From 06d5387b9376d0342fd058a3f17bc44b957ae3cc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 6 Mar 2025 06:31:58 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-254r-xffm-9c3g.json | 34 ++++++++++++ .../GHSA-2vj5-r237-wrxw.json | 34 ++++++++++++ .../GHSA-3p64-362g-h8x8.json | 34 ++++++++++++ .../GHSA-5q3h-6jgm-m9jp.json | 34 ++++++++++++ .../GHSA-6hq3-hc5r-5f4q.json | 34 ++++++++++++ .../GHSA-6pmv-x33r-9ff9.json | 34 ++++++++++++ .../GHSA-8m69-67p7-65wf.json | 34 ++++++++++++ .../GHSA-99qq-fm4c-vcf7.json | 34 ++++++++++++ .../GHSA-9vfg-jxgp-wpqw.json | 40 ++++++++++++++ .../GHSA-cm69-vmxj-g523.json | 34 ++++++++++++ .../GHSA-cxq5-3cfv-xmp4.json | 34 ++++++++++++ .../GHSA-f5mh-3qjm-hxpc.json | 34 ++++++++++++ .../GHSA-fqh9-9vhw-c28w.json | 40 ++++++++++++++ .../GHSA-gh7g-5ppc-r4w8.json | 34 ++++++++++++ .../GHSA-ghv5-9m7m-pgpq.json | 34 ++++++++++++ .../GHSA-gqfc-m35p-wwj8.json | 34 ++++++++++++ .../GHSA-h2vv-cc2x-4852.json | 34 ++++++++++++ .../GHSA-h972-4xrw-8jjv.json | 34 ++++++++++++ .../GHSA-hrg5-27wv-98c8.json | 34 ++++++++++++ .../GHSA-jrjr-94fq-fmhh.json | 34 ++++++++++++ .../GHSA-m8m2-32hv-cg3p.json | 34 ++++++++++++ .../GHSA-m8pg-33qj-5wxr.json | 40 ++++++++++++++ .../GHSA-pm86-584v-rq4w.json | 34 ++++++++++++ .../GHSA-qjcx-8429-2j74.json | 29 +++++++++++ .../GHSA-qmpx-c8jm-g9qv.json | 34 ++++++++++++ .../GHSA-rv7v-x668-2w85.json | 34 ++++++++++++ .../GHSA-w228-pxvr-7mf5.json | 34 ++++++++++++ .../GHSA-w4rh-fgx7-q63m.json | 52 +++++++++++++++++++ .../GHSA-w82f-ppmw-v55m.json | 34 ++++++++++++ .../GHSA-w933-5675-hw56.json | 34 ++++++++++++ .../GHSA-x7gq-v5gc-rcm4.json | 34 ++++++++++++ .../GHSA-x9f9-8qf2-6qvm.json | 34 ++++++++++++ 32 files changed, 1119 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-254r-xffm-9c3g/GHSA-254r-xffm-9c3g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2vj5-r237-wrxw/GHSA-2vj5-r237-wrxw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3p64-362g-h8x8/GHSA-3p64-362g-h8x8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5q3h-6jgm-m9jp/GHSA-5q3h-6jgm-m9jp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hq3-hc5r-5f4q/GHSA-6hq3-hc5r-5f4q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6pmv-x33r-9ff9/GHSA-6pmv-x33r-9ff9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8m69-67p7-65wf/GHSA-8m69-67p7-65wf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-99qq-fm4c-vcf7/GHSA-99qq-fm4c-vcf7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vfg-jxgp-wpqw/GHSA-9vfg-jxgp-wpqw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cm69-vmxj-g523/GHSA-cm69-vmxj-g523.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cxq5-3cfv-xmp4/GHSA-cxq5-3cfv-xmp4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f5mh-3qjm-hxpc/GHSA-f5mh-3qjm-hxpc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fqh9-9vhw-c28w/GHSA-fqh9-9vhw-c28w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh7g-5ppc-r4w8/GHSA-gh7g-5ppc-r4w8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ghv5-9m7m-pgpq/GHSA-ghv5-9m7m-pgpq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gqfc-m35p-wwj8/GHSA-gqfc-m35p-wwj8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h2vv-cc2x-4852/GHSA-h2vv-cc2x-4852.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h972-4xrw-8jjv/GHSA-h972-4xrw-8jjv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hrg5-27wv-98c8/GHSA-hrg5-27wv-98c8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jrjr-94fq-fmhh/GHSA-jrjr-94fq-fmhh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m8m2-32hv-cg3p/GHSA-m8m2-32hv-cg3p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m8pg-33qj-5wxr/GHSA-m8pg-33qj-5wxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pm86-584v-rq4w/GHSA-pm86-584v-rq4w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qmpx-c8jm-g9qv/GHSA-qmpx-c8jm-g9qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rv7v-x668-2w85/GHSA-rv7v-x668-2w85.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w228-pxvr-7mf5/GHSA-w228-pxvr-7mf5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w82f-ppmw-v55m/GHSA-w82f-ppmw-v55m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w933-5675-hw56/GHSA-w933-5675-hw56.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x7gq-v5gc-rcm4/GHSA-x7gq-v5gc-rcm4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x9f9-8qf2-6qvm/GHSA-x9f9-8qf2-6qvm.json diff --git a/advisories/unreviewed/2025/03/GHSA-254r-xffm-9c3g/GHSA-254r-xffm-9c3g.json b/advisories/unreviewed/2025/03/GHSA-254r-xffm-9c3g/GHSA-254r-xffm-9c3g.json new file mode 100644 index 00000000000..a2ef7776a08 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-254r-xffm-9c3g/GHSA-254r-xffm-9c3g.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-254r-xffm-9c3g", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:53Z", + "aliases": [ + "CVE-2025-20932" + ], + "details": "Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20932" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2vj5-r237-wrxw/GHSA-2vj5-r237-wrxw.json b/advisories/unreviewed/2025/03/GHSA-2vj5-r237-wrxw/GHSA-2vj5-r237-wrxw.json new file mode 100644 index 00000000000..a64ed5456ed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2vj5-r237-wrxw/GHSA-2vj5-r237-wrxw.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vj5-r237-wrxw", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20915" + ], + "details": "Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20915" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3p64-362g-h8x8/GHSA-3p64-362g-h8x8.json b/advisories/unreviewed/2025/03/GHSA-3p64-362g-h8x8/GHSA-3p64-362g-h8x8.json new file mode 100644 index 00000000000..1b9a1036abe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3p64-362g-h8x8/GHSA-3p64-362g-h8x8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p64-362g-h8x8", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20922" + ], + "details": "Out-of-bounds read in appending text paragraph in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20922" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5q3h-6jgm-m9jp/GHSA-5q3h-6jgm-m9jp.json b/advisories/unreviewed/2025/03/GHSA-5q3h-6jgm-m9jp/GHSA-5q3h-6jgm-m9jp.json new file mode 100644 index 00000000000..e1b4c284b51 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5q3h-6jgm-m9jp/GHSA-5q3h-6jgm-m9jp.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q3h-6jgm-m9jp", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20910" + ], + "details": "Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20910" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hq3-hc5r-5f4q/GHSA-6hq3-hc5r-5f4q.json b/advisories/unreviewed/2025/03/GHSA-6hq3-hc5r-5f4q/GHSA-6hq3-hc5r-5f4q.json new file mode 100644 index 00000000000..b5eda87ec97 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hq3-hc5r-5f4q/GHSA-6hq3-hc5r-5f4q.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hq3-hc5r-5f4q", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20924" + ], + "details": "Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20924" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6pmv-x33r-9ff9/GHSA-6pmv-x33r-9ff9.json b/advisories/unreviewed/2025/03/GHSA-6pmv-x33r-9ff9/GHSA-6pmv-x33r-9ff9.json new file mode 100644 index 00000000000..e5e853079f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6pmv-x33r-9ff9/GHSA-6pmv-x33r-9ff9.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pmv-x33r-9ff9", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20919" + ], + "details": "Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20919" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8m69-67p7-65wf/GHSA-8m69-67p7-65wf.json b/advisories/unreviewed/2025/03/GHSA-8m69-67p7-65wf/GHSA-8m69-67p7-65wf.json new file mode 100644 index 00000000000..98378438b69 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8m69-67p7-65wf/GHSA-8m69-67p7-65wf.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m69-67p7-65wf", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20926" + ], + "details": "Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20926" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-99qq-fm4c-vcf7/GHSA-99qq-fm4c-vcf7.json b/advisories/unreviewed/2025/03/GHSA-99qq-fm4c-vcf7/GHSA-99qq-fm4c-vcf7.json new file mode 100644 index 00000000000..1f9a30f9cf2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-99qq-fm4c-vcf7/GHSA-99qq-fm4c-vcf7.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99qq-fm4c-vcf7", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20929" + ], + "details": "Out-of-bounds write in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20929" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vfg-jxgp-wpqw/GHSA-9vfg-jxgp-wpqw.json b/advisories/unreviewed/2025/03/GHSA-9vfg-jxgp-wpqw/GHSA-9vfg-jxgp-wpqw.json new file mode 100644 index 00000000000..818a908052c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9vfg-jxgp-wpqw/GHSA-9vfg-jxgp-wpqw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vfg-jxgp-wpqw", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-24864" + ], + "details": "Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24864" + }, + { + "type": "WEB", + "url": "https://help.rview.com/hc/ja/articles/38287019277843-%E7%B7%8A%E6%80%A5%E3%83%91%E3%83%83%E3%83%81%E4%BD%9C%E6%A5%AD%E3%81%AE%E3%81%94%E6%A1%88%E5%86%85-2025-02-13-%E5%AE%8C%E4%BA%86" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN24992507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T04:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cm69-vmxj-g523/GHSA-cm69-vmxj-g523.json b/advisories/unreviewed/2025/03/GHSA-cm69-vmxj-g523/GHSA-cm69-vmxj-g523.json new file mode 100644 index 00000000000..40a9c6103fc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cm69-vmxj-g523/GHSA-cm69-vmxj-g523.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm69-vmxj-g523", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20911" + ], + "details": "Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update MAC address of Galaxy Watch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20911" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cxq5-3cfv-xmp4/GHSA-cxq5-3cfv-xmp4.json b/advisories/unreviewed/2025/03/GHSA-cxq5-3cfv-xmp4/GHSA-cxq5-3cfv-xmp4.json new file mode 100644 index 00000000000..287383e2cdc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cxq5-3cfv-xmp4/GHSA-cxq5-3cfv-xmp4.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxq5-3cfv-xmp4", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:53Z", + "aliases": [ + "CVE-2025-20933" + ], + "details": "Out-of-bounds read in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20933" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f5mh-3qjm-hxpc/GHSA-f5mh-3qjm-hxpc.json b/advisories/unreviewed/2025/03/GHSA-f5mh-3qjm-hxpc/GHSA-f5mh-3qjm-hxpc.json new file mode 100644 index 00000000000..2d484a02331 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f5mh-3qjm-hxpc/GHSA-f5mh-3qjm-hxpc.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5mh-3qjm-hxpc", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20928" + ], + "details": "Out-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20928" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fqh9-9vhw-c28w/GHSA-fqh9-9vhw-c28w.json b/advisories/unreviewed/2025/03/GHSA-fqh9-9vhw-c28w/GHSA-fqh9-9vhw-c28w.json new file mode 100644 index 00000000000..99cfd7fab2b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fqh9-9vhw-c28w/GHSA-fqh9-9vhw-c28w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqh9-9vhw-c28w", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-22447" + ], + "details": "Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22447" + }, + { + "type": "WEB", + "url": "https://help.rview.com/hc/ja/articles/38287019277843-%E7%B7%8A%E6%80%A5%E3%83%91%E3%83%83%E3%83%81%E4%BD%9C%E6%A5%AD%E3%81%AE%E3%81%94%E6%A1%88%E5%86%85-2025-02-13-%E5%AE%8C%E4%BA%86" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN24992507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T04:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gh7g-5ppc-r4w8/GHSA-gh7g-5ppc-r4w8.json b/advisories/unreviewed/2025/03/GHSA-gh7g-5ppc-r4w8/GHSA-gh7g-5ppc-r4w8.json new file mode 100644 index 00000000000..34b2b92cc22 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gh7g-5ppc-r4w8/GHSA-gh7g-5ppc-r4w8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh7g-5ppc-r4w8", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20925" + ], + "details": "Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to potentially read memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20925" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ghv5-9m7m-pgpq/GHSA-ghv5-9m7m-pgpq.json b/advisories/unreviewed/2025/03/GHSA-ghv5-9m7m-pgpq/GHSA-ghv5-9m7m-pgpq.json new file mode 100644 index 00000000000..b64979691cc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ghv5-9m7m-pgpq/GHSA-ghv5-9m7m-pgpq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghv5-9m7m-pgpq", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20913" + ], + "details": "Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20913" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gqfc-m35p-wwj8/GHSA-gqfc-m35p-wwj8.json b/advisories/unreviewed/2025/03/GHSA-gqfc-m35p-wwj8/GHSA-gqfc-m35p-wwj8.json new file mode 100644 index 00000000000..e38a1314c8b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gqfc-m35p-wwj8/GHSA-gqfc-m35p-wwj8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqfc-m35p-wwj8", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20908" + ], + "details": "Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20908" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h2vv-cc2x-4852/GHSA-h2vv-cc2x-4852.json b/advisories/unreviewed/2025/03/GHSA-h2vv-cc2x-4852/GHSA-h2vv-cc2x-4852.json new file mode 100644 index 00000000000..27bdccd933c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h2vv-cc2x-4852/GHSA-h2vv-cc2x-4852.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2vv-cc2x-4852", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20920" + ], + "details": "Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20920" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h972-4xrw-8jjv/GHSA-h972-4xrw-8jjv.json b/advisories/unreviewed/2025/03/GHSA-h972-4xrw-8jjv/GHSA-h972-4xrw-8jjv.json new file mode 100644 index 00000000000..df339142821 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h972-4xrw-8jjv/GHSA-h972-4xrw-8jjv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h972-4xrw-8jjv", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20916" + ], + "details": "Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20916" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hrg5-27wv-98c8/GHSA-hrg5-27wv-98c8.json b/advisories/unreviewed/2025/03/GHSA-hrg5-27wv-98c8/GHSA-hrg5-27wv-98c8.json new file mode 100644 index 00000000000..8e8ac0b9b52 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hrg5-27wv-98c8/GHSA-hrg5-27wv-98c8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrg5-27wv-98c8", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20921" + ], + "details": "Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20921" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jrjr-94fq-fmhh/GHSA-jrjr-94fq-fmhh.json b/advisories/unreviewed/2025/03/GHSA-jrjr-94fq-fmhh/GHSA-jrjr-94fq-fmhh.json new file mode 100644 index 00000000000..8648a55c83c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jrjr-94fq-fmhh/GHSA-jrjr-94fq-fmhh.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrjr-94fq-fmhh", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20903" + ], + "details": "Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20903" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m8m2-32hv-cg3p/GHSA-m8m2-32hv-cg3p.json b/advisories/unreviewed/2025/03/GHSA-m8m2-32hv-cg3p/GHSA-m8m2-32hv-cg3p.json new file mode 100644 index 00000000000..ed82bc86638 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m8m2-32hv-cg3p/GHSA-m8m2-32hv-cg3p.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8m2-32hv-cg3p", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20917" + ], + "details": "Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20917" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m8pg-33qj-5wxr/GHSA-m8pg-33qj-5wxr.json b/advisories/unreviewed/2025/03/GHSA-m8pg-33qj-5wxr/GHSA-m8pg-33qj-5wxr.json new file mode 100644 index 00000000000..d98a61c47ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m8pg-33qj-5wxr/GHSA-m8pg-33qj-5wxr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8pg-33qj-5wxr", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:53Z", + "aliases": [ + "CVE-2025-22623" + ], + "details": "Ad Inserter - Ad Manager and AdSense Ads 2.8.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/includes/dst/dst.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22623" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/skims-8" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/ad-inserter/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pm86-584v-rq4w/GHSA-pm86-584v-rq4w.json b/advisories/unreviewed/2025/03/GHSA-pm86-584v-rq4w/GHSA-pm86-584v-rq4w.json new file mode 100644 index 00000000000..db516dbe9d7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pm86-584v-rq4w/GHSA-pm86-584v-rq4w.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm86-584v-rq4w", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20930" + ], + "details": "Out-of-bounds read in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20930" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json b/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json new file mode 100644 index 00000000000..5298ea4b89e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjcx-8429-2j74", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:53Z", + "aliases": [ + "CVE-2024-13868" + ], + "details": "The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13868" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0bff1645-dd53-4416-a90f-7cf4a6b33c1a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T06:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qmpx-c8jm-g9qv/GHSA-qmpx-c8jm-g9qv.json b/advisories/unreviewed/2025/03/GHSA-qmpx-c8jm-g9qv/GHSA-qmpx-c8jm-g9qv.json new file mode 100644 index 00000000000..e2bd9cb8a4f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qmpx-c8jm-g9qv/GHSA-qmpx-c8jm-g9qv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmpx-c8jm-g9qv", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:53Z", + "aliases": [ + "CVE-2025-20931" + ], + "details": "Out-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20931" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rv7v-x668-2w85/GHSA-rv7v-x668-2w85.json b/advisories/unreviewed/2025/03/GHSA-rv7v-x668-2w85/GHSA-rv7v-x668-2w85.json new file mode 100644 index 00000000000..e77bda6ce1f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rv7v-x668-2w85/GHSA-rv7v-x668-2w85.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv7v-x668-2w85", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20914" + ], + "details": "Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20914" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w228-pxvr-7mf5/GHSA-w228-pxvr-7mf5.json b/advisories/unreviewed/2025/03/GHSA-w228-pxvr-7mf5/GHSA-w228-pxvr-7mf5.json new file mode 100644 index 00000000000..1a5f88f0e63 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w228-pxvr-7mf5/GHSA-w228-pxvr-7mf5.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w228-pxvr-7mf5", + "modified": "2025-03-06T06:30:53Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20923" + ], + "details": "Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20923" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json b/advisories/unreviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json new file mode 100644 index 00000000000..51311836c2d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4rh-fgx7-q63m", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-1979" + ], + "details": "Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is passed as an argument, it will be logged and could potentially leak the password.\n\nThis is only exploitable if:\n\n1) Logging is enabled;\n\n2) Redis is using password authentication;\n\n3) Those logs are accessible to an attacker, who can reach that redis instance.\n\n**Note:**\n\nIt is recommended that anyone who is running in this configuration should update to the latest version of Ray, then rotate their redis password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1979" + }, + { + "type": "WEB", + "url": "https://github.com/ray-project/ray/issues/50266" + }, + { + "type": "WEB", + "url": "https://github.com/ray-project/ray/pull/50409" + }, + { + "type": "WEB", + "url": "https://github.com/ray-project/ray/commit/64a2e4010522d60b90c389634f24df77b603d85d" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-PYTHON-RAY-8745212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w82f-ppmw-v55m/GHSA-w82f-ppmw-v55m.json b/advisories/unreviewed/2025/03/GHSA-w82f-ppmw-v55m/GHSA-w82f-ppmw-v55m.json new file mode 100644 index 00000000000..9286bb194bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w82f-ppmw-v55m/GHSA-w82f-ppmw-v55m.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w82f-ppmw-v55m", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20912" + ], + "details": "Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20912" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w933-5675-hw56/GHSA-w933-5675-hw56.json b/advisories/unreviewed/2025/03/GHSA-w933-5675-hw56/GHSA-w933-5675-hw56.json new file mode 100644 index 00000000000..eceec929a38 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w933-5675-hw56/GHSA-w933-5675-hw56.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w933-5675-hw56", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20927" + ], + "details": "Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20927" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x7gq-v5gc-rcm4/GHSA-x7gq-v5gc-rcm4.json b/advisories/unreviewed/2025/03/GHSA-x7gq-v5gc-rcm4/GHSA-x7gq-v5gc-rcm4.json new file mode 100644 index 00000000000..6a6c6861172 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x7gq-v5gc-rcm4/GHSA-x7gq-v5gc-rcm4.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7gq-v5gc-rcm4", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20918" + ], + "details": "Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20918" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x9f9-8qf2-6qvm/GHSA-x9f9-8qf2-6qvm.json b/advisories/unreviewed/2025/03/GHSA-x9f9-8qf2-6qvm/GHSA-x9f9-8qf2-6qvm.json new file mode 100644 index 00000000000..0d60796c0be --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x9f9-8qf2-6qvm/GHSA-x9f9-8qf2-6qvm.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9f9-8qf2-6qvm", + "modified": "2025-03-06T06:30:52Z", + "published": "2025-03-06T06:30:52Z", + "aliases": [ + "CVE-2025-20909" + ], + "details": "Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20909" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T05:15:17Z" + } +} \ No newline at end of file