diff --git a/advisories/unreviewed/2022/05/GHSA-rc4w-p9f6-7c7q/GHSA-rc4w-p9f6-7c7q.json b/advisories/unreviewed/2022/05/GHSA-rc4w-p9f6-7c7q/GHSA-rc4w-p9f6-7c7q.json index 78ffa779a0f..c2a6d5ae91a 100644 --- a/advisories/unreviewed/2022/05/GHSA-rc4w-p9f6-7c7q/GHSA-rc4w-p9f6-7c7q.json +++ b/advisories/unreviewed/2022/05/GHSA-rc4w-p9f6-7c7q/GHSA-rc4w-p9f6-7c7q.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-5jrc-78c2-4pq8/GHSA-5jrc-78c2-4pq8.json b/advisories/unreviewed/2024/02/GHSA-5jrc-78c2-4pq8/GHSA-5jrc-78c2-4pq8.json index 85d27a3ae23..e2ba710cedd 100644 --- a/advisories/unreviewed/2024/02/GHSA-5jrc-78c2-4pq8/GHSA-5jrc-78c2-4pq8.json +++ b/advisories/unreviewed/2024/02/GHSA-5jrc-78c2-4pq8/GHSA-5jrc-78c2-4pq8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h63h-pmj2-4jvv/GHSA-h63h-pmj2-4jvv.json b/advisories/unreviewed/2024/02/GHSA-h63h-pmj2-4jvv/GHSA-h63h-pmj2-4jvv.json index caf69f6f2c1..2bda89ba666 100644 --- a/advisories/unreviewed/2024/02/GHSA-h63h-pmj2-4jvv/GHSA-h63h-pmj2-4jvv.json +++ b/advisories/unreviewed/2024/02/GHSA-h63h-pmj2-4jvv/GHSA-h63h-pmj2-4jvv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-29x5-88xm-c43q/GHSA-29x5-88xm-c43q.json b/advisories/unreviewed/2024/05/GHSA-29x5-88xm-c43q/GHSA-29x5-88xm-c43q.json index 3ef51f8dc50..445e7815e1b 100644 --- a/advisories/unreviewed/2024/05/GHSA-29x5-88xm-c43q/GHSA-29x5-88xm-c43q.json +++ b/advisories/unreviewed/2024/05/GHSA-29x5-88xm-c43q/GHSA-29x5-88xm-c43q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29x5-88xm-c43q", - "modified": "2024-05-20T09:30:50Z", + "modified": "2025-02-10T15:32:15Z", "published": "2024-05-20T09:30:50Z", "aliases": [ "CVE-2024-5123" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-2wrg-v6wv-9q7f/GHSA-2wrg-v6wv-9q7f.json b/advisories/unreviewed/2024/05/GHSA-2wrg-v6wv-9q7f/GHSA-2wrg-v6wv-9q7f.json index 72f50982d74..cf5f9ab6e49 100644 --- a/advisories/unreviewed/2024/05/GHSA-2wrg-v6wv-9q7f/GHSA-2wrg-v6wv-9q7f.json +++ b/advisories/unreviewed/2024/05/GHSA-2wrg-v6wv-9q7f/GHSA-2wrg-v6wv-9q7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2wrg-v6wv-9q7f", - "modified": "2024-05-20T06:30:34Z", + "modified": "2025-02-10T15:32:14Z", "published": "2024-05-20T06:30:34Z", "aliases": [ "CVE-2024-5118" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-334h-3www-4425/GHSA-334h-3www-4425.json b/advisories/unreviewed/2024/05/GHSA-334h-3www-4425/GHSA-334h-3www-4425.json index 04a94fbbc8b..108e10c4931 100644 --- a/advisories/unreviewed/2024/05/GHSA-334h-3www-4425/GHSA-334h-3www-4425.json +++ b/advisories/unreviewed/2024/05/GHSA-334h-3www-4425/GHSA-334h-3www-4425.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-334h-3www-4425", - "modified": "2024-05-18T21:30:35Z", + "modified": "2025-02-10T15:32:12Z", "published": "2024-05-18T21:30:34Z", "aliases": [ "CVE-2024-5094" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-36qv-9gxf-hqxc/GHSA-36qv-9gxf-hqxc.json b/advisories/unreviewed/2024/05/GHSA-36qv-9gxf-hqxc/GHSA-36qv-9gxf-hqxc.json index 393106eb534..ae8bcbf3c30 100644 --- a/advisories/unreviewed/2024/05/GHSA-36qv-9gxf-hqxc/GHSA-36qv-9gxf-hqxc.json +++ b/advisories/unreviewed/2024/05/GHSA-36qv-9gxf-hqxc/GHSA-36qv-9gxf-hqxc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36qv-9gxf-hqxc", - "modified": "2024-05-16T09:33:07Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T09:33:07Z", "aliases": [ "CVE-2024-4966" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-4vwm-gcfx-wvpw/GHSA-4vwm-gcfx-wvpw.json b/advisories/unreviewed/2024/05/GHSA-4vwm-gcfx-wvpw/GHSA-4vwm-gcfx-wvpw.json index ad75da7ce81..3f863d49f9e 100644 --- a/advisories/unreviewed/2024/05/GHSA-4vwm-gcfx-wvpw/GHSA-4vwm-gcfx-wvpw.json +++ b/advisories/unreviewed/2024/05/GHSA-4vwm-gcfx-wvpw/GHSA-4vwm-gcfx-wvpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vwm-gcfx-wvpw", - "modified": "2024-05-16T06:30:51Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T06:30:51Z", "aliases": [ "CVE-2024-4946" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-52wr-2fpp-5m5m/GHSA-52wr-2fpp-5m5m.json b/advisories/unreviewed/2024/05/GHSA-52wr-2fpp-5m5m/GHSA-52wr-2fpp-5m5m.json index a3562b10275..a23520cf914 100644 --- a/advisories/unreviewed/2024/05/GHSA-52wr-2fpp-5m5m/GHSA-52wr-2fpp-5m5m.json +++ b/advisories/unreviewed/2024/05/GHSA-52wr-2fpp-5m5m/GHSA-52wr-2fpp-5m5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-52wr-2fpp-5m5m", - "modified": "2024-05-20T09:30:50Z", + "modified": "2025-02-10T15:32:15Z", "published": "2024-05-20T09:30:50Z", "aliases": [ "CVE-2024-5122" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-53w5-qqw7-7gxj/GHSA-53w5-qqw7-7gxj.json b/advisories/unreviewed/2024/05/GHSA-53w5-qqw7-7gxj/GHSA-53w5-qqw7-7gxj.json index 718f98d825c..2cda2bd17c3 100644 --- a/advisories/unreviewed/2024/05/GHSA-53w5-qqw7-7gxj/GHSA-53w5-qqw7-7gxj.json +++ b/advisories/unreviewed/2024/05/GHSA-53w5-qqw7-7gxj/GHSA-53w5-qqw7-7gxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53w5-qqw7-7gxj", - "modified": "2024-05-20T06:30:34Z", + "modified": "2025-02-10T15:32:14Z", "published": "2024-05-20T06:30:34Z", "aliases": [ "CVE-2024-5119" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json b/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json index 582fad9b856..5353e0d2ac6 100644 --- a/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json +++ b/advisories/unreviewed/2024/05/GHSA-68x2-v9x5-vw53/GHSA-68x2-v9x5-vw53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68x2-v9x5-vw53", - "modified": "2024-05-17T15:31:08Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-17T15:31:08Z", "aliases": [ "CVE-2024-5046" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-6f9v-qjpx-j4pc/GHSA-6f9v-qjpx-j4pc.json b/advisories/unreviewed/2024/05/GHSA-6f9v-qjpx-j4pc/GHSA-6f9v-qjpx-j4pc.json index 985dd539e29..ff7e80a091c 100644 --- a/advisories/unreviewed/2024/05/GHSA-6f9v-qjpx-j4pc/GHSA-6f9v-qjpx-j4pc.json +++ b/advisories/unreviewed/2024/05/GHSA-6f9v-qjpx-j4pc/GHSA-6f9v-qjpx-j4pc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6f9v-qjpx-j4pc", - "modified": "2024-05-20T06:30:34Z", + "modified": "2025-02-10T15:32:14Z", "published": "2024-05-20T06:30:34Z", "aliases": [ "CVE-2024-5117" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-6grx-4j6r-rxx4/GHSA-6grx-4j6r-rxx4.json b/advisories/unreviewed/2024/05/GHSA-6grx-4j6r-rxx4/GHSA-6grx-4j6r-rxx4.json index c5d390bf757..44de674505f 100644 --- a/advisories/unreviewed/2024/05/GHSA-6grx-4j6r-rxx4/GHSA-6grx-4j6r-rxx4.json +++ b/advisories/unreviewed/2024/05/GHSA-6grx-4j6r-rxx4/GHSA-6grx-4j6r-rxx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6grx-4j6r-rxx4", - "modified": "2024-05-20T06:30:34Z", + "modified": "2025-02-10T15:32:15Z", "published": "2024-05-20T06:30:34Z", "aliases": [ "CVE-2024-5120" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-6xw9-wghr-5p6r/GHSA-6xw9-wghr-5p6r.json b/advisories/unreviewed/2024/05/GHSA-6xw9-wghr-5p6r/GHSA-6xw9-wghr-5p6r.json index 23c76e9e185..6df47a69b02 100644 --- a/advisories/unreviewed/2024/05/GHSA-6xw9-wghr-5p6r/GHSA-6xw9-wghr-5p6r.json +++ b/advisories/unreviewed/2024/05/GHSA-6xw9-wghr-5p6r/GHSA-6xw9-wghr-5p6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xw9-wghr-5p6r", - "modified": "2024-05-16T03:30:45Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T03:30:44Z", "aliases": [ "CVE-2024-4926" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7v78-784x-w6p3/GHSA-7v78-784x-w6p3.json b/advisories/unreviewed/2024/05/GHSA-7v78-784x-w6p3/GHSA-7v78-784x-w6p3.json index f74cbc3dc8e..71616387c85 100644 --- a/advisories/unreviewed/2024/05/GHSA-7v78-784x-w6p3/GHSA-7v78-784x-w6p3.json +++ b/advisories/unreviewed/2024/05/GHSA-7v78-784x-w6p3/GHSA-7v78-784x-w6p3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v78-784x-w6p3", - "modified": "2024-05-19T06:31:55Z", + "modified": "2025-02-10T15:32:13Z", "published": "2024-05-19T06:31:55Z", "aliases": [ "CVE-2024-5098" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-82hf-rjv3-p249/GHSA-82hf-rjv3-p249.json b/advisories/unreviewed/2024/05/GHSA-82hf-rjv3-p249/GHSA-82hf-rjv3-p249.json index 2f0a3b0b924..764bca6a4b7 100644 --- a/advisories/unreviewed/2024/05/GHSA-82hf-rjv3-p249/GHSA-82hf-rjv3-p249.json +++ b/advisories/unreviewed/2024/05/GHSA-82hf-rjv3-p249/GHSA-82hf-rjv3-p249.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-82hf-rjv3-p249", - "modified": "2024-05-16T06:30:50Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T06:30:50Z", "aliases": [ "CVE-2024-4945" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -38,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-88pr-jxqf-jwjw/GHSA-88pr-jxqf-jwjw.json b/advisories/unreviewed/2024/05/GHSA-88pr-jxqf-jwjw/GHSA-88pr-jxqf-jwjw.json index b19329858f3..840b3657d5f 100644 --- a/advisories/unreviewed/2024/05/GHSA-88pr-jxqf-jwjw/GHSA-88pr-jxqf-jwjw.json +++ b/advisories/unreviewed/2024/05/GHSA-88pr-jxqf-jwjw/GHSA-88pr-jxqf-jwjw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88pr-jxqf-jwjw", - "modified": "2024-05-20T06:30:34Z", + "modified": "2025-02-10T15:32:14Z", "published": "2024-05-20T06:30:34Z", "aliases": [ "CVE-2024-5116" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-89qm-pg8x-wj9m/GHSA-89qm-pg8x-wj9m.json b/advisories/unreviewed/2024/05/GHSA-89qm-pg8x-wj9m/GHSA-89qm-pg8x-wj9m.json index ea79eafb0f5..3cdb5b69edf 100644 --- a/advisories/unreviewed/2024/05/GHSA-89qm-pg8x-wj9m/GHSA-89qm-pg8x-wj9m.json +++ b/advisories/unreviewed/2024/05/GHSA-89qm-pg8x-wj9m/GHSA-89qm-pg8x-wj9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89qm-pg8x-wj9m", - "modified": "2024-05-19T09:34:45Z", + "modified": "2025-02-10T15:32:13Z", "published": "2024-05-19T09:34:45Z", "aliases": [ "CVE-2024-5099" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-8gh2-6pxg-ww94/GHSA-8gh2-6pxg-ww94.json b/advisories/unreviewed/2024/05/GHSA-8gh2-6pxg-ww94/GHSA-8gh2-6pxg-ww94.json index b1014022bd7..33cc66021c6 100644 --- a/advisories/unreviewed/2024/05/GHSA-8gh2-6pxg-ww94/GHSA-8gh2-6pxg-ww94.json +++ b/advisories/unreviewed/2024/05/GHSA-8gh2-6pxg-ww94/GHSA-8gh2-6pxg-ww94.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gh2-6pxg-ww94", - "modified": "2024-05-16T09:33:09Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T09:33:09Z", "aliases": [ "CVE-2024-4968" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json b/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json index 0357fb2cb9b..19e71cfcb20 100644 --- a/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json +++ b/advisories/unreviewed/2024/05/GHSA-cxjp-8rhj-f8c5/GHSA-cxjp-8rhj-f8c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxjp-8rhj-f8c5", - "modified": "2024-05-17T15:31:08Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-17T15:31:08Z", "aliases": [ "CVE-2024-5045" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-fwm8-cg5f-xc9c/GHSA-fwm8-cg5f-xc9c.json b/advisories/unreviewed/2024/05/GHSA-fwm8-cg5f-xc9c/GHSA-fwm8-cg5f-xc9c.json index 54f0bb8cb03..8630d6527b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-fwm8-cg5f-xc9c/GHSA-fwm8-cg5f-xc9c.json +++ b/advisories/unreviewed/2024/05/GHSA-fwm8-cg5f-xc9c/GHSA-fwm8-cg5f-xc9c.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fwm8-cg5f-xc9c", - "modified": "2024-05-02T15:30:35Z", + "modified": "2025-02-10T15:32:09Z", "published": "2024-05-02T15:30:35Z", "aliases": [ "CVE-2024-3543" ], - "details": "\nUse of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.\n\n", + "details": "Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.", "severity": [ { "type": "CVSS_V3", @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-257" + "CWE-257", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-gcmx-rh8w-85v2/GHSA-gcmx-rh8w-85v2.json b/advisories/unreviewed/2024/05/GHSA-gcmx-rh8w-85v2/GHSA-gcmx-rh8w-85v2.json index 4b2abc6eef6..94e03e613ad 100644 --- a/advisories/unreviewed/2024/05/GHSA-gcmx-rh8w-85v2/GHSA-gcmx-rh8w-85v2.json +++ b/advisories/unreviewed/2024/05/GHSA-gcmx-rh8w-85v2/GHSA-gcmx-rh8w-85v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcmx-rh8w-85v2", - "modified": "2024-05-19T03:30:34Z", + "modified": "2025-02-10T15:32:12Z", "published": "2024-05-19T03:30:33Z", "aliases": [ "CVE-2024-5097" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-h46v-63q8-chhv/GHSA-h46v-63q8-chhv.json b/advisories/unreviewed/2024/05/GHSA-h46v-63q8-chhv/GHSA-h46v-63q8-chhv.json index 9f88c34458a..5583ce6cb23 100644 --- a/advisories/unreviewed/2024/05/GHSA-h46v-63q8-chhv/GHSA-h46v-63q8-chhv.json +++ b/advisories/unreviewed/2024/05/GHSA-h46v-63q8-chhv/GHSA-h46v-63q8-chhv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h46v-63q8-chhv", - "modified": "2024-05-19T12:30:39Z", + "modified": "2025-02-10T15:32:13Z", "published": "2024-05-19T12:30:39Z", "aliases": [ "CVE-2024-5100" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json b/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json index 6d944a20a64..acf0e3b2bb4 100644 --- a/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json +++ b/advisories/unreviewed/2024/05/GHSA-hw9q-4579-p566/GHSA-hw9q-4579-p566.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9q-4579-p566", - "modified": "2024-05-17T15:31:12Z", + "modified": "2025-02-10T15:32:12Z", "published": "2024-05-17T15:31:12Z", "aliases": [ "CVE-2024-5051" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-m2gh-p757-6rf2/GHSA-m2gh-p757-6rf2.json b/advisories/unreviewed/2024/05/GHSA-m2gh-p757-6rf2/GHSA-m2gh-p757-6rf2.json index d68f792954c..0305b5fa923 100644 --- a/advisories/unreviewed/2024/05/GHSA-m2gh-p757-6rf2/GHSA-m2gh-p757-6rf2.json +++ b/advisories/unreviewed/2024/05/GHSA-m2gh-p757-6rf2/GHSA-m2gh-p757-6rf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2gh-p757-6rf2", - "modified": "2024-05-16T03:30:44Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T03:30:44Z", "aliases": [ "CVE-2024-4922" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-pcp6-6739-hm3f/GHSA-pcp6-6739-hm3f.json b/advisories/unreviewed/2024/05/GHSA-pcp6-6739-hm3f/GHSA-pcp6-6739-hm3f.json index d5b69315f46..8ef0b2d7a87 100644 --- a/advisories/unreviewed/2024/05/GHSA-pcp6-6739-hm3f/GHSA-pcp6-6739-hm3f.json +++ b/advisories/unreviewed/2024/05/GHSA-pcp6-6739-hm3f/GHSA-pcp6-6739-hm3f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcp6-6739-hm3f", - "modified": "2024-05-18T21:30:35Z", + "modified": "2025-02-10T15:32:12Z", "published": "2024-05-18T21:30:34Z", "aliases": [ "CVE-2024-5093" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-px9h-g363-q9hw/GHSA-px9h-g363-q9hw.json b/advisories/unreviewed/2024/05/GHSA-px9h-g363-q9hw/GHSA-px9h-g363-q9hw.json index 6b3336cee2b..c4e8b19633a 100644 --- a/advisories/unreviewed/2024/05/GHSA-px9h-g363-q9hw/GHSA-px9h-g363-q9hw.json +++ b/advisories/unreviewed/2024/05/GHSA-px9h-g363-q9hw/GHSA-px9h-g363-q9hw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-px9h-g363-q9hw", - "modified": "2024-05-16T03:30:44Z", + "modified": "2025-02-10T15:32:10Z", "published": "2024-05-16T03:30:44Z", "aliases": [ "CVE-2024-4921" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-q7q5-hvh8-gjh4/GHSA-q7q5-hvh8-gjh4.json b/advisories/unreviewed/2024/05/GHSA-q7q5-hvh8-gjh4/GHSA-q7q5-hvh8-gjh4.json index c594f142c3a..522822b7bc0 100644 --- a/advisories/unreviewed/2024/05/GHSA-q7q5-hvh8-gjh4/GHSA-q7q5-hvh8-gjh4.json +++ b/advisories/unreviewed/2024/05/GHSA-q7q5-hvh8-gjh4/GHSA-q7q5-hvh8-gjh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7q5-hvh8-gjh4", - "modified": "2024-05-16T00:32:03Z", + "modified": "2025-02-10T15:32:10Z", "published": "2024-05-16T00:32:03Z", "aliases": [ "CVE-2024-4920" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-r9m3-wwfj-6962/GHSA-r9m3-wwfj-6962.json b/advisories/unreviewed/2024/05/GHSA-r9m3-wwfj-6962/GHSA-r9m3-wwfj-6962.json index c3111359327..7c371cad996 100644 --- a/advisories/unreviewed/2024/05/GHSA-r9m3-wwfj-6962/GHSA-r9m3-wwfj-6962.json +++ b/advisories/unreviewed/2024/05/GHSA-r9m3-wwfj-6962/GHSA-r9m3-wwfj-6962.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9m3-wwfj-6962", - "modified": "2024-05-20T09:30:50Z", + "modified": "2025-02-10T15:32:15Z", "published": "2024-05-20T09:30:49Z", "aliases": [ "CVE-2024-5121" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-w9m6-fh4g-pg7r/GHSA-w9m6-fh4g-pg7r.json b/advisories/unreviewed/2024/05/GHSA-w9m6-fh4g-pg7r/GHSA-w9m6-fh4g-pg7r.json index 3b16712d262..80f88e53629 100644 --- a/advisories/unreviewed/2024/05/GHSA-w9m6-fh4g-pg7r/GHSA-w9m6-fh4g-pg7r.json +++ b/advisories/unreviewed/2024/05/GHSA-w9m6-fh4g-pg7r/GHSA-w9m6-fh4g-pg7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9m6-fh4g-pg7r", - "modified": "2024-05-16T09:33:09Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T09:33:09Z", "aliases": [ "CVE-2024-4967" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-wfr2-g3j3-8w7v/GHSA-wfr2-g3j3-8w7v.json b/advisories/unreviewed/2024/05/GHSA-wfr2-g3j3-8w7v/GHSA-wfr2-g3j3-8w7v.json index a4bec945a1d..879a2edc2f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-wfr2-g3j3-8w7v/GHSA-wfr2-g3j3-8w7v.json +++ b/advisories/unreviewed/2024/05/GHSA-wfr2-g3j3-8w7v/GHSA-wfr2-g3j3-8w7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wfr2-g3j3-8w7v", - "modified": "2024-05-21T00:30:51Z", + "modified": "2025-02-10T15:32:16Z", "published": "2024-05-21T00:30:51Z", "aliases": [ "CVE-2024-5145" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-wh2x-972h-6xmh/GHSA-wh2x-972h-6xmh.json b/advisories/unreviewed/2024/05/GHSA-wh2x-972h-6xmh/GHSA-wh2x-972h-6xmh.json index a81b1296b03..90ffaa34ffe 100644 --- a/advisories/unreviewed/2024/05/GHSA-wh2x-972h-6xmh/GHSA-wh2x-972h-6xmh.json +++ b/advisories/unreviewed/2024/05/GHSA-wh2x-972h-6xmh/GHSA-wh2x-972h-6xmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wh2x-972h-6xmh", - "modified": "2024-05-19T15:30:38Z", + "modified": "2025-02-10T15:32:14Z", "published": "2024-05-19T15:30:38Z", "aliases": [ "CVE-2024-5101" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json b/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json index b1f325af833..cdd0fe1b186 100644 --- a/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json +++ b/advisories/unreviewed/2024/05/GHSA-x5m5-jxc3-3g5c/GHSA-x5m5-jxc3-3g5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5m5-jxc3-3g5c", - "modified": "2024-05-17T15:31:11Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-17T15:31:10Z", "aliases": [ "CVE-2024-5047" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-xp32-h6c2-42q9/GHSA-xp32-h6c2-42q9.json b/advisories/unreviewed/2024/05/GHSA-xp32-h6c2-42q9/GHSA-xp32-h6c2-42q9.json index 89c9db0d924..939e26646e5 100644 --- a/advisories/unreviewed/2024/05/GHSA-xp32-h6c2-42q9/GHSA-xp32-h6c2-42q9.json +++ b/advisories/unreviewed/2024/05/GHSA-xp32-h6c2-42q9/GHSA-xp32-h6c2-42q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xp32-h6c2-42q9", - "modified": "2024-05-16T03:30:45Z", + "modified": "2025-02-10T15:32:11Z", "published": "2024-05-16T03:30:45Z", "aliases": [ "CVE-2024-4925" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/01/GHSA-35ff-c49r-m93w/GHSA-35ff-c49r-m93w.json b/advisories/unreviewed/2025/01/GHSA-35ff-c49r-m93w/GHSA-35ff-c49r-m93w.json index db6e2a56a71..a1e60c516ed 100644 --- a/advisories/unreviewed/2025/01/GHSA-35ff-c49r-m93w/GHSA-35ff-c49r-m93w.json +++ b/advisories/unreviewed/2025/01/GHSA-35ff-c49r-m93w/GHSA-35ff-c49r-m93w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json b/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json index be49532d551..00081eaf99e 100644 --- a/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json +++ b/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r8x-g2v5-x892", - "modified": "2025-02-06T18:31:05Z", + "modified": "2025-02-10T15:32:19Z", "published": "2025-02-06T18:31:05Z", "aliases": [ "CVE-2024-36557" ], "details": "The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T18:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json b/advisories/unreviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json index 06f73ad2c0d..86f1af34f4d 100644 --- a/advisories/unreviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json +++ b/advisories/unreviewed/2025/02/GHSA-4c37-7m5h-c8m9/GHSA-4c37-7m5h-c8m9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4c37-7m5h-c8m9", - "modified": "2025-02-10T12:30:45Z", + "modified": "2025-02-10T15:32:19Z", "published": "2025-02-10T12:30:45Z", "aliases": [ "CVE-2025-25247" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.\n\nThis issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8.\n\nUsers are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T12:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6w6c-5vv5-gw2w/GHSA-6w6c-5vv5-gw2w.json b/advisories/unreviewed/2025/02/GHSA-6w6c-5vv5-gw2w/GHSA-6w6c-5vv5-gw2w.json new file mode 100644 index 00000000000..abf341d873d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6w6c-5vv5-gw2w/GHSA-6w6c-5vv5-gw2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w6c-5vv5-gw2w", + "modified": "2025-02-10T15:32:20Z", + "published": "2025-02-10T15:32:20Z", + "aliases": [ + "CVE-2024-8684" + ], + "details": "OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to execute OS commands on the device via the ‘php/dal.php’ endpoint, in the ‘arrSaveConfig’ parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8684" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-kunbus-gmbhs-revolution-pi" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7348-rmw4-rhvw/GHSA-7348-rmw4-rhvw.json b/advisories/unreviewed/2025/02/GHSA-7348-rmw4-rhvw/GHSA-7348-rmw4-rhvw.json new file mode 100644 index 00000000000..01236e5268d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7348-rmw4-rhvw/GHSA-7348-rmw4-rhvw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7348-rmw4-rhvw", + "modified": "2025-02-10T15:32:22Z", + "published": "2025-02-10T15:32:22Z", + "aliases": [ + "CVE-2024-10334" + ], + "details": "A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used. \n\nAn attacker who successfully exploited the vulnerability could, in the worst case scenario, stop or manipulate the video feed.\nThis issue affects System 800xA: 5.1.X; System 800xA: 6.0.3.X; System 800xA: 6.1.1.X; System 800xA: 6.2.X.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10334" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=7PAA012159&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json b/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json new file mode 100644 index 00000000000..d6262df84e6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73x9-xqqp-w963", + "modified": "2025-02-10T15:32:22Z", + "published": "2025-02-10T15:32:22Z", + "aliases": [ + "CVE-2025-1147" + ], + "details": "A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1147" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15881" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485254" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gmxm-43jx-6cmc/GHSA-gmxm-43jx-6cmc.json b/advisories/unreviewed/2025/02/GHSA-gmxm-43jx-6cmc/GHSA-gmxm-43jx-6cmc.json new file mode 100644 index 00000000000..538add5cd72 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gmxm-43jx-6cmc/GHSA-gmxm-43jx-6cmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmxm-43jx-6cmc", + "modified": "2025-02-10T15:32:20Z", + "published": "2025-02-10T15:32:20Z", + "aliases": [ + "CVE-2025-1175" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions between 3.2C and 5.1K. This vulnerability could allow an attacker to execute a JavaScript payload by making a POST request and injecting malicious code into the editable ‘username’ parameter of the ‘/PageLoginVisio.do’ endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1175" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-kelio-visio" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json b/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json new file mode 100644 index 00000000000..99425c874b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqj6-fppc-vr34", + "modified": "2025-02-10T15:32:22Z", + "published": "2025-02-10T15:32:22Z", + "aliases": [ + "CVE-2025-1148" + ], + "details": "A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1148" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15887" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32576" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485747" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gvgm-vg2q-4mrw/GHSA-gvgm-vg2q-4mrw.json b/advisories/unreviewed/2025/02/GHSA-gvgm-vg2q-4mrw/GHSA-gvgm-vg2q-4mrw.json new file mode 100644 index 00000000000..d8f614f42b9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gvgm-vg2q-4mrw/GHSA-gvgm-vg2q-4mrw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvgm-vg2q-4mrw", + "modified": "2025-02-10T15:32:21Z", + "published": "2025-02-10T15:32:21Z", + "aliases": [ + "CVE-2024-11621" + ], + "details": "Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack.\n\nVersions affected are :\nRemote Desktop Manager macOS 2024.3.9.0 and earlier\nRemote Desktop Manager Linux 2024.3.2.5 and earlier\nRemote Desktop Manager Android 2024.3.3.7 and earlier\nRemote Desktop Manager iOS 2024.3.3.0 and earlier\n\nRemote Desktop Manager Powershell 2024.3.6.0 and earlier", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11621" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jq4h-5chq-vxw8/GHSA-jq4h-5chq-vxw8.json b/advisories/unreviewed/2025/02/GHSA-jq4h-5chq-vxw8/GHSA-jq4h-5chq-vxw8.json new file mode 100644 index 00000000000..67839b2c3e8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jq4h-5chq-vxw8/GHSA-jq4h-5chq-vxw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq4h-5chq-vxw8", + "modified": "2025-02-10T15:32:20Z", + "published": "2025-02-10T15:32:20Z", + "aliases": [ + "CVE-2024-8685" + ], + "details": "Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8685" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-kunbus-gmbhs-revolution-pi" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json b/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json index 00b8b67bac2..5a51055f44e 100644 --- a/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json +++ b/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mr5r-6xxx-6h84", - "modified": "2025-02-06T18:31:06Z", + "modified": "2025-02-10T15:32:19Z", "published": "2025-02-06T18:31:05Z", "aliases": [ "CVE-2024-36554" ], "details": "Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-497" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T18:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json b/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json index 112f3c34c08..843f22732db 100644 --- a/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json +++ b/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3wg-39gf-vffc", - "modified": "2025-02-06T18:31:05Z", + "modified": "2025-02-10T15:32:19Z", "published": "2025-02-06T18:31:05Z", "aliases": [ "CVE-2024-36555" ], "details": "Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity of the device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T18:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v3wx-9j8m-4934/GHSA-v3wx-9j8m-4934.json b/advisories/unreviewed/2025/02/GHSA-v3wx-9j8m-4934/GHSA-v3wx-9j8m-4934.json new file mode 100644 index 00000000000..5bf9d784547 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v3wx-9j8m-4934/GHSA-v3wx-9j8m-4934.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3wx-9j8m-4934", + "modified": "2025-02-10T15:32:22Z", + "published": "2025-02-10T15:32:22Z", + "aliases": [ + "CVE-2025-1193" + ], + "details": "Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack \nby presenting a certificate for a different host.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1193" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vwfw-r6qw-22rw/GHSA-vwfw-r6qw-22rw.json b/advisories/unreviewed/2025/02/GHSA-vwfw-r6qw-22rw/GHSA-vwfw-r6qw-22rw.json new file mode 100644 index 00000000000..79aa87fa762 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vwfw-r6qw-22rw/GHSA-vwfw-r6qw-22rw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwfw-r6qw-22rw", + "modified": "2025-02-10T15:32:22Z", + "published": "2025-02-10T15:32:22Z", + "aliases": [ + "CVE-2025-1149" + ], + "details": "A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1149" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15887" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32576" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295053" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295053" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T15:15:13Z" + } +} \ No newline at end of file