From 1ae20bfe91f9ae624f3ae5afbd4abce6b017690d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 5 Feb 2025 00:32:57 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-98qh-xxww-5r96.json | 13 ++++-- .../GHSA-gwxh-45g8-xg45.json | 9 ++++- .../GHSA-xvh2-pw6x-f8hh.json | 13 ++++-- .../GHSA-23h9-xj7q-3m7r.json | 4 +- .../GHSA-6xj4-vchf-pfcc.json | 4 +- .../GHSA-7cw6-gq2v-qm88.json | 4 +- .../GHSA-86c2-r56g-p9g8.json | 4 +- .../GHSA-9cmh-qh3j-rrp8.json | 4 +- .../GHSA-c9hp-6vqm-w35v.json | 4 +- .../GHSA-fp5g-p2fh-5344.json | 4 +- .../GHSA-pgq2-vhv9-8pr9.json | 4 +- .../GHSA-xmpx-2mhf-xq2j.json | 4 +- .../GHSA-237v-gpwr-jc57.json | 39 ++++++++++++++++++ .../GHSA-3pgx-69pv-46wx.json | 15 +++++-- .../GHSA-3rm7-84wp-m4qh.json | 36 +++++++++++++++++ .../GHSA-7xvx-6q95-x86w.json | 29 ++++++++++++++ .../GHSA-9m2c-r2hc-7gcr.json | 38 ++++++++++++++++++ .../GHSA-9q34-cgj6-mc9j.json | 36 +++++++++++++++++ .../GHSA-c2c9-4ffg-xh97.json | 40 +++++++++++++++++++ .../GHSA-fq5r-22jj-7j7q.json | 36 +++++++++++++++++ .../GHSA-h7wc-p5w7-r3qj.json | 36 +++++++++++++++++ .../GHSA-jr3r-m6fm-vvg6.json | 40 +++++++++++++++++++ .../GHSA-m4hr-g8rp-8xv4.json | 38 ++++++++++++++++++ .../GHSA-rh8j-9cjq-pg53.json | 36 +++++++++++++++++ .../GHSA-vg5c-jm85-v84v.json | 39 ++++++++++++++++++ .../GHSA-w478-m9j9-whwq.json | 36 +++++++++++++++++ .../GHSA-wwfq-cq3f-8qx7.json | 40 +++++++++++++++++++ 27 files changed, 584 insertions(+), 21 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3rm7-84wp-m4qh/GHSA-3rm7-84wp-m4qh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9q34-cgj6-mc9j/GHSA-9q34-cgj6-mc9j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c2c9-4ffg-xh97/GHSA-c2c9-4ffg-xh97.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fq5r-22jj-7j7q/GHSA-fq5r-22jj-7j7q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h7wc-p5w7-r3qj/GHSA-h7wc-p5w7-r3qj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jr3r-m6fm-vvg6/GHSA-jr3r-m6fm-vvg6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m4hr-g8rp-8xv4/GHSA-m4hr-g8rp-8xv4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rh8j-9cjq-pg53/GHSA-rh8j-9cjq-pg53.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w478-m9j9-whwq/GHSA-w478-m9j9-whwq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wwfq-cq3f-8qx7/GHSA-wwfq-cq3f-8qx7.json diff --git a/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json b/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json index ec3b6fc477e..5e3b58578cc 100644 --- a/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json +++ b/advisories/unreviewed/2022/05/GHSA-98qh-xxww-5r96/GHSA-98qh-xxww-5r96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98qh-xxww-5r96", - "modified": "2022-05-24T17:22:56Z", + "modified": "2025-02-05T00:31:12Z", "published": "2022-05-24T17:22:56Z", "aliases": [ "CVE-2020-1040" ], "details": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-gwxh-45g8-xg45/GHSA-gwxh-45g8-xg45.json b/advisories/unreviewed/2022/05/GHSA-gwxh-45g8-xg45/GHSA-gwxh-45g8-xg45.json index c9390fa56db..f9a3e9ab36f 100644 --- a/advisories/unreviewed/2022/05/GHSA-gwxh-45g8-xg45/GHSA-gwxh-45g8-xg45.json +++ b/advisories/unreviewed/2022/05/GHSA-gwxh-45g8-xg45/GHSA-gwxh-45g8-xg45.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gwxh-45g8-xg45", - "modified": "2022-05-14T02:15:26Z", + "modified": "2025-02-05T00:31:09Z", "published": "2022-05-14T02:15:26Z", "aliases": [ "CVE-2012-0767" ], "details": "Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka \"Universal XSS (UXSS),\" as exploited in the wild in February 2012.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json b/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json index 4297a4c3b56..bb2fdd358bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json +++ b/advisories/unreviewed/2022/05/GHSA-xvh2-pw6x-f8hh/GHSA-xvh2-pw6x-f8hh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xvh2-pw6x-f8hh", - "modified": "2024-12-20T06:30:45Z", + "modified": "2025-02-05T00:31:09Z", "published": "2022-05-17T00:22:28Z", "aliases": [ "CVE-2012-4969" ], "details": "Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -60,7 +65,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json b/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json index eb762a7ca82..f13603dd468 100644 --- a/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json +++ b/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json b/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json index c79c255aaf7..20c73e0b992 100644 --- a/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json +++ b/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json b/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json index f7f7a49fc09..e8e8c5cde1e 100644 --- a/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json +++ b/advisories/unreviewed/2025/01/GHSA-7cw6-gq2v-qm88/GHSA-7cw6-gq2v-qm88.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json b/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json index 816631b869f..f6a818bd7c6 100644 --- a/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json +++ b/advisories/unreviewed/2025/01/GHSA-86c2-r56g-p9g8/GHSA-86c2-r56g-p9g8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json b/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json index 74ffdce196f..4ed91a841c7 100644 --- a/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json +++ b/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-754" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json b/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json index ec349bbfb9e..eb6d062e224 100644 --- a/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json +++ b/advisories/unreviewed/2025/01/GHSA-c9hp-6vqm-w35v/GHSA-c9hp-6vqm-w35v.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json b/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json index e26159c82d3..82a909aa334 100644 --- a/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json +++ b/advisories/unreviewed/2025/01/GHSA-fp5g-p2fh-5344/GHSA-fp5g-p2fh-5344.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json b/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json index cb72cf03c51..8d7821a7f97 100644 --- a/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json +++ b/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json b/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json index fd1f33c8cda..d29ddf246ff 100644 --- a/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json +++ b/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json b/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json new file mode 100644 index 00000000000..8d75eec10f2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-237v-gpwr-jc57", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-13722" + ], + "details": "The \"NagVis\" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13722" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werks?version=2.3.0p10" + }, + { + "type": "WEB", + "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-001.txt" + }, + { + "type": "WEB", + "url": "https://www.nagvis.org/downloads/changelog/1.9.42" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3pgx-69pv-46wx/GHSA-3pgx-69pv-46wx.json b/advisories/unreviewed/2025/02/GHSA-3pgx-69pv-46wx/GHSA-3pgx-69pv-46wx.json index ff8f414a847..e65b40e9c64 100644 --- a/advisories/unreviewed/2025/02/GHSA-3pgx-69pv-46wx/GHSA-3pgx-69pv-46wx.json +++ b/advisories/unreviewed/2025/02/GHSA-3pgx-69pv-46wx/GHSA-3pgx-69pv-46wx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3pgx-69pv-46wx", - "modified": "2025-02-04T15:31:36Z", + "modified": "2025-02-05T00:31:13Z", "published": "2025-02-04T15:31:36Z", "aliases": [ "CVE-2025-1013" ], "details": "A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3rm7-84wp-m4qh/GHSA-3rm7-84wp-m4qh.json b/advisories/unreviewed/2025/02/GHSA-3rm7-84wp-m4qh/GHSA-3rm7-84wp-m4qh.json new file mode 100644 index 00000000000..4df5a050b59 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3rm7-84wp-m4qh/GHSA-3rm7-84wp-m4qh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rm7-84wp-m4qh", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-53964" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53964" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T00:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json b/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json new file mode 100644 index 00000000000..f9c89476ec6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xvx-6q95-x86w", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-48445" + ], + "details": "An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48445" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/188996" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json b/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json new file mode 100644 index 00000000000..3e4ea1a1617 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m2c-r2hc-7gcr", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-11468" + ], + "details": "Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11468" + }, + { + "type": "WEB", + "url": "https://static.omnissa.com/sites/default/files/OMSA-2024-0002.pdf" + }, + { + "type": "WEB", + "url": "https://www.omnissa.com/omnissa-security-response" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9q34-cgj6-mc9j/GHSA-9q34-cgj6-mc9j.json b/advisories/unreviewed/2025/02/GHSA-9q34-cgj6-mc9j/GHSA-9q34-cgj6-mc9j.json new file mode 100644 index 00000000000..7031fc1424e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9q34-cgj6-mc9j/GHSA-9q34-cgj6-mc9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q34-cgj6-mc9j", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-53965" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated link or input data into a vulnerable page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53965" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T00:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c2c9-4ffg-xh97/GHSA-c2c9-4ffg-xh97.json b/advisories/unreviewed/2025/02/GHSA-c2c9-4ffg-xh97/GHSA-c2c9-4ffg-xh97.json new file mode 100644 index 00000000000..ae8e9fd9001 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c2c9-4ffg-xh97/GHSA-c2c9-4ffg-xh97.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2c9-4ffg-xh97", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2023-39943" + ], + "details": "In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39943" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fq5r-22jj-7j7q/GHSA-fq5r-22jj-7j7q.json b/advisories/unreviewed/2025/02/GHSA-fq5r-22jj-7j7q/GHSA-fq5r-22jj-7j7q.json new file mode 100644 index 00000000000..b363bf04b1e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fq5r-22jj-7j7q/GHSA-fq5r-22jj-7j7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq5r-22jj-7j7q", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-8125" + ], + "details": "Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. \n\nA bad actor with the required OpenText Content Management privileges (not root) could expose\nthe vulnerability to carry out a remote code execution attack on the target system.\n\nThis issue affects Content Management (Extended ECM): from 10.0 through 24.4 \n\n with WebReports module\ninstalled and enabled.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:H/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8125" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0834058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T22:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h7wc-p5w7-r3qj/GHSA-h7wc-p5w7-r3qj.json b/advisories/unreviewed/2025/02/GHSA-h7wc-p5w7-r3qj/GHSA-h7wc-p5w7-r3qj.json new file mode 100644 index 00000000000..25d319cb0b5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h7wc-p5w7-r3qj/GHSA-h7wc-p5w7-r3qj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7wc-p5w7-r3qj", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-53963" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated link or input data into a vulnerable page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53963" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T00:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jr3r-m6fm-vvg6/GHSA-jr3r-m6fm-vvg6.json b/advisories/unreviewed/2025/02/GHSA-jr3r-m6fm-vvg6/GHSA-jr3r-m6fm-vvg6.json new file mode 100644 index 00000000000..6d6c92968ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jr3r-m6fm-vvg6/GHSA-jr3r-m6fm-vvg6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr3r-m6fm-vvg6", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2023-40222" + ], + "details": "In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40222" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4hr-g8rp-8xv4/GHSA-m4hr-g8rp-8xv4.json b/advisories/unreviewed/2025/02/GHSA-m4hr-g8rp-8xv4/GHSA-m4hr-g8rp-8xv4.json new file mode 100644 index 00000000000..5f9abfe4a4c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4hr-g8rp-8xv4/GHSA-m4hr-g8rp-8xv4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4hr-g8rp-8xv4", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-11467" + ], + "details": "Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11467" + }, + { + "type": "WEB", + "url": "https://static.omnissa.com/sites/default/files/OMSA-2024-0002.pdf" + }, + { + "type": "WEB", + "url": "https://www.omnissa.com/omnissa-security-response" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rh8j-9cjq-pg53/GHSA-rh8j-9cjq-pg53.json b/advisories/unreviewed/2025/02/GHSA-rh8j-9cjq-pg53/GHSA-rh8j-9cjq-pg53.json new file mode 100644 index 00000000000..256b4cc9914 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rh8j-9cjq-pg53/GHSA-rh8j-9cjq-pg53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh8j-9cjq-pg53", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-53966" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53966" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T00:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json b/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json new file mode 100644 index 00000000000..3f1b1a988de --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg5c-jm85-v84v", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-13723" + ], + "details": "The \"NagVis\" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13723" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werks?version=2.3.0p10" + }, + { + "type": "WEB", + "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-002.txt" + }, + { + "type": "WEB", + "url": "https://www.nagvis.org/downloads/changelog/1.9.42" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w478-m9j9-whwq/GHSA-w478-m9j9-whwq.json b/advisories/unreviewed/2025/02/GHSA-w478-m9j9-whwq/GHSA-w478-m9j9-whwq.json new file mode 100644 index 00000000000..6991c1b7c2e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w478-m9j9-whwq/GHSA-w478-m9j9-whwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w478-m9j9-whwq", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2024-53962" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53962" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T00:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wwfq-cq3f-8qx7/GHSA-wwfq-cq3f-8qx7.json b/advisories/unreviewed/2025/02/GHSA-wwfq-cq3f-8qx7/GHSA-wwfq-cq3f-8qx7.json new file mode 100644 index 00000000000..13510c47d7e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wwfq-cq3f-8qx7/GHSA-wwfq-cq3f-8qx7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwfq-cq3f-8qx7", + "modified": "2025-02-05T00:31:13Z", + "published": "2025-02-05T00:31:13Z", + "aliases": [ + "CVE-2025-0413" + ], + "details": "Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. \nThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Technical Data Reporter component. By creating a symbolic link, an attacker can abuse the service to change the permissions of arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-25014.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0413" + }, + { + "type": "WEB", + "url": "https://kb.parallels.com/130212" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-082" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T00:15:28Z" + } +} \ No newline at end of file