Publish Advisories

GHSA-5qm4-cm2h-3cgf
GHSA-6qxv-37xg-xg4w
GHSA-h6j7-2w2f-q5rm
GHSA-5mr2-xg52-9g99
GHSA-66rh-m5r2-4gx2
GHSA-68jf-3wjw-q37v
GHSA-fphw-hp4w-p8m4
GHSA-pq3r-x8gq-g8xm
GHSA-r955-pv6h-62wj
GHSA-v43g-f5c4-v4jm
GHSA-vqfj-mm88-89m5
GHSA-4545-q8rv-g7f9
GHSA-866w-76w7-m942
GHSA-9qcv-f3w6-jhh5
GHSA-m5hx-8765-fjpm
GHSA-63xr-9hmx-v966
GHSA-6g48-x687-vqf9
GHSA-h735-q6rm-hjcj
GHSA-xqm8-c3rv-5vpf
This commit is contained in:
advisory-database[bot]
2025-01-03 18:31:38 +00:00
parent 1643472e73
commit 336fbccb81
19 changed files with 192 additions and 14 deletions
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-312",
"CWE-522"
],
"severity": "MODERATE",
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-203"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-345"
"CWE-345",
"CWE-346"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m5hx-8765-fjpm",
"modified": "2024-12-12T03:33:00Z",
"modified": "2025-01-03T18:30:33Z",
"published": "2024-12-08T00:31:20Z",
"aliases": [
"CVE-2024-53473"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://github.com/nilsonLazarin/WeGIA/commit/3998672f1b86db58eab2808a640903d73b37bd2d"
},
{
"type": "WEB",
"url": "https://github.com/nmmorette/vulnerability-research/blob/main/CVE-2024-53473/README.md"
},
{
"type": "WEB",
"url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-53473"
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63xr-9hmx-v966",
"modified": "2025-01-03T18:30:34Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2024-35365"
],
"details": "FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35365"
},
{
"type": "WEB",
"url": "https://github.com/ffmpeg/ffmpeg/commit/ced5c5fdb8634d39ca9472a2026b2d2fea16c4e5"
},
{
"type": "WEB",
"url": "https://gist.github.com/1047524396/d7d4ea8055b75c4a9f9bbcff31d21423"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/fftools/ffmpeg_mux_init.c#L886"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T18:15:15Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6g48-x687-vqf9",
"modified": "2025-01-03T18:30:34Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2025-0195"
],
"details": "A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0195"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/Masamuneee/1ac717728823d58ef365a418c8f39810"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.290132"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.290132"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.473349"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T18:15:17Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h735-q6rm-hjcj",
"modified": "2025-01-03T18:30:34Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2024-55507"
],
"details": "An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55507"
},
{
"type": "WEB",
"url": "https://github.com/CV1523/CVEs/blob/main/CVE-2024-55507.md"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T16:15:26Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqm8-c3rv-5vpf",
"modified": "2025-01-03T18:30:34Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2024-36613"
],
"details": "FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36613"
},
{
"type": "WEB",
"url": "https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540"
},
{
"type": "WEB",
"url": "https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T18:15:15Z"
}
}