From 37f1959a46b8bc843237964deae30944b662b893 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Mar 2025 15:32:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-7hpv-rcx2-vjx9.json | 9 ++++- .../GHSA-wj8f-vwpr-gq38.json | 13 ++++-- .../GHSA-2chf-w4v5-vmmg.json | 2 +- .../GHSA-2r47-fxrj-f7vv.json | 2 +- .../GHSA-39m8-rph8-x6gj.json | 5 ++- .../GHSA-3r45-9m8q-2cch.json | 3 +- .../GHSA-4j3q-rqjq-x3f3.json | 10 ++++- .../GHSA-4qcf-7phg-fpvq.json | 4 +- .../GHSA-5cxj-h7vw-5448.json | 2 +- .../GHSA-5f27-4gv5-7jhc.json | 2 +- .../GHSA-5xw7-xf7p-gm82.json | 6 ++- .../GHSA-6x74-cjf9-r2hc.json | 3 +- .../GHSA-7qcw-gg9p-56xr.json | 2 +- .../GHSA-c9q4-2w45-hjcr.json | 3 +- .../GHSA-h98q-9vm9-92vw.json | 2 +- .../GHSA-mw5v-q85w-g5pq.json | 2 +- .../GHSA-pmjf-pf92-c43q.json | 2 +- .../GHSA-rr3r-2gr7-hh53.json | 2 +- .../GHSA-w58h-9w4c-p7rf.json | 2 +- .../GHSA-xgrf-rhvw-h8mr.json | 3 +- .../GHSA-jv75-4p2q-rw9j.json | 4 +- .../GHSA-r382-73hv-r5j2.json | 3 +- .../GHSA-r8g7-9pvc-p6p6.json | 4 +- .../GHSA-rvvf-rc7q-23qm.json | 1 + .../GHSA-q677-7pjp-5hq5.json | 3 +- .../GHSA-r5fv-vx8p-jvrq.json | 1 + .../GHSA-72c9-vcqr-cxj8.json | 4 +- .../GHSA-6pxp-6h5g-5389.json | 3 +- .../GHSA-8hpx-q4cx-gfxw.json | 1 + .../GHSA-96qq-4jq4-p5hw.json | 1 + .../GHSA-wq97-58c8-w5g5.json | 1 + .../GHSA-48g3-w2gf-xjrv.json | 6 ++- .../GHSA-28qf-h8m9-4x6x.json | 36 +++++++++++++++++ .../GHSA-29mf-g5hc-vfvc.json | 4 +- .../GHSA-2jgf-qh2v-pfqg.json | 36 +++++++++++++++++ .../GHSA-3fpr-88w3-v99m.json | 15 +++++-- .../GHSA-3pjj-2f8w-vhh5.json | 11 +++-- .../GHSA-44x6-67xw-4m95.json | 15 +++++-- .../GHSA-46f9-rmg7-hh9m.json | 15 +++++-- .../GHSA-4878-3496-cr5j.json | 11 +++-- .../GHSA-53v3-522x-7x4p.json | 36 +++++++++++++++++ .../GHSA-5pg4-gp5m-jv5v.json | 36 +++++++++++++++++ .../GHSA-5pwg-63cp-76fj.json | 11 +++-- .../GHSA-5rcp-4jvr-rpqr.json | 36 +++++++++++++++++ .../GHSA-5wqh-pcq3-r3px.json | 11 +++-- .../GHSA-665f-p6v8-5227.json | 40 +++++++++++++++++++ .../GHSA-673g-crrq-7x55.json | 11 +++-- .../GHSA-6pf8-q335-vxv9.json | 38 ++++++++++++++++++ .../GHSA-6qrv-h235-q5x7.json | 11 +++-- .../GHSA-6vr9-h9pm-5frx.json | 11 +++-- .../GHSA-7635-mr68-26j6.json | 11 +++-- .../GHSA-76c9-635j-h2r5.json | 11 +++-- .../GHSA-7g63-967x-cfvv.json | 3 +- .../GHSA-8jxr-w3j2-x85w.json | 11 +++-- .../GHSA-8wwq-574q-q2j9.json | 4 +- .../GHSA-9f58-q6j7-m5vv.json | 15 +++++-- .../GHSA-9xhf-3wg6-87r4.json | 4 +- .../GHSA-c22c-4xww-2fqr.json | 3 +- .../GHSA-c8w4-q7v8-687p.json | 15 +++++-- .../GHSA-c993-hrcm-4cp8.json | 11 +++-- .../GHSA-ch85-v3jm-42jh.json | 4 +- .../GHSA-cvr2-vqw8-v6q9.json | 15 +++++-- .../GHSA-cw73-w3vc-7g28.json | 11 +++-- .../GHSA-f32g-h75h-7vgp.json | 11 +++-- .../GHSA-f33w-26qx-6hvm.json | 15 +++++-- .../GHSA-ffm9-v534-h8c2.json | 11 +++-- .../GHSA-fg5v-3r25-5f95.json | 11 +++-- .../GHSA-fp8m-c995-8jh3.json | 40 +++++++++++++++++++ .../GHSA-fvgf-g9j6-cf8m.json | 15 +++++-- .../GHSA-g4w6-jw6r-6882.json | 15 +++++-- .../GHSA-gqcv-v7gm-vw94.json | 11 +++-- .../GHSA-gqmm-fccw-xjf3.json | 15 +++++-- .../GHSA-gv64-36xp-c47j.json | 36 +++++++++++++++++ .../GHSA-h2gq-85xh-8c3c.json | 11 +++-- .../GHSA-h5xv-5cpx-pf45.json | 36 +++++++++++++++++ .../GHSA-h77r-2p45-qp9h.json | 40 +++++++++++++++++++ .../GHSA-hcgq-vpp8-j6q4.json | 40 +++++++++++++++++++ .../GHSA-hrqh-mj8r-gjgp.json | 4 +- .../GHSA-j2pq-j692-qx87.json | 15 +++++-- .../GHSA-jhf6-432q-gp6x.json | 36 +++++++++++++++++ .../GHSA-jv5x-w5jr-8gvf.json | 11 +++-- .../GHSA-m9wc-3h85-pp63.json | 36 +++++++++++++++++ .../GHSA-mh6c-cj4f-f948.json | 15 +++++-- .../GHSA-p7j9-4392-6r7p.json | 15 +++++-- .../GHSA-pgm2-324j-f3jh.json | 36 +++++++++++++++++ .../GHSA-q27q-f4wr-gh4j.json | 11 +++-- .../GHSA-q4g4-gmvw-9fqc.json | 15 +++++-- .../GHSA-qgmq-76m4-c2jv.json | 15 +++++-- .../GHSA-qgrj-c4rv-c2r5.json | 11 +++-- .../GHSA-qq4f-w524-x6mg.json | 11 +++-- .../GHSA-qqq7-68c5-p37w.json | 11 +++-- .../GHSA-r7x2-wq2h-f7x7.json | 15 +++++-- .../GHSA-rgxv-4464-wf8w.json | 11 +++-- .../GHSA-v797-6jmw-529f.json | 36 +++++++++++++++++ .../GHSA-v7v5-m765-h4w4.json | 40 +++++++++++++++++++ .../GHSA-vp5v-47wj-p5r2.json | 15 +++++-- .../GHSA-vrf6-366f-p2hr.json | 15 +++++-- .../GHSA-w3jj-5rxp-759m.json | 15 +++++-- .../GHSA-w523-c69w-6x53.json | 11 +++-- .../GHSA-wwgv-3xwq-6qmc.json | 11 +++-- .../GHSA-wxgw-xr8v-5p75.json | 15 +++++-- .../GHSA-xp75-w7vq-5x6j.json | 15 +++++-- .../GHSA-xq2v-cc3g-cmw3.json | 6 ++- 103 files changed, 1168 insertions(+), 199 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-28qf-h8m9-4x6x/GHSA-28qf-h8m9-4x6x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2jgf-qh2v-pfqg/GHSA-2jgf-qh2v-pfqg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-53v3-522x-7x4p/GHSA-53v3-522x-7x4p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5pg4-gp5m-jv5v/GHSA-5pg4-gp5m-jv5v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5rcp-4jvr-rpqr/GHSA-5rcp-4jvr-rpqr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-665f-p6v8-5227/GHSA-665f-p6v8-5227.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6pf8-q335-vxv9/GHSA-6pf8-q335-vxv9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fp8m-c995-8jh3/GHSA-fp8m-c995-8jh3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gv64-36xp-c47j/GHSA-gv64-36xp-c47j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5xv-5cpx-pf45/GHSA-h5xv-5cpx-pf45.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h77r-2p45-qp9h/GHSA-h77r-2p45-qp9h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hcgq-vpp8-j6q4/GHSA-hcgq-vpp8-j6q4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jhf6-432q-gp6x/GHSA-jhf6-432q-gp6x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m9wc-3h85-pp63/GHSA-m9wc-3h85-pp63.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pgm2-324j-f3jh/GHSA-pgm2-324j-f3jh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v797-6jmw-529f/GHSA-v797-6jmw-529f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v7v5-m765-h4w4/GHSA-v7v5-m765-h4w4.json diff --git a/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json b/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json index 01bc802c5f1..950225cfe70 100644 --- a/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json +++ b/advisories/unreviewed/2022/05/GHSA-7hpv-rcx2-vjx9/GHSA-7hpv-rcx2-vjx9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7hpv-rcx2-vjx9", - "modified": "2022-05-24T17:23:48Z", + "modified": "2025-03-25T15:31:09Z", "published": "2022-05-24T17:23:48Z", "aliases": [ "CVE-2020-4316" ], "details": "IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177354.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-wj8f-vwpr-gq38/GHSA-wj8f-vwpr-gq38.json b/advisories/unreviewed/2022/05/GHSA-wj8f-vwpr-gq38/GHSA-wj8f-vwpr-gq38.json index 841ab66e81d..3c33abd2fe5 100644 --- a/advisories/unreviewed/2022/05/GHSA-wj8f-vwpr-gq38/GHSA-wj8f-vwpr-gq38.json +++ b/advisories/unreviewed/2022/05/GHSA-wj8f-vwpr-gq38/GHSA-wj8f-vwpr-gq38.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wj8f-vwpr-gq38", - "modified": "2022-05-24T17:08:45Z", + "modified": "2025-03-25T15:31:09Z", "published": "2022-05-24T17:08:45Z", "aliases": [ "CVE-2019-4431" ], "details": "IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162888.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-2chf-w4v5-vmmg/GHSA-2chf-w4v5-vmmg.json b/advisories/unreviewed/2023/02/GHSA-2chf-w4v5-vmmg/GHSA-2chf-w4v5-vmmg.json index d789149ad7d..cead737f84c 100644 --- a/advisories/unreviewed/2023/02/GHSA-2chf-w4v5-vmmg/GHSA-2chf-w4v5-vmmg.json +++ b/advisories/unreviewed/2023/02/GHSA-2chf-w4v5-vmmg/GHSA-2chf-w4v5-vmmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2chf-w4v5-vmmg", - "modified": "2023-02-15T18:30:19Z", + "modified": "2025-03-25T15:31:09Z", "published": "2023-02-07T21:30:23Z", "aliases": [ "CVE-2022-47412" diff --git a/advisories/unreviewed/2023/02/GHSA-2r47-fxrj-f7vv/GHSA-2r47-fxrj-f7vv.json b/advisories/unreviewed/2023/02/GHSA-2r47-fxrj-f7vv/GHSA-2r47-fxrj-f7vv.json index a154c8ccfba..53691c46a20 100644 --- a/advisories/unreviewed/2023/02/GHSA-2r47-fxrj-f7vv/GHSA-2r47-fxrj-f7vv.json +++ b/advisories/unreviewed/2023/02/GHSA-2r47-fxrj-f7vv/GHSA-2r47-fxrj-f7vv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2r47-fxrj-f7vv", - "modified": "2023-02-17T15:30:25Z", + "modified": "2025-03-25T15:31:13Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48295" diff --git a/advisories/unreviewed/2023/02/GHSA-39m8-rph8-x6gj/GHSA-39m8-rph8-x6gj.json b/advisories/unreviewed/2023/02/GHSA-39m8-rph8-x6gj/GHSA-39m8-rph8-x6gj.json index 0f2854c6787..ff8b2db66ce 100644 --- a/advisories/unreviewed/2023/02/GHSA-39m8-rph8-x6gj/GHSA-39m8-rph8-x6gj.json +++ b/advisories/unreviewed/2023/02/GHSA-39m8-rph8-x6gj/GHSA-39m8-rph8-x6gj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-39m8-rph8-x6gj", - "modified": "2023-02-16T15:30:30Z", + "modified": "2025-03-25T15:31:10Z", "published": "2023-02-07T21:30:22Z", "aliases": [ "CVE-2022-45768" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json b/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json index 4202e99c254..f07da94e207 100644 --- a/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json +++ b/advisories/unreviewed/2023/02/GHSA-3r45-9m8q-2cch/GHSA-3r45-9m8q-2cch.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-4j3q-rqjq-x3f3/GHSA-4j3q-rqjq-x3f3.json b/advisories/unreviewed/2023/02/GHSA-4j3q-rqjq-x3f3/GHSA-4j3q-rqjq-x3f3.json index d4dca14e2df..259b991e086 100644 --- a/advisories/unreviewed/2023/02/GHSA-4j3q-rqjq-x3f3/GHSA-4j3q-rqjq-x3f3.json +++ b/advisories/unreviewed/2023/02/GHSA-4j3q-rqjq-x3f3/GHSA-4j3q-rqjq-x3f3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4j3q-rqjq-x3f3", - "modified": "2023-02-17T00:30:28Z", + "modified": "2025-03-25T15:31:11Z", "published": "2023-02-08T21:30:20Z", "aliases": [ "CVE-2023-0751" @@ -22,10 +22,16 @@ { "type": "WEB", "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-23:01.geli.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230316-0004" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json b/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json index 53a5def73a4..3c769fbe13b 100644 --- a/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json +++ b/advisories/unreviewed/2023/02/GHSA-4qcf-7phg-fpvq/GHSA-4qcf-7phg-fpvq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-5cxj-h7vw-5448/GHSA-5cxj-h7vw-5448.json b/advisories/unreviewed/2023/02/GHSA-5cxj-h7vw-5448/GHSA-5cxj-h7vw-5448.json index 46f4b98c5a6..ee77f976aba 100644 --- a/advisories/unreviewed/2023/02/GHSA-5cxj-h7vw-5448/GHSA-5cxj-h7vw-5448.json +++ b/advisories/unreviewed/2023/02/GHSA-5cxj-h7vw-5448/GHSA-5cxj-h7vw-5448.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5cxj-h7vw-5448", - "modified": "2023-02-16T18:30:28Z", + "modified": "2025-03-25T15:31:10Z", "published": "2023-02-08T00:30:34Z", "aliases": [ "CVE-2022-47415" diff --git a/advisories/unreviewed/2023/02/GHSA-5f27-4gv5-7jhc/GHSA-5f27-4gv5-7jhc.json b/advisories/unreviewed/2023/02/GHSA-5f27-4gv5-7jhc/GHSA-5f27-4gv5-7jhc.json index ef0fa3aeb25..2ead595a6f9 100644 --- a/advisories/unreviewed/2023/02/GHSA-5f27-4gv5-7jhc/GHSA-5f27-4gv5-7jhc.json +++ b/advisories/unreviewed/2023/02/GHSA-5f27-4gv5-7jhc/GHSA-5f27-4gv5-7jhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5f27-4gv5-7jhc", - "modified": "2023-02-17T15:30:26Z", + "modified": "2025-03-25T15:31:13Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48296" diff --git a/advisories/unreviewed/2023/02/GHSA-5xw7-xf7p-gm82/GHSA-5xw7-xf7p-gm82.json b/advisories/unreviewed/2023/02/GHSA-5xw7-xf7p-gm82/GHSA-5xw7-xf7p-gm82.json index 70d9b0660d1..e6e9f5f4536 100644 --- a/advisories/unreviewed/2023/02/GHSA-5xw7-xf7p-gm82/GHSA-5xw7-xf7p-gm82.json +++ b/advisories/unreviewed/2023/02/GHSA-5xw7-xf7p-gm82/GHSA-5xw7-xf7p-gm82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xw7-xf7p-gm82", - "modified": "2023-02-16T15:30:29Z", + "modified": "2025-03-25T15:31:10Z", "published": "2023-02-07T21:30:22Z", "aliases": [ "CVE-2022-46663" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/gwsw/less/commit/a78e1351113cef564d790a730d657a321624d79c" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LR7AUWB34JD4PCW3HHASBEDGGHFWPAQP" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LR7AUWB34JD4PCW3HHASBEDGGHFWPAQP" diff --git a/advisories/unreviewed/2023/02/GHSA-6x74-cjf9-r2hc/GHSA-6x74-cjf9-r2hc.json b/advisories/unreviewed/2023/02/GHSA-6x74-cjf9-r2hc/GHSA-6x74-cjf9-r2hc.json index f3fcb890180..9ceb15c89d7 100644 --- a/advisories/unreviewed/2023/02/GHSA-6x74-cjf9-r2hc/GHSA-6x74-cjf9-r2hc.json +++ b/advisories/unreviewed/2023/02/GHSA-6x74-cjf9-r2hc/GHSA-6x74-cjf9-r2hc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6x74-cjf9-r2hc", - "modified": "2023-02-16T21:30:27Z", + "modified": "2025-03-25T15:31:13Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48297" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-7qcw-gg9p-56xr/GHSA-7qcw-gg9p-56xr.json b/advisories/unreviewed/2023/02/GHSA-7qcw-gg9p-56xr/GHSA-7qcw-gg9p-56xr.json index 4efaf10ca01..2605eebfd48 100644 --- a/advisories/unreviewed/2023/02/GHSA-7qcw-gg9p-56xr/GHSA-7qcw-gg9p-56xr.json +++ b/advisories/unreviewed/2023/02/GHSA-7qcw-gg9p-56xr/GHSA-7qcw-gg9p-56xr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qcw-gg9p-56xr", - "modified": "2023-02-15T21:30:31Z", + "modified": "2025-03-25T15:31:10Z", "published": "2023-02-08T00:30:35Z", "aliases": [ "CVE-2022-47413" diff --git a/advisories/unreviewed/2023/02/GHSA-c9q4-2w45-hjcr/GHSA-c9q4-2w45-hjcr.json b/advisories/unreviewed/2023/02/GHSA-c9q4-2w45-hjcr/GHSA-c9q4-2w45-hjcr.json index 7f1a55ab9c0..927323e3083 100644 --- a/advisories/unreviewed/2023/02/GHSA-c9q4-2w45-hjcr/GHSA-c9q4-2w45-hjcr.json +++ b/advisories/unreviewed/2023/02/GHSA-c9q4-2w45-hjcr/GHSA-c9q4-2w45-hjcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9q4-2w45-hjcr", - "modified": "2023-02-16T21:30:27Z", + "modified": "2025-03-25T15:31:13Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48298" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-h98q-9vm9-92vw/GHSA-h98q-9vm9-92vw.json b/advisories/unreviewed/2023/02/GHSA-h98q-9vm9-92vw/GHSA-h98q-9vm9-92vw.json index e9e0c6d0134..1c16b7af49a 100644 --- a/advisories/unreviewed/2023/02/GHSA-h98q-9vm9-92vw/GHSA-h98q-9vm9-92vw.json +++ b/advisories/unreviewed/2023/02/GHSA-h98q-9vm9-92vw/GHSA-h98q-9vm9-92vw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h98q-9vm9-92vw", - "modified": "2023-02-16T18:30:27Z", + "modified": "2025-03-25T15:31:10Z", "published": "2023-02-08T00:30:34Z", "aliases": [ "CVE-2022-47416" diff --git a/advisories/unreviewed/2023/02/GHSA-mw5v-q85w-g5pq/GHSA-mw5v-q85w-g5pq.json b/advisories/unreviewed/2023/02/GHSA-mw5v-q85w-g5pq/GHSA-mw5v-q85w-g5pq.json index 2ad324f0e29..ffbc58d8573 100644 --- a/advisories/unreviewed/2023/02/GHSA-mw5v-q85w-g5pq/GHSA-mw5v-q85w-g5pq.json +++ b/advisories/unreviewed/2023/02/GHSA-mw5v-q85w-g5pq/GHSA-mw5v-q85w-g5pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw5v-q85w-g5pq", - "modified": "2023-02-16T18:30:27Z", + "modified": "2025-03-25T15:31:11Z", "published": "2023-02-08T00:30:34Z", "aliases": [ "CVE-2022-47417" diff --git a/advisories/unreviewed/2023/02/GHSA-pmjf-pf92-c43q/GHSA-pmjf-pf92-c43q.json b/advisories/unreviewed/2023/02/GHSA-pmjf-pf92-c43q/GHSA-pmjf-pf92-c43q.json index 7c58395b21b..05793307f77 100644 --- a/advisories/unreviewed/2023/02/GHSA-pmjf-pf92-c43q/GHSA-pmjf-pf92-c43q.json +++ b/advisories/unreviewed/2023/02/GHSA-pmjf-pf92-c43q/GHSA-pmjf-pf92-c43q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmjf-pf92-c43q", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-25T15:31:13Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48299" diff --git a/advisories/unreviewed/2023/02/GHSA-rr3r-2gr7-hh53/GHSA-rr3r-2gr7-hh53.json b/advisories/unreviewed/2023/02/GHSA-rr3r-2gr7-hh53/GHSA-rr3r-2gr7-hh53.json index eecab771955..6b81430ed3b 100644 --- a/advisories/unreviewed/2023/02/GHSA-rr3r-2gr7-hh53/GHSA-rr3r-2gr7-hh53.json +++ b/advisories/unreviewed/2023/02/GHSA-rr3r-2gr7-hh53/GHSA-rr3r-2gr7-hh53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rr3r-2gr7-hh53", - "modified": "2023-02-15T21:30:31Z", + "modified": "2025-03-25T15:31:10Z", "published": "2023-02-08T00:30:35Z", "aliases": [ "CVE-2022-47414" diff --git a/advisories/unreviewed/2023/02/GHSA-w58h-9w4c-p7rf/GHSA-w58h-9w4c-p7rf.json b/advisories/unreviewed/2023/02/GHSA-w58h-9w4c-p7rf/GHSA-w58h-9w4c-p7rf.json index ee3acf7ddf8..a759c778e4f 100644 --- a/advisories/unreviewed/2023/02/GHSA-w58h-9w4c-p7rf/GHSA-w58h-9w4c-p7rf.json +++ b/advisories/unreviewed/2023/02/GHSA-w58h-9w4c-p7rf/GHSA-w58h-9w4c-p7rf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w58h-9w4c-p7rf", - "modified": "2023-02-16T18:30:27Z", + "modified": "2025-03-25T15:31:11Z", "published": "2023-02-08T00:30:34Z", "aliases": [ "CVE-2022-47418" diff --git a/advisories/unreviewed/2023/02/GHSA-xgrf-rhvw-h8mr/GHSA-xgrf-rhvw-h8mr.json b/advisories/unreviewed/2023/02/GHSA-xgrf-rhvw-h8mr/GHSA-xgrf-rhvw-h8mr.json index c06f2d91fdb..4d8cc2c849f 100644 --- a/advisories/unreviewed/2023/02/GHSA-xgrf-rhvw-h8mr/GHSA-xgrf-rhvw-h8mr.json +++ b/advisories/unreviewed/2023/02/GHSA-xgrf-rhvw-h8mr/GHSA-xgrf-rhvw-h8mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xgrf-rhvw-h8mr", - "modified": "2023-02-16T15:30:29Z", + "modified": "2025-03-25T15:31:12Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48286" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-jv75-4p2q-rw9j/GHSA-jv75-4p2q-rw9j.json b/advisories/unreviewed/2024/04/GHSA-jv75-4p2q-rw9j/GHSA-jv75-4p2q-rw9j.json index 2adb7d4d829..420fb7886d8 100644 --- a/advisories/unreviewed/2024/04/GHSA-jv75-4p2q-rw9j/GHSA-jv75-4p2q-rw9j.json +++ b/advisories/unreviewed/2024/04/GHSA-jv75-4p2q-rw9j/GHSA-jv75-4p2q-rw9j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json b/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json index d78a3c863f7..341b0a0115f 100644 --- a/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json +++ b/advisories/unreviewed/2024/04/GHSA-r382-73hv-r5j2/GHSA-r382-73hv-r5j2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-347" + "CWE-347", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json index a8db1829fd8..0037ccfb30f 100644 --- a/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json +++ b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rvvf-rc7q-23qm/GHSA-rvvf-rc7q-23qm.json b/advisories/unreviewed/2024/07/GHSA-rvvf-rc7q-23qm/GHSA-rvvf-rc7q-23qm.json index 0571fe48bae..b57b074cd37 100644 --- a/advisories/unreviewed/2024/07/GHSA-rvvf-rc7q-23qm/GHSA-rvvf-rc7q-23qm.json +++ b/advisories/unreviewed/2024/07/GHSA-rvvf-rc7q-23qm/GHSA-rvvf-rc7q-23qm.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json b/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json index 3c23a66b777..0ad33d8a802 100644 --- a/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json +++ b/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-349" + "CWE-349", + "CWE-444" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r5fv-vx8p-jvrq/GHSA-r5fv-vx8p-jvrq.json b/advisories/unreviewed/2024/09/GHSA-r5fv-vx8p-jvrq/GHSA-r5fv-vx8p-jvrq.json index 9518926007f..fde6c041d73 100644 --- a/advisories/unreviewed/2024/09/GHSA-r5fv-vx8p-jvrq/GHSA-r5fv-vx8p-jvrq.json +++ b/advisories/unreviewed/2024/09/GHSA-r5fv-vx8p-jvrq/GHSA-r5fv-vx8p-jvrq.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-114", "CWE-427" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json b/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json index 53b0d8594c6..db5a70d1066 100644 --- a/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json +++ b/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-6pxp-6h5g-5389/GHSA-6pxp-6h5g-5389.json b/advisories/unreviewed/2025/01/GHSA-6pxp-6h5g-5389/GHSA-6pxp-6h5g-5389.json index 7a9ea26cbc2..e89e91c1493 100644 --- a/advisories/unreviewed/2025/01/GHSA-6pxp-6h5g-5389/GHSA-6pxp-6h5g-5389.json +++ b/advisories/unreviewed/2025/01/GHSA-6pxp-6h5g-5389/GHSA-6pxp-6h5g-5389.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-277" + "CWE-277", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json b/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json index b7ccdc063cd..1da2d3fd6d5 100644 --- a/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json +++ b/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-617", "CWE-770" ], diff --git a/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json b/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json index 272dee85a75..aad159a8fc9 100644 --- a/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json +++ b/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-203" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-wq97-58c8-w5g5/GHSA-wq97-58c8-w5g5.json b/advisories/unreviewed/2025/01/GHSA-wq97-58c8-w5g5/GHSA-wq97-58c8-w5g5.json index eecfa025403..8db7219c2ac 100644 --- a/advisories/unreviewed/2025/01/GHSA-wq97-58c8-w5g5/GHSA-wq97-58c8-w5g5.json +++ b/advisories/unreviewed/2025/01/GHSA-wq97-58c8-w5g5/GHSA-wq97-58c8-w5g5.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-798" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-48g3-w2gf-xjrv/GHSA-48g3-w2gf-xjrv.json b/advisories/unreviewed/2025/02/GHSA-48g3-w2gf-xjrv/GHSA-48g3-w2gf-xjrv.json index 92fc41497e5..f20751accd0 100644 --- a/advisories/unreviewed/2025/02/GHSA-48g3-w2gf-xjrv/GHSA-48g3-w2gf-xjrv.json +++ b/advisories/unreviewed/2025/02/GHSA-48g3-w2gf-xjrv/GHSA-48g3-w2gf-xjrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48g3-w2gf-xjrv", - "modified": "2025-03-13T15:32:46Z", + "modified": "2025-03-25T15:31:17Z", "published": "2025-02-22T12:30:29Z", "aliases": [ "CVE-2025-21704" @@ -45,6 +45,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/f64079bef6a8a7823358c3f352ea29a617844636" + }, + { + "type": "WEB", + "url": "https://project-zero.issues.chromium.org/issues/395107243" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-28qf-h8m9-4x6x/GHSA-28qf-h8m9-4x6x.json b/advisories/unreviewed/2025/03/GHSA-28qf-h8m9-4x6x/GHSA-28qf-h8m9-4x6x.json new file mode 100644 index 00000000000..28fc0732997 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-28qf-h8m9-4x6x/GHSA-28qf-h8m9-4x6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28qf-h8m9-4x6x", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-2532" + ], + "details": "Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of usdc files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23709.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2532" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json b/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json index 0c7ae2d94ad..32b1b10e5a1 100644 --- a/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json +++ b/advisories/unreviewed/2025/03/GHSA-29mf-g5hc-vfvc/GHSA-29mf-g5hc-vfvc.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-2jgf-qh2v-pfqg/GHSA-2jgf-qh2v-pfqg.json b/advisories/unreviewed/2025/03/GHSA-2jgf-qh2v-pfqg/GHSA-2jgf-qh2v-pfqg.json new file mode 100644 index 00000000000..ae9ec45509c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2jgf-qh2v-pfqg/GHSA-2jgf-qh2v-pfqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jgf-qh2v-pfqg", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-27631" + ], + "details": "The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27631" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000210&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-90" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3fpr-88w3-v99m/GHSA-3fpr-88w3-v99m.json b/advisories/unreviewed/2025/03/GHSA-3fpr-88w3-v99m/GHSA-3fpr-88w3-v99m.json index 5cb2b2f033e..7607eb9f605 100644 --- a/advisories/unreviewed/2025/03/GHSA-3fpr-88w3-v99m/GHSA-3fpr-88w3-v99m.json +++ b/advisories/unreviewed/2025/03/GHSA-3fpr-88w3-v99m/GHSA-3fpr-88w3-v99m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3fpr-88w3-v99m", - "modified": "2025-03-13T15:32:54Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58071" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nteam: prevent adding a device which is already a team device lower\n\nPrevent adding a device which is already a team device lower,\ne.g. adding veth0 if vlan1 was already added and veth0 is a lower of\nvlan1.\n\nThis is not useful in practice and can lead to recursive locking:\n\n$ ip link add veth0 type veth peer name veth1\n$ ip link set veth0 up\n$ ip link set veth1 up\n$ ip link add link veth0 name veth0.1 type vlan protocol 802.1Q id 1\n$ ip link add team0 type team\n$ ip link set veth0.1 down\n$ ip link set veth0.1 master team0\nteam0: Port device veth0.1 added\n$ ip link set veth0 down\n$ ip link set veth0 master team0\n\n============================================\nWARNING: possible recursive locking detected\n6.13.0-rc2-virtme-00441-ga14a429069bb #46 Not tainted\n--------------------------------------------\nip/7684 is trying to acquire lock:\nffff888016848e00 (team->team_lock_key){+.+.}-{4:4}, at: team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\n\nbut task is already holding lock:\nffff888016848e00 (team->team_lock_key){+.+.}-{4:4}, at: team_add_slave (drivers/net/team/team_core.c:1147 drivers/net/team/team_core.c:1977)\n\nother info that might help us debug this:\nPossible unsafe locking scenario:\n\nCPU0\n----\nlock(team->team_lock_key);\nlock(team->team_lock_key);\n\n*** DEADLOCK ***\n\nMay be due to missing lock nesting notation\n\n2 locks held by ip/7684:\n\nstack backtrace:\nCPU: 3 UID: 0 PID: 7684 Comm: ip Not tainted 6.13.0-rc2-virtme-00441-ga14a429069bb #46\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n\ndump_stack_lvl (lib/dump_stack.c:122)\nprint_deadlock_bug.cold (kernel/locking/lockdep.c:3040)\n__lock_acquire (kernel/locking/lockdep.c:3893 kernel/locking/lockdep.c:5226)\n? netlink_broadcast_filtered (net/netlink/af_netlink.c:1548)\nlock_acquire.part.0 (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5851)\n? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\n? trace_lock_acquire (./include/trace/events/lock.h:24 (discriminator 2))\n? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\n? lock_acquire (kernel/locking/lockdep.c:5822)\n? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\n__mutex_lock (kernel/locking/mutex.c:587 kernel/locking/mutex.c:735)\n? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\n? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\n? fib_sync_up (net/ipv4/fib_semantics.c:2167)\n? team_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\nteam_device_event (drivers/net/team/team_core.c:2928 drivers/net/team/team_core.c:2951 drivers/net/team/team_core.c:2973)\nnotifier_call_chain (kernel/notifier.c:85)\ncall_netdevice_notifiers_info (net/core/dev.c:1996)\n__dev_notify_flags (net/core/dev.c:8993)\n? __dev_change_flags (net/core/dev.c:8975)\ndev_change_flags (net/core/dev.c:9027)\nvlan_device_event (net/8021q/vlan.c:85 net/8021q/vlan.c:470)\n? br_device_event (net/bridge/br.c:143)\nnotifier_call_chain (kernel/notifier.c:85)\ncall_netdevice_notifiers_info (net/core/dev.c:1996)\ndev_open (net/core/dev.c:1519 net/core/dev.c:1505)\nteam_add_slave (drivers/net/team/team_core.c:1219 drivers/net/team/team_core.c:1977)\n? __pfx_team_add_slave (drivers/net/team/team_core.c:1972)\ndo_set_master (net/core/rtnetlink.c:2917)\ndo_setlink.isra.0 (net/core/rtnetlink.c:3117)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json b/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json index 53bc1e434f6..d8a11b17a05 100644 --- a/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json +++ b/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3pjj-2f8w-vhh5", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-12769" ], "details": "The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-44x6-67xw-4m95/GHSA-44x6-67xw-4m95.json b/advisories/unreviewed/2025/03/GHSA-44x6-67xw-4m95/GHSA-44x6-67xw-4m95.json index 6e1ad09ba2f..b02265aee2a 100644 --- a/advisories/unreviewed/2025/03/GHSA-44x6-67xw-4m95/GHSA-44x6-67xw-4m95.json +++ b/advisories/unreviewed/2025/03/GHSA-44x6-67xw-4m95/GHSA-44x6-67xw-4m95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-44x6-67xw-4m95", - "modified": "2025-03-06T18:31:10Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58070" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT\n\nIn PREEMPT_RT, kmalloc(GFP_ATOMIC) is still not safe in non preemptible\ncontext. bpf_mem_alloc must be used in PREEMPT_RT. This patch is\nto enforce bpf_mem_alloc in the bpf_local_storage when CONFIG_PREEMPT_RT\nis enabled.\n\n[ 35.118559] BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\n[ 35.118566] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1832, name: test_progs\n[ 35.118569] preempt_count: 1, expected: 0\n[ 35.118571] RCU nest depth: 1, expected: 1\n[ 35.118577] INFO: lockdep is turned off.\n ...\n[ 35.118647] __might_resched+0x433/0x5b0\n[ 35.118677] rt_spin_lock+0xc3/0x290\n[ 35.118700] ___slab_alloc+0x72/0xc40\n[ 35.118723] __kmalloc_noprof+0x13f/0x4e0\n[ 35.118732] bpf_map_kzalloc+0xe5/0x220\n[ 35.118740] bpf_selem_alloc+0x1d2/0x7b0\n[ 35.118755] bpf_local_storage_update+0x2fa/0x8b0\n[ 35.118784] bpf_sk_storage_get_tracing+0x15a/0x1d0\n[ 35.118791] bpf_prog_9a118d86fca78ebb_trace_inet_sock_set_state+0x44/0x66\n[ 35.118795] bpf_trace_run3+0x222/0x400\n[ 35.118820] __bpf_trace_inet_sock_set_state+0x11/0x20\n[ 35.118824] trace_inet_sock_set_state+0x112/0x130\n[ 35.118830] inet_sk_state_store+0x41/0x90\n[ 35.118836] tcp_set_state+0x3b3/0x640\n\nThere is no need to adjust the gfp_flags passing to the\nbpf_mem_cache_alloc_flags() which only honors the GFP_KERNEL.\nThe verifier has ensured GFP_KERNEL is passed only in sleepable context.\n\nIt has been an old issue since the first introduction of the\nbpf_local_storage ~5 years ago, so this patch targets the bpf-next.\n\nbpf_mem_alloc is needed to solve it, so the Fixes tag is set\nto the commit when bpf_mem_alloc was first used in the bpf_local_storage.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json b/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json index 889d61e2060..7e84d007a71 100644 --- a/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json +++ b/advisories/unreviewed/2025/03/GHSA-46f9-rmg7-hh9m/GHSA-46f9-rmg7-hh9m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46f9-rmg7-hh9m", - "modified": "2025-03-04T21:30:58Z", + "modified": "2025-03-25T15:31:21Z", "published": "2025-03-04T21:30:58Z", "aliases": [ "CVE-2020-23438" ], "details": "Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-04T21:15:10Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json b/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json index b79bc9014ab..a74a8e90dbb 100644 --- a/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json +++ b/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4878-3496-cr5j", - "modified": "2025-03-25T06:30:28Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:28Z", "aliases": [ "CVE-2024-13618" ], "details": "The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-53v3-522x-7x4p/GHSA-53v3-522x-7x4p.json b/advisories/unreviewed/2025/03/GHSA-53v3-522x-7x4p/GHSA-53v3-522x-7x4p.json new file mode 100644 index 00000000000..b474d855187 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-53v3-522x-7x4p/GHSA-53v3-522x-7x4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53v3-522x-7x4p", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-26742" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through 1.0.0.35.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26742" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/feed-instagram-lite/vulnerability/wordpress-gallery-for-social-photo-plugin-1-0-0-35-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5pg4-gp5m-jv5v/GHSA-5pg4-gp5m-jv5v.json b/advisories/unreviewed/2025/03/GHSA-5pg4-gp5m-jv5v/GHSA-5pg4-gp5m-jv5v.json new file mode 100644 index 00000000000..cc53ea734bd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5pg4-gp5m-jv5v/GHSA-5pg4-gp5m-jv5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pg4-gp5m-jv5v", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2024-42533" + ], + "details": "SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42533" + }, + { + "type": "WEB", + "url": "https://gist.github.com/7h30th3r0n3/eae27e0eed39741365c55dfd46b57dc8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json b/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json index c9b999b5390..7c04c09f4c3 100644 --- a/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json +++ b/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5pwg-63cp-76fj", - "modified": "2025-03-25T06:30:28Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:28Z", "aliases": [ "CVE-2024-13863" ], "details": "The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5rcp-4jvr-rpqr/GHSA-5rcp-4jvr-rpqr.json b/advisories/unreviewed/2025/03/GHSA-5rcp-4jvr-rpqr/GHSA-5rcp-4jvr-rpqr.json new file mode 100644 index 00000000000..b52443d42d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5rcp-4jvr-rpqr/GHSA-5rcp-4jvr-rpqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rcp-4jvr-rpqr", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-2530" + ], + "details": "Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of dae files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23698.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2530" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-173" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json b/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json index a6000117369..43f1b77aebe 100644 --- a/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json +++ b/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5wqh-pcq3-r3px", - "modified": "2025-03-25T06:30:28Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:28Z", "aliases": [ "CVE-2024-9770" ], "details": "The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-665f-p6v8-5227/GHSA-665f-p6v8-5227.json b/advisories/unreviewed/2025/03/GHSA-665f-p6v8-5227/GHSA-665f-p6v8-5227.json new file mode 100644 index 00000000000..8ade826beb0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-665f-p6v8-5227/GHSA-665f-p6v8-5227.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-665f-p6v8-5227", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2024-10037" + ], + "details": "A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection.\nAn attacker must be properly authenticated and the test mode function of RTU500 must be enabled to exploit this vulnerability.\n\nThe affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10037" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000207&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json b/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json index 5c8d72ad73b..89c144fb400 100644 --- a/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json +++ b/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-673g-crrq-7x55", - "modified": "2025-03-25T06:30:28Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:28Z", "aliases": [ "CVE-2025-1798" ], "details": "The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6pf8-q335-vxv9/GHSA-6pf8-q335-vxv9.json b/advisories/unreviewed/2025/03/GHSA-6pf8-q335-vxv9/GHSA-6pf8-q335-vxv9.json new file mode 100644 index 00000000000..f128abc6aca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6pf8-q335-vxv9/GHSA-6pf8-q335-vxv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pf8-q335-vxv9", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2024-12169" + ], + "details": "A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3 (TLS) is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12169" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000207&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json b/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json index f65ad85cd09..62a90e4e95a 100644 --- a/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json +++ b/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6qrv-h235-q5x7", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-13123" ], "details": "The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json b/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json index c6e8e8665ff..116ec505821 100644 --- a/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json +++ b/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6vr9-h9pm-5frx", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:27Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10105" ], "details": "The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json b/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json index 17ce5b74c9b..e42f45bdeaa 100644 --- a/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json +++ b/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7635-mr68-26j6", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-13118" ], "details": "The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json b/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json index 711a92dd44b..434e7bc34ae 100644 --- a/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json +++ b/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-76c9-635j-h2r5", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10566" ], "details": "The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7g63-967x-cfvv/GHSA-7g63-967x-cfvv.json b/advisories/unreviewed/2025/03/GHSA-7g63-967x-cfvv/GHSA-7g63-967x-cfvv.json index c74dca88d1d..39cb1d9f749 100644 --- a/advisories/unreviewed/2025/03/GHSA-7g63-967x-cfvv/GHSA-7g63-967x-cfvv.json +++ b/advisories/unreviewed/2025/03/GHSA-7g63-967x-cfvv/GHSA-7g63-967x-cfvv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json b/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json index 3386e29fdb2..a937b23643e 100644 --- a/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json +++ b/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8jxr-w3j2-x85w", - "modified": "2025-03-25T06:30:28Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:28Z", "aliases": [ "CVE-2025-0717" ], "details": "To exploit the vulnerability, it is necessary:", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json b/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json index 16cd444f1d2..d70aeb9988f 100644 --- a/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json +++ b/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-9f58-q6j7-m5vv/GHSA-9f58-q6j7-m5vv.json b/advisories/unreviewed/2025/03/GHSA-9f58-q6j7-m5vv/GHSA-9f58-q6j7-m5vv.json index 5068711a6a5..570ceb4ae53 100644 --- a/advisories/unreviewed/2025/03/GHSA-9f58-q6j7-m5vv/GHSA-9f58-q6j7-m5vv.json +++ b/advisories/unreviewed/2025/03/GHSA-9f58-q6j7-m5vv/GHSA-9f58-q6j7-m5vv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9f58-q6j7-m5vv", - "modified": "2025-03-06T18:31:10Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: check dpu_plane_atomic_print_state() for valid sspp\n\nSimilar to the r_pipe sspp protect, add a check to protect\nthe pipe state prints to avoid NULL ptr dereference for cases when\nthe state is dumped without a corresponding atomic_check() where the\npipe->sspp is assigned.\n\nPatchwork: https://patchwork.freedesktop.org/patch/628404/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9xhf-3wg6-87r4/GHSA-9xhf-3wg6-87r4.json b/advisories/unreviewed/2025/03/GHSA-9xhf-3wg6-87r4/GHSA-9xhf-3wg6-87r4.json index f83c36d2808..4e259f2d812 100644 --- a/advisories/unreviewed/2025/03/GHSA-9xhf-3wg6-87r4/GHSA-9xhf-3wg6-87r4.json +++ b/advisories/unreviewed/2025/03/GHSA-9xhf-3wg6-87r4/GHSA-9xhf-3wg6-87r4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json b/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json index bfa787af9cf..973bec12074 100644 --- a/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json +++ b/advisories/unreviewed/2025/03/GHSA-c22c-4xww-2fqr/GHSA-c22c-4xww-2fqr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-451" + "CWE-451", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-c8w4-q7v8-687p/GHSA-c8w4-q7v8-687p.json b/advisories/unreviewed/2025/03/GHSA-c8w4-q7v8-687p/GHSA-c8w4-q7v8-687p.json index 8c7124fe4ac..c822190c3ec 100644 --- a/advisories/unreviewed/2025/03/GHSA-c8w4-q7v8-687p/GHSA-c8w4-q7v8-687p.json +++ b/advisories/unreviewed/2025/03/GHSA-c8w4-q7v8-687p/GHSA-c8w4-q7v8-687p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c8w4-q7v8-687p", - "modified": "2025-03-06T18:31:12Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:12Z", "aliases": [ "CVE-2025-21833" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Avoid use of NULL after WARN_ON_ONCE\n\nThere is a WARN_ON_ONCE to catch an unlikely situation when\ndomain_remove_dev_pasid can't find the `pasid`. In case it nevertheless\nhappens we must avoid using a NULL pointer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T17:15:23Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json b/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json index ab2c0086718..706e6579e02 100644 --- a/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json +++ b/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c993-hrcm-4cp8", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:27Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10472" ], "details": "The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json b/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json index e0be8ea7b96..d9b0615ae34 100644 --- a/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json +++ b/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-359" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-cvr2-vqw8-v6q9/GHSA-cvr2-vqw8-v6q9.json b/advisories/unreviewed/2025/03/GHSA-cvr2-vqw8-v6q9/GHSA-cvr2-vqw8-v6q9.json index bf4f1ff48e1..9791967878a 100644 --- a/advisories/unreviewed/2025/03/GHSA-cvr2-vqw8-v6q9/GHSA-cvr2-vqw8-v6q9.json +++ b/advisories/unreviewed/2025/03/GHSA-cvr2-vqw8-v6q9/GHSA-cvr2-vqw8-v6q9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cvr2-vqw8-v6q9", - "modified": "2025-03-06T18:31:10Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() check\n\nThe devm_kzalloc() function doesn't return error pointers, it returns\nNULL on error. Update the check to match.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json b/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json index fa83bb8fc5b..f7fe45291d2 100644 --- a/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json +++ b/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cw73-w3vc-7g28", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-12109" ], "details": "The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json b/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json index aae9efbe16a..b58bfe07b0f 100644 --- a/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json +++ b/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f32g-h75h-7vgp", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-13617" ], "details": "The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f33w-26qx-6hvm/GHSA-f33w-26qx-6hvm.json b/advisories/unreviewed/2025/03/GHSA-f33w-26qx-6hvm/GHSA-f33w-26qx-6hvm.json index e749d8c0ff8..f0c7051999f 100644 --- a/advisories/unreviewed/2025/03/GHSA-f33w-26qx-6hvm/GHSA-f33w-26qx-6hvm.json +++ b/advisories/unreviewed/2025/03/GHSA-f33w-26qx-6hvm/GHSA-f33w-26qx-6hvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f33w-26qx-6hvm", - "modified": "2025-03-13T15:32:53Z", + "modified": "2025-03-25T15:31:21Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58052" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table\n\nThe function atomctrl_get_smc_sclk_range_table() does not check the return\nvalue of smu_atom_get_data_table(). If smu_atom_get_data_table() fails to\nretrieve SMU_Info table, it returns NULL which is later dereferenced.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\nIn practice this should never happen as this code only gets called\non polaris chips and the vbios data table will always be present on\nthose chips.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:51Z" diff --git a/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json b/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json index 2528a2a778a..41803a66349 100644 --- a/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json +++ b/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ffm9-v534-h8c2", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10703" ], "details": "The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json b/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json index 1c2d231ce0f..3595a9788a5 100644 --- a/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json +++ b/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg5v-3r25-5f95", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-12682" ], "details": "The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fp8m-c995-8jh3/GHSA-fp8m-c995-8jh3.json b/advisories/unreviewed/2025/03/GHSA-fp8m-c995-8jh3/GHSA-fp8m-c995-8jh3.json new file mode 100644 index 00000000000..6dfd6710cc4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fp8m-c995-8jh3/GHSA-fp8m-c995-8jh3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp8m-c995-8jh3", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-30091" + ], + "details": "In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30091" + }, + { + "type": "WEB", + "url": "https://www.moxiemanager.com/changelog" + }, + { + "type": "WEB", + "url": "https://www.moxiemanager.com/documentation/SEC-1063.php" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fvgf-g9j6-cf8m/GHSA-fvgf-g9j6-cf8m.json b/advisories/unreviewed/2025/03/GHSA-fvgf-g9j6-cf8m/GHSA-fvgf-g9j6-cf8m.json index d2de660ae9b..8d366d7af97 100644 --- a/advisories/unreviewed/2025/03/GHSA-fvgf-g9j6-cf8m/GHSA-fvgf-g9j6-cf8m.json +++ b/advisories/unreviewed/2025/03/GHSA-fvgf-g9j6-cf8m/GHSA-fvgf-g9j6-cf8m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvgf-g9j6-cf8m", - "modified": "2025-03-06T18:31:10Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58068" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nOPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized\n\nIf a driver calls dev_pm_opp_find_bw_ceil/floor() the retrieve bandwidth\nfrom the OPP table but the bandwidth table was not created because the\ninterconnect properties were missing in the OPP consumer node, the\nkernel will crash with:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000004\n...\npc : _read_bw+0x8/0x10\nlr : _opp_table_find_key+0x9c/0x174\n...\nCall trace:\n _read_bw+0x8/0x10 (P)\n _opp_table_find_key+0x9c/0x174 (L)\n _find_key+0x98/0x168\n dev_pm_opp_find_bw_ceil+0x50/0x88\n...\n\nIn order to fix the crash, create an assert function to check\nif the bandwidth table was created before trying to get a\nbandwidth with _read_bw().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-g4w6-jw6r-6882/GHSA-g4w6-jw6r-6882.json b/advisories/unreviewed/2025/03/GHSA-g4w6-jw6r-6882/GHSA-g4w6-jw6r-6882.json index 46d3af1a88a..7e595f85d9d 100644 --- a/advisories/unreviewed/2025/03/GHSA-g4w6-jw6r-6882/GHSA-g4w6-jw6r-6882.json +++ b/advisories/unreviewed/2025/03/GHSA-g4w6-jw6r-6882/GHSA-g4w6-jw6r-6882.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4w6-jw6r-6882", - "modified": "2025-03-06T18:31:09Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58065" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() check\n\nThe devm_kzalloc() function returns NULL on error, not error pointers.\nFix the check.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json b/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json index 4e9ea5bf6d4..b95da649e32 100644 --- a/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json +++ b/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqcv-v7gm-vw94", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10638" ], "details": "The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gqmm-fccw-xjf3/GHSA-gqmm-fccw-xjf3.json b/advisories/unreviewed/2025/03/GHSA-gqmm-fccw-xjf3/GHSA-gqmm-fccw-xjf3.json index 47e9bef0035..affa8070e7d 100644 --- a/advisories/unreviewed/2025/03/GHSA-gqmm-fccw-xjf3/GHSA-gqmm-fccw-xjf3.json +++ b/advisories/unreviewed/2025/03/GHSA-gqmm-fccw-xjf3/GHSA-gqmm-fccw-xjf3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqmm-fccw-xjf3", - "modified": "2025-03-06T18:31:11Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:11Z", "aliases": [ "CVE-2024-58081" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mmp2: call pm_genpd_init() only after genpd.name is set\n\nSetting the genpd's struct device's name with dev_set_name() is\nhappening within pm_genpd_init(). If it remains NULL, things can blow up\nlater, such as when crafting the devfs hierarchy for the power domain:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000000 when read\n ...\n Call trace:\n strlen from start_creating+0x90/0x138\n start_creating from debugfs_create_dir+0x20/0x178\n debugfs_create_dir from genpd_debug_add.part.0+0x4c/0x144\n genpd_debug_add.part.0 from genpd_debug_init+0x74/0x90\n genpd_debug_init from do_one_initcall+0x5c/0x244\n do_one_initcall from kernel_init_freeable+0x19c/0x1f4\n kernel_init_freeable from kernel_init+0x1c/0x12c\n kernel_init from ret_from_fork+0x14/0x28\n\nBisecting tracks this crash back to commit 899f44531fe6 (\"pmdomain: core:\nAdd GENPD_FLAG_DEV_NAME_FW flag\"), which exchanges use of genpd->name\nwith dev_name(&genpd->dev) in genpd_debug_add.part().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T17:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gv64-36xp-c47j/GHSA-gv64-36xp-c47j.json b/advisories/unreviewed/2025/03/GHSA-gv64-36xp-c47j/GHSA-gv64-36xp-c47j.json new file mode 100644 index 00000000000..06f53bead86 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gv64-36xp-c47j/GHSA-gv64-36xp-c47j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv64-36xp-c47j", + "modified": "2025-03-25T15:31:28Z", + "published": "2025-03-25T15:31:28Z", + "aliases": [ + "CVE-2025-27632" + ], + "details": "A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27632" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000210&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json b/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json index f09a6b343ab..567a3b7634b 100644 --- a/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json +++ b/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h2gq-85xh-8c3c", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10679" ], "details": "The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h5xv-5cpx-pf45/GHSA-h5xv-5cpx-pf45.json b/advisories/unreviewed/2025/03/GHSA-h5xv-5cpx-pf45/GHSA-h5xv-5cpx-pf45.json new file mode 100644 index 00000000000..15d6a6ec1b9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5xv-5cpx-pf45/GHSA-h5xv-5cpx-pf45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5xv-5cpx-pf45", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-22230" + ], + "details": "VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22230" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h77r-2p45-qp9h/GHSA-h77r-2p45-qp9h.json b/advisories/unreviewed/2025/03/GHSA-h77r-2p45-qp9h/GHSA-h77r-2p45-qp9h.json new file mode 100644 index 00000000000..e4456bc729d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h77r-2p45-qp9h/GHSA-h77r-2p45-qp9h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h77r-2p45-qp9h", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2024-11499" + ], + "details": "A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections.\n\nThe affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11499" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000207&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hcgq-vpp8-j6q4/GHSA-hcgq-vpp8-j6q4.json b/advisories/unreviewed/2025/03/GHSA-hcgq-vpp8-j6q4/GHSA-hcgq-vpp8-j6q4.json new file mode 100644 index 00000000000..7793443d9ef --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hcgq-vpp8-j6q4/GHSA-hcgq-vpp8-j6q4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcgq-vpp8-j6q4", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-1445" + ], + "details": "A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active.\n\nPrecondition is that IEC61850 as client or server are configured using TLS on RTU500 device. It affects the CMU the IEC61850 stack is configured on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1445" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000207&languageCode=en&Preview=true" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-820" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hrqh-mj8r-gjgp/GHSA-hrqh-mj8r-gjgp.json b/advisories/unreviewed/2025/03/GHSA-hrqh-mj8r-gjgp/GHSA-hrqh-mj8r-gjgp.json index 6d63064d86b..1730258bff2 100644 --- a/advisories/unreviewed/2025/03/GHSA-hrqh-mj8r-gjgp/GHSA-hrqh-mj8r-gjgp.json +++ b/advisories/unreviewed/2025/03/GHSA-hrqh-mj8r-gjgp/GHSA-hrqh-mj8r-gjgp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-277" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-j2pq-j692-qx87/GHSA-j2pq-j692-qx87.json b/advisories/unreviewed/2025/03/GHSA-j2pq-j692-qx87/GHSA-j2pq-j692-qx87.json index a02ea48a055..f0ef345dc91 100644 --- a/advisories/unreviewed/2025/03/GHSA-j2pq-j692-qx87/GHSA-j2pq-j692-qx87.json +++ b/advisories/unreviewed/2025/03/GHSA-j2pq-j692-qx87/GHSA-j2pq-j692-qx87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j2pq-j692-qx87", - "modified": "2025-03-13T15:32:54Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:11Z", "aliases": [ "CVE-2024-58076" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: gcc-sm6350: Add missing parent_map for two clocks\n\nIf a clk_rcg2 has a parent, it should also have parent_map defined,\notherwise we'll get a NULL pointer dereference when calling clk_set_rate\nlike the following:\n\n [ 3.388105] Call trace:\n [ 3.390664] qcom_find_src_index+0x3c/0x70 (P)\n [ 3.395301] qcom_find_src_index+0x1c/0x70 (L)\n [ 3.399934] _freq_tbl_determine_rate+0x48/0x100\n [ 3.404753] clk_rcg2_determine_rate+0x1c/0x28\n [ 3.409387] clk_core_determine_round_nolock+0x58/0xe4\n [ 3.421414] clk_core_round_rate_nolock+0x48/0xfc\n [ 3.432974] clk_core_round_rate_nolock+0xd0/0xfc\n [ 3.444483] clk_core_set_rate_nolock+0x8c/0x300\n [ 3.455886] clk_set_rate+0x38/0x14c\n\nAdd the parent_map property for two clocks where it's missing and also\nun-inline the parent_data as well to keep the matching parent_map and\nparent_data together.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T17:15:20Z" diff --git a/advisories/unreviewed/2025/03/GHSA-jhf6-432q-gp6x/GHSA-jhf6-432q-gp6x.json b/advisories/unreviewed/2025/03/GHSA-jhf6-432q-gp6x/GHSA-jhf6-432q-gp6x.json new file mode 100644 index 00000000000..31c6599d29d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jhf6-432q-gp6x/GHSA-jhf6-432q-gp6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhf6-432q-gp6x", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-2531" + ], + "details": "Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of dae files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23704.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2531" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-174" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json b/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json index 46435019e33..b409f70c08a 100644 --- a/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json +++ b/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jv5x-w5jr-8gvf", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-11272" ], "details": "The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-m9wc-3h85-pp63/GHSA-m9wc-3h85-pp63.json b/advisories/unreviewed/2025/03/GHSA-m9wc-3h85-pp63/GHSA-m9wc-3h85-pp63.json new file mode 100644 index 00000000000..f3f16df99cd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m9wc-3h85-pp63/GHSA-m9wc-3h85-pp63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9wc-3h85-pp63", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-29635" + ], + "details": "A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29635" + }, + { + "type": "WEB", + "url": "https://github.com/mono7s/Dir-823x/blob/main/set_prohibiting/set_prohibiting.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mh6c-cj4f-f948/GHSA-mh6c-cj4f-f948.json b/advisories/unreviewed/2025/03/GHSA-mh6c-cj4f-f948/GHSA-mh6c-cj4f-f948.json index edae9356cb3..3ecd46a8a18 100644 --- a/advisories/unreviewed/2025/03/GHSA-mh6c-cj4f-f948/GHSA-mh6c-cj4f-f948.json +++ b/advisories/unreviewed/2025/03/GHSA-mh6c-cj4f-f948/GHSA-mh6c-cj4f-f948.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mh6c-cj4f-f948", - "modified": "2025-03-06T18:31:09Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58062" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: avoid NULL pointer dereference\n\nWhen iterating over the links of a vif, we need to make sure that the\npointer is valid (in other words - that the link exists) before\ndereferncing it.\nUse for_each_vif_active_link that also does the check.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p7j9-4392-6r7p/GHSA-p7j9-4392-6r7p.json b/advisories/unreviewed/2025/03/GHSA-p7j9-4392-6r7p/GHSA-p7j9-4392-6r7p.json index 724a92c97e2..2ae1f73b141 100644 --- a/advisories/unreviewed/2025/03/GHSA-p7j9-4392-6r7p/GHSA-p7j9-4392-6r7p.json +++ b/advisories/unreviewed/2025/03/GHSA-p7j9-4392-6r7p/GHSA-p7j9-4392-6r7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p7j9-4392-6r7p", - "modified": "2025-03-13T15:32:54Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58069" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read\n\nThe nvmem interface supports variable buffer sizes, while the regmap\ninterface operates with fixed-size storage. If an nvmem client uses a\nbuffer size less than 4 bytes, regmap_read will write out of bounds\nas it expects the buffer to point at an unsigned int.\n\nFix this by using an intermediary unsigned int to hold the value.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pgm2-324j-f3jh/GHSA-pgm2-324j-f3jh.json b/advisories/unreviewed/2025/03/GHSA-pgm2-324j-f3jh/GHSA-pgm2-324j-f3jh.json new file mode 100644 index 00000000000..f69b977374f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pgm2-324j-f3jh/GHSA-pgm2-324j-f3jh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgm2-324j-f3jh", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-27633" + ], + "details": "The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality and integrity of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27633" + }, + { + "type": "WEB", + "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000210&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json b/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json index bff109a403c..f6b4e539731 100644 --- a/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json +++ b/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q27q-f4wr-gh4j", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:27Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10554" ], "details": "The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-q4g4-gmvw-9fqc/GHSA-q4g4-gmvw-9fqc.json b/advisories/unreviewed/2025/03/GHSA-q4g4-gmvw-9fqc/GHSA-q4g4-gmvw-9fqc.json index 8f9eaf205f0..4f94ea1db36 100644 --- a/advisories/unreviewed/2025/03/GHSA-q4g4-gmvw-9fqc/GHSA-q4g4-gmvw-9fqc.json +++ b/advisories/unreviewed/2025/03/GHSA-q4g4-gmvw-9fqc/GHSA-q4g4-gmvw-9fqc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4g4-gmvw-9fqc", - "modified": "2025-03-13T15:32:53Z", + "modified": "2025-03-25T15:31:21Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58055" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: Don't free command immediately\n\nDon't prematurely free the command. Wait for the status completion of\nthe sense status. It can be freed then. Otherwise we will double-free\nthe command.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:51Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qgmq-76m4-c2jv/GHSA-qgmq-76m4-c2jv.json b/advisories/unreviewed/2025/03/GHSA-qgmq-76m4-c2jv/GHSA-qgmq-76m4-c2jv.json index 35dbfe298f6..886ae3afb2b 100644 --- a/advisories/unreviewed/2025/03/GHSA-qgmq-76m4-c2jv/GHSA-qgmq-76m4-c2jv.json +++ b/advisories/unreviewed/2025/03/GHSA-qgmq-76m4-c2jv/GHSA-qgmq-76m4-c2jv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgmq-76m4-c2jv", - "modified": "2025-03-06T18:31:09Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58059" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Fix deadlock during uvc_probe\n\nIf uvc_probe() fails, it can end up calling uvc_status_unregister() before\nuvc_status_init() is called.\n\nFix this by checking if dev->status is NULL or not in\nuvc_status_unregister().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json b/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json index 4a369497aee..5d5c3a9481b 100644 --- a/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json +++ b/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgrj-c4rv-c2r5", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-11273" ], "details": "The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json b/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json index f86c66192ca..c68b7338b7e 100644 --- a/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json +++ b/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qq4f-w524-x6mg", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10565" ], "details": "The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json b/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json index 4f1fdb2c76a..5fdee40d3c0 100644 --- a/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json +++ b/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqq7-68c5-p37w", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-13122" ], "details": "The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r7x2-wq2h-f7x7/GHSA-r7x2-wq2h-f7x7.json b/advisories/unreviewed/2025/03/GHSA-r7x2-wq2h-f7x7/GHSA-r7x2-wq2h-f7x7.json index a87f223207e..c74934c27a8 100644 --- a/advisories/unreviewed/2025/03/GHSA-r7x2-wq2h-f7x7/GHSA-r7x2-wq2h-f7x7.json +++ b/advisories/unreviewed/2025/03/GHSA-r7x2-wq2h-f7x7/GHSA-r7x2-wq2h-f7x7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r7x2-wq2h-f7x7", - "modified": "2025-03-06T18:31:10Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58067" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mmp: pxa1908-mpmu: Fix a NULL vs IS_ERR() check\n\nThe devm_kzalloc() function returns NULL on error, not error pointers.\nUpdate the check to match.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json b/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json index fdc60e5bf78..a613e13fe80 100644 --- a/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json +++ b/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgxv-4464-wf8w", - "modified": "2025-03-25T06:30:28Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:28Z", "aliases": [ "CVE-2025-1452" ], "details": "The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v797-6jmw-529f/GHSA-v797-6jmw-529f.json b/advisories/unreviewed/2025/03/GHSA-v797-6jmw-529f/GHSA-v797-6jmw-529f.json new file mode 100644 index 00000000000..05b7fcdf3ca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v797-6jmw-529f/GHSA-v797-6jmw-529f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v797-6jmw-529f", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2025-29932" + ], + "details": "In JetBrains GoLand before 2025.1 an XXE during debugging was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29932" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v7v5-m765-h4w4/GHSA-v7v5-m765-h4w4.json b/advisories/unreviewed/2025/03/GHSA-v7v5-m765-h4w4/GHSA-v7v5-m765-h4w4.json new file mode 100644 index 00000000000..d7a86ced821 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v7v5-m765-h4w4/GHSA-v7v5-m765-h4w4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7v5-m765-h4w4", + "modified": "2025-03-25T15:31:29Z", + "published": "2025-03-25T15:31:29Z", + "aliases": [ + "CVE-2022-1804" + ], + "details": "accountsservice no longer drops permissions when writting .pam_environment", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1804" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/1974250" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-5439-1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vp5v-47wj-p5r2/GHSA-vp5v-47wj-p5r2.json b/advisories/unreviewed/2025/03/GHSA-vp5v-47wj-p5r2/GHSA-vp5v-47wj-p5r2.json index 57dee266ad0..447e0965837 100644 --- a/advisories/unreviewed/2025/03/GHSA-vp5v-47wj-p5r2/GHSA-vp5v-47wj-p5r2.json +++ b/advisories/unreviewed/2025/03/GHSA-vp5v-47wj-p5r2/GHSA-vp5v-47wj-p5r2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vp5v-47wj-p5r2", - "modified": "2025-03-13T15:32:53Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: fix memory leaks and invalid access at probe error path\n\nDeinitialize at reverse order when probe fails.\n\nWhen init_sw_vars fails, rtl_deinit_core should not be called, specially\nnow that it destroys the rtl_wq workqueue.\n\nAnd call rtl_pci_deinit and deinit_sw_vars, otherwise, memory will be\nleaked.\n\nRemove pci_set_drvdata call as it will already be cleaned up by the core\ndriver code and could lead to memory leaks too. cf. commit 8d450935ae7f\n(\"wireless: rtlwifi: remove unnecessary pci_set_drvdata()\") and\ncommit 3d86b93064c7 (\"rtlwifi: Fix PCI probe error path orphaned memory\").", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vrf6-366f-p2hr/GHSA-vrf6-366f-p2hr.json b/advisories/unreviewed/2025/03/GHSA-vrf6-366f-p2hr/GHSA-vrf6-366f-p2hr.json index d2263bbbe7a..3564126c542 100644 --- a/advisories/unreviewed/2025/03/GHSA-vrf6-366f-p2hr/GHSA-vrf6-366f-p2hr.json +++ b/advisories/unreviewed/2025/03/GHSA-vrf6-366f-p2hr/GHSA-vrf6-366f-p2hr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrf6-366f-p2hr", - "modified": "2025-03-06T18:31:11Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:11Z", "aliases": [ "CVE-2024-58080" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: qcom: dispcc-sm6350: Add missing parent_map for a clock\n\nIf a clk_rcg2 has a parent, it should also have parent_map defined,\notherwise we'll get a NULL pointer dereference when calling clk_set_rate\nlike the following:\n\n [ 3.388105] Call trace:\n [ 3.390664] qcom_find_src_index+0x3c/0x70 (P)\n [ 3.395301] qcom_find_src_index+0x1c/0x70 (L)\n [ 3.399934] _freq_tbl_determine_rate+0x48/0x100\n [ 3.404753] clk_rcg2_determine_rate+0x1c/0x28\n [ 3.409387] clk_core_determine_round_nolock+0x58/0xe4\n [ 3.421414] clk_core_round_rate_nolock+0x48/0xfc\n [ 3.432974] clk_core_round_rate_nolock+0xd0/0xfc\n [ 3.444483] clk_core_set_rate_nolock+0x8c/0x300\n [ 3.455886] clk_set_rate+0x38/0x14c\n\nAdd the parent_map property for the clock where it's missing and also\nun-inline the parent_data as well to keep the matching parent_map and\nparent_data together.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T17:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w3jj-5rxp-759m/GHSA-w3jj-5rxp-759m.json b/advisories/unreviewed/2025/03/GHSA-w3jj-5rxp-759m/GHSA-w3jj-5rxp-759m.json index 8f5ad8784e0..c5d1c8c37cb 100644 --- a/advisories/unreviewed/2025/03/GHSA-w3jj-5rxp-759m/GHSA-w3jj-5rxp-759m.json +++ b/advisories/unreviewed/2025/03/GHSA-w3jj-5rxp-759m/GHSA-w3jj-5rxp-759m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3jj-5rxp-759m", - "modified": "2025-03-06T18:31:09Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-06T18:31:09Z", "aliases": [ "CVE-2024-58064" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: tests: Fix potential NULL dereference in test_cfg80211_parse_colocated_ap()\n\nkunit_kzalloc() may return NULL, dereferencing it without NULL check may\nlead to NULL dereference.\nAdd a NULL check for ies.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json b/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json index 74981ce8872..6af8b2fd38d 100644 --- a/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json +++ b/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w523-c69w-6x53", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-10560" ], "details": "The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json b/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json index c97487f7ac7..4929282d6a8 100644 --- a/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json +++ b/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wwgv-3xwq-6qmc", - "modified": "2025-03-25T06:30:27Z", + "modified": "2025-03-25T15:31:28Z", "published": "2025-03-25T06:30:27Z", "aliases": [ "CVE-2024-11503" ], "details": "The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T06:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wxgw-xr8v-5p75/GHSA-wxgw-xr8v-5p75.json b/advisories/unreviewed/2025/03/GHSA-wxgw-xr8v-5p75/GHSA-wxgw-xr8v-5p75.json index fd377e06241..c711da150dc 100644 --- a/advisories/unreviewed/2025/03/GHSA-wxgw-xr8v-5p75/GHSA-wxgw-xr8v-5p75.json +++ b/advisories/unreviewed/2025/03/GHSA-wxgw-xr8v-5p75/GHSA-wxgw-xr8v-5p75.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxgw-xr8v-5p75", - "modified": "2025-03-13T15:32:54Z", + "modified": "2025-03-25T15:31:21Z", "published": "2025-03-06T18:31:10Z", "aliases": [ "CVE-2024-58058" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: skip dumping tnc tree when zroot is null\n\nClearing slab cache will free all znode in memory and make\nc->zroot.znode = NULL, then dumping tnc tree will access\nc->zroot.znode which cause null pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T16:15:52Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json b/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json index bd67f871cb8..9ef028fc40a 100644 --- a/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json +++ b/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xp75-w7vq-5x6j", - "modified": "2025-03-24T21:30:34Z", + "modified": "2025-03-25T15:31:23Z", "published": "2025-03-24T21:30:34Z", "aliases": [ "CVE-2025-29314" ], "details": "Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive information via a man-in-the-middle attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-311" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xq2v-cc3g-cmw3/GHSA-xq2v-cc3g-cmw3.json b/advisories/unreviewed/2025/03/GHSA-xq2v-cc3g-cmw3/GHSA-xq2v-cc3g-cmw3.json index fecaa9dacf0..5845fd95a7e 100644 --- a/advisories/unreviewed/2025/03/GHSA-xq2v-cc3g-cmw3/GHSA-xq2v-cc3g-cmw3.json +++ b/advisories/unreviewed/2025/03/GHSA-xq2v-cc3g-cmw3/GHSA-xq2v-cc3g-cmw3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq2v-cc3g-cmw3", - "modified": "2025-03-23T15:30:33Z", + "modified": "2025-03-25T15:31:22Z", "published": "2025-03-23T15:30:33Z", "aliases": [ "CVE-2025-0927" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0927" }, + { + "type": "WEB", + "url": "https://ssd-disclosure.com/ssd-advisory-linux-kernel-hfsplus-slab-out-of-bounds-write" + }, { "type": "WEB", "url": "https://ubuntu.com/security/CVE-2025-0927"