diff --git a/advisories/unreviewed/2022/04/GHSA-9m2p-5h5q-x254/GHSA-9m2p-5h5q-x254.json b/advisories/unreviewed/2022/04/GHSA-9m2p-5h5q-x254/GHSA-9m2p-5h5q-x254.json index 32cb918b345..56a02564031 100644 --- a/advisories/unreviewed/2022/04/GHSA-9m2p-5h5q-x254/GHSA-9m2p-5h5q-x254.json +++ b/advisories/unreviewed/2022/04/GHSA-9m2p-5h5q-x254/GHSA-9m2p-5h5q-x254.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9m2p-5h5q-x254", - "modified": "2022-04-30T18:16:48Z", + "modified": "2025-04-23T18:30:34Z", "published": "2022-04-30T18:16:48Z", "aliases": [ "CVE-2001-0827" ], "details": "Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of \"PASV\" requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json b/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json index 5e68ee03c61..2c82e99b9a1 100644 --- a/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json +++ b/advisories/unreviewed/2022/05/GHSA-878r-5qjm-6859/GHSA-878r-5qjm-6859.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-878r-5qjm-6859", - "modified": "2022-05-14T01:34:19Z", + "modified": "2025-04-23T18:30:35Z", "published": "2022-05-14T01:34:19Z", "aliases": [ "CVE-2015-8104" ], "details": "The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-8g9h-pmc4-wcr4/GHSA-8g9h-pmc4-wcr4.json b/advisories/unreviewed/2022/05/GHSA-8g9h-pmc4-wcr4/GHSA-8g9h-pmc4-wcr4.json index 8cbe33422c9..6fca7e94c05 100644 --- a/advisories/unreviewed/2022/05/GHSA-8g9h-pmc4-wcr4/GHSA-8g9h-pmc4-wcr4.json +++ b/advisories/unreviewed/2022/05/GHSA-8g9h-pmc4-wcr4/GHSA-8g9h-pmc4-wcr4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8g9h-pmc4-wcr4", - "modified": "2022-05-02T03:36:10Z", + "modified": "2025-04-23T18:30:35Z", "published": "2022-05-02T03:36:10Z", "aliases": [ "CVE-2009-2541" ], "details": "The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json b/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json index fcd8efce1aa..7369e08140f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json +++ b/advisories/unreviewed/2022/05/GHSA-9rgw-x23v-g78g/GHSA-9rgw-x23v-g78g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9rgw-x23v-g78g", - "modified": "2022-05-02T03:48:31Z", + "modified": "2025-04-23T18:30:35Z", "published": "2022-05-02T03:48:31Z", "aliases": [ "CVE-2009-3791" ], "details": "Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json b/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json index ac8b8c45988..7a94b472135 100644 --- a/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json +++ b/advisories/unreviewed/2022/05/GHSA-hwc8-3mcr-2wjf/GHSA-hwc8-3mcr-2wjf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hwc8-3mcr-2wjf", - "modified": "2022-05-01T23:32:07Z", + "modified": "2025-04-23T18:30:34Z", "published": "2022-05-01T23:32:07Z", "aliases": [ "CVE-2008-0642" ], "details": "Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-1280.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-x8hv-5jw9-w467/GHSA-x8hv-5jw9-w467.json b/advisories/unreviewed/2022/05/GHSA-x8hv-5jw9-w467/GHSA-x8hv-5jw9-w467.json index ba0c2ba5211..fa1224168cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8hv-5jw9-w467/GHSA-x8hv-5jw9-w467.json +++ b/advisories/unreviewed/2022/05/GHSA-x8hv-5jw9-w467/GHSA-x8hv-5jw9-w467.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8hv-5jw9-w467", - "modified": "2022-05-01T23:55:29Z", + "modified": "2025-04-23T18:30:34Z", "published": "2022-05-01T23:55:29Z", "aliases": [ "CVE-2008-2991" ], "details": "Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/07/GHSA-gfj3-3p98-wrpg/GHSA-gfj3-3p98-wrpg.json b/advisories/unreviewed/2022/07/GHSA-gfj3-3p98-wrpg/GHSA-gfj3-3p98-wrpg.json index 25c230e9aa0..fcf7055ffd9 100644 --- a/advisories/unreviewed/2022/07/GHSA-gfj3-3p98-wrpg/GHSA-gfj3-3p98-wrpg.json +++ b/advisories/unreviewed/2022/07/GHSA-gfj3-3p98-wrpg/GHSA-gfj3-3p98-wrpg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/08/GHSA-rc6f-9g56-mr6q/GHSA-rc6f-9g56-mr6q.json b/advisories/unreviewed/2022/08/GHSA-rc6f-9g56-mr6q/GHSA-rc6f-9g56-mr6q.json index dceacbf08d1..100a3a0434d 100644 --- a/advisories/unreviewed/2022/08/GHSA-rc6f-9g56-mr6q/GHSA-rc6f-9g56-mr6q.json +++ b/advisories/unreviewed/2022/08/GHSA-rc6f-9g56-mr6q/GHSA-rc6f-9g56-mr6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rc6f-9g56-mr6q", - "modified": "2022-09-07T00:01:53Z", + "modified": "2025-04-23T18:30:35Z", "published": "2022-08-29T20:06:50Z", "aliases": [ "CVE-2022-1199" @@ -50,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-476" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-4f9v-9c5h-xw7r/GHSA-4f9v-9c5h-xw7r.json b/advisories/unreviewed/2022/12/GHSA-4f9v-9c5h-xw7r/GHSA-4f9v-9c5h-xw7r.json index 4452e1586f1..7a52023fc9a 100644 --- a/advisories/unreviewed/2022/12/GHSA-4f9v-9c5h-xw7r/GHSA-4f9v-9c5h-xw7r.json +++ b/advisories/unreviewed/2022/12/GHSA-4f9v-9c5h-xw7r/GHSA-4f9v-9c5h-xw7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4f9v-9c5h-xw7r", - "modified": "2022-12-08T15:30:25Z", + "modified": "2025-04-23T18:30:36Z", "published": "2022-12-06T21:30:46Z", "aliases": [ "CVE-2022-43369" diff --git a/advisories/unreviewed/2022/12/GHSA-4w4g-w5xw-9p3m/GHSA-4w4g-w5xw-9p3m.json b/advisories/unreviewed/2022/12/GHSA-4w4g-w5xw-9p3m/GHSA-4w4g-w5xw-9p3m.json index 43403ae21a8..9405649b79f 100644 --- a/advisories/unreviewed/2022/12/GHSA-4w4g-w5xw-9p3m/GHSA-4w4g-w5xw-9p3m.json +++ b/advisories/unreviewed/2022/12/GHSA-4w4g-w5xw-9p3m/GHSA-4w4g-w5xw-9p3m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6vx5-8rxp-jw26/GHSA-6vx5-8rxp-jw26.json b/advisories/unreviewed/2022/12/GHSA-6vx5-8rxp-jw26/GHSA-6vx5-8rxp-jw26.json index be81b629777..2f0caba98c1 100644 --- a/advisories/unreviewed/2022/12/GHSA-6vx5-8rxp-jw26/GHSA-6vx5-8rxp-jw26.json +++ b/advisories/unreviewed/2022/12/GHSA-6vx5-8rxp-jw26/GHSA-6vx5-8rxp-jw26.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-835" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-8gp4-vw26-j7xc/GHSA-8gp4-vw26-j7xc.json b/advisories/unreviewed/2022/12/GHSA-8gp4-vw26-j7xc/GHSA-8gp4-vw26-j7xc.json index 852a5f8f952..7845e96a3c7 100644 --- a/advisories/unreviewed/2022/12/GHSA-8gp4-vw26-j7xc/GHSA-8gp4-vw26-j7xc.json +++ b/advisories/unreviewed/2022/12/GHSA-8gp4-vw26-j7xc/GHSA-8gp4-vw26-j7xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gp4-vw26-j7xc", - "modified": "2022-12-09T15:30:29Z", + "modified": "2025-04-23T18:30:37Z", "published": "2022-12-07T03:30:18Z", "aliases": [ "CVE-2022-45915" diff --git a/advisories/unreviewed/2022/12/GHSA-8wm6-g26m-hfv9/GHSA-8wm6-g26m-hfv9.json b/advisories/unreviewed/2022/12/GHSA-8wm6-g26m-hfv9/GHSA-8wm6-g26m-hfv9.json index e72f6d71168..d1d082c014a 100644 --- a/advisories/unreviewed/2022/12/GHSA-8wm6-g26m-hfv9/GHSA-8wm6-g26m-hfv9.json +++ b/advisories/unreviewed/2022/12/GHSA-8wm6-g26m-hfv9/GHSA-8wm6-g26m-hfv9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-9fhw-hf7x-9gjc/GHSA-9fhw-hf7x-9gjc.json b/advisories/unreviewed/2022/12/GHSA-9fhw-hf7x-9gjc/GHSA-9fhw-hf7x-9gjc.json index cb3e4b01ff2..1ea72dcc460 100644 --- a/advisories/unreviewed/2022/12/GHSA-9fhw-hf7x-9gjc/GHSA-9fhw-hf7x-9gjc.json +++ b/advisories/unreviewed/2022/12/GHSA-9fhw-hf7x-9gjc/GHSA-9fhw-hf7x-9gjc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fhw-hf7x-9gjc", - "modified": "2022-12-12T18:30:28Z", + "modified": "2025-04-23T18:30:40Z", "published": "2022-12-09T00:30:18Z", "aliases": [ "CVE-2022-38765" diff --git a/advisories/unreviewed/2022/12/GHSA-9v63-c998-mq62/GHSA-9v63-c998-mq62.json b/advisories/unreviewed/2022/12/GHSA-9v63-c998-mq62/GHSA-9v63-c998-mq62.json index 6d6192e43e8..16f64baabc7 100644 --- a/advisories/unreviewed/2022/12/GHSA-9v63-c998-mq62/GHSA-9v63-c998-mq62.json +++ b/advisories/unreviewed/2022/12/GHSA-9v63-c998-mq62/GHSA-9v63-c998-mq62.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-ghhq-5mmr-7wf5/GHSA-ghhq-5mmr-7wf5.json b/advisories/unreviewed/2022/12/GHSA-ghhq-5mmr-7wf5/GHSA-ghhq-5mmr-7wf5.json index 77b988a66b2..2bd87b84e2a 100644 --- a/advisories/unreviewed/2022/12/GHSA-ghhq-5mmr-7wf5/GHSA-ghhq-5mmr-7wf5.json +++ b/advisories/unreviewed/2022/12/GHSA-ghhq-5mmr-7wf5/GHSA-ghhq-5mmr-7wf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ghhq-5mmr-7wf5", - "modified": "2022-12-12T18:30:28Z", + "modified": "2025-04-23T18:30:40Z", "published": "2022-12-08T21:30:19Z", "aliases": [ "CVE-2022-44938" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-330" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-gvwr-2f69-3xgr/GHSA-gvwr-2f69-3xgr.json b/advisories/unreviewed/2022/12/GHSA-gvwr-2f69-3xgr/GHSA-gvwr-2f69-3xgr.json index f1bea10bdd2..e5142bd9fe9 100644 --- a/advisories/unreviewed/2022/12/GHSA-gvwr-2f69-3xgr/GHSA-gvwr-2f69-3xgr.json +++ b/advisories/unreviewed/2022/12/GHSA-gvwr-2f69-3xgr/GHSA-gvwr-2f69-3xgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvwr-2f69-3xgr", - "modified": "2022-12-08T18:30:49Z", + "modified": "2025-04-23T18:30:36Z", "published": "2022-12-06T15:30:28Z", "aliases": [ "CVE-2022-46383" diff --git a/advisories/unreviewed/2022/12/GHSA-hf6q-rx44-fh6j/GHSA-hf6q-rx44-fh6j.json b/advisories/unreviewed/2022/12/GHSA-hf6q-rx44-fh6j/GHSA-hf6q-rx44-fh6j.json index 28c0a1ba78d..2a8fe4c9e1b 100644 --- a/advisories/unreviewed/2022/12/GHSA-hf6q-rx44-fh6j/GHSA-hf6q-rx44-fh6j.json +++ b/advisories/unreviewed/2022/12/GHSA-hf6q-rx44-fh6j/GHSA-hf6q-rx44-fh6j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hf6q-rx44-fh6j", - "modified": "2022-12-08T18:30:50Z", + "modified": "2025-04-23T18:30:37Z", "published": "2022-12-07T03:30:18Z", "aliases": [ "CVE-2022-45917" diff --git a/advisories/unreviewed/2022/12/GHSA-hpjg-5532-2p8m/GHSA-hpjg-5532-2p8m.json b/advisories/unreviewed/2022/12/GHSA-hpjg-5532-2p8m/GHSA-hpjg-5532-2p8m.json index 2a442f2f9e3..768577afad3 100644 --- a/advisories/unreviewed/2022/12/GHSA-hpjg-5532-2p8m/GHSA-hpjg-5532-2p8m.json +++ b/advisories/unreviewed/2022/12/GHSA-hpjg-5532-2p8m/GHSA-hpjg-5532-2p8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpjg-5532-2p8m", - "modified": "2022-12-08T18:30:50Z", + "modified": "2025-04-23T18:30:37Z", "published": "2022-12-07T03:30:18Z", "aliases": [ "CVE-2022-45916" diff --git a/advisories/unreviewed/2022/12/GHSA-m4vp-q257-m88x/GHSA-m4vp-q257-m88x.json b/advisories/unreviewed/2022/12/GHSA-m4vp-q257-m88x/GHSA-m4vp-q257-m88x.json index 895e191f06f..f17c0bea05b 100644 --- a/advisories/unreviewed/2022/12/GHSA-m4vp-q257-m88x/GHSA-m4vp-q257-m88x.json +++ b/advisories/unreviewed/2022/12/GHSA-m4vp-q257-m88x/GHSA-m4vp-q257-m88x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-qf5h-2qwh-9v97/GHSA-qf5h-2qwh-9v97.json b/advisories/unreviewed/2022/12/GHSA-qf5h-2qwh-9v97/GHSA-qf5h-2qwh-9v97.json index e50036358ac..776e3737fc1 100644 --- a/advisories/unreviewed/2022/12/GHSA-qf5h-2qwh-9v97/GHSA-qf5h-2qwh-9v97.json +++ b/advisories/unreviewed/2022/12/GHSA-qf5h-2qwh-9v97/GHSA-qf5h-2qwh-9v97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf5h-2qwh-9v97", - "modified": "2022-12-08T18:30:49Z", + "modified": "2025-04-23T18:30:36Z", "published": "2022-12-06T18:30:19Z", "aliases": [ "CVE-2022-46382" diff --git a/advisories/unreviewed/2022/12/GHSA-vqg4-f4c6-fxj3/GHSA-vqg4-f4c6-fxj3.json b/advisories/unreviewed/2022/12/GHSA-vqg4-f4c6-fxj3/GHSA-vqg4-f4c6-fxj3.json index 9eeb1d7e406..25a3e09195b 100644 --- a/advisories/unreviewed/2022/12/GHSA-vqg4-f4c6-fxj3/GHSA-vqg4-f4c6-fxj3.json +++ b/advisories/unreviewed/2022/12/GHSA-vqg4-f4c6-fxj3/GHSA-vqg4-f4c6-fxj3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-x8rw-qrmg-7cmp/GHSA-x8rw-qrmg-7cmp.json b/advisories/unreviewed/2022/12/GHSA-x8rw-qrmg-7cmp/GHSA-x8rw-qrmg-7cmp.json index 68ed671e809..638adf592f8 100644 --- a/advisories/unreviewed/2022/12/GHSA-x8rw-qrmg-7cmp/GHSA-x8rw-qrmg-7cmp.json +++ b/advisories/unreviewed/2022/12/GHSA-x8rw-qrmg-7cmp/GHSA-x8rw-qrmg-7cmp.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/03/GHSA-frcw-7v9f-qh6g/GHSA-frcw-7v9f-qh6g.json b/advisories/unreviewed/2023/03/GHSA-frcw-7v9f-qh6g/GHSA-frcw-7v9f-qh6g.json index 9effdf73d36..b450647960f 100644 --- a/advisories/unreviewed/2023/03/GHSA-frcw-7v9f-qh6g/GHSA-frcw-7v9f-qh6g.json +++ b/advisories/unreviewed/2023/03/GHSA-frcw-7v9f-qh6g/GHSA-frcw-7v9f-qh6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frcw-7v9f-qh6g", - "modified": "2023-03-10T06:30:21Z", + "modified": "2025-04-23T18:30:41Z", "published": "2023-03-02T18:30:26Z", "aliases": [ "CVE-2023-1118" diff --git a/advisories/unreviewed/2023/04/GHSA-w6wj-g5cv-fh4w/GHSA-w6wj-g5cv-fh4w.json b/advisories/unreviewed/2023/04/GHSA-w6wj-g5cv-fh4w/GHSA-w6wj-g5cv-fh4w.json index 37f89b61f64..f694927e00e 100644 --- a/advisories/unreviewed/2023/04/GHSA-w6wj-g5cv-fh4w/GHSA-w6wj-g5cv-fh4w.json +++ b/advisories/unreviewed/2023/04/GHSA-w6wj-g5cv-fh4w/GHSA-w6wj-g5cv-fh4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6wj-g5cv-fh4w", - "modified": "2023-11-26T12:30:23Z", + "modified": "2025-04-23T18:30:42Z", "published": "2023-04-11T00:30:24Z", "aliases": [ "CVE-2023-1668" diff --git a/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json b/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json index be6a5120c4e..e616da77fda 100644 --- a/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json +++ b/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mm53-x3wx-jgr2", - "modified": "2024-04-04T07:14:45Z", + "modified": "2025-04-23T18:30:45Z", "published": "2023-08-28T21:31:06Z", "aliases": [ "CVE-2023-39810" @@ -26,6 +26,18 @@ { "type": "WEB", "url": "http://busybox.com" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/23/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/23/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/23/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json b/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json index 298bc7d057d..1999f2e2f79 100644 --- a/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json +++ b/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x7w6-3cp2-qjcv", - "modified": "2023-11-08T21:30:33Z", + "modified": "2025-04-23T18:30:50Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5561" diff --git a/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json b/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json index 10b0f1ea339..b315dd5a257 100644 --- a/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json +++ b/advisories/unreviewed/2023/12/GHSA-2x74-jrhg-mr4p/GHSA-2x74-jrhg-mr4p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x74-jrhg-mr4p", - "modified": "2024-01-04T00:30:19Z", + "modified": "2025-04-23T18:30:51Z", "published": "2023-12-25T09:30:21Z", "aliases": [ "CVE-2023-49954" diff --git a/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json b/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json index 6457a2505c0..161b67f07ca 100644 --- a/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json +++ b/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g845-grc9-p9qg", - "modified": "2024-01-02T21:30:25Z", + "modified": "2025-04-23T18:30:51Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-50175" diff --git a/advisories/unreviewed/2023/12/GHSA-g8w6-ghch-w9w2/GHSA-g8w6-ghch-w9w2.json b/advisories/unreviewed/2023/12/GHSA-g8w6-ghch-w9w2/GHSA-g8w6-ghch-w9w2.json index b52f1aed320..2859e3652a1 100644 --- a/advisories/unreviewed/2023/12/GHSA-g8w6-ghch-w9w2/GHSA-g8w6-ghch-w9w2.json +++ b/advisories/unreviewed/2023/12/GHSA-g8w6-ghch-w9w2/GHSA-g8w6-ghch-w9w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8w6-ghch-w9w2", - "modified": "2024-01-04T18:30:20Z", + "modified": "2025-04-23T18:30:51Z", "published": "2023-12-26T09:30:18Z", "aliases": [ "CVE-2023-45740" diff --git a/advisories/unreviewed/2023/12/GHSA-xhgw-9c9f-wj5v/GHSA-xhgw-9c9f-wj5v.json b/advisories/unreviewed/2023/12/GHSA-xhgw-9c9f-wj5v/GHSA-xhgw-9c9f-wj5v.json index 2428849b5e5..0766ddcccd8 100644 --- a/advisories/unreviewed/2023/12/GHSA-xhgw-9c9f-wj5v/GHSA-xhgw-9c9f-wj5v.json +++ b/advisories/unreviewed/2023/12/GHSA-xhgw-9c9f-wj5v/GHSA-xhgw-9c9f-wj5v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xhgw-9c9f-wj5v", - "modified": "2023-12-29T21:30:45Z", + "modified": "2025-04-23T18:30:50Z", "published": "2023-12-22T00:30:31Z", "aliases": [ "CVE-2023-37519" ], - "details": "Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. \n", + "details": "Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server. ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json b/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json index 169d6684975..1c52f6ba6f0 100644 --- a/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json +++ b/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xrgp-j4fj-fqwr/GHSA-xrgp-j4fj-fqwr.json b/advisories/unreviewed/2024/03/GHSA-xrgp-j4fj-fqwr/GHSA-xrgp-j4fj-fqwr.json index 28a3d719bfd..b3382e8e99f 100644 --- a/advisories/unreviewed/2024/03/GHSA-xrgp-j4fj-fqwr/GHSA-xrgp-j4fj-fqwr.json +++ b/advisories/unreviewed/2024/03/GHSA-xrgp-j4fj-fqwr/GHSA-xrgp-j4fj-fqwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrgp-j4fj-fqwr", - "modified": "2024-03-05T12:30:33Z", + "modified": "2025-04-23T18:30:52Z", "published": "2024-03-05T12:30:33Z", "aliases": [ "CVE-2023-45600" diff --git a/advisories/unreviewed/2024/05/GHSA-92qm-mq2f-95w2/GHSA-92qm-mq2f-95w2.json b/advisories/unreviewed/2024/05/GHSA-92qm-mq2f-95w2/GHSA-92qm-mq2f-95w2.json index 75ae9660b5c..e158a489619 100644 --- a/advisories/unreviewed/2024/05/GHSA-92qm-mq2f-95w2/GHSA-92qm-mq2f-95w2.json +++ b/advisories/unreviewed/2024/05/GHSA-92qm-mq2f-95w2/GHSA-92qm-mq2f-95w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92qm-mq2f-95w2", - "modified": "2024-05-02T18:30:53Z", + "modified": "2025-04-23T18:30:55Z", "published": "2024-05-02T18:30:53Z", "aliases": [ "CVE-2024-2346" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-7fxc-245r-5w9m/GHSA-7fxc-245r-5w9m.json b/advisories/unreviewed/2025/03/GHSA-7fxc-245r-5w9m/GHSA-7fxc-245r-5w9m.json index f14e10686c7..c9429d5dee6 100644 --- a/advisories/unreviewed/2025/03/GHSA-7fxc-245r-5w9m/GHSA-7fxc-245r-5w9m.json +++ b/advisories/unreviewed/2025/03/GHSA-7fxc-245r-5w9m/GHSA-7fxc-245r-5w9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fxc-245r-5w9m", - "modified": "2025-04-16T00:31:31Z", + "modified": "2025-04-23T18:30:55Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27654" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-xss-04" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-c558-7gx5-7hf4/GHSA-c558-7gx5-7hf4.json b/advisories/unreviewed/2025/03/GHSA-c558-7gx5-7hf4/GHSA-c558-7gx5-7hf4.json index b14c3b87e7e..65d6d83b291 100644 --- a/advisories/unreviewed/2025/03/GHSA-c558-7gx5-7hf4/GHSA-c558-7gx5-7hf4.json +++ b/advisories/unreviewed/2025/03/GHSA-c558-7gx5-7hf4/GHSA-c558-7gx5-7hf4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c558-7gx5-7hf4", - "modified": "2025-04-16T00:31:30Z", + "modified": "2025-04-23T18:30:55Z", "published": "2025-03-05T06:31:41Z", "aliases": [ "CVE-2025-27637" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-xss-01" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-fv6c-6rqc-j6m8/GHSA-fv6c-6rqc-j6m8.json b/advisories/unreviewed/2025/03/GHSA-fv6c-6rqc-j6m8/GHSA-fv6c-6rqc-j6m8.json index 998c97d2a84..f0d45edd122 100644 --- a/advisories/unreviewed/2025/03/GHSA-fv6c-6rqc-j6m8/GHSA-fv6c-6rqc-j6m8.json +++ b/advisories/unreviewed/2025/03/GHSA-fv6c-6rqc-j6m8/GHSA-fv6c-6rqc-j6m8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv6c-6rqc-j6m8", - "modified": "2025-04-16T00:31:31Z", + "modified": "2025-04-23T18:30:55Z", "published": "2025-03-05T06:31:42Z", "aliases": [ "CVE-2025-27653" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-stored-xss" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-gxmw-96jw-fwjw/GHSA-gxmw-96jw-fwjw.json b/advisories/unreviewed/2025/03/GHSA-gxmw-96jw-fwjw/GHSA-gxmw-96jw-fwjw.json index ba9f8c98669..f5e5ba9a33a 100644 --- a/advisories/unreviewed/2025/03/GHSA-gxmw-96jw-fwjw/GHSA-gxmw-96jw-fwjw.json +++ b/advisories/unreviewed/2025/03/GHSA-gxmw-96jw-fwjw/GHSA-gxmw-96jw-fwjw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gxmw-96jw-fwjw", - "modified": "2025-04-16T00:31:32Z", + "modified": "2025-04-23T18:30:55Z", "published": "2025-03-05T06:31:43Z", "aliases": [ "CVE-2025-27676" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html" + }, + { + "type": "WEB", + "url": "https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-xss-03" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-2cc5-v43v-fh92/GHSA-2cc5-v43v-fh92.json b/advisories/unreviewed/2025/04/GHSA-2cc5-v43v-fh92/GHSA-2cc5-v43v-fh92.json new file mode 100644 index 00000000000..efec09fb4cd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cc5-v43v-fh92/GHSA-2cc5-v43v-fh92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cc5-v43v-fh92", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-1050" + ], + "details": "Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. \n\nThe specific flaw exists within the processing of HLS playlist data. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the anacapa user. Was ZDI-CAN-25606.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1050" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2cpg-xxmj-g6gp/GHSA-2cpg-xxmj-g6gp.json b/advisories/unreviewed/2025/04/GHSA-2cpg-xxmj-g6gp/GHSA-2cpg-xxmj-g6gp.json new file mode 100644 index 00000000000..8032444d139 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cpg-xxmj-g6gp/GHSA-2cpg-xxmj-g6gp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cpg-xxmj-g6gp", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-28020" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28020" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow3-1948e5e2b1a280c28ef5c6e54b49324d?pvs=73" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28020-BufferOverflow3-1948e5e2b1a280c28ef5c6e54b49324d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2j46-43q5-rfcp/GHSA-2j46-43q5-rfcp.json b/advisories/unreviewed/2025/04/GHSA-2j46-43q5-rfcp/GHSA-2j46-43q5-rfcp.json new file mode 100644 index 00000000000..22c322a83fa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2j46-43q5-rfcp/GHSA-2j46-43q5-rfcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j46-43q5-rfcp", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2771" + ], + "details": "BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2771" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2pwc-7gr8-9w97/GHSA-2pwc-7gr8-9w97.json b/advisories/unreviewed/2025/04/GHSA-2pwc-7gr8-9w97/GHSA-2pwc-7gr8-9w97.json new file mode 100644 index 00000000000..054fdb3c8b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2pwc-7gr8-9w97/GHSA-2pwc-7gr8-9w97.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pwc-7gr8-9w97", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2765" + ], + "details": "CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the configuration of the wireless hotspot. The issue results from the use of hard-coded credentials. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-24349.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2765" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-35q6-wq6r-22f5/GHSA-35q6-wq6r-22f5.json b/advisories/unreviewed/2025/04/GHSA-35q6-wq6r-22f5/GHSA-35q6-wq6r-22f5.json new file mode 100644 index 00000000000..3ca4d1ad6a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35q6-wq6r-22f5/GHSA-35q6-wq6r-22f5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35q6-wq6r-22f5", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-28018" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28018" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow2-1948e5e2b1a28070a8d1d1ba725febff" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json b/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json index 5e15fac5aa9..e1bbf50fc36 100644 --- a/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json +++ b/advisories/unreviewed/2025/04/GHSA-3x28-h2m6-h5pv/GHSA-3x28-h2m6-h5pv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4hvh-76hf-pj59/GHSA-4hvh-76hf-pj59.json b/advisories/unreviewed/2025/04/GHSA-4hvh-76hf-pj59/GHSA-4hvh-76hf-pj59.json new file mode 100644 index 00000000000..d6912107946 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4hvh-76hf-pj59/GHSA-4hvh-76hf-pj59.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hvh-76hf-pj59", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-1046" + ], + "details": "Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23646.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1046" + }, + { + "type": "WEB", + "url": "https://download.keyshot.com/cert/ksa-113962/ksa-113962.pdf?version=1.0&_gl=1*1x6i3a*_gcl_au*MTU0ODMwNDI4Ny4xNzQzNTUyMjcx" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4vrp-pmwp-p4h4/GHSA-4vrp-pmwp-p4h4.json b/advisories/unreviewed/2025/04/GHSA-4vrp-pmwp-p4h4/GHSA-4vrp-pmwp-p4h4.json new file mode 100644 index 00000000000..735f9afbbd2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4vrp-pmwp-p4h4/GHSA-4vrp-pmwp-p4h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vrp-pmwp-p4h4", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2770" + ], + "details": "BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the web-based user interface. The issue results from storing credentials in a recoverable format. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25986.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2770" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-55cg-p3v8-2vr3/GHSA-55cg-p3v8-2vr3.json b/advisories/unreviewed/2025/04/GHSA-55cg-p3v8-2vr3/GHSA-55cg-p3v8-2vr3.json new file mode 100644 index 00000000000..f3dfe00a6ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-55cg-p3v8-2vr3/GHSA-55cg-p3v8-2vr3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55cg-p3v8-2vr3", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-1522" + ], + "details": "PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PostHog. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the database_schema method. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this vulnerability to disclose information in the context of the service account. Was ZDI-CAN-25358.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1522" + }, + { + "type": "WEB", + "url": "https://github.com/PostHog/posthog/commit/3732c0fd9551ed29521b58611bf1e44d918c1032" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5c9p-fhrc-7hw4/GHSA-5c9p-fhrc-7hw4.json b/advisories/unreviewed/2025/04/GHSA-5c9p-fhrc-7hw4/GHSA-5c9p-fhrc-7hw4.json new file mode 100644 index 00000000000..5c1f7bfc1be --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5c9p-fhrc-7hw4/GHSA-5c9p-fhrc-7hw4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c9p-fhrc-7hw4", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-3903" + ], + "details": "Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3903" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-044" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5m6v-fcw2-pgcq/GHSA-5m6v-fcw2-pgcq.json b/advisories/unreviewed/2025/04/GHSA-5m6v-fcw2-pgcq/GHSA-5m6v-fcw2-pgcq.json new file mode 100644 index 00000000000..fb89a44491d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5m6v-fcw2-pgcq/GHSA-5m6v-fcw2-pgcq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m6v-fcw2-pgcq", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2762" + ], + "details": "CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of CarlinKit CPC200-CCPA devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the configuration of the application system-on-chip (SoC). The issue results from the lack of a properly configured hardware root of trust. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the boot process. Was ZDI-CAN-25948.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2762" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-176" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1326" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5rg9-mgvq-2fqh/GHSA-5rg9-mgvq-2fqh.json b/advisories/unreviewed/2025/04/GHSA-5rg9-mgvq-2fqh/GHSA-5rg9-mgvq-2fqh.json index 051b238e59b..64b8d9d8875 100644 --- a/advisories/unreviewed/2025/04/GHSA-5rg9-mgvq-2fqh/GHSA-5rg9-mgvq-2fqh.json +++ b/advisories/unreviewed/2025/04/GHSA-5rg9-mgvq-2fqh/GHSA-5rg9-mgvq-2fqh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5rww-hpvh-w7p4/GHSA-5rww-hpvh-w7p4.json b/advisories/unreviewed/2025/04/GHSA-5rww-hpvh-w7p4/GHSA-5rww-hpvh-w7p4.json new file mode 100644 index 00000000000..bfe5b0a1c38 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5rww-hpvh-w7p4/GHSA-5rww-hpvh-w7p4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rww-hpvh-w7p4", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-3907" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3907" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-777m-jvh5-prpj/GHSA-777m-jvh5-prpj.json b/advisories/unreviewed/2025/04/GHSA-777m-jvh5-prpj/GHSA-777m-jvh5-prpj.json new file mode 100644 index 00000000000..e000c50e91b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-777m-jvh5-prpj/GHSA-777m-jvh5-prpj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-777m-jvh5-prpj", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-3901" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3901" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7gwg-2mr3-xhpm/GHSA-7gwg-2mr3-xhpm.json b/advisories/unreviewed/2025/04/GHSA-7gwg-2mr3-xhpm/GHSA-7gwg-2mr3-xhpm.json new file mode 100644 index 00000000000..8574da9afe0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7gwg-2mr3-xhpm/GHSA-7gwg-2mr3-xhpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gwg-2mr3-xhpm", + "modified": "2025-04-23T18:30:56Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-43014" + ], + "details": "In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43014" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json b/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json index 84bf48583c9..aae59cb8926 100644 --- a/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json +++ b/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7rrr-jvfx-w2gc", - "modified": "2025-04-11T15:32:29Z", + "modified": "2025-04-23T18:30:56Z", "published": "2025-04-11T15:32:29Z", "aliases": [ "CVE-2025-3422" diff --git a/advisories/unreviewed/2025/04/GHSA-7xp4-3vq7-9563/GHSA-7xp4-3vq7-9563.json b/advisories/unreviewed/2025/04/GHSA-7xp4-3vq7-9563/GHSA-7xp4-3vq7-9563.json new file mode 100644 index 00000000000..4b45b834ba6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7xp4-3vq7-9563/GHSA-7xp4-3vq7-9563.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xp4-3vq7-9563", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-29526" + ], + "details": "A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29526" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/15vZXyzddcOv61sFSb3Lf9Dg1rnZ9n3Q6ANoa82jzcNA/edit?usp=sharing" + }, + { + "type": "WEB", + "url": "https://gist.github.com/k4nt0r/6ee5bfe9215cb10a436a03c67cf908fd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8w5j-q5mj-5jpv/GHSA-8w5j-q5mj-5jpv.json b/advisories/unreviewed/2025/04/GHSA-8w5j-q5mj-5jpv/GHSA-8w5j-q5mj-5jpv.json new file mode 100644 index 00000000000..4533225e704 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8w5j-q5mj-5jpv/GHSA-8w5j-q5mj-5jpv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w5j-q5mj-5jpv", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-1521" + ], + "details": "PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PostHog. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the processing of the slack_incoming_webhook parameter. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-25352.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1521" + }, + { + "type": "WEB", + "url": "https://github.com/PostHog/posthog/commit/6e8f035f9acd339c5ba87ba6ea40fc1ab3053d42" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-096" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8xwr-7fm3-xp6f/GHSA-8xwr-7fm3-xp6f.json b/advisories/unreviewed/2025/04/GHSA-8xwr-7fm3-xp6f/GHSA-8xwr-7fm3-xp6f.json new file mode 100644 index 00000000000..7de6a15dc14 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8xwr-7fm3-xp6f/GHSA-8xwr-7fm3-xp6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xwr-7fm3-xp6f", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2768" + ], + "details": "Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25041.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2768" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-99gc-w2rj-vq34/GHSA-99gc-w2rj-vq34.json b/advisories/unreviewed/2025/04/GHSA-99gc-w2rj-vq34/GHSA-99gc-w2rj-vq34.json new file mode 100644 index 00000000000..60f443c45fa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-99gc-w2rj-vq34/GHSA-99gc-w2rj-vq34.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99gc-w2rj-vq34", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-28025" + ], + "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28025" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow1-19e8e5e2b1a280bfbe52ec9975287f77" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow1-19e8e5e2b1a280bfbe52ec9975287f77?pvs=73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9cm6-6m3f-x97h/GHSA-9cm6-6m3f-x97h.json b/advisories/unreviewed/2025/04/GHSA-9cm6-6m3f-x97h/GHSA-9cm6-6m3f-x97h.json new file mode 100644 index 00000000000..46d61098fbd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9cm6-6m3f-x97h/GHSA-9cm6-6m3f-x97h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cm6-6m3f-x97h", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-28017" + ], + "details": "TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28017" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28017-TOTOLINK-A800R-RCE-1938e5e2b1a280d696bbd25699fb5e97" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/TOTOLINK-A800R-RCE-1938e5e2b1a280d696bbd25699fb5e97" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json b/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json index c690f28194f..6aaeb3653c6 100644 --- a/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json +++ b/advisories/unreviewed/2025/04/GHSA-9g64-r942-fvmp/GHSA-9g64-r942-fvmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9g64-r942-fvmp", - "modified": "2025-04-18T18:31:23Z", + "modified": "2025-04-23T18:30:57Z", "published": "2025-04-18T18:31:23Z", "aliases": [ "CVE-2025-29953" ], "details": "Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client.\n\nThis issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious responses that may eventually cause arbitrary code execution on the client. Version 2.1.0 introduced a allow/denylist feature to restrict deserialization, but this feature could be bypassed.\n\nThe .NET team has deprecated the built-in .NET binary serialization feature starting with .NET 9 and suggests migrating away from binary serialization. The project is considering to follow suit and drop this part of the NMS API altogether.\n\nUsers are recommended to upgrade to version 2.1.1, which fixes the issue. We also recommend to migrate away from relying on .NET binary serialization as a hardening method for the future.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c8rp-3hj7-pr8f/GHSA-c8rp-3hj7-pr8f.json b/advisories/unreviewed/2025/04/GHSA-c8rp-3hj7-pr8f/GHSA-c8rp-3hj7-pr8f.json new file mode 100644 index 00000000000..8db9c58a1ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8rp-3hj7-pr8f/GHSA-c8rp-3hj7-pr8f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8rp-3hj7-pr8f", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-1045" + ], + "details": "Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of KSP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24586.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1045" + }, + { + "type": "WEB", + "url": "https://download.keyshot.com/cert/ksa-113962/ksa-113962.pdf?version=1.0&_gl=1*1x6i3a*_gcl_au*MTU0ODMwNDI4Ny4xNzQzNTUyMjcx" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfvj-xgjr-h478/GHSA-cfvj-xgjr-h478.json b/advisories/unreviewed/2025/04/GHSA-cfvj-xgjr-h478/GHSA-cfvj-xgjr-h478.json new file mode 100644 index 00000000000..471489af019 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cfvj-xgjr-h478/GHSA-cfvj-xgjr-h478.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfvj-xgjr-h478", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-3904" + ], + "details": "Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3904" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-045" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json b/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json index 55668b35803..186822e1368 100644 --- a/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json +++ b/advisories/unreviewed/2025/04/GHSA-fc67-q532-m8q4/GHSA-fc67-q532-m8q4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fc67-q532-m8q4", - "modified": "2025-04-23T15:30:57Z", + "modified": "2025-04-23T18:30:57Z", "published": "2025-04-23T15:30:57Z", "aliases": [ "CVE-2025-45427" ], "details": "In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-23T15:16:00Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fcqc-4825-4p6v/GHSA-fcqc-4825-4p6v.json b/advisories/unreviewed/2025/04/GHSA-fcqc-4825-4p6v/GHSA-fcqc-4825-4p6v.json index 3a3bb1f5d23..4f14c401e93 100644 --- a/advisories/unreviewed/2025/04/GHSA-fcqc-4825-4p6v/GHSA-fcqc-4825-4p6v.json +++ b/advisories/unreviewed/2025/04/GHSA-fcqc-4825-4p6v/GHSA-fcqc-4825-4p6v.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json b/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json new file mode 100644 index 00000000000..f1fd3270879 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvp7-w3vq-22p7", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-3900" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3900" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gfww-4w9g-j3mr/GHSA-gfww-4w9g-j3mr.json b/advisories/unreviewed/2025/04/GHSA-gfww-4w9g-j3mr/GHSA-gfww-4w9g-j3mr.json new file mode 100644 index 00000000000..4db661e7064 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gfww-4w9g-j3mr/GHSA-gfww-4w9g-j3mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfww-4w9g-j3mr", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2763" + ], + "details": "CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of update packages on USB drives. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24356.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2763" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gj4f-mppc-xjrp/GHSA-gj4f-mppc-xjrp.json b/advisories/unreviewed/2025/04/GHSA-gj4f-mppc-xjrp/GHSA-gj4f-mppc-xjrp.json new file mode 100644 index 00000000000..72e969e5935 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gj4f-mppc-xjrp/GHSA-gj4f-mppc-xjrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj4f-mppc-xjrp", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-1049" + ], + "details": "Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. \n\nThe specific flaw exists within the processing of ID3 data. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the anacapa user. Was ZDI-CAN-25601.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1049" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-224" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h5q7-f44m-25fc/GHSA-h5q7-f44m-25fc.json b/advisories/unreviewed/2025/04/GHSA-h5q7-f44m-25fc/GHSA-h5q7-f44m-25fc.json new file mode 100644 index 00000000000..c2b69efcdb3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h5q7-f44m-25fc/GHSA-h5q7-f44m-25fc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5q7-f44m-25fc", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-28022" + ], + "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28022" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow3-1948e5e2b1a280ec8061ed308b33b5bc?pvs=73" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28022-BufferOverflow3-1948e5e2b1a280ec8061ed308b33b5bc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h868-x49r-ph66/GHSA-h868-x49r-ph66.json b/advisories/unreviewed/2025/04/GHSA-h868-x49r-ph66/GHSA-h868-x49r-ph66.json new file mode 100644 index 00000000000..35db8dd668b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h868-x49r-ph66/GHSA-h868-x49r-ph66.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h868-x49r-ph66", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-1048" + ], + "details": "Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the processing of SMB data. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the anacapa user. Was ZDI-CAN-25535.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1048" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hp97-2rvx-p2ch/GHSA-hp97-2rvx-p2ch.json b/advisories/unreviewed/2025/04/GHSA-hp97-2rvx-p2ch/GHSA-hp97-2rvx-p2ch.json new file mode 100644 index 00000000000..4c76423e329 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hp97-2rvx-p2ch/GHSA-hp97-2rvx-p2ch.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp97-2rvx-p2ch", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-1047" + ], + "details": "Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of pvs files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23694.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1047" + }, + { + "type": "WEB", + "url": "https://download.keyshot.com/cert/ksa-113962/ksa-113962.pdf?version=1.0&_gl=1*1x6i3a*_gcl_au*MTU0ODMwNDI4Ny4xNzQzNTUyMjcx" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json b/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json index e7da12110a9..d6ddc210639 100644 --- a/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json +++ b/advisories/unreviewed/2025/04/GHSA-hv4h-276c-jjqx/GHSA-hv4h-276c-jjqx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json b/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json index cf2860ec889..5e5887076d9 100644 --- a/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json +++ b/advisories/unreviewed/2025/04/GHSA-jfvg-qm4p-473x/GHSA-jfvg-qm4p-473x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jghh-8mmw-259x/GHSA-jghh-8mmw-259x.json b/advisories/unreviewed/2025/04/GHSA-jghh-8mmw-259x/GHSA-jghh-8mmw-259x.json new file mode 100644 index 00000000000..0d1548edd09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jghh-8mmw-259x/GHSA-jghh-8mmw-259x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jghh-8mmw-259x", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-2773" + ], + "details": "BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.\n\nThe specific flaw exists within the management interface, which listens on TCP port 22 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-25903.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2773" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jgrp-8284-4crq/GHSA-jgrp-8284-4crq.json b/advisories/unreviewed/2025/04/GHSA-jgrp-8284-4crq/GHSA-jgrp-8284-4crq.json new file mode 100644 index 00000000000..21fa8352ae0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jgrp-8284-4crq/GHSA-jgrp-8284-4crq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgrp-8284-4crq", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-28019" + ], + "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28019" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow1-1948e5e2b1a280ad96efca529ecae658" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28019-BufferOverflow1-1948e5e2b1a280ad96efca529ecae658" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json b/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json index 5426c39f3a7..15c28b417f1 100644 --- a/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json +++ b/advisories/unreviewed/2025/04/GHSA-jqqv-g9pc-97qc/GHSA-jqqv-g9pc-97qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqqv-g9pc-97qc", - "modified": "2025-04-23T15:30:57Z", + "modified": "2025-04-23T18:30:57Z", "published": "2025-04-23T15:30:57Z", "aliases": [ "CVE-2025-45428" ], "details": "In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-23T15:16:00Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m4gg-j947-295m/GHSA-m4gg-j947-295m.json b/advisories/unreviewed/2025/04/GHSA-m4gg-j947-295m/GHSA-m4gg-j947-295m.json new file mode 100644 index 00000000000..bdd2412b9f1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m4gg-j947-295m/GHSA-m4gg-j947-295m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4gg-j947-295m", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-28021" + ], + "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 parameters", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28021" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow1-1948e5e2b1a280e8aa5ad87964c5cd3d?pvs=73" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28021-BufferOverflow1-1948e5e2b1a280e8aa5ad87964c5cd3d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mxxr-2fvg-xw43/GHSA-mxxr-2fvg-xw43.json b/advisories/unreviewed/2025/04/GHSA-mxxr-2fvg-xw43/GHSA-mxxr-2fvg-xw43.json new file mode 100644 index 00000000000..5e328cfa8bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mxxr-2fvg-xw43/GHSA-mxxr-2fvg-xw43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxxr-2fvg-xw43", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2764" + ], + "details": "CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.\n\nThe specific flaw exists within the handling of update packages provided to update.cgi. The issue results from the lack of proper verification of a cryptographic signature. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24355.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2764" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q89g-m3mc-fgwc/GHSA-q89g-m3mc-fgwc.json b/advisories/unreviewed/2025/04/GHSA-q89g-m3mc-fgwc/GHSA-q89g-m3mc-fgwc.json new file mode 100644 index 00000000000..471b5d6a301 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q89g-m3mc-fgwc/GHSA-q89g-m3mc-fgwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q89g-m3mc-fgwc", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2760" + ], + "details": "GIMP XWD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25082.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2760" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-203" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rj6h-c4q3-734p/GHSA-rj6h-c4q3-734p.json b/advisories/unreviewed/2025/04/GHSA-rj6h-c4q3-734p/GHSA-rj6h-c4q3-734p.json new file mode 100644 index 00000000000..b86cec63777 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rj6h-c4q3-734p/GHSA-rj6h-c4q3-734p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj6h-c4q3-734p", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-2772" + ], + "details": "BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within /cgi-bin/tools_usermanage.asp. The issue results from transmitting a list of users and their credentials to be handled on the client side. An attacker can leverage this vulnerability to disclose transported credentials, leading to further compromise. Was ZDI-CAN-25895.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2772" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rrv5-483w-xmr9/GHSA-rrv5-483w-xmr9.json b/advisories/unreviewed/2025/04/GHSA-rrv5-483w-xmr9/GHSA-rrv5-483w-xmr9.json new file mode 100644 index 00000000000..cccb407fde7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rrv5-483w-xmr9/GHSA-rrv5-483w-xmr9.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrv5-483w-xmr9", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2024-58251" + ], + "details": "In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58251" + }, + { + "type": "WEB", + "url": "https://bugs.busybox.net/show_bug.cgi?id=15922" + }, + { + "type": "WEB", + "url": "https://www.busybox.net" + }, + { + "type": "WEB", + "url": "https://www.busybox.net/downloads" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-150" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T18:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v484-6wmj-xwfq/GHSA-v484-6wmj-xwfq.json b/advisories/unreviewed/2025/04/GHSA-v484-6wmj-xwfq/GHSA-v484-6wmj-xwfq.json new file mode 100644 index 00000000000..cf8dc2143bb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v484-6wmj-xwfq/GHSA-v484-6wmj-xwfq.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v484-6wmj-xwfq", + "modified": "2025-04-23T18:31:00Z", + "published": "2025-04-23T18:31:00Z", + "aliases": [ + "CVE-2025-3902" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block Class: from 4.0.0 before 4.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3902" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v64v-fq96-c5wv/GHSA-v64v-fq96-c5wv.json b/advisories/unreviewed/2025/04/GHSA-v64v-fq96-c5wv/GHSA-v64v-fq96-c5wv.json new file mode 100644 index 00000000000..d105153ef1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v64v-fq96-c5wv/GHSA-v64v-fq96-c5wv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v64v-fq96-c5wv", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-1520" + ], + "details": "PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PostHog. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the SQL parser. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the database account. Was ZDI-CAN-25350.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1520" + }, + { + "type": "WEB", + "url": "https://github.com/PostHog/posthog/commit/6e8f035f9acd339c5ba87ba6ea40fc1ab3053d42" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-099" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vcjh-9r25-r392/GHSA-vcjh-9r25-r392.json b/advisories/unreviewed/2025/04/GHSA-vcjh-9r25-r392/GHSA-vcjh-9r25-r392.json new file mode 100644 index 00000000000..6e53d8d0ef3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vcjh-9r25-r392/GHSA-vcjh-9r25-r392.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcjh-9r25-r392", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2767" + ], + "details": "Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability.\n\nThe specific flaw exists within the processing of the User-Agent HTTP header. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24407.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2767" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-181" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vf42-fm5m-wqq9/GHSA-vf42-fm5m-wqq9.json b/advisories/unreviewed/2025/04/GHSA-vf42-fm5m-wqq9/GHSA-vf42-fm5m-wqq9.json new file mode 100644 index 00000000000..495746b70b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vf42-fm5m-wqq9/GHSA-vf42-fm5m-wqq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf42-fm5m-wqq9", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-45429" + ], + "details": "In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45429" + }, + { + "type": "WEB", + "url": "https://github.com/shuqi233/loophole/blob/main/Tenda%20AC9/WifiWpsStart-index.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vh6j-cr3m-vvfm/GHSA-vh6j-cr3m-vvfm.json b/advisories/unreviewed/2025/04/GHSA-vh6j-cr3m-vvfm/GHSA-vh6j-cr3m-vvfm.json new file mode 100644 index 00000000000..94135abc07a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vh6j-cr3m-vvfm/GHSA-vh6j-cr3m-vvfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh6j-cr3m-vvfm", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2769" + ], + "details": "Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25295.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2769" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-183" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json b/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json index f1260546735..dcb4d278474 100644 --- a/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json +++ b/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-1284" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json b/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json new file mode 100644 index 00000000000..4bf9864ff5a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp4q-9jq4-gv74", + "modified": "2025-04-23T18:30:57Z", + "published": "2025-04-23T18:30:57Z", + "aliases": [ + "CVE-2025-46394" + ], + "details": "In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46394" + }, + { + "type": "WEB", + "url": "https://bugs.busybox.net/show_bug.cgi?id=16018" + }, + { + "type": "WEB", + "url": "https://www.busybox.net" + }, + { + "type": "WEB", + "url": "https://www.busybox.net/downloads" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x4wh-mww5-5258/GHSA-x4wh-mww5-5258.json b/advisories/unreviewed/2025/04/GHSA-x4wh-mww5-5258/GHSA-x4wh-mww5-5258.json new file mode 100644 index 00000000000..2f3ac70c820 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x4wh-mww5-5258/GHSA-x4wh-mww5-5258.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4wh-mww5-5258", + "modified": "2025-04-23T18:30:58Z", + "published": "2025-04-23T18:30:58Z", + "aliases": [ + "CVE-2025-28028" + ], + "details": "TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v5 parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28028" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/BufferOverflow4-1948e5e2b1a280b9809af4db6f9e65d1" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2025-28028-BufferOverflow4-1948e5e2b1a280b9809af4db6f9e65d1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x72f-pwfg-wpx2/GHSA-x72f-pwfg-wpx2.json b/advisories/unreviewed/2025/04/GHSA-x72f-pwfg-wpx2/GHSA-x72f-pwfg-wpx2.json new file mode 100644 index 00000000000..e9cc739a238 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x72f-pwfg-wpx2/GHSA-x72f-pwfg-wpx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x72f-pwfg-wpx2", + "modified": "2025-04-23T18:30:59Z", + "published": "2025-04-23T18:30:59Z", + "aliases": [ + "CVE-2025-2761" + ], + "details": "GIMP FLI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of FLI files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25100.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2761" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-204" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-23T17:16:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json b/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json index fdcde1f67d2..dc5dcb1171f 100644 --- a/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json +++ b/advisories/unreviewed/2025/04/GHSA-x7cp-g8mq-6p3p/GHSA-x7cp-g8mq-6p3p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x7cp-g8mq-6p3p", - "modified": "2025-04-22T18:32:11Z", + "modified": "2025-04-23T18:30:57Z", "published": "2025-04-22T18:32:11Z", "aliases": [ "CVE-2025-28037" ], "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-22T16:15:45Z"