From 1b8170309052b4662676cc7f88c7540408914578 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Feb 2025 18:33:41 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pf6r-c2f8-xcp4.json | 1 + .../GHSA-28pv-xxcq-fr89.json | 1 + .../GHSA-74h5-c7r2-qfwr.json | 4 +- .../GHSA-gv4w-cvg2-4g88.json | 4 +- .../GHSA-hxx7-8jpf-2vg3.json | 4 +- .../GHSA-mg2c-gg6q-f5px.json | 4 +- .../GHSA-mq3m-hjx5-g783.json | 4 +- .../GHSA-q7g2-v5xx-cmxx.json | 4 +- .../GHSA-w4q6-hmcg-gwmg.json | 4 +- .../GHSA-wfw9-4xc8-gxcw.json | 4 +- .../GHSA-v2cg-42gp-pjqv.json | 4 +- .../GHSA-6xjf-hqcm-9g3f.json | 4 +- .../GHSA-h7pr-3fcx-999q.json | 7 ++-- .../GHSA-vhvm-hvvj-qf99.json | 4 +- .../GHSA-275c-3cvw-rvcg.json | 36 +++++++++++++++++ .../GHSA-2gg3-vm5q-jcq2.json | 36 +++++++++++++++++ .../GHSA-7q4p-93g6-4wf9.json | 40 +++++++++++++++++++ .../GHSA-7qjx-378m-p8hm.json | 40 +++++++++++++++++++ .../GHSA-7w44-cfph-xhh9.json | 3 +- .../GHSA-c28h-3w95-v6xg.json | 40 +++++++++++++++++++ .../GHSA-c52f-45m8-h2r6.json | 40 +++++++++++++++++++ .../GHSA-f9x4-234p-wh9g.json | 40 +++++++++++++++++++ .../GHSA-gc32-fmf5-c742.json | 40 +++++++++++++++++++ .../GHSA-gf8x-6jh7-3mjv.json | 40 +++++++++++++++++++ .../GHSA-hp9r-wcfh-72pr.json | 40 +++++++++++++++++++ .../GHSA-j4gm-mr6g-474q.json | 36 +++++++++++++++++ .../GHSA-m858-gm2f-6jcg.json | 2 +- .../GHSA-mq8h-f329-fxx2.json | 15 +++++-- .../GHSA-vq4p-pj29-ggrf.json | 2 +- .../GHSA-vxgr-vw7p-4h7x.json | 3 +- .../GHSA-w4pr-2hxh-45hj.json | 2 +- .../GHSA-wv34-xcj8-f3mq.json | 40 +++++++++++++++++++ .../GHSA-xvv5-5j36-r65h.json | 2 +- 33 files changed, 524 insertions(+), 26 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-275c-3cvw-rvcg/GHSA-275c-3cvw-rvcg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f9x4-234p-wh9g/GHSA-f9x4-234p-wh9g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json diff --git a/advisories/unreviewed/2022/08/GHSA-pf6r-c2f8-xcp4/GHSA-pf6r-c2f8-xcp4.json b/advisories/unreviewed/2022/08/GHSA-pf6r-c2f8-xcp4/GHSA-pf6r-c2f8-xcp4.json index 3733fc02a7e..37b62f16a93 100644 --- a/advisories/unreviewed/2022/08/GHSA-pf6r-c2f8-xcp4/GHSA-pf6r-c2f8-xcp4.json +++ b/advisories/unreviewed/2022/08/GHSA-pf6r-c2f8-xcp4/GHSA-pf6r-c2f8-xcp4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json b/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json index 8ae2402d428..e7bdc507a27 100644 --- a/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json +++ b/advisories/unreviewed/2023/03/GHSA-28pv-xxcq-fr89/GHSA-28pv-xxcq-fr89.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-125" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json b/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json index 222b069eb05..b666b69e12d 100644 --- a/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json +++ b/advisories/unreviewed/2023/03/GHSA-74h5-c7r2-qfwr/GHSA-74h5-c7r2-qfwr.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-gv4w-cvg2-4g88/GHSA-gv4w-cvg2-4g88.json b/advisories/unreviewed/2023/03/GHSA-gv4w-cvg2-4g88/GHSA-gv4w-cvg2-4g88.json index ff692c82a1a..07331dc7845 100644 --- a/advisories/unreviewed/2023/03/GHSA-gv4w-cvg2-4g88/GHSA-gv4w-cvg2-4g88.json +++ b/advisories/unreviewed/2023/03/GHSA-gv4w-cvg2-4g88/GHSA-gv4w-cvg2-4g88.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-610" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json b/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json index 086bead83f7..880beb474a6 100644 --- a/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json +++ b/advisories/unreviewed/2023/03/GHSA-hxx7-8jpf-2vg3/GHSA-hxx7-8jpf-2vg3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-926" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-mg2c-gg6q-f5px/GHSA-mg2c-gg6q-f5px.json b/advisories/unreviewed/2023/03/GHSA-mg2c-gg6q-f5px/GHSA-mg2c-gg6q-f5px.json index 02c82de3277..1367c9b0ce3 100644 --- a/advisories/unreviewed/2023/03/GHSA-mg2c-gg6q-f5px/GHSA-mg2c-gg6q-f5px.json +++ b/advisories/unreviewed/2023/03/GHSA-mg2c-gg6q-f5px/GHSA-mg2c-gg6q-f5px.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-mq3m-hjx5-g783/GHSA-mq3m-hjx5-g783.json b/advisories/unreviewed/2023/03/GHSA-mq3m-hjx5-g783/GHSA-mq3m-hjx5-g783.json index 2aa3b1c5584..f0e0f0e798a 100644 --- a/advisories/unreviewed/2023/03/GHSA-mq3m-hjx5-g783/GHSA-mq3m-hjx5-g783.json +++ b/advisories/unreviewed/2023/03/GHSA-mq3m-hjx5-g783/GHSA-mq3m-hjx5-g783.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-q7g2-v5xx-cmxx/GHSA-q7g2-v5xx-cmxx.json b/advisories/unreviewed/2023/03/GHSA-q7g2-v5xx-cmxx/GHSA-q7g2-v5xx-cmxx.json index c8b277d4d90..5ea5657f15f 100644 --- a/advisories/unreviewed/2023/03/GHSA-q7g2-v5xx-cmxx/GHSA-q7g2-v5xx-cmxx.json +++ b/advisories/unreviewed/2023/03/GHSA-q7g2-v5xx-cmxx/GHSA-q7g2-v5xx-cmxx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-703" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-w4q6-hmcg-gwmg/GHSA-w4q6-hmcg-gwmg.json b/advisories/unreviewed/2023/03/GHSA-w4q6-hmcg-gwmg/GHSA-w4q6-hmcg-gwmg.json index fd2d09a9a66..de487bf30c1 100644 --- a/advisories/unreviewed/2023/03/GHSA-w4q6-hmcg-gwmg/GHSA-w4q6-hmcg-gwmg.json +++ b/advisories/unreviewed/2023/03/GHSA-w4q6-hmcg-gwmg/GHSA-w4q6-hmcg-gwmg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json b/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json index 213ed17fae8..abf97559dd2 100644 --- a/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json +++ b/advisories/unreviewed/2023/03/GHSA-wfw9-4xc8-gxcw/GHSA-wfw9-4xc8-gxcw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-266" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json b/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json index 79a7a3cf22e..5aab51e9e2d 100644 --- a/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json +++ b/advisories/unreviewed/2023/04/GHSA-v2cg-42gp-pjqv/GHSA-v2cg-42gp-pjqv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-691" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json b/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json index df7e079df13..95a6362968a 100644 --- a/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json +++ b/advisories/unreviewed/2024/02/GHSA-6xjf-hqcm-9g3f/GHSA-6xjf-hqcm-9g3f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6xjf-hqcm-9g3f", - "modified": "2024-02-23T12:30:31Z", + "modified": "2025-02-25T18:31:18Z", "published": "2024-02-23T12:30:31Z", "aliases": [ "CVE-2024-25928" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json b/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json index 22500afe362..1b69e01338e 100644 --- a/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json +++ b/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h7pr-3fcx-999q", - "modified": "2024-03-06T03:30:29Z", + "modified": "2025-02-25T18:31:18Z", "published": "2024-03-06T03:30:29Z", "aliases": [ "CVE-2024-1220" ], - "details": "A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.\n\n", + "details": "A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-vhvm-hvvj-qf99/GHSA-vhvm-hvvj-qf99.json b/advisories/unreviewed/2024/05/GHSA-vhvm-hvvj-qf99/GHSA-vhvm-hvvj-qf99.json index 0d324704e93..f696338a0ef 100644 --- a/advisories/unreviewed/2024/05/GHSA-vhvm-hvvj-qf99/GHSA-vhvm-hvvj-qf99.json +++ b/advisories/unreviewed/2024/05/GHSA-vhvm-hvvj-qf99/GHSA-vhvm-hvvj-qf99.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vhvm-hvvj-qf99", - "modified": "2024-05-03T09:30:51Z", + "modified": "2025-02-25T18:31:18Z", "published": "2024-05-03T09:30:51Z", "aliases": [ "CVE-2024-28072" ], - "details": "A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. \n\n\n\n\n\n\n", + "details": "A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-275c-3cvw-rvcg/GHSA-275c-3cvw-rvcg.json b/advisories/unreviewed/2025/02/GHSA-275c-3cvw-rvcg/GHSA-275c-3cvw-rvcg.json new file mode 100644 index 00000000000..99a2c7fefd2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-275c-3cvw-rvcg/GHSA-275c-3cvw-rvcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-275c-3cvw-rvcg", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-1068" + ], + "details": "There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS AllSource, the file could execute and run malicious commands under the context of the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1068" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/administration/administration/arcgis-pro-and-arcgis-allsource-patches-address-high-severity-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json b/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json new file mode 100644 index 00000000000..7a39e71dbf8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gg3-vm5q-jcq2", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-1067" + ], + "details": "There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specific action using ArcGIS \n\nArcGIS Pro \n\n, the file could execute and run malicious commands under the context of the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1067" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/administration/administration/arcgis-pro-and-arcgis-allsource-patches-address-high-severity-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json new file mode 100644 index 00000000000..f7aaf0d1b13 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q4p-93g6-4wf9", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26600" + ], + "details": "A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26600" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26600" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json new file mode 100644 index 00000000000..592d78970ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qjx-378m-p8hm", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26597" + ], + "details": "A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26597" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26597" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345255" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7w44-cfph-xhh9/GHSA-7w44-cfph-xhh9.json b/advisories/unreviewed/2025/02/GHSA-7w44-cfph-xhh9/GHSA-7w44-cfph-xhh9.json index 76b9ac44002..133724da088 100644 --- a/advisories/unreviewed/2025/02/GHSA-7w44-cfph-xhh9/GHSA-7w44-cfph-xhh9.json +++ b/advisories/unreviewed/2025/02/GHSA-7w44-cfph-xhh9/GHSA-7w44-cfph-xhh9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-321" + "CWE-321", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json new file mode 100644 index 00000000000..e633a022d37 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c28h-3w95-v6xg", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26598" + ], + "details": "An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26598" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26598" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json new file mode 100644 index 00000000000..dca44159c4b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c52f-45m8-h2r6", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26596" + ], + "details": "A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26596" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26596" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345256" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f9x4-234p-wh9g/GHSA-f9x4-234p-wh9g.json b/advisories/unreviewed/2025/02/GHSA-f9x4-234p-wh9g/GHSA-f9x4-234p-wh9g.json new file mode 100644 index 00000000000..63abea926d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f9x4-234p-wh9g/GHSA-f9x4-234p-wh9g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9x4-234p-wh9g", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-1204" + ], + "details": "The \"update\" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function triggers if the 'C' button is pressed at a specific time during the boot process. If an attacker is able to control or impersonate this IP address, they could upload and overwrite files on the device.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1204" + }, + { + "type": "WEB", + "url": "https://claroty.com/team82/research/are-contec-cms8000-patient-monitors-infected-with-a-chinese-backdoor-the-reality-is-more-complicated?ref=vault33.org" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json new file mode 100644 index 00000000000..2edfd3c6500 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc32-fmf5-c742", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26594" + ], + "details": "A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26594" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26594" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345248" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json new file mode 100644 index 00000000000..a091fcc3191 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf8x-6jh7-3mjv", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26601" + ], + "details": "A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after-free when the alarm eventually triggers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26601" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26601" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json new file mode 100644 index 00000000000..c380f0c5953 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp9r-wcfh-72pr", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26595" + ], + "details": "A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26595" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26595" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345257" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json b/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json new file mode 100644 index 00000000000..5b7a413952c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j4gm-mr6g-474q/GHSA-j4gm-mr6g-474q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4gm-mr6g-474q", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2024-12368" + ], + "details": "Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12368" + }, + { + "type": "WEB", + "url": "https://github.com/odoo/odoo/issues/193854" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m858-gm2f-6jcg/GHSA-m858-gm2f-6jcg.json b/advisories/unreviewed/2025/02/GHSA-m858-gm2f-6jcg/GHSA-m858-gm2f-6jcg.json index 2231b0d466b..b26a8253f78 100644 --- a/advisories/unreviewed/2025/02/GHSA-m858-gm2f-6jcg/GHSA-m858-gm2f-6jcg.json +++ b/advisories/unreviewed/2025/02/GHSA-m858-gm2f-6jcg/GHSA-m858-gm2f-6jcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m858-gm2f-6jcg", - "modified": "2025-02-20T12:31:15Z", + "modified": "2025-02-25T18:31:23Z", "published": "2025-02-20T12:31:15Z", "aliases": [ "CVE-2025-1328" diff --git a/advisories/unreviewed/2025/02/GHSA-mq8h-f329-fxx2/GHSA-mq8h-f329-fxx2.json b/advisories/unreviewed/2025/02/GHSA-mq8h-f329-fxx2/GHSA-mq8h-f329-fxx2.json index 8468d355226..b9389600274 100644 --- a/advisories/unreviewed/2025/02/GHSA-mq8h-f329-fxx2/GHSA-mq8h-f329-fxx2.json +++ b/advisories/unreviewed/2025/02/GHSA-mq8h-f329-fxx2/GHSA-mq8h-f329-fxx2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mq8h-f329-fxx2", - "modified": "2025-02-24T09:35:48Z", + "modified": "2025-02-25T18:31:23Z", "published": "2025-02-24T09:35:48Z", "aliases": [ "CVE-2023-52926" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIORING_OP_READ did not correctly consume the provided buffer list when\nread i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return).\nThis can lead to a potential use-after-free when the completion via\nio_rw_done runs at separate context.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T09:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vq4p-pj29-ggrf/GHSA-vq4p-pj29-ggrf.json b/advisories/unreviewed/2025/02/GHSA-vq4p-pj29-ggrf/GHSA-vq4p-pj29-ggrf.json index 304cd94ee1c..e84714be917 100644 --- a/advisories/unreviewed/2025/02/GHSA-vq4p-pj29-ggrf/GHSA-vq4p-pj29-ggrf.json +++ b/advisories/unreviewed/2025/02/GHSA-vq4p-pj29-ggrf/GHSA-vq4p-pj29-ggrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vq4p-pj29-ggrf", - "modified": "2025-02-21T06:31:09Z", + "modified": "2025-02-25T18:31:23Z", "published": "2025-02-21T06:31:09Z", "aliases": [ "CVE-2024-13818" diff --git a/advisories/unreviewed/2025/02/GHSA-vxgr-vw7p-4h7x/GHSA-vxgr-vw7p-4h7x.json b/advisories/unreviewed/2025/02/GHSA-vxgr-vw7p-4h7x/GHSA-vxgr-vw7p-4h7x.json index 4e3d1b51554..a25c9fc5993 100644 --- a/advisories/unreviewed/2025/02/GHSA-vxgr-vw7p-4h7x/GHSA-vxgr-vw7p-4h7x.json +++ b/advisories/unreviewed/2025/02/GHSA-vxgr-vw7p-4h7x/GHSA-vxgr-vw7p-4h7x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-w4pr-2hxh-45hj/GHSA-w4pr-2hxh-45hj.json b/advisories/unreviewed/2025/02/GHSA-w4pr-2hxh-45hj/GHSA-w4pr-2hxh-45hj.json index abe43984b4a..d84299978e2 100644 --- a/advisories/unreviewed/2025/02/GHSA-w4pr-2hxh-45hj/GHSA-w4pr-2hxh-45hj.json +++ b/advisories/unreviewed/2025/02/GHSA-w4pr-2hxh-45hj/GHSA-w4pr-2hxh-45hj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4pr-2hxh-45hj", - "modified": "2025-02-20T12:31:15Z", + "modified": "2025-02-25T18:31:22Z", "published": "2025-02-20T12:31:15Z", "aliases": [ "CVE-2024-6432" diff --git a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json new file mode 100644 index 00000000000..2eb8b3b8dbb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv34-xcj8-f3mq", + "modified": "2025-02-25T18:31:24Z", + "published": "2025-02-25T18:31:24Z", + "aliases": [ + "CVE-2025-26599" + ], + "details": "An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26599" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26599" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345253" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xvv5-5j36-r65h/GHSA-xvv5-5j36-r65h.json b/advisories/unreviewed/2025/02/GHSA-xvv5-5j36-r65h/GHSA-xvv5-5j36-r65h.json index 6161630c149..92212d5097c 100644 --- a/advisories/unreviewed/2025/02/GHSA-xvv5-5j36-r65h/GHSA-xvv5-5j36-r65h.json +++ b/advisories/unreviewed/2025/02/GHSA-xvv5-5j36-r65h/GHSA-xvv5-5j36-r65h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvv5-5j36-r65h", - "modified": "2025-02-12T06:30:32Z", + "modified": "2025-02-25T18:31:21Z", "published": "2025-02-12T06:30:32Z", "aliases": [ "CVE-2024-11746"