From 2f6edd2f607db7eab701d423fce905de1f5fad0b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 29 Apr 2025 03:32:03 +0000 Subject: [PATCH] Publish Advisories GHSA-363q-mrhx-5q4w GHSA-36c4-c6rg-wqpc GHSA-3f92-4q6m-m3rv GHSA-5jgj-vxr6-w56j GHSA-64fc-m8mv-x59j GHSA-72pc-mw67-6f3f GHSA-7wfr-865w-3mvg GHSA-8243-c3qw-cfqr GHSA-86pf-577r-267c GHSA-929h-9mmv-9rj6 GHSA-fj6q-h8w7-mx3g GHSA-j8hf-p5v4-xpj9 GHSA-j8p7-m3g9-jw25 GHSA-jj9m-3528-27j2 GHSA-m5ph-8w8x-4mpc GHSA-p9vx-xf7x-8hp9 GHSA-pchj-w8gf-xx64 GHSA-pjvr-p8qr-3fg8 GHSA-vhj2-4h8c-jc8m GHSA-vmwg-3cwg-gccp GHSA-xmww-383x-h57w --- .../GHSA-363q-mrhx-5q4w.json | 25 ++++++++ .../GHSA-36c4-c6rg-wqpc.json | 25 ++++++++ .../GHSA-3f92-4q6m-m3rv.json | 25 ++++++++ .../GHSA-5jgj-vxr6-w56j.json | 53 +++++++++++++++++ .../GHSA-64fc-m8mv-x59j.json | 25 ++++++++ .../GHSA-72pc-mw67-6f3f.json | 53 +++++++++++++++++ .../GHSA-7wfr-865w-3mvg.json | 53 +++++++++++++++++ .../GHSA-8243-c3qw-cfqr.json | 25 ++++++++ .../GHSA-86pf-577r-267c.json | 53 +++++++++++++++++ .../GHSA-929h-9mmv-9rj6.json | 25 ++++++++ .../GHSA-fj6q-h8w7-mx3g.json | 53 +++++++++++++++++ .../GHSA-j8hf-p5v4-xpj9.json | 53 +++++++++++++++++ .../GHSA-j8p7-m3g9-jw25.json | 25 ++++++++ .../GHSA-jj9m-3528-27j2.json | 25 ++++++++ .../GHSA-m5ph-8w8x-4mpc.json | 25 ++++++++ .../GHSA-p9vx-xf7x-8hp9.json | 53 +++++++++++++++++ .../GHSA-pchj-w8gf-xx64.json | 25 ++++++++ .../GHSA-pjvr-p8qr-3fg8.json | 25 ++++++++ .../GHSA-vhj2-4h8c-jc8m.json | 57 +++++++++++++++++++ .../GHSA-vmwg-3cwg-gccp.json | 41 +++++++++++++ .../GHSA-xmww-383x-h57w.json | 53 +++++++++++++++++ 21 files changed, 797 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-363q-mrhx-5q4w/GHSA-363q-mrhx-5q4w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-36c4-c6rg-wqpc/GHSA-36c4-c6rg-wqpc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3f92-4q6m-m3rv/GHSA-3f92-4q6m-m3rv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5jgj-vxr6-w56j/GHSA-5jgj-vxr6-w56j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-64fc-m8mv-x59j/GHSA-64fc-m8mv-x59j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7wfr-865w-3mvg/GHSA-7wfr-865w-3mvg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8243-c3qw-cfqr/GHSA-8243-c3qw-cfqr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-929h-9mmv-9rj6/GHSA-929h-9mmv-9rj6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j8p7-m3g9-jw25/GHSA-j8p7-m3g9-jw25.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jj9m-3528-27j2/GHSA-jj9m-3528-27j2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m5ph-8w8x-4mpc/GHSA-m5ph-8w8x-4mpc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p9vx-xf7x-8hp9/GHSA-p9vx-xf7x-8hp9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pchj-w8gf-xx64/GHSA-pchj-w8gf-xx64.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pjvr-p8qr-3fg8/GHSA-pjvr-p8qr-3fg8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json diff --git a/advisories/unreviewed/2025/04/GHSA-363q-mrhx-5q4w/GHSA-363q-mrhx-5q4w.json b/advisories/unreviewed/2025/04/GHSA-363q-mrhx-5q4w/GHSA-363q-mrhx-5q4w.json new file mode 100644 index 00000000000..94362c528bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-363q-mrhx-5q4w/GHSA-363q-mrhx-5q4w.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-363q-mrhx-5q4w", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2018-13372" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-13372" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-36c4-c6rg-wqpc/GHSA-36c4-c6rg-wqpc.json b/advisories/unreviewed/2025/04/GHSA-36c4-c6rg-wqpc/GHSA-36c4-c6rg-wqpc.json new file mode 100644 index 00000000000..85e2b0d1f60 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-36c4-c6rg-wqpc/GHSA-36c4-c6rg-wqpc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36c4-c6rg-wqpc", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46753" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46753" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3f92-4q6m-m3rv/GHSA-3f92-4q6m-m3rv.json b/advisories/unreviewed/2025/04/GHSA-3f92-4q6m-m3rv/GHSA-3f92-4q6m-m3rv.json new file mode 100644 index 00000000000..c6fd8ba708c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3f92-4q6m-m3rv/GHSA-3f92-4q6m-m3rv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f92-4q6m-m3rv", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46757" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46757" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5jgj-vxr6-w56j/GHSA-5jgj-vxr6-w56j.json b/advisories/unreviewed/2025/04/GHSA-5jgj-vxr6-w56j/GHSA-5jgj-vxr6-w56j.json new file mode 100644 index 00000000000..d92d3c9c1ba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5jgj-vxr6-w56j/GHSA-5jgj-vxr6-w56j.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jgj-vxr6-w56j", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-24270" + ], + "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to leak sensitive user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24270" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-64fc-m8mv-x59j/GHSA-64fc-m8mv-x59j.json b/advisories/unreviewed/2025/04/GHSA-64fc-m8mv-x59j/GHSA-64fc-m8mv-x59j.json new file mode 100644 index 00000000000..ec74b9b34c3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-64fc-m8mv-x59j/GHSA-64fc-m8mv-x59j.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64fc-m8mv-x59j", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46760" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46760" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json b/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json new file mode 100644 index 00000000000..815aacc9255 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-72pc-mw67-6f3f/GHSA-72pc-mw67-6f3f.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72pc-mw67-6f3f", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-24271" + ], + "details": "An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24271" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7wfr-865w-3mvg/GHSA-7wfr-865w-3mvg.json b/advisories/unreviewed/2025/04/GHSA-7wfr-865w-3mvg/GHSA-7wfr-865w-3mvg.json new file mode 100644 index 00000000000..7762cc9a002 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7wfr-865w-3mvg/GHSA-7wfr-865w-3mvg.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wfr-865w-3mvg", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-24252" + ], + "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24252" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8243-c3qw-cfqr/GHSA-8243-c3qw-cfqr.json b/advisories/unreviewed/2025/04/GHSA-8243-c3qw-cfqr/GHSA-8243-c3qw-cfqr.json new file mode 100644 index 00000000000..10ecdc129bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8243-c3qw-cfqr/GHSA-8243-c3qw-cfqr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8243-c3qw-cfqr", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46756" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46756" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json b/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json new file mode 100644 index 00000000000..4264f654da2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-86pf-577r-267c/GHSA-86pf-577r-267c.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86pf-577r-267c", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-24179" + ], + "details": "A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, visionOS 2.3, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Sequoia 15.3, tvOS 18.3. An attacker on the local network may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24179" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122066" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122072" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122073" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-929h-9mmv-9rj6/GHSA-929h-9mmv-9rj6.json b/advisories/unreviewed/2025/04/GHSA-929h-9mmv-9rj6/GHSA-929h-9mmv-9rj6.json new file mode 100644 index 00000000000..43cfb27b3be --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-929h-9mmv-9rj6/GHSA-929h-9mmv-9rj6.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-929h-9mmv-9rj6", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46758" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46758" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json b/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json new file mode 100644 index 00000000000..4e59773a09b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fj6q-h8w7-mx3g/GHSA-fj6q-h8w7-mx3g.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj6q-h8w7-mx3g", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-31203" + ], + "details": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, watchOS 11.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31203" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122376" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json b/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json new file mode 100644 index 00000000000..2b5c99282db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8hf-p5v4-xpj9/GHSA-j8hf-p5v4-xpj9.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8hf-p5v4-xpj9", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-31197" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31197" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8p7-m3g9-jw25/GHSA-j8p7-m3g9-jw25.json b/advisories/unreviewed/2025/04/GHSA-j8p7-m3g9-jw25/GHSA-j8p7-m3g9-jw25.json new file mode 100644 index 00000000000..0b062400c5a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8p7-m3g9-jw25/GHSA-j8p7-m3g9-jw25.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8p7-m3g9-jw25", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46759" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46759" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jj9m-3528-27j2/GHSA-jj9m-3528-27j2.json b/advisories/unreviewed/2025/04/GHSA-jj9m-3528-27j2/GHSA-jj9m-3528-27j2.json new file mode 100644 index 00000000000..c06f469be52 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jj9m-3528-27j2/GHSA-jj9m-3528-27j2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj9m-3528-27j2", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46755" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46755" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m5ph-8w8x-4mpc/GHSA-m5ph-8w8x-4mpc.json b/advisories/unreviewed/2025/04/GHSA-m5ph-8w8x-4mpc/GHSA-m5ph-8w8x-4mpc.json new file mode 100644 index 00000000000..11c24e9cfc7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m5ph-8w8x-4mpc/GHSA-m5ph-8w8x-4mpc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5ph-8w8x-4mpc", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46761" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46761" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p9vx-xf7x-8hp9/GHSA-p9vx-xf7x-8hp9.json b/advisories/unreviewed/2025/04/GHSA-p9vx-xf7x-8hp9/GHSA-p9vx-xf7x-8hp9.json new file mode 100644 index 00000000000..5af88ea3ee7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p9vx-xf7x-8hp9/GHSA-p9vx-xf7x-8hp9.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9vx-xf7x-8hp9", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-24206" + ], + "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to bypass authentication policy.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24206" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pchj-w8gf-xx64/GHSA-pchj-w8gf-xx64.json b/advisories/unreviewed/2025/04/GHSA-pchj-w8gf-xx64/GHSA-pchj-w8gf-xx64.json new file mode 100644 index 00000000000..251fbc34fc4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pchj-w8gf-xx64/GHSA-pchj-w8gf-xx64.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pchj-w8gf-xx64", + "modified": "2025-04-29T03:30:32Z", + "published": "2025-04-29T03:30:32Z", + "aliases": [ + "CVE-2017-7740" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7740" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pjvr-p8qr-3fg8/GHSA-pjvr-p8qr-3fg8.json b/advisories/unreviewed/2025/04/GHSA-pjvr-p8qr-3fg8/GHSA-pjvr-p8qr-3fg8.json new file mode 100644 index 00000000000..e478dcc8857 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pjvr-p8qr-3fg8/GHSA-pjvr-p8qr-3fg8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjvr-p8qr-3fg8", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:34Z", + "aliases": [ + "CVE-2025-46754" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46754" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json b/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json new file mode 100644 index 00000000000..0c3c4103376 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhj2-4h8c-jc8m/GHSA-vhj2-4h8c-jc8m.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhj2-4h8c-jc8m", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-24251" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, watchOS 11.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24251" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122376" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json b/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json new file mode 100644 index 00000000000..be60d4d7308 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vmwg-3cwg-gccp/GHSA-vmwg-3cwg-gccp.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmwg-3cwg-gccp", + "modified": "2025-04-29T03:30:34Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-31202" + ], + "details": "A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31202" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json b/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json new file mode 100644 index 00000000000..271ef8f513b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xmww-383x-h57w/GHSA-xmww-383x-h57w.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmww-383x-h57w", + "modified": "2025-04-29T03:30:33Z", + "published": "2025-04-29T03:30:33Z", + "aliases": [ + "CVE-2025-30445" + ], + "details": "A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30445" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122371" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122373" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122374" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122375" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122377" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122378" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T03:15:34Z" + } +} \ No newline at end of file