From 3072f8ea6854c3fe5f9f218f6404862f2b9ddee6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 13 Apr 2025 21:32:17 +0000 Subject: [PATCH] Publish Advisories GHSA-53gr-8h72-9w7p GHSA-2j99-5q75-3f57 GHSA-p6jf-pv8c-623c GHSA-w9rr-95wc-r9jf --- .../GHSA-53gr-8h72-9w7p.json | 6 +- .../GHSA-2j99-5q75-3f57.json | 6 +- .../GHSA-p6jf-pv8c-623c.json | 2 +- .../GHSA-w9rr-95wc-r9jf.json | 56 +++++++++++++++++++ 4 files changed, 67 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-w9rr-95wc-r9jf/GHSA-w9rr-95wc-r9jf.json diff --git a/advisories/unreviewed/2024/12/GHSA-53gr-8h72-9w7p/GHSA-53gr-8h72-9w7p.json b/advisories/unreviewed/2024/12/GHSA-53gr-8h72-9w7p/GHSA-53gr-8h72-9w7p.json index e5257be7df4..b65bd1c7f5d 100644 --- a/advisories/unreviewed/2024/12/GHSA-53gr-8h72-9w7p/GHSA-53gr-8h72-9w7p.json +++ b/advisories/unreviewed/2024/12/GHSA-53gr-8h72-9w7p/GHSA-53gr-8h72-9w7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53gr-8h72-9w7p", - "modified": "2024-12-09T12:31:07Z", + "modified": "2025-04-13T21:30:25Z", "published": "2024-12-09T12:31:07Z", "aliases": [ "CVE-2024-46901" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46901" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00023.html" + }, { "type": "WEB", "url": "https://subversion.apache.org/security/CVE-2024-46901-advisory.txt" diff --git a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json index 29b6c2a7e8f..0def63176b8 100644 --- a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json +++ b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j99-5q75-3f57", - "modified": "2025-04-11T15:32:26Z", + "modified": "2025-04-13T21:30:25Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2025-24201" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://support.apple.com/en-us/122376" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Apr/16" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2025/Mar/2" diff --git a/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json b/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json index 6964f632fc2..c72433cb5c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json +++ b/advisories/unreviewed/2025/04/GHSA-p6jf-pv8c-623c/GHSA-p6jf-pv8c-623c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6jf-pv8c-623c", - "modified": "2025-04-13T18:30:32Z", + "modified": "2025-04-13T21:30:25Z", "published": "2025-04-13T15:30:21Z", "aliases": [ "CVE-2024-56406" diff --git a/advisories/unreviewed/2025/04/GHSA-w9rr-95wc-r9jf/GHSA-w9rr-95wc-r9jf.json b/advisories/unreviewed/2025/04/GHSA-w9rr-95wc-r9jf/GHSA-w9rr-95wc-r9jf.json new file mode 100644 index 00000000000..33fdec01ee2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w9rr-95wc-r9jf/GHSA-w9rr-95wc-r9jf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9rr-95wc-r9jf", + "modified": "2025-04-13T21:30:25Z", + "published": "2025-04-13T21:30:25Z", + "aliases": [ + "CVE-2025-3538" + ], + "details": "A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the component jhttpd. The manipulation of the argument callback leads to stack-based buffer overflow. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3538" + }, + { + "type": "WEB", + "url": "https://github.com/Fizz-L/CVE1/blob/main/DI-8100Command%20execution2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304577" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304577" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524224" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-13T19:15:14Z" + } +} \ No newline at end of file