diff --git a/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json b/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json new file mode 100644 index 00000000000..d9d1e33d49f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22v5-q59j-h85m", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-5959" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5959" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/422313191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json b/advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json new file mode 100644 index 00000000000..9898ecd9042 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29jf-p5rf-wvx6", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49790" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49790" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json b/advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json new file mode 100644 index 00000000000..4d5b95f8730 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4979-ffcq-3f48", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2024-1244" + ], + "details": "Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1244" + }, + { + "type": "WEB", + "url": "https://pentraze.com" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json b/advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json new file mode 100644 index 00000000000..8814916a833 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gv-4jrq-r6pg", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49788" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49788" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json b/advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json new file mode 100644 index 00000000000..354c1ec6e59 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6frq-j7qq-pmc9", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49793" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49793" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json b/advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json new file mode 100644 index 00000000000..8accba65d48 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c52-6wjh-x2v8", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49787" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49787" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json b/advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json new file mode 100644 index 00000000000..31eed405d3a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fgq-497v-jgqg", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49791" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49791" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json b/advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json new file mode 100644 index 00000000000..65640574aba --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4f3-5vvh-xjgj", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49091" + ], + "details": "KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49091" + }, + { + "type": "WEB", + "url": "https://invent.kde.org/utilities/konsole/-/commit/09d20dea109050b4c02fb73095f327b5642a2b75" + }, + { + "type": "WEB", + "url": "https://invent.kde.org/utilities/konsole/-/tags" + }, + { + "type": "WEB", + "url": "https://kde.org/info/security/advisory-20250609-1.txt" + }, + { + "type": "WEB", + "url": "https://konsole.kde.org/changelog.html" + }, + { + "type": "WEB", + "url": "https://proofnet.de/publikationen/konsole_rce.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2025/06/10/5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-670" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json b/advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json new file mode 100644 index 00000000000..b4c4837ad81 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmx2-2cmp-r6x7", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49785" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49785" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json b/advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json new file mode 100644 index 00000000000..5f9e1d18132 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9r5-7mg9-fwrr", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-4275" + ], + "details": "Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4275" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/sa-2025002" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/211341" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json b/advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json new file mode 100644 index 00000000000..02d220b2fd7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpcv-2p6g-35h8", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49786" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49786" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json b/advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json new file mode 100644 index 00000000000..a3dbc64d634 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqh8-7hvc-6rqm", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49789" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49789" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json b/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json new file mode 100644 index 00000000000..7cd0dcea7a6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x573-8wx6-vhf4", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-5958" + ], + "details": "Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5958" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/420150619" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json b/advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json new file mode 100644 index 00000000000..b77e3a49f90 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x78m-5f4r-8hwh", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49792" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49792" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file