From 2c0b09f15f065c4396ee2985fc55e90386f7c55d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 17 Mar 2025 21:32:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7c8f-5r89-mjgx.json | 9 ++- .../GHSA-3c7c-p4m9-gwhc.json | 2 +- .../GHSA-fj8r-46q3-hp4r.json | 2 +- .../GHSA-fp7x-pqr7-6fpj.json | 2 +- .../GHSA-q74f-hvfr-7jqc.json | 2 +- .../GHSA-rcch-h9m9-rwjw.json | 3 +- .../GHSA-p6hw-8jfc-qq89.json | 4 +- .../GHSA-9hgh-cqm9-hh6h.json | 4 +- .../GHSA-89gm-fv57-9hjw.json | 4 +- .../GHSA-rxjf-75rj-r875.json | 4 +- .../GHSA-2v89-wpgr-r5vm.json | 15 ++-- .../GHSA-4f7j-px6v-m38x.json | 15 ++-- .../GHSA-5p75-8vmp-h6xw.json | 15 ++-- .../GHSA-7jh3-f4p5-7prm.json | 15 ++-- .../GHSA-7pxw-57qc-2vjm.json | 15 ++-- .../GHSA-9rhh-9h7r-f9gf.json | 15 ++-- .../GHSA-c442-c8m7-hp5v.json | 15 ++-- .../GHSA-fc4h-jq3v-6rrg.json | 15 ++-- .../GHSA-g674-vjfp-rx8j.json | 15 ++-- .../GHSA-gjw5-w65f-c5gw.json | 15 ++-- .../GHSA-qvrx-p9gg-46f8.json | 15 ++-- .../GHSA-xjpw-qmp3-4x22.json | 15 ++-- .../GHSA-xp8w-5r26-q5qh.json | 15 ++-- .../GHSA-2j7h-v8wc-gmgr.json | 15 ++-- .../GHSA-33f4-xj2w-x86q.json | 52 ++++++++++++++ .../GHSA-38cq-v43p-vhvf.json | 56 +++++++++++++++ .../GHSA-3c2x-g6mp-5gcv.json | 15 ++-- .../GHSA-3h28-663g-h6cx.json | 56 +++++++++++++++ .../GHSA-3jqw-73hh-rjm4.json | 29 ++++++++ .../GHSA-3rw8-4xrq-3f7p.json | 33 +++++++++ .../GHSA-4hqj-96cj-gmwp.json | 52 ++++++++++++++ .../GHSA-54v8-qjwx-hj66.json | 16 +++-- .../GHSA-54vm-jhgv-phv5.json | 48 +++++++++++++ .../GHSA-5g2r-4fp2-x498.json | 11 ++- .../GHSA-622v-pr25-m36f.json | 62 +++++++++++++++++ .../GHSA-6735-jgp5-qf5j.json | 52 ++++++++++++++ .../GHSA-67jw-xp2p-xpv9.json | 38 +++++++++++ .../GHSA-6f67-378m-2772.json | 29 ++++++++ .../GHSA-6gpc-pr73-3q2j.json | 36 ++++++++++ .../GHSA-7wv3-wp67-hwwp.json | 66 ++++++++++++++++++ .../GHSA-8j69-hcq4-p2fc.json | 56 +++++++++++++++ .../GHSA-9rw4-jg9w-jw2g.json | 15 ++-- .../GHSA-c3m4-xrx9-mwc5.json | 15 ++-- .../GHSA-cfrr-86xw-mjgp.json | 37 ++++++++++ .../GHSA-f7q7-fjw5-wrf4.json | 46 +++++++++++++ .../GHSA-f9q9-85g5-cwgj.json | 45 ++++++++++++ .../GHSA-g72j-3qqx-86gg.json | 66 ++++++++++++++++++ .../GHSA-ghrp-fhch-vvr7.json | 40 +++++++++++ .../GHSA-h8cc-85qr-g7ff.json | 46 +++++++++++++ .../GHSA-jcrc-wc7g-62pw.json | 15 ++-- .../GHSA-m439-5w5w-f32v.json | 40 +++++++++++ .../GHSA-m6q7-6hrv-f732.json | 48 +++++++++++++ .../GHSA-mgjf-p92m-4xxw.json | 46 +++++++++++++ .../GHSA-pj4h-hmj2-pj85.json | 29 ++++++++ .../GHSA-q28f-p3wj-9rm8.json | 29 ++++++++ .../GHSA-q656-wcrg-wwx4.json | 40 +++++++++++ .../GHSA-q7vq-qpq4-684g.json | 29 ++++++++ .../GHSA-q9jg-pgrj-wq8v.json | 15 ++-- .../GHSA-qj2x-5f28-cg38.json | 68 +++++++++++++++++++ .../GHSA-r398-vw7q-9j92.json | 29 ++++++++ .../GHSA-rrxc-83pc-mr58.json | 40 +++++++++++ .../GHSA-v9vj-4w4v-xqvj.json | 56 +++++++++++++++ .../GHSA-vq76-vp85-3v38.json | 66 ++++++++++++++++++ .../GHSA-w4r7-mmm7-q5mj.json | 29 ++++++++ .../GHSA-x43f-46qx-3qx9.json | 56 +++++++++++++++ .../GHSA-xcfp-c436-mm2r.json | 11 ++- .../GHSA-xmrj-2g7q-5pcq.json | 50 ++++++++++++++ .../GHSA-xpwf-pw24-jcwf.json | 48 +++++++++++++ .../GHSA-xw57-qhqx-v67p.json | 33 +++++++++ 69 files changed, 1943 insertions(+), 97 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-33f4-xj2w-x86q/GHSA-33f4-xj2w-x86q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38cq-v43p-vhvf/GHSA-38cq-v43p-vhvf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3rw8-4xrq-3f7p/GHSA-3rw8-4xrq-3f7p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4hqj-96cj-gmwp/GHSA-4hqj-96cj-gmwp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-54vm-jhgv-phv5/GHSA-54vm-jhgv-phv5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-622v-pr25-m36f/GHSA-622v-pr25-m36f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6735-jgp5-qf5j/GHSA-6735-jgp5-qf5j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-67jw-xp2p-xpv9/GHSA-67jw-xp2p-xpv9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6gpc-pr73-3q2j/GHSA-6gpc-pr73-3q2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7wv3-wp67-hwwp/GHSA-7wv3-wp67-hwwp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cfrr-86xw-mjgp/GHSA-cfrr-86xw-mjgp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f7q7-fjw5-wrf4/GHSA-f7q7-fjw5-wrf4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g72j-3qqx-86gg/GHSA-g72j-3qqx-86gg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ghrp-fhch-vvr7/GHSA-ghrp-fhch-vvr7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h8cc-85qr-g7ff/GHSA-h8cc-85qr-g7ff.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m439-5w5w-f32v/GHSA-m439-5w5w-f32v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m6q7-6hrv-f732/GHSA-m6q7-6hrv-f732.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mgjf-p92m-4xxw/GHSA-mgjf-p92m-4xxw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pj4h-hmj2-pj85/GHSA-pj4h-hmj2-pj85.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q656-wcrg-wwx4/GHSA-q656-wcrg-wwx4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q7vq-qpq4-684g/GHSA-q7vq-qpq4-684g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qj2x-5f28-cg38/GHSA-qj2x-5f28-cg38.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rrxc-83pc-mr58/GHSA-rrxc-83pc-mr58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vq76-vp85-3v38/GHSA-vq76-vp85-3v38.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x43f-46qx-3qx9/GHSA-x43f-46qx-3qx9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xmrj-2g7q-5pcq/GHSA-xmrj-2g7q-5pcq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xpwf-pw24-jcwf/GHSA-xpwf-pw24-jcwf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json diff --git a/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json b/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json index 18a9a43e52e..03664321ddc 100644 --- a/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json +++ b/advisories/unreviewed/2022/05/GHSA-7c8f-5r89-mjgx/GHSA-7c8f-5r89-mjgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c8f-5r89-mjgx", - "modified": "2022-10-21T19:01:13Z", + "modified": "2025-03-17T21:30:21Z", "published": "2022-05-24T17:37:22Z", "aliases": [ "CVE-2020-10148" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://kb.cert.org/vuls/id/843464" }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/843464" + }, { "type": "WEB", "url": "https://www.solarwinds.com/securityadvisory" @@ -31,7 +35,8 @@ "database_specific": { "cwe_ids": [ "CWE-287", - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-3c7c-p4m9-gwhc/GHSA-3c7c-p4m9-gwhc.json b/advisories/unreviewed/2023/02/GHSA-3c7c-p4m9-gwhc/GHSA-3c7c-p4m9-gwhc.json index 5e730c2e50f..2926c5a1e72 100644 --- a/advisories/unreviewed/2023/02/GHSA-3c7c-p4m9-gwhc/GHSA-3c7c-p4m9-gwhc.json +++ b/advisories/unreviewed/2023/02/GHSA-3c7c-p4m9-gwhc/GHSA-3c7c-p4m9-gwhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3c7c-p4m9-gwhc", - "modified": "2023-03-06T18:30:20Z", + "modified": "2025-03-17T21:30:23Z", "published": "2023-02-24T00:30:16Z", "aliases": [ "CVE-2023-23296" diff --git a/advisories/unreviewed/2023/02/GHSA-fj8r-46q3-hp4r/GHSA-fj8r-46q3-hp4r.json b/advisories/unreviewed/2023/02/GHSA-fj8r-46q3-hp4r/GHSA-fj8r-46q3-hp4r.json index 84795d7c630..004688d1c83 100644 --- a/advisories/unreviewed/2023/02/GHSA-fj8r-46q3-hp4r/GHSA-fj8r-46q3-hp4r.json +++ b/advisories/unreviewed/2023/02/GHSA-fj8r-46q3-hp4r/GHSA-fj8r-46q3-hp4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj8r-46q3-hp4r", - "modified": "2023-03-03T21:30:18Z", + "modified": "2025-03-17T21:30:22Z", "published": "2023-02-23T21:30:16Z", "aliases": [ "CVE-2023-23920" diff --git a/advisories/unreviewed/2023/02/GHSA-fp7x-pqr7-6fpj/GHSA-fp7x-pqr7-6fpj.json b/advisories/unreviewed/2023/02/GHSA-fp7x-pqr7-6fpj/GHSA-fp7x-pqr7-6fpj.json index 0e0c6054bdb..88aed03e91a 100644 --- a/advisories/unreviewed/2023/02/GHSA-fp7x-pqr7-6fpj/GHSA-fp7x-pqr7-6fpj.json +++ b/advisories/unreviewed/2023/02/GHSA-fp7x-pqr7-6fpj/GHSA-fp7x-pqr7-6fpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp7x-pqr7-6fpj", - "modified": "2023-02-28T21:30:17Z", + "modified": "2025-03-17T21:30:21Z", "published": "2023-02-18T03:30:17Z", "aliases": [ "CVE-2022-40348" diff --git a/advisories/unreviewed/2023/02/GHSA-q74f-hvfr-7jqc/GHSA-q74f-hvfr-7jqc.json b/advisories/unreviewed/2023/02/GHSA-q74f-hvfr-7jqc/GHSA-q74f-hvfr-7jqc.json index 5ac185a9efc..93caa13513f 100644 --- a/advisories/unreviewed/2023/02/GHSA-q74f-hvfr-7jqc/GHSA-q74f-hvfr-7jqc.json +++ b/advisories/unreviewed/2023/02/GHSA-q74f-hvfr-7jqc/GHSA-q74f-hvfr-7jqc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q74f-hvfr-7jqc", - "modified": "2023-03-06T21:30:19Z", + "modified": "2025-03-17T21:30:22Z", "published": "2023-02-24T00:30:16Z", "aliases": [ "CVE-2023-23295" diff --git a/advisories/unreviewed/2023/03/GHSA-rcch-h9m9-rwjw/GHSA-rcch-h9m9-rwjw.json b/advisories/unreviewed/2023/03/GHSA-rcch-h9m9-rwjw/GHSA-rcch-h9m9-rwjw.json index 6fb159267af..82898a1f79e 100644 --- a/advisories/unreviewed/2023/03/GHSA-rcch-h9m9-rwjw/GHSA-rcch-h9m9-rwjw.json +++ b/advisories/unreviewed/2023/03/GHSA-rcch-h9m9-rwjw/GHSA-rcch-h9m9-rwjw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-p6hw-8jfc-qq89/GHSA-p6hw-8jfc-qq89.json b/advisories/unreviewed/2024/02/GHSA-p6hw-8jfc-qq89/GHSA-p6hw-8jfc-qq89.json index 0f456e8de3f..4d3df8fa19e 100644 --- a/advisories/unreviewed/2024/02/GHSA-p6hw-8jfc-qq89/GHSA-p6hw-8jfc-qq89.json +++ b/advisories/unreviewed/2024/02/GHSA-p6hw-8jfc-qq89/GHSA-p6hw-8jfc-qq89.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9hgh-cqm9-hh6h/GHSA-9hgh-cqm9-hh6h.json b/advisories/unreviewed/2024/03/GHSA-9hgh-cqm9-hh6h/GHSA-9hgh-cqm9-hh6h.json index 61018733552..209c32bb708 100644 --- a/advisories/unreviewed/2024/03/GHSA-9hgh-cqm9-hh6h/GHSA-9hgh-cqm9-hh6h.json +++ b/advisories/unreviewed/2024/03/GHSA-9hgh-cqm9-hh6h/GHSA-9hgh-cqm9-hh6h.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-89gm-fv57-9hjw/GHSA-89gm-fv57-9hjw.json b/advisories/unreviewed/2024/07/GHSA-89gm-fv57-9hjw/GHSA-89gm-fv57-9hjw.json index 54aaf9a3091..31ed4586dd7 100644 --- a/advisories/unreviewed/2024/07/GHSA-89gm-fv57-9hjw/GHSA-89gm-fv57-9hjw.json +++ b/advisories/unreviewed/2024/07/GHSA-89gm-fv57-9hjw/GHSA-89gm-fv57-9hjw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rxjf-75rj-r875/GHSA-rxjf-75rj-r875.json b/advisories/unreviewed/2024/07/GHSA-rxjf-75rj-r875/GHSA-rxjf-75rj-r875.json index 28ec16d7752..0f23fef82a7 100644 --- a/advisories/unreviewed/2024/07/GHSA-rxjf-75rj-r875/GHSA-rxjf-75rj-r875.json +++ b/advisories/unreviewed/2024/07/GHSA-rxjf-75rj-r875/GHSA-rxjf-75rj-r875.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2v89-wpgr-r5vm/GHSA-2v89-wpgr-r5vm.json b/advisories/unreviewed/2025/02/GHSA-2v89-wpgr-r5vm/GHSA-2v89-wpgr-r5vm.json index 17e806f3055..0880f598880 100644 --- a/advisories/unreviewed/2025/02/GHSA-2v89-wpgr-r5vm/GHSA-2v89-wpgr-r5vm.json +++ b/advisories/unreviewed/2025/02/GHSA-2v89-wpgr-r5vm/GHSA-2v89-wpgr-r5vm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2v89-wpgr-r5vm", - "modified": "2025-02-21T18:31:15Z", + "modified": "2025-03-17T21:30:31Z", "published": "2025-02-21T18:31:15Z", "aliases": [ "CVE-2025-25875" ], "details": "A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T18:16:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4f7j-px6v-m38x/GHSA-4f7j-px6v-m38x.json b/advisories/unreviewed/2025/02/GHSA-4f7j-px6v-m38x/GHSA-4f7j-px6v-m38x.json index 9c1b9fcadd2..dd2d9182aaf 100644 --- a/advisories/unreviewed/2025/02/GHSA-4f7j-px6v-m38x/GHSA-4f7j-px6v-m38x.json +++ b/advisories/unreviewed/2025/02/GHSA-4f7j-px6v-m38x/GHSA-4f7j-px6v-m38x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4f7j-px6v-m38x", - "modified": "2025-02-14T00:30:44Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2024-57378" ], "details": "Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T22:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5p75-8vmp-h6xw/GHSA-5p75-8vmp-h6xw.json b/advisories/unreviewed/2025/02/GHSA-5p75-8vmp-h6xw/GHSA-5p75-8vmp-h6xw.json index 3bd8d970909..2b7a5451c31 100644 --- a/advisories/unreviewed/2025/02/GHSA-5p75-8vmp-h6xw/GHSA-5p75-8vmp-h6xw.json +++ b/advisories/unreviewed/2025/02/GHSA-5p75-8vmp-h6xw/GHSA-5p75-8vmp-h6xw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5p75-8vmp-h6xw", - "modified": "2025-02-14T00:30:45Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:45Z", "aliases": [ "CVE-2024-57782" ], "details": "An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7jh3-f4p5-7prm/GHSA-7jh3-f4p5-7prm.json b/advisories/unreviewed/2025/02/GHSA-7jh3-f4p5-7prm/GHSA-7jh3-f4p5-7prm.json index 092b48a1a86..5728e2da4bd 100644 --- a/advisories/unreviewed/2025/02/GHSA-7jh3-f4p5-7prm/GHSA-7jh3-f4p5-7prm.json +++ b/advisories/unreviewed/2025/02/GHSA-7jh3-f4p5-7prm/GHSA-7jh3-f4p5-7prm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jh3-f4p5-7prm", - "modified": "2025-02-21T18:31:14Z", + "modified": "2025-03-17T21:30:31Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2024-55156" ], "details": "An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-134" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T18:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7pxw-57qc-2vjm/GHSA-7pxw-57qc-2vjm.json b/advisories/unreviewed/2025/02/GHSA-7pxw-57qc-2vjm/GHSA-7pxw-57qc-2vjm.json index 418ebdd640c..e25985dc467 100644 --- a/advisories/unreviewed/2025/02/GHSA-7pxw-57qc-2vjm/GHSA-7pxw-57qc-2vjm.json +++ b/advisories/unreviewed/2025/02/GHSA-7pxw-57qc-2vjm/GHSA-7pxw-57qc-2vjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7pxw-57qc-2vjm", - "modified": "2025-02-14T00:30:45Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:45Z", "aliases": [ "CVE-2025-22960" ], "details": "A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files (/logs/debug/xteLog*), potentially revealing sensitive session-related information such as session IDs (sess_id) and authentication success tokens (user_check_password OK). Exploiting this flaw could allow attackers to hijack active sessions, gain unauthorized access, and escalate privileges on affected devices.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9rhh-9h7r-f9gf/GHSA-9rhh-9h7r-f9gf.json b/advisories/unreviewed/2025/02/GHSA-9rhh-9h7r-f9gf/GHSA-9rhh-9h7r-f9gf.json index c7359f9006b..980ccbe849d 100644 --- a/advisories/unreviewed/2025/02/GHSA-9rhh-9h7r-f9gf/GHSA-9rhh-9h7r-f9gf.json +++ b/advisories/unreviewed/2025/02/GHSA-9rhh-9h7r-f9gf/GHSA-9rhh-9h7r-f9gf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9rhh-9h7r-f9gf", - "modified": "2025-02-14T15:31:05Z", + "modified": "2025-03-17T21:30:31Z", "published": "2025-02-14T15:31:05Z", "aliases": [ "CVE-2025-25740" ], "details": "D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter in the SetQuickVPNSettings module.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T15:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c442-c8m7-hp5v/GHSA-c442-c8m7-hp5v.json b/advisories/unreviewed/2025/02/GHSA-c442-c8m7-hp5v/GHSA-c442-c8m7-hp5v.json index c7be905871e..bd3fdcf9099 100644 --- a/advisories/unreviewed/2025/02/GHSA-c442-c8m7-hp5v/GHSA-c442-c8m7-hp5v.json +++ b/advisories/unreviewed/2025/02/GHSA-c442-c8m7-hp5v/GHSA-c442-c8m7-hp5v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c442-c8m7-hp5v", - "modified": "2025-02-14T00:30:45Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2024-53309" ], "details": "A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the \"-f\" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-fc4h-jq3v-6rrg/GHSA-fc4h-jq3v-6rrg.json b/advisories/unreviewed/2025/02/GHSA-fc4h-jq3v-6rrg/GHSA-fc4h-jq3v-6rrg.json index 35dd3f64f6a..b55b1659968 100644 --- a/advisories/unreviewed/2025/02/GHSA-fc4h-jq3v-6rrg/GHSA-fc4h-jq3v-6rrg.json +++ b/advisories/unreviewed/2025/02/GHSA-fc4h-jq3v-6rrg/GHSA-fc4h-jq3v-6rrg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fc4h-jq3v-6rrg", - "modified": "2025-02-14T00:30:44Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2023-34406" ], "details": "An issue was discovered on Mercedes Benz NTG 6. A possible integer overflow exists in the user data import/export function of NTG (New Telematics Generation) 6 head units. To perform this attack, local access to USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-g674-vjfp-rx8j/GHSA-g674-vjfp-rx8j.json b/advisories/unreviewed/2025/02/GHSA-g674-vjfp-rx8j/GHSA-g674-vjfp-rx8j.json index 3e096ea224c..125678f5cef 100644 --- a/advisories/unreviewed/2025/02/GHSA-g674-vjfp-rx8j/GHSA-g674-vjfp-rx8j.json +++ b/advisories/unreviewed/2025/02/GHSA-g674-vjfp-rx8j/GHSA-g674-vjfp-rx8j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g674-vjfp-rx8j", - "modified": "2025-02-14T18:30:51Z", + "modified": "2025-03-17T21:30:31Z", "published": "2025-02-14T18:30:51Z", "aliases": [ "CVE-2024-57790" ], "details": "IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically proximate attackers to gain root access via UART or SSH.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gjw5-w65f-c5gw/GHSA-gjw5-w65f-c5gw.json b/advisories/unreviewed/2025/02/GHSA-gjw5-w65f-c5gw/GHSA-gjw5-w65f-c5gw.json index e7b7922cbd4..cb7a0a61136 100644 --- a/advisories/unreviewed/2025/02/GHSA-gjw5-w65f-c5gw/GHSA-gjw5-w65f-c5gw.json +++ b/advisories/unreviewed/2025/02/GHSA-gjw5-w65f-c5gw/GHSA-gjw5-w65f-c5gw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gjw5-w65f-c5gw", - "modified": "2025-02-21T18:31:15Z", + "modified": "2025-03-17T21:30:31Z", "published": "2025-02-21T18:31:15Z", "aliases": [ "CVE-2024-57176" ], "details": "An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal and access sensitive endpoints via a crafted URL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-437" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T18:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qvrx-p9gg-46f8/GHSA-qvrx-p9gg-46f8.json b/advisories/unreviewed/2025/02/GHSA-qvrx-p9gg-46f8/GHSA-qvrx-p9gg-46f8.json index dab9a52f155..994b0d576c0 100644 --- a/advisories/unreviewed/2025/02/GHSA-qvrx-p9gg-46f8/GHSA-qvrx-p9gg-46f8.json +++ b/advisories/unreviewed/2025/02/GHSA-qvrx-p9gg-46f8/GHSA-qvrx-p9gg-46f8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvrx-p9gg-46f8", - "modified": "2025-02-14T00:30:45Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:45Z", "aliases": [ "CVE-2024-56908" ], "details": "In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directories of their choice, potentially leading to remote code execution or server compromise.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-444" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xjpw-qmp3-4x22/GHSA-xjpw-qmp3-4x22.json b/advisories/unreviewed/2025/02/GHSA-xjpw-qmp3-4x22/GHSA-xjpw-qmp3-4x22.json index e1993963752..fa8a7425dbf 100644 --- a/advisories/unreviewed/2025/02/GHSA-xjpw-qmp3-4x22/GHSA-xjpw-qmp3-4x22.json +++ b/advisories/unreviewed/2025/02/GHSA-xjpw-qmp3-4x22/GHSA-xjpw-qmp3-4x22.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjpw-qmp3-4x22", - "modified": "2025-02-14T00:30:45Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2024-53311" ], "details": "A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xp8w-5r26-q5qh/GHSA-xp8w-5r26-q5qh.json b/advisories/unreviewed/2025/02/GHSA-xp8w-5r26-q5qh/GHSA-xp8w-5r26-q5qh.json index f20c1a59694..de4493e4f75 100644 --- a/advisories/unreviewed/2025/02/GHSA-xp8w-5r26-q5qh/GHSA-xp8w-5r26-q5qh.json +++ b/advisories/unreviewed/2025/02/GHSA-xp8w-5r26-q5qh/GHSA-xp8w-5r26-q5qh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xp8w-5r26-q5qh", - "modified": "2025-02-14T00:30:44Z", + "modified": "2025-03-17T21:30:30Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2023-34404" ], "details": "Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all registered services in router and achieve command injection vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2j7h-v8wc-gmgr/GHSA-2j7h-v8wc-gmgr.json b/advisories/unreviewed/2025/03/GHSA-2j7h-v8wc-gmgr/GHSA-2j7h-v8wc-gmgr.json index b7a25daa438..9a63645017a 100644 --- a/advisories/unreviewed/2025/03/GHSA-2j7h-v8wc-gmgr/GHSA-2j7h-v8wc-gmgr.json +++ b/advisories/unreviewed/2025/03/GHSA-2j7h-v8wc-gmgr/GHSA-2j7h-v8wc-gmgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2j7h-v8wc-gmgr", - "modified": "2025-03-14T18:30:51Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T18:30:51Z", "aliases": [ "CVE-2025-29386" ], "details": "In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T17:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-33f4-xj2w-x86q/GHSA-33f4-xj2w-x86q.json b/advisories/unreviewed/2025/03/GHSA-33f4-xj2w-x86q/GHSA-33f4-xj2w-x86q.json new file mode 100644 index 00000000000..ee79253a684 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-33f4-xj2w-x86q/GHSA-33f4-xj2w-x86q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33f4-xj2w-x86q", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-2397" + ], + "details": "A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2397" + }, + { + "type": "WEB", + "url": "https://github.com/Fizz-L/Vulnerability-report/blob/main/Unauthorized%20access%20to%20execute%20the%20telnet%20command.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299896" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299896" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514957" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38cq-v43p-vhvf/GHSA-38cq-v43p-vhvf.json b/advisories/unreviewed/2025/03/GHSA-38cq-v43p-vhvf/GHSA-38cq-v43p-vhvf.json new file mode 100644 index 00000000000..e5f78b7ea40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38cq-v43p-vhvf/GHSA-38cq-v43p-vhvf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38cq-v43p-vhvf", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2025-2390" + ], + "details": "A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2390" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL8.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299889" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299889" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516908" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3c2x-g6mp-5gcv/GHSA-3c2x-g6mp-5gcv.json b/advisories/unreviewed/2025/03/GHSA-3c2x-g6mp-5gcv/GHSA-3c2x-g6mp-5gcv.json index 16f19e6d9a6..bc9821a4497 100644 --- a/advisories/unreviewed/2025/03/GHSA-3c2x-g6mp-5gcv/GHSA-3c2x-g6mp-5gcv.json +++ b/advisories/unreviewed/2025/03/GHSA-3c2x-g6mp-5gcv/GHSA-3c2x-g6mp-5gcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c2x-g6mp-5gcv", - "modified": "2025-03-14T15:32:03Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T15:32:03Z", "aliases": [ "CVE-2025-29030" ], "details": "Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T14:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json b/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json new file mode 100644 index 00000000000..79a70ae4a4d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3h28-663g-h6cx/GHSA-3h28-663g-h6cx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h28-663g-h6cx", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-2391" + ], + "details": "A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_login.php of the component Admin Login Page. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2391" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL10.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299890" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299890" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516910" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json b/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json new file mode 100644 index 00000000000..ac8f0b6adc4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jqw-73hh-rjm4", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2025-29425" + ], + "details": "Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29425" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3rw8-4xrq-3f7p/GHSA-3rw8-4xrq-3f7p.json b/advisories/unreviewed/2025/03/GHSA-3rw8-4xrq-3f7p/GHSA-3rw8-4xrq-3f7p.json new file mode 100644 index 00000000000..2b81e6c0147 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3rw8-4xrq-3f7p/GHSA-3rw8-4xrq-3f7p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rw8-4xrq-3f7p", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2025-26042" + ], + "details": "Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26042" + }, + { + "type": "WEB", + "url": "https://github.com/louislam/uptime-kuma/issues/5574" + }, + { + "type": "WEB", + "url": "https://github.com/louislam/uptime-kuma/pull/5573" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4hqj-96cj-gmwp/GHSA-4hqj-96cj-gmwp.json b/advisories/unreviewed/2025/03/GHSA-4hqj-96cj-gmwp/GHSA-4hqj-96cj-gmwp.json new file mode 100644 index 00000000000..92bec081be9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4hqj-96cj-gmwp/GHSA-4hqj-96cj-gmwp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hqj-96cj-gmwp", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:33Z", + "aliases": [ + "CVE-2022-49523" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nath11k: disable spectral scan during spectral deinit\n\nWhen ath11k modules are removed using rmmod with spectral scan enabled,\ncrash is observed. Different crash trace is observed for each crash.\n\nSend spectral scan disable WMI command to firmware before cleaning\nthe spectral dbring in the spectral_deinit API to avoid this crash.\n\ncall trace from one of the crash observed:\n[ 1252.880802] Unable to handle kernel NULL pointer dereference at virtual address 00000008\n[ 1252.882722] pgd = 0f42e886\n[ 1252.890955] [00000008] *pgd=00000000\n[ 1252.893478] Internal error: Oops: 5 [#1] PREEMPT SMP ARM\n[ 1253.093035] CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.4.89 #0\n[ 1253.115261] Hardware name: Generic DT based system\n[ 1253.121149] PC is at ath11k_spectral_process_data+0x434/0x574 [ath11k]\n[ 1253.125940] LR is at 0x88e31017\n[ 1253.132448] pc : [<7f9387b8>] lr : [<88e31017>] psr: a0000193\n[ 1253.135488] sp : 80d01bc8 ip : 00000001 fp : 970e0000\n[ 1253.141737] r10: 88e31000 r9 : 970ec000 r8 : 00000080\n[ 1253.146946] r7 : 94734040 r6 : a0000113 r5 : 00000057 r4 : 00000000\n[ 1253.152159] r3 : e18cb694 r2 : 00000217 r1 : 1df1f000 r0 : 00000001\n[ 1253.158755] Flags: NzCv IRQs off FIQs on Mode SVC_32 ISA ARM Segment user\n[ 1253.165266] Control: 10c0383d Table: 5e71006a DAC: 00000055\n[ 1253.172472] Process swapper/0 (pid: 0, stack limit = 0x60870141)\n[ 1253.458055] [<7f9387b8>] (ath11k_spectral_process_data [ath11k]) from [<7f917fdc>] (ath11k_dbring_buffer_release_event+0x214/0x2e4 [ath11k])\n[ 1253.466139] [<7f917fdc>] (ath11k_dbring_buffer_release_event [ath11k]) from [<7f8ea3c4>] (ath11k_wmi_tlv_op_rx+0x1840/0x29cc [ath11k])\n[ 1253.478807] [<7f8ea3c4>] (ath11k_wmi_tlv_op_rx [ath11k]) from [<7f8fe868>] (ath11k_htc_rx_completion_handler+0x180/0x4e0 [ath11k])\n[ 1253.490699] [<7f8fe868>] (ath11k_htc_rx_completion_handler [ath11k]) from [<7f91308c>] (ath11k_ce_per_engine_service+0x2c4/0x3b4 [ath11k])\n[ 1253.502386] [<7f91308c>] (ath11k_ce_per_engine_service [ath11k]) from [<7f9a4198>] (ath11k_pci_ce_tasklet+0x28/0x80 [ath11k_pci])\n[ 1253.514811] [<7f9a4198>] (ath11k_pci_ce_tasklet [ath11k_pci]) from [<8032227c>] (tasklet_action_common.constprop.2+0x64/0xe8)\n[ 1253.526476] [<8032227c>] (tasklet_action_common.constprop.2) from [<803021e8>] (__do_softirq+0x130/0x2d0)\n[ 1253.537756] [<803021e8>] (__do_softirq) from [<80322610>] (irq_exit+0xcc/0xe8)\n[ 1253.547304] [<80322610>] (irq_exit) from [<8036a4a4>] (__handle_domain_irq+0x60/0xb4)\n[ 1253.554428] [<8036a4a4>] (__handle_domain_irq) from [<805eb348>] (gic_handle_irq+0x4c/0x90)\n[ 1253.562321] [<805eb348>] (gic_handle_irq) from [<80301a78>] (__irq_svc+0x58/0x8c)\n\nTested-on: QCN6122 hw1.0 AHB WLAN.HK.2.6.0.1-00851-QCAHKSWPL_SILICONZ-1", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49523" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/161c64de239c7018e0295e7e0520a19f00aa32dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/451b9076903a057b7b8d5b24dc84b3e436a1c743" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b9c54caef58d2b55074710952cda70540722c01" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60afa4f4e1350c876d8a061182a70c224de275dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f15e67af9bec5a69e815e0230a70cffddae371a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-54v8-qjwx-hj66/GHSA-54v8-qjwx-hj66.json b/advisories/unreviewed/2025/03/GHSA-54v8-qjwx-hj66/GHSA-54v8-qjwx-hj66.json index 29b3b50d325..06414d77d23 100644 --- a/advisories/unreviewed/2025/03/GHSA-54v8-qjwx-hj66/GHSA-54v8-qjwx-hj66.json +++ b/advisories/unreviewed/2025/03/GHSA-54v8-qjwx-hj66/GHSA-54v8-qjwx-hj66.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-54v8-qjwx-hj66", - "modified": "2025-03-14T18:30:50Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T18:30:50Z", "aliases": [ "CVE-2025-29387" ], "details": "In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,11 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121", + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T17:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-54vm-jhgv-phv5/GHSA-54vm-jhgv-phv5.json b/advisories/unreviewed/2025/03/GHSA-54vm-jhgv-phv5/GHSA-54vm-jhgv-phv5.json new file mode 100644 index 00000000000..a5e25500bea --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-54vm-jhgv-phv5/GHSA-54vm-jhgv-phv5.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54vm-jhgv-phv5", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49311" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: staging: rtl8192bs: Fix deadlock in rtw_joinbss_event_prehandle()\n\nThere is a deadlock in rtw_joinbss_event_prehandle(), which is shown\nbelow:\n\n (Thread 1) | (Thread 2)\n | _set_timer()\nrtw_joinbss_event_prehandle()| mod_timer()\n spin_lock_bh() //(1) | (wait a time)\n ... | _rtw_join_timeout_handler()\n del_timer_sync() | spin_lock_bh() //(2)\n (wait timer to stop) | ...\n\nWe hold pmlmepriv->lock in position (1) of thread 1 and\nuse del_timer_sync() to wait timer to stop, but timer handler\nalso need pmlmepriv->lock in position (2) of thread 2.\nAs a result, rtw_joinbss_event_prehandle() will block forever.\n\nThis patch extracts del_timer_sync() from the protection of\nspin_lock_bh(), which could let timer handler to obtain\nthe needed lock. What`s more, we change spin_lock_bh() to\nspin_lock_irq() in _rtw_join_timeout_handler() in order to\nprevent deadlock.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49311" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/041879b12ddb0c6c83ed9c0bdd10dc82a056f2fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f6c99b94ca3caad346876b3e22e3ca3d25bc8ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae60744d5fad840b9d056d35b4b652d95e755846" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eca9748d9267a38d532464e3305a38629e9c35a9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5g2r-4fp2-x498/GHSA-5g2r-4fp2-x498.json b/advisories/unreviewed/2025/03/GHSA-5g2r-4fp2-x498/GHSA-5g2r-4fp2-x498.json index 60304bfd39f..d15d5b5daae 100644 --- a/advisories/unreviewed/2025/03/GHSA-5g2r-4fp2-x498/GHSA-5g2r-4fp2-x498.json +++ b/advisories/unreviewed/2025/03/GHSA-5g2r-4fp2-x498/GHSA-5g2r-4fp2-x498.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5g2r-4fp2-x498", - "modified": "2025-03-16T06:30:24Z", + "modified": "2025-03-17T21:30:34Z", "published": "2025-03-16T06:30:24Z", "aliases": [ "CVE-2025-1622" ], "details": "The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-622v-pr25-m36f/GHSA-622v-pr25-m36f.json b/advisories/unreviewed/2025/03/GHSA-622v-pr25-m36f/GHSA-622v-pr25-m36f.json new file mode 100644 index 00000000000..653c5b72dca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-622v-pr25-m36f/GHSA-622v-pr25-m36f.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-622v-pr25-m36f", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:33Z", + "aliases": [ + "CVE-2022-49439" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/fsl_rio: Fix refcount leak in fsl_rio_setup\n\nof_parse_phandle() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when not need anymore.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49439" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46fd994763cf6884b88a2da712af918f3ed54d7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51e25fbf20c9152d84a34b7afac15a41fe5c9116" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5607a77a365df8c0fd5ff43ac424812b95775527" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b8aa2ba38c010f47c965dd9bb5a8561813ed649" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b668a59ddfb32727e39b06fdf52b28e58c684e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcb6c4c5eb4836a21411dfe8247bf9951eb6e7c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c70dd353d37158e06bf8d450d4b31a7091609924" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcee96924ba1596ca80a6770b2567ca546f9a482" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6735-jgp5-qf5j/GHSA-6735-jgp5-qf5j.json b/advisories/unreviewed/2025/03/GHSA-6735-jgp5-qf5j/GHSA-6735-jgp5-qf5j.json new file mode 100644 index 00000000000..d27a8119dea --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6735-jgp5-qf5j/GHSA-6735-jgp5-qf5j.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6735-jgp5-qf5j", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:33Z", + "aliases": [ + "CVE-2022-49312" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8712: fix a potential memory leak in r871xu_drv_init()\n\nIn r871xu_drv_init(), if r8712_init_drv_sw() fails, then the memory\nallocated by r8712_alloc_io_queue() in r8712_usb_dvobj_init() is not\nproperly released as there is no action will be performed by\nr8712_usb_dvobj_deinit().\nTo properly release it, we should call r8712_free_io_queue() in\nr8712_usb_dvobj_deinit().\n\nBesides, in r871xu_dev_remove(), r8712_usb_dvobj_deinit() will be called\nby r871x_dev_unload() under condition `padapter->bup` and\nr8712_free_io_queue() is called by r8712_free_drv_sw().\nHowever, r8712_usb_dvobj_deinit() does not rely on `padapter->bup` and\ncalling r8712_free_io_queue() in r8712_free_drv_sw() is negative for\nbetter understading the code.\nSo I move r8712_usb_dvobj_deinit() into r871xu_dev_remove(), and remove\nr8712_free_io_queue() from r8712_free_drv_sw().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49312" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/205e039fead72e87ad2838f5e649a4c4834f648b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a89a92efc342dd7c44b6056da87debc598f9c73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7288ff561de650d4139fab80e9cb0da9b5b32434" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8eb42d6d10f8fe509117859defddf9e72b4fa4d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2882b8baad068d21c99fb2ab5a85a2bdbd5b834" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-67jw-xp2p-xpv9/GHSA-67jw-xp2p-xpv9.json b/advisories/unreviewed/2025/03/GHSA-67jw-xp2p-xpv9/GHSA-67jw-xp2p-xpv9.json new file mode 100644 index 00000000000..4ca73abbe1a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-67jw-xp2p-xpv9/GHSA-67jw-xp2p-xpv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67jw-xp2p-xpv9", + "modified": "2025-03-17T21:30:32Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49240" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8195: Fix error handling in mt8195_mt6359_rt1019_rt5682_dev_probe\n\nThe device_node pointer is returned by of_parse_phandle() with refcount\nincremented. We should use of_node_put() on it when done.\n\nThis function only calls of_node_put() in the regular path.\nAnd it will cause refcount leak in error path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49240" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4b7174fe5bb875a09a78674a14a1589d1a672f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c652f8f0875b569f8afa80b8cf9762828fd6187b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json b/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json new file mode 100644 index 00000000000..ee23bb63e98 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6f67-378m-2772/GHSA-6f67-378m-2772.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f67-378m-2772", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2024-54559" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54559" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6gpc-pr73-3q2j/GHSA-6gpc-pr73-3q2j.json b/advisories/unreviewed/2025/03/GHSA-6gpc-pr73-3q2j/GHSA-6gpc-pr73-3q2j.json new file mode 100644 index 00000000000..d9365d6b3c6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6gpc-pr73-3q2j/GHSA-6gpc-pr73-3q2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gpc-pr73-3q2j", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-26393" + ], + "details": "SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26393" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-653" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7wv3-wp67-hwwp/GHSA-7wv3-wp67-hwwp.json b/advisories/unreviewed/2025/03/GHSA-7wv3-wp67-hwwp/GHSA-7wv3-wp67-hwwp.json new file mode 100644 index 00000000000..a5cd2038303 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7wv3-wp67-hwwp/GHSA-7wv3-wp67-hwwp.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wv3-wp67-hwwp", + "modified": "2025-03-17T21:30:32Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49242" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mxs: Fix error handling in mxs_sgtl5000_probe\n\nThis function only calls of_node_put() in the regular path.\nAnd it will cause refcount leak in error paths.\nFor example, when codec_np is NULL, saif_np[0] and saif_np[1]\nare not NULL, it will cause leaks.\n\nof_node_put() will check if the node pointer is NULL, so we can\ncall it directly to release the refcount of regular pointers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49242" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44acdaf7acb60054d872bed18ce0e7db8ce900ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67e12f1cb2f97468c12b59e21975eaa0f332e7d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ae0a4d8fec551ec581d620f0eb1fe31f755551c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/790d2628e3fcc819d8f5572eb5615113fb2e727a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86b6cf989437e694fd0a15782b5a513853a739e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d880226c86f37624e2a5f3c6d92ac0ec3375f96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2923b48d99fe663cb93d8b481c93299fcd68656" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f16ad2c0e22687f80e5981c67374023f51c204b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8d38056bcd220ea6f0802a5586d1a12ebcce849" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json b/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json new file mode 100644 index 00000000000..da6a8058c43 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8j69-hcq4-p2fc/GHSA-8j69-hcq4-p2fc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j69-hcq4-p2fc", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-2392" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/activate.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2392" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL11.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299891" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299891" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9rw4-jg9w-jw2g/GHSA-9rw4-jg9w-jw2g.json b/advisories/unreviewed/2025/03/GHSA-9rw4-jg9w-jw2g/GHSA-9rw4-jg9w-jw2g.json index 5cc56a2fda3..1998ffe3c67 100644 --- a/advisories/unreviewed/2025/03/GHSA-9rw4-jg9w-jw2g/GHSA-9rw4-jg9w-jw2g.json +++ b/advisories/unreviewed/2025/03/GHSA-9rw4-jg9w-jw2g/GHSA-9rw4-jg9w-jw2g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9rw4-jg9w-jw2g", - "modified": "2025-03-14T15:32:03Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T15:32:03Z", "aliases": [ "CVE-2025-29029" ], "details": "Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T14:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c3m4-xrx9-mwc5/GHSA-c3m4-xrx9-mwc5.json b/advisories/unreviewed/2025/03/GHSA-c3m4-xrx9-mwc5/GHSA-c3m4-xrx9-mwc5.json index 374ebc5c5ea..d6715fc1960 100644 --- a/advisories/unreviewed/2025/03/GHSA-c3m4-xrx9-mwc5/GHSA-c3m4-xrx9-mwc5.json +++ b/advisories/unreviewed/2025/03/GHSA-c3m4-xrx9-mwc5/GHSA-c3m4-xrx9-mwc5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c3m4-xrx9-mwc5", - "modified": "2025-03-14T18:30:51Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T18:30:51Z", "aliases": [ "CVE-2025-29384" ], "details": "In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T17:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cfrr-86xw-mjgp/GHSA-cfrr-86xw-mjgp.json b/advisories/unreviewed/2025/03/GHSA-cfrr-86xw-mjgp/GHSA-cfrr-86xw-mjgp.json new file mode 100644 index 00000000000..eded955fd33 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cfrr-86xw-mjgp/GHSA-cfrr-86xw-mjgp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfrr-86xw-mjgp", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-24185" + ], + "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.3, macOS Sonoma 14.7.3. Parsing a maliciously crafted file may lead to an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24185" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f7q7-fjw5-wrf4/GHSA-f7q7-fjw5-wrf4.json b/advisories/unreviewed/2025/03/GHSA-f7q7-fjw5-wrf4/GHSA-f7q7-fjw5-wrf4.json new file mode 100644 index 00000000000..2568571d3be --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f7q7-fjw5-wrf4/GHSA-f7q7-fjw5-wrf4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7q7-fjw5-wrf4", + "modified": "2025-03-17T21:30:32Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49310" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nchar: xillybus: fix a refcount leak in cleanup_dev()\n\nusb_get_dev is called in xillyusb_probe. So it is better to call\nusb_put_dev before xdev is released.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49310" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21f1f167d727f3f857e26d509ef5a6d47fd31bc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b67d19662fdee275c479d21853bc1239600a798f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc8fceda3b89006e8a7dda8a097d36045d044c25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e277b95acdab84cd5d2f8d537a37aef6d21e988b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json b/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json new file mode 100644 index 00000000000..ec77a2ac7e7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f9q9-85g5-cwgj/GHSA-f9q9-85g5-cwgj.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9q9-85g5-cwgj", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2024-54525" + ], + "details": "A logic issue was addressed with improved file handling. This issue is fixed in visionOS 2.2, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54525" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121843" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121844" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g72j-3qqx-86gg/GHSA-g72j-3qqx-86gg.json b/advisories/unreviewed/2025/03/GHSA-g72j-3qqx-86gg/GHSA-g72j-3qqx-86gg.json new file mode 100644 index 00000000000..04c1f35808f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g72j-3qqx-86gg/GHSA-g72j-3qqx-86gg.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g72j-3qqx-86gg", + "modified": "2025-03-17T21:30:31Z", + "published": "2025-03-17T21:30:31Z", + "aliases": [ + "CVE-2022-49185" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: nomadik: Add missing of_node_put() in nmk_pinctrl_probe\n\nThis node pointer is returned by of_parse_phandle() with refcount\nincremented in this function. Calling of_node_put() to avoid\nthe refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49185" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0067ba448f1c29ca06e5aee00d8506889ed1f9d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0356d4b64a03d23daf99a2a29d7d7d91d6ec2ea8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59250d547542f1c7765a78dc97ddfe5e6b0d2ab0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62580a40c9bef3d8a90629c64dda381344b35ffd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/669b05ff43bd7ed684379c6e2006a6dad5127b71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9511c6018cd772668def8b034bc67269847e591a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc1e29a35147c1ba6ea2b06a16cb0028f7c852d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c09ac191b1f97cfa06f394dbfd7a5db07986cefc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c52703355766c347f270df222a744e0c491a02f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ghrp-fhch-vvr7/GHSA-ghrp-fhch-vvr7.json b/advisories/unreviewed/2025/03/GHSA-ghrp-fhch-vvr7/GHSA-ghrp-fhch-vvr7.json new file mode 100644 index 00000000000..df3eadf54f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ghrp-fhch-vvr7/GHSA-ghrp-fhch-vvr7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghrp-fhch-vvr7", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:33Z", + "aliases": [ + "CVE-2022-49531" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nloop: implement ->free_disk\n\nEnsure that the lo_device which is stored in the gendisk private\ndata is valid until the gendisk is freed. Currently the loop driver\nuses a lot of effort to make sure a device is not freed when it is\nstill in use, but to to fix a potential deadlock this will be relaxed\na bit soon.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49531" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aadd1443aae7fe8956e3b11157827067f034406a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2c7f56f8b5256d57f9e3fc7794c31361d43bdd9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h8cc-85qr-g7ff/GHSA-h8cc-85qr-g7ff.json b/advisories/unreviewed/2025/03/GHSA-h8cc-85qr-g7ff/GHSA-h8cc-85qr-g7ff.json new file mode 100644 index 00000000000..9a1301c311e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h8cc-85qr-g7ff/GHSA-h8cc-85qr-g7ff.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8cc-85qr-g7ff", + "modified": "2025-03-17T21:30:31Z", + "published": "2025-03-17T21:30:31Z", + "aliases": [ + "CVE-2022-49183" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix ref leak when switching zones\n\nWhen switching zones or network namespaces without doing a ct clear in\nbetween, it is now leaking a reference to the old ct entry. That's\nbecause tcf_ct_skb_nfct_cached() returns false and\ntcf_ct_flow_table_lookup() may simply overwrite it.\n\nThe fix is to, as the ct entry is not reusable, free it already at\ntcf_ct_skb_nfct_cached().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49183" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4bb42d73def9411e5cad885b9811987d72431df1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b24793a37d91aacad7cb9893b226a7924a89636a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcb74e132a76ce0502bb33d5b65533a4ed72d159" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcbf4e5c3b5b373cd61528392dd1ec8e9c0fd33d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jcrc-wc7g-62pw/GHSA-jcrc-wc7g-62pw.json b/advisories/unreviewed/2025/03/GHSA-jcrc-wc7g-62pw/GHSA-jcrc-wc7g-62pw.json index 7c61a4658dc..c126eef27c4 100644 --- a/advisories/unreviewed/2025/03/GHSA-jcrc-wc7g-62pw/GHSA-jcrc-wc7g-62pw.json +++ b/advisories/unreviewed/2025/03/GHSA-jcrc-wc7g-62pw/GHSA-jcrc-wc7g-62pw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jcrc-wc7g-62pw", - "modified": "2025-03-14T18:30:50Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T18:30:50Z", "aliases": [ "CVE-2025-29385" ], "details": "In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T17:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-m439-5w5w-f32v/GHSA-m439-5w5w-f32v.json b/advisories/unreviewed/2025/03/GHSA-m439-5w5w-f32v/GHSA-m439-5w5w-f32v.json new file mode 100644 index 00000000000..99b1e55c21c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m439-5w5w-f32v/GHSA-m439-5w5w-f32v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m439-5w5w-f32v", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2024-8510" + ], + "details": "N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. \n\nThis vulnerability is present in all deployments of N-central prior to N-central 2024.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8510" + }, + { + "type": "WEB", + "url": "https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2024.6_Release_Notes.htm" + }, + { + "type": "WEB", + "url": "https://me.n-able.com/s/security-advisory/aArVy0000000XgjKAE/cve20248510-ncentral-path-traversal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m6q7-6hrv-f732/GHSA-m6q7-6hrv-f732.json b/advisories/unreviewed/2025/03/GHSA-m6q7-6hrv-f732/GHSA-m6q7-6hrv-f732.json new file mode 100644 index 00000000000..a0069ba1b19 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m6q7-6hrv-f732/GHSA-m6q7-6hrv-f732.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6q7-6hrv-f732", + "modified": "2025-03-17T21:30:31Z", + "published": "2025-03-17T21:30:31Z", + "aliases": [ + "CVE-2022-49184" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sparx5: switchdev: fix possible NULL pointer dereference\n\nAs the possible failure of the allocation, devm_kzalloc() may return NULL\npointer.\nTherefore, it should be better to check the 'db' in order to prevent\nthe dereference of NULL pointer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49184" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0906f3a3df07835e37077d8971aac65347f2ed57" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b375ea083fa649092cd016ac1f89a2d1fd8f8e8b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c346791877e6ce923bb21e34b30c6f99326aa5a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7e1fff76c4c57688dc7d53a3b6212182d5628d0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mgjf-p92m-4xxw/GHSA-mgjf-p92m-4xxw.json b/advisories/unreviewed/2025/03/GHSA-mgjf-p92m-4xxw/GHSA-mgjf-p92m-4xxw.json new file mode 100644 index 00000000000..ed0f3295c48 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mgjf-p92m-4xxw/GHSA-mgjf-p92m-4xxw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgjf-p92m-4xxw", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:33Z", + "aliases": [ + "CVE-2022-49437" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/xive: Fix refcount leak in xive_spapr_init\n\nof_find_compatible_node() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49437" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d1fb9618bdd5a5fbf9a9eb75133da301d33721c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65f11ccdd746e0e7f0b469cc989ba43d4f30ecfe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e806485d851986a2445267608f27cb4ba2ed774" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc62dde2a5f4ba14016fd9caec76f08d388f4b9c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pj4h-hmj2-pj85/GHSA-pj4h-hmj2-pj85.json b/advisories/unreviewed/2025/03/GHSA-pj4h-hmj2-pj85/GHSA-pj4h-hmj2-pj85.json new file mode 100644 index 00000000000..4754a4a9aae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pj4h-hmj2-pj85/GHSA-pj4h-hmj2-pj85.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj4h-hmj2-pj85", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2024-44276" + ], + "details": "This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44276" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121837" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json b/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json new file mode 100644 index 00000000000..f250eb6faac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q28f-p3wj-9rm8/GHSA-q28f-p3wj-9rm8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q28f-p3wj-9rm8", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2024-54565" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54565" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/121839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q656-wcrg-wwx4/GHSA-q656-wcrg-wwx4.json b/advisories/unreviewed/2025/03/GHSA-q656-wcrg-wwx4/GHSA-q656-wcrg-wwx4.json new file mode 100644 index 00000000000..b0157d2c001 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q656-wcrg-wwx4/GHSA-q656-wcrg-wwx4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q656-wcrg-wwx4", + "modified": "2025-03-17T21:30:32Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49186" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: visconti: prevent array overflow in visconti_clk_register_gates()\n\nThis code was using -1 to represent that there was no reset function.\nUnfortunately, the -1 was stored in u8 so the if (clks[i].rs_id >= 0)\ncondition was always true. This lead to an out of bounds access in\nvisconti_clk_register_gates().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49186" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2723543c1d60278d5aef1c4ad732dbad24b84a81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5601e0720ce1a3ad895f94a5838530edde01ed3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q7vq-qpq4-684g/GHSA-q7vq-qpq4-684g.json b/advisories/unreviewed/2025/03/GHSA-q7vq-qpq4-684g/GHSA-q7vq-qpq4-684g.json new file mode 100644 index 00000000000..9def39720f0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q7vq-qpq4-684g/GHSA-q7vq-qpq4-684g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7vq-qpq4-684g", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-25914" + ], + "details": "SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25914" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/online-exam-mastering-system_sqlinject.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T20:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q9jg-pgrj-wq8v/GHSA-q9jg-pgrj-wq8v.json b/advisories/unreviewed/2025/03/GHSA-q9jg-pgrj-wq8v/GHSA-q9jg-pgrj-wq8v.json index 8550febf0af..3c0d72727ff 100644 --- a/advisories/unreviewed/2025/03/GHSA-q9jg-pgrj-wq8v/GHSA-q9jg-pgrj-wq8v.json +++ b/advisories/unreviewed/2025/03/GHSA-q9jg-pgrj-wq8v/GHSA-q9jg-pgrj-wq8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q9jg-pgrj-wq8v", - "modified": "2025-03-14T15:32:03Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-14T15:32:03Z", "aliases": [ "CVE-2025-29031" ], "details": "Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T14:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qj2x-5f28-cg38/GHSA-qj2x-5f28-cg38.json b/advisories/unreviewed/2025/03/GHSA-qj2x-5f28-cg38/GHSA-qj2x-5f28-cg38.json new file mode 100644 index 00000000000..a0ec3e22ff0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qj2x-5f28-cg38/GHSA-qj2x-5f28-cg38.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj2x-5f28-cg38", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49307" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: synclink_gt: Fix null-pointer-dereference in slgt_clean()\n\nWhen the driver fails at alloc_hdlcdev(), and then we remove the driver\nmodule, we will get the following splat:\n\n[ 25.065966] general protection fault, probably for non-canonical address 0xdffffc0000000182: 0000 [#1] PREEMPT SMP KASAN PTI\n[ 25.066914] KASAN: null-ptr-deref in range [0x0000000000000c10-0x0000000000000c17]\n[ 25.069262] RIP: 0010:detach_hdlc_protocol+0x2a/0x3e0\n[ 25.077709] Call Trace:\n[ 25.077924] \n[ 25.078108] unregister_hdlc_device+0x16/0x30\n[ 25.078481] slgt_cleanup+0x157/0x9f0 [synclink_gt]\n\nFix this by checking whether the 'info->netdev' is a null pointer first.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49307" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/078212ad15dbd88840c82c97f12c93d83703c8fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ceb4ca9543a8a788febf6bc8dad2e605e172d5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50c341f9a2adc4c32a8ad5a39eb99d9c4a419e0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/689ca31c542687709ba21ec2195c1fbce34fd029" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a95696bdc0e13f8980f05b54a3b9081963d1256" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba08cbc5b53e151d0acf1930fb526fc65b7f3e65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d68d5e68b7f64de7170f8e04dd9b995c36b2c71c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddd67751ab86c6a65f95c35293c42f85a42ac05d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6e07eb7ebec53ffe81fc2489589320fbe4a6b75" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json b/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json new file mode 100644 index 00000000000..bd1eb51d618 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r398-vw7q-9j92", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2025-29427" + ], + "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29427" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System-profile.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rrxc-83pc-mr58/GHSA-rrxc-83pc-mr58.json b/advisories/unreviewed/2025/03/GHSA-rrxc-83pc-mr58/GHSA-rrxc-83pc-mr58.json new file mode 100644 index 00000000000..d5363c05876 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rrxc-83pc-mr58/GHSA-rrxc-83pc-mr58.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrxc-83pc-mr58", + "modified": "2025-03-17T21:30:31Z", + "published": "2025-03-17T21:30:31Z", + "aliases": [ + "CVE-2022-49177" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwrng: cavium - fix NULL but dereferenced coccicheck error\n\nFix following coccicheck warning:\n./drivers/char/hw_random/cavium-rng-vf.c:182:17-20: ERROR:\npdev is NULL but dereferenced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49177" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e47b12f9415169eceda6770fcf45802e0c8d2a66" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6205ad58a7ac194abfb33897585b38687d797fa" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json b/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json new file mode 100644 index 00000000000..05128c63b98 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v9vj-4w4v-xqvj/GHSA-v9vj-4w4v-xqvj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9vj-4w4v-xqvj", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2025-2389" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_city.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2389" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL7.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299888" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299888" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516906" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vq76-vp85-3v38/GHSA-vq76-vp85-3v38.json b/advisories/unreviewed/2025/03/GHSA-vq76-vp85-3v38/GHSA-vq76-vp85-3v38.json new file mode 100644 index 00000000000..ae7fdca143c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vq76-vp85-3v38/GHSA-vq76-vp85-3v38.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq76-vp85-3v38", + "modified": "2025-03-17T21:30:33Z", + "published": "2025-03-17T21:30:33Z", + "aliases": [ + "CVE-2022-49438" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: sparcspkr - fix refcount leak in bbc_beep_probe\n\nof_find_node_by_path() calls of_find_node_opts_by_path(),\nwhich returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49438" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1124e39fea0e2fdb4202f95b716cb97cc7de7cc7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f51db16cb740ff90086189a1ef2581eab665591" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/353bc58ac6c782d4dcde9136a91d1f90867938fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/418b6a3e12f75638abc5673eb76cb32127d0ab13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e07ccc7d56130f760d23f67a70c45366c07debc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73d6f42d8d86648bec2e73d34fe1648cb6d23e08" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbc2b0ce6042dd3117827f10ea8cb67e0ab786da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8994b30d71d64d5dcc9bc0edbfdf367171aa96f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f13064b0f2c651a3fbb0749932795c6fd21556a8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json b/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json new file mode 100644 index 00000000000..2de8d0efe4d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4r7-mmm7-q5mj", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-29426" + ], + "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29426" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System-class.php.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x43f-46qx-3qx9/GHSA-x43f-46qx-3qx9.json b/advisories/unreviewed/2025/03/GHSA-x43f-46qx-3qx9/GHSA-x43f-46qx-3qx9.json new file mode 100644 index 00000000000..cf74f8bc491 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x43f-46qx-3qx9/GHSA-x43f-46qx-3qx9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x43f-46qx-3qx9", + "modified": "2025-03-17T21:30:35Z", + "published": "2025-03-17T21:30:35Z", + "aliases": [ + "CVE-2025-2393" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/salut_del.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2393" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL12.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299892" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299892" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516917" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json b/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json index 788eb18e95e..8622ed82a69 100644 --- a/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json +++ b/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcfp-c436-mm2r", - "modified": "2025-03-16T06:30:23Z", + "modified": "2025-03-17T21:30:33Z", "published": "2025-03-16T06:30:23Z", "aliases": [ "CVE-2024-13126" ], "details": "The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:11Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xmrj-2g7q-5pcq/GHSA-xmrj-2g7q-5pcq.json b/advisories/unreviewed/2025/03/GHSA-xmrj-2g7q-5pcq/GHSA-xmrj-2g7q-5pcq.json new file mode 100644 index 00000000000..f77657ed3de --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xmrj-2g7q-5pcq/GHSA-xmrj-2g7q-5pcq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmrj-2g7q-5pcq", + "modified": "2025-03-17T21:30:32Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49241" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: atmel: Fix error handling in sam9x5_wm8731_driver_probe\n\nThe device_node pointer is returned by of_parse_phandle() with refcount\nincremented. We should use of_node_put() on it when done.\n\nThis function only calls of_node_put() in the regular path.\nAnd it will cause refcount leak in error path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49241" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14228225091a0854b1de23e5b4fe8bdeeca9683b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/740dc3e846537c3743da98bf106f376023fd085c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90ac679aa6a01841da90ec5a4aaa4b5e0badddf0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f43ad5dc43240289f4cf13c16cc506f4f7087931" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f589063b585ac6dd2081bde6c145411cf48d8d92" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xpwf-pw24-jcwf/GHSA-xpwf-pw24-jcwf.json b/advisories/unreviewed/2025/03/GHSA-xpwf-pw24-jcwf/GHSA-xpwf-pw24-jcwf.json new file mode 100644 index 00000000000..c4df0f30d2f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xpwf-pw24-jcwf/GHSA-xpwf-pw24-jcwf.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpwf-pw24-jcwf", + "modified": "2025-03-17T21:30:32Z", + "published": "2025-03-17T21:30:32Z", + "aliases": [ + "CVE-2022-49309" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()\n\nThere is a deadlock in rtw_surveydone_event_callback(),\nwhich is shown below:\n\n (Thread 1) | (Thread 2)\n | _set_timer()\nrtw_surveydone_event_callback()| mod_timer()\n spin_lock_bh() //(1) | (wait a time)\n ... | rtw_scan_timeout_handler()\n del_timer_sync() | spin_lock_bh() //(2)\n (wait timer to stop) | ...\n\nWe hold pmlmepriv->lock in position (1) of thread 1 and use\ndel_timer_sync() to wait timer to stop, but timer handler\nalso need pmlmepriv->lock in position (2) of thread 2.\nAs a result, rtw_surveydone_event_callback() will block forever.\n\nThis patch extracts del_timer_sync() from the protection of\nspin_lock_bh(), which could let timer handler to obtain\nthe needed lock. What`s more, we change spin_lock_bh() in\nrtw_scan_timeout_handler() to spin_lock_irq(). Otherwise,\nspin_lock_bh() will also cause deadlock() in timer handler.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49309" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c41f5c341853f84b7bc2f32605d4e2782e8c279" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc7ad0d77b51c872d629bcd98aea463a3c4109e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce129d3efd181da5fd56f4360cc8827122afa67e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f89f6c3ebf69623b8ea48200bd690e9e210335a1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json b/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json new file mode 100644 index 00000000000..fcc4deefba1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw57-qhqx-v67p", + "modified": "2025-03-17T21:30:34Z", + "published": "2025-03-17T21:30:34Z", + "aliases": [ + "CVE-2024-44866" + ], + "details": "A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44866" + }, + { + "type": "WEB", + "url": "https://github.com/moonadon9/CVE_2024" + }, + { + "type": "WEB", + "url": "https://musescore.org/ko/download/musescore.msi" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T19:15:22Z" + } +} \ No newline at end of file