From 3be6f78bae32929087a28efa8cb126e7cdbc4d81 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 11 Apr 2025 18:32:30 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6chh-6c6m-xqrh.json | 1 + .../GHSA-8x84-9m3r-fv77.json | 4 +- .../GHSA-99h8-7p7x-vjc6.json | 1 + .../GHSA-9vpq-m98h-94f2.json | 1 + .../GHSA-4rqc-6cwc-8fr7.json | 7 +-- .../GHSA-c8pw-6p2w-cpm2.json | 4 +- .../GHSA-ch7v-4hfq-6r4x.json | 4 +- .../GHSA-f9p5-24wv-w5qx.json | 4 +- .../GHSA-fgcf-ch4w-m3f6.json | 4 +- .../GHSA-mx83-4qpc-6m5h.json | 7 +-- .../GHSA-q6r9-2g53-c4qf.json | 7 +-- .../GHSA-q9rx-4p5p-q33x.json | 4 +- .../GHSA-r553-v847-23pr.json | 3 +- .../GHSA-rqrg-8xc9-5vw3.json | 4 +- .../GHSA-4v5j-ww69-fg82.json | 3 +- .../GHSA-pfh7-q24c-mjwh.json | 4 +- .../GHSA-c583-9378-q3jc.json | 6 ++- .../GHSA-gjf9-pfmc-2689.json | 6 ++- .../GHSA-jrx7-5cr9-c5v4.json | 3 +- .../GHSA-phf9-ch44-7c3w.json | 5 ++- .../GHSA-x2v7-w9j6-rqmx.json | 3 +- .../GHSA-2387-rw9f-fxf8.json | 40 +++++++++++++++++ .../GHSA-379r-vg26-3rr8.json | 36 +++++++++++++++ .../GHSA-426f-2r7q-j2xm.json | 40 +++++++++++++++++ .../GHSA-4hmh-4xrv-g83v.json | 40 +++++++++++++++++ .../GHSA-4xv5-48m7-9qhq.json | 40 +++++++++++++++++ .../GHSA-5892-jw8m-4684.json | 15 +++++-- .../GHSA-5fq6-fcwr-3q76.json | 40 +++++++++++++++++ .../GHSA-5x97-hgxc-62pv.json | 15 +++++-- .../GHSA-64h7-7273-jw5g.json | 15 +++++-- .../GHSA-6xj5-r9h7-wphq.json | 15 +++++-- .../GHSA-8mfv-756x-xchg.json | 40 +++++++++++++++++ .../GHSA-9j63-jqr8-fh2v.json | 6 ++- .../GHSA-9v4c-q3xh-jx9r.json | 40 +++++++++++++++++ .../GHSA-9v5v-qfv2-66qp.json | 15 +++++-- .../GHSA-cmwf-4hcv-45rc.json | 15 +++++-- .../GHSA-cr5h-9jcq-9f6f.json | 40 +++++++++++++++++ .../GHSA-fc6v-27mr-w8pc.json | 40 +++++++++++++++++ .../GHSA-fc78-895f-8fh8.json | 15 +++++-- .../GHSA-grw4-4pm5-246x.json | 40 +++++++++++++++++ .../GHSA-h4wc-9444-frmv.json | 40 +++++++++++++++++ .../GHSA-j97h-5fwv-4rhj.json | 15 +++++-- .../GHSA-m6p7-g6ff-wxw5.json | 15 +++++-- .../GHSA-p288-3mcf-2f3w.json | 40 +++++++++++++++++ .../GHSA-pmvp-2f47-m6wx.json | 15 +++++-- .../GHSA-prqg-f9gx-75qh.json | 40 +++++++++++++++++ .../GHSA-r5vx-68x4-4jcf.json | 40 +++++++++++++++++ .../GHSA-r65j-4h86-f5h7.json | 40 +++++++++++++++++ .../GHSA-vrgf-xjqc-rwfc.json | 36 +++++++++++++++ .../GHSA-wv3j-j89q-mvh8.json | 40 +++++++++++++++++ .../GHSA-xmr2-c47x-rm4p.json | 44 +++++++++++++++++++ 51 files changed, 924 insertions(+), 73 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2387-rw9f-fxf8/GHSA-2387-rw9f-fxf8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-379r-vg26-3rr8/GHSA-379r-vg26-3rr8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-426f-2r7q-j2xm/GHSA-426f-2r7q-j2xm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4hmh-4xrv-g83v/GHSA-4hmh-4xrv-g83v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4xv5-48m7-9qhq/GHSA-4xv5-48m7-9qhq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5fq6-fcwr-3q76/GHSA-5fq6-fcwr-3q76.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8mfv-756x-xchg/GHSA-8mfv-756x-xchg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9v4c-q3xh-jx9r/GHSA-9v4c-q3xh-jx9r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cr5h-9jcq-9f6f/GHSA-cr5h-9jcq-9f6f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fc6v-27mr-w8pc/GHSA-fc6v-27mr-w8pc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-grw4-4pm5-246x/GHSA-grw4-4pm5-246x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h4wc-9444-frmv/GHSA-h4wc-9444-frmv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p288-3mcf-2f3w/GHSA-p288-3mcf-2f3w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-prqg-f9gx-75qh/GHSA-prqg-f9gx-75qh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r5vx-68x4-4jcf/GHSA-r5vx-68x4-4jcf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r65j-4h86-f5h7/GHSA-r65j-4h86-f5h7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vrgf-xjqc-rwfc/GHSA-vrgf-xjqc-rwfc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wv3j-j89q-mvh8/GHSA-wv3j-j89q-mvh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xmr2-c47x-rm4p/GHSA-xmr2-c47x-rm4p.json diff --git a/advisories/unreviewed/2022/12/GHSA-6chh-6c6m-xqrh/GHSA-6chh-6c6m-xqrh.json b/advisories/unreviewed/2022/12/GHSA-6chh-6c6m-xqrh/GHSA-6chh-6c6m-xqrh.json index 70ca2c71a1f..27cc8590398 100644 --- a/advisories/unreviewed/2022/12/GHSA-6chh-6c6m-xqrh/GHSA-6chh-6c6m-xqrh.json +++ b/advisories/unreviewed/2022/12/GHSA-6chh-6c6m-xqrh/GHSA-6chh-6c6m-xqrh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-8x84-9m3r-fv77/GHSA-8x84-9m3r-fv77.json b/advisories/unreviewed/2022/12/GHSA-8x84-9m3r-fv77/GHSA-8x84-9m3r-fv77.json index a35f5c045d0..c4bfd2c00a6 100644 --- a/advisories/unreviewed/2022/12/GHSA-8x84-9m3r-fv77/GHSA-8x84-9m3r-fv77.json +++ b/advisories/unreviewed/2022/12/GHSA-8x84-9m3r-fv77/GHSA-8x84-9m3r-fv77.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-99h8-7p7x-vjc6/GHSA-99h8-7p7x-vjc6.json b/advisories/unreviewed/2022/12/GHSA-99h8-7p7x-vjc6/GHSA-99h8-7p7x-vjc6.json index e469e8fa6d6..c59973d5cf4 100644 --- a/advisories/unreviewed/2022/12/GHSA-99h8-7p7x-vjc6/GHSA-99h8-7p7x-vjc6.json +++ b/advisories/unreviewed/2022/12/GHSA-99h8-7p7x-vjc6/GHSA-99h8-7p7x-vjc6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-9vpq-m98h-94f2/GHSA-9vpq-m98h-94f2.json b/advisories/unreviewed/2022/12/GHSA-9vpq-m98h-94f2/GHSA-9vpq-m98h-94f2.json index 736930e01c7..6c99517f640 100644 --- a/advisories/unreviewed/2022/12/GHSA-9vpq-m98h-94f2/GHSA-9vpq-m98h-94f2.json +++ b/advisories/unreviewed/2022/12/GHSA-9vpq-m98h-94f2/GHSA-9vpq-m98h-94f2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json b/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json index acdade719de..bfc1edf6c1d 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json +++ b/advisories/unreviewed/2024/02/GHSA-4rqc-6cwc-8fr7/GHSA-4rqc-6cwc-8fr7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4rqc-6cwc-8fr7", - "modified": "2025-01-28T18:31:20Z", + "modified": "2025-04-11T18:30:27Z", "published": "2024-02-22T03:30:36Z", "aliases": [ "CVE-2024-23127" ], - "details": "A maliciously crafted MODEL, SLDPRT or SLDASM file when parsed VCRUNTIME140.dll through Autodesk AutoCAD can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted MODEL, SLDPRT or SLDASM file when parsed VCRUNTIME140.dll through Autodesk AutoCAD can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-c8pw-6p2w-cpm2/GHSA-c8pw-6p2w-cpm2.json b/advisories/unreviewed/2024/02/GHSA-c8pw-6p2w-cpm2/GHSA-c8pw-6p2w-cpm2.json index 47079dd33d0..f74724350bf 100644 --- a/advisories/unreviewed/2024/02/GHSA-c8pw-6p2w-cpm2/GHSA-c8pw-6p2w-cpm2.json +++ b/advisories/unreviewed/2024/02/GHSA-c8pw-6p2w-cpm2/GHSA-c8pw-6p2w-cpm2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-c8pw-6p2w-cpm2", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:25Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23121" ], - "details": "A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-ch7v-4hfq-6r4x/GHSA-ch7v-4hfq-6r4x.json b/advisories/unreviewed/2024/02/GHSA-ch7v-4hfq-6r4x/GHSA-ch7v-4hfq-6r4x.json index 96ff9958927..f7aa44e993b 100644 --- a/advisories/unreviewed/2024/02/GHSA-ch7v-4hfq-6r4x/GHSA-ch7v-4hfq-6r4x.json +++ b/advisories/unreviewed/2024/02/GHSA-ch7v-4hfq-6r4x/GHSA-ch7v-4hfq-6r4x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ch7v-4hfq-6r4x", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:26Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23124" ], - "details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json b/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json index 5e3eeba94d9..0babbb8a910 100644 --- a/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json +++ b/advisories/unreviewed/2024/02/GHSA-f9p5-24wv-w5qx/GHSA-f9p5-24wv-w5qx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f9p5-24wv-w5qx", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:25Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23122" ], - "details": "A maliciously crafted 3DM file when parsed in opennurbs.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted 3DM file when parsed in opennurbs.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json b/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json index b55d95e46a4..4b48946250b 100644 --- a/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json +++ b/advisories/unreviewed/2024/02/GHSA-fgcf-ch4w-m3f6/GHSA-fgcf-ch4w-m3f6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fgcf-ch4w-m3f6", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:25Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23123" ], - "details": "A maliciously crafted CATPART file when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted CATPART file when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-mx83-4qpc-6m5h/GHSA-mx83-4qpc-6m5h.json b/advisories/unreviewed/2024/02/GHSA-mx83-4qpc-6m5h/GHSA-mx83-4qpc-6m5h.json index 66de6bcdaf6..2bc5ed63cfb 100644 --- a/advisories/unreviewed/2024/02/GHSA-mx83-4qpc-6m5h/GHSA-mx83-4qpc-6m5h.json +++ b/advisories/unreviewed/2024/02/GHSA-mx83-4qpc-6m5h/GHSA-mx83-4qpc-6m5h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mx83-4qpc-6m5h", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:27Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23126" ], - "details": "A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-q6r9-2g53-c4qf/GHSA-q6r9-2g53-c4qf.json b/advisories/unreviewed/2024/02/GHSA-q6r9-2g53-c4qf/GHSA-q6r9-2g53-c4qf.json index bd176bc4cfc..1191ab958e2 100644 --- a/advisories/unreviewed/2024/02/GHSA-q6r9-2g53-c4qf/GHSA-q6r9-2g53-c4qf.json +++ b/advisories/unreviewed/2024/02/GHSA-q6r9-2g53-c4qf/GHSA-q6r9-2g53-c4qf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q6r9-2g53-c4qf", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:26Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-23125" ], - "details": "A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json b/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json index 79bdfcb3810..132c9d57fbb 100644 --- a/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json +++ b/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q9rx-4p5p-q33x", - "modified": "2025-02-11T00:31:24Z", + "modified": "2025-04-11T18:30:24Z", "published": "2024-02-22T00:31:01Z", "aliases": [ "CVE-2024-0446" ], - "details": "A maliciously crafted STP, CATPART or MODEL file when parsed in ASMKERN228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process. \n", + "details": "A maliciously crafted STP, CATPART or MODEL file when parsed in ASMKERN228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process. ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json b/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json index 623d99cde1c..2e82d8bd7f3 100644 --- a/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json +++ b/advisories/unreviewed/2024/02/GHSA-r553-v847-23pr/GHSA-r553-v847-23pr.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-rqrg-8xc9-5vw3/GHSA-rqrg-8xc9-5vw3.json b/advisories/unreviewed/2024/02/GHSA-rqrg-8xc9-5vw3/GHSA-rqrg-8xc9-5vw3.json index 66206127cfa..f5d39e417c4 100644 --- a/advisories/unreviewed/2024/02/GHSA-rqrg-8xc9-5vw3/GHSA-rqrg-8xc9-5vw3.json +++ b/advisories/unreviewed/2024/02/GHSA-rqrg-8xc9-5vw3/GHSA-rqrg-8xc9-5vw3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rqrg-8xc9-5vw3", - "modified": "2024-08-01T15:31:27Z", + "modified": "2025-04-11T18:30:24Z", "published": "2024-02-22T00:31:02Z", "aliases": [ "CVE-2024-23120" ], - "details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.\n", + "details": "A maliciously crafted STP file when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-4v5j-ww69-fg82/GHSA-4v5j-ww69-fg82.json b/advisories/unreviewed/2024/04/GHSA-4v5j-ww69-fg82/GHSA-4v5j-ww69-fg82.json index 9ea6924e957..6952fd6b074 100644 --- a/advisories/unreviewed/2024/04/GHSA-4v5j-ww69-fg82/GHSA-4v5j-ww69-fg82.json +++ b/advisories/unreviewed/2024/04/GHSA-4v5j-ww69-fg82/GHSA-4v5j-ww69-fg82.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-pfh7-q24c-mjwh/GHSA-pfh7-q24c-mjwh.json b/advisories/unreviewed/2024/04/GHSA-pfh7-q24c-mjwh/GHSA-pfh7-q24c-mjwh.json index 421eb960e85..f361fd12016 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfh7-q24c-mjwh/GHSA-pfh7-q24c-mjwh.json +++ b/advisories/unreviewed/2024/04/GHSA-pfh7-q24c-mjwh/GHSA-pfh7-q24c-mjwh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pfh7-q24c-mjwh", - "modified": "2024-04-15T21:30:46Z", + "modified": "2025-04-11T18:30:32Z", "published": "2024-04-15T21:30:46Z", "aliases": [ "CVE-2024-23560" ], - "details": "HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. \n", + "details": "HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/10/GHSA-c583-9378-q3jc/GHSA-c583-9378-q3jc.json b/advisories/unreviewed/2024/10/GHSA-c583-9378-q3jc/GHSA-c583-9378-q3jc.json index 2ffd0ab6c56..21992c0ae96 100644 --- a/advisories/unreviewed/2024/10/GHSA-c583-9378-q3jc/GHSA-c583-9378-q3jc.json +++ b/advisories/unreviewed/2024/10/GHSA-c583-9378-q3jc/GHSA-c583-9378-q3jc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c583-9378-q3jc", - "modified": "2024-10-30T00:31:05Z", + "modified": "2025-04-11T18:30:35Z", "published": "2024-10-30T00:31:04Z", "aliases": [ "CVE-2024-7991" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0021" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0021" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json b/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json index 280a4ac4717..beb27b8b7e3 100644 --- a/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json +++ b/advisories/unreviewed/2024/10/GHSA-gjf9-pfmc-2689/GHSA-gjf9-pfmc-2689.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjf9-pfmc-2689", - "modified": "2024-10-30T00:31:05Z", + "modified": "2025-04-11T18:30:35Z", "published": "2024-10-30T00:31:04Z", "aliases": [ "CVE-2024-7992" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0021" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0021" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json b/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json index 57f95c860c3..ff146945897 100644 --- a/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json +++ b/advisories/unreviewed/2025/03/GHSA-jrx7-5cr9-c5v4/GHSA-jrx7-5cr9-c5v4.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-phf9-ch44-7c3w/GHSA-phf9-ch44-7c3w.json b/advisories/unreviewed/2025/03/GHSA-phf9-ch44-7c3w/GHSA-phf9-ch44-7c3w.json index 0245bf699fc..58223ee7ba4 100644 --- a/advisories/unreviewed/2025/03/GHSA-phf9-ch44-7c3w/GHSA-phf9-ch44-7c3w.json +++ b/advisories/unreviewed/2025/03/GHSA-phf9-ch44-7c3w/GHSA-phf9-ch44-7c3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phf9-ch44-7c3w", - "modified": "2025-03-27T03:33:36Z", + "modified": "2025-04-11T18:30:39Z", "published": "2025-03-27T03:33:36Z", "aliases": [ "CVE-2025-2831" @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json b/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json index f5316026aa5..e572408b40a 100644 --- a/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json +++ b/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x2v7-w9j6-rqmx", - "modified": "2025-03-28T15:31:55Z", + "modified": "2025-04-11T18:30:40Z", "published": "2025-03-28T03:30:24Z", "aliases": [ "CVE-2024-13939" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-208" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-2387-rw9f-fxf8/GHSA-2387-rw9f-fxf8.json b/advisories/unreviewed/2025/04/GHSA-2387-rw9f-fxf8/GHSA-2387-rw9f-fxf8.json new file mode 100644 index 00000000000..e9f3705a9b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2387-rw9f-fxf8/GHSA-2387-rw9f-fxf8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2387-rw9f-fxf8", + "modified": "2025-04-11T18:31:07Z", + "published": "2025-04-11T18:31:07Z", + "aliases": [ + "CVE-2025-32067" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Growth Experiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Growth Experiments Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32067" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/GrowthExperiments/+/1122163" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T386963" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-379r-vg26-3rr8/GHSA-379r-vg26-3rr8.json b/advisories/unreviewed/2025/04/GHSA-379r-vg26-3rr8/GHSA-379r-vg26-3rr8.json new file mode 100644 index 00000000000..5f5f2f1bf09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-379r-vg26-3rr8/GHSA-379r-vg26-3rr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-379r-vg26-3rr8", + "modified": "2025-04-11T18:31:09Z", + "published": "2025-04-11T18:31:09Z", + "aliases": [ + "CVE-2025-0123" + ], + "details": "A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data captured using the packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture in decrypted HTTP/2 data streams traversing network interfaces on the firewall. HTTP/1.1 data streams are not impacted.\n\nIn normal conditions, decrypted packet captures are available to firewall administrators after they obtain and install a free Decryption Port Mirror license. The license requirement ensures that this feature can only be used after approved personnel purposefully activate the license. For more information, review how to configure decryption port mirroring https://docs.paloaltonetworks.com/network-security/decryption/administration/monitoring-decryption/configure-decryption-port-mirroring .\n\nThe administrator must obtain network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. Risk of this issue can be greatly reduced by restricting access to the management interface to only trusted administrators and from only internal IP addresses according to our recommended critical deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\nCustomer firewall administrators do not have access to the packet capture feature in Cloud NGFW. This feature is available only to authorized Palo Alto Networks personnel permitted to perform troubleshooting.\n\nPrisma® Access is not impacted by this vulnerability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0123" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-426f-2r7q-j2xm/GHSA-426f-2r7q-j2xm.json b/advisories/unreviewed/2025/04/GHSA-426f-2r7q-j2xm/GHSA-426f-2r7q-j2xm.json new file mode 100644 index 00000000000..c4c26e1b02f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-426f-2r7q-j2xm/GHSA-426f-2r7q-j2xm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-426f-2r7q-j2xm", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32073" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32073" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/HTMLTags/+/1121056" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T386337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4hmh-4xrv-g83v/GHSA-4hmh-4xrv-g83v.json b/advisories/unreviewed/2025/04/GHSA-4hmh-4xrv-g83v/GHSA-4hmh-4xrv-g83v.json new file mode 100644 index 00000000000..6def6c55618 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4hmh-4xrv-g83v/GHSA-4hmh-4xrv-g83v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hmh-4xrv-g83v", + "modified": "2025-04-11T18:31:07Z", + "published": "2025-04-11T18:31:07Z", + "aliases": [ + "CVE-2025-32071" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikidata Extension allows Cross-Site Scripting (XSS) from widthheight message via ImageHandler::getDimensionsString()This issue affects Mediawiki - Wikidata Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32071" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Iac1f1c27054bfd1a4a4251281ab8c72f59204a90" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T389369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4xv5-48m7-9qhq/GHSA-4xv5-48m7-9qhq.json b/advisories/unreviewed/2025/04/GHSA-4xv5-48m7-9qhq/GHSA-4xv5-48m7-9qhq.json new file mode 100644 index 00000000000..76a8b2c0cd7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4xv5-48m7-9qhq/GHSA-4xv5-48m7-9qhq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xv5-48m7-9qhq", + "modified": "2025-04-11T18:31:07Z", + "published": "2025-04-11T18:31:07Z", + "aliases": [ + "CVE-2025-32068" + ], + "details": "Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32068" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I27b61af2cdfb862a42432e7a87b863033d540cfc" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T336113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json b/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json index dcc85b9945c..2c2ecc18d2e 100644 --- a/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json +++ b/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5892-jw8m-4684", - "modified": "2025-04-11T15:32:30Z", + "modified": "2025-04-11T18:31:05Z", "published": "2025-04-11T15:32:30Z", "aliases": [ "CVE-2023-42875" ], "details": "Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5fq6-fcwr-3q76/GHSA-5fq6-fcwr-3q76.json b/advisories/unreviewed/2025/04/GHSA-5fq6-fcwr-3q76/GHSA-5fq6-fcwr-3q76.json new file mode 100644 index 00000000000..e1685ee0535 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5fq6-fcwr-3q76/GHSA-5fq6-fcwr-3q76.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fq6-fcwr-3q76", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32075" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Tabs Extension allows Code Injection.This issue affects Mediawiki - Tabs Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32075" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I03bec9528ee3ed05f35187458cde4e2fc4b51092" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T386887" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json b/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json index 5c44930cf7c..73682cea0d8 100644 --- a/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json +++ b/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5x97-hgxc-62pv", - "modified": "2025-04-11T15:32:30Z", + "modified": "2025-04-11T18:31:05Z", "published": "2025-04-11T15:32:30Z", "aliases": [ "CVE-2023-38614" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json b/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json index 96ed30ded4e..3bf6e0ed594 100644 --- a/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json +++ b/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-64h7-7273-jw5g", - "modified": "2025-04-11T15:32:30Z", + "modified": "2025-04-11T18:31:05Z", "published": "2025-04-11T15:32:30Z", "aliases": [ "CVE-2023-42969" ], "details": "An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. The issue was addressed with improved handling of caches.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json b/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json index 8bd0b38990b..4753bb2bbda 100644 --- a/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json +++ b/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6xj5-r9h7-wphq", - "modified": "2025-04-10T15:31:43Z", + "modified": "2025-04-11T18:30:41Z", "published": "2025-04-01T18:30:53Z", "aliases": [ "CVE-2025-21957" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla1280: Fix kernel oops when debug level > 2\n\nA null dereference or oops exception will eventually occur when qla1280.c\ndriver is compiled with DEBUG_QLA1280 enabled and ql_debug_level > 2. I\nthink its clear from the code that the intention here is sg_dma_len(s) not\nlength of sg_next(s) when printing the debug info.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8mfv-756x-xchg/GHSA-8mfv-756x-xchg.json b/advisories/unreviewed/2025/04/GHSA-8mfv-756x-xchg/GHSA-8mfv-756x-xchg.json new file mode 100644 index 00000000000..3aa5c905107 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8mfv-756x-xchg/GHSA-8mfv-756x-xchg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mfv-756x-xchg", + "modified": "2025-04-11T18:31:07Z", + "published": "2025-04-11T18:31:07Z", + "aliases": [ + "CVE-2025-32069" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32069" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Ie969a8cfeab0d4457417773fa884e271968e5657" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T387691" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9j63-jqr8-fh2v/GHSA-9j63-jqr8-fh2v.json b/advisories/unreviewed/2025/04/GHSA-9j63-jqr8-fh2v/GHSA-9j63-jqr8-fh2v.json index 8baf417bded..2f1527bef9d 100644 --- a/advisories/unreviewed/2025/04/GHSA-9j63-jqr8-fh2v/GHSA-9j63-jqr8-fh2v.json +++ b/advisories/unreviewed/2025/04/GHSA-9j63-jqr8-fh2v/GHSA-9j63-jqr8-fh2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9j63-jqr8-fh2v", - "modified": "2025-04-10T15:31:47Z", + "modified": "2025-04-11T18:30:41Z", "published": "2025-04-07T15:31:12Z", "aliases": [ "CVE-2025-32366" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://lapis-sawfish-be3.notion.site/0-day-Comman-memory-Leak-190dc00d01d080688472d322c93c4340" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20250410130356/https://lapis-sawfish-be3.notion.site/0-day-Comman-memory-Leak-190dc00d01d080688472d322c93c4340" + }, { "type": "WEB", "url": "https://web.git.kernel.org/pub/scm/network/connman/connman.git/tree/src/dnsproxy.c?h=1.44#n1001" diff --git a/advisories/unreviewed/2025/04/GHSA-9v4c-q3xh-jx9r/GHSA-9v4c-q3xh-jx9r.json b/advisories/unreviewed/2025/04/GHSA-9v4c-q3xh-jx9r/GHSA-9v4c-q3xh-jx9r.json new file mode 100644 index 00000000000..255cf468d32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9v4c-q3xh-jx9r/GHSA-9v4c-q3xh-jx9r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v4c-q3xh-jx9r", + "modified": "2025-04-11T18:31:06Z", + "published": "2025-04-11T18:31:06Z", + "aliases": [ + "CVE-2025-31935" + ], + "details": "Subnet Solutions \n\nPowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31935" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json b/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json index 6dcf86ddb82..264562726f1 100644 --- a/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json +++ b/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9v5v-qfv2-66qp", - "modified": "2025-04-11T15:32:30Z", + "modified": "2025-04-11T18:31:05Z", "published": "2025-04-11T15:32:30Z", "aliases": [ "CVE-2023-42970" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json b/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json index a1d0e6e07d5..6290e2ff1c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json +++ b/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cmwf-4hcv-45rc", - "modified": "2025-04-11T15:32:31Z", + "modified": "2025-04-11T18:31:05Z", "published": "2025-04-11T15:32:31Z", "aliases": [ "CVE-2023-42973" ], "details": "Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cr5h-9jcq-9f6f/GHSA-cr5h-9jcq-9f6f.json b/advisories/unreviewed/2025/04/GHSA-cr5h-9jcq-9f6f/GHSA-cr5h-9jcq-9f6f.json new file mode 100644 index 00000000000..e5880bcdd47 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cr5h-9jcq-9f6f/GHSA-cr5h-9jcq-9f6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr5h-9jcq-9f6f", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32079" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments allows HTTP DoS.This issue affects Mediawiki - GrowthExperiments: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32079" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/GrowthExperiments/+/1114020" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T384244" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc6v-27mr-w8pc/GHSA-fc6v-27mr-w8pc.json b/advisories/unreviewed/2025/04/GHSA-fc6v-27mr-w8pc/GHSA-fc6v-27mr-w8pc.json new file mode 100644 index 00000000000..e9cd1d4bc06 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc6v-27mr-w8pc/GHSA-fc6v-27mr-w8pc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc6v-27mr-w8pc", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32078" + ], + "details": "Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Version Compare Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32078" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/If901b3b98e615e1a4f4034d932d2d592000b51d0" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T384269" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json b/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json index 3f8018fc85a..2e7a4cc62ea 100644 --- a/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json +++ b/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fc78-895f-8fh8", - "modified": "2025-04-11T15:32:31Z", + "modified": "2025-04-11T18:31:06Z", "published": "2025-04-11T15:32:31Z", "aliases": [ "CVE-2023-42981" ], "details": "Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-grw4-4pm5-246x/GHSA-grw4-4pm5-246x.json b/advisories/unreviewed/2025/04/GHSA-grw4-4pm5-246x/GHSA-grw4-4pm5-246x.json new file mode 100644 index 00000000000..47f07ec5a19 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-grw4-4pm5-246x/GHSA-grw4-4pm5-246x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grw4-4pm5-246x", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32076" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Visual Data Extension allows HTTP DoS.This issue affects Mediawiki - Visual Data Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32076" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/VisualData/+/1121732" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T385935" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h4wc-9444-frmv/GHSA-h4wc-9444-frmv.json b/advisories/unreviewed/2025/04/GHSA-h4wc-9444-frmv/GHSA-h4wc-9444-frmv.json new file mode 100644 index 00000000000..5c28342fcc1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h4wc-9444-frmv/GHSA-h4wc-9444-frmv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4wc-9444-frmv", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32077" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Extension:SimpleCalendar allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Extension:SimpleCalendar: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32077" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Ic5b5ce8f7791026eff1aafffb32a68f3aab119be" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T383472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json b/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json index bcbd14a4ea4..ee2e661ba98 100644 --- a/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json +++ b/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j97h-5fwv-4rhj", - "modified": "2025-04-01T18:30:52Z", + "modified": "2025-04-11T18:30:41Z", "published": "2025-04-01T18:30:52Z", "aliases": [ "CVE-2025-21953" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: cleanup mana struct after debugfs_remove()\n\nWhen on a MANA VM hibernation is triggered, as part of hibernate_snapshot(),\nmana_gd_suspend() and mana_gd_resume() are called. If during this\nmana_gd_resume(), a failure occurs with HWC creation, mana_port_debugfs\npointer does not get reinitialized and ends up pointing to older,\ncleaned-up dentry.\nFurther in the hibernation path, as part of power_down(), mana_gd_shutdown()\nis triggered. This call, unaware of the failures in resume, tries to cleanup\nthe already cleaned up mana_port_debugfs value and hits the following bug:\n\n[ 191.359296] mana 7870:00:00.0: Shutdown was called\n[ 191.359918] BUG: kernel NULL pointer dereference, address: 0000000000000098\n[ 191.360584] #PF: supervisor write access in kernel mode\n[ 191.361125] #PF: error_code(0x0002) - not-present page\n[ 191.361727] PGD 1080ea067 P4D 0\n[ 191.362172] Oops: Oops: 0002 [#1] SMP NOPTI\n[ 191.362606] CPU: 11 UID: 0 PID: 1674 Comm: bash Not tainted 6.14.0-rc5+ #2\n[ 191.363292] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 11/21/2024\n[ 191.364124] RIP: 0010:down_write+0x19/0x50\n[ 191.364537] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 00 00 55 48 89 e5 53 48 89 fb e8 de cd ff ff 31 c0 ba 01 00 00 00 48 0f b1 13 75 16 65 48 8b 05 88 24 4c 6a 48 89 43 08 48 8b 5d\n[ 191.365867] RSP: 0000:ff45fbe0c1c037b8 EFLAGS: 00010246\n[ 191.366350] RAX: 0000000000000000 RBX: 0000000000000098 RCX: ffffff8100000000\n[ 191.366951] RDX: 0000000000000001 RSI: 0000000000000064 RDI: 0000000000000098\n[ 191.367600] RBP: ff45fbe0c1c037c0 R08: 0000000000000000 R09: 0000000000000001\n[ 191.368225] R10: ff45fbe0d2b01000 R11: 0000000000000008 R12: 0000000000000000\n[ 191.368874] R13: 000000000000000b R14: ff43dc27509d67c0 R15: 0000000000000020\n[ 191.369549] FS: 00007dbc5001e740(0000) GS:ff43dc663f380000(0000) knlGS:0000000000000000\n[ 191.370213] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 191.370830] CR2: 0000000000000098 CR3: 0000000168e8e002 CR4: 0000000000b73ef0\n[ 191.371557] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 191.372192] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 191.372906] Call Trace:\n[ 191.373262] \n[ 191.373621] ? show_regs+0x64/0x70\n[ 191.374040] ? __die+0x24/0x70\n[ 191.374468] ? page_fault_oops+0x290/0x5b0\n[ 191.374875] ? do_user_addr_fault+0x448/0x800\n[ 191.375357] ? exc_page_fault+0x7a/0x160\n[ 191.375971] ? asm_exc_page_fault+0x27/0x30\n[ 191.376416] ? down_write+0x19/0x50\n[ 191.376832] ? down_write+0x12/0x50\n[ 191.377232] simple_recursive_removal+0x4a/0x2a0\n[ 191.377679] ? __pfx_remove_one+0x10/0x10\n[ 191.378088] debugfs_remove+0x44/0x70\n[ 191.378530] mana_detach+0x17c/0x4f0\n[ 191.378950] ? __flush_work+0x1e2/0x3b0\n[ 191.379362] ? __cond_resched+0x1a/0x50\n[ 191.379787] mana_remove+0xf2/0x1a0\n[ 191.380193] mana_gd_shutdown+0x3b/0x70\n[ 191.380642] pci_device_shutdown+0x3a/0x80\n[ 191.381063] device_shutdown+0x13e/0x230\n[ 191.381480] kernel_power_off+0x35/0x80\n[ 191.381890] hibernate+0x3c6/0x470\n[ 191.382312] state_store+0xcb/0xd0\n[ 191.382734] kobj_attr_store+0x12/0x30\n[ 191.383211] sysfs_kf_write+0x3e/0x50\n[ 191.383640] kernfs_fop_write_iter+0x140/0x1d0\n[ 191.384106] vfs_write+0x271/0x440\n[ 191.384521] ksys_write+0x72/0xf0\n[ 191.384924] __x64_sys_write+0x19/0x20\n[ 191.385313] x64_sys_call+0x2b0/0x20b0\n[ 191.385736] do_syscall_64+0x79/0x150\n[ 191.386146] ? __mod_memcg_lruvec_state+0xe7/0x240\n[ 191.386676] ? __lruvec_stat_mod_folio+0x79/0xb0\n[ 191.387124] ? __pfx_lru_add+0x10/0x10\n[ 191.387515] ? queued_spin_unlock+0x9/0x10\n[ 191.387937] ? do_anonymous_page+0x33c/0xa00\n[ 191.388374] ? __handle_mm_fault+0xcf3/0x1210\n[ 191.388805] ? __count_memcg_events+0xbe/0x180\n[ 191.389235] ? handle_mm_fault+0xae/0x300\n[ 19\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json b/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json index a6e7e7a28ba..0fb001bca95 100644 --- a/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json +++ b/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m6p7-g6ff-wxw5", - "modified": "2025-04-11T15:32:31Z", + "modified": "2025-04-11T18:31:06Z", "published": "2025-04-11T15:32:31Z", "aliases": [ "CVE-2023-42977" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:45Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p288-3mcf-2f3w/GHSA-p288-3mcf-2f3w.json b/advisories/unreviewed/2025/04/GHSA-p288-3mcf-2f3w/GHSA-p288-3mcf-2f3w.json new file mode 100644 index 00000000000..a0a6505cf54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p288-3mcf-2f3w/GHSA-p288-3mcf-2f3w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p288-3mcf-2f3w", + "modified": "2025-04-11T18:31:06Z", + "published": "2025-04-11T18:31:06Z", + "aliases": [ + "CVE-2025-31354" + ], + "details": "Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31354" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json b/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json index 4b0bc1db834..ff120c65a34 100644 --- a/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json +++ b/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pmvp-2f47-m6wx", - "modified": "2025-04-11T15:32:30Z", + "modified": "2025-04-11T18:31:05Z", "published": "2025-04-11T15:32:30Z", "aliases": [ "CVE-2023-41076" ], "details": "An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-11T15:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-prqg-f9gx-75qh/GHSA-prqg-f9gx-75qh.json b/advisories/unreviewed/2025/04/GHSA-prqg-f9gx-75qh/GHSA-prqg-f9gx-75qh.json new file mode 100644 index 00000000000..a418c278817 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-prqg-f9gx-75qh/GHSA-prqg-f9gx-75qh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prqg-f9gx-75qh", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32074" + ], + "details": "Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Confirm Account Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32074" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I86f47103ffb78c671890b44ccd59fcff6613975f" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T386908" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r5vx-68x4-4jcf/GHSA-r5vx-68x4-4jcf.json b/advisories/unreviewed/2025/04/GHSA-r5vx-68x4-4jcf/GHSA-r5vx-68x4-4jcf.json new file mode 100644 index 00000000000..65989834213 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r5vx-68x4-4jcf/GHSA-r5vx-68x4-4jcf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5vx-68x4-4jcf", + "modified": "2025-04-11T18:31:07Z", + "published": "2025-04-11T18:31:07Z", + "aliases": [ + "CVE-2025-32072" + ], + "details": "Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32072" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1120134" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T386175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r65j-4h86-f5h7/GHSA-r65j-4h86-f5h7.json b/advisories/unreviewed/2025/04/GHSA-r65j-4h86-f5h7/GHSA-r65j-4h86-f5h7.json new file mode 100644 index 00000000000..ad6dbc84720 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r65j-4h86-f5h7/GHSA-r65j-4h86-f5h7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r65j-4h86-f5h7", + "modified": "2025-04-11T18:31:07Z", + "published": "2025-04-11T18:31:07Z", + "aliases": [ + "CVE-2025-32070" + ], + "details": "Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - AJAX Poll Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - AJAX Poll Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32070" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Ib59c59b2cd36928ab200149c851e2bfcf5cf920c" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T389590" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vrgf-xjqc-rwfc/GHSA-vrgf-xjqc-rwfc.json b/advisories/unreviewed/2025/04/GHSA-vrgf-xjqc-rwfc/GHSA-vrgf-xjqc-rwfc.json new file mode 100644 index 00000000000..eca0ef51b0c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vrgf-xjqc-rwfc/GHSA-vrgf-xjqc-rwfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrgf-xjqc-rwfc", + "modified": "2025-04-11T18:31:09Z", + "published": "2025-04-11T18:31:09Z", + "aliases": [ + "CVE-2025-0119" + ], + "details": "A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0119" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wv3j-j89q-mvh8/GHSA-wv3j-j89q-mvh8.json b/advisories/unreviewed/2025/04/GHSA-wv3j-j89q-mvh8/GHSA-wv3j-j89q-mvh8.json new file mode 100644 index 00000000000..676af7282d2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wv3j-j89q-mvh8/GHSA-wv3j-j89q-mvh8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv3j-j89q-mvh8", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32367" + ], + "details": "The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object Reference. NOTE: the number 4.0.8 was used for both the unpatched and patched versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32367" + }, + { + "type": "WEB", + "url": "https://medium.com/@antonsimonyan7/idor-in-oz-forensics-face-recognition-application-cve-2025-32367-53684ee312ea" + }, + { + "type": "WEB", + "url": "https://ozforensics.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmr2-c47x-rm4p/GHSA-xmr2-c47x-rm4p.json b/advisories/unreviewed/2025/04/GHSA-xmr2-c47x-rm4p/GHSA-xmr2-c47x-rm4p.json new file mode 100644 index 00000000000..f5298a854e7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xmr2-c47x-rm4p/GHSA-xmr2-c47x-rm4p.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmr2-c47x-rm4p", + "modified": "2025-04-11T18:31:08Z", + "published": "2025-04-11T18:31:08Z", + "aliases": [ + "CVE-2025-32080" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Shared Resource Manipulation.This issue affects Mediawiki - Mobile Frontend Extension: from 1.39 through 1.43.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32080" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/c/mediawiki/extensions/MobileFrontend/+/1123392" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/Ia5c3be79db37240acbaa630834e430ec3147e61c" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T366402" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T17:15:44Z" + } +} \ No newline at end of file