Publish Advisories

GHSA-22v5-q59j-h85m
GHSA-29jf-p5rf-wvx6
GHSA-4979-ffcq-3f48
GHSA-62gv-4jrq-r6pg
GHSA-6frq-j7qq-pmc9
GHSA-7c52-6wjh-x2v8
GHSA-7fgq-497v-jgqg
GHSA-h4f3-5vvh-xjgj
GHSA-rmx2-2cmp-r6x7
GHSA-v9r5-7mg9-fwrr
GHSA-wpcv-2p6g-35h8
GHSA-wqh8-7hvc-6rqm
GHSA-x573-8wx6-vhf4
GHSA-x78m-5f4r-8hwh
This commit is contained in:
advisory-database[bot]
2025-06-11 03:32:19 +00:00
parent 50a07213dc
commit 0e06cc0cbd
14 changed files with 429 additions and 0 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22v5-q59j-h85m",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-5959"
],
"details": "Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5959"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/422313191"
}
],
"database_specific": {
"cwe_ids": [
"CWE-843"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T01:15:21Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29jf-p5rf-wvx6",
"modified": "2025-06-11T03:31:08Z",
"published": "2025-06-11T03:31:08Z",
"aliases": [
"CVE-2025-49790"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49790"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4979-ffcq-3f48",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2024-1244"
],
"details": "Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1244"
},
{
"type": "WEB",
"url": "https://pentraze.com"
},
{
"type": "WEB",
"url": "https://pentraze.com/vulnerability-reports"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:21Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62gv-4jrq-r6pg",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-49788"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49788"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6frq-j7qq-pmc9",
"modified": "2025-06-11T03:31:08Z",
"published": "2025-06-11T03:31:08Z",
"aliases": [
"CVE-2025-49793"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49793"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7c52-6wjh-x2v8",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-49787"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49787"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fgq-497v-jgqg",
"modified": "2025-06-11T03:31:08Z",
"published": "2025-06-11T03:31:08Z",
"aliases": [
"CVE-2025-49791"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49791"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4f3-5vvh-xjgj",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-49091"
],
"details": "KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49091"
},
{
"type": "WEB",
"url": "https://invent.kde.org/utilities/konsole/-/commit/09d20dea109050b4c02fb73095f327b5642a2b75"
},
{
"type": "WEB",
"url": "https://invent.kde.org/utilities/konsole/-/tags"
},
{
"type": "WEB",
"url": "https://kde.org/info/security/advisory-20250609-1.txt"
},
{
"type": "WEB",
"url": "https://konsole.kde.org/changelog.html"
},
{
"type": "WEB",
"url": "https://proofnet.de/publikationen/konsole_rce.html"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2025/06/10/5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-670"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T01:15:20Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmx2-2cmp-r6x7",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-49785"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49785"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9r5-7mg9-fwrr",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-4275"
],
"details": "Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4275"
},
{
"type": "WEB",
"url": "https://www.insyde.com/security-pledge/sa-2025002"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/211341"
}
],
"database_specific": {
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T01:15:20Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wpcv-2p6g-35h8",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-49786"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49786"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wqh8-7hvc-6rqm",
"modified": "2025-06-11T03:31:08Z",
"published": "2025-06-11T03:31:08Z",
"aliases": [
"CVE-2025-49789"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49789"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x573-8wx6-vhf4",
"modified": "2025-06-11T03:31:07Z",
"published": "2025-06-11T03:31:07Z",
"aliases": [
"CVE-2025-5958"
],
"details": "Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5958"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/420150619"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T01:15:20Z"
}
}
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x78m-5f4r-8hwh",
"modified": "2025-06-11T03:31:08Z",
"published": "2025-06-11T03:31:08Z",
"aliases": [
"CVE-2025-49792"
],
"details": "Rejected reason: Not used",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49792"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-11T03:15:22Z"
}
}