Auto-Update: 2024-06-07T23:55:17.964768+00:00

This commit is contained in:
cad-safe-bot 2024-06-07 23:58:11 +00:00
parent 22beb55222
commit a6a59291cb
3 changed files with 80 additions and 33 deletions

View File

@ -0,0 +1,59 @@
{
"id": "CVE-2024-0444",
"sourceIdentifier": "zdi-disclosures@trendmicro.com",
"published": "2024-06-07T23:15:47.267",
"lastModified": "2024-06-07T23:15:47.267",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.\n\nThe specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "zdi-disclosures@trendmicro.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.6,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "zdi-disclosures@trendmicro.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-121"
}
]
}
],
"references": [
{
"url": "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f368d63ecd89e01fd2cf0b1c4def5fc782b2c390",
"source": "zdi-disclosures@trendmicro.com"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-24-567/",
"source": "zdi-disclosures@trendmicro.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-06-07T22:00:18.053257+00:00
2024-06-07T23:55:17.964768+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-06-07T21:15:35.677000+00:00
2024-06-07T23:15:47.267000+00:00
```
### Last Data Feed Release
@ -33,33 +33,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
253018
253019
```
### CVEs added in the last Commit
Recently added CVEs: `6`
Recently added CVEs: `1`
- [CVE-2023-49221](CVE-2023/CVE-2023-492xx/CVE-2023-49221.json) (`2024-06-07T20:15:10.470`)
- [CVE-2023-49222](CVE-2023/CVE-2023-492xx/CVE-2023-49222.json) (`2024-06-07T20:15:10.577`)
- [CVE-2023-49223](CVE-2023/CVE-2023-492xx/CVE-2023-49223.json) (`2024-06-07T20:15:10.660`)
- [CVE-2023-49224](CVE-2023/CVE-2023-492xx/CVE-2023-49224.json) (`2024-06-07T20:15:10.747`)
- [CVE-2023-7261](CVE-2023/CVE-2023-72xx/CVE-2023-7261.json) (`2024-06-07T20:15:10.887`)
- [CVE-2024-1694](CVE-2024/CVE-2024-16xx/CVE-2024-1694.json) (`2024-06-07T20:15:10.973`)
- [CVE-2024-0444](CVE-2024/CVE-2024-04xx/CVE-2024-0444.json) (`2024-06-07T23:15:47.267`)
### CVEs modified in the last Commit
Recently modified CVEs: `8`
Recently modified CVEs: `0`
- [CVE-2024-2575](CVE-2024/CVE-2024-25xx/CVE-2024-2575.json) (`2024-06-07T20:15:11.520`)
- [CVE-2024-4903](CVE-2024/CVE-2024-49xx/CVE-2024-4903.json) (`2024-06-07T20:15:11.967`)
- [CVE-2024-4907](CVE-2024/CVE-2024-49xx/CVE-2024-4907.json) (`2024-06-07T20:15:12.077`)
- [CVE-2024-5357](CVE-2024/CVE-2024-53xx/CVE-2024-5357.json) (`2024-06-07T20:15:12.387`)
- [CVE-2024-5369](CVE-2024/CVE-2024-53xx/CVE-2024-5369.json) (`2024-06-07T20:15:12.487`)
- [CVE-2024-5378](CVE-2024/CVE-2024-53xx/CVE-2024-5378.json) (`2024-06-07T20:15:12.587`)
- [CVE-2024-5391](CVE-2024/CVE-2024-53xx/CVE-2024-5391.json) (`2024-06-07T20:15:12.687`)
- [CVE-2024-5745](CVE-2024/CVE-2024-57xx/CVE-2024-5745.json) (`2024-06-07T21:15:35.677`)
## Download and Usage

View File

@ -236033,10 +236033,10 @@ CVE-2023-49214,0,0,a0afee994e43332c905ae46f1402a540ab99f0fb5005ed3146dcd6018e2a0
CVE-2023-49215,0,0,3c26af53af291af7f1b962cb2cd08a23fabd41c0e948ad3fa77f16c836d5a862,2023-11-30T04:56:12.590000
CVE-2023-49216,0,0,ad2db903e4c663e4c81367d1e67112cd095df59e785dcc55471850fbb5aa6f81,2023-11-30T04:56:18.617000
CVE-2023-4922,0,0,7a4053a720178fbf5ce70edceb9e6f8bc04f3e44dde847a94f283d80d99b2164,2023-12-01T19:51:57.237000
CVE-2023-49221,1,1,71580fe73ac9b7b34d7e8beb89b324a86b754c3f68723a70e1969f82a32ca7a6,2024-06-07T20:15:10.470000
CVE-2023-49222,1,1,635319de0c59b4560bb0de22b8ebefdda13a69c4d18528994c2e4fc8f81b976e,2024-06-07T20:15:10.577000
CVE-2023-49223,1,1,883b63eab8001e40fb19b01a0c6281c753f6a6efe209d7185dff734d91f9aa92,2024-06-07T20:15:10.660000
CVE-2023-49224,1,1,02286ec98f5ce7a0cac3f6847374174392f8bb0ecf3af413bec6dc905f644a41,2024-06-07T20:15:10.747000
CVE-2023-49221,0,0,71580fe73ac9b7b34d7e8beb89b324a86b754c3f68723a70e1969f82a32ca7a6,2024-06-07T20:15:10.470000
CVE-2023-49222,0,0,635319de0c59b4560bb0de22b8ebefdda13a69c4d18528994c2e4fc8f81b976e,2024-06-07T20:15:10.577000
CVE-2023-49223,0,0,883b63eab8001e40fb19b01a0c6281c753f6a6efe209d7185dff734d91f9aa92,2024-06-07T20:15:10.660000
CVE-2023-49224,0,0,02286ec98f5ce7a0cac3f6847374174392f8bb0ecf3af413bec6dc905f644a41,2024-06-07T20:15:10.747000
CVE-2023-49225,0,0,67ae01b5198a01c140f5deaeaca8526fd2eaf70466f07438af6053aa64cc8dcb,2023-12-12T17:04:37.617000
CVE-2023-49226,0,0,f1a97f1312ace441154176f1d2587ee178c928f3456e9b9c638512f47ae381ae,2024-01-03T22:54:12.677000
CVE-2023-49228,0,0,b37aa175fce7fe3dc61886d1f496eca0de99535cf0452ee346d5f2bbad00baaa,2024-01-04T17:54:01.673000
@ -240279,7 +240279,7 @@ CVE-2023-7252,0,0,2392d7e3f3e585dc7390c0e965b0650ef11fa8ae2796aaf6e5db491d8ab57d
CVE-2023-7253,0,0,6a907485fdee60605139b38f9229fa03da0ccfe5b94dcf86ca3826725a280a6c,2024-04-24T13:39:42.883000
CVE-2023-7258,0,0,5ff9fbb18c87cd79eeba5bdac9e20b834be684e2899fd63fb3e107422ede555b,2024-05-15T18:35:11.453000
CVE-2023-7259,0,0,291fdf96791c66804d1f0d3fb86a244e544f8112f70bc253658c7b47edf99960,2024-06-04T19:18:14.193000
CVE-2023-7261,1,1,be50b25670116aed3310e1bff8d1dcc720304738a2aed4afd9de5a40e1b23396,2024-06-07T20:15:10.887000
CVE-2023-7261,0,0,be50b25670116aed3310e1bff8d1dcc720304738a2aed4afd9de5a40e1b23396,2024-06-07T20:15:10.887000
CVE-2024-0007,0,0,3bebeca11ed66b29340ad5b2f4a6fdda381d640f217ed7214dda7d3a471e9da1,2024-02-15T06:23:39.303000
CVE-2024-0008,0,0,db70626ccf03b2491d218a1d6d38cb10870a351e02a617fba1e6e23a0ac8502b,2024-02-15T06:23:39.303000
CVE-2024-0009,0,0,a481cbe6336f9e8c7286d10d3efcc3169667e3db231d83fec3fad506beda4652,2024-02-15T06:23:39.303000
@ -240606,6 +240606,7 @@ CVE-2024-0439,0,0,4f05abe07b33d52630e7e2f16b2fc654dc7361de9b17d784a387c5f2734969
CVE-2024-0440,0,0,1b8c6151d9e5112082edfbd55485c048af1a0e6af77ae8e6651b84d68c946722,2024-02-26T16:32:25.577000
CVE-2024-0442,0,0,8cdba0674d25b3b3ea9cdded4aa83352a5239f2b65f68583fbcda0cd98fb79ab,2024-02-29T13:49:29.390000
CVE-2024-0443,0,0,66f5ebd159b753199898dddfe8b1a62dd2999c1556a51d08b06f9a74e312a3e2,2024-05-20T11:15:08.403000
CVE-2024-0444,1,1,786c01cbda4efbfcbc7789f860e5c7c13f5f94487248cc513cf3a2ea5f661ca7,2024-06-07T23:15:47.267000
CVE-2024-0445,0,0,abd39d6705adef15e4807879de948efd276d4ecca782592229f9c11a318d87fe,2024-05-14T16:13:02.773000
CVE-2024-0446,0,0,177f0f6fa9da6f41d147a83b94c4a1a182c538433bae32bd44fabede9ad39c08,2024-03-01T05:15:08.440000
CVE-2024-0447,0,0,462dd19e6dceba84c0c2bc16f20ac9c6c50b5a3824b0b2c21023eddf8c13abda,2024-03-13T18:16:18.563000
@ -241724,7 +241725,7 @@ CVE-2024-1690,0,0,f64df43faf81ef2a8a790a9c7a5603e22ee6007009a611d7b1688df8108966
CVE-2024-1691,0,0,f122d989b2d57485de350b354a899ca74c01df04d45a49a682097dfa29b4d980,2024-03-13T18:15:58.530000
CVE-2024-1692,0,0,ef8c2f206aee0606f4bca6d6f966b02bdbb84047340b5cc369611d2c6473005f,2024-04-01T01:12:59.077000
CVE-2024-1693,0,0,b624988ff4a09eec6c53b0f2ae5516cc1adb4934a04da7ef0fc2561598df5ab5,2024-05-14T16:13:02.773000
CVE-2024-1694,1,1,85ac08d0c7ab762c565f35a39a0ce74803d6e3a1fe1c28b6bcdf7d656fe08164,2024-06-07T20:15:10.973000
CVE-2024-1694,0,0,85ac08d0c7ab762c565f35a39a0ce74803d6e3a1fe1c28b6bcdf7d656fe08164,2024-06-07T20:15:10.973000
CVE-2024-1695,0,0,7fe18c9cbac30241384ca3bf0665e46f72ea6ee4e4c64dee52dbbf5f058010dc,2024-05-07T13:39:32.710000
CVE-2024-1696,0,0,99a90d5f5f3ed72de58d46078f56367f3c20ea4ece7ee2f1509d303d1823a04c,2024-03-12T12:40:13.500000
CVE-2024-1697,0,0,f12238fd2cf039d39a224b6767f588eae71af5d9fa3c34248b412c33612f7c95,2024-03-25T01:51:01.223000
@ -245343,7 +245344,7 @@ CVE-2024-25743,0,0,f4ab9fa0626070f639cae75d30842deed655e3fbae514e1ed4d7bb8f6f7ef
CVE-2024-25744,0,0,4b0b476da30d39c3d73f2f74d7d6a3fe7e372d371ce439923d15b6b4e22ccfeb,2024-02-12T14:20:03.287000
CVE-2024-25746,0,0,6272a47b2c23f44a1fdd2c4a804d33aa59797a37bb203c19911b0f26f1951dd8,2024-02-23T02:42:54.547000
CVE-2024-25748,0,0,beca6aa38f2f4693ac0e2f34d593b69359263cf9d72b56c066509cc509297ece,2024-02-23T02:42:54.547000
CVE-2024-2575,0,1,b1403399c0a3c45b9bfa4be5661cd43f7e5138dd887b4badd9c7212489928ef2,2024-06-07T20:15:11.520000
CVE-2024-2575,0,0,b1403399c0a3c45b9bfa4be5661cd43f7e5138dd887b4badd9c7212489928ef2,2024-06-07T20:15:11.520000
CVE-2024-25751,0,0,395becc114c34ed66ca0b69212e22c009bdd05d997290a2e353e3ceaba1432fb,2024-02-27T14:20:06.637000
CVE-2024-25753,0,0,97dfe859c1dbb063c05c6ed623d7cc9a1e99c3b82663c228697d879092a15d4c,2024-02-23T02:42:54.547000
CVE-2024-25756,0,0,a0b03055fd48d565532bce772e2eeb093af08c302ddbed1c7683c7dfdc663118,2024-02-23T02:42:54.547000
@ -252592,11 +252593,11 @@ CVE-2024-4894,0,0,d68130303d356c053d0f6768d0ee08506e206d16216142c952b9b56af8835d
CVE-2024-4895,0,0,be42ef886a64c01ec9437b4cfbce4dfdf0b902fbee0c6083bfc71de776f15b0e,2024-05-24T01:15:30.977000
CVE-2024-4896,0,0,6456cc9b22aff68532bfeeb7637d5235216630d84771d1ec52d84fa467e4b7a6,2024-05-22T12:46:53.887000
CVE-2024-4902,0,0,190ae6556b466a5228ce6680f8d8f4ba4789cfafa6765b2e868dc7feb28ee1e3,2024-06-07T14:56:05.647000
CVE-2024-4903,0,1,74f6793baa838082db19325ded8d53157feab60a90892d7bb13ebdea205ed94c,2024-06-07T20:15:11.967000
CVE-2024-4903,0,0,74f6793baa838082db19325ded8d53157feab60a90892d7bb13ebdea205ed94c,2024-06-07T20:15:11.967000
CVE-2024-4904,0,0,44558a4b32290e2f940be10d0a83b859aa6fae2c01ef1c881d37a435bb46f91d,2024-06-04T19:20:52.380000
CVE-2024-4905,0,0,4d48951e7b7cf79f9190550a03c32ee936be1c12de421cb217aeb522ad401862,2024-06-04T19:20:52.480000
CVE-2024-4906,0,0,deae30fe8658d7b7dc2e38990d636f813f81fb947f100adf273391bc50fa76b2,2024-06-04T19:20:52.587000
CVE-2024-4907,0,1,7d3ddcded507d8bb337fa7b5783d69526c12600cfeb19ef48972bfd223e65e2f,2024-06-07T20:15:12.077000
CVE-2024-4907,0,0,7d3ddcded507d8bb337fa7b5783d69526c12600cfeb19ef48972bfd223e65e2f,2024-06-07T20:15:12.077000
CVE-2024-4908,0,0,9e09f6a2f9a218779732fea781667ee8f6dc1ffb9cf3473e4eb2eb5c8236291d,2024-06-04T19:20:52.687000
CVE-2024-4909,0,0,36a6d81d489512b5b8e782e39c8dbe61fff624aa66e5258e6727be91d75f4deb,2024-06-04T19:20:52.787000
CVE-2024-4910,0,0,ac9410e8d259dc7b1afc48d3cc430fd77fc192e7b884d7f8da244fe2bc5c75fc,2024-06-04T19:20:52.883000
@ -252875,7 +252876,7 @@ CVE-2024-5353,0,0,c0452c10a6c3859854731d138a1ea97665b0bb741243aa0e6b3937e8e3c1cd
CVE-2024-5354,0,0,80116fe9070ab6e375db0b5bc0c51c9a36b49ccefb2da1dcb5b0b31c6fff09f4,2024-06-04T19:21:05.783000
CVE-2024-5355,0,0,00aa75f7857f03bd46763179249f6adf8ea2d9b0256cb2c4fe94d6d9216b31a1,2024-06-04T19:21:05.883000
CVE-2024-5356,0,0,f2eb92d8fdbf8fc3e69ce4eb5e3b56734904831419346033963b281f256535d5,2024-06-04T19:21:05.977000
CVE-2024-5357,0,1,bf2649a0aac1b990c8be2f20818d1e301cceaa9a4cd75754df11c382a0068eae,2024-06-07T20:15:12.387000
CVE-2024-5357,0,0,bf2649a0aac1b990c8be2f20818d1e301cceaa9a4cd75754df11c382a0068eae,2024-06-07T20:15:12.387000
CVE-2024-5358,0,0,7bd2768d2d2c24346c504dfa342019ef2f8615878968f4c2c5a31afc23caeee3,2024-06-04T19:21:06.077000
CVE-2024-5359,0,0,1ba440c9c645caa6eccb06eef480e5da606cfb904e19bb5b583740be8e74d910,2024-06-04T19:21:06.183000
CVE-2024-5360,0,0,8c1d79f76afa2b85ca0748d90983b5a266e3fb1389a56ef3e4cb12cba62a8df3,2024-05-28T12:39:42.673000
@ -252887,7 +252888,7 @@ CVE-2024-5365,0,0,91f951b99174e6c9cbb6f95148c2cb72ed6cb8790e556e0dd8eb3187de2b19
CVE-2024-5366,0,0,046d67650c6eafc54b50e85532438e9673e3197d7251bb2d4dc3d1f0384c552f,2024-06-04T19:21:06.690000
CVE-2024-5367,0,0,c983fb545b5267cc9909cd0ed562a0f858fbea315942b13141c76a3624f18134,2024-06-04T19:21:06.783000
CVE-2024-5368,0,0,c5ab8d8f08565dd2921171ed5fb5c11e013b54e9510b359fe024bb053e784807,2024-06-04T19:21:06.887000
CVE-2024-5369,0,1,f6a16380f915ca61925e07e9d2a7846e1e0319237ab149395ce1f955f4382002,2024-06-07T20:15:12.487000
CVE-2024-5369,0,0,f6a16380f915ca61925e07e9d2a7846e1e0319237ab149395ce1f955f4382002,2024-06-07T20:15:12.487000
CVE-2024-5370,0,0,f417daf9e0779e0680052907c0a5ac7a3202a9f5d273948c6c7e52cd6a1aaa87,2024-06-04T19:21:06.980000
CVE-2024-5371,0,0,e63b8991bb41da8424ad90a87ddf537766a9d3bc80c5b993b03423dd4333dd3c,2024-06-04T19:21:07.077000
CVE-2024-5372,0,0,4b10cfb95cc16870dfe3007fb1df5665b7459aaaa10b5e859e7cf8647fa40ee9,2024-05-28T12:39:28.377000
@ -252896,7 +252897,7 @@ CVE-2024-5374,0,0,e29b3f3087c3232ae7e72f5fd8fe02836aa8673f343622e8d7b7398253ad29
CVE-2024-5375,0,0,f64e4c98f9d0653b6d7e7e2e66913a97e2fbb1513853639490417c8b7e05f46f,2024-06-04T19:21:07.297000
CVE-2024-5376,0,0,e0e8040856113b6c405fba07818958405e57a1882a7c47b4395df16782473df6,2024-06-04T19:21:07.390000
CVE-2024-5377,0,0,72f56c4031b9e74b22c9cf48d1b3bf9644a2e5070a378a5e6525d03b10dde518,2024-06-04T19:21:07.497000
CVE-2024-5378,0,1,148a87086232eda42c434d5fe5d00513f3931c1ca72dd0be40d0e8f850360e65,2024-06-07T20:15:12.587000
CVE-2024-5378,0,0,148a87086232eda42c434d5fe5d00513f3931c1ca72dd0be40d0e8f850360e65,2024-06-07T20:15:12.587000
CVE-2024-5379,0,0,277bc909bff1a068e1c48fc1ef4b1615918e5d8487d80bd58ecd8d35c658e8d7,2024-06-04T19:21:07.600000
CVE-2024-5380,0,0,56b659096d0cadc3ed42194acfc455a2eddb616212e0b2f1ca97c16d5fb6cf3f,2024-06-04T19:21:07.720000
CVE-2024-5381,0,0,0ef6ed2792ff355a165fe99f9fd0fc42b814ce55af6ee2eb1b953b6060d4abd6,2024-06-04T19:21:07.820000
@ -252907,7 +252908,7 @@ CVE-2024-5385,0,0,bc3c0d01b2051e708e659a5c3590b7dd8cb9dd588e93f64ca3944fc804f9c9
CVE-2024-5387,0,0,857b2af9507e1fb781392f9f45599eb9ea380f1e8b91dd3c69ea7be187de1f2a,2024-06-03T19:15:09.500000
CVE-2024-5388,0,0,0c90149987e278137050d2b65080c43dd31aa72e74992bde244a30e0d49fbf46,2024-06-03T19:15:09.557000
CVE-2024-5390,0,0,7bbbc0fbbf0080c37ea508796076f5055d10a83119ccd7fea3223bbf180b1d73,2024-06-04T19:21:08.020000
CVE-2024-5391,0,1,00f61420375c40b8d29b33273a9abb170480b355b8f71230d76cd6238a9db4ff,2024-06-07T20:15:12.687000
CVE-2024-5391,0,0,00f61420375c40b8d29b33273a9abb170480b355b8f71230d76cd6238a9db4ff,2024-06-07T20:15:12.687000
CVE-2024-5392,0,0,f7219b2013d34cef28a688dbd5b89c3b8013dcb24b8103dca8d259a586db6696,2024-06-04T19:21:08.117000
CVE-2024-5393,0,0,daa9f838a2f4996c6a08647643f12cdf79bc99391c85739d24201450e8b3cc47,2024-06-04T19:21:08.420000
CVE-2024-5394,0,0,17dbba90f49e761d9504f5f97bd28c7acbc936cdd27f9a1fd596b4898f18a460,2024-06-04T19:21:08.527000
@ -253015,5 +253016,5 @@ CVE-2024-5684,0,0,b2f8ad263f684025e461aeac45146ad505c13a2339a4851373464b5600c433
CVE-2024-5732,0,0,164b158659f154321408f970302d5931abbeea5b0cb278b288a24fa0afd832a5,2024-06-07T15:15:51.007000
CVE-2024-5733,0,0,912af201a333601d8ad85caf06bb206334f6fa2fa638d7d63d5571cfacf454d4,2024-06-07T14:56:05.647000
CVE-2024-5734,0,0,6c2e32afe9f36cd041d920f75c3584a92a72063480e933c9394a66845b572658,2024-06-07T17:15:52.140000
CVE-2024-5745,0,1,9a08beb597625a8f9218e015acd2adbc0482fee791723cecca0d81c8a3e3751e,2024-06-07T21:15:35.677000
CVE-2024-5745,0,0,9a08beb597625a8f9218e015acd2adbc0482fee791723cecca0d81c8a3e3751e,2024-06-07T21:15:35.677000
CVE-2024-5761,0,0,e0022a8d80317cd3941058bae14b514f68707790a5051038049a1d552ba8de69,2024-06-07T19:15:24.467000

Can't render this file because it is too large.