json) (`2023-09-04T03:15:11.163`) -* [CVE-2023-20843](CVE-2023/CVE-2023-208xx/CVE-2023-20843.json) (`2023-09-04T03:15:11.343`) -* [CVE-2023-20844](CVE-2023/CVE-2023-208xx/CVE-2023-20844.json) (`2023-09-04T03:15:11.443`) -* [CVE-2023-20845](CVE-2023/CVE-2023-208xx/CVE-2023-20845.json) (`2023-09-04T03:15:11.523`) -* [CVE-2023-20846](CVE-2023/CVE-2023-208xx/CVE-2023-20846.json) (`2023-09-04T03:15:11.637`) -* [CVE-2023-20847](CVE-2023/CVE-2023-208xx/CVE-2023-20847.json) (`2023-09-04T03:15:11.717`) -* [CVE-2023-20848](CVE-2023/CVE-2023-208xx/CVE-2023-20848.json) (`2023-09-04T03:15:11.830`) -* [CVE-2023-20849](CVE-2023/CVE-2023-208xx/CVE-2023-20849.json) (`2023-09-04T03:15:11.983`) -* [CVE-2023-20850](CVE-2023/CVE-2023-208xx/CVE-2023-20850.json) (`2023-09-04T03:15:12.033`) -* [CVE-2023-20851](CVE-2023/CVE-2023-208xx/CVE-2023-20851.json) (`2023-09-04T03:15:12.083`) -* [CVE-2023-32805](CVE-2023/CVE-2023-328xx/CVE-2023-32805.json) (`2023-09-04T03:15:12.140`) -* [CVE-2023-32806](CVE-2023/CVE-2023-328xx/CVE-2023-32806.json) (`2023-09-04T03:15:12.393`) -* [CVE-2023-32807](CVE-2023/CVE-2023-328xx/CVE-2023-32807.json) (`2023-09-04T03:15:12.657`) -* [CVE-2023-32808](CVE-2023/CVE-2023-328xx/CVE-2023-32808.json) (`2023-09-04T03:15:12.840`) -* [CVE-2023-32809](CVE-2023/CVE-2023-328xx/CVE-2023-32809.json) (`2023-09-04T03:15:13.023`) -* [CVE-2023-32810](CVE-2023/CVE-2023-328xx/CVE-2023-32810.json) (`2023-09-04T03:15:13.223`) -* [CVE-2023-32811](CVE-2023/CVE-2023-328xx/CVE-2023-32811.json) (`2023-09-04T03:15:13.387`) -* [CVE-2023-32812](CVE-2023/CVE-2023-328xx/CVE-2023-32812.json) (`2023-09-04T03:15:13.440`) -* [CVE-2023-32813](CVE-2023/CVE-2023-328xx/CVE-2023-32813.json) (`2023-09-04T03:15:13.527`) -* [CVE-2023-32814](CVE-2023/CVE-2023-328xx/CVE-2023-32814.json) (`2023-09-04T03:15:13.783`) -* [CVE-2023-32815](CVE-2023/CVE-2023-328xx/CVE-2023-32815.json) (`2023-09-04T03:15:13.990`) -* [CVE-2023-32816](CVE-2023/CVE-2023-328xx/CVE-2023-32816.json) (`2023-09-04T03:15:14.220`) -* [CVE-2023-32817](CVE-2023/CVE-2023-328xx/CVE-2023-32817.json) (`2023-09-04T03:15:14.277`) +* [CVE-2023-4613](CVE-2023/CVE-2023-46xx/CVE-2023-4613.json) (`2023-09-04T09:15:07.510`) +* [CVE-2023-4754](CVE-2023/CVE-2023-47xx/CVE-2023-4754.json) (`2023-09-04T09:15:07.897`) +* [CVE-2023-4756](CVE-2023/CVE-2023-47xx/CVE-2023-4756.json) (`2023-09-04T09:15:07.990`) ### CVEs modified in the last Commit -Recently modified CVEs: `5` +Recently modified CVEs: `0` -* [CVE-2023-4744](CVE-2023/CVE-2023-47xx/CVE-2023-4744.json) (`2023-09-04T03:51:45.317`) -* [CVE-2023-4745](CVE-2023/CVE-2023-47xx/CVE-2023-4745.json) (`2023-09-04T03:51:45.317`) -* [CVE-2023-4746](CVE-2023/CVE-2023-47xx/CVE-2023-4746.json) (`2023-09-04T03:51:45.317`) -* [CVE-2023-4747](CVE-2023/CVE-2023-47xx/CVE-2023-4747.json) (`2023-09-04T03:51:45.317`) -* [CVE-2023-4749](CVE-2023/CVE-2023-47xx/CVE-2023-4749.json) (`2023-09-04T03:51:45.317`) ## Download and Usage