diff --git a/advisories/unreviewed/2024/02/GHSA-3g6v-v5hj-c234/GHSA-3g6v-v5hj-c234.json b/advisories/unreviewed/2024/02/GHSA-3g6v-v5hj-c234/GHSA-3g6v-v5hj-c234.json index 2320e4949c3..fbc5e97c4e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-3g6v-v5hj-c234/GHSA-3g6v-v5hj-c234.json +++ b/advisories/unreviewed/2024/02/GHSA-3g6v-v5hj-c234/GHSA-3g6v-v5hj-c234.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g6v-v5hj-c234", - "modified": "2024-10-10T12:31:11Z", + "modified": "2025-02-21T15:31:54Z", "published": "2024-02-23T15:30:37Z", "aliases": [ "CVE-2024-26596" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/844f104790bd69c2e4dbb9ee3eba46fde1fcea7b" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e9953f5e4d6d11a9dad56fdee307bb923302809" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/dbd909c20c11f0d29c0054d41e0d1f668a60e8c8" diff --git a/advisories/unreviewed/2024/05/GHSA-4wx2-mhc4-vv9j/GHSA-4wx2-mhc4-vv9j.json b/advisories/unreviewed/2024/05/GHSA-4wx2-mhc4-vv9j/GHSA-4wx2-mhc4-vv9j.json index 1ac985c88de..a7fe8c0aa94 100644 --- a/advisories/unreviewed/2024/05/GHSA-4wx2-mhc4-vv9j/GHSA-4wx2-mhc4-vv9j.json +++ b/advisories/unreviewed/2024/05/GHSA-4wx2-mhc4-vv9j/GHSA-4wx2-mhc4-vv9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wx2-mhc4-vv9j", - "modified": "2024-05-16T00:32:02Z", + "modified": "2025-02-21T15:31:56Z", "published": "2024-05-16T00:32:02Z", "aliases": [ "CVE-2024-4917" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-59jh-6p6q-f5jr/GHSA-59jh-6p6q-f5jr.json b/advisories/unreviewed/2024/05/GHSA-59jh-6p6q-f5jr/GHSA-59jh-6p6q-f5jr.json index 4fe6e8c4878..4e21869f43e 100644 --- a/advisories/unreviewed/2024/05/GHSA-59jh-6p6q-f5jr/GHSA-59jh-6p6q-f5jr.json +++ b/advisories/unreviewed/2024/05/GHSA-59jh-6p6q-f5jr/GHSA-59jh-6p6q-f5jr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59jh-6p6q-f5jr", - "modified": "2024-05-16T00:32:02Z", + "modified": "2025-02-21T15:31:56Z", "published": "2024-05-16T00:32:02Z", "aliases": [ "CVE-2024-4914" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-6g8r-23r5-62g2/GHSA-6g8r-23r5-62g2.json b/advisories/unreviewed/2024/05/GHSA-6g8r-23r5-62g2/GHSA-6g8r-23r5-62g2.json index dec1a437fa6..3278af55eea 100644 --- a/advisories/unreviewed/2024/05/GHSA-6g8r-23r5-62g2/GHSA-6g8r-23r5-62g2.json +++ b/advisories/unreviewed/2024/05/GHSA-6g8r-23r5-62g2/GHSA-6g8r-23r5-62g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6g8r-23r5-62g2", - "modified": "2024-05-16T00:32:02Z", + "modified": "2025-02-21T15:31:57Z", "published": "2024-05-16T00:32:02Z", "aliases": [ "CVE-2024-4918" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-926q-c6xf-358g/GHSA-926q-c6xf-358g.json b/advisories/unreviewed/2024/05/GHSA-926q-c6xf-358g/GHSA-926q-c6xf-358g.json index 30d70510c52..37a1981a58f 100644 --- a/advisories/unreviewed/2024/05/GHSA-926q-c6xf-358g/GHSA-926q-c6xf-358g.json +++ b/advisories/unreviewed/2024/05/GHSA-926q-c6xf-358g/GHSA-926q-c6xf-358g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-926q-c6xf-358g", - "modified": "2024-05-16T00:32:02Z", + "modified": "2025-02-21T15:31:56Z", "published": "2024-05-16T00:32:02Z", "aliases": [ "CVE-2024-4916" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-m78g-6w88-h522/GHSA-m78g-6w88-h522.json b/advisories/unreviewed/2024/05/GHSA-m78g-6w88-h522/GHSA-m78g-6w88-h522.json index 6dab75f39a9..0b7cf758dac 100644 --- a/advisories/unreviewed/2024/05/GHSA-m78g-6w88-h522/GHSA-m78g-6w88-h522.json +++ b/advisories/unreviewed/2024/05/GHSA-m78g-6w88-h522/GHSA-m78g-6w88-h522.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m78g-6w88-h522", - "modified": "2024-05-15T21:31:26Z", + "modified": "2025-02-21T15:31:56Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4912" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-rmq9-5xx5-hhgg/GHSA-rmq9-5xx5-hhgg.json b/advisories/unreviewed/2024/05/GHSA-rmq9-5xx5-hhgg/GHSA-rmq9-5xx5-hhgg.json index d8e04d4c5bf..3cf2fb2c135 100644 --- a/advisories/unreviewed/2024/05/GHSA-rmq9-5xx5-hhgg/GHSA-rmq9-5xx5-hhgg.json +++ b/advisories/unreviewed/2024/05/GHSA-rmq9-5xx5-hhgg/GHSA-rmq9-5xx5-hhgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rmq9-5xx5-hhgg", - "modified": "2024-05-15T21:31:26Z", + "modified": "2025-02-21T15:31:56Z", "published": "2024-05-15T21:31:26Z", "aliases": [ "CVE-2024-4913" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-wfg8-26x9-33j6/GHSA-wfg8-26x9-33j6.json b/advisories/unreviewed/2024/05/GHSA-wfg8-26x9-33j6/GHSA-wfg8-26x9-33j6.json index 3a6329b0ab4..e88b3fc035f 100644 --- a/advisories/unreviewed/2024/05/GHSA-wfg8-26x9-33j6/GHSA-wfg8-26x9-33j6.json +++ b/advisories/unreviewed/2024/05/GHSA-wfg8-26x9-33j6/GHSA-wfg8-26x9-33j6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfg8-26x9-33j6", - "modified": "2024-05-16T00:32:02Z", + "modified": "2025-02-21T15:31:56Z", "published": "2024-05-16T00:32:02Z", "aliases": [ "CVE-2024-4915" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/07/GHSA-fh5c-w77m-vmmm/GHSA-fh5c-w77m-vmmm.json b/advisories/unreviewed/2024/07/GHSA-fh5c-w77m-vmmm/GHSA-fh5c-w77m-vmmm.json index 7bb39980e76..da144b3fe84 100644 --- a/advisories/unreviewed/2024/07/GHSA-fh5c-w77m-vmmm/GHSA-fh5c-w77m-vmmm.json +++ b/advisories/unreviewed/2024/07/GHSA-fh5c-w77m-vmmm/GHSA-fh5c-w77m-vmmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fh5c-w77m-vmmm", - "modified": "2025-02-03T18:30:37Z", + "modified": "2025-02-21T15:31:57Z", "published": "2024-07-12T15:31:28Z", "aliases": [ "CVE-2024-40945" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/61a96da9649a6b6a1a5d5bde9374b045fdb5c12e" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6325eab6c108fed27f60ff51852e3eac0ba23f3f" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/700f564758882db7c039dfba9443fe762561a3f8" diff --git a/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json b/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json index f79cd9ac1d9..de3f110c011 100644 --- a/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json +++ b/advisories/unreviewed/2024/07/GHSA-hq79-5p4q-xv2w/GHSA-hq79-5p4q-xv2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq79-5p4q-xv2w", - "modified": "2024-12-09T15:31:32Z", + "modified": "2025-02-21T15:31:57Z", "published": "2024-07-30T09:31:52Z", "aliases": [ "CVE-2024-42122" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/062edd612fcd300f0f79a36fca5b8b6a5e2fce70" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/552e7938b4d7fe548fbf29b9950a14c6149d0470" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8e65a1b7118acf6af96449e1e66b7adbc9396912" diff --git a/advisories/unreviewed/2024/10/GHSA-4p5q-rg67-69xg/GHSA-4p5q-rg67-69xg.json b/advisories/unreviewed/2024/10/GHSA-4p5q-rg67-69xg/GHSA-4p5q-rg67-69xg.json index 5caf47fbda0..93f097f5f8d 100644 --- a/advisories/unreviewed/2024/10/GHSA-4p5q-rg67-69xg/GHSA-4p5q-rg67-69xg.json +++ b/advisories/unreviewed/2024/10/GHSA-4p5q-rg67-69xg/GHSA-4p5q-rg67-69xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p5q-rg67-69xg", - "modified": "2024-10-24T00:33:36Z", + "modified": "2025-02-21T15:31:58Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50061" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50061" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a21bad9964c91b34d65ba269914233720c0b1ce" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/609366e7a06d035990df78f1562291c3bf0d4a12" diff --git a/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json b/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json index 64e135578f2..20f7a41aa39 100644 --- a/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json +++ b/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6ppv-9jp4-gprm", - "modified": "2024-10-24T21:31:02Z", + "modified": "2025-02-21T15:31:57Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49923" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49923" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39a580cd15397e102aaec25986ae5acf492f8930" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5559598742fb4538e4c51c48ef70563c49c2af23" diff --git a/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json b/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json index 27217623cfe..37f9f87c931 100644 --- a/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json +++ b/advisories/unreviewed/2024/10/GHSA-g6j9-66rq-g4jr/GHSA-g6j9-66rq-g4jr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g6j9-66rq-g4jr", - "modified": "2024-10-30T18:30:48Z", + "modified": "2025-02-21T15:31:58Z", "published": "2024-10-29T03:31:06Z", "aliases": [ "CVE-2024-50070" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3b36bb1fca2b87f6292ca2a8593f297c5e9fab41" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8d52de0a6c6b091b2771bcb98ce408cf9d69fe3" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b0f0e3f0552a566def55c844b0d44250c58e4df6" diff --git a/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json b/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json index 8e07b7b0b14..89c64f0229b 100644 --- a/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json +++ b/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jmxw-f4w9-294j", - "modified": "2024-10-25T21:31:26Z", + "modified": "2025-02-21T15:31:58Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49989" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/cf6f3ebd6312d465fee096d1f58089b177c7c67f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df948b5ba6858d5da34f622d408e5517057cec07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-m3v4-26gh-289c/GHSA-m3v4-26gh-289c.json b/advisories/unreviewed/2024/10/GHSA-m3v4-26gh-289c/GHSA-m3v4-26gh-289c.json index fe85eb2b98c..d660dda4c71 100644 --- a/advisories/unreviewed/2024/10/GHSA-m3v4-26gh-289c/GHSA-m3v4-26gh-289c.json +++ b/advisories/unreviewed/2024/10/GHSA-m3v4-26gh-289c/GHSA-m3v4-26gh-289c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3v4-26gh-289c", - "modified": "2025-01-09T18:32:12Z", + "modified": "2025-02-21T15:31:57Z", "published": "2024-10-21T15:32:26Z", "aliases": [ "CVE-2024-47726" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/e3db757ff9b7101ae68650ac5f6dd5743b68164e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f81302decd64245bb1bd154ecae0f65a9ee21f04" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json b/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json index eb965079904..d44d3f2643a 100644 --- a/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json +++ b/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wh99-hh68-w2m5", - "modified": "2024-10-25T15:31:25Z", + "modified": "2025-02-21T15:31:57Z", "published": "2024-10-21T18:30:57Z", "aliases": [ "CVE-2024-49919" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49919" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16ce8fd94da8599bb6f0496895d392a69aead1c0" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/390d757621f5f35d11a63ed7d9d3262ead240064" diff --git a/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json b/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json index 56dfa2e674a..687b25cb005 100644 --- a/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json +++ b/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm4v-3pg5-6f5c", - "modified": "2025-02-17T12:30:30Z", + "modified": "2025-02-21T15:31:58Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56549" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/9582c7664103c9043e80a78f5c382aa6bdd67418" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6bba3ece960129a553d4b16f1b00c884dc0993a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f98770440c9bc468e2fd878212ec9526dbe08293" diff --git a/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json b/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json index 62a931cda77..bfafa5eafe9 100644 --- a/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json +++ b/advisories/unreviewed/2025/01/GHSA-5fwx-95cc-hcxv/GHSA-5fwx-95cc-hcxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5fwx-95cc-hcxv", - "modified": "2025-01-14T18:32:01Z", + "modified": "2025-02-21T15:31:59Z", "published": "2025-01-14T18:32:01Z", "aliases": [ "CVE-2024-13161" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json b/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json index ef551e7ac86..530df000467 100644 --- a/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json +++ b/advisories/unreviewed/2025/01/GHSA-6v62-48r8-7wh2/GHSA-6v62-48r8-7wh2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v62-48r8-7wh2", - "modified": "2025-01-14T18:32:01Z", + "modified": "2025-02-21T15:31:58Z", "published": "2025-01-14T18:32:01Z", "aliases": [ "CVE-2024-13159" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json b/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json index 1cf5f221f90..ed7f4958300 100644 --- a/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json +++ b/advisories/unreviewed/2025/01/GHSA-c5xq-93hx-p95r/GHSA-c5xq-93hx-p95r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5xq-93hx-p95r", - "modified": "2025-01-14T18:31:59Z", + "modified": "2025-02-21T15:31:58Z", "published": "2025-01-14T18:31:59Z", "aliases": [ "CVE-2024-10811" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json b/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json index c98b2fc9e52..608adbd17e1 100644 --- a/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json +++ b/advisories/unreviewed/2025/01/GHSA-cfw8-99m9-5qfm/GHSA-cfw8-99m9-5qfm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfw8-99m9-5qfm", - "modified": "2025-01-14T18:32:01Z", + "modified": "2025-02-21T15:31:59Z", "published": "2025-01-14T18:32:01Z", "aliases": [ "CVE-2024-13160" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json b/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json index 41f292de9fd..a1c92c268f7 100644 --- a/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json +++ b/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-268v-p5rc-rhmv", - "modified": "2025-02-13T15:31:27Z", + "modified": "2025-02-21T15:32:00Z", "published": "2025-02-13T15:31:27Z", "aliases": [ "CVE-2025-21701" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/4dc880245f9b529fa8f476b5553c799d2848b47b" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1cb37a31a482df3dd35a6ac166282dac47664f4" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b382ab9b885cbb665e0e70a727f101c981b4edf3" diff --git a/advisories/unreviewed/2025/02/GHSA-33h8-vfvx-rpgx/GHSA-33h8-vfvx-rpgx.json b/advisories/unreviewed/2025/02/GHSA-33h8-vfvx-rpgx/GHSA-33h8-vfvx-rpgx.json new file mode 100644 index 00000000000..74c9e5d9a04 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-33h8-vfvx-rpgx/GHSA-33h8-vfvx-rpgx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33h8-vfvx-rpgx", + "modified": "2025-02-21T15:32:03Z", + "published": "2025-02-21T15:32:03Z", + "aliases": [ + "CVE-2024-10222" + ], + "details": "The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to upload SVG files can be extended to authors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10222" + }, + { + "type": "WEB", + "url": "https://github.com/benbodhi/svg-support/commit/eee3e13b650511c9cc9ee0746be485d031c7c072" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3244181" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/svg-support/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5852f08d-0506-464e-afd1-c625e4034e1d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4h72-f3hc-p28v/GHSA-4h72-f3hc-p28v.json b/advisories/unreviewed/2025/02/GHSA-4h72-f3hc-p28v/GHSA-4h72-f3hc-p28v.json index c1e0da1d0ce..2ed05262e29 100644 --- a/advisories/unreviewed/2025/02/GHSA-4h72-f3hc-p28v/GHSA-4h72-f3hc-p28v.json +++ b/advisories/unreviewed/2025/02/GHSA-4h72-f3hc-p28v/GHSA-4h72-f3hc-p28v.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4h72-f3hc-p28v", - "modified": "2025-02-18T12:31:17Z", + "modified": "2025-02-21T15:32:02Z", "published": "2025-02-18T12:31:17Z", "aliases": [ "CVE-2025-1023" ], "details": "A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json b/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json new file mode 100644 index 00000000000..c175c643899 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-52g7-964p-h422/GHSA-52g7-964p-h422.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52g7-964p-h422", + "modified": "2025-02-21T15:32:03Z", + "published": "2025-02-21T15:32:03Z", + "aliases": [ + "CVE-2025-1538" + ], + "details": "A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1538" + }, + { + "type": "WEB", + "url": "https://legacy.us.dlink.com/pages/product.aspx?id=4b2bbe2e3f1d440ea65bc56c7e3dcc5c" + }, + { + "type": "WEB", + "url": "https://tasty-foxtrot-3a8.notion.site/D-link-DAP-1320-set_ws_action-Vulnerability-1950448e61958049be3cc606d434bc9d" + }, + { + "type": "WEB", + "url": "https://tasty-foxtrot-3a8.notion.site/D-link-DAP-1320-set_ws_action-Vulnerability-1950448e61958049be3cc606d434bc9d?pvs=74" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296479" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296479" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497301" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json b/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json new file mode 100644 index 00000000000..68945a28422 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57q4-cgqr-6cw7", + "modified": "2025-02-21T15:32:03Z", + "published": "2025-02-21T15:32:03Z", + "aliases": [ + "CVE-2020-6158" + ], + "details": "Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user into providing sensitive data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-6158" + }, + { + "type": "WEB", + "url": "https://security.opera.com/en/address-bar-spoofing-in-opera-mini-for-android-opera-security-advisories" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json b/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json index 49dcdc791dd..83fc8198e65 100644 --- a/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json +++ b/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6j8j-86h8-528v", - "modified": "2025-02-18T21:32:46Z", + "modified": "2025-02-21T15:32:00Z", "published": "2025-02-15T09:30:29Z", "aliases": [ "CVE-2025-22208" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22208" }, + { + "type": "WEB", + "url": "https://github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-22208" + }, { "type": "WEB", "url": "https://joomsky.com/js-jobs-joomla" diff --git a/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json b/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json index e5b16831778..33ab5c51a1e 100644 --- a/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json +++ b/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-846x-232r-8564", - "modified": "2025-02-20T18:31:24Z", + "modified": "2025-02-21T15:32:02Z", "published": "2025-02-20T18:31:24Z", "aliases": [ "CVE-2025-26307" ], "details": "A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T17:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-8fvq-rgm5-cff9/GHSA-8fvq-rgm5-cff9.json b/advisories/unreviewed/2025/02/GHSA-8fvq-rgm5-cff9/GHSA-8fvq-rgm5-cff9.json index 23d66268991..82ea4b57ccf 100644 --- a/advisories/unreviewed/2025/02/GHSA-8fvq-rgm5-cff9/GHSA-8fvq-rgm5-cff9.json +++ b/advisories/unreviewed/2025/02/GHSA-8fvq-rgm5-cff9/GHSA-8fvq-rgm5-cff9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8fvq-rgm5-cff9", - "modified": "2025-02-19T09:33:27Z", + "modified": "2025-02-21T15:32:01Z", "published": "2025-02-18T12:31:17Z", "aliases": [ "CVE-2025-0981" ], "details": "A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-94x8-gvq5-m85g/GHSA-94x8-gvq5-m85g.json b/advisories/unreviewed/2025/02/GHSA-94x8-gvq5-m85g/GHSA-94x8-gvq5-m85g.json index cc45bab20dd..503d9d8188b 100644 --- a/advisories/unreviewed/2025/02/GHSA-94x8-gvq5-m85g/GHSA-94x8-gvq5-m85g.json +++ b/advisories/unreviewed/2025/02/GHSA-94x8-gvq5-m85g/GHSA-94x8-gvq5-m85g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94x8-gvq5-m85g", - "modified": "2025-02-18T12:31:17Z", + "modified": "2025-02-21T15:32:01Z", "published": "2025-02-18T12:31:17Z", "aliases": [ "CVE-2024-13369" diff --git a/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json b/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json index e699f0c839f..a0d299df454 100644 --- a/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json +++ b/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9v7f-8fcp-rxqx", - "modified": "2025-02-18T21:32:46Z", + "modified": "2025-02-21T15:32:00Z", "published": "2025-02-15T09:30:29Z", "aliases": [ "CVE-2025-22209" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22209" }, + { + "type": "WEB", + "url": "https://github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-22209" + }, { "type": "WEB", "url": "https://joomsky.com/js-jobs-joomla" diff --git a/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json b/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json index e94c13b2b1d..786ab083c08 100644 --- a/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json +++ b/advisories/unreviewed/2025/02/GHSA-cg86-m5xc-jqrm/GHSA-cg86-m5xc-jqrm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg86-m5xc-jqrm", - "modified": "2025-02-18T18:33:21Z", + "modified": "2025-02-21T15:32:02Z", "published": "2025-02-18T15:31:09Z", "aliases": [ "CVE-2025-21703" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/638ba5089324796c2ee49af10427459c2de35f71" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b79ca9a1de6a428d486ff52fb3d602321c08f55" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/839ecc583fa00fab785fde1c85a326743657fd32" diff --git a/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json b/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json index 5d3f8e35f25..6a692c796fd 100644 --- a/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json +++ b/advisories/unreviewed/2025/02/GHSA-j3qr-8f3v-fgjj/GHSA-j3qr-8f3v-fgjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j3qr-8f3v-fgjj", - "modified": "2025-02-10T18:30:47Z", + "modified": "2025-02-21T15:31:59Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-12133" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://gitlab.com/gnutls/libtasn1/-/issues/52" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/02/06/6" diff --git a/advisories/unreviewed/2025/02/GHSA-m3vc-g23p-w9p4/GHSA-m3vc-g23p-w9p4.json b/advisories/unreviewed/2025/02/GHSA-m3vc-g23p-w9p4/GHSA-m3vc-g23p-w9p4.json new file mode 100644 index 00000000000..4441510e80f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m3vc-g23p-w9p4/GHSA-m3vc-g23p-w9p4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3vc-g23p-w9p4", + "modified": "2025-02-21T15:32:03Z", + "published": "2025-02-21T15:32:03Z", + "aliases": [ + "CVE-2025-1536" + ], + "details": "A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1536" + }, + { + "type": "WEB", + "url": "https://github.com/koishi0x01/CVE/blob/main/CVE_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296476" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296476" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json b/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json index da04cc8fafa..d8c06e63d7a 100644 --- a/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json +++ b/advisories/unreviewed/2025/02/GHSA-m4w5-f9xf-8fgr/GHSA-m4w5-f9xf-8fgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4w5-f9xf-8fgr", - "modified": "2025-02-11T18:31:33Z", + "modified": "2025-02-21T15:31:59Z", "published": "2025-02-09T12:30:53Z", "aliases": [ "CVE-2025-21684" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/b0111650ee596219bb5defa0ce1a1308e6e77ccf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0ed2d0abc021f56fa27dc6d0770535c1851a43b" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-m9gf-vf48-rg58/GHSA-m9gf-vf48-rg58.json b/advisories/unreviewed/2025/02/GHSA-m9gf-vf48-rg58/GHSA-m9gf-vf48-rg58.json new file mode 100644 index 00000000000..cab81991332 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m9gf-vf48-rg58/GHSA-m9gf-vf48-rg58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9gf-vf48-rg58", + "modified": "2025-02-21T15:32:03Z", + "published": "2025-02-21T15:32:03Z", + "aliases": [ + "CVE-2025-0838" + ], + "details": "There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass a very large size that would cause an integer overflow when computing the size of the container's backing store, and a subsequent out-of-bounds memory write. Subsequent accesses to the container might also access out-of-bounds memory. We recommend upgrading past commit 5a0e2cb5e3958dd90bb8569a2766622cb74d90c1", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0838" + }, + { + "type": "WEB", + "url": "https://github.com/abseil/abseil-cpp/commit/5a0e2cb5e3958dd90bb8569a2766622cb74d90c1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q3hh-qh22-77x8/GHSA-q3hh-qh22-77x8.json b/advisories/unreviewed/2025/02/GHSA-q3hh-qh22-77x8/GHSA-q3hh-qh22-77x8.json index 50bf16d86e1..85d623cb413 100644 --- a/advisories/unreviewed/2025/02/GHSA-q3hh-qh22-77x8/GHSA-q3hh-qh22-77x8.json +++ b/advisories/unreviewed/2025/02/GHSA-q3hh-qh22-77x8/GHSA-q3hh-qh22-77x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3hh-qh22-77x8", - "modified": "2025-02-17T12:30:31Z", + "modified": "2025-02-21T15:32:00Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2025-21687" @@ -18,6 +18,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/03844b1908114680ca35fa0a0aba3d906a6d78af" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1485932496a1b025235af8aa1e21988d6b7ccd54" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/198090eb6f5f094cf3a268c3c30ef1e9c84a6dbe" diff --git a/advisories/unreviewed/2025/02/GHSA-qh8x-qjjx-2j6q/GHSA-qh8x-qjjx-2j6q.json b/advisories/unreviewed/2025/02/GHSA-qh8x-qjjx-2j6q/GHSA-qh8x-qjjx-2j6q.json new file mode 100644 index 00000000000..75bdf83450d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qh8x-qjjx-2j6q/GHSA-qh8x-qjjx-2j6q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh8x-qjjx-2j6q", + "modified": "2025-02-21T15:32:03Z", + "published": "2025-02-21T15:32:03Z", + "aliases": [ + "CVE-2025-1537" + ], + "details": "A vulnerability was found in Harpia DiagSystem 12. It has been rated as critical. This issue affects some unknown processing of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument codexame leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1537" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/10IspKbYh7TYmxRPRIQZ7oRg6Xise8ykJ/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296477" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296477" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qjmr-r57j-mpf5/GHSA-qjmr-r57j-mpf5.json b/advisories/unreviewed/2025/02/GHSA-qjmr-r57j-mpf5/GHSA-qjmr-r57j-mpf5.json new file mode 100644 index 00000000000..8e66b2d197c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qjmr-r57j-mpf5/GHSA-qjmr-r57j-mpf5.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjmr-r57j-mpf5", + "modified": "2025-02-21T15:32:04Z", + "published": "2025-02-21T15:32:04Z", + "aliases": [ + "CVE-2025-1539" + ], + "details": "A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00. Affected by this issue is the function replace_special_char of the file /storagein.pd-XXXXXX. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1539" + }, + { + "type": "WEB", + "url": "https://legacy.us.dlink.com/pages/product.aspx?id=4b2bbe2e3f1d440ea65bc56c7e3dcc5c" + }, + { + "type": "WEB", + "url": "https://tasty-foxtrot-3a8.notion.site/D-link-DAP-1320-replace_special_char-Vulnerability-1960448e6195809c94f9fd2ff1f59bcf?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296480" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497496" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json b/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json index 7a3a8ca7242..e565104b5b2 100644 --- a/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json +++ b/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r79j-x479-2vhw", - "modified": "2025-02-13T15:31:25Z", + "modified": "2025-02-21T15:32:00Z", "published": "2025-02-13T12:31:07Z", "aliases": [ "CVE-2025-21700" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/bc50835e83f60f56e9bec2b392fb5544f250fb6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/deda09c0543a66fa51554abc5ffd723d99b191bf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json b/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json new file mode 100644 index 00000000000..a98ddf5a80d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8m7-99rg-xp5c", + "modified": "2025-02-21T15:32:02Z", + "published": "2025-02-21T15:32:02Z", + "aliases": [ + "CVE-2025-26794" + ], + "details": "Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26794" + }, + { + "type": "WEB", + "url": "https://exim.org" + }, + { + "type": "WEB", + "url": "https://www.exim.org/static/doc/security/CVE-2025-26794.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/19/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json b/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json index f7f50613ea0..83499d9ccd0 100644 --- a/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json +++ b/advisories/unreviewed/2025/02/GHSA-w63g-mh88-r763/GHSA-w63g-mh88-r763.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w63g-mh88-r763", - "modified": "2025-02-21T00:31:11Z", + "modified": "2025-02-21T15:32:02Z", "published": "2025-02-21T00:31:11Z", "aliases": [ "CVE-2025-25957" ], "details": "Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T23:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json b/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json index de990297597..120cd78e3d8 100644 --- a/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json +++ b/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmcv-pj3g-38rp", - "modified": "2025-02-20T00:32:02Z", + "modified": "2025-02-21T15:32:00Z", "published": "2025-02-12T21:31:54Z", "aliases": [ "CVE-2025-0111" ], "details": "An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.\n\nYou can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\n\n\nThis issue does not affect Cloud NGFW or Prisma Access software.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" @@ -26,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-610", "CWE-73" ], "severity": "HIGH",