Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-02-27 21:33:32 +00:00
parent bbd6da34bf
commit 39f751509e
127 changed files with 4386 additions and 77 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2787-j4hr-mpvr",
"modified": "2023-03-15T15:30:23Z",
"modified": "2025-02-27T21:31:49Z",
"published": "2023-03-10T15:30:42Z",
"aliases": [
"CVE-2022-48111"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qm7-j7mp-35jq",
"modified": "2023-03-16T18:30:31Z",
"modified": "2025-02-27T21:31:49Z",
"published": "2023-03-13T12:30:17Z",
"aliases": [
"CVE-2023-25283"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc55-g3cv-hx93",
"modified": "2023-03-16T18:30:28Z",
"modified": "2025-02-27T21:31:53Z",
"published": "2023-03-14T18:30:23Z",
"aliases": [
"CVE-2023-27069"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fg8g-w97j-ff9c",
"modified": "2023-03-15T18:30:23Z",
"modified": "2025-02-27T21:31:49Z",
"published": "2023-03-10T18:30:22Z",
"aliases": [
"CVE-2023-26075"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html"
},
{
"type": "WEB",
"url": "https://project-zero.issues.chromium.org/issues/42451537"
},
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/processor/mobile-processor"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjmx-fc7p-8h6w",
"modified": "2023-03-17T06:30:35Z",
"modified": "2025-02-27T21:31:51Z",
"published": "2023-03-14T15:30:16Z",
"aliases": [
"CVE-2023-27073"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-427"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfm6-gxrr-6c2j",
"modified": "2024-04-04T03:31:08Z",
"modified": "2025-02-27T21:31:56Z",
"published": "2024-04-04T03:31:08Z",
"aliases": [
"CVE-2024-2868"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-80"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmh5-6rg4-ggmq",
"modified": "2024-10-31T15:30:57Z",
"modified": "2025-02-27T21:31:56Z",
"published": "2024-04-03T18:30:41Z",
"aliases": [
"CVE-2024-26735"
@@ -58,6 +58,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241101-0012"
}
],
"database_specific": {
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xwrr-gvqm-j58v",
"modified": "2024-04-05T21:32:43Z",
"modified": "2025-02-27T21:31:56Z",
"published": "2024-04-05T21:32:43Z",
"aliases": [
"CVE-2024-29741"
],
"details": "In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-05T20:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-49vr-v9q4-q4ph",
"modified": "2024-10-16T09:30:30Z",
"modified": "2025-02-27T21:31:59Z",
"published": "2024-10-16T09:30:30Z",
"aliases": [
"CVE-2020-36835"
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf2q-g3w5-qq7r",
"modified": "2024-10-08T18:33:14Z",
"modified": "2025-02-27T21:31:58Z",
"published": "2024-10-08T18:33:14Z",
"aliases": [
"CVE-2024-8626"
],
"details": "Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -26,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-401"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p6v-g3wm-x2qp",
"modified": "2025-01-24T00:31:47Z",
"modified": "2025-02-27T21:32:01Z",
"published": "2025-01-24T00:31:47Z",
"aliases": [
"CVE-2024-53379"
],
"details": "Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12c83b38f85c943dee0112e428dc2a43 allows a remote attacker to trigger a Denial-of-Service via a malformed Client-Hello message.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-23T23:15:07Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22qr-hr3v-pmr2",
"modified": "2025-02-27T21:32:18Z",
"published": "2025-02-27T21:32:18Z",
"aliases": [
"CVE-2024-41338"
],
"details": "A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to cause a Denial of Service (DoS) via a crafted DHCP request.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41338"
},
{
"type": "WEB",
"url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
},
{
"type": "WEB",
"url": "http://draytek.com"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T21:15:36Z"
}
}
@@ -0,0 +1,45 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2c2p-jp6r-5757",
"modified": "2025-02-27T21:32:18Z",
"published": "2025-02-27T21:32:18Z",
"aliases": [
"CVE-2024-55160"
],
"details": "GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55160"
},
{
"type": "WEB",
"url": "https://github.com/SuperDu1/CVE/issues/2"
},
{
"type": "WEB",
"url": "https://github.com/tiger1103/gfast/blob/os-v3.2/api/v1/system/sys_oper_log.go#L35"
},
{
"type": "WEB",
"url": "https://github.com/tiger1103/gfast/blob/os-v3.2/internal/app/system/logic/sysOperLog/sys_oper_log.go#L121"
},
{
"type": "WEB",
"url": "https://github.com/tiger1103/gfast/tree/os-v3.2"
},
{
"type": "WEB",
"url": "http://gfast.com"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T21:15:37Z"
}
}
File diff suppressed because one or more lines are too long
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37p3-cfcq-p2hp",
"modified": "2025-02-27T21:32:17Z",
"published": "2025-02-27T21:32:17Z",
"aliases": [
"CVE-2025-21815"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/compaction: fix UBSAN shift-out-of-bounds warning\n\nsyzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order)\nin isolate_freepages_block(). The bogus compound_order can be any value\nbecause it is union with flags. Add back the MAX_PAGE_ORDER check to fix\nthe warning.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21815"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/10b7d3eb535098ccd4c82a182a33655d8a0e5c88"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4491159774d973a9e2e998d25d8fbb20fada6dfa"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d1366e74342e75555af2648a2964deb2d5c92200"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T20:16:04Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f4p-8qj7-5fxp",
"modified": "2025-02-27T21:32:17Z",
"published": "2025-02-27T21:32:17Z",
"aliases": [
"CVE-2025-21817"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: mark GFP_NOIO around sysfs ->store()\n\nsysfs ->store is called with queue freezed, meantime we have several\n->store() callbacks(update_nr_requests, wbt, scheduler) to allocate\nmemory with GFP_KERNEL which may run into direct reclaim code path,\nthen potential deadlock can be caused.\n\nFix the issue by marking NOIO around sysfs ->store()",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21817"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T20:16:04Z"
}
}

Some files were not shown because too many files have changed in this diff Show More