diff --git a/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json b/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json index 234fa73e631..23411950ffb 100644 --- a/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json +++ b/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-266" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json b/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json index 9081fc7a5dd..817911c111d 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json +++ b/advisories/unreviewed/2024/04/GHSA-xrxq-p636-j73q/GHSA-xrxq-p636-j73q.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-h7pc-vx5r-jf48/GHSA-h7pc-vx5r-jf48.json b/advisories/unreviewed/2024/07/GHSA-h7pc-vx5r-jf48/GHSA-h7pc-vx5r-jf48.json index eab3c57e3ef..6b56938f7f5 100644 --- a/advisories/unreviewed/2024/07/GHSA-h7pc-vx5r-jf48/GHSA-h7pc-vx5r-jf48.json +++ b/advisories/unreviewed/2024/07/GHSA-h7pc-vx5r-jf48/GHSA-h7pc-vx5r-jf48.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json index 1c13cd55216..b399acdf021 100644 --- a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json +++ b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2p9-j475-2wp5", - "modified": "2025-03-19T21:30:41Z", + "modified": "2025-03-21T00:31:20Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9956" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://mastersplinter.work/research/passkey" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=43408674" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json b/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json index a407c63dcc0..2d87d7f324c 100644 --- a/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json +++ b/advisories/unreviewed/2024/12/GHSA-hjmx-m9c7-h485/GHSA-hjmx-m9c7-h485.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjmx-m9c7-h485", - "modified": "2024-12-12T18:30:55Z", + "modified": "2025-03-21T00:31:20Z", "published": "2024-12-12T03:33:06Z", "aliases": [ "CVE-2024-54471" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54471" }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=43425605" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/121568" @@ -26,6 +30,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/121570" + }, + { + "type": "WEB", + "url": "https://wts.dev/posts/password-leak" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json b/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json new file mode 100644 index 00000000000..66b9caa04f1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29mf-g5hc-vfvc", + "modified": "2025-03-21T00:31:21Z", + "published": "2025-03-21T00:31:21Z", + "aliases": [ + "CVE-2024-54564" + ], + "details": "This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54564" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120909" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120911" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120915" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T00:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9hv4-q92m-86w6/GHSA-9hv4-q92m-86w6.json b/advisories/unreviewed/2025/03/GHSA-9hv4-q92m-86w6/GHSA-9hv4-q92m-86w6.json new file mode 100644 index 00000000000..b319d33c3aa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9hv4-q92m-86w6/GHSA-9hv4-q92m-86w6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hv4-q92m-86w6", + "modified": "2025-03-21T00:31:21Z", + "published": "2025-03-21T00:31:21Z", + "aliases": [ + "CVE-2024-44199" + ], + "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected system termination or read kernel memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44199" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120911" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T00:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gqm6-fmp7-jxxx/GHSA-gqm6-fmp7-jxxx.json b/advisories/unreviewed/2025/03/GHSA-gqm6-fmp7-jxxx/GHSA-gqm6-fmp7-jxxx.json new file mode 100644 index 00000000000..3b51a7bac91 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gqm6-fmp7-jxxx/GHSA-gqm6-fmp7-jxxx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqm6-fmp7-jxxx", + "modified": "2025-03-21T00:31:21Z", + "published": "2025-03-21T00:31:21Z", + "aliases": [ + "CVE-2024-44305" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44305" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120911" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T00:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hrw4-vr8h-245c/GHSA-hrw4-vr8h-245c.json b/advisories/unreviewed/2025/03/GHSA-hrw4-vr8h-245c/GHSA-hrw4-vr8h-245c.json new file mode 100644 index 00000000000..4ed3315fafe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hrw4-vr8h-245c/GHSA-hrw4-vr8h-245c.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrw4-vr8h-245c", + "modified": "2025-03-21T00:31:21Z", + "published": "2025-03-21T00:31:21Z", + "aliases": [ + "CVE-2024-54551" + ], + "details": "The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.6, tvOS 17.6, Safari 17.6, macOS Sonoma 14.6, visionOS 1.3, iOS 17.6 and iPadOS 17.6. Processing web content may lead to a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54551" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120909" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120911" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120913" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120914" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120915" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120916" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T00:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pm9w-q8x2-5x3q/GHSA-pm9w-q8x2-5x3q.json b/advisories/unreviewed/2025/03/GHSA-pm9w-q8x2-5x3q/GHSA-pm9w-q8x2-5x3q.json new file mode 100644 index 00000000000..45493f18ba4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pm9w-q8x2-5x3q/GHSA-pm9w-q8x2-5x3q.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm9w-q8x2-5x3q", + "modified": "2025-03-21T00:31:21Z", + "published": "2025-03-21T00:31:21Z", + "aliases": [ + "CVE-2025-2198" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2198" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json b/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json index a249d6e55b4..0de1a73767d 100644 --- a/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json +++ b/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxc8-qhvr-5954", - "modified": "2025-03-20T21:31:47Z", + "modified": "2025-03-21T00:31:20Z", "published": "2025-03-20T21:31:47Z", "aliases": [ "CVE-2025-30334" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30334" }, + { + "type": "WEB", + "url": "https://github.com/openbsd/src/commit/c06199859734d958552a581d72b4c0f910e68d7c" + }, { "type": "WEB", "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.5/common/015_wg.patch.sig"