diff --git a/advisories/unreviewed/2023/05/GHSA-w9r9-chq3-mf43/GHSA-w9r9-chq3-mf43.json b/advisories/unreviewed/2023/05/GHSA-w9r9-chq3-mf43/GHSA-w9r9-chq3-mf43.json index a43434939b6..f5d4175f657 100644 --- a/advisories/unreviewed/2023/05/GHSA-w9r9-chq3-mf43/GHSA-w9r9-chq3-mf43.json +++ b/advisories/unreviewed/2023/05/GHSA-w9r9-chq3-mf43/GHSA-w9r9-chq3-mf43.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-34wm-j673-236g/GHSA-34wm-j673-236g.json b/advisories/unreviewed/2024/02/GHSA-34wm-j673-236g/GHSA-34wm-j673-236g.json index 68442987b83..45468ae63f6 100644 --- a/advisories/unreviewed/2024/02/GHSA-34wm-j673-236g/GHSA-34wm-j673-236g.json +++ b/advisories/unreviewed/2024/02/GHSA-34wm-j673-236g/GHSA-34wm-j673-236g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34wm-j673-236g", - "modified": "2024-02-14T18:30:26Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-24775" diff --git a/advisories/unreviewed/2024/02/GHSA-4x3g-wfmq-27q5/GHSA-4x3g-wfmq-27q5.json b/advisories/unreviewed/2024/02/GHSA-4x3g-wfmq-27q5/GHSA-4x3g-wfmq-27q5.json index ec40b35e643..a7965875a08 100644 --- a/advisories/unreviewed/2024/02/GHSA-4x3g-wfmq-27q5/GHSA-4x3g-wfmq-27q5.json +++ b/advisories/unreviewed/2024/02/GHSA-4x3g-wfmq-27q5/GHSA-4x3g-wfmq-27q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4x3g-wfmq-27q5", - "modified": "2024-02-14T18:30:25Z", + "modified": "2025-01-23T21:31:47Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-22093" diff --git a/advisories/unreviewed/2024/02/GHSA-5qf5-p4mh-hv7h/GHSA-5qf5-p4mh-hv7h.json b/advisories/unreviewed/2024/02/GHSA-5qf5-p4mh-hv7h/GHSA-5qf5-p4mh-hv7h.json index 363977709d9..f8dde464b4e 100644 --- a/advisories/unreviewed/2024/02/GHSA-5qf5-p4mh-hv7h/GHSA-5qf5-p4mh-hv7h.json +++ b/advisories/unreviewed/2024/02/GHSA-5qf5-p4mh-hv7h/GHSA-5qf5-p4mh-hv7h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qf5-p4mh-hv7h", - "modified": "2024-02-14T18:30:25Z", + "modified": "2025-01-23T21:31:47Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-23306" diff --git a/advisories/unreviewed/2024/02/GHSA-5qm7-5w7x-5mcg/GHSA-5qm7-5w7x-5mcg.json b/advisories/unreviewed/2024/02/GHSA-5qm7-5w7x-5mcg/GHSA-5qm7-5w7x-5mcg.json index d372ffb1bf0..aa210ed803b 100644 --- a/advisories/unreviewed/2024/02/GHSA-5qm7-5w7x-5mcg/GHSA-5qm7-5w7x-5mcg.json +++ b/advisories/unreviewed/2024/02/GHSA-5qm7-5w7x-5mcg/GHSA-5qm7-5w7x-5mcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qm7-5w7x-5mcg", - "modified": "2024-02-15T03:30:20Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-02-15T03:30:20Z", "aliases": [ "CVE-2024-26261" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26261" }, + { + "type": "WEB", + "url": "https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html" diff --git a/advisories/unreviewed/2024/02/GHSA-8gwr-pghr-44v9/GHSA-8gwr-pghr-44v9.json b/advisories/unreviewed/2024/02/GHSA-8gwr-pghr-44v9/GHSA-8gwr-pghr-44v9.json index 1d77e7e6fba..1f4b01868d5 100644 --- a/advisories/unreviewed/2024/02/GHSA-8gwr-pghr-44v9/GHSA-8gwr-pghr-44v9.json +++ b/advisories/unreviewed/2024/02/GHSA-8gwr-pghr-44v9/GHSA-8gwr-pghr-44v9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gwr-pghr-44v9", - "modified": "2024-02-14T18:30:25Z", + "modified": "2025-01-23T21:31:47Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-21771" diff --git a/advisories/unreviewed/2024/02/GHSA-gwgj-3v6v-5fj2/GHSA-gwgj-3v6v-5fj2.json b/advisories/unreviewed/2024/02/GHSA-gwgj-3v6v-5fj2/GHSA-gwgj-3v6v-5fj2.json index 54a5ec6b624..d8bb2741220 100644 --- a/advisories/unreviewed/2024/02/GHSA-gwgj-3v6v-5fj2/GHSA-gwgj-3v6v-5fj2.json +++ b/advisories/unreviewed/2024/02/GHSA-gwgj-3v6v-5fj2/GHSA-gwgj-3v6v-5fj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gwgj-3v6v-5fj2", - "modified": "2024-02-14T18:30:26Z", + "modified": "2025-01-23T21:31:47Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-23805" diff --git a/advisories/unreviewed/2024/02/GHSA-gx7x-8xvv-gh38/GHSA-gx7x-8xvv-gh38.json b/advisories/unreviewed/2024/02/GHSA-gx7x-8xvv-gh38/GHSA-gx7x-8xvv-gh38.json index a60162b561b..0154ada2c5b 100644 --- a/advisories/unreviewed/2024/02/GHSA-gx7x-8xvv-gh38/GHSA-gx7x-8xvv-gh38.json +++ b/advisories/unreviewed/2024/02/GHSA-gx7x-8xvv-gh38/GHSA-gx7x-8xvv-gh38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx7x-8xvv-gh38", - "modified": "2024-02-14T18:30:26Z", + "modified": "2025-01-23T21:31:47Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-23976" diff --git a/advisories/unreviewed/2024/02/GHSA-hvxg-wm6p-c93r/GHSA-hvxg-wm6p-c93r.json b/advisories/unreviewed/2024/02/GHSA-hvxg-wm6p-c93r/GHSA-hvxg-wm6p-c93r.json index 71c0786a201..c08e1de10cc 100644 --- a/advisories/unreviewed/2024/02/GHSA-hvxg-wm6p-c93r/GHSA-hvxg-wm6p-c93r.json +++ b/advisories/unreviewed/2024/02/GHSA-hvxg-wm6p-c93r/GHSA-hvxg-wm6p-c93r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hvxg-wm6p-c93r", - "modified": "2024-02-15T03:30:20Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-02-15T03:30:20Z", "aliases": [ "CVE-2024-26260" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26260" }, + { + "type": "WEB", + "url": "https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/tw/cp-132-7673-688b7-1.html" diff --git a/advisories/unreviewed/2024/03/GHSA-3p73-75xq-v9wv/GHSA-3p73-75xq-v9wv.json b/advisories/unreviewed/2024/03/GHSA-3p73-75xq-v9wv/GHSA-3p73-75xq-v9wv.json index ac72ea28229..be21de24a93 100644 --- a/advisories/unreviewed/2024/03/GHSA-3p73-75xq-v9wv/GHSA-3p73-75xq-v9wv.json +++ b/advisories/unreviewed/2024/03/GHSA-3p73-75xq-v9wv/GHSA-3p73-75xq-v9wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3p73-75xq-v9wv", - "modified": "2024-03-12T09:30:42Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-03-12T09:30:42Z", "aliases": [ "CVE-2024-26001" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-3q3p-mxc5-jrmq/GHSA-3q3p-mxc5-jrmq.json b/advisories/unreviewed/2024/03/GHSA-3q3p-mxc5-jrmq/GHSA-3q3p-mxc5-jrmq.json index 11fb981a637..d552a584bad 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q3p-mxc5-jrmq/GHSA-3q3p-mxc5-jrmq.json +++ b/advisories/unreviewed/2024/03/GHSA-3q3p-mxc5-jrmq/GHSA-3q3p-mxc5-jrmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q3p-mxc5-jrmq", - "modified": "2024-03-12T09:30:42Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-03-12T09:30:42Z", "aliases": [ "CVE-2024-26000" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json index 8c92fe01d2d..0044f47f6a2 100644 --- a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json +++ b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-44xr-qjp2-rmf4/GHSA-44xr-qjp2-rmf4.json b/advisories/unreviewed/2024/03/GHSA-44xr-qjp2-rmf4/GHSA-44xr-qjp2-rmf4.json index 14b1a26af59..9f109cf75e5 100644 --- a/advisories/unreviewed/2024/03/GHSA-44xr-qjp2-rmf4/GHSA-44xr-qjp2-rmf4.json +++ b/advisories/unreviewed/2024/03/GHSA-44xr-qjp2-rmf4/GHSA-44xr-qjp2-rmf4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-48pg-h3wr-cm2c/GHSA-48pg-h3wr-cm2c.json b/advisories/unreviewed/2024/03/GHSA-48pg-h3wr-cm2c/GHSA-48pg-h3wr-cm2c.json index 9cf68a14836..3d569083151 100644 --- a/advisories/unreviewed/2024/03/GHSA-48pg-h3wr-cm2c/GHSA-48pg-h3wr-cm2c.json +++ b/advisories/unreviewed/2024/03/GHSA-48pg-h3wr-cm2c/GHSA-48pg-h3wr-cm2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48pg-h3wr-cm2c", - "modified": "2024-03-13T18:31:32Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-03-13T18:31:32Z", "aliases": [ "CVE-2024-0377" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-54j6-6hq9-52fg/GHSA-54j6-6hq9-52fg.json b/advisories/unreviewed/2024/03/GHSA-54j6-6hq9-52fg/GHSA-54j6-6hq9-52fg.json index ed338bc7e0a..08f8ad9c130 100644 --- a/advisories/unreviewed/2024/03/GHSA-54j6-6hq9-52fg/GHSA-54j6-6hq9-52fg.json +++ b/advisories/unreviewed/2024/03/GHSA-54j6-6hq9-52fg/GHSA-54j6-6hq9-52fg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54j6-6hq9-52fg", - "modified": "2024-03-12T09:30:42Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-03-12T09:30:42Z", "aliases": [ "CVE-2024-25994" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-65mr-fw35-qf44/GHSA-65mr-fw35-qf44.json b/advisories/unreviewed/2024/03/GHSA-65mr-fw35-qf44/GHSA-65mr-fw35-qf44.json index aa49e2d6a9e..bdcf63e8585 100644 --- a/advisories/unreviewed/2024/03/GHSA-65mr-fw35-qf44/GHSA-65mr-fw35-qf44.json +++ b/advisories/unreviewed/2024/03/GHSA-65mr-fw35-qf44/GHSA-65mr-fw35-qf44.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65mr-fw35-qf44", - "modified": "2024-03-15T00:30:22Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-15T00:30:22Z", "aliases": [ "CVE-2024-26475" ], "details": "An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T22:15:22Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json b/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json index ea15d92a8ce..71ff038c07b 100644 --- a/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json +++ b/advisories/unreviewed/2024/03/GHSA-6xfp-26pf-r3p6/GHSA-6xfp-26pf-r3p6.json @@ -27,7 +27,8 @@ "database_specific": { "cwe_ids": [ "CWE-74", - "CWE-76" + "CWE-76", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-72hq-qgjx-8fhx/GHSA-72hq-qgjx-8fhx.json b/advisories/unreviewed/2024/03/GHSA-72hq-qgjx-8fhx/GHSA-72hq-qgjx-8fhx.json index 377294d6f8c..c39998b4f1d 100644 --- a/advisories/unreviewed/2024/03/GHSA-72hq-qgjx-8fhx/GHSA-72hq-qgjx-8fhx.json +++ b/advisories/unreviewed/2024/03/GHSA-72hq-qgjx-8fhx/GHSA-72hq-qgjx-8fhx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-72hq-qgjx-8fhx", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1409" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-92r5-9pqm-cxcj/GHSA-92r5-9pqm-cxcj.json b/advisories/unreviewed/2024/03/GHSA-92r5-9pqm-cxcj/GHSA-92r5-9pqm-cxcj.json index 082cc2bc6e9..5d7445b726a 100644 --- a/advisories/unreviewed/2024/03/GHSA-92r5-9pqm-cxcj/GHSA-92r5-9pqm-cxcj.json +++ b/advisories/unreviewed/2024/03/GHSA-92r5-9pqm-cxcj/GHSA-92r5-9pqm-cxcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92r5-9pqm-cxcj", - "modified": "2024-03-15T06:30:34Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-15T06:30:34Z", "aliases": [ "CVE-2024-2480" diff --git a/advisories/unreviewed/2024/03/GHSA-9rq9-8fj4-xfv5/GHSA-9rq9-8fj4-xfv5.json b/advisories/unreviewed/2024/03/GHSA-9rq9-8fj4-xfv5/GHSA-9rq9-8fj4-xfv5.json index 5bccf547ff8..ffe39a046fe 100644 --- a/advisories/unreviewed/2024/03/GHSA-9rq9-8fj4-xfv5/GHSA-9rq9-8fj4-xfv5.json +++ b/advisories/unreviewed/2024/03/GHSA-9rq9-8fj4-xfv5/GHSA-9rq9-8fj4-xfv5.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ccc2-7fh4-pj2x/GHSA-ccc2-7fh4-pj2x.json b/advisories/unreviewed/2024/03/GHSA-ccc2-7fh4-pj2x/GHSA-ccc2-7fh4-pj2x.json index 5933c557e81..3d4045b0324 100644 --- a/advisories/unreviewed/2024/03/GHSA-ccc2-7fh4-pj2x/GHSA-ccc2-7fh4-pj2x.json +++ b/advisories/unreviewed/2024/03/GHSA-ccc2-7fh4-pj2x/GHSA-ccc2-7fh4-pj2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ccc2-7fh4-pj2x", - "modified": "2024-03-15T06:30:33Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-15T06:30:33Z", "aliases": [ "CVE-2024-25227" ], "details": "SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T06:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-cf7p-r9h9-x3gj/GHSA-cf7p-r9h9-x3gj.json b/advisories/unreviewed/2024/03/GHSA-cf7p-r9h9-x3gj/GHSA-cf7p-r9h9-x3gj.json index 1810b6c65cc..c02e4be529d 100644 --- a/advisories/unreviewed/2024/03/GHSA-cf7p-r9h9-x3gj/GHSA-cf7p-r9h9-x3gj.json +++ b/advisories/unreviewed/2024/03/GHSA-cf7p-r9h9-x3gj/GHSA-cf7p-r9h9-x3gj.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cmmr-m837-c539/GHSA-cmmr-m837-c539.json b/advisories/unreviewed/2024/03/GHSA-cmmr-m837-c539/GHSA-cmmr-m837-c539.json index 0c0a79d8d9f..84f69a05268 100644 --- a/advisories/unreviewed/2024/03/GHSA-cmmr-m837-c539/GHSA-cmmr-m837-c539.json +++ b/advisories/unreviewed/2024/03/GHSA-cmmr-m837-c539/GHSA-cmmr-m837-c539.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmmr-m837-c539", - "modified": "2024-03-15T15:30:43Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-15T15:30:43Z", "aliases": [ "CVE-2024-25593" diff --git a/advisories/unreviewed/2024/03/GHSA-cq96-g7rw-4595/GHSA-cq96-g7rw-4595.json b/advisories/unreviewed/2024/03/GHSA-cq96-g7rw-4595/GHSA-cq96-g7rw-4595.json index 68fb44b8f69..3bdedf35118 100644 --- a/advisories/unreviewed/2024/03/GHSA-cq96-g7rw-4595/GHSA-cq96-g7rw-4595.json +++ b/advisories/unreviewed/2024/03/GHSA-cq96-g7rw-4595/GHSA-cq96-g7rw-4595.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-f67x-2xxx-wc98/GHSA-f67x-2xxx-wc98.json b/advisories/unreviewed/2024/03/GHSA-f67x-2xxx-wc98/GHSA-f67x-2xxx-wc98.json index 1aa3ff7a90a..2a77af8c2e3 100644 --- a/advisories/unreviewed/2024/03/GHSA-f67x-2xxx-wc98/GHSA-f67x-2xxx-wc98.json +++ b/advisories/unreviewed/2024/03/GHSA-f67x-2xxx-wc98/GHSA-f67x-2xxx-wc98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f67x-2xxx-wc98", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-1806" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fcvq-8pj4-r94x/GHSA-fcvq-8pj4-r94x.json b/advisories/unreviewed/2024/03/GHSA-fcvq-8pj4-r94x/GHSA-fcvq-8pj4-r94x.json index ea2e2aec8ba..283aea5820b 100644 --- a/advisories/unreviewed/2024/03/GHSA-fcvq-8pj4-r94x/GHSA-fcvq-8pj4-r94x.json +++ b/advisories/unreviewed/2024/03/GHSA-fcvq-8pj4-r94x/GHSA-fcvq-8pj4-r94x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fcvq-8pj4-r94x", - "modified": "2024-03-12T09:30:42Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-03-12T09:30:42Z", "aliases": [ "CVE-2024-25999" diff --git a/advisories/unreviewed/2024/03/GHSA-fcx8-38mg-gr6r/GHSA-fcx8-38mg-gr6r.json b/advisories/unreviewed/2024/03/GHSA-fcx8-38mg-gr6r/GHSA-fcx8-38mg-gr6r.json index 91b48b2f48a..394b205074c 100644 --- a/advisories/unreviewed/2024/03/GHSA-fcx8-38mg-gr6r/GHSA-fcx8-38mg-gr6r.json +++ b/advisories/unreviewed/2024/03/GHSA-fcx8-38mg-gr6r/GHSA-fcx8-38mg-gr6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fcx8-38mg-gr6r", - "modified": "2024-03-12T09:30:42Z", + "modified": "2025-01-23T21:31:48Z", "published": "2024-03-12T09:30:42Z", "aliases": [ "CVE-2024-25998" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-gr37-6cx4-ch8m/GHSA-gr37-6cx4-ch8m.json b/advisories/unreviewed/2024/03/GHSA-gr37-6cx4-ch8m/GHSA-gr37-6cx4-ch8m.json index 50aab8d179f..cd03475e25a 100644 --- a/advisories/unreviewed/2024/03/GHSA-gr37-6cx4-ch8m/GHSA-gr37-6cx4-ch8m.json +++ b/advisories/unreviewed/2024/03/GHSA-gr37-6cx4-ch8m/GHSA-gr37-6cx4-ch8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gr37-6cx4-ch8m", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-1684" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-h4j9-fx9v-cwgq/GHSA-h4j9-fx9v-cwgq.json b/advisories/unreviewed/2024/03/GHSA-h4j9-fx9v-cwgq/GHSA-h4j9-fx9v-cwgq.json index 976cdbbdd69..74f4a8b537d 100644 --- a/advisories/unreviewed/2024/03/GHSA-h4j9-fx9v-cwgq/GHSA-h4j9-fx9v-cwgq.json +++ b/advisories/unreviewed/2024/03/GHSA-h4j9-fx9v-cwgq/GHSA-h4j9-fx9v-cwgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h4j9-fx9v-cwgq", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-25101" diff --git a/advisories/unreviewed/2024/03/GHSA-h6gq-c5v8-r5hw/GHSA-h6gq-c5v8-r5hw.json b/advisories/unreviewed/2024/03/GHSA-h6gq-c5v8-r5hw/GHSA-h6gq-c5v8-r5hw.json index 2ee22039378..b77038ce24d 100644 --- a/advisories/unreviewed/2024/03/GHSA-h6gq-c5v8-r5hw/GHSA-h6gq-c5v8-r5hw.json +++ b/advisories/unreviewed/2024/03/GHSA-h6gq-c5v8-r5hw/GHSA-h6gq-c5v8-r5hw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6gq-c5v8-r5hw", - "modified": "2024-03-29T09:30:43Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-29T09:30:43Z", "aliases": [ "CVE-2024-2108" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json b/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json index 714e58f473b..1d7c8baad50 100644 --- a/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json +++ b/advisories/unreviewed/2024/03/GHSA-j4hp-4mqq-mv7f/GHSA-j4hp-4mqq-mv7f.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mmm7-fjvq-6pqr/GHSA-mmm7-fjvq-6pqr.json b/advisories/unreviewed/2024/03/GHSA-mmm7-fjvq-6pqr/GHSA-mmm7-fjvq-6pqr.json index f5535f87cc9..37628447366 100644 --- a/advisories/unreviewed/2024/03/GHSA-mmm7-fjvq-6pqr/GHSA-mmm7-fjvq-6pqr.json +++ b/advisories/unreviewed/2024/03/GHSA-mmm7-fjvq-6pqr/GHSA-mmm7-fjvq-6pqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmm7-fjvq-6pqr", - "modified": "2024-03-15T09:30:37Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-15T09:30:37Z", "aliases": [ "CVE-2024-1795" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json b/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json index 8e561f3ef75..90626f6f468 100644 --- a/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json +++ b/advisories/unreviewed/2024/03/GHSA-rg8g-7365-wq9j/GHSA-rg8g-7365-wq9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rg8g-7365-wq9j", - "modified": "2024-03-29T06:30:30Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-29T06:30:30Z", "aliases": [ "CVE-2024-2841" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-v3wq-mp87-4m6r/GHSA-v3wq-mp87-4m6r.json b/advisories/unreviewed/2024/03/GHSA-v3wq-mp87-4m6r/GHSA-v3wq-mp87-4m6r.json index 7ee3333f7b6..f0fa8199f52 100644 --- a/advisories/unreviewed/2024/03/GHSA-v3wq-mp87-4m6r/GHSA-v3wq-mp87-4m6r.json +++ b/advisories/unreviewed/2024/03/GHSA-v3wq-mp87-4m6r/GHSA-v3wq-mp87-4m6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3wq-mp87-4m6r", - "modified": "2024-03-15T15:30:43Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-15T15:30:43Z", "aliases": [ "CVE-2023-50861" diff --git a/advisories/unreviewed/2024/03/GHSA-x4hm-m25h-2c6q/GHSA-x4hm-m25h-2c6q.json b/advisories/unreviewed/2024/03/GHSA-x4hm-m25h-2c6q/GHSA-x4hm-m25h-2c6q.json index 8c4abc3e588..9a1541388a9 100644 --- a/advisories/unreviewed/2024/03/GHSA-x4hm-m25h-2c6q/GHSA-x4hm-m25h-2c6q.json +++ b/advisories/unreviewed/2024/03/GHSA-x4hm-m25h-2c6q/GHSA-x4hm-m25h-2c6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x4hm-m25h-2c6q", - "modified": "2024-03-29T09:30:43Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-03-29T09:30:43Z", "aliases": [ "CVE-2024-2113" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xh6j-v8vp-q869/GHSA-xh6j-v8vp-q869.json b/advisories/unreviewed/2024/03/GHSA-xh6j-v8vp-q869/GHSA-xh6j-v8vp-q869.json index c05d83ef7d7..2866c1f626d 100644 --- a/advisories/unreviewed/2024/03/GHSA-xh6j-v8vp-q869/GHSA-xh6j-v8vp-q869.json +++ b/advisories/unreviewed/2024/03/GHSA-xh6j-v8vp-q869/GHSA-xh6j-v8vp-q869.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh6j-v8vp-q869", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-01-23T21:31:49Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-1691" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hxwm-2grv-7xcx/GHSA-hxwm-2grv-7xcx.json b/advisories/unreviewed/2024/05/GHSA-hxwm-2grv-7xcx/GHSA-hxwm-2grv-7xcx.json index e73899e01a5..a2afa58ff62 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxwm-2grv-7xcx/GHSA-hxwm-2grv-7xcx.json +++ b/advisories/unreviewed/2024/05/GHSA-hxwm-2grv-7xcx/GHSA-hxwm-2grv-7xcx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-wpvh-7c2r-23rh/GHSA-wpvh-7c2r-23rh.json b/advisories/unreviewed/2024/05/GHSA-wpvh-7c2r-23rh/GHSA-wpvh-7c2r-23rh.json index 8cf5dc47bb3..3c573bdb028 100644 --- a/advisories/unreviewed/2024/05/GHSA-wpvh-7c2r-23rh/GHSA-wpvh-7c2r-23rh.json +++ b/advisories/unreviewed/2024/05/GHSA-wpvh-7c2r-23rh/GHSA-wpvh-7c2r-23rh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wpvh-7c2r-23rh", - "modified": "2024-05-14T18:30:59Z", + "modified": "2025-01-23T21:31:50Z", "published": "2024-05-14T18:30:59Z", "aliases": [ "CVE-2024-28135" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json b/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json index 7733c55331c..eb286d8775e 100644 --- a/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json +++ b/advisories/unreviewed/2024/08/GHSA-xpwm-vrv5-5mgm/GHSA-xpwm-vrv5-5mgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xpwm-vrv5-5mgm", - "modified": "2024-08-13T15:31:36Z", + "modified": "2025-01-23T21:31:51Z", "published": "2024-08-13T15:31:36Z", "aliases": [ "CVE-2024-6788" diff --git a/advisories/unreviewed/2024/10/GHSA-rrr5-xgg4-xqq7/GHSA-rrr5-xgg4-xqq7.json b/advisories/unreviewed/2024/10/GHSA-rrr5-xgg4-xqq7/GHSA-rrr5-xgg4-xqq7.json index 5d00054504e..373b93cfb83 100644 --- a/advisories/unreviewed/2024/10/GHSA-rrr5-xgg4-xqq7/GHSA-rrr5-xgg4-xqq7.json +++ b/advisories/unreviewed/2024/10/GHSA-rrr5-xgg4-xqq7/GHSA-rrr5-xgg4-xqq7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rrr5-xgg4-xqq7", - "modified": "2024-10-25T15:31:30Z", + "modified": "2025-01-23T21:31:51Z", "published": "2024-10-25T09:32:01Z", "aliases": [ "CVE-2024-9628" diff --git a/advisories/unreviewed/2025/01/GHSA-36m4-mv4f-9c4q/GHSA-36m4-mv4f-9c4q.json b/advisories/unreviewed/2025/01/GHSA-36m4-mv4f-9c4q/GHSA-36m4-mv4f-9c4q.json index 5b50cdd4cc8..822b9e8f9f4 100644 --- a/advisories/unreviewed/2025/01/GHSA-36m4-mv4f-9c4q/GHSA-36m4-mv4f-9c4q.json +++ b/advisories/unreviewed/2025/01/GHSA-36m4-mv4f-9c4q/GHSA-36m4-mv4f-9c4q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36m4-mv4f-9c4q", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2023-37029" ], "details": "Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station or via an unauthenticated cellphone within range of a base station managed by the MME, causing a denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5jf6-rm4j-mpjr/GHSA-5jf6-rm4j-mpjr.json b/advisories/unreviewed/2025/01/GHSA-5jf6-rm4j-mpjr/GHSA-5jf6-rm4j-mpjr.json index b20c1e0ab02..c13e741e31b 100644 --- a/advisories/unreviewed/2025/01/GHSA-5jf6-rm4j-mpjr/GHSA-5jf6-rm4j-mpjr.json +++ b/advisories/unreviewed/2025/01/GHSA-5jf6-rm4j-mpjr/GHSA-5jf6-rm4j-mpjr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5jf6-rm4j-mpjr", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-24428" ], "details": "A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json b/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json index 4e8784028d8..9f16ecaae25 100644 --- a/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json +++ b/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-625q-8mvq-3q7x/GHSA-625q-8mvq-3q7x.json b/advisories/unreviewed/2025/01/GHSA-625q-8mvq-3q7x/GHSA-625q-8mvq-3q7x.json index 2f7b62a9f94..94066765091 100644 --- a/advisories/unreviewed/2025/01/GHSA-625q-8mvq-3q7x/GHSA-625q-8mvq-3q7x.json +++ b/advisories/unreviewed/2025/01/GHSA-625q-8mvq-3q7x/GHSA-625q-8mvq-3q7x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-733h-c5c6-mqj2/GHSA-733h-c5c6-mqj2.json b/advisories/unreviewed/2025/01/GHSA-733h-c5c6-mqj2/GHSA-733h-c5c6-mqj2.json index de8c78a5dc3..9b623943150 100644 --- a/advisories/unreviewed/2025/01/GHSA-733h-c5c6-mqj2/GHSA-733h-c5c6-mqj2.json +++ b/advisories/unreviewed/2025/01/GHSA-733h-c5c6-mqj2/GHSA-733h-c5c6-mqj2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-983q-mwq9-x6m2/GHSA-983q-mwq9-x6m2.json b/advisories/unreviewed/2025/01/GHSA-983q-mwq9-x6m2/GHSA-983q-mwq9-x6m2.json index 6037a488ef2..f8dc2a6ebd0 100644 --- a/advisories/unreviewed/2025/01/GHSA-983q-mwq9-x6m2/GHSA-983q-mwq9-x6m2.json +++ b/advisories/unreviewed/2025/01/GHSA-983q-mwq9-x6m2/GHSA-983q-mwq9-x6m2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-983q-mwq9-x6m2", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9389" ], "details": "In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9rmr-pw3x-x887/GHSA-9rmr-pw3x-x887.json b/advisories/unreviewed/2025/01/GHSA-9rmr-pw3x-x887/GHSA-9rmr-pw3x-x887.json index 01c5cf8fb8c..2dc8d15aab9 100644 --- a/advisories/unreviewed/2025/01/GHSA-9rmr-pw3x-x887/GHSA-9rmr-pw3x-x887.json +++ b/advisories/unreviewed/2025/01/GHSA-9rmr-pw3x-x887/GHSA-9rmr-pw3x-x887.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9rmr-pw3x-x887", - "modified": "2025-01-22T00:33:36Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-22T00:33:36Z", "aliases": [ "CVE-2023-37024" ], "details": "A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency Number List` Information Element.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cr8g-q77h-p4gp/GHSA-cr8g-q77h-p4gp.json b/advisories/unreviewed/2025/01/GHSA-cr8g-q77h-p4gp/GHSA-cr8g-q77h-p4gp.json index c023f41426b..9df5e25c9aa 100644 --- a/advisories/unreviewed/2025/01/GHSA-cr8g-q77h-p4gp/GHSA-cr8g-q77h-p4gp.json +++ b/advisories/unreviewed/2025/01/GHSA-cr8g-q77h-p4gp/GHSA-cr8g-q77h-p4gp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cr8g-q77h-p4gp", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-24427" ], "details": "A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fr48-xrq7-qc9m/GHSA-fr48-xrq7-qc9m.json b/advisories/unreviewed/2025/01/GHSA-fr48-xrq7-qc9m/GHSA-fr48-xrq7-qc9m.json index 7ca687e22e0..9a5a202da5d 100644 --- a/advisories/unreviewed/2025/01/GHSA-fr48-xrq7-qc9m/GHSA-fr48-xrq7-qc9m.json +++ b/advisories/unreviewed/2025/01/GHSA-fr48-xrq7-qc9m/GHSA-fr48-xrq7-qc9m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-gp34-pj6p-5cxx/GHSA-gp34-pj6p-5cxx.json b/advisories/unreviewed/2025/01/GHSA-gp34-pj6p-5cxx/GHSA-gp34-pj6p-5cxx.json index f1104f11a5e..a5604c1c377 100644 --- a/advisories/unreviewed/2025/01/GHSA-gp34-pj6p-5cxx/GHSA-gp34-pj6p-5cxx.json +++ b/advisories/unreviewed/2025/01/GHSA-gp34-pj6p-5cxx/GHSA-gp34-pj6p-5cxx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gp34-pj6p-5cxx", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9406" ], "details": "In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jq8v-x7gq-gghc/GHSA-jq8v-x7gq-gghc.json b/advisories/unreviewed/2025/01/GHSA-jq8v-x7gq-gghc/GHSA-jq8v-x7gq-gghc.json index c24e742cb51..827b1d088a4 100644 --- a/advisories/unreviewed/2025/01/GHSA-jq8v-x7gq-gghc/GHSA-jq8v-x7gq-gghc.json +++ b/advisories/unreviewed/2025/01/GHSA-jq8v-x7gq-gghc/GHSA-jq8v-x7gq-gghc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jq8v-x7gq-gghc", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2017-13322" ], "details": "In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-p2j4-x5h5-fmjm/GHSA-p2j4-x5h5-fmjm.json b/advisories/unreviewed/2025/01/GHSA-p2j4-x5h5-fmjm/GHSA-p2j4-x5h5-fmjm.json new file mode 100644 index 00000000000..78ac8b84e43 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p2j4-x5h5-fmjm/GHSA-p2j4-x5h5-fmjm.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2j4-x5h5-fmjm", + "modified": "2025-01-23T21:31:52Z", + "published": "2025-01-23T21:31:52Z", + "aliases": [ + "CVE-2025-23011" + ], + "details": "Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives (\"Zip Slip\"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23011" + }, + { + "type": "WEB", + "url": "https://github.com/fcrepo-exts/migration-utils" + }, + { + "type": "WEB", + "url": "https://github.com/fcrepo/fcrepo/releases" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-021-01.json" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-23T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json b/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json index 184755b99be..45ea61a6f00 100644 --- a/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json +++ b/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6qw-j3rw-2577", - "modified": "2025-01-23T18:31:17Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2024-57370" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/sunnygkp10/Online-Exam-System" }, + { + "type": "WEB", + "url": "https://github.com/sunnygkp10/Online-Exam-System-" + }, { "type": "WEB", "url": "https://royblume.github.io/CVE-2024-57370" diff --git a/advisories/unreviewed/2025/01/GHSA-pcf2-f983-h6w2/GHSA-pcf2-f983-h6w2.json b/advisories/unreviewed/2025/01/GHSA-pcf2-f983-h6w2/GHSA-pcf2-f983-h6w2.json index 0f2fb56830b..9ea58bf11e2 100644 --- a/advisories/unreviewed/2025/01/GHSA-pcf2-f983-h6w2/GHSA-pcf2-f983-h6w2.json +++ b/advisories/unreviewed/2025/01/GHSA-pcf2-f983-h6w2/GHSA-pcf2-f983-h6w2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pcf2-f983-h6w2", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-23T21:31:51Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-24443" ], "details": "An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDU Session Resource Setup Response.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rh26-2566-h5m7/GHSA-rh26-2566-h5m7.json b/advisories/unreviewed/2025/01/GHSA-rh26-2566-h5m7/GHSA-rh26-2566-h5m7.json index 2f219cf70e9..0f5fde3b813 100644 --- a/advisories/unreviewed/2025/01/GHSA-rh26-2566-h5m7/GHSA-rh26-2566-h5m7.json +++ b/advisories/unreviewed/2025/01/GHSA-rh26-2566-h5m7/GHSA-rh26-2566-h5m7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-rrq3-36q9-c259/GHSA-rrq3-36q9-c259.json b/advisories/unreviewed/2025/01/GHSA-rrq3-36q9-c259/GHSA-rrq3-36q9-c259.json new file mode 100644 index 00000000000..42e9cae395a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rrq3-36q9-c259/GHSA-rrq3-36q9-c259.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrq3-36q9-c259", + "modified": "2025-01-23T21:31:52Z", + "published": "2025-01-23T21:31:52Z", + "aliases": [ + "CVE-2025-23012" + ], + "details": "Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23012" + }, + { + "type": "WEB", + "url": "https://github.com/fcrepo-exts/migration-utils" + }, + { + "type": "WEB", + "url": "https://github.com/fcrepo/fcrepo/releases" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-021-01.json" + }, + { + "type": "WEB", + "url": "https://wiki.lyrasis.org/display/FEDORA38/XACML+Policy+Enforcement#XACMLPolicyEnforcement-4.1fedora-usersattributes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-23T21:15:15Z" + } +} \ No newline at end of file