From 23a40335dd667b0291f25d2c88df2053d7ad86e5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 00:34:40 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-23pr-9jjv-5m9h.json | 40 ++++++++++++++++ .../GHSA-244r-4cqf-v63r.json | 40 ++++++++++++++++ .../GHSA-2f29-v4g5-53hv.json | 40 ++++++++++++++++ .../GHSA-2fc3-r2jr-m2w4.json | 40 ++++++++++++++++ .../GHSA-35p6-x466-363j.json | 40 ++++++++++++++++ .../GHSA-3793-4q29-j9vm.json | 40 ++++++++++++++++ .../GHSA-38wm-547c-5mmg.json | 40 ++++++++++++++++ .../GHSA-3wf7-83q3-948c.json | 29 +++++++++++ .../GHSA-4369-mg8x-jq9f.json | 29 +++++++++++ .../GHSA-456w-h99j-m5vj.json | 40 ++++++++++++++++ .../GHSA-474w-fcfg-344q.json | 40 ++++++++++++++++ .../GHSA-4gh6-vw59-7gq4.json | 40 ++++++++++++++++ .../GHSA-4qmr-c42j-3wg2.json | 40 ++++++++++++++++ .../GHSA-52j5-46fc-2h8g.json | 40 ++++++++++++++++ .../GHSA-58fw-739x-rp4m.json | 40 ++++++++++++++++ .../GHSA-59px-4p89-v94g.json | 40 ++++++++++++++++ .../GHSA-5gqq-8pmr-37wh.json | 40 ++++++++++++++++ .../GHSA-5wg2-r9hm-329c.json | 29 +++++++++++ .../GHSA-62xq-66fv-wc89.json | 40 ++++++++++++++++ .../GHSA-63vr-qrp5-7r43.json | 40 ++++++++++++++++ .../GHSA-648v-44jr-95mp.json | 40 ++++++++++++++++ .../GHSA-64gc-vjfp-q9cj.json | 29 +++++++++++ .../GHSA-6cf8-66gc-38x4.json | 40 ++++++++++++++++ .../GHSA-6vv3-869f-rhv7.json | 40 ++++++++++++++++ .../GHSA-72hr-gv3f-g44q.json | 40 ++++++++++++++++ .../GHSA-72px-4jm6-9942.json | 15 ++++-- .../GHSA-739j-9mp5-mmf8.json | 29 +++++++++++ .../GHSA-73qc-g3pc-j338.json | 29 +++++++++++ .../GHSA-772m-773g-qmhc.json | 33 +++++++++++++ .../GHSA-782g-678g-f5mh.json | 40 ++++++++++++++++ .../GHSA-7jpp-9623-r487.json | 40 ++++++++++++++++ .../GHSA-7q45-6pqj-jm2r.json | 40 ++++++++++++++++ .../GHSA-8799-xc4m-6fcp.json | 40 ++++++++++++++++ .../GHSA-8fc2-fhh6-f6m5.json | 29 +++++++++++ .../GHSA-8hpf-983v-7frq.json | 40 ++++++++++++++++ .../GHSA-8qx7-7grr-r4cv.json | 40 ++++++++++++++++ .../GHSA-954h-pp6m-w6fr.json | 40 ++++++++++++++++ .../GHSA-c436-8rvh-pgj5.json | 40 ++++++++++++++++ .../GHSA-cg5c-r7gf-4xwg.json | 40 ++++++++++++++++ .../GHSA-cjhq-mx8m-2rp6.json | 40 ++++++++++++++++ .../GHSA-cqgm-mrvf-v72c.json | 40 ++++++++++++++++ .../GHSA-cx69-99pw-64rh.json | 40 ++++++++++++++++ .../GHSA-cxhc-4mwx-cq5w.json | 40 ++++++++++++++++ .../GHSA-f35f-m57h-gmh5.json | 40 ++++++++++++++++ .../GHSA-f3cm-3h89-xrg5.json | 40 ++++++++++++++++ .../GHSA-f4jq-8gqc-63v2.json | 29 +++++++++++ .../GHSA-fc9q-2cc3-vm2g.json | 40 ++++++++++++++++ .../GHSA-fh5x-3cc2-p28r.json | 40 ++++++++++++++++ .../GHSA-g5pm-xmgf-pjcq.json | 40 ++++++++++++++++ .../GHSA-g63g-p6q2-j7c8.json | 40 ++++++++++++++++ .../GHSA-g764-x6j6-xvv9.json | 40 ++++++++++++++++ .../GHSA-gqjf-56cj-6r7p.json | 40 ++++++++++++++++ .../GHSA-h7cr-rpch-75hm.json | 29 +++++++++++ .../GHSA-h8pj-rh9p-5jjx.json | 15 ++++-- .../GHSA-h9vj-j3r3-ppmq.json | 40 ++++++++++++++++ .../GHSA-hmq6-3hm7-3h78.json | 15 ++++-- .../GHSA-j6pv-hgjx-wrcm.json | 40 ++++++++++++++++ .../GHSA-jfw5-jjhf-gfrp.json | 40 ++++++++++++++++ .../GHSA-jj6x-6pqm-w934.json | 40 ++++++++++++++++ .../GHSA-mc5v-w52w-gjpc.json | 40 ++++++++++++++++ .../GHSA-mcf6-5wr6-j2wx.json | 40 ++++++++++++++++ .../GHSA-mj9v-hh2h-mg7f.json | 40 ++++++++++++++++ .../GHSA-mjj4-76fc-q29v.json | 40 ++++++++++++++++ .../GHSA-mpg8-8x9c-p9gv.json | 33 +++++++++++++ .../GHSA-p87p-wmhg-7j37.json | 40 ++++++++++++++++ .../GHSA-pc6x-4v99-366p.json | 29 +++++++++++ .../GHSA-ph64-gwhp-q7m9.json | 40 ++++++++++++++++ .../GHSA-prp5-wffw-rmqq.json | 48 +++++++++++++++++++ .../GHSA-prq3-r4gw-34vp.json | 15 ++++-- .../GHSA-pvv4-6724-vgwp.json | 33 +++++++++++++ .../GHSA-pw24-vxq6-ghrm.json | 15 ++++-- .../GHSA-pw2v-hvc7-4w3q.json | 40 ++++++++++++++++ .../GHSA-qh26-pvc5-g99h.json | 15 ++++-- .../GHSA-qmfg-mq72-7q5w.json | 40 ++++++++++++++++ .../GHSA-qrcc-hpw3-5q3x.json | 40 ++++++++++++++++ .../GHSA-r6h8-vrh6-m65f.json | 40 ++++++++++++++++ .../GHSA-rfxv-rpwj-gvc7.json | 29 +++++++++++ .../GHSA-rmph-h336-23fp.json | 29 +++++++++++ .../GHSA-rpx9-4223-347m.json | 40 ++++++++++++++++ .../GHSA-rw8g-q53g-4m8g.json | 40 ++++++++++++++++ .../GHSA-vcrj-34mv-cmcg.json | 40 ++++++++++++++++ .../GHSA-vgrj-w768-vh7r.json | 40 ++++++++++++++++ .../GHSA-wfx9-cpjp-4xfj.json | 40 ++++++++++++++++ .../GHSA-wqwq-7w88-r45v.json | 40 ++++++++++++++++ .../GHSA-wr4g-hvjj-f7fp.json | 29 +++++++++++ .../GHSA-wwj6-8m7r-rqxf.json | 40 ++++++++++++++++ .../GHSA-wxg6-cwh7-4c8c.json | 40 ++++++++++++++++ .../GHSA-x2gp-2qw3-6f2v.json | 40 ++++++++++++++++ .../GHSA-xp5v-36w8-hwxm.json | 48 +++++++++++++++++++ 89 files changed, 3238 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-23pr-9jjv-5m9h/GHSA-23pr-9jjv-5m9h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-244r-4cqf-v63r/GHSA-244r-4cqf-v63r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2f29-v4g5-53hv/GHSA-2f29-v4g5-53hv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2fc3-r2jr-m2w4/GHSA-2fc3-r2jr-m2w4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-35p6-x466-363j/GHSA-35p6-x466-363j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3793-4q29-j9vm/GHSA-3793-4q29-j9vm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-38wm-547c-5mmg/GHSA-38wm-547c-5mmg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3wf7-83q3-948c/GHSA-3wf7-83q3-948c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4369-mg8x-jq9f/GHSA-4369-mg8x-jq9f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-456w-h99j-m5vj/GHSA-456w-h99j-m5vj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-474w-fcfg-344q/GHSA-474w-fcfg-344q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4gh6-vw59-7gq4/GHSA-4gh6-vw59-7gq4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4qmr-c42j-3wg2/GHSA-4qmr-c42j-3wg2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-52j5-46fc-2h8g/GHSA-52j5-46fc-2h8g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-58fw-739x-rp4m/GHSA-58fw-739x-rp4m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-59px-4p89-v94g/GHSA-59px-4p89-v94g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5gqq-8pmr-37wh/GHSA-5gqq-8pmr-37wh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5wg2-r9hm-329c/GHSA-5wg2-r9hm-329c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-62xq-66fv-wc89/GHSA-62xq-66fv-wc89.json create mode 100644 advisories/unreviewed/2025/02/GHSA-63vr-qrp5-7r43/GHSA-63vr-qrp5-7r43.json create mode 100644 advisories/unreviewed/2025/02/GHSA-648v-44jr-95mp/GHSA-648v-44jr-95mp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-64gc-vjfp-q9cj/GHSA-64gc-vjfp-q9cj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6cf8-66gc-38x4/GHSA-6cf8-66gc-38x4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6vv3-869f-rhv7/GHSA-6vv3-869f-rhv7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-72hr-gv3f-g44q/GHSA-72hr-gv3f-g44q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-73qc-g3pc-j338/GHSA-73qc-g3pc-j338.json create mode 100644 advisories/unreviewed/2025/02/GHSA-772m-773g-qmhc/GHSA-772m-773g-qmhc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-782g-678g-f5mh/GHSA-782g-678g-f5mh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7jpp-9623-r487/GHSA-7jpp-9623-r487.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7q45-6pqj-jm2r/GHSA-7q45-6pqj-jm2r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8799-xc4m-6fcp/GHSA-8799-xc4m-6fcp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8fc2-fhh6-f6m5/GHSA-8fc2-fhh6-f6m5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8hpf-983v-7frq/GHSA-8hpf-983v-7frq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-954h-pp6m-w6fr/GHSA-954h-pp6m-w6fr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c436-8rvh-pgj5/GHSA-c436-8rvh-pgj5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cg5c-r7gf-4xwg/GHSA-cg5c-r7gf-4xwg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cjhq-mx8m-2rp6/GHSA-cjhq-mx8m-2rp6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cqgm-mrvf-v72c/GHSA-cqgm-mrvf-v72c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cx69-99pw-64rh/GHSA-cx69-99pw-64rh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cxhc-4mwx-cq5w/GHSA-cxhc-4mwx-cq5w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f35f-m57h-gmh5/GHSA-f35f-m57h-gmh5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f3cm-3h89-xrg5/GHSA-f3cm-3h89-xrg5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f4jq-8gqc-63v2/GHSA-f4jq-8gqc-63v2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fc9q-2cc3-vm2g/GHSA-fc9q-2cc3-vm2g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fh5x-3cc2-p28r/GHSA-fh5x-3cc2-p28r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g5pm-xmgf-pjcq/GHSA-g5pm-xmgf-pjcq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g63g-p6q2-j7c8/GHSA-g63g-p6q2-j7c8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g764-x6j6-xvv9/GHSA-g764-x6j6-xvv9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gqjf-56cj-6r7p/GHSA-gqjf-56cj-6r7p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h7cr-rpch-75hm/GHSA-h7cr-rpch-75hm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h9vj-j3r3-ppmq/GHSA-h9vj-j3r3-ppmq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j6pv-hgjx-wrcm/GHSA-j6pv-hgjx-wrcm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jfw5-jjhf-gfrp/GHSA-jfw5-jjhf-gfrp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jj6x-6pqm-w934/GHSA-jj6x-6pqm-w934.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mc5v-w52w-gjpc/GHSA-mc5v-w52w-gjpc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mcf6-5wr6-j2wx/GHSA-mcf6-5wr6-j2wx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mj9v-hh2h-mg7f/GHSA-mj9v-hh2h-mg7f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mjj4-76fc-q29v/GHSA-mjj4-76fc-q29v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mpg8-8x9c-p9gv/GHSA-mpg8-8x9c-p9gv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p87p-wmhg-7j37/GHSA-p87p-wmhg-7j37.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ph64-gwhp-q7m9/GHSA-ph64-gwhp-q7m9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-prp5-wffw-rmqq/GHSA-prp5-wffw-rmqq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pvv4-6724-vgwp/GHSA-pvv4-6724-vgwp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pw2v-hvc7-4w3q/GHSA-pw2v-hvc7-4w3q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qmfg-mq72-7q5w/GHSA-qmfg-mq72-7q5w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qrcc-hpw3-5q3x/GHSA-qrcc-hpw3-5q3x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r6h8-vrh6-m65f/GHSA-r6h8-vrh6-m65f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rfxv-rpwj-gvc7/GHSA-rfxv-rpwj-gvc7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rpx9-4223-347m/GHSA-rpx9-4223-347m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rw8g-q53g-4m8g/GHSA-rw8g-q53g-4m8g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vcrj-34mv-cmcg/GHSA-vcrj-34mv-cmcg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vgrj-w768-vh7r/GHSA-vgrj-w768-vh7r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wfx9-cpjp-4xfj/GHSA-wfx9-cpjp-4xfj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wqwq-7w88-r45v/GHSA-wqwq-7w88-r45v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wr4g-hvjj-f7fp/GHSA-wr4g-hvjj-f7fp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wwj6-8m7r-rqxf/GHSA-wwj6-8m7r-rqxf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wxg6-cwh7-4c8c/GHSA-wxg6-cwh7-4c8c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x2gp-2qw3-6f2v/GHSA-x2gp-2qw3-6f2v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xp5v-36w8-hwxm/GHSA-xp5v-36w8-hwxm.json diff --git a/advisories/unreviewed/2025/02/GHSA-23pr-9jjv-5m9h/GHSA-23pr-9jjv-5m9h.json b/advisories/unreviewed/2025/02/GHSA-23pr-9jjv-5m9h/GHSA-23pr-9jjv-5m9h.json new file mode 100644 index 00000000000..e495928c29d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-23pr-9jjv-5m9h/GHSA-23pr-9jjv-5m9h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23pr-9jjv-5m9h", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-41917" + ], + "details": "Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41917" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01230.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-244r-4cqf-v63r/GHSA-244r-4cqf-v63r.json b/advisories/unreviewed/2025/02/GHSA-244r-4cqf-v63r/GHSA-244r-4cqf-v63r.json new file mode 100644 index 00000000000..585823532f3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-244r-4cqf-v63r/GHSA-244r-4cqf-v63r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-244r-4cqf-v63r", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-29214" + ], + "details": "Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29214" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2f29-v4g5-53hv/GHSA-2f29-v4g5-53hv.json b/advisories/unreviewed/2025/02/GHSA-2f29-v4g5-53hv/GHSA-2f29-v4g5-53hv.json new file mode 100644 index 00000000000..718df301643 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2f29-v4g5-53hv/GHSA-2f29-v4g5-53hv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f29-v4g5-53hv", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39365" + ], + "details": "Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39365" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01218.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2fc3-r2jr-m2w4/GHSA-2fc3-r2jr-m2w4.json b/advisories/unreviewed/2025/02/GHSA-2fc3-r2jr-m2w4/GHSA-2fc3-r2jr-m2w4.json new file mode 100644 index 00000000000..993cb51efd1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2fc3-r2jr-m2w4/GHSA-2fc3-r2jr-m2w4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fc3-r2jr-m2w4", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-32942" + ], + "details": "Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32942" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01156.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-35p6-x466-363j/GHSA-35p6-x466-363j.json b/advisories/unreviewed/2025/02/GHSA-35p6-x466-363j/GHSA-35p6-x466-363j.json new file mode 100644 index 00000000000..ecaf41f8382 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-35p6-x466-363j/GHSA-35p6-x466-363j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35p6-x466-363j", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36293" + ], + "details": "Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36293" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01213.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3793-4q29-j9vm/GHSA-3793-4q29-j9vm.json b/advisories/unreviewed/2025/02/GHSA-3793-4q29-j9vm/GHSA-3793-4q29-j9vm.json new file mode 100644 index 00000000000..8f421d81360 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3793-4q29-j9vm/GHSA-3793-4q29-j9vm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3793-4q29-j9vm", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-31153" + ], + "details": "Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31153" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-38wm-547c-5mmg/GHSA-38wm-547c-5mmg.json b/advisories/unreviewed/2025/02/GHSA-38wm-547c-5mmg/GHSA-38wm-547c-5mmg.json new file mode 100644 index 00000000000..b7aab0275ee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-38wm-547c-5mmg/GHSA-38wm-547c-5mmg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38wm-547c-5mmg", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39813" + ], + "details": "Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39813" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01227.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3wf7-83q3-948c/GHSA-3wf7-83q3-948c.json b/advisories/unreviewed/2025/02/GHSA-3wf7-83q3-948c/GHSA-3wf7-83q3-948c.json new file mode 100644 index 00000000000..d50f5f4d828 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3wf7-83q3-948c/GHSA-3wf7-83q3-948c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wf7-83q3-948c", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-57601" + ], + "details": "Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57601" + }, + { + "type": "WEB", + "url": "https://hkohi.ca/vulnerability/13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4369-mg8x-jq9f/GHSA-4369-mg8x-jq9f.json b/advisories/unreviewed/2025/02/GHSA-4369-mg8x-jq9f/GHSA-4369-mg8x-jq9f.json new file mode 100644 index 00000000000..104a1b6f3a6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4369-mg8x-jq9f/GHSA-4369-mg8x-jq9f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4369-mg8x-jq9f", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-34520" + ], + "details": "An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34520" + }, + { + "type": "WEB", + "url": "https://github.com/whitewhale-dmb/Vulnerability-Research/tree/main/CVE-2024-34520" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-456w-h99j-m5vj/GHSA-456w-h99j-m5vj.json b/advisories/unreviewed/2025/02/GHSA-456w-h99j-m5vj/GHSA-456w-h99j-m5vj.json new file mode 100644 index 00000000000..094ef1873d8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-456w-h99j-m5vj/GHSA-456w-h99j-m5vj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-456w-h99j-m5vj", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39372" + ], + "details": "Uncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39372" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01215.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-474w-fcfg-344q/GHSA-474w-fcfg-344q.json b/advisories/unreviewed/2025/02/GHSA-474w-fcfg-344q/GHSA-474w-fcfg-344q.json new file mode 100644 index 00000000000..20e2056726d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-474w-fcfg-344q/GHSA-474w-fcfg-344q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-474w-fcfg-344q", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-34440" + ], + "details": "Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34440" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4gh6-vw59-7gq4/GHSA-4gh6-vw59-7gq4.json b/advisories/unreviewed/2025/02/GHSA-4gh6-vw59-7gq4/GHSA-4gh6-vw59-7gq4.json new file mode 100644 index 00000000000..a34b11f6715 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4gh6-vw59-7gq4/GHSA-4gh6-vw59-7gq4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gh6-vw59-7gq4", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39355" + ], + "details": "Improper handling of physical or environmental conditions in some Intel(R) Processors may allow an authenticated user to enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39355" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01228.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1384" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4qmr-c42j-3wg2/GHSA-4qmr-c42j-3wg2.json b/advisories/unreviewed/2025/02/GHSA-4qmr-c42j-3wg2/GHSA-4qmr-c42j-3wg2.json new file mode 100644 index 00000000000..301951ec67a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4qmr-c42j-3wg2/GHSA-4qmr-c42j-3wg2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qmr-c42j-3wg2", + "modified": "2025-02-13T00:33:03Z", + "published": "2025-02-13T00:33:03Z", + "aliases": [ + "CVE-2022-31631" + ], + "details": "In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31631" + }, + { + "type": "WEB", + "url": "https://bugs.php.net/bug.php?id=81740" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230223-0007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-52j5-46fc-2h8g/GHSA-52j5-46fc-2h8g.json b/advisories/unreviewed/2025/02/GHSA-52j5-46fc-2h8g/GHSA-52j5-46fc-2h8g.json new file mode 100644 index 00000000000..98fdd88d548 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-52j5-46fc-2h8g/GHSA-52j5-46fc-2h8g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52j5-46fc-2h8g", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-29223" + ], + "details": "Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29223" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-58fw-739x-rp4m/GHSA-58fw-739x-rp4m.json b/advisories/unreviewed/2025/02/GHSA-58fw-739x-rp4m/GHSA-58fw-739x-rp4m.json new file mode 100644 index 00000000000..4b5be97489c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-58fw-739x-rp4m/GHSA-58fw-739x-rp4m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58fw-739x-rp4m", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-30211" + ], + "details": "Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30211" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01152.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-59px-4p89-v94g/GHSA-59px-4p89-v94g.json b/advisories/unreviewed/2025/02/GHSA-59px-4p89-v94g/GHSA-59px-4p89-v94g.json new file mode 100644 index 00000000000..04934ea5165 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-59px-4p89-v94g/GHSA-59px-4p89-v94g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59px-4p89-v94g", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-49603" + ], + "details": "Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49603" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01203.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5gqq-8pmr-37wh/GHSA-5gqq-8pmr-37wh.json b/advisories/unreviewed/2025/02/GHSA-5gqq-8pmr-37wh/GHSA-5gqq-8pmr-37wh.json new file mode 100644 index 00000000000..fc31ab7a7e2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5gqq-8pmr-37wh/GHSA-5gqq-8pmr-37wh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gqq-8pmr-37wh", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-37020" + ], + "details": "Sequence of processor instructions leads to unexpected behavior in the Intel(R) DSA V1.0 for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37020" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01194.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1281" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5wg2-r9hm-329c/GHSA-5wg2-r9hm-329c.json b/advisories/unreviewed/2025/02/GHSA-5wg2-r9hm-329c/GHSA-5wg2-r9hm-329c.json new file mode 100644 index 00000000000..7a720f24d0a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5wg2-r9hm-329c/GHSA-5wg2-r9hm-329c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wg2-r9hm-329c", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-34521" + ], + "details": "A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the file permissions of the privileged system user running the application.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34521" + }, + { + "type": "WEB", + "url": "https://github.com/whitewhale-dmb/Vulnerability-Research/tree/main/CVE-2024-34521" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-62xq-66fv-wc89/GHSA-62xq-66fv-wc89.json b/advisories/unreviewed/2025/02/GHSA-62xq-66fv-wc89/GHSA-62xq-66fv-wc89.json new file mode 100644 index 00000000000..cc7d5ed0da6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-62xq-66fv-wc89/GHSA-62xq-66fv-wc89.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62xq-66fv-wc89", + "modified": "2025-02-13T00:33:03Z", + "published": "2025-02-13T00:33:03Z", + "aliases": [ + "CVE-2023-31276" + ], + "details": "Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31276" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-63vr-qrp5-7r43/GHSA-63vr-qrp5-7r43.json b/advisories/unreviewed/2025/02/GHSA-63vr-qrp5-7r43/GHSA-63vr-qrp5-7r43.json new file mode 100644 index 00000000000..cc09580f573 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-63vr-qrp5-7r43/GHSA-63vr-qrp5-7r43.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63vr-qrp5-7r43", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39805" + ], + "details": "Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39805" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01030.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-648v-44jr-95mp/GHSA-648v-44jr-95mp.json b/advisories/unreviewed/2025/02/GHSA-648v-44jr-95mp/GHSA-648v-44jr-95mp.json new file mode 100644 index 00000000000..13c8d77c79d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-648v-44jr-95mp/GHSA-648v-44jr-95mp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-648v-44jr-95mp", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-43758" + ], + "details": "Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43758" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-64gc-vjfp-q9cj/GHSA-64gc-vjfp-q9cj.json b/advisories/unreviewed/2025/02/GHSA-64gc-vjfp-q9cj/GHSA-64gc-vjfp-q9cj.json new file mode 100644 index 00000000000..2ee2a25b65f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-64gc-vjfp-q9cj/GHSA-64gc-vjfp-q9cj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64gc-vjfp-q9cj", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-46922" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_parser_bos in the Xclipse Driver.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46922" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6cf8-66gc-38x4/GHSA-6cf8-66gc-38x4.json b/advisories/unreviewed/2025/02/GHSA-6cf8-66gc-38x4/GHSA-6cf8-66gc-38x4.json new file mode 100644 index 00000000000..dd4c8410fde --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6cf8-66gc-38x4/GHSA-6cf8-66gc-38x4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cf8-66gc-38x4", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-42492" + ], + "details": "Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42492" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01237.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6vv3-869f-rhv7/GHSA-6vv3-869f-rhv7.json b/advisories/unreviewed/2025/02/GHSA-6vv3-869f-rhv7/GHSA-6vv3-869f-rhv7.json new file mode 100644 index 00000000000..00c8c87f22f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6vv3-869f-rhv7/GHSA-6vv3-869f-rhv7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vv3-869f-rhv7", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39271" + ], + "details": "Improper restriction of communication channel to intended endpoints in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software before version 23.80 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39271" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-72hr-gv3f-g44q/GHSA-72hr-gv3f-g44q.json b/advisories/unreviewed/2025/02/GHSA-72hr-gv3f-g44q/GHSA-72hr-gv3f-g44q.json new file mode 100644 index 00000000000..de5efce8b06 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-72hr-gv3f-g44q/GHSA-72hr-gv3f-g44q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72hr-gv3f-g44q", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-49615" + ], + "details": "Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49615" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01203.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json b/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json index e9dfb41f414..5b35bb508fe 100644 --- a/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json +++ b/advisories/unreviewed/2025/02/GHSA-72px-4jm6-9942/GHSA-72px-4jm6-9942.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-72px-4jm6-9942", - "modified": "2025-02-12T00:32:17Z", + "modified": "2025-02-13T00:33:03Z", "published": "2025-02-12T00:32:17Z", "aliases": [ "CVE-2024-54772" ], "details": "An issue was discovered in the Winbox service of MikroTik RouterOS v6.43 through v7.16.1. A discrepancy in response times between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-208" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T23:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json b/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json new file mode 100644 index 00000000000..aba462373a7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-739j-9mp5-mmf8", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-56939" + ], + "details": "LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56939" + }, + { + "type": "WEB", + "url": "https://github.com/nikolas-ch/CVEs/tree/main/LearnDash_v6.7.1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-73qc-g3pc-j338/GHSA-73qc-g3pc-j338.json b/advisories/unreviewed/2025/02/GHSA-73qc-g3pc-j338/GHSA-73qc-g3pc-j338.json new file mode 100644 index 00000000000..d25fcc156b5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-73qc-g3pc-j338/GHSA-73qc-g3pc-j338.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73qc-g3pc-j338", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-46923" + ], + "details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_ib_fill in the Xclipse Driver.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46923" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-772m-773g-qmhc/GHSA-772m-773g-qmhc.json b/advisories/unreviewed/2025/02/GHSA-772m-773g-qmhc/GHSA-772m-773g-qmhc.json new file mode 100644 index 00000000000..271170f701e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-772m-773g-qmhc/GHSA-772m-773g-qmhc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772m-773g-qmhc", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-57603" + ], + "details": "An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57603" + }, + { + "type": "WEB", + "url": "https://github.com/mayswind/ezbookkeeping/issues/33" + }, + { + "type": "WEB", + "url": "https://hkohi.ca/vulnerability/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-782g-678g-f5mh/GHSA-782g-678g-f5mh.json b/advisories/unreviewed/2025/02/GHSA-782g-678g-f5mh/GHSA-782g-678g-f5mh.json new file mode 100644 index 00000000000..c3b2aad18e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-782g-678g-f5mh/GHSA-782g-678g-f5mh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-782g-678g-f5mh", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-32938" + ], + "details": "Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32938" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01207.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7jpp-9623-r487/GHSA-7jpp-9623-r487.json b/advisories/unreviewed/2025/02/GHSA-7jpp-9623-r487/GHSA-7jpp-9623-r487.json new file mode 100644 index 00000000000..cb946526fb8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7jpp-9623-r487/GHSA-7jpp-9623-r487.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jpp-9623-r487", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-31157" + ], + "details": "Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31157" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7q45-6pqj-jm2r/GHSA-7q45-6pqj-jm2r.json b/advisories/unreviewed/2025/02/GHSA-7q45-6pqj-jm2r/GHSA-7q45-6pqj-jm2r.json new file mode 100644 index 00000000000..0911b5448a4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7q45-6pqj-jm2r/GHSA-7q45-6pqj-jm2r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q45-6pqj-jm2r", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39284" + ], + "details": "Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39284" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01208.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8799-xc4m-6fcp/GHSA-8799-xc4m-6fcp.json b/advisories/unreviewed/2025/02/GHSA-8799-xc4m-6fcp/GHSA-8799-xc4m-6fcp.json new file mode 100644 index 00000000000..7dd9ac87f7d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8799-xc4m-6fcp/GHSA-8799-xc4m-6fcp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8799-xc4m-6fcp", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-26021" + ], + "details": "Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26021" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01152.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8fc2-fhh6-f6m5/GHSA-8fc2-fhh6-f6m5.json b/advisories/unreviewed/2025/02/GHSA-8fc2-fhh6-f6m5/GHSA-8fc2-fhh6-f6m5.json new file mode 100644 index 00000000000..66b383ff728 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8fc2-fhh6-f6m5/GHSA-8fc2-fhh6-f6m5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fc2-fhh6-f6m5", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-57602" + ], + "details": "An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57602" + }, + { + "type": "WEB", + "url": "https://hkohi.ca/vulnerability/12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8hpf-983v-7frq/GHSA-8hpf-983v-7frq.json b/advisories/unreviewed/2025/02/GHSA-8hpf-983v-7frq/GHSA-8hpf-983v-7frq.json new file mode 100644 index 00000000000..0897af4242f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8hpf-983v-7frq/GHSA-8hpf-983v-7frq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hpf-983v-7frq", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-38310" + ], + "details": "Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38310" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01235.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json b/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json new file mode 100644 index 00000000000..c828db0a838 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qx7-7grr-r4cv", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39356" + ], + "details": "NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39356" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-954h-pp6m-w6fr/GHSA-954h-pp6m-w6fr.json b/advisories/unreviewed/2025/02/GHSA-954h-pp6m-w6fr/GHSA-954h-pp6m-w6fr.json new file mode 100644 index 00000000000..ba4c017c2a0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-954h-pp6m-w6fr/GHSA-954h-pp6m-w6fr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-954h-pp6m-w6fr", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2025-20097" + ], + "details": "Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before version R01.02.0002 may allow an authenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20097" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c436-8rvh-pgj5/GHSA-c436-8rvh-pgj5.json b/advisories/unreviewed/2025/02/GHSA-c436-8rvh-pgj5/GHSA-c436-8rvh-pgj5.json new file mode 100644 index 00000000000..d1b9282d1d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c436-8rvh-pgj5/GHSA-c436-8rvh-pgj5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c436-8rvh-pgj5", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-25571" + ], + "details": "Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25571" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01120.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cg5c-r7gf-4xwg/GHSA-cg5c-r7gf-4xwg.json b/advisories/unreviewed/2025/02/GHSA-cg5c-r7gf-4xwg/GHSA-cg5c-r7gf-4xwg.json new file mode 100644 index 00000000000..75c1da36aa1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cg5c-r7gf-4xwg/GHSA-cg5c-r7gf-4xwg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg5c-r7gf-4xwg", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39797" + ], + "details": "Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39797" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00590.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cjhq-mx8m-2rp6/GHSA-cjhq-mx8m-2rp6.json b/advisories/unreviewed/2025/02/GHSA-cjhq-mx8m-2rp6/GHSA-cjhq-mx8m-2rp6.json new file mode 100644 index 00000000000..f63f11c41ad --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cjhq-mx8m-2rp6/GHSA-cjhq-mx8m-2rp6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjhq-mx8m-2rp6", + "modified": "2025-02-13T00:33:03Z", + "published": "2025-02-13T00:33:03Z", + "aliases": [ + "CVE-2023-29164" + ], + "details": "Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29164" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00990.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cqgm-mrvf-v72c/GHSA-cqgm-mrvf-v72c.json b/advisories/unreviewed/2025/02/GHSA-cqgm-mrvf-v72c/GHSA-cqgm-mrvf-v72c.json new file mode 100644 index 00000000000..2c8459fbe6f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cqgm-mrvf-v72c/GHSA-cqgm-mrvf-v72c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqgm-mrvf-v72c", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-31155" + ], + "details": "Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31155" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01198.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cx69-99pw-64rh/GHSA-cx69-99pw-64rh.json b/advisories/unreviewed/2025/02/GHSA-cx69-99pw-64rh/GHSA-cx69-99pw-64rh.json new file mode 100644 index 00000000000..d77ee38be21 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cx69-99pw-64rh/GHSA-cx69-99pw-64rh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx69-99pw-64rh", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-49618" + ], + "details": "Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49618" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01203.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cxhc-4mwx-cq5w/GHSA-cxhc-4mwx-cq5w.json b/advisories/unreviewed/2025/02/GHSA-cxhc-4mwx-cq5w/GHSA-cxhc-4mwx-cq5w.json new file mode 100644 index 00000000000..561269cb327 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cxhc-4mwx-cq5w/GHSA-cxhc-4mwx-cq5w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxhc-4mwx-cq5w", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-28127" + ], + "details": "Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28127" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f35f-m57h-gmh5/GHSA-f35f-m57h-gmh5.json b/advisories/unreviewed/2025/02/GHSA-f35f-m57h-gmh5/GHSA-f35f-m57h-gmh5.json new file mode 100644 index 00000000000..7e393bcdeef --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f35f-m57h-gmh5/GHSA-f35f-m57h-gmh5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f35f-m57h-gmh5", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-42405" + ], + "details": "Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42405" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01231.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f3cm-3h89-xrg5/GHSA-f3cm-3h89-xrg5.json b/advisories/unreviewed/2025/02/GHSA-f3cm-3h89-xrg5/GHSA-f3cm-3h89-xrg5.json new file mode 100644 index 00000000000..e23f3421913 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f3cm-3h89-xrg5/GHSA-f3cm-3h89-xrg5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3cm-3h89-xrg5", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-38307" + ], + "details": "Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38307" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01152.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f4jq-8gqc-63v2/GHSA-f4jq-8gqc-63v2.json b/advisories/unreviewed/2025/02/GHSA-f4jq-8gqc-63v2/GHSA-f4jq-8gqc-63v2.json new file mode 100644 index 00000000000..e35d5932c30 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f4jq-8gqc-63v2/GHSA-f4jq-8gqc-63v2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4jq-8gqc-63v2", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-56940" + ], + "details": "An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56940" + }, + { + "type": "WEB", + "url": "https://github.com/nikolas-ch/CVEs/tree/main/LearnDash_v6.7.1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fc9q-2cc3-vm2g/GHSA-fc9q-2cc3-vm2g.json b/advisories/unreviewed/2025/02/GHSA-fc9q-2cc3-vm2g/GHSA-fc9q-2cc3-vm2g.json new file mode 100644 index 00000000000..e87e505a3ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fc9q-2cc3-vm2g/GHSA-fc9q-2cc3-vm2g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc9q-2cc3-vm2g", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-32941" + ], + "details": "NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32941" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01238.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fh5x-3cc2-p28r/GHSA-fh5x-3cc2-p28r.json b/advisories/unreviewed/2025/02/GHSA-fh5x-3cc2-p28r/GHSA-fh5x-3cc2-p28r.json new file mode 100644 index 00000000000..34bc6c4fca6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fh5x-3cc2-p28r/GHSA-fh5x-3cc2-p28r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh5x-3cc2-p28r", + "modified": "2025-02-13T00:33:03Z", + "published": "2025-02-13T00:33:03Z", + "aliases": [ + "CVE-2023-32277" + ], + "details": "Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32277" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g5pm-xmgf-pjcq/GHSA-g5pm-xmgf-pjcq.json b/advisories/unreviewed/2025/02/GHSA-g5pm-xmgf-pjcq/GHSA-g5pm-xmgf-pjcq.json new file mode 100644 index 00000000000..5d9d97c89c3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g5pm-xmgf-pjcq/GHSA-g5pm-xmgf-pjcq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5pm-xmgf-pjcq", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-24582" + ], + "details": "Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24582" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g63g-p6q2-j7c8/GHSA-g63g-p6q2-j7c8.json b/advisories/unreviewed/2025/02/GHSA-g63g-p6q2-j7c8/GHSA-g63g-p6q2-j7c8.json new file mode 100644 index 00000000000..7bfda144151 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g63g-p6q2-j7c8/GHSA-g63g-p6q2-j7c8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g63g-p6q2-j7c8", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36280" + ], + "details": "Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36280" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01214.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g764-x6j6-xvv9/GHSA-g764-x6j6-xvv9.json b/advisories/unreviewed/2025/02/GHSA-g764-x6j6-xvv9/GHSA-g764-x6j6-xvv9.json new file mode 100644 index 00000000000..2c265dedc96 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g764-x6j6-xvv9/GHSA-g764-x6j6-xvv9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g764-x6j6-xvv9", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39779" + ], + "details": "Stack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39779" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00590.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gqjf-56cj-6r7p/GHSA-gqjf-56cj-6r7p.json b/advisories/unreviewed/2025/02/GHSA-gqjf-56cj-6r7p/GHSA-gqjf-56cj-6r7p.json new file mode 100644 index 00000000000..8039073b2fc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gqjf-56cj-6r7p/GHSA-gqjf-56cj-6r7p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqjf-56cj-6r7p", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-42410" + ], + "details": "Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42410" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01235.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h7cr-rpch-75hm/GHSA-h7cr-rpch-75hm.json b/advisories/unreviewed/2025/02/GHSA-h7cr-rpch-75hm/GHSA-h7cr-rpch-75hm.json new file mode 100644 index 00000000000..a488de11a10 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h7cr-rpch-75hm/GHSA-h7cr-rpch-75hm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7cr-rpch-75hm", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-51123" + ], + "details": "An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensitive information via the /compose-pdf.xhtml?convid=[id] component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51123" + }, + { + "type": "WEB", + "url": "https://github.com/MVRC-ITSEC/CVEs/blob/main/CVE-2024-51123" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json b/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json index c50d428feb0..9f1e7c6e88c 100644 --- a/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json +++ b/advisories/unreviewed/2025/02/GHSA-h8pj-rh9p-5jjx/GHSA-h8pj-rh9p-5jjx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h8pj-rh9p-5jjx", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-13T00:33:02Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2024-55212" ], "details": "DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T22:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-h9vj-j3r3-ppmq/GHSA-h9vj-j3r3-ppmq.json b/advisories/unreviewed/2025/02/GHSA-h9vj-j3r3-ppmq/GHSA-h9vj-j3r3-ppmq.json new file mode 100644 index 00000000000..c49ce0fde3d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h9vj-j3r3-ppmq/GHSA-h9vj-j3r3-ppmq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9vj-j3r3-ppmq", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-40887" + ], + "details": "Race condition in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40887" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json b/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json index 8c877270b7f..1f51dffff69 100644 --- a/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json +++ b/advisories/unreviewed/2025/02/GHSA-hmq6-3hm7-3h78/GHSA-hmq6-3hm7-3h78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmq6-3hm7-3h78", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-13T00:33:02Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2022-37660" ], "details": "In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-323" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T23:15:08Z" diff --git a/advisories/unreviewed/2025/02/GHSA-j6pv-hgjx-wrcm/GHSA-j6pv-hgjx-wrcm.json b/advisories/unreviewed/2025/02/GHSA-j6pv-hgjx-wrcm/GHSA-j6pv-hgjx-wrcm.json new file mode 100644 index 00000000000..6730b5f13a6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j6pv-hgjx-wrcm/GHSA-j6pv-hgjx-wrcm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6pv-hgjx-wrcm", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39606" + ], + "details": "Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39606" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jfw5-jjhf-gfrp/GHSA-jfw5-jjhf-gfrp.json b/advisories/unreviewed/2025/02/GHSA-jfw5-jjhf-gfrp/GHSA-jfw5-jjhf-gfrp.json new file mode 100644 index 00000000000..53de11bf231 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jfw5-jjhf-gfrp/GHSA-jfw5-jjhf-gfrp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfw5-jjhf-gfrp", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-41168" + ], + "details": "Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41168" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jj6x-6pqm-w934/GHSA-jj6x-6pqm-w934.json b/advisories/unreviewed/2025/02/GHSA-jj6x-6pqm-w934/GHSA-jj6x-6pqm-w934.json new file mode 100644 index 00000000000..2ca8e1592a8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jj6x-6pqm-w934/GHSA-jj6x-6pqm-w934.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj6x-6pqm-w934", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36274" + ], + "details": "Out-of-bounds write in the Intel(R) 800 Series Ethernet Driver for Intel(R) Ethernet Adapter Complete Driver Pack before versions 29.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36274" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01144.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mc5v-w52w-gjpc/GHSA-mc5v-w52w-gjpc.json b/advisories/unreviewed/2025/02/GHSA-mc5v-w52w-gjpc/GHSA-mc5v-w52w-gjpc.json new file mode 100644 index 00000000000..e1239be3f79 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mc5v-w52w-gjpc/GHSA-mc5v-w52w-gjpc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc5v-w52w-gjpc", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-47006" + ], + "details": "Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47006" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01240.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mcf6-5wr6-j2wx/GHSA-mcf6-5wr6-j2wx.json b/advisories/unreviewed/2025/02/GHSA-mcf6-5wr6-j2wx/GHSA-mcf6-5wr6-j2wx.json new file mode 100644 index 00000000000..6bc17dfa70e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mcf6-5wr6-j2wx/GHSA-mcf6-5wr6-j2wx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcf6-5wr6-j2wx", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-48366" + ], + "details": "Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48366" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01203.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mj9v-hh2h-mg7f/GHSA-mj9v-hh2h-mg7f.json b/advisories/unreviewed/2025/02/GHSA-mj9v-hh2h-mg7f/GHSA-mj9v-hh2h-mg7f.json new file mode 100644 index 00000000000..65127af606d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mj9v-hh2h-mg7f/GHSA-mj9v-hh2h-mg7f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj9v-hh2h-mg7f", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-31858" + ], + "details": "Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31858" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01124.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mjj4-76fc-q29v/GHSA-mjj4-76fc-q29v.json b/advisories/unreviewed/2025/02/GHSA-mjj4-76fc-q29v/GHSA-mjj4-76fc-q29v.json new file mode 100644 index 00000000000..85564980214 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mjj4-76fc-q29v/GHSA-mjj4-76fc-q29v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjj4-76fc-q29v", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-21830" + ], + "details": "Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21830" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01044.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mpg8-8x9c-p9gv/GHSA-mpg8-8x9c-p9gv.json b/advisories/unreviewed/2025/02/GHSA-mpg8-8x9c-p9gv/GHSA-mpg8-8x9c-p9gv.json new file mode 100644 index 00000000000..52a315b2014 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mpg8-8x9c-p9gv/GHSA-mpg8-8x9c-p9gv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpg8-8x9c-p9gv", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-57604" + ], + "details": "An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57604" + }, + { + "type": "WEB", + "url": "https://github.com/mayswind/ezbookkeeping/issues/33" + }, + { + "type": "WEB", + "url": "https://hkohi.ca/vulnerability/2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p87p-wmhg-7j37/GHSA-p87p-wmhg-7j37.json b/advisories/unreviewed/2025/02/GHSA-p87p-wmhg-7j37/GHSA-p87p-wmhg-7j37.json new file mode 100644 index 00000000000..50263029d1b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p87p-wmhg-7j37/GHSA-p87p-wmhg-7j37.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p87p-wmhg-7j37", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-28047" + ], + "details": "Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28047" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json b/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json new file mode 100644 index 00000000000..081cf72abdd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc6x-4v99-366p", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-51440" + ], + "details": "An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51440" + }, + { + "type": "WEB", + "url": "https://sharedobject.blog/posts/nothing-bpf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ph64-gwhp-q7m9/GHSA-ph64-gwhp-q7m9.json b/advisories/unreviewed/2025/02/GHSA-ph64-gwhp-q7m9/GHSA-ph64-gwhp-q7m9.json new file mode 100644 index 00000000000..d6d9abd30da --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ph64-gwhp-q7m9/GHSA-ph64-gwhp-q7m9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph64-gwhp-q7m9", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39286" + ], + "details": "Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39286" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01236.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-279" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-prp5-wffw-rmqq/GHSA-prp5-wffw-rmqq.json b/advisories/unreviewed/2025/02/GHSA-prp5-wffw-rmqq/GHSA-prp5-wffw-rmqq.json new file mode 100644 index 00000000000..b62b64e60e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-prp5-wffw-rmqq/GHSA-prp5-wffw-rmqq.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prp5-wffw-rmqq", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2025-1229" + ], + "details": "A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected by this vulnerability is an unknown functionality of the file /read/?page=1&logfile=eee&match=. The manipulation of the argument path leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1229" + }, + { + "type": "WEB", + "url": "https://gitee.com/olajowon/loggrove/issues/IBJT1K" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json b/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json index da7135c4950..a30da930731 100644 --- a/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json +++ b/advisories/unreviewed/2025/02/GHSA-prq3-r4gw-34vp/GHSA-prq3-r4gw-34vp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prq3-r4gw-34vp", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-13T00:33:02Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2024-51324" ], "details": "An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T22:15:28Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pvv4-6724-vgwp/GHSA-pvv4-6724-vgwp.json b/advisories/unreviewed/2025/02/GHSA-pvv4-6724-vgwp/GHSA-pvv4-6724-vgwp.json new file mode 100644 index 00000000000..23f29d46668 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pvv4-6724-vgwp/GHSA-pvv4-6724-vgwp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvv4-6724-vgwp", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-51376" + ], + "details": "Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action?path= component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51376" + }, + { + "type": "WEB", + "url": "https://github.com/yeqifu/carRental/issues/43" + }, + { + "type": "WEB", + "url": "https://github.com/echo0d/vulnerability/blob/main/yeqifu_carRental/DirectoryTraversal.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json b/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json index e24c0255ef1..3748a898329 100644 --- a/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json +++ b/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pw24-vxq6-ghrm", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-13T00:33:03Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2024-33469" ], "details": "An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T23:15:08Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pw2v-hvc7-4w3q/GHSA-pw2v-hvc7-4w3q.json b/advisories/unreviewed/2025/02/GHSA-pw2v-hvc7-4w3q/GHSA-pw2v-hvc7-4w3q.json new file mode 100644 index 00000000000..b4b98e8b453 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pw2v-hvc7-4w3q/GHSA-pw2v-hvc7-4w3q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw2v-hvc7-4w3q", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-39279" + ], + "details": "Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39279" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json b/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json index bc2f50c4275..8b4cb47d82d 100644 --- a/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json +++ b/advisories/unreviewed/2025/02/GHSA-qh26-pvc5-g99h/GHSA-qh26-pvc5-g99h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qh26-pvc5-g99h", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-13T00:33:03Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2024-44336" ], "details": "An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ichi2.anki/ directory and save it into publicly available storage.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T23:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qmfg-mq72-7q5w/GHSA-qmfg-mq72-7q5w.json b/advisories/unreviewed/2025/02/GHSA-qmfg-mq72-7q5w/GHSA-qmfg-mq72-7q5w.json new file mode 100644 index 00000000000..b73302eb609 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qmfg-mq72-7q5w/GHSA-qmfg-mq72-7q5w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmfg-mq72-7q5w", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36285" + ], + "details": "Race condition in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36285" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qrcc-hpw3-5q3x/GHSA-qrcc-hpw3-5q3x.json b/advisories/unreviewed/2025/02/GHSA-qrcc-hpw3-5q3x/GHSA-qrcc-hpw3-5q3x.json new file mode 100644 index 00000000000..c74a29680ff --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qrcc-hpw3-5q3x/GHSA-qrcc-hpw3-5q3x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrcc-hpw3-5q3x", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2023-48267" + ], + "details": "Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48267" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01203.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r6h8-vrh6-m65f/GHSA-r6h8-vrh6-m65f.json b/advisories/unreviewed/2025/02/GHSA-r6h8-vrh6-m65f/GHSA-r6h8-vrh6-m65f.json new file mode 100644 index 00000000000..4fed220b883 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r6h8-vrh6-m65f/GHSA-r6h8-vrh6-m65f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6h8-vrh6-m65f", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36291" + ], + "details": "Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36291" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01184.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rfxv-rpwj-gvc7/GHSA-rfxv-rpwj-gvc7.json b/advisories/unreviewed/2025/02/GHSA-rfxv-rpwj-gvc7/GHSA-rfxv-rpwj-gvc7.json new file mode 100644 index 00000000000..20b74375b2b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rfxv-rpwj-gvc7/GHSA-rfxv-rpwj-gvc7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfxv-rpwj-gvc7", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-51122" + ], + "details": "Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, CN parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51122" + }, + { + "type": "WEB", + "url": "https://github.com/MVRC-ITSEC/CVEs/blob/main/CVE-2024-51122" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json b/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json new file mode 100644 index 00000000000..666d6948231 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmph-h336-23fp", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-56938" + ], + "details": "LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56938" + }, + { + "type": "WEB", + "url": "https://github.com/nikolas-ch/CVEs/tree/main/LearnDash_v6.7.1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rpx9-4223-347m/GHSA-rpx9-4223-347m.json b/advisories/unreviewed/2025/02/GHSA-rpx9-4223-347m/GHSA-rpx9-4223-347m.json new file mode 100644 index 00000000000..57ad95f3db6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rpx9-4223-347m/GHSA-rpx9-4223-347m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpx9-4223-347m", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-41934" + ], + "details": "Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41934" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01233.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rw8g-q53g-4m8g/GHSA-rw8g-q53g-4m8g.json b/advisories/unreviewed/2025/02/GHSA-rw8g-q53g-4m8g/GHSA-rw8g-q53g-4m8g.json new file mode 100644 index 00000000000..0d825d4d85a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rw8g-q53g-4m8g/GHSA-rw8g-q53g-4m8g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw8g-q53g-4m8g", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-41166" + ], + "details": "Stack-based buffer overflow in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41166" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vcrj-34mv-cmcg/GHSA-vcrj-34mv-cmcg.json b/advisories/unreviewed/2025/02/GHSA-vcrj-34mv-cmcg/GHSA-vcrj-34mv-cmcg.json new file mode 100644 index 00000000000..006e698e7dd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vcrj-34mv-cmcg/GHSA-vcrj-34mv-cmcg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcrj-34mv-cmcg", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-21859" + ], + "details": "Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21859" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01198.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vgrj-w768-vh7r/GHSA-vgrj-w768-vh7r.json b/advisories/unreviewed/2025/02/GHSA-vgrj-w768-vh7r/GHSA-vgrj-w768-vh7r.json new file mode 100644 index 00000000000..d79ced1813f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vgrj-w768-vh7r/GHSA-vgrj-w768-vh7r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgrj-w768-vh7r", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-31068" + ], + "details": "Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31068" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01166.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1245" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wfx9-cpjp-4xfj/GHSA-wfx9-cpjp-4xfj.json b/advisories/unreviewed/2025/02/GHSA-wfx9-cpjp-4xfj/GHSA-wfx9-cpjp-4xfj.json new file mode 100644 index 00000000000..c3fec86ccbc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wfx9-cpjp-4xfj/GHSA-wfx9-cpjp-4xfj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfx9-cpjp-4xfj", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36283" + ], + "details": "Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36283" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01232.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wqwq-7w88-r45v/GHSA-wqwq-7w88-r45v.json b/advisories/unreviewed/2025/02/GHSA-wqwq-7w88-r45v/GHSA-wqwq-7w88-r45v.json new file mode 100644 index 00000000000..9f0d4367371 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wqwq-7w88-r45v/GHSA-wqwq-7w88-r45v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqwq-7w88-r45v", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-42419" + ], + "details": "Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42419" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01233.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wr4g-hvjj-f7fp/GHSA-wr4g-hvjj-f7fp.json b/advisories/unreviewed/2025/02/GHSA-wr4g-hvjj-f7fp/GHSA-wr4g-hvjj-f7fp.json new file mode 100644 index 00000000000..42091ddebaa --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wr4g-hvjj-f7fp/GHSA-wr4g-hvjj-f7fp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr4g-hvjj-f7fp", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2024-57605" + ], + "details": "Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57605" + }, + { + "type": "WEB", + "url": "https://hkohi.ca/vulnerability/3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wwj6-8m7r-rqxf/GHSA-wwj6-8m7r-rqxf.json b/advisories/unreviewed/2025/02/GHSA-wwj6-8m7r-rqxf/GHSA-wwj6-8m7r-rqxf.json new file mode 100644 index 00000000000..bbb4425536b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wwj6-8m7r-rqxf/GHSA-wwj6-8m7r-rqxf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwj6-8m7r-rqxf", + "modified": "2025-02-13T00:33:04Z", + "published": "2025-02-13T00:33:04Z", + "aliases": [ + "CVE-2024-24852" + ], + "details": "Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24852" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01144.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wxg6-cwh7-4c8c/GHSA-wxg6-cwh7-4c8c.json b/advisories/unreviewed/2025/02/GHSA-wxg6-cwh7-4c8c/GHSA-wxg6-cwh7-4c8c.json new file mode 100644 index 00000000000..e1b8d823eb6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wxg6-cwh7-4c8c/GHSA-wxg6-cwh7-4c8c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxg6-cwh7-4c8c", + "modified": "2025-02-13T00:33:05Z", + "published": "2025-02-13T00:33:05Z", + "aliases": [ + "CVE-2024-36262" + ], + "details": "Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36262" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01203.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x2gp-2qw3-6f2v/GHSA-x2gp-2qw3-6f2v.json b/advisories/unreviewed/2025/02/GHSA-x2gp-2qw3-6f2v/GHSA-x2gp-2qw3-6f2v.json new file mode 100644 index 00000000000..1253ffa3d01 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x2gp-2qw3-6f2v/GHSA-x2gp-2qw3-6f2v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2gp-2qw3-6f2v", + "modified": "2025-02-13T00:33:06Z", + "published": "2025-02-13T00:33:06Z", + "aliases": [ + "CVE-2024-37355" + ], + "details": "Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37355" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01235.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xp5v-36w8-hwxm/GHSA-xp5v-36w8-hwxm.json b/advisories/unreviewed/2025/02/GHSA-xp5v-36w8-hwxm/GHSA-xp5v-36w8-hwxm.json new file mode 100644 index 00000000000..cff4037044b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xp5v-36w8-hwxm/GHSA-xp5v-36w8-hwxm.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp5v-36w8-hwxm", + "modified": "2025-02-13T00:33:07Z", + "published": "2025-02-13T00:33:07Z", + "aliases": [ + "CVE-2025-1228" + ], + "details": "A vulnerability classified as problematic has been found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Affected is an unknown function of the file /read/?page=1&logfile=LOG_Monitor of the component Logfile Update Handler. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1228" + }, + { + "type": "WEB", + "url": "https://gitee.com/olajowon/loggrove/issues/IBJSXS" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T22:15:41Z" + } +} \ No newline at end of file