From 08fe2cd4e47e36399638512df26b6754949ca52c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 4 Mar 2025 15:33:31 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-78xr-cmr3-fxq9.json | 10 +++- .../GHSA-c5qp-mx9f-m5c7.json | 3 +- .../GHSA-3r6h-cmr9-36j6.json | 15 +++-- .../GHSA-5cc9-m24m-vpr3.json | 15 +++-- .../GHSA-6prj-x8h3-vcvh.json | 15 +++-- .../GHSA-h6q4-jv34-9rpm.json | 10 +++- .../GHSA-mjhr-3845-j2r5.json | 15 +++-- .../GHSA-249w-xh84-97wj.json | 33 +++++++++++ .../GHSA-35x7-m572-w69v.json | 56 +++++++++++++++++++ .../GHSA-3g8j-6hfm-wj7g.json | 40 +++++++++++++ .../GHSA-5289-2q6r-6q3g.json | 41 ++++++++++++++ .../GHSA-5427-6cg5-37h6.json | 41 ++++++++++++++ .../GHSA-57gw-hcmr-f4g2.json | 33 +++++++++++ .../GHSA-77p2-mfp5-w993.json | 33 +++++++++++ .../GHSA-8454-mw8r-4mjq.json | 37 ++++++++++++ .../GHSA-8ggp-3pgj-q2gm.json | 36 ++++++++++++ .../GHSA-9xc8-27jp-6jj2.json | 33 +++++++++++ .../GHSA-c22c-4xww-2fqr.json | 37 ++++++++++++ .../GHSA-f8xf-r8j3-6845.json | 37 ++++++++++++ .../GHSA-gqx4-7r84-32m6.json | 33 +++++++++++ .../GHSA-h267-996p-9gjc.json | 37 ++++++++++++ .../GHSA-m2rp-964h-h237.json | 33 +++++++++++ .../GHSA-m793-xp46-r76w.json | 33 +++++++++++ .../GHSA-ppp4-p6wj-8gp8.json | 11 +++- .../GHSA-qwhp-hhhx-5xg8.json | 41 ++++++++++++++ .../GHSA-r83v-rmq7-r5m4.json | 33 +++++++++++ .../GHSA-r84f-4wj3-r6vx.json | 41 ++++++++++++++ .../GHSA-x4j2-c46q-7jp5.json | 37 ++++++++++++ .../GHSA-x9h6-qwxm-528g.json | 33 +++++++++++ 29 files changed, 850 insertions(+), 22 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-35x7-m572-w69v/GHSA-35x7-m572-w69v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3g8j-6hfm-wj7g/GHSA-3g8j-6hfm-wj7g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5289-2q6r-6q3g/GHSA-5289-2q6r-6q3g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5427-6cg5-37h6/GHSA-5427-6cg5-37h6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-77p2-mfp5-w993/GHSA-77p2-mfp5-w993.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8ggp-3pgj-q2gm/GHSA-8ggp-3pgj-q2gm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qwhp-hhhx-5xg8/GHSA-qwhp-hhhx-5xg8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x4j2-c46q-7jp5/GHSA-x4j2-c46q-7jp5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json diff --git a/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json b/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json index 23615eb9a9f..cf413cce144 100644 --- a/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json +++ b/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78xr-cmr3-fxq9", - "modified": "2025-01-17T21:31:39Z", + "modified": "2025-03-04T15:31:46Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2025-21399" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21399" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/elevation-of-privilege-vulnerability-in-microsoft-edge-chromium-based-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/elevation-of-privilege-vulnerability-in-microsoft-edge-chromium-based-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json b/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json index 0d54ed87cee..e8ec808831b 100644 --- a/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json +++ b/advisories/unreviewed/2025/01/GHSA-c5qp-mx9f-m5c7/GHSA-c5qp-mx9f-m5c7.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json b/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json index ab501d44b79..0455bb19235 100644 --- a/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json +++ b/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3r6h-cmr9-36j6", - "modified": "2025-02-27T21:32:16Z", + "modified": "2025-03-04T15:31:47Z", "published": "2025-02-27T21:32:16Z", "aliases": [ "CVE-2024-53944" ], "details": "An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to sanitize shell metacharacters sent via JSON parameters, thus allowing attackers to execute arbitrary OS commands with root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T20:16:01Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json b/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json index ab249ae31b6..a56717971b4 100644 --- a/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json +++ b/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5cc9-m24m-vpr3", - "modified": "2025-02-27T15:31:52Z", + "modified": "2025-03-04T15:31:47Z", "published": "2025-02-27T15:31:52Z", "aliases": [ "CVE-2025-25760" ], "details": "A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T15:15:41Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json b/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json index e471a813385..a9ed2ca30ff 100644 --- a/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json +++ b/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6prj-x8h3-vcvh", - "modified": "2025-02-27T15:31:52Z", + "modified": "2025-03-04T15:31:47Z", "published": "2025-02-27T15:31:52Z", "aliases": [ "CVE-2025-25759" ], "details": "An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T15:15:41Z" diff --git a/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json b/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json index cc64e19ff7a..17a2c37cc04 100644 --- a/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json +++ b/advisories/unreviewed/2025/02/GHSA-h6q4-jv34-9rpm/GHSA-h6q4-jv34-9rpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6q4-jv34-9rpm", - "modified": "2025-02-11T18:31:36Z", + "modified": "2025-03-04T15:31:46Z", "published": "2025-02-11T18:31:36Z", "aliases": [ "CVE-2025-21181" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21181" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21181-denial-of-service-vulnerability-in-microsoft-message-queuing-detection-script" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-21181-denial-of-service-vulnerability-in-microsoft-message-queuing-mitigation-script" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json b/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json index 722fe533efb..802a2666e9a 100644 --- a/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json +++ b/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mjhr-3845-j2r5", - "modified": "2025-02-27T00:30:27Z", + "modified": "2025-03-04T15:31:47Z", "published": "2025-02-27T00:30:27Z", "aliases": [ "CVE-2024-57040" ], "details": "TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained via a brute force attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-26T22:15:14Z" diff --git a/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json b/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json new file mode 100644 index 00000000000..c1e4946258c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-249w-xh84-97wj/GHSA-249w-xh84-97wj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-249w-xh84-97wj", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2025-27425" + ], + "details": "Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27425" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1941525" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35x7-m572-w69v/GHSA-35x7-m572-w69v.json b/advisories/unreviewed/2025/03/GHSA-35x7-m572-w69v/GHSA-35x7-m572-w69v.json new file mode 100644 index 00000000000..db76bb78ec5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-35x7-m572-w69v/GHSA-35x7-m572-w69v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35x7-m572-w69v", + "modified": "2025-03-04T15:31:48Z", + "published": "2025-03-04T15:31:48Z", + "aliases": [ + "CVE-2025-1925" + ], + "details": "A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1925" + }, + { + "type": "WEB", + "url": "https://github.com/open5gs/open5gs/pull/3711" + }, + { + "type": "WEB", + "url": "https://github.com/guoweifk/BugReport/blob/main/Open5GS%20AMF%20Denial%20of%20Service%20via%20PDU%20Session%20ID%20Conflict" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298513" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298513" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.506038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3g8j-6hfm-wj7g/GHSA-3g8j-6hfm-wj7g.json b/advisories/unreviewed/2025/03/GHSA-3g8j-6hfm-wj7g/GHSA-3g8j-6hfm-wj7g.json new file mode 100644 index 00000000000..a4cfe54f9e3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3g8j-6hfm-wj7g/GHSA-3g8j-6hfm-wj7g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g8j-6hfm-wj7g", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2025-1943" + ], + "details": "Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1943" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1869650%2C1938451%2C1940326%2C1944052%2C1944063%2C1947281" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5289-2q6r-6q3g/GHSA-5289-2q6r-6q3g.json b/advisories/unreviewed/2025/03/GHSA-5289-2q6r-6q3g/GHSA-5289-2q6r-6q3g.json new file mode 100644 index 00000000000..5d3c7f0cdef --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5289-2q6r-6q3g/GHSA-5289-2q6r-6q3g.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5289-2q6r-6q3g", + "modified": "2025-03-04T15:31:48Z", + "published": "2025-03-04T15:31:48Z", + "aliases": [ + "CVE-2025-1930" + ], + "details": "On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1930" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1902309" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-15" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5427-6cg5-37h6/GHSA-5427-6cg5-37h6.json b/advisories/unreviewed/2025/03/GHSA-5427-6cg5-37h6/GHSA-5427-6cg5-37h6.json new file mode 100644 index 00000000000..ee3f0e03274 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5427-6cg5-37h6/GHSA-5427-6cg5-37h6.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5427-6cg5-37h6", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1937" + ], + "details": "Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1937" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1938471%2C1940716" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-15" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json b/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json new file mode 100644 index 00000000000..568a6f82e1b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-57gw-hcmr-f4g2/GHSA-57gw-hcmr-f4g2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57gw-hcmr-f4g2", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2025-27426" + ], + "details": "Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox for iOS < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27426" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1933079" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-77p2-mfp5-w993/GHSA-77p2-mfp5-w993.json b/advisories/unreviewed/2025/03/GHSA-77p2-mfp5-w993/GHSA-77p2-mfp5-w993.json new file mode 100644 index 00000000000..99552f97d22 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-77p2-mfp5-w993/GHSA-77p2-mfp5-w993.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77p2-mfp5-w993", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2024-50706" + ], + "details": "Unauthenticated SQL injection vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary SQL queries on the backend database.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50706" + }, + { + "type": "WEB", + "url": "https://uniguest.com/cve-bulletins" + }, + { + "type": "WEB", + "url": "https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50706-Vulnerability-Summary.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json b/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json new file mode 100644 index 00000000000..e67da597b90 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8454-mw8r-4mjq/GHSA-8454-mw8r-4mjq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8454-mw8r-4mjq", + "modified": "2025-03-04T15:31:48Z", + "published": "2025-03-04T15:31:48Z", + "aliases": [ + "CVE-2025-1934" + ], + "details": "It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1934" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1942881" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8ggp-3pgj-q2gm/GHSA-8ggp-3pgj-q2gm.json b/advisories/unreviewed/2025/03/GHSA-8ggp-3pgj-q2gm/GHSA-8ggp-3pgj-q2gm.json new file mode 100644 index 00000000000..a15d21df4d1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8ggp-3pgj-q2gm/GHSA-8ggp-3pgj-q2gm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ggp-3pgj-q2gm", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2024-9149" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce Website Template: before v1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9149" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json b/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json new file mode 100644 index 00000000000..e11bff8cb56 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9xc8-27jp-6jj2/GHSA-9xc8-27jp-6jj2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xc8-27jp-6jj2", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2024-50705" + ], + "details": "Unauthenticated reflected cross-site scripting (XSS) in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50705" + }, + { + "type": "WEB", + "url": "https://uniguest.com/cve-bulletins" + }, + { + "type": "WEB", + "url": "https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50705-Vulnerability-Summary.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json b/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json new file mode 100644 index 00000000000..a1c50bc7579 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c22c-4xww-2fqr", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1935" + ], + "details": "A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1935" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1866661" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json b/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json new file mode 100644 index 00000000000..b18817426d8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f8xf-r8j3-6845/GHSA-f8xf-r8j3-6845.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8xf-r8j3-6845", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1938" + ], + "details": "Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1938" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1922889%2C1935004%2C1943586%2C1943912%2C1948111" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json b/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json new file mode 100644 index 00000000000..511aa068d6d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gqx4-7r84-32m6/GHSA-gqx4-7r84-32m6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqx4-7r84-32m6", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1940" + ], + "details": "A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. \n*This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1940" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1908488" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json b/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json new file mode 100644 index 00000000000..9354f48f37f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h267-996p-9gjc/GHSA-h267-996p-9gjc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h267-996p-9gjc", + "modified": "2025-03-04T15:31:48Z", + "published": "2025-03-04T15:31:48Z", + "aliases": [ + "CVE-2025-1932" + ], + "details": "An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1932" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944313" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json b/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json new file mode 100644 index 00000000000..aea8f62a503 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m2rp-964h-h237/GHSA-m2rp-964h-h237.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2rp-964h-h237", + "modified": "2025-03-04T15:31:50Z", + "published": "2025-03-04T15:31:50Z", + "aliases": [ + "CVE-2025-27424" + ], + "details": "Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27424" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1945392" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json b/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json new file mode 100644 index 00000000000..46e60942b64 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m793-xp46-r76w/GHSA-m793-xp46-r76w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m793-xp46-r76w", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1941" + ], + "details": "Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1941" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944665" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json b/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json index 44627b1b908..8fd0579bcd1 100644 --- a/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json +++ b/advisories/unreviewed/2025/03/GHSA-ppp4-p6wj-8gp8/GHSA-ppp4-p6wj-8gp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ppp4-p6wj-8gp8", - "modified": "2025-03-04T06:30:34Z", + "modified": "2025-03-04T15:31:48Z", "published": "2025-03-04T06:30:34Z", "aliases": [ "CVE-2024-13685" ], "details": "The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T06:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qwhp-hhhx-5xg8/GHSA-qwhp-hhhx-5xg8.json b/advisories/unreviewed/2025/03/GHSA-qwhp-hhhx-5xg8/GHSA-qwhp-hhhx-5xg8.json new file mode 100644 index 00000000000..d4cbaf7b34b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qwhp-hhhx-5xg8/GHSA-qwhp-hhhx-5xg8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwhp-hhhx-5xg8", + "modified": "2025-03-04T15:31:48Z", + "published": "2025-03-04T15:31:48Z", + "aliases": [ + "CVE-2025-1931" + ], + "details": "It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1931" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1944126" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-15" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json b/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json new file mode 100644 index 00000000000..b9b284072ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r83v-rmq7-r5m4/GHSA-r83v-rmq7-r5m4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r83v-rmq7-r5m4", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1942" + ], + "details": "When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1942" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1947139" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json b/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json new file mode 100644 index 00000000000..7deb8e60bf7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r84f-4wj3-r6vx/GHSA-r84f-4wj3-r6vx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r84f-4wj3-r6vx", + "modified": "2025-03-04T15:31:48Z", + "published": "2025-03-04T15:31:48Z", + "aliases": [ + "CVE-2025-1933" + ], + "details": "On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1933" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1946004" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-15" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x4j2-c46q-7jp5/GHSA-x4j2-c46q-7jp5.json b/advisories/unreviewed/2025/03/GHSA-x4j2-c46q-7jp5/GHSA-x4j2-c46q-7jp5.json new file mode 100644 index 00000000000..1833df68a61 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x4j2-c46q-7jp5/GHSA-x4j2-c46q-7jp5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4j2-c46q-7jp5", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1936" + ], + "details": "jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1936" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1940027" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json b/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json new file mode 100644 index 00000000000..8fc11e3713e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x9h6-qwxm-528g/GHSA-x9h6-qwxm-528g.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9h6-qwxm-528g", + "modified": "2025-03-04T15:31:49Z", + "published": "2025-03-04T15:31:49Z", + "aliases": [ + "CVE-2025-1939" + ], + "details": "Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1939" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1928334" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-14" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-04T14:15:38Z" + } +} \ No newline at end of file