From 13b43476bb5c5bdadcd9aec734891883626e9e0f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 17 Jan 2025 03:31:57 +0000 Subject: [PATCH] Publish Advisories GHSA-884m-x6fw-69hf GHSA-gv69-7q7f-c8fh GHSA-h39j-xvhj-phrp GHSA-whvm-p394-24wc --- .../GHSA-884m-x6fw-69hf.json | 36 +++++++++++++++++ .../GHSA-gv69-7q7f-c8fh.json | 40 +++++++++++++++++++ .../GHSA-h39j-xvhj-phrp.json | 36 +++++++++++++++++ .../GHSA-whvm-p394-24wc.json | 36 +++++++++++++++++ 4 files changed, 148 insertions(+) create mode 100644 advisories/unreviewed/2025/01/GHSA-884m-x6fw-69hf/GHSA-884m-x6fw-69hf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gv69-7q7f-c8fh/GHSA-gv69-7q7f-c8fh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h39j-xvhj-phrp/GHSA-h39j-xvhj-phrp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-whvm-p394-24wc/GHSA-whvm-p394-24wc.json diff --git a/advisories/unreviewed/2025/01/GHSA-884m-x6fw-69hf/GHSA-884m-x6fw-69hf.json b/advisories/unreviewed/2025/01/GHSA-884m-x6fw-69hf/GHSA-884m-x6fw-69hf.json new file mode 100644 index 00000000000..c23a9486e8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-884m-x6fw-69hf/GHSA-884m-x6fw-69hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-884m-x6fw-69hf", + "modified": "2025-01-17T03:30:29Z", + "published": "2025-01-17T03:30:29Z", + "aliases": [ + "CVE-2024-51462" + ], + "details": "IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51462" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-471" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gv69-7q7f-c8fh/GHSA-gv69-7q7f-c8fh.json b/advisories/unreviewed/2025/01/GHSA-gv69-7q7f-c8fh/GHSA-gv69-7q7f-c8fh.json new file mode 100644 index 00000000000..2811cb3655b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gv69-7q7f-c8fh/GHSA-gv69-7q7f-c8fh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv69-7q7f-c8fh", + "modified": "2025-01-17T03:30:29Z", + "published": "2025-01-17T03:30:29Z", + "aliases": [ + "CVE-2024-34579" + ], + "details": "Fuji Electric Alpha5 SMART \n\nis vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34579" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-016-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T01:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h39j-xvhj-phrp/GHSA-h39j-xvhj-phrp.json b/advisories/unreviewed/2025/01/GHSA-h39j-xvhj-phrp/GHSA-h39j-xvhj-phrp.json new file mode 100644 index 00000000000..c3cf7920910 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h39j-xvhj-phrp/GHSA-h39j-xvhj-phrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h39j-xvhj-phrp", + "modified": "2025-01-17T03:30:29Z", + "published": "2025-01-17T03:30:29Z", + "aliases": [ + "CVE-2024-52363" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52363" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176515" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T02:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-whvm-p394-24wc/GHSA-whvm-p394-24wc.json b/advisories/unreviewed/2025/01/GHSA-whvm-p394-24wc/GHSA-whvm-p394-24wc.json new file mode 100644 index 00000000000..a6f023885bb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-whvm-p394-24wc/GHSA-whvm-p394-24wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whvm-p394-24wc", + "modified": "2025-01-17T03:30:29Z", + "published": "2025-01-17T03:30:29Z", + "aliases": [ + "CVE-2025-21325" + ], + "details": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21325" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21325" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T01:15:31Z" + } +} \ No newline at end of file