Publish Advisories

GHSA-5rmc-9cm9-28cr
GHSA-66mh-pcv7-gg73
GHSA-8pmj-vrj3-r692
GHSA-fgjj-2m6m-vf56
GHSA-jm38-gf7c-9f3f
GHSA-mpmg-6f4c-m3x8
GHSA-qfqf-rmhj-ffx6
GHSA-vf8c-ccvq-v376
GHSA-vx3m-9554-cpqq
This commit is contained in:
advisory-database[bot]
2025-03-25 03:31:49 +00:00
parent 6b338ef561
commit 36a77a7974
9 changed files with 468 additions and 0 deletions
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rmc-9cm9-28cr",
"modified": "2025-03-25T03:30:25Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2728"
],
"details": "A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2728"
},
{
"type": "WEB",
"url": "https://github.com/RK1Y8/cve_cve/blob/main/h3c.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300748"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300748"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520462"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T03:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66mh-pcv7-gg73",
"modified": "2025-03-25T03:30:25Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2727"
],
"details": "A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2727"
},
{
"type": "WEB",
"url": "https://github.com/ggstrunk/CVE/blob/main/wizard_getNetworkStatus.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300747"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300747"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520394"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T03:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pmj-vrj3-r692",
"modified": "2025-03-25T03:30:25Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2729"
],
"details": "A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2729"
},
{
"type": "WEB",
"url": "https://github.com/Qwen11/CVE_store/blob/main/H3C/vulnerability%20Information_1.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300749"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300749"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520494"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T03:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgjj-2m6m-vf56",
"modified": "2025-03-25T03:30:24Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2726"
],
"details": "A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2726"
},
{
"type": "WEB",
"url": "https://github.com/ZIKH26/CVE-information/blob/master/H3C/Vulnerability%20Information_2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300746"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300746"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520393"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T03:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jm38-gf7c-9f3f",
"modified": "2025-03-25T03:30:25Z",
"published": "2025-03-25T03:30:25Z",
"aliases": [
"CVE-2025-2730"
],
"details": "A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2730"
},
{
"type": "WEB",
"url": "https://github.com/Qwen11/CVE_store/blob/main/H3C/vulnerability%20Information_2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300750"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300750"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520495"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T03:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpmg-6f4c-m3x8",
"modified": "2025-03-25T03:30:24Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2722"
],
"details": "A vulnerability was found in GNOME libgsf up to 1.14.53. It has been declared as critical. This vulnerability affects the function gsf_prop_settings_collect_va. The manipulation of the argument n_alloced_params leads to heap-based buffer overflow. Local access is required to approach this attack. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2722"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300742"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300742"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520182"
},
{
"type": "WEB",
"url": "https://www.gnome.org"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T01:15:11Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfqf-rmhj-ffx6",
"modified": "2025-03-25T03:30:24Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2724"
],
"details": "A vulnerability classified as problematic has been found in GNOME libgsf up to 1.14.53. Affected is the function sorting_key_copy. The manipulation of the argument Name leads to out-of-bounds read. It is possible to launch the attack on the local host. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2724"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300744"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300744"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520184"
},
{
"type": "WEB",
"url": "https://www.gnome.org"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T02:15:14Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf8c-ccvq-v376",
"modified": "2025-03-25T03:30:24Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2725"
],
"details": "A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2725"
},
{
"type": "WEB",
"url": "https://github.com/ZIKH26/CVE-information/blob/master/H3C/Vulnerability%20Information_1.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300745"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300745"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520390"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T03:15:16Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vx3m-9554-cpqq",
"modified": "2025-03-25T03:30:24Z",
"published": "2025-03-25T03:30:24Z",
"aliases": [
"CVE-2025-2723"
],
"details": "A vulnerability was found in GNOME libgsf up to 1.14.53. It has been rated as critical. This issue affects the function gsf_property_settings_collec. The manipulation of the argument n_alloced_params leads to heap-based buffer overflow. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2723"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300743"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300743"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.520183"
},
{
"type": "WEB",
"url": "https://www.gnome.org"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T01:15:11Z"
}
}