From 0e06cc0cbdd5e784c8ad0c0ade8763782533b2c5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Jun 2025 03:32:19 +0000 Subject: [PATCH] Publish Advisories GHSA-22v5-q59j-h85m GHSA-29jf-p5rf-wvx6 GHSA-4979-ffcq-3f48 GHSA-62gv-4jrq-r6pg GHSA-6frq-j7qq-pmc9 GHSA-7c52-6wjh-x2v8 GHSA-7fgq-497v-jgqg GHSA-h4f3-5vvh-xjgj GHSA-rmx2-2cmp-r6x7 GHSA-v9r5-7mg9-fwrr GHSA-wpcv-2p6g-35h8 GHSA-wqh8-7hvc-6rqm GHSA-x573-8wx6-vhf4 GHSA-x78m-5f4r-8hwh --- .../GHSA-22v5-q59j-h85m.json | 35 ++++++++++++ .../GHSA-29jf-p5rf-wvx6.json | 25 +++++++++ .../GHSA-4979-ffcq-3f48.json | 40 +++++++++++++ .../GHSA-62gv-4jrq-r6pg.json | 25 +++++++++ .../GHSA-6frq-j7qq-pmc9.json | 25 +++++++++ .../GHSA-7c52-6wjh-x2v8.json | 25 +++++++++ .../GHSA-7fgq-497v-jgqg.json | 25 +++++++++ .../GHSA-h4f3-5vvh-xjgj.json | 56 +++++++++++++++++++ .../GHSA-rmx2-2cmp-r6x7.json | 25 +++++++++ .../GHSA-v9r5-7mg9-fwrr.json | 38 +++++++++++++ .../GHSA-wpcv-2p6g-35h8.json | 25 +++++++++ .../GHSA-wqh8-7hvc-6rqm.json | 25 +++++++++ .../GHSA-x573-8wx6-vhf4.json | 35 ++++++++++++ .../GHSA-x78m-5f4r-8hwh.json | 25 +++++++++ 14 files changed, 429 insertions(+) create mode 100644 advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json create mode 100644 advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json create mode 100644 advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json create mode 100644 advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json create mode 100644 advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json create mode 100644 advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json create mode 100644 advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json diff --git a/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json b/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json new file mode 100644 index 00000000000..d9d1e33d49f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-22v5-q59j-h85m/GHSA-22v5-q59j-h85m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22v5-q59j-h85m", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-5959" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5959" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/422313191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json b/advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json new file mode 100644 index 00000000000..9898ecd9042 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-29jf-p5rf-wvx6/GHSA-29jf-p5rf-wvx6.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29jf-p5rf-wvx6", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49790" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49790" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json b/advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json new file mode 100644 index 00000000000..4d5b95f8730 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4979-ffcq-3f48/GHSA-4979-ffcq-3f48.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4979-ffcq-3f48", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2024-1244" + ], + "details": "Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or in possession of the agent's key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1244" + }, + { + "type": "WEB", + "url": "https://pentraze.com" + }, + { + "type": "WEB", + "url": "https://pentraze.com/vulnerability-reports" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json b/advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json new file mode 100644 index 00000000000..8814916a833 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-62gv-4jrq-r6pg/GHSA-62gv-4jrq-r6pg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gv-4jrq-r6pg", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49788" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49788" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json b/advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json new file mode 100644 index 00000000000..354c1ec6e59 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6frq-j7qq-pmc9/GHSA-6frq-j7qq-pmc9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6frq-j7qq-pmc9", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49793" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49793" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json b/advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json new file mode 100644 index 00000000000..8accba65d48 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7c52-6wjh-x2v8/GHSA-7c52-6wjh-x2v8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c52-6wjh-x2v8", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49787" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49787" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json b/advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json new file mode 100644 index 00000000000..31eed405d3a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7fgq-497v-jgqg/GHSA-7fgq-497v-jgqg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fgq-497v-jgqg", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49791" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49791" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json b/advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json new file mode 100644 index 00000000000..65640574aba --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h4f3-5vvh-xjgj/GHSA-h4f3-5vvh-xjgj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4f3-5vvh-xjgj", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49091" + ], + "details": "KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49091" + }, + { + "type": "WEB", + "url": "https://invent.kde.org/utilities/konsole/-/commit/09d20dea109050b4c02fb73095f327b5642a2b75" + }, + { + "type": "WEB", + "url": "https://invent.kde.org/utilities/konsole/-/tags" + }, + { + "type": "WEB", + "url": "https://kde.org/info/security/advisory-20250609-1.txt" + }, + { + "type": "WEB", + "url": "https://konsole.kde.org/changelog.html" + }, + { + "type": "WEB", + "url": "https://proofnet.de/publikationen/konsole_rce.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2025/06/10/5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-670" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json b/advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json new file mode 100644 index 00000000000..b4c4837ad81 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rmx2-2cmp-r6x7/GHSA-rmx2-2cmp-r6x7.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmx2-2cmp-r6x7", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49785" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49785" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json b/advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json new file mode 100644 index 00000000000..5f9e1d18132 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v9r5-7mg9-fwrr/GHSA-v9r5-7mg9-fwrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9r5-7mg9-fwrr", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-4275" + ], + "details": "Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4275" + }, + { + "type": "WEB", + "url": "https://www.insyde.com/security-pledge/sa-2025002" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/211341" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json b/advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json new file mode 100644 index 00000000000..02d220b2fd7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wpcv-2p6g-35h8/GHSA-wpcv-2p6g-35h8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpcv-2p6g-35h8", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-49786" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49786" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json b/advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json new file mode 100644 index 00000000000..a3dbc64d634 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wqh8-7hvc-6rqm/GHSA-wqh8-7hvc-6rqm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqh8-7hvc-6rqm", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49789" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49789" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json b/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json new file mode 100644 index 00000000000..7cd0dcea7a6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x573-8wx6-vhf4/GHSA-x573-8wx6-vhf4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x573-8wx6-vhf4", + "modified": "2025-06-11T03:31:07Z", + "published": "2025-06-11T03:31:07Z", + "aliases": [ + "CVE-2025-5958" + ], + "details": "Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5958" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_10.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/420150619" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json b/advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json new file mode 100644 index 00000000000..b77e3a49f90 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x78m-5f4r-8hwh/GHSA-x78m-5f4r-8hwh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x78m-5f4r-8hwh", + "modified": "2025-06-11T03:31:08Z", + "published": "2025-06-11T03:31:08Z", + "aliases": [ + "CVE-2025-49792" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49792" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-11T03:15:22Z" + } +} \ No newline at end of file