From 036be48390d019397ce2330ea1f8b9acdf808ccd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Apr 2025 18:32:44 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2459-9w34-v79g.json | 2 +- .../GHSA-3q68-3vrx-8h5f.json | 2 +- .../GHSA-436h-cr23-m9m7.json | 2 +- .../GHSA-46rh-mcf3-6v59.json | 3 +- .../GHSA-4c5j-gp4q-69vc.json | 6 ++- .../GHSA-4jg9-9xg2-cc8h.json | 2 +- .../GHSA-4jxg-7cv4-3gcc.json | 6 ++- .../GHSA-4p72-6jxp-vmqx.json | 2 +- .../GHSA-547p-jx2r-224g.json | 6 ++- .../GHSA-6gfq-p2cr-3q5j.json | 6 ++- .../GHSA-6j29-45pf-r9wm.json | 6 ++- .../GHSA-737f-pfm5-cmq6.json | 2 +- .../GHSA-748v-pxm5-9m8q.json | 3 +- .../GHSA-74v3-gjvq-vv7f.json | 2 +- .../GHSA-79cc-3p55-rr77.json | 2 +- .../GHSA-7vcp-35cw-vjp4.json | 6 ++- .../GHSA-9jhw-8cjq-cxc8.json | 2 +- .../GHSA-c55w-hjjc-53ww.json | 2 +- .../GHSA-c7rr-pw6j-xvp5.json | 2 +- .../GHSA-c8rg-fhg7-c5p9.json | 2 +- .../GHSA-f7vm-6g4j-64q8.json | 6 ++- .../GHSA-f82m-4qrp-29gx.json | 2 +- .../GHSA-gx64-jm35-rwvr.json | 2 +- .../GHSA-hj6m-j4xw-c8m8.json | 2 +- .../GHSA-m3h7-qq8m-r923.json | 2 +- .../GHSA-m6jf-wj3w-42j2.json | 2 +- .../GHSA-mj64-2668-m2rv.json | 2 +- .../GHSA-mw2h-r48f-g8c9.json | 2 +- .../GHSA-q68w-fq74-6jp9.json | 3 +- .../GHSA-r7fp-wxjp-2rf9.json | 6 ++- .../GHSA-vwhh-g8g6-6pf7.json | 2 +- .../GHSA-wrfx-qxxc-92rj.json | 2 +- .../GHSA-cgpr-m9mx-94j6.json | 3 +- .../GHSA-3j53-j44c-wp43.json | 15 ++++-- .../GHSA-443g-xxfv-37vx.json | 15 ++++-- .../GHSA-6839-rv39-32jh.json | 3 +- .../GHSA-7grr-8552-9wc6.json | 3 +- .../GHSA-8295-hcjh-5w9p.json | 15 ++++-- .../GHSA-82pw-rh3v-pr35.json | 3 +- .../GHSA-9hcv-xw76-m4h6.json | 6 ++- .../GHSA-cg23-v479-px36.json | 15 ++++-- .../GHSA-cqjv-v7jg-7vp4.json | 3 +- .../GHSA-24hh-5wmw-c8j8.json | 15 ++++-- .../GHSA-24v5-8m4q-mh6j.json | 29 +++++++++++ .../GHSA-25fv-45mr-wm5r.json | 49 +++++++++++++++++++ .../GHSA-2g48-r5cc-hm38.json | 36 ++++++++++++++ .../GHSA-37j4-mqr6-6m6x.json | 36 ++++++++++++++ .../GHSA-4h7q-pj8m-5675.json | 15 ++++-- .../GHSA-4v94-f8pq-mj8v.json | 15 ++++-- .../GHSA-4w84-6c7g-5c25.json | 34 +++++++++++++ .../GHSA-5px9-qgxf-p79c.json | 15 ++++-- .../GHSA-64v9-w92q-4pv8.json | 36 ++++++++++++++ .../GHSA-6m8x-cvmh-fpwm.json | 15 ++++-- .../GHSA-6x8p-pjfm-rgxq.json | 36 ++++++++++++++ .../GHSA-7fc4-8q5h-8mjj.json | 15 ++++-- .../GHSA-7xmj-r3rh-c5m3.json | 36 ++++++++++++++ .../GHSA-9879-4r59-96j2.json | 3 +- .../GHSA-98g5-ch9p-4pc6.json | 29 +++++++++++ .../GHSA-cjrr-3f69-p92j.json | 15 ++++-- .../GHSA-cqjr-x55g-2j6v.json | 15 ++++-- .../GHSA-fchw-692r-4w73.json | 19 +++++-- .../GHSA-fp4x-j6ch-w8q5.json | 40 +++++++++++++++ .../GHSA-h7mj-68q6-fwp5.json | 33 +++++++++++++ .../GHSA-j57r-qmgx-xp34.json | 15 ++++-- .../GHSA-m875-mcc5-r6hx.json | 29 +++++++++++ .../GHSA-p43c-fp87-rj5p.json | 40 +++++++++++++++ .../GHSA-prv3-9p5f-cqv2.json | 37 ++++++++++++++ .../GHSA-q26c-m38m-777f.json | 29 +++++++++++ .../GHSA-qp2m-387q-grcf.json | 29 +++++++++++ .../GHSA-rjg7-w27j-q4vj.json | 29 +++++++++++ .../GHSA-vg6j-x3v7-mwq9.json | 40 +++++++++++++++ .../GHSA-x29x-qf6c-w9cj.json | 34 +++++++++++++ .../GHSA-x97h-4pwx-3c9h.json | 15 ++++-- .../GHSA-x9qw-9cw3-55vf.json | 15 ++++-- .../GHSA-xrq2-2h92-m6m8.json | 40 +++++++++++++++ 75 files changed, 957 insertions(+), 111 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-24v5-8m4q-mh6j/GHSA-24v5-8m4q-mh6j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2g48-r5cc-hm38/GHSA-2g48-r5cc-hm38.json create mode 100644 advisories/unreviewed/2025/04/GHSA-37j4-mqr6-6m6x/GHSA-37j4-mqr6-6m6x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json create mode 100644 advisories/unreviewed/2025/04/GHSA-64v9-w92q-4pv8/GHSA-64v9-w92q-4pv8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6x8p-pjfm-rgxq/GHSA-6x8p-pjfm-rgxq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7xmj-r3rh-c5m3/GHSA-7xmj-r3rh-c5m3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h7mj-68q6-fwp5/GHSA-h7mj-68q6-fwp5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m875-mcc5-r6hx/GHSA-m875-mcc5-r6hx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p43c-fp87-rj5p/GHSA-p43c-fp87-rj5p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q26c-m38m-777f/GHSA-q26c-m38m-777f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qp2m-387q-grcf/GHSA-qp2m-387q-grcf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rjg7-w27j-q4vj/GHSA-rjg7-w27j-q4vj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json diff --git a/advisories/unreviewed/2022/12/GHSA-2459-9w34-v79g/GHSA-2459-9w34-v79g.json b/advisories/unreviewed/2022/12/GHSA-2459-9w34-v79g/GHSA-2459-9w34-v79g.json index a10bc120a74..79bd858fd8d 100644 --- a/advisories/unreviewed/2022/12/GHSA-2459-9w34-v79g/GHSA-2459-9w34-v79g.json +++ b/advisories/unreviewed/2022/12/GHSA-2459-9w34-v79g/GHSA-2459-9w34-v79g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2459-9w34-v79g", - "modified": "2023-01-04T03:30:32Z", + "modified": "2025-04-15T18:31:32Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-36317" diff --git a/advisories/unreviewed/2022/12/GHSA-3q68-3vrx-8h5f/GHSA-3q68-3vrx-8h5f.json b/advisories/unreviewed/2022/12/GHSA-3q68-3vrx-8h5f/GHSA-3q68-3vrx-8h5f.json index a6a79477081..3d25520953b 100644 --- a/advisories/unreviewed/2022/12/GHSA-3q68-3vrx-8h5f/GHSA-3q68-3vrx-8h5f.json +++ b/advisories/unreviewed/2022/12/GHSA-3q68-3vrx-8h5f/GHSA-3q68-3vrx-8h5f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q68-3vrx-8h5f", - "modified": "2023-01-04T03:30:32Z", + "modified": "2025-04-15T18:31:33Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-36318" diff --git a/advisories/unreviewed/2022/12/GHSA-436h-cr23-m9m7/GHSA-436h-cr23-m9m7.json b/advisories/unreviewed/2022/12/GHSA-436h-cr23-m9m7/GHSA-436h-cr23-m9m7.json index f45aad3a8cf..80c101d7784 100644 --- a/advisories/unreviewed/2022/12/GHSA-436h-cr23-m9m7/GHSA-436h-cr23-m9m7.json +++ b/advisories/unreviewed/2022/12/GHSA-436h-cr23-m9m7/GHSA-436h-cr23-m9m7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-436h-cr23-m9m7", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-45405" diff --git a/advisories/unreviewed/2022/12/GHSA-46rh-mcf3-6v59/GHSA-46rh-mcf3-6v59.json b/advisories/unreviewed/2022/12/GHSA-46rh-mcf3-6v59/GHSA-46rh-mcf3-6v59.json index cb793c05240..939059b00f4 100644 --- a/advisories/unreviewed/2022/12/GHSA-46rh-mcf3-6v59/GHSA-46rh-mcf3-6v59.json +++ b/advisories/unreviewed/2022/12/GHSA-46rh-mcf3-6v59/GHSA-46rh-mcf3-6v59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46rh-mcf3-6v59", - "modified": "2022-12-30T18:30:44Z", + "modified": "2025-04-15T18:31:31Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-34484" @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-617" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-4c5j-gp4q-69vc/GHSA-4c5j-gp4q-69vc.json b/advisories/unreviewed/2022/12/GHSA-4c5j-gp4q-69vc/GHSA-4c5j-gp4q-69vc.json index 2ec4045ab0f..045d4c0c507 100644 --- a/advisories/unreviewed/2022/12/GHSA-4c5j-gp4q-69vc/GHSA-4c5j-gp4q-69vc.json +++ b/advisories/unreviewed/2022/12/GHSA-4c5j-gp4q-69vc/GHSA-4c5j-gp4q-69vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4c5j-gp4q-69vc", - "modified": "2023-01-04T06:30:35Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40957" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-240" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4jg9-9xg2-cc8h/GHSA-4jg9-9xg2-cc8h.json b/advisories/unreviewed/2022/12/GHSA-4jg9-9xg2-cc8h/GHSA-4jg9-9xg2-cc8h.json index bb284c9222e..161da753076 100644 --- a/advisories/unreviewed/2022/12/GHSA-4jg9-9xg2-cc8h/GHSA-4jg9-9xg2-cc8h.json +++ b/advisories/unreviewed/2022/12/GHSA-4jg9-9xg2-cc8h/GHSA-4jg9-9xg2-cc8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jg9-9xg2-cc8h", - "modified": "2023-01-04T03:30:31Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-42928" diff --git a/advisories/unreviewed/2022/12/GHSA-4jxg-7cv4-3gcc/GHSA-4jxg-7cv4-3gcc.json b/advisories/unreviewed/2022/12/GHSA-4jxg-7cv4-3gcc/GHSA-4jxg-7cv4-3gcc.json index 9e868fd3603..9298f282cf7 100644 --- a/advisories/unreviewed/2022/12/GHSA-4jxg-7cv4-3gcc/GHSA-4jxg-7cv4-3gcc.json +++ b/advisories/unreviewed/2022/12/GHSA-4jxg-7cv4-3gcc/GHSA-4jxg-7cv4-3gcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jxg-7cv4-3gcc", - "modified": "2023-01-04T03:30:32Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-36319" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1021" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4p72-6jxp-vmqx/GHSA-4p72-6jxp-vmqx.json b/advisories/unreviewed/2022/12/GHSA-4p72-6jxp-vmqx/GHSA-4p72-6jxp-vmqx.json index 838f5e32c1c..68f44025c51 100644 --- a/advisories/unreviewed/2022/12/GHSA-4p72-6jxp-vmqx/GHSA-4p72-6jxp-vmqx.json +++ b/advisories/unreviewed/2022/12/GHSA-4p72-6jxp-vmqx/GHSA-4p72-6jxp-vmqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p72-6jxp-vmqx", - "modified": "2023-01-04T06:30:35Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-45403" diff --git a/advisories/unreviewed/2022/12/GHSA-547p-jx2r-224g/GHSA-547p-jx2r-224g.json b/advisories/unreviewed/2022/12/GHSA-547p-jx2r-224g/GHSA-547p-jx2r-224g.json index 222a0b02c4f..63d71c67702 100644 --- a/advisories/unreviewed/2022/12/GHSA-547p-jx2r-224g/GHSA-547p-jx2r-224g.json +++ b/advisories/unreviewed/2022/12/GHSA-547p-jx2r-224g/GHSA-547p-jx2r-224g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-547p-jx2r-224g", - "modified": "2023-01-04T18:31:01Z", + "modified": "2025-04-15T18:31:35Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-45404" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6gfq-p2cr-3q5j/GHSA-6gfq-p2cr-3q5j.json b/advisories/unreviewed/2022/12/GHSA-6gfq-p2cr-3q5j/GHSA-6gfq-p2cr-3q5j.json index b25524e099a..85eef52f4a0 100644 --- a/advisories/unreviewed/2022/12/GHSA-6gfq-p2cr-3q5j/GHSA-6gfq-p2cr-3q5j.json +++ b/advisories/unreviewed/2022/12/GHSA-6gfq-p2cr-3q5j/GHSA-6gfq-p2cr-3q5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gfq-p2cr-3q5j", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-3155" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6j29-45pf-r9wm/GHSA-6j29-45pf-r9wm.json b/advisories/unreviewed/2022/12/GHSA-6j29-45pf-r9wm/GHSA-6j29-45pf-r9wm.json index cc7165d87f1..25e5777e96e 100644 --- a/advisories/unreviewed/2022/12/GHSA-6j29-45pf-r9wm/GHSA-6j29-45pf-r9wm.json +++ b/advisories/unreviewed/2022/12/GHSA-6j29-45pf-r9wm/GHSA-6j29-45pf-r9wm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6j29-45pf-r9wm", - "modified": "2023-01-04T03:30:31Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-42929" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-737f-pfm5-cmq6/GHSA-737f-pfm5-cmq6.json b/advisories/unreviewed/2022/12/GHSA-737f-pfm5-cmq6/GHSA-737f-pfm5-cmq6.json index 494576f1faf..8a8b24a0c31 100644 --- a/advisories/unreviewed/2022/12/GHSA-737f-pfm5-cmq6/GHSA-737f-pfm5-cmq6.json +++ b/advisories/unreviewed/2022/12/GHSA-737f-pfm5-cmq6/GHSA-737f-pfm5-cmq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-737f-pfm5-cmq6", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-42930" diff --git a/advisories/unreviewed/2022/12/GHSA-748v-pxm5-9m8q/GHSA-748v-pxm5-9m8q.json b/advisories/unreviewed/2022/12/GHSA-748v-pxm5-9m8q/GHSA-748v-pxm5-9m8q.json index 54d0e6c6861..6a14d577e0b 100644 --- a/advisories/unreviewed/2022/12/GHSA-748v-pxm5-9m8q/GHSA-748v-pxm5-9m8q.json +++ b/advisories/unreviewed/2022/12/GHSA-748v-pxm5-9m8q/GHSA-748v-pxm5-9m8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-748v-pxm5-9m8q", - "modified": "2023-01-04T03:30:31Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-42931" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-922" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/12/GHSA-74v3-gjvq-vv7f/GHSA-74v3-gjvq-vv7f.json b/advisories/unreviewed/2022/12/GHSA-74v3-gjvq-vv7f/GHSA-74v3-gjvq-vv7f.json index c30a4be12f4..f8776b4238e 100644 --- a/advisories/unreviewed/2022/12/GHSA-74v3-gjvq-vv7f/GHSA-74v3-gjvq-vv7f.json +++ b/advisories/unreviewed/2022/12/GHSA-74v3-gjvq-vv7f/GHSA-74v3-gjvq-vv7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74v3-gjvq-vv7f", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-40956" diff --git a/advisories/unreviewed/2022/12/GHSA-79cc-3p55-rr77/GHSA-79cc-3p55-rr77.json b/advisories/unreviewed/2022/12/GHSA-79cc-3p55-rr77/GHSA-79cc-3p55-rr77.json index 666f71bdf4a..1c84dcb3467 100644 --- a/advisories/unreviewed/2022/12/GHSA-79cc-3p55-rr77/GHSA-79cc-3p55-rr77.json +++ b/advisories/unreviewed/2022/12/GHSA-79cc-3p55-rr77/GHSA-79cc-3p55-rr77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79cc-3p55-rr77", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-38477" diff --git a/advisories/unreviewed/2022/12/GHSA-7vcp-35cw-vjp4/GHSA-7vcp-35cw-vjp4.json b/advisories/unreviewed/2022/12/GHSA-7vcp-35cw-vjp4/GHSA-7vcp-35cw-vjp4.json index 573a905d0cb..2ef2dd3205a 100644 --- a/advisories/unreviewed/2022/12/GHSA-7vcp-35cw-vjp4/GHSA-7vcp-35cw-vjp4.json +++ b/advisories/unreviewed/2022/12/GHSA-7vcp-35cw-vjp4/GHSA-7vcp-35cw-vjp4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7vcp-35cw-vjp4", - "modified": "2022-12-30T18:30:44Z", + "modified": "2025-04-15T18:31:30Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-34482" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-9jhw-8cjq-cxc8/GHSA-9jhw-8cjq-cxc8.json b/advisories/unreviewed/2022/12/GHSA-9jhw-8cjq-cxc8/GHSA-9jhw-8cjq-cxc8.json index 02a04e6ffdd..3bd6ce759e7 100644 --- a/advisories/unreviewed/2022/12/GHSA-9jhw-8cjq-cxc8/GHSA-9jhw-8cjq-cxc8.json +++ b/advisories/unreviewed/2022/12/GHSA-9jhw-8cjq-cxc8/GHSA-9jhw-8cjq-cxc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jhw-8cjq-cxc8", - "modified": "2023-01-04T03:30:31Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-42927" diff --git a/advisories/unreviewed/2022/12/GHSA-c55w-hjjc-53ww/GHSA-c55w-hjjc-53ww.json b/advisories/unreviewed/2022/12/GHSA-c55w-hjjc-53ww/GHSA-c55w-hjjc-53ww.json index 1b79287ecf3..ecffbdf8838 100644 --- a/advisories/unreviewed/2022/12/GHSA-c55w-hjjc-53ww/GHSA-c55w-hjjc-53ww.json +++ b/advisories/unreviewed/2022/12/GHSA-c55w-hjjc-53ww/GHSA-c55w-hjjc-53ww.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c55w-hjjc-53ww", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-38474" diff --git a/advisories/unreviewed/2022/12/GHSA-c7rr-pw6j-xvp5/GHSA-c7rr-pw6j-xvp5.json b/advisories/unreviewed/2022/12/GHSA-c7rr-pw6j-xvp5/GHSA-c7rr-pw6j-xvp5.json index 2cee7429083..8fd2f1b26d9 100644 --- a/advisories/unreviewed/2022/12/GHSA-c7rr-pw6j-xvp5/GHSA-c7rr-pw6j-xvp5.json +++ b/advisories/unreviewed/2022/12/GHSA-c7rr-pw6j-xvp5/GHSA-c7rr-pw6j-xvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c7rr-pw6j-xvp5", - "modified": "2023-01-03T21:30:19Z", + "modified": "2025-04-15T18:31:33Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-36320" diff --git a/advisories/unreviewed/2022/12/GHSA-c8rg-fhg7-c5p9/GHSA-c8rg-fhg7-c5p9.json b/advisories/unreviewed/2022/12/GHSA-c8rg-fhg7-c5p9/GHSA-c8rg-fhg7-c5p9.json index e103d28ddee..eb1817e583d 100644 --- a/advisories/unreviewed/2022/12/GHSA-c8rg-fhg7-c5p9/GHSA-c8rg-fhg7-c5p9.json +++ b/advisories/unreviewed/2022/12/GHSA-c8rg-fhg7-c5p9/GHSA-c8rg-fhg7-c5p9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8rg-fhg7-c5p9", - "modified": "2022-12-30T18:30:44Z", + "modified": "2025-04-15T18:31:31Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-34485" diff --git a/advisories/unreviewed/2022/12/GHSA-f7vm-6g4j-64q8/GHSA-f7vm-6g4j-64q8.json b/advisories/unreviewed/2022/12/GHSA-f7vm-6g4j-64q8/GHSA-f7vm-6g4j-64q8.json index 134dae6f036..78156ff1162 100644 --- a/advisories/unreviewed/2022/12/GHSA-f7vm-6g4j-64q8/GHSA-f7vm-6g4j-64q8.json +++ b/advisories/unreviewed/2022/12/GHSA-f7vm-6g4j-64q8/GHSA-f7vm-6g4j-64q8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f7vm-6g4j-64q8", - "modified": "2022-12-30T18:30:44Z", + "modified": "2025-04-15T18:31:30Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-34483" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-f82m-4qrp-29gx/GHSA-f82m-4qrp-29gx.json b/advisories/unreviewed/2022/12/GHSA-f82m-4qrp-29gx/GHSA-f82m-4qrp-29gx.json index ce6b59c1943..1eecfaa3d96 100644 --- a/advisories/unreviewed/2022/12/GHSA-f82m-4qrp-29gx/GHSA-f82m-4qrp-29gx.json +++ b/advisories/unreviewed/2022/12/GHSA-f82m-4qrp-29gx/GHSA-f82m-4qrp-29gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f82m-4qrp-29gx", - "modified": "2022-12-30T21:30:16Z", + "modified": "2025-04-15T18:31:30Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-34481" diff --git a/advisories/unreviewed/2022/12/GHSA-gx64-jm35-rwvr/GHSA-gx64-jm35-rwvr.json b/advisories/unreviewed/2022/12/GHSA-gx64-jm35-rwvr/GHSA-gx64-jm35-rwvr.json index 52842d24596..fe80316ef78 100644 --- a/advisories/unreviewed/2022/12/GHSA-gx64-jm35-rwvr/GHSA-gx64-jm35-rwvr.json +++ b/advisories/unreviewed/2022/12/GHSA-gx64-jm35-rwvr/GHSA-gx64-jm35-rwvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx64-jm35-rwvr", - "modified": "2022-12-30T18:30:44Z", + "modified": "2025-04-15T18:31:30Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-34480" diff --git a/advisories/unreviewed/2022/12/GHSA-hj6m-j4xw-c8m8/GHSA-hj6m-j4xw-c8m8.json b/advisories/unreviewed/2022/12/GHSA-hj6m-j4xw-c8m8/GHSA-hj6m-j4xw-c8m8.json index b3a0be31695..9242a427544 100644 --- a/advisories/unreviewed/2022/12/GHSA-hj6m-j4xw-c8m8/GHSA-hj6m-j4xw-c8m8.json +++ b/advisories/unreviewed/2022/12/GHSA-hj6m-j4xw-c8m8/GHSA-hj6m-j4xw-c8m8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hj6m-j4xw-c8m8", - "modified": "2023-01-04T06:30:35Z", + "modified": "2025-04-15T18:31:32Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-36316" diff --git a/advisories/unreviewed/2022/12/GHSA-m3h7-qq8m-r923/GHSA-m3h7-qq8m-r923.json b/advisories/unreviewed/2022/12/GHSA-m3h7-qq8m-r923/GHSA-m3h7-qq8m-r923.json index 8c5b1017728..742a4484241 100644 --- a/advisories/unreviewed/2022/12/GHSA-m3h7-qq8m-r923/GHSA-m3h7-qq8m-r923.json +++ b/advisories/unreviewed/2022/12/GHSA-m3h7-qq8m-r923/GHSA-m3h7-qq8m-r923.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3h7-qq8m-r923", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T18:31:33Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-3266" diff --git a/advisories/unreviewed/2022/12/GHSA-m6jf-wj3w-42j2/GHSA-m6jf-wj3w-42j2.json b/advisories/unreviewed/2022/12/GHSA-m6jf-wj3w-42j2/GHSA-m6jf-wj3w-42j2.json index 08d563bc24a..09aefb75e2c 100644 --- a/advisories/unreviewed/2022/12/GHSA-m6jf-wj3w-42j2/GHSA-m6jf-wj3w-42j2.json +++ b/advisories/unreviewed/2022/12/GHSA-m6jf-wj3w-42j2/GHSA-m6jf-wj3w-42j2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6jf-wj3w-42j2", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T18:31:31Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-36314" diff --git a/advisories/unreviewed/2022/12/GHSA-mj64-2668-m2rv/GHSA-mj64-2668-m2rv.json b/advisories/unreviewed/2022/12/GHSA-mj64-2668-m2rv/GHSA-mj64-2668-m2rv.json index 43e8c5c1054..cd6f45d4191 100644 --- a/advisories/unreviewed/2022/12/GHSA-mj64-2668-m2rv/GHSA-mj64-2668-m2rv.json +++ b/advisories/unreviewed/2022/12/GHSA-mj64-2668-m2rv/GHSA-mj64-2668-m2rv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mj64-2668-m2rv", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-38476" diff --git a/advisories/unreviewed/2022/12/GHSA-mw2h-r48f-g8c9/GHSA-mw2h-r48f-g8c9.json b/advisories/unreviewed/2022/12/GHSA-mw2h-r48f-g8c9/GHSA-mw2h-r48f-g8c9.json index 76533ac2fca..703729e9631 100644 --- a/advisories/unreviewed/2022/12/GHSA-mw2h-r48f-g8c9/GHSA-mw2h-r48f-g8c9.json +++ b/advisories/unreviewed/2022/12/GHSA-mw2h-r48f-g8c9/GHSA-mw2h-r48f-g8c9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw2h-r48f-g8c9", - "modified": "2023-01-04T03:30:31Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-42932" diff --git a/advisories/unreviewed/2022/12/GHSA-q68w-fq74-6jp9/GHSA-q68w-fq74-6jp9.json b/advisories/unreviewed/2022/12/GHSA-q68w-fq74-6jp9/GHSA-q68w-fq74-6jp9.json index 5abc61ec587..b5f9c8519cd 100644 --- a/advisories/unreviewed/2022/12/GHSA-q68w-fq74-6jp9/GHSA-q68w-fq74-6jp9.json +++ b/advisories/unreviewed/2022/12/GHSA-q68w-fq74-6jp9/GHSA-q68w-fq74-6jp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q68w-fq74-6jp9", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T18:31:33Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-3033" @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-r7fp-wxjp-2rf9/GHSA-r7fp-wxjp-2rf9.json b/advisories/unreviewed/2022/12/GHSA-r7fp-wxjp-2rf9/GHSA-r7fp-wxjp-2rf9.json index 95b1944d2e6..02f120a4f48 100644 --- a/advisories/unreviewed/2022/12/GHSA-r7fp-wxjp-2rf9/GHSA-r7fp-wxjp-2rf9.json +++ b/advisories/unreviewed/2022/12/GHSA-r7fp-wxjp-2rf9/GHSA-r7fp-wxjp-2rf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7fp-wxjp-2rf9", - "modified": "2023-01-03T15:30:16Z", + "modified": "2025-04-15T18:31:30Z", "published": "2022-12-22T21:30:29Z", "aliases": [ "CVE-2022-29915" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-vwhh-g8g6-6pf7/GHSA-vwhh-g8g6-6pf7.json b/advisories/unreviewed/2022/12/GHSA-vwhh-g8g6-6pf7/GHSA-vwhh-g8g6-6pf7.json index 12a94a3ac42..d2076f968fa 100644 --- a/advisories/unreviewed/2022/12/GHSA-vwhh-g8g6-6pf7/GHSA-vwhh-g8g6-6pf7.json +++ b/advisories/unreviewed/2022/12/GHSA-vwhh-g8g6-6pf7/GHSA-vwhh-g8g6-6pf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwhh-g8g6-6pf7", - "modified": "2023-01-03T21:30:20Z", + "modified": "2025-04-15T18:31:33Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-38475" diff --git a/advisories/unreviewed/2022/12/GHSA-wrfx-qxxc-92rj/GHSA-wrfx-qxxc-92rj.json b/advisories/unreviewed/2022/12/GHSA-wrfx-qxxc-92rj/GHSA-wrfx-qxxc-92rj.json index 19a0a32963f..1bc4c07a561 100644 --- a/advisories/unreviewed/2022/12/GHSA-wrfx-qxxc-92rj/GHSA-wrfx-qxxc-92rj.json +++ b/advisories/unreviewed/2022/12/GHSA-wrfx-qxxc-92rj/GHSA-wrfx-qxxc-92rj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrfx-qxxc-92rj", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T18:31:34Z", "published": "2022-12-22T21:30:28Z", "aliases": [ "CVE-2022-3034" diff --git a/advisories/unreviewed/2024/05/GHSA-cgpr-m9mx-94j6/GHSA-cgpr-m9mx-94j6.json b/advisories/unreviewed/2024/05/GHSA-cgpr-m9mx-94j6/GHSA-cgpr-m9mx-94j6.json index 1ac032e9b35..88cc2b4b239 100644 --- a/advisories/unreviewed/2024/05/GHSA-cgpr-m9mx-94j6/GHSA-cgpr-m9mx-94j6.json +++ b/advisories/unreviewed/2024/05/GHSA-cgpr-m9mx-94j6/GHSA-cgpr-m9mx-94j6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-124" + "CWE-124", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json b/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json index c8ffa61fc2d..523c7717fd7 100644 --- a/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json +++ b/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3j53-j44c-wp43", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T18:31:41Z", "published": "2025-03-27T18:31:25Z", "aliases": [ "CVE-2023-52936" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup()\n\nWhen calling debugfs_lookup() the result must have dput() called on it,\notherwise the memory will leak over time. To make things simpler, just\ncall debugfs_lookup_and_remove() instead which handles all of the logic\nat once.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json b/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json index 87a1bf68321..ca77b96c437 100644 --- a/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json +++ b/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-443g-xxfv-37vx", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-03-27T18:31:25Z", "aliases": [ "CVE-2023-52932" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/swapfile: add cond_resched() in get_swap_pages()\n\nThe softlockup still occurs in get_swap_pages() under memory pressure. 64\nCPU cores, 64GB memory, and 28 zram devices, the disksize of each zram\ndevice is 50MB with same priority as si. Use the stress-ng tool to\nincrease memory pressure, causing the system to oom frequently.\n\nThe plist_for_each_entry_safe() loops in get_swap_pages() could reach tens\nof thousands of times to find available space (extreme case:\ncond_resched() is not called in scan_swap_map_slots()). Let's add\ncond_resched() into get_swap_pages() when failed to find available space\nto avoid softlockup.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6839-rv39-32jh/GHSA-6839-rv39-32jh.json b/advisories/unreviewed/2025/03/GHSA-6839-rv39-32jh/GHSA-6839-rv39-32jh.json index 2dca77846fd..cbc9b183560 100644 --- a/advisories/unreviewed/2025/03/GHSA-6839-rv39-32jh/GHSA-6839-rv39-32jh.json +++ b/advisories/unreviewed/2025/03/GHSA-6839-rv39-32jh/GHSA-6839-rv39-32jh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-7grr-8552-9wc6/GHSA-7grr-8552-9wc6.json b/advisories/unreviewed/2025/03/GHSA-7grr-8552-9wc6/GHSA-7grr-8552-9wc6.json index c9db08cecc0..0fee8e05f0f 100644 --- a/advisories/unreviewed/2025/03/GHSA-7grr-8552-9wc6/GHSA-7grr-8552-9wc6.json +++ b/advisories/unreviewed/2025/03/GHSA-7grr-8552-9wc6/GHSA-7grr-8552-9wc6.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json b/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json index 9810c3ce79c..846cd122647 100644 --- a/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json +++ b/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8295-hcjh-5w9p", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T18:31:41Z", "published": "2025-03-27T18:31:25Z", "aliases": [ "CVE-2023-52930" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix potential bit_17 double-free\n\nA userspace with multiple threads racing I915_GEM_SET_TILING to set the\ntiling to I915_TILING_NONE could trigger a double free of the bit_17\nbitmask. (Or conversely leak memory on the transition to tiled.) Move\nallocation/free'ing of the bitmask within the section protected by the\nobj lock.\n\n[tursulin: Correct fixes tag and added cc stable.]\n(cherry picked from commit 10e0cbaaf1104f449d695c80bcacf930dcd3c42e)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-82pw-rh3v-pr35/GHSA-82pw-rh3v-pr35.json b/advisories/unreviewed/2025/03/GHSA-82pw-rh3v-pr35/GHSA-82pw-rh3v-pr35.json index f686929f59c..2911dee52ef 100644 --- a/advisories/unreviewed/2025/03/GHSA-82pw-rh3v-pr35/GHSA-82pw-rh3v-pr35.json +++ b/advisories/unreviewed/2025/03/GHSA-82pw-rh3v-pr35/GHSA-82pw-rh3v-pr35.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-476" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json index 94d1bf139d7..648bf21306e 100644 --- a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json +++ b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcv-xw76-m4h6", - "modified": "2025-04-09T09:31:24Z", + "modified": "2025-04-15T18:31:41Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2024-8176" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:3734" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3913" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8176" diff --git a/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json b/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json index bb0cb57e6ff..2a713c3ff5c 100644 --- a/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json +++ b/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cg23-v479-px36", - "modified": "2025-03-27T18:31:25Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-03-27T18:31:25Z", "aliases": [ "CVE-2023-52937" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHV: hv_balloon: fix memory leak with using debugfs_lookup()\n\nWhen calling debugfs_lookup() the result must have dput() called on it,\notherwise the memory will leak over time. To make things simpler, just\ncall debugfs_lookup_and_remove() instead which handles all of the logic\nat once.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T17:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cqjv-v7jg-7vp4/GHSA-cqjv-v7jg-7vp4.json b/advisories/unreviewed/2025/03/GHSA-cqjv-v7jg-7vp4/GHSA-cqjv-v7jg-7vp4.json index b8b9c0085db..b7513e9c543 100644 --- a/advisories/unreviewed/2025/03/GHSA-cqjv-v7jg-7vp4/GHSA-cqjv-v7jg-7vp4.json +++ b/advisories/unreviewed/2025/03/GHSA-cqjv-v7jg-7vp4/GHSA-cqjv-v7jg-7vp4.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json b/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json index 522c5497bdf..7ebe4ab99a2 100644 --- a/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json +++ b/advisories/unreviewed/2025/04/GHSA-24hh-5wmw-c8j8/GHSA-24hh-5wmw-c8j8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24hh-5wmw-c8j8", - "modified": "2025-04-15T15:30:53Z", + "modified": "2025-04-15T18:31:43Z", "published": "2025-04-15T15:30:53Z", "aliases": [ "CVE-2025-29280" ], "details": "Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T14:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-24v5-8m4q-mh6j/GHSA-24v5-8m4q-mh6j.json b/advisories/unreviewed/2025/04/GHSA-24v5-8m4q-mh6j/GHSA-24v5-8m4q-mh6j.json new file mode 100644 index 00000000000..980f61b89ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24v5-8m4q-mh6j/GHSA-24v5-8m4q-mh6j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24v5-8m4q-mh6j", + "modified": "2025-04-15T18:31:45Z", + "published": "2025-04-15T18:31:44Z", + "aliases": [ + "CVE-2025-28198" + ], + "details": "A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the orderBy parameter of the StoreController.java component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28198" + }, + { + "type": "WEB", + "url": "https://github.com/Hitout/carsale/issues/24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json b/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json new file mode 100644 index 00000000000..247fde0ed67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-25fv-45mr-wm5r/GHSA-25fv-45mr-wm5r.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25fv-45mr-wm5r", + "modified": "2025-04-15T18:31:46Z", + "published": "2025-04-15T18:31:46Z", + "aliases": [ + "CVE-2021-27289" + ], + "details": "A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27289" + }, + { + "type": "WEB", + "url": "https://github.com/TheMalwareGuardian/CVE-2021-27289" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/160331/Ksix-Zigbee-Devices-Playback-Protection-Bypass.html" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/49169" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=5IFUpRKEioA" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=XFOy3wSlC9Q" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=yc9IEt5IMmA" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2g48-r5cc-hm38/GHSA-2g48-r5cc-hm38.json b/advisories/unreviewed/2025/04/GHSA-2g48-r5cc-hm38/GHSA-2g48-r5cc-hm38.json new file mode 100644 index 00000000000..2af9fff97a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2g48-r5cc-hm38/GHSA-2g48-r5cc-hm38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g48-r5cc-hm38", + "modified": "2025-04-15T18:31:46Z", + "published": "2025-04-15T18:31:46Z", + "aliases": [ + "CVE-2024-42200" + ], + "details": "HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42200" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120585" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-37j4-mqr6-6m6x/GHSA-37j4-mqr6-6m6x.json b/advisories/unreviewed/2025/04/GHSA-37j4-mqr6-6m6x/GHSA-37j4-mqr6-6m6x.json new file mode 100644 index 00000000000..11630504872 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37j4-mqr6-6m6x/GHSA-37j4-mqr6-6m6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37j4-mqr6-6m6x", + "modified": "2025-04-15T18:31:46Z", + "published": "2025-04-15T18:31:46Z", + "aliases": [ + "CVE-2024-42189" + ], + "details": "HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42189" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120585" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json b/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json index 022a21241d6..04ad4ddb298 100644 --- a/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json +++ b/advisories/unreviewed/2025/04/GHSA-4h7q-pj8m-5675/GHSA-4h7q-pj8m-5675.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4h7q-pj8m-5675", - "modified": "2025-04-15T15:30:54Z", + "modified": "2025-04-15T18:31:43Z", "published": "2025-04-15T15:30:54Z", "aliases": [ "CVE-2025-3523" ], "details": "When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability affects Thunderbird < 137.0.2 and Thunderbird < 128.9.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T15:16:09Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json b/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json index bf111ab2a1f..07cb4a05a49 100644 --- a/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json +++ b/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4v94-f8pq-mj8v", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21915" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncdx: Fix possible UAF error in driver_override_show()\n\nFixed a possible UAF problem in driver_override_show() in drivers/cdx/cdx.c\n\nThis function driver_override_show() is part of DEVICE_ATTR_RW, which\nincludes both driver_override_show() and driver_override_store().\nThese functions can be executed concurrently in sysfs.\n\nThe driver_override_store() function uses driver_set_override() to\nupdate the driver_override value, and driver_set_override() internally\nlocks the device (device_lock(dev)). If driver_override_show() reads\ncdx_dev->driver_override without locking, it could potentially access\na freed pointer if driver_override_store() frees the string\nconcurrently. This could lead to printing a kernel address, which is a\nsecurity risk since DEVICE_ATTR can be read by all users.\n\nAdditionally, a similar pattern is used in drivers/amba/bus.c, as well\nas many other bus drivers, where device_lock() is taken in the show\nfunction, and it has been working without issues.\n\nThis potential bug was detected by our experimental static analysis\ntool, which analyzes locking APIs and paired functions to identify\ndata races and atomicity violations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json b/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json new file mode 100644 index 00000000000..e938804cb91 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w84-6c7g-5c25", + "modified": "2025-04-15T18:31:48Z", + "published": "2025-04-15T18:31:48Z", + "aliases": [ + "CVE-2025-3618" + ], + "details": "A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3618" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1727.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json b/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json index aae26f1b488..c68d579cf41 100644 --- a/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json +++ b/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5px9-qgxf-p79c", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21900" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix a deadlock when recovering state on a sillyrenamed file\n\nIf the file is sillyrenamed, and slated for delete on close, it is\npossible for a server reboot to triggeer an open reclaim, with can again\nrace with the application call to close(). When that happens, the call\nto put_nfs_open_context() can trigger a synchronous delegreturn call\nwhich deadlocks because it is not marked as privileged.\n\nInstead, ensure that the call to nfs4_inode_return_delegation_on_close()\ncatches the delegreturn, and schedules it asynchronously.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-64v9-w92q-4pv8/GHSA-64v9-w92q-4pv8.json b/advisories/unreviewed/2025/04/GHSA-64v9-w92q-4pv8/GHSA-64v9-w92q-4pv8.json new file mode 100644 index 00000000000..27d30ee7ed9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-64v9-w92q-4pv8/GHSA-64v9-w92q-4pv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64v9-w92q-4pv8", + "modified": "2025-04-15T18:31:45Z", + "published": "2025-04-15T18:31:45Z", + "aliases": [ + "CVE-2025-29817" + ], + "details": "Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29817" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29817" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json b/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json index 7e8f8d6dabe..50b795897ce 100644 --- a/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json +++ b/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6m8x-cvmh-fpwm", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21908" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix nfs_release_folio() to not deadlock via kcompactd writeback\n\nAdd PF_KCOMPACTD flag and current_is_kcompactd() helper to check for it so\nnfs_release_folio() can skip calling nfs_wb_folio() from kcompactd.\n\nOtherwise NFS can deadlock waiting for kcompactd enduced writeback which\nrecurses back to NFS (which triggers writeback to NFSD via NFS loopback\nmount on the same host, NFSD blocks waiting for XFS's call to\n__filemap_get_folio):\n\n6070.550357] INFO: task kcompactd0:58 blocked for more than 4435 seconds.\n\n{---\n[58] \"kcompactd0\"\n[<0>] folio_wait_bit+0xe8/0x200\n[<0>] folio_wait_writeback+0x2b/0x80\n[<0>] nfs_wb_folio+0x80/0x1b0 [nfs]\n[<0>] nfs_release_folio+0x68/0x130 [nfs]\n[<0>] split_huge_page_to_list_to_order+0x362/0x840\n[<0>] migrate_pages_batch+0x43d/0xb90\n[<0>] migrate_pages_sync+0x9a/0x240\n[<0>] migrate_pages+0x93c/0x9f0\n[<0>] compact_zone+0x8e2/0x1030\n[<0>] compact_node+0xdb/0x120\n[<0>] kcompactd+0x121/0x2e0\n[<0>] kthread+0xcf/0x100\n[<0>] ret_from_fork+0x31/0x40\n[<0>] ret_from_fork_asm+0x1a/0x30\n---}\n\n[akpm@linux-foundation.org: fix build]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6x8p-pjfm-rgxq/GHSA-6x8p-pjfm-rgxq.json b/advisories/unreviewed/2025/04/GHSA-6x8p-pjfm-rgxq/GHSA-6x8p-pjfm-rgxq.json new file mode 100644 index 00000000000..b75e47d469d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6x8p-pjfm-rgxq/GHSA-6x8p-pjfm-rgxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x8p-pjfm-rgxq", + "modified": "2025-04-15T18:31:44Z", + "published": "2025-04-15T18:31:44Z", + "aliases": [ + "CVE-2024-13177" + ], + "details": "Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”. A standard user could potentially create a symlink of the file “nsinstallation” to escalate the privileges of a different file on the system. \nThis issue affects Netskope Client: before 123.0, before 117.1.11.2310, before 120.1.10.2306.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13177" + }, + { + "type": "WEB", + "url": "https://support.netskope.com/s/article/Netskope-Security-Advisory-Netskope-Client-installer-with-symbolic-link-following-vulnerability-leading-to-privilege-escalation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-610" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json b/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json index 35d6b446e3b..cd593528d3f 100644 --- a/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json +++ b/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7fc4-8q5h-8mjj", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21905" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: limit printed string from FW file\n\nThere's no guarantee here that the file is always with a\nNUL-termination, so reading the string may read beyond the\nend of the TLV. If that's the last TLV in the file, it can\nperhaps even read beyond the end of the file buffer.\n\nFix that by limiting the print format to the size of the\nbuffer we have.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7xmj-r3rh-c5m3/GHSA-7xmj-r3rh-c5m3.json b/advisories/unreviewed/2025/04/GHSA-7xmj-r3rh-c5m3/GHSA-7xmj-r3rh-c5m3.json new file mode 100644 index 00000000000..38046869f6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7xmj-r3rh-c5m3/GHSA-7xmj-r3rh-c5m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xmj-r3rh-c5m3", + "modified": "2025-04-15T18:31:44Z", + "published": "2025-04-15T18:31:44Z", + "aliases": [ + "CVE-2024-11084" + ], + "details": "Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11084" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SeWbYAK" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9879-4r59-96j2/GHSA-9879-4r59-96j2.json b/advisories/unreviewed/2025/04/GHSA-9879-4r59-96j2/GHSA-9879-4r59-96j2.json index 1bab686ac3e..1509074480e 100644 --- a/advisories/unreviewed/2025/04/GHSA-9879-4r59-96j2/GHSA-9879-4r59-96j2.json +++ b/advisories/unreviewed/2025/04/GHSA-9879-4r59-96j2/GHSA-9879-4r59-96j2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json b/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json new file mode 100644 index 00000000000..632442d32f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-98g5-ch9p-4pc6/GHSA-98g5-ch9p-4pc6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98g5-ch9p-4pc6", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:47Z", + "aliases": [ + "CVE-2025-28100" + ], + "details": "A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the \"operateOrder.php\" id parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28100" + }, + { + "type": "WEB", + "url": "https://github.com/gh3-dk/vul/blob/main/sql%20injection/dingfanzu/dingfanzu-CMS%20operateOrder.php%20id%20SQL-inject.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json b/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json index 875531cb4bf..8125c7d438e 100644 --- a/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json +++ b/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjrr-3f69-p92j", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21898" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Avoid potential division by zero in function_stat_show()\n\nCheck whether denominator expression x * (x - 1) * 1000 mod {2^32, 2^64}\nproduce zero and skip stddev computation in that case.\n\nFor now don't care about rec->counter * rec->counter overflow because\nrec->time * rec->time overflow will likely happen earlier.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json b/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json index ad9b31989db..e030cf475da 100644 --- a/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json +++ b/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqjr-x55g-2j6v", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21912" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: rcar: Use raw_spinlock to protect register access\n\nUse raw_spinlock in order to fix spurious messages about invalid context\nwhen spinlock debugging is enabled. The lock is only used to serialize\nregister access.\n\n [ 4.239592] =============================\n [ 4.239595] [ BUG: Invalid wait context ]\n [ 4.239599] 6.13.0-rc7-arm64-renesas-05496-gd088502a519f #35 Not tainted\n [ 4.239603] -----------------------------\n [ 4.239606] kworker/u8:5/76 is trying to lock:\n [ 4.239609] ffff0000091898a0 (&p->lock){....}-{3:3}, at: gpio_rcar_config_interrupt_input_mode+0x34/0x164\n [ 4.239641] other info that might help us debug this:\n [ 4.239643] context-{5:5}\n [ 4.239646] 5 locks held by kworker/u8:5/76:\n [ 4.239651] #0: ffff0000080fb148 ((wq_completion)async){+.+.}-{0:0}, at: process_one_work+0x190/0x62c\n [ 4.250180] OF: /soc/sound@ec500000/ports/port@0/endpoint: Read of boolean property 'frame-master' with a value.\n [ 4.254094] #1: ffff80008299bd80 ((work_completion)(&entry->work)){+.+.}-{0:0}, at: process_one_work+0x1b8/0x62c\n [ 4.254109] #2: ffff00000920c8f8\n [ 4.258345] OF: /soc/sound@ec500000/ports/port@1/endpoint: Read of boolean property 'bitclock-master' with a value.\n [ 4.264803] (&dev->mutex){....}-{4:4}, at: __device_attach_async_helper+0x3c/0xdc\n [ 4.264820] #3: ffff00000a50ca40 (request_class#2){+.+.}-{4:4}, at: __setup_irq+0xa0/0x690\n [ 4.264840] #4:\n [ 4.268872] OF: /soc/sound@ec500000/ports/port@1/endpoint: Read of boolean property 'frame-master' with a value.\n [ 4.273275] ffff00000a50c8c8 (lock_class){....}-{2:2}, at: __setup_irq+0xc4/0x690\n [ 4.296130] renesas_sdhi_internal_dmac ee100000.mmc: mmc1 base at 0x00000000ee100000, max clock rate 200 MHz\n [ 4.304082] stack backtrace:\n [ 4.304086] CPU: 1 UID: 0 PID: 76 Comm: kworker/u8:5 Not tainted 6.13.0-rc7-arm64-renesas-05496-gd088502a519f #35\n [ 4.304092] Hardware name: Renesas Salvator-X 2nd version board based on r8a77965 (DT)\n [ 4.304097] Workqueue: async async_run_entry_fn\n [ 4.304106] Call trace:\n [ 4.304110] show_stack+0x14/0x20 (C)\n [ 4.304122] dump_stack_lvl+0x6c/0x90\n [ 4.304131] dump_stack+0x14/0x1c\n [ 4.304138] __lock_acquire+0xdfc/0x1584\n [ 4.426274] lock_acquire+0x1c4/0x33c\n [ 4.429942] _raw_spin_lock_irqsave+0x5c/0x80\n [ 4.434307] gpio_rcar_config_interrupt_input_mode+0x34/0x164\n [ 4.440061] gpio_rcar_irq_set_type+0xd4/0xd8\n [ 4.444422] __irq_set_trigger+0x5c/0x178\n [ 4.448435] __setup_irq+0x2e4/0x690\n [ 4.452012] request_threaded_irq+0xc4/0x190\n [ 4.456285] devm_request_threaded_irq+0x7c/0xf4\n [ 4.459398] ata1: link resume succeeded after 1 retries\n [ 4.460902] mmc_gpiod_request_cd_irq+0x68/0xe0\n [ 4.470660] mmc_start_host+0x50/0xac\n [ 4.474327] mmc_add_host+0x80/0xe4\n [ 4.477817] tmio_mmc_host_probe+0x2b0/0x440\n [ 4.482094] renesas_sdhi_probe+0x488/0x6f4\n [ 4.486281] renesas_sdhi_internal_dmac_probe+0x60/0x78\n [ 4.491509] platform_probe+0x64/0xd8\n [ 4.495178] really_probe+0xb8/0x2a8\n [ 4.498756] __driver_probe_device+0x74/0x118\n [ 4.503116] driver_probe_device+0x3c/0x154\n [ 4.507303] __device_attach_driver+0xd4/0x160\n [ 4.511750] bus_for_each_drv+0x84/0xe0\n [ 4.515588] __device_attach_async_helper+0xb0/0xdc\n [ 4.520470] async_run_entry_fn+0x30/0xd8\n [ 4.524481] process_one_work+0x210/0x62c\n [ 4.528494] worker_thread+0x1ac/0x340\n [ 4.532245] kthread+0x10c/0x110\n [ 4.535476] ret_from_fork+0x10/0x20", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json b/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json index a2fb3a734f5..b672c3955be 100644 --- a/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json +++ b/advisories/unreviewed/2025/04/GHSA-fchw-692r-4w73/GHSA-fchw-692r-4w73.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fchw-692r-4w73", - "modified": "2025-04-15T15:30:53Z", + "modified": "2025-04-15T18:31:43Z", "published": "2025-04-15T15:30:53Z", "aliases": [ "CVE-2025-28137" ], "details": "The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -18,14 +23,20 @@ "type": "WEB", "url": "https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28137.md" }, + { + "type": "WEB", + "url": "https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756" + }, { "type": "WEB", "url": "https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756?pvs=4" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-15T14:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json new file mode 100644 index 00000000000..25c04738102 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp4x-j6ch-w8q5", + "modified": "2025-04-15T18:31:45Z", + "published": "2025-04-15T18:31:45Z", + "aliases": [ + "CVE-2025-32911" + ], + "details": "A flaw was found in libsoup, which is vulnerable to a use-after-free memory issue not on the heap in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32911" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-32911" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-590" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h7mj-68q6-fwp5/GHSA-h7mj-68q6-fwp5.json b/advisories/unreviewed/2025/04/GHSA-h7mj-68q6-fwp5/GHSA-h7mj-68q6-fwp5.json new file mode 100644 index 00000000000..7bd6c195b14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h7mj-68q6-fwp5/GHSA-h7mj-68q6-fwp5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7mj-68q6-fwp5", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:47Z", + "aliases": [ + "CVE-2025-29705" + ], + "details": "code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29705" + }, + { + "type": "WEB", + "url": "https://gitee.com/durcframework/code-gen" + }, + { + "type": "WEB", + "url": "https://github.com/yxzrw/CVE-2025-29705" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json b/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json index 1f7acae6ab4..062bda8c375 100644 --- a/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json +++ b/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j57r-qmgx-xp34", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21901" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Add sanity checks on rdev validity\n\nThere is a possibility that ulp_irq_stop and ulp_irq_start\ncallbacks will be called when the device is in detached state.\nThis can cause a crash due to NULL pointer dereference as\nthe rdev is already freed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m875-mcc5-r6hx/GHSA-m875-mcc5-r6hx.json b/advisories/unreviewed/2025/04/GHSA-m875-mcc5-r6hx/GHSA-m875-mcc5-r6hx.json new file mode 100644 index 00000000000..8b1a87303ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m875-mcc5-r6hx/GHSA-m875-mcc5-r6hx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m875-mcc5-r6hx", + "modified": "2025-04-15T18:31:44Z", + "published": "2025-04-15T18:31:44Z", + "aliases": [ + "CVE-2024-36842" + ], + "details": "An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number PlatformVER:K24-2023/05/09-v0.01 allows a remote attacker to execute arbitrary code via the ADB port component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36842" + }, + { + "type": "WEB", + "url": "https://github.com/abbiy/Backdooring-Oncord-Android-Sterio-/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p43c-fp87-rj5p/GHSA-p43c-fp87-rj5p.json b/advisories/unreviewed/2025/04/GHSA-p43c-fp87-rj5p/GHSA-p43c-fp87-rj5p.json new file mode 100644 index 00000000000..d69238596ed --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p43c-fp87-rj5p/GHSA-p43c-fp87-rj5p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p43c-fp87-rj5p", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:47Z", + "aliases": [ + "CVE-2025-33028" + ], + "details": "In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, WinZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33028" + }, + { + "type": "WEB", + "url": "https://github.com/EnisAksu/Argonis/blob/main/CVEs/CVE-2025-33028%20%28WinZip%29/CVE-2025-33028.md" + }, + { + "type": "WEB", + "url": "https://kb.winzip.com/help/help_whatsnew.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-830" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json b/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json new file mode 100644 index 00000000000..d40ae9df76a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-prv3-9p5f-cqv2/GHSA-prv3-9p5f-cqv2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prv3-9p5f-cqv2", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:46Z", + "aliases": [ + "CVE-2024-50960" + ], + "details": "A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50960" + }, + { + "type": "WEB", + "url": "https://github.com/layer8secure/extron-smp-inject" + }, + { + "type": "WEB", + "url": "https://ryanmroth.com/articles/exploiting-extron-smp-command-injection" + }, + { + "type": "WEB", + "url": "https://www.extron.com/article/smp" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q26c-m38m-777f/GHSA-q26c-m38m-777f.json b/advisories/unreviewed/2025/04/GHSA-q26c-m38m-777f/GHSA-q26c-m38m-777f.json new file mode 100644 index 00000000000..2e8f40c4d7a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q26c-m38m-777f/GHSA-q26c-m38m-777f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q26c-m38m-777f", + "modified": "2025-04-15T18:31:44Z", + "published": "2025-04-15T18:31:44Z", + "aliases": [ + "CVE-2025-24948" + ], + "details": "In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24948" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qp2m-387q-grcf/GHSA-qp2m-387q-grcf.json b/advisories/unreviewed/2025/04/GHSA-qp2m-387q-grcf/GHSA-qp2m-387q-grcf.json new file mode 100644 index 00000000000..1fb1f2b1a87 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qp2m-387q-grcf/GHSA-qp2m-387q-grcf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp2m-387q-grcf", + "modified": "2025-04-15T18:31:43Z", + "published": "2025-04-15T18:31:43Z", + "aliases": [ + "CVE-2020-18243" + ], + "details": "SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo-view-case.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18243" + }, + { + "type": "WEB", + "url": "https://github.com/enricozab/CMS/issues/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rjg7-w27j-q4vj/GHSA-rjg7-w27j-q4vj.json b/advisories/unreviewed/2025/04/GHSA-rjg7-w27j-q4vj/GHSA-rjg7-w27j-q4vj.json new file mode 100644 index 00000000000..cebd8cedc43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rjg7-w27j-q4vj/GHSA-rjg7-w27j-q4vj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjg7-w27j-q4vj", + "modified": "2025-04-15T18:31:44Z", + "published": "2025-04-15T18:31:44Z", + "aliases": [ + "CVE-2025-24949" + ], + "details": "In JotUrl 2.0, is possible to bypass security requirements during the password change process.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24949" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T16:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json b/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json new file mode 100644 index 00000000000..e8822a41e8f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vg6j-x3v7-mwq9/GHSA-vg6j-x3v7-mwq9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg6j-x3v7-mwq9", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:47Z", + "aliases": [ + "CVE-2025-33026" + ], + "details": "In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, PeaZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33026" + }, + { + "type": "WEB", + "url": "https://github.com/EnisAksu/Argonis/blob/main/CVEs/CVE-2025-33026%20%28PeaZip%29/CVE-2025-33026.md" + }, + { + "type": "WEB", + "url": "https://peazip.github.io/peazip-64bit.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-830" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json b/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json new file mode 100644 index 00000000000..23d234afe6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x29x-qf6c-w9cj", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:47Z", + "aliases": [ + "CVE-2025-3617" + ], + "details": "A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3617" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1727.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json b/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json index 9430a66f232..48935a88816 100644 --- a/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json +++ b/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x97h-4pwx-3c9h", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21904" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncaif_virtio: fix wrong pointer check in cfv_probe()\n\ndel_vqs() frees virtqueues, therefore cfv->vq_tx pointer should be checked\nfor NULL before calling it, not cfv->vdev. Also the current implementation\nis redundant because the pointer cfv->vdev is dereferenced before it is\nchecked for NULL.\n\nFix this by checking cfv->vq_tx for NULL instead of cfv->vdev before\ncalling del_vqs().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json b/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json index 0e2b7d8df45..375767c4c66 100644 --- a/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json +++ b/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9qw-9cw3-55vf", - "modified": "2025-04-01T18:30:50Z", + "modified": "2025-04-15T18:31:42Z", "published": "2025-04-01T18:30:50Z", "aliases": [ "CVE-2025-21911" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: avoid deadlock on fence release\n\nDo scheduler queue fence release processing on a workqueue, rather\nthan in the release function itself.\n\nFixes deadlock issues such as the following:\n\n[ 607.400437] ============================================\n[ 607.405755] WARNING: possible recursive locking detected\n[ 607.415500] --------------------------------------------\n[ 607.420817] weston:zfq0/24149 is trying to acquire lock:\n[ 607.426131] ffff000017d041a0 (reservation_ww_class_mutex){+.+.}-{3:3}, at: pvr_gem_object_vunmap+0x40/0xc0 [powervr]\n[ 607.436728]\n but task is already holding lock:\n[ 607.442554] ffff000017d105a0 (reservation_ww_class_mutex){+.+.}-{3:3}, at: dma_buf_ioctl+0x250/0x554\n[ 607.451727]\n other info that might help us debug this:\n[ 607.458245] Possible unsafe locking scenario:\n\n[ 607.464155] CPU0\n[ 607.466601] ----\n[ 607.469044] lock(reservation_ww_class_mutex);\n[ 607.473584] lock(reservation_ww_class_mutex);\n[ 607.478114]\n *** DEADLOCK ***", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json b/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json new file mode 100644 index 00000000000..ecbeaea4005 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xrq2-2h92-m6m8/GHSA-xrq2-2h92-m6m8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrq2-2h92-m6m8", + "modified": "2025-04-15T18:31:47Z", + "published": "2025-04-15T18:31:47Z", + "aliases": [ + "CVE-2025-33027" + ], + "details": "In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, Bandizip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33027" + }, + { + "type": "WEB", + "url": "https://en.bandisoft.com/bandizip" + }, + { + "type": "WEB", + "url": "https://github.com/EnisAksu/Argonis/blob/main/CVEs/CVE-2025-33027%20%28Bandizip%29/CVE-2025-33027.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-830" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T18:15:53Z" + } +} \ No newline at end of file