mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-22v5-q59j-h85m GHSA-29jf-p5rf-wvx6 GHSA-4979-ffcq-3f48 GHSA-62gv-4jrq-r6pg GHSA-6frq-j7qq-pmc9 GHSA-7c52-6wjh-x2v8 GHSA-7fgq-497v-jgqg GHSA-h4f3-5vvh-xjgj GHSA-rmx2-2cmp-r6x7 GHSA-v9r5-7mg9-fwrr GHSA-wpcv-2p6g-35h8 GHSA-wqh8-7hvc-6rqm GHSA-x573-8wx6-vhf4 GHSA-x78m-5f4r-8hwh
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-22v5-q59j-h85m",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-5959"
|
||||
],
|
||||
"details": "Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5959"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/422313191"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-843"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T01:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-29jf-p5rf-wvx6",
|
||||
"modified": "2025-06-11T03:31:08Z",
|
||||
"published": "2025-06-11T03:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49790"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49790"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4979-ffcq-3f48",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2024-1244"
|
||||
],
|
||||
"details": "Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1244"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pentraze.com"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pentraze.com/vulnerability-reports"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-62gv-4jrq-r6pg",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49788"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49788"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6frq-j7qq-pmc9",
|
||||
"modified": "2025-06-11T03:31:08Z",
|
||||
"published": "2025-06-11T03:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49793"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49793"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7c52-6wjh-x2v8",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49787"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49787"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7fgq-497v-jgqg",
|
||||
"modified": "2025-06-11T03:31:08Z",
|
||||
"published": "2025-06-11T03:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49791"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49791"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,56 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h4f3-5vvh-xjgj",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49091"
|
||||
],
|
||||
"details": "KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49091"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://invent.kde.org/utilities/konsole/-/commit/09d20dea109050b4c02fb73095f327b5642a2b75"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://invent.kde.org/utilities/konsole/-/tags"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://kde.org/info/security/advisory-20250609-1.txt"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://konsole.kde.org/changelog.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://proofnet.de/publikationen/konsole_rce.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.openwall.com/lists/oss-security/2025/06/10/5"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-670"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T01:15:20Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rmx2-2cmp-r6x7",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49785"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49785"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v9r5-7mg9-fwrr",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-4275"
|
||||
],
|
||||
"details": "Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4275"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.insyde.com/security-pledge/sa-2025002"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.kb.cert.org/vuls/id/211341"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T01:15:20Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wpcv-2p6g-35h8",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49786"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49786"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wqh8-7hvc-6rqm",
|
||||
"modified": "2025-06-11T03:31:08Z",
|
||||
"published": "2025-06-11T03:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49789"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49789"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x573-8wx6-vhf4",
|
||||
"modified": "2025-06-11T03:31:07Z",
|
||||
"published": "2025-06-11T03:31:07Z",
|
||||
"aliases": [
|
||||
"CVE-2025-5958"
|
||||
],
|
||||
"details": "Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5958"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://issues.chromium.org/issues/420150619"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-416"
|
||||
],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T01:15:20Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x78m-5f4r-8hwh",
|
||||
"modified": "2025-06-11T03:31:08Z",
|
||||
"published": "2025-06-11T03:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2025-49792"
|
||||
],
|
||||
"details": "Rejected reason: Not used",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49792"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-06-11T03:15:22Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user