From 33864449fb20e6278a7296bba52a9247bb48cfe4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 4 Apr 2025 21:32:11 +0000 Subject: [PATCH] Publish Advisories GHSA-9p6p-h2p9-wv46 GHSA-4rq4-8r9h-8884 GHSA-722g-wg5c-74m2 GHSA-chp6-wqp3-f3gg GHSA-fxp5-2pjw-x9j4 GHSA-g9c9-v54c-gj4f GHSA-j7p9-8xw7-jgxw GHSA-g7w8-g554-fvr3 GHSA-r566-6rjj-gpgw GHSA-5j8h-9jcx-3px3 GHSA-6ppw-4vff-76v2 GHSA-7jfm-6phc-jjwh GHSA-7vjf-fgr6-pcmc GHSA-8cmp-jx7c-f587 GHSA-8hwm-7pvv-qmx5 GHSA-9jwq-9jr3-cjg5 GHSA-gq44-92v2-6j39 GHSA-h7mx-548v-cr9r GHSA-qgv4-vprj-x2fq GHSA-w3mx-ghvj-8vc2 GHSA-w9qw-39gf-jp7r GHSA-x8jj-j32x-rqj9 --- .../GHSA-9p6p-h2p9-wv46.json | 2 +- .../GHSA-4rq4-8r9h-8884.json | 4 +- .../GHSA-722g-wg5c-74m2.json | 4 +- .../GHSA-chp6-wqp3-f3gg.json | 2 +- .../GHSA-fxp5-2pjw-x9j4.json | 2 +- .../GHSA-g9c9-v54c-gj4f.json | 2 +- .../GHSA-j7p9-8xw7-jgxw.json | 4 +- .../GHSA-g7w8-g554-fvr3.json | 2 +- .../GHSA-r566-6rjj-gpgw.json | 15 +++-- .../GHSA-5j8h-9jcx-3px3.json | 15 +++-- .../GHSA-6ppw-4vff-76v2.json | 56 +++++++++++++++++++ .../GHSA-7jfm-6phc-jjwh.json | 15 +++-- .../GHSA-7vjf-fgr6-pcmc.json | 15 +++-- .../GHSA-8cmp-jx7c-f587.json | 52 +++++++++++++++++ .../GHSA-8hwm-7pvv-qmx5.json | 52 +++++++++++++++++ .../GHSA-9jwq-9jr3-cjg5.json | 6 +- .../GHSA-gq44-92v2-6j39.json | 52 +++++++++++++++++ .../GHSA-h7mx-548v-cr9r.json | 6 +- .../GHSA-qgv4-vprj-x2fq.json | 15 +++-- .../GHSA-w3mx-ghvj-8vc2.json | 15 +++-- .../GHSA-w9qw-39gf-jp7r.json | 15 +++-- .../GHSA-x8jj-j32x-rqj9.json | 15 +++-- 22 files changed, 324 insertions(+), 42 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-6ppw-4vff-76v2/GHSA-6ppw-4vff-76v2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8cmp-jx7c-f587/GHSA-8cmp-jx7c-f587.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8hwm-7pvv-qmx5/GHSA-8hwm-7pvv-qmx5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gq44-92v2-6j39/GHSA-gq44-92v2-6j39.json diff --git a/advisories/unreviewed/2022/05/GHSA-9p6p-h2p9-wv46/GHSA-9p6p-h2p9-wv46.json b/advisories/unreviewed/2022/05/GHSA-9p6p-h2p9-wv46/GHSA-9p6p-h2p9-wv46.json index 7895fc42dcb..8a43a6652d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9p6p-h2p9-wv46/GHSA-9p6p-h2p9-wv46.json +++ b/advisories/unreviewed/2022/05/GHSA-9p6p-h2p9-wv46/GHSA-9p6p-h2p9-wv46.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9p6p-h2p9-wv46", - "modified": "2022-05-14T01:05:22Z", + "modified": "2025-04-04T21:30:34Z", "published": "2022-05-14T01:05:22Z", "aliases": [ "CVE-2018-0878" diff --git a/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json b/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json index 4307049241d..cde271969fd 100644 --- a/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json +++ b/advisories/unreviewed/2023/01/GHSA-4rq4-8r9h-8884/GHSA-4rq4-8r9h-8884.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-248" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-722g-wg5c-74m2/GHSA-722g-wg5c-74m2.json b/advisories/unreviewed/2023/01/GHSA-722g-wg5c-74m2/GHSA-722g-wg5c-74m2.json index 45fc68e401f..1150c307443 100644 --- a/advisories/unreviewed/2023/01/GHSA-722g-wg5c-74m2/GHSA-722g-wg5c-74m2.json +++ b/advisories/unreviewed/2023/01/GHSA-722g-wg5c-74m2/GHSA-722g-wg5c-74m2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json b/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json index 748d2999ba2..179190206f3 100644 --- a/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json +++ b/advisories/unreviewed/2023/01/GHSA-chp6-wqp3-f3gg/GHSA-chp6-wqp3-f3gg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chp6-wqp3-f3gg", - "modified": "2023-01-23T21:30:26Z", + "modified": "2025-04-04T21:30:44Z", "published": "2023-01-17T21:30:21Z", "aliases": [ "CVE-2023-0122" diff --git a/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json b/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json index e047352e05d..976220d5fe1 100644 --- a/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json +++ b/advisories/unreviewed/2023/01/GHSA-fxp5-2pjw-x9j4/GHSA-fxp5-2pjw-x9j4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fxp5-2pjw-x9j4", - "modified": "2023-01-24T21:30:30Z", + "modified": "2025-04-04T21:30:41Z", "published": "2023-01-16T18:30:26Z", "aliases": [ "CVE-2022-4547" diff --git a/advisories/unreviewed/2023/01/GHSA-g9c9-v54c-gj4f/GHSA-g9c9-v54c-gj4f.json b/advisories/unreviewed/2023/01/GHSA-g9c9-v54c-gj4f/GHSA-g9c9-v54c-gj4f.json index 473bf615e36..295dcb092f8 100644 --- a/advisories/unreviewed/2023/01/GHSA-g9c9-v54c-gj4f/GHSA-g9c9-v54c-gj4f.json +++ b/advisories/unreviewed/2023/01/GHSA-g9c9-v54c-gj4f/GHSA-g9c9-v54c-gj4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9c9-v54c-gj4f", - "modified": "2023-01-25T00:30:39Z", + "modified": "2025-04-04T21:30:42Z", "published": "2023-01-17T12:30:33Z", "aliases": [ "CVE-2023-22279" diff --git a/advisories/unreviewed/2023/01/GHSA-j7p9-8xw7-jgxw/GHSA-j7p9-8xw7-jgxw.json b/advisories/unreviewed/2023/01/GHSA-j7p9-8xw7-jgxw/GHSA-j7p9-8xw7-jgxw.json index 152dfe26179..41bcb725e55 100644 --- a/advisories/unreviewed/2023/01/GHSA-j7p9-8xw7-jgxw/GHSA-j7p9-8xw7-jgxw.json +++ b/advisories/unreviewed/2023/01/GHSA-j7p9-8xw7-jgxw/GHSA-j7p9-8xw7-jgxw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-g7w8-g554-fvr3/GHSA-g7w8-g554-fvr3.json b/advisories/unreviewed/2023/02/GHSA-g7w8-g554-fvr3/GHSA-g7w8-g554-fvr3.json index 18a02f813e7..a5afa2483b5 100644 --- a/advisories/unreviewed/2023/02/GHSA-g7w8-g554-fvr3/GHSA-g7w8-g554-fvr3.json +++ b/advisories/unreviewed/2023/02/GHSA-g7w8-g554-fvr3/GHSA-g7w8-g554-fvr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7w8-g554-fvr3", - "modified": "2023-02-10T03:30:20Z", + "modified": "2025-04-04T21:30:44Z", "published": "2023-02-03T18:30:26Z", "aliases": [ "CVE-2021-37497" diff --git a/advisories/unreviewed/2024/12/GHSA-r566-6rjj-gpgw/GHSA-r566-6rjj-gpgw.json b/advisories/unreviewed/2024/12/GHSA-r566-6rjj-gpgw/GHSA-r566-6rjj-gpgw.json index 9c0f2403bf8..b19d69dda90 100644 --- a/advisories/unreviewed/2024/12/GHSA-r566-6rjj-gpgw/GHSA-r566-6rjj-gpgw.json +++ b/advisories/unreviewed/2024/12/GHSA-r566-6rjj-gpgw/GHSA-r566-6rjj-gpgw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r566-6rjj-gpgw", - "modified": "2024-12-19T00:37:35Z", + "modified": "2025-04-04T21:30:45Z", "published": "2024-12-19T00:37:35Z", "aliases": [ "CVE-2024-55505" ], "details": "An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T22:15:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json b/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json index 5db6e3f27ab..8a6801e2673 100644 --- a/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json +++ b/advisories/unreviewed/2025/04/GHSA-5j8h-9jcx-3px3/GHSA-5j8h-9jcx-3px3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5j8h-9jcx-3px3", - "modified": "2025-04-01T00:30:45Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-01T00:30:45Z", "aliases": [ "CVE-2025-3061" ], "details": "Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:30Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6ppw-4vff-76v2/GHSA-6ppw-4vff-76v2.json b/advisories/unreviewed/2025/04/GHSA-6ppw-4vff-76v2/GHSA-6ppw-4vff-76v2.json new file mode 100644 index 00000000000..3115fe1d1c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6ppw-4vff-76v2/GHSA-6ppw-4vff-76v2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ppw-4vff-76v2", + "modified": "2025-04-04T21:30:51Z", + "published": "2025-04-04T21:30:51Z", + "aliases": [ + "CVE-2025-3265" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-category.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3265" + }, + { + "type": "WEB", + "url": "https://github.com/yasuoz99/CVE-/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303337" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303337" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json b/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json index edc4f6cfb04..11ef0d46cd6 100644 --- a/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json +++ b/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7jfm-6phc-jjwh", - "modified": "2025-04-01T21:31:30Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-01T21:31:30Z", "aliases": [ "CVE-2025-29033" ], "details": "An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=\" HTTP GET parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T21:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7vjf-fgr6-pcmc/GHSA-7vjf-fgr6-pcmc.json b/advisories/unreviewed/2025/04/GHSA-7vjf-fgr6-pcmc/GHSA-7vjf-fgr6-pcmc.json index d4dbb1e8362..87c4b1c2496 100644 --- a/advisories/unreviewed/2025/04/GHSA-7vjf-fgr6-pcmc/GHSA-7vjf-fgr6-pcmc.json +++ b/advisories/unreviewed/2025/04/GHSA-7vjf-fgr6-pcmc/GHSA-7vjf-fgr6-pcmc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7vjf-fgr6-pcmc", - "modified": "2025-04-02T00:31:41Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-02T00:31:41Z", "aliases": [ "CVE-2023-46988" ], "details": "Directory Traversal vulnerability in ONLYOFFICE Document Server v.7.5.0 and before allows a remote attacker to obtain sensitive information via a crafted file upload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T22:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8cmp-jx7c-f587/GHSA-8cmp-jx7c-f587.json b/advisories/unreviewed/2025/04/GHSA-8cmp-jx7c-f587/GHSA-8cmp-jx7c-f587.json new file mode 100644 index 00000000000..566fd8a4d6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8cmp-jx7c-f587/GHSA-8cmp-jx7c-f587.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cmp-jx7c-f587", + "modified": "2025-04-04T21:30:51Z", + "published": "2025-04-04T21:30:51Z", + "aliases": [ + "CVE-2025-3266" + ], + "details": "A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this issue is some unknown functionality of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3266" + }, + { + "type": "WEB", + "url": "https://magnificent-dill-351.notion.site/Stack-Overflow-in-TinyWebServer-1-0-1c9c693918ed80229bbce911b3513054" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303338" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303338" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8hwm-7pvv-qmx5/GHSA-8hwm-7pvv-qmx5.json b/advisories/unreviewed/2025/04/GHSA-8hwm-7pvv-qmx5/GHSA-8hwm-7pvv-qmx5.json new file mode 100644 index 00000000000..f24d596d9e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8hwm-7pvv-qmx5/GHSA-8hwm-7pvv-qmx5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hwm-7pvv-qmx5", + "modified": "2025-04-04T21:30:51Z", + "published": "2025-04-04T21:30:51Z", + "aliases": [ + "CVE-2025-3267" + ], + "details": "A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3267" + }, + { + "type": "WEB", + "url": "https://magnificent-dill-351.notion.site/SQL-Injection-in-TinyWebServer-1-0-1c9c693918ed800ba172f55997565735" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303339" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303339" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549228" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json b/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json index ebc9f924dbc..3fa306c0313 100644 --- a/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json +++ b/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jwq-9jr3-cjg5", - "modified": "2025-04-04T18:31:07Z", + "modified": "2025-04-04T21:30:51Z", "published": "2025-04-04T18:31:07Z", "aliases": [ "CVE-2025-3259" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3259" }, + { + "type": "WEB", + "url": "https://sixth-action-50e.notion.site/Tenda-RX3-Buffer-Overflow-1c9f6468377380a2977cd6c3a81f453c" + }, { "type": "WEB", "url": "https://sixth-action-50e.notion.site/Tenda-RX3-Buffer-Overflow-1c9f6468377380a2977cd6c3a81f453c?pvs=4" diff --git a/advisories/unreviewed/2025/04/GHSA-gq44-92v2-6j39/GHSA-gq44-92v2-6j39.json b/advisories/unreviewed/2025/04/GHSA-gq44-92v2-6j39/GHSA-gq44-92v2-6j39.json new file mode 100644 index 00000000000..e1a2fa91b3f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gq44-92v2-6j39/GHSA-gq44-92v2-6j39.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq44-92v2-6j39", + "modified": "2025-04-04T21:30:51Z", + "published": "2025-04-04T21:30:51Z", + "aliases": [ + "CVE-2025-3268" + ], + "details": "A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3268" + }, + { + "type": "WEB", + "url": "https://magnificent-dill-351.notion.site/Improper-Authentication-in-TinyWebServer-1-0-1c9c693918ed80cfa0f5db1a1d03c5e7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303340" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303340" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json index cd94c76b076..170fdd01799 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json +++ b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7mx-548v-cr9r", - "modified": "2025-04-03T15:31:19Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-3155" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357091" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/04/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json b/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json index cc82c78fd2b..4e3cc33cc45 100644 --- a/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json +++ b/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgv4-vprj-x2fq", - "modified": "2025-04-04T03:30:19Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-01T21:31:30Z", "aliases": [ "CVE-2025-29070" ], "details": "A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T21:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json b/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json index 30ebc54be0e..a283967f75a 100644 --- a/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json +++ b/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3mx-ghvj-8vc2", - "modified": "2025-04-01T21:31:29Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-01T21:31:29Z", "aliases": [ "CVE-2003-20001" ], "details": "An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T21:15:40Z" diff --git a/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json b/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json index 2507ee82e64..76410d54bb1 100644 --- a/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json +++ b/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w9qw-39gf-jp7r", - "modified": "2025-04-03T21:32:57Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-01T21:31:29Z", "aliases": [ "CVE-2025-29069" ], "details": "A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T20:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json b/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json index 81be21cf1f0..bdc915745c4 100644 --- a/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json +++ b/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8jj-j32x-rqj9", - "modified": "2025-04-01T21:31:30Z", + "modified": "2025-04-04T21:30:50Z", "published": "2025-04-01T21:31:30Z", "aliases": [ "CVE-2025-29036" ], "details": "An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T21:15:43Z"