From 3cb7bc79b10e8bcf6929c95ce714e7f588e1991e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 21 Jan 2025 18:31:35 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-23qq-p4gq-gc2g/GHSA-23qq-p4gq-gc2g.json | 6 +++++- .../GHSA-qmjf-wc2h-6x3q/GHSA-qmjf-wc2h-6x3q.json | 6 +++++- .../GHSA-9x88-4jg8-4vf7/GHSA-9x88-4jg8-4vf7.json | 6 +++++- .../GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json | 6 +++++- .../GHSA-vwgf-7f9h-h499/GHSA-vwgf-7f9h-h499.json | 6 +++++- .../GHSA-r3jq-4r5c-j9hp/GHSA-r3jq-4r5c-j9hp.json | 6 +++++- .../GHSA-cg87-wmx4-v546/GHSA-cg87-wmx4-v546.json | 8 ++++++-- .../GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json | 12 +++++++++--- .../GHSA-24xr-jc8x-c65v/GHSA-24xr-jc8x-c65v.json | 13 ++++++++++--- .../GHSA-2vw2-h5mp-gfhw/GHSA-2vw2-h5mp-gfhw.json | 2 +- .../GHSA-2wgx-r6j7-j62r/GHSA-2wgx-r6j7-j62r.json | 13 ++++++++++--- .../GHSA-33xc-j7q8-qcjm/GHSA-33xc-j7q8-qcjm.json | 13 ++++++++++--- .../GHSA-6fvg-8hhr-r65p/GHSA-6fvg-8hhr-r65p.json | 12 +++++++++--- .../GHSA-74cx-pw34-jqwr/GHSA-74cx-pw34-jqwr.json | 9 +++++++-- .../GHSA-7967-3g5v-3pfc/GHSA-7967-3g5v-3pfc.json | 9 +++++++-- .../GHSA-7w6f-prr7-wp9h/GHSA-7w6f-prr7-wp9h.json | 9 +++++++-- .../GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json | 9 +++++++-- .../GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json | 9 +++++++-- .../GHSA-9c2j-5jrv-c2w9/GHSA-9c2j-5jrv-c2w9.json | 9 +++++++-- .../GHSA-c63x-h9v9-hmcr/GHSA-c63x-h9v9-hmcr.json | 13 ++++++++++--- .../GHSA-c68r-4jrw-42vq/GHSA-c68r-4jrw-42vq.json | 9 +++++++-- .../GHSA-cm3v-7fgr-4cc4/GHSA-cm3v-7fgr-4cc4.json | 13 ++++++++++--- .../GHSA-cr8p-vp27-f6rh/GHSA-cr8p-vp27-f6rh.json | 9 +++++++-- .../GHSA-h2v2-wmf8-gvvv/GHSA-h2v2-wmf8-gvvv.json | 13 ++++++++++--- .../GHSA-h9cc-4rm6-chr3/GHSA-h9cc-4rm6-chr3.json | 9 +++++++-- .../GHSA-hvf6-hpg3-c749/GHSA-hvf6-hpg3-c749.json | 9 +++++++-- .../GHSA-q32m-8w96-wchw/GHSA-q32m-8w96-wchw.json | 9 +++++++-- .../GHSA-qmr8-gx65-85gx/GHSA-qmr8-gx65-85gx.json | 9 +++++++-- .../GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json | 9 +++++++-- .../GHSA-rpc4-j585-wg54/GHSA-rpc4-j585-wg54.json | 13 ++++++++++--- .../GHSA-rpp3-6c33-vw2f/GHSA-rpp3-6c33-vw2f.json | 9 +++++++-- .../GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json | 9 +++++++-- .../GHSA-wfv6-vr6v-73h2/GHSA-wfv6-vr6v-73h2.json | 9 +++++++-- .../GHSA-wpx6-2rpm-7rx4/GHSA-wpx6-2rpm-7rx4.json | 13 ++++++++++--- .../GHSA-x3v7-899j-3p69/GHSA-x3v7-899j-3p69.json | 9 +++++++-- .../GHSA-x8j8-qwww-5jwf/GHSA-x8j8-qwww-5jwf.json | 13 ++++++++++--- .../GHSA-xm68-4v8h-h9rf/GHSA-xm68-4v8h-h9rf.json | 10 ++++++++-- .../GHSA-hxm4-2wfq-fq5q/GHSA-hxm4-2wfq-fq5q.json | 4 +++- .../GHSA-pw44-h9q2-jw5p/GHSA-pw44-h9q2-jw5p.json | 3 ++- .../GHSA-9c57-j536-h7mm/GHSA-9c57-j536-h7mm.json | 15 +++++++++++---- .../GHSA-7m64-7mmv-p9hm/GHSA-7m64-7mmv-p9hm.json | 15 +++++++++++---- .../GHSA-86vf-v4p3-jf4g/GHSA-86vf-v4p3-jf4g.json | 6 ++++-- .../GHSA-8xvw-38qv-7f9f/GHSA-8xvw-38qv-7f9f.json | 4 +++- .../GHSA-cmx8-2m2f-ggxf/GHSA-cmx8-2m2f-ggxf.json | 4 +++- .../GHSA-r9jp-3v2v-qr5m/GHSA-r9jp-3v2v-qr5m.json | 4 +++- .../GHSA-vqc4-wfj3-2mr7/GHSA-vqc4-wfj3-2mr7.json | 4 +++- .../GHSA-343c-q42r-xrgp/GHSA-343c-q42r-xrgp.json | 3 ++- .../GHSA-3v43-hgv9-g7jj/GHSA-3v43-hgv9-g7jj.json | 3 ++- .../GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json | 11 ++++++++--- .../GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json | 3 ++- .../GHSA-6qpc-4p3x-g9p3/GHSA-6qpc-4p3x-g9p3.json | 3 ++- .../GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json | 3 ++- .../GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json | 5 +++-- .../GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json | 2 +- .../GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json | 2 +- .../GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json | 2 +- .../GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json | 2 +- .../GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json | 2 +- .../GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json | 2 +- .../GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json | 5 +++-- .../GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json | 2 +- 61 files changed, 346 insertions(+), 113 deletions(-) diff --git a/advisories/github-reviewed/2024/05/GHSA-23qq-p4gq-gc2g/GHSA-23qq-p4gq-gc2g.json b/advisories/github-reviewed/2024/05/GHSA-23qq-p4gq-gc2g/GHSA-23qq-p4gq-gc2g.json index abecc826792..7598d03798d 100644 --- a/advisories/github-reviewed/2024/05/GHSA-23qq-p4gq-gc2g/GHSA-23qq-p4gq-gc2g.json +++ b/advisories/github-reviewed/2024/05/GHSA-23qq-p4gq-gc2g/GHSA-23qq-p4gq-gc2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23qq-p4gq-gc2g", - "modified": "2024-11-01T21:41:21Z", + "modified": "2025-01-21T18:28:26Z", "published": "2024-05-06T00:30:52Z", "aliases": [ "CVE-2024-34528" @@ -59,6 +59,10 @@ { "type": "WEB", "url": "https://github.com/WordOps/WordOps/blob/ecf20192c7853925e2cb3f8c8378cd0d86ca0d62/wo/cli/plugins/stack_pref.py#L77" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/wordops/PYSEC-2024-175.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/05/GHSA-qmjf-wc2h-6x3q/GHSA-qmjf-wc2h-6x3q.json b/advisories/github-reviewed/2024/05/GHSA-qmjf-wc2h-6x3q/GHSA-qmjf-wc2h-6x3q.json index c09886c9395..055c9000cc6 100644 --- a/advisories/github-reviewed/2024/05/GHSA-qmjf-wc2h-6x3q/GHSA-qmjf-wc2h-6x3q.json +++ b/advisories/github-reviewed/2024/05/GHSA-qmjf-wc2h-6x3q/GHSA-qmjf-wc2h-6x3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmjf-wc2h-6x3q", - "modified": "2024-05-29T18:40:56Z", + "modified": "2025-01-21T18:30:41Z", "published": "2024-05-29T18:40:56Z", "aliases": [ "CVE-2024-36112" @@ -82,6 +82,10 @@ { "type": "PACKAGE", "url": "https://github.com/nautobot/nautobot" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/nautobot/PYSEC-2024-166.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/06/GHSA-9x88-4jg8-4vf7/GHSA-9x88-4jg8-4vf7.json b/advisories/github-reviewed/2024/06/GHSA-9x88-4jg8-4vf7/GHSA-9x88-4jg8-4vf7.json index e995fca31e5..8e7b3b1e59f 100644 --- a/advisories/github-reviewed/2024/06/GHSA-9x88-4jg8-4vf7/GHSA-9x88-4jg8-4vf7.json +++ b/advisories/github-reviewed/2024/06/GHSA-9x88-4jg8-4vf7/GHSA-9x88-4jg8-4vf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9x88-4jg8-4vf7", - "modified": "2024-06-06T22:21:21Z", + "modified": "2025-01-21T18:29:12Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-2035" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/zenml-io/zenml/commit/b95f083efffa56831cd41d8ed536aeb0b6038fa3" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zenml/PYSEC-2024-169.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/zenml-io/zenml" diff --git a/advisories/github-reviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json b/advisories/github-reviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json index b65a9f91dac..bf1d1ff6347 100644 --- a/advisories/github-reviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json +++ b/advisories/github-reviewed/2024/06/GHSA-cgvx-9447-vcch/GHSA-cgvx-9447-vcch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvx-9447-vcch", - "modified": "2024-08-26T19:13:46Z", + "modified": "2025-01-21T18:28:57Z", "published": "2024-06-28T00:33:31Z", "aliases": [ "CVE-2024-39705" @@ -60,6 +60,10 @@ "type": "PACKAGE", "url": "https://github.com/nltk/nltk" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2024-167.yaml" + }, { "type": "WEB", "url": "https://www.vicarius.io/vsociety/posts/rce-in-python-nltk-cve-2024-39705-39706" diff --git a/advisories/github-reviewed/2024/06/GHSA-vwgf-7f9h-h499/GHSA-vwgf-7f9h-h499.json b/advisories/github-reviewed/2024/06/GHSA-vwgf-7f9h-h499/GHSA-vwgf-7f9h-h499.json index ee876e5ba62..62ffd231c31 100644 --- a/advisories/github-reviewed/2024/06/GHSA-vwgf-7f9h-h499/GHSA-vwgf-7f9h-h499.json +++ b/advisories/github-reviewed/2024/06/GHSA-vwgf-7f9h-h499/GHSA-vwgf-7f9h-h499.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwgf-7f9h-h499", - "modified": "2024-10-11T16:30:36Z", + "modified": "2025-01-21T18:29:05Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-2171" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/zenml-io/zenml/commit/68bcb3ba60cba9729c9713a49c39502d40fb945e" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zenml/PYSEC-2024-170.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/zenml-io/zenml" diff --git a/advisories/github-reviewed/2024/08/GHSA-r3jq-4r5c-j9hp/GHSA-r3jq-4r5c-j9hp.json b/advisories/github-reviewed/2024/08/GHSA-r3jq-4r5c-j9hp/GHSA-r3jq-4r5c-j9hp.json index 8430bd1fdb6..70f1a81591d 100644 --- a/advisories/github-reviewed/2024/08/GHSA-r3jq-4r5c-j9hp/GHSA-r3jq-4r5c-j9hp.json +++ b/advisories/github-reviewed/2024/08/GHSA-r3jq-4r5c-j9hp/GHSA-r3jq-4r5c-j9hp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r3jq-4r5c-j9hp", - "modified": "2024-10-16T19:32:14Z", + "modified": "2025-01-21T18:28:45Z", "published": "2024-08-27T19:50:59Z", "aliases": [ "CVE-2024-47833" @@ -58,6 +58,10 @@ { "type": "WEB", "url": "https://github.com/Avaiga/taipy/blob/develop/frontend/taipy-gui/src/components/Taipy/Navigate.tsx#L67" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/taipy/PYSEC-2024-168.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2025/01/GHSA-cg87-wmx4-v546/GHSA-cg87-wmx4-v546.json b/advisories/github-reviewed/2025/01/GHSA-cg87-wmx4-v546/GHSA-cg87-wmx4-v546.json index 8c8998f2fc3..beeb80c9c6c 100644 --- a/advisories/github-reviewed/2025/01/GHSA-cg87-wmx4-v546/GHSA-cg87-wmx4-v546.json +++ b/advisories/github-reviewed/2025/01/GHSA-cg87-wmx4-v546/GHSA-cg87-wmx4-v546.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg87-wmx4-v546", - "modified": "2025-01-17T21:22:57Z", + "modified": "2025-01-21T18:31:02Z", "published": "2025-01-17T21:22:56Z", "aliases": [ "CVE-2025-23207" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/KaTeX/KaTeX/security/advisories/GHSA-cg87-wmx4-v546" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23207" + }, { "type": "WEB", "url": "https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c" @@ -59,6 +63,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-17T21:22:56Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-17T22:15:29Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json b/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json index 9800807e756..11c1e3a11fc 100644 --- a/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json +++ b/advisories/unreviewed/2022/05/GHSA-24fj-8422-2v9w/GHSA-24fj-8422-2v9w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24fj-8422-2v9w", - "modified": "2022-05-02T03:36:00Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:36:00Z", "aliases": [ "CVE-2009-2516" ], "details": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka \"Windows Kernel NULL Pointer Dereference Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-24xr-jc8x-c65v/GHSA-24xr-jc8x-c65v.json b/advisories/unreviewed/2022/05/GHSA-24xr-jc8x-c65v/GHSA-24xr-jc8x-c65v.json index 64be96da8fa..5a47c1362bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-24xr-jc8x-c65v/GHSA-24xr-jc8x-c65v.json +++ b/advisories/unreviewed/2022/05/GHSA-24xr-jc8x-c65v/GHSA-24xr-jc8x-c65v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24xr-jc8x-c65v", - "modified": "2022-05-14T01:31:29Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-14T01:31:29Z", "aliases": [ "CVE-2010-1883" ], "details": "Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka \"Embedded OpenType Font Integer Overflow Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-2vw2-h5mp-gfhw/GHSA-2vw2-h5mp-gfhw.json b/advisories/unreviewed/2022/05/GHSA-2vw2-h5mp-gfhw/GHSA-2vw2-h5mp-gfhw.json index 253d99509e0..25e22e69be0 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vw2-h5mp-gfhw/GHSA-2vw2-h5mp-gfhw.json +++ b/advisories/unreviewed/2022/05/GHSA-2vw2-h5mp-gfhw/GHSA-2vw2-h5mp-gfhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vw2-h5mp-gfhw", - "modified": "2024-02-02T18:30:21Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:35:01Z", "aliases": [ "CVE-2009-2416" diff --git a/advisories/unreviewed/2022/05/GHSA-2wgx-r6j7-j62r/GHSA-2wgx-r6j7-j62r.json b/advisories/unreviewed/2022/05/GHSA-2wgx-r6j7-j62r/GHSA-2wgx-r6j7-j62r.json index d611f15ff93..1b8aecaf31f 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wgx-r6j7-j62r/GHSA-2wgx-r6j7-j62r.json +++ b/advisories/unreviewed/2022/05/GHSA-2wgx-r6j7-j62r/GHSA-2wgx-r6j7-j62r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wgx-r6j7-j62r", - "modified": "2022-05-02T06:13:03Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T06:13:03Z", "aliases": [ "CVE-2010-0481" ], "details": "The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka \"Windows Virtual Path Parsing Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-33xc-j7q8-qcjm/GHSA-33xc-j7q8-qcjm.json b/advisories/unreviewed/2022/05/GHSA-33xc-j7q8-qcjm/GHSA-33xc-j7q8-qcjm.json index 6c01483144a..5e71c889fa9 100644 --- a/advisories/unreviewed/2022/05/GHSA-33xc-j7q8-qcjm/GHSA-33xc-j7q8-qcjm.json +++ b/advisories/unreviewed/2022/05/GHSA-33xc-j7q8-qcjm/GHSA-33xc-j7q8-qcjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-33xc-j7q8-qcjm", - "modified": "2022-05-13T01:15:32Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:15:32Z", "aliases": [ "CVE-2011-1887" ], "details": "win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka \"Win32k Null Pointer De-reference Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-6fvg-8hhr-r65p/GHSA-6fvg-8hhr-r65p.json b/advisories/unreviewed/2022/05/GHSA-6fvg-8hhr-r65p/GHSA-6fvg-8hhr-r65p.json index 99263dfef2c..b4e561f42b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-6fvg-8hhr-r65p/GHSA-6fvg-8hhr-r65p.json +++ b/advisories/unreviewed/2022/05/GHSA-6fvg-8hhr-r65p/GHSA-6fvg-8hhr-r65p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6fvg-8hhr-r65p", - "modified": "2022-05-02T06:13:05Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-02T06:13:05Z", "aliases": [ "CVE-2010-0488" ], "details": "Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified \"encoding strings,\" which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka \"Post Encoding Information Disclosure Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -53,7 +58,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-74cx-pw34-jqwr/GHSA-74cx-pw34-jqwr.json b/advisories/unreviewed/2022/05/GHSA-74cx-pw34-jqwr/GHSA-74cx-pw34-jqwr.json index 2a0ad21d90c..8d7e6ca6b7d 100644 --- a/advisories/unreviewed/2022/05/GHSA-74cx-pw34-jqwr/GHSA-74cx-pw34-jqwr.json +++ b/advisories/unreviewed/2022/05/GHSA-74cx-pw34-jqwr/GHSA-74cx-pw34-jqwr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-74cx-pw34-jqwr", - "modified": "2022-05-02T03:12:58Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:12:58Z", "aliases": [ "CVE-2009-0130" ], "details": "** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus \"this report is invalid.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-7967-3g5v-3pfc/GHSA-7967-3g5v-3pfc.json b/advisories/unreviewed/2022/05/GHSA-7967-3g5v-3pfc/GHSA-7967-3g5v-3pfc.json index 73557acb44e..eec8c00f402 100644 --- a/advisories/unreviewed/2022/05/GHSA-7967-3g5v-3pfc/GHSA-7967-3g5v-3pfc.json +++ b/advisories/unreviewed/2022/05/GHSA-7967-3g5v-3pfc/GHSA-7967-3g5v-3pfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7967-3g5v-3pfc", - "modified": "2022-05-02T06:09:45Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T06:09:45Z", "aliases": [ "CVE-2010-0021" ], "details": "Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka \"SMB Memory Corruption Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-7w6f-prr7-wp9h/GHSA-7w6f-prr7-wp9h.json b/advisories/unreviewed/2022/05/GHSA-7w6f-prr7-wp9h/GHSA-7w6f-prr7-wp9h.json index 88f920931f3..90022a4d961 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w6f-prr7-wp9h/GHSA-7w6f-prr7-wp9h.json +++ b/advisories/unreviewed/2022/05/GHSA-7w6f-prr7-wp9h/GHSA-7w6f-prr7-wp9h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7w6f-prr7-wp9h", - "modified": "2022-05-14T02:13:17Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-14T02:13:17Z", "aliases": [ "CVE-2010-2554" ], "details": "The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka \"Tracing Registry Key ACL Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json b/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json index 2501edccff4..74066f4d31c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json +++ b/advisories/unreviewed/2022/05/GHSA-8v76-643q-v8h8/GHSA-8v76-643q-v8h8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8v76-643q-v8h8", - "modified": "2024-03-21T03:33:03Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-17T05:36:53Z", "aliases": [ "CVE-2011-0736" ], "details": "** DISPUTED ** Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json b/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json index 261c6b4d41d..01fb8c2cf18 100644 --- a/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json +++ b/advisories/unreviewed/2022/05/GHSA-8vq2-fxxp-56hm/GHSA-8vq2-fxxp-56hm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vq2-fxxp-56hm", - "modified": "2022-05-02T03:35:59Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:35:59Z", "aliases": [ "CVE-2009-2512" ], "details": "The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka \"Web Services on Devices API Memory Corruption Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-9c2j-5jrv-c2w9/GHSA-9c2j-5jrv-c2w9.json b/advisories/unreviewed/2022/05/GHSA-9c2j-5jrv-c2w9/GHSA-9c2j-5jrv-c2w9.json index 2835606655b..611dad20688 100644 --- a/advisories/unreviewed/2022/05/GHSA-9c2j-5jrv-c2w9/GHSA-9c2j-5jrv-c2w9.json +++ b/advisories/unreviewed/2022/05/GHSA-9c2j-5jrv-c2w9/GHSA-9c2j-5jrv-c2w9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9c2j-5jrv-c2w9", - "modified": "2022-05-14T02:36:48Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-14T02:36:48Z", "aliases": [ "CVE-2010-1889" ], "details": "Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka \"Windows Kernel Double Free Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-c63x-h9v9-hmcr/GHSA-c63x-h9v9-hmcr.json b/advisories/unreviewed/2022/05/GHSA-c63x-h9v9-hmcr/GHSA-c63x-h9v9-hmcr.json index 679d633c3ef..8e61961a29d 100644 --- a/advisories/unreviewed/2022/05/GHSA-c63x-h9v9-hmcr/GHSA-c63x-h9v9-hmcr.json +++ b/advisories/unreviewed/2022/05/GHSA-c63x-h9v9-hmcr/GHSA-c63x-h9v9-hmcr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c63x-h9v9-hmcr", - "modified": "2022-05-13T01:15:25Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:15:25Z", "aliases": [ "CVE-2011-0663" ], "details": "Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a crafted web page, aka \"Scripting Memory Reallocation Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-c68r-4jrw-42vq/GHSA-c68r-4jrw-42vq.json b/advisories/unreviewed/2022/05/GHSA-c68r-4jrw-42vq/GHSA-c68r-4jrw-42vq.json index 26009191ef0..5c0c03ae7a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-c68r-4jrw-42vq/GHSA-c68r-4jrw-42vq.json +++ b/advisories/unreviewed/2022/05/GHSA-c68r-4jrw-42vq/GHSA-c68r-4jrw-42vq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c68r-4jrw-42vq", - "modified": "2022-05-14T01:32:13Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-14T01:32:13Z", "aliases": [ "CVE-2011-0096" ], "details": "The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka \"MHTML Mime-Formatted Request Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-cm3v-7fgr-4cc4/GHSA-cm3v-7fgr-4cc4.json b/advisories/unreviewed/2022/05/GHSA-cm3v-7fgr-4cc4/GHSA-cm3v-7fgr-4cc4.json index 866532fcd3a..92bfa988189 100644 --- a/advisories/unreviewed/2022/05/GHSA-cm3v-7fgr-4cc4/GHSA-cm3v-7fgr-4cc4.json +++ b/advisories/unreviewed/2022/05/GHSA-cm3v-7fgr-4cc4/GHSA-cm3v-7fgr-4cc4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cm3v-7fgr-4cc4", - "modified": "2022-05-13T01:15:34Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:15:34Z", "aliases": [ "CVE-2011-1985" ], "details": "win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka \"Win32k Null Pointer De-reference Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cr8p-vp27-f6rh/GHSA-cr8p-vp27-f6rh.json b/advisories/unreviewed/2022/05/GHSA-cr8p-vp27-f6rh/GHSA-cr8p-vp27-f6rh.json index b27c1a1edfd..b1b600cf978 100644 --- a/advisories/unreviewed/2022/05/GHSA-cr8p-vp27-f6rh/GHSA-cr8p-vp27-f6rh.json +++ b/advisories/unreviewed/2022/05/GHSA-cr8p-vp27-f6rh/GHSA-cr8p-vp27-f6rh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cr8p-vp27-f6rh", - "modified": "2022-05-02T03:42:30Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:42:30Z", "aliases": [ "CVE-2009-3168" ], "details": "Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-h2v2-wmf8-gvvv/GHSA-h2v2-wmf8-gvvv.json b/advisories/unreviewed/2022/05/GHSA-h2v2-wmf8-gvvv/GHSA-h2v2-wmf8-gvvv.json index 22e150baedc..84232e43618 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2v2-wmf8-gvvv/GHSA-h2v2-wmf8-gvvv.json +++ b/advisories/unreviewed/2022/05/GHSA-h2v2-wmf8-gvvv/GHSA-h2v2-wmf8-gvvv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h2v2-wmf8-gvvv", - "modified": "2022-05-13T01:15:26Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:15:26Z", "aliases": [ "CVE-2011-0676" ], "details": "win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other \"Vulnerability Type 2\" CVEs listed in MS11-034, aka \"Win32k Null Pointer De-reference Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -60,7 +65,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-h9cc-4rm6-chr3/GHSA-h9cc-4rm6-chr3.json b/advisories/unreviewed/2022/05/GHSA-h9cc-4rm6-chr3/GHSA-h9cc-4rm6-chr3.json index b0d1d79f2d4..12e0a6c3ca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-h9cc-4rm6-chr3/GHSA-h9cc-4rm6-chr3.json +++ b/advisories/unreviewed/2022/05/GHSA-h9cc-4rm6-chr3/GHSA-h9cc-4rm6-chr3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9cc-4rm6-chr3", - "modified": "2022-05-02T06:13:05Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T06:13:05Z", "aliases": [ "CVE-2010-0485" ], "details": "The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 \"do not properly validate all callback parameters when creating a new window,\" which allows local users to execute arbitrary code, aka \"Win32k Window Creation Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-hvf6-hpg3-c749/GHSA-hvf6-hpg3-c749.json b/advisories/unreviewed/2022/05/GHSA-hvf6-hpg3-c749/GHSA-hvf6-hpg3-c749.json index 934a9223017..4241650ac35 100644 --- a/advisories/unreviewed/2022/05/GHSA-hvf6-hpg3-c749/GHSA-hvf6-hpg3-c749.json +++ b/advisories/unreviewed/2022/05/GHSA-hvf6-hpg3-c749/GHSA-hvf6-hpg3-c749.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hvf6-hpg3-c749", - "modified": "2022-05-03T03:25:29Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-03T03:25:29Z", "aliases": [ "CVE-2011-0042" ], "details": "SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka \"DVR-MS Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-q32m-8w96-wchw/GHSA-q32m-8w96-wchw.json b/advisories/unreviewed/2022/05/GHSA-q32m-8w96-wchw/GHSA-q32m-8w96-wchw.json index 7069a45e438..5dca06ebf14 100644 --- a/advisories/unreviewed/2022/05/GHSA-q32m-8w96-wchw/GHSA-q32m-8w96-wchw.json +++ b/advisories/unreviewed/2022/05/GHSA-q32m-8w96-wchw/GHSA-q32m-8w96-wchw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q32m-8w96-wchw", - "modified": "2022-05-02T03:12:44Z", + "modified": "2025-01-21T18:30:59Z", "published": "2022-05-02T03:12:44Z", "aliases": [ "CVE-2009-0082" ], "details": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified \"actions,\" aka \"Windows Kernel Handle Validation Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-qmr8-gx65-85gx/GHSA-qmr8-gx65-85gx.json b/advisories/unreviewed/2022/05/GHSA-qmr8-gx65-85gx/GHSA-qmr8-gx65-85gx.json index 005a70c6934..8595aa84745 100644 --- a/advisories/unreviewed/2022/05/GHSA-qmr8-gx65-85gx/GHSA-qmr8-gx65-85gx.json +++ b/advisories/unreviewed/2022/05/GHSA-qmr8-gx65-85gx/GHSA-qmr8-gx65-85gx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qmr8-gx65-85gx", - "modified": "2022-05-02T03:26:05Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:26:05Z", "aliases": [ "CVE-2009-1532" ], "details": "Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via \"malformed row property references\" that trigger an access of an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"HTML Objects Memory Corruption Vulnerability\" or \"HTML Object Memory Corruption Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json b/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json index 3c20a50585c..c082db324c0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json +++ b/advisories/unreviewed/2022/05/GHSA-r9xq-fpxc-46xw/GHSA-r9xq-fpxc-46xw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r9xq-fpxc-46xw", - "modified": "2022-05-02T03:16:36Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:16:36Z", "aliases": [ "CVE-2009-0554" ], "details": "Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka \"Uninitialized Memory Corruption Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-rpc4-j585-wg54/GHSA-rpc4-j585-wg54.json b/advisories/unreviewed/2022/05/GHSA-rpc4-j585-wg54/GHSA-rpc4-j585-wg54.json index c8d4898e026..f487f8485d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpc4-j585-wg54/GHSA-rpc4-j585-wg54.json +++ b/advisories/unreviewed/2022/05/GHSA-rpc4-j585-wg54/GHSA-rpc4-j585-wg54.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rpc4-j585-wg54", - "modified": "2022-05-14T01:31:54Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-14T01:31:54Z", "aliases": [ "CVE-2010-3957" ], "details": "Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka \"OpenType Font Double Free Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-415" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rpp3-6c33-vw2f/GHSA-rpp3-6c33-vw2f.json b/advisories/unreviewed/2022/05/GHSA-rpp3-6c33-vw2f/GHSA-rpp3-6c33-vw2f.json index edb091d1b49..ed53fc4c5d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-rpp3-6c33-vw2f/GHSA-rpp3-6c33-vw2f.json +++ b/advisories/unreviewed/2022/05/GHSA-rpp3-6c33-vw2f/GHSA-rpp3-6c33-vw2f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rpp3-6c33-vw2f", - "modified": "2022-05-02T03:26:10Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:26:10Z", "aliases": [ "CVE-2009-1547" ], "details": "Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka \"Data Stream Header Corruption Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json b/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json index 49309166c66..b7e78fec586 100644 --- a/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json +++ b/advisories/unreviewed/2022/05/GHSA-vvv4-6xjg-7crg/GHSA-vvv4-6xjg-7crg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vvv4-6xjg-7crg", - "modified": "2022-05-02T03:35:49Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:35:49Z", "aliases": [ "CVE-2009-2494" ], "details": "The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka \"ATL Object Type Mismatch Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-wfv6-vr6v-73h2/GHSA-wfv6-vr6v-73h2.json b/advisories/unreviewed/2022/05/GHSA-wfv6-vr6v-73h2/GHSA-wfv6-vr6v-73h2.json index 700f3c59e4e..efe14bba888 100644 --- a/advisories/unreviewed/2022/05/GHSA-wfv6-vr6v-73h2/GHSA-wfv6-vr6v-73h2.json +++ b/advisories/unreviewed/2022/05/GHSA-wfv6-vr6v-73h2/GHSA-wfv6-vr6v-73h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wfv6-vr6v-73h2", - "modified": "2022-05-13T01:07:45Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:07:45Z", "aliases": [ "CVE-2011-1252" ], "details": "Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka \"toStaticHTML Information Disclosure Vulnerability\" or \"HTML Sanitization Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-wpx6-2rpm-7rx4/GHSA-wpx6-2rpm-7rx4.json b/advisories/unreviewed/2022/05/GHSA-wpx6-2rpm-7rx4/GHSA-wpx6-2rpm-7rx4.json index 94b5535c7a4..f64ab78f53c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wpx6-2rpm-7rx4/GHSA-wpx6-2rpm-7rx4.json +++ b/advisories/unreviewed/2022/05/GHSA-wpx6-2rpm-7rx4/GHSA-wpx6-2rpm-7rx4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wpx6-2rpm-7rx4", - "modified": "2022-05-13T01:15:27Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:15:27Z", "aliases": [ "CVE-2011-1236" ], "details": "Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other \"Vulnerability Type 1\" CVEs listed in MS11-034, aka \"Win32k Use After Free Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -60,7 +65,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x3v7-899j-3p69/GHSA-x3v7-899j-3p69.json b/advisories/unreviewed/2022/05/GHSA-x3v7-899j-3p69/GHSA-x3v7-899j-3p69.json index 171c9234a17..23b0adad012 100644 --- a/advisories/unreviewed/2022/05/GHSA-x3v7-899j-3p69/GHSA-x3v7-899j-3p69.json +++ b/advisories/unreviewed/2022/05/GHSA-x3v7-899j-3p69/GHSA-x3v7-899j-3p69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x3v7-899j-3p69", - "modified": "2022-05-13T01:07:44Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:07:44Z", "aliases": [ "CVE-2010-3330" ], "details": "Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka \"Cross-Domain Information Disclosure Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-x8j8-qwww-5jwf/GHSA-x8j8-qwww-5jwf.json b/advisories/unreviewed/2022/05/GHSA-x8j8-qwww-5jwf/GHSA-x8j8-qwww-5jwf.json index 55badfecb1f..95a46404950 100644 --- a/advisories/unreviewed/2022/05/GHSA-x8j8-qwww-5jwf/GHSA-x8j8-qwww-5jwf.json +++ b/advisories/unreviewed/2022/05/GHSA-x8j8-qwww-5jwf/GHSA-x8j8-qwww-5jwf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8j8-qwww-5jwf", - "modified": "2022-05-13T01:15:30Z", + "modified": "2025-01-21T18:31:01Z", "published": "2022-05-13T01:15:30Z", "aliases": [ "CVE-2011-1874" ], "details": "Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka \"Win32k Use After Free Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xm68-4v8h-h9rf/GHSA-xm68-4v8h-h9rf.json b/advisories/unreviewed/2022/05/GHSA-xm68-4v8h-h9rf/GHSA-xm68-4v8h-h9rf.json index 8f3128036a9..d53d1d63968 100644 --- a/advisories/unreviewed/2022/05/GHSA-xm68-4v8h-h9rf/GHSA-xm68-4v8h-h9rf.json +++ b/advisories/unreviewed/2022/05/GHSA-xm68-4v8h-h9rf/GHSA-xm68-4v8h-h9rf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xm68-4v8h-h9rf", - "modified": "2022-05-02T03:55:15Z", + "modified": "2025-01-21T18:31:00Z", "published": "2022-05-02T03:55:15Z", "aliases": [ "CVE-2009-4488" ], "details": "** DISPUTED ** Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. NOTE: the vendor disputes the significance of this report, stating that \"This is not a security problem in Varnish or any other piece of software which writes a logfile. The real problem is the mistaken belief that you can cat(1) a random logfile to your terminal safely.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-hxm4-2wfq-fq5q/GHSA-hxm4-2wfq-fq5q.json b/advisories/unreviewed/2023/05/GHSA-hxm4-2wfq-fq5q/GHSA-hxm4-2wfq-fq5q.json index 3a08e93e3a7..8a3f420b821 100644 --- a/advisories/unreviewed/2023/05/GHSA-hxm4-2wfq-fq5q/GHSA-hxm4-2wfq-fq5q.json +++ b/advisories/unreviewed/2023/05/GHSA-hxm4-2wfq-fq5q/GHSA-hxm4-2wfq-fq5q.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-pw44-h9q2-jw5p/GHSA-pw44-h9q2-jw5p.json b/advisories/unreviewed/2023/05/GHSA-pw44-h9q2-jw5p/GHSA-pw44-h9q2-jw5p.json index c7dc6cea383..e1b74a5dcc9 100644 --- a/advisories/unreviewed/2023/05/GHSA-pw44-h9q2-jw5p/GHSA-pw44-h9q2-jw5p.json +++ b/advisories/unreviewed/2023/05/GHSA-pw44-h9q2-jw5p/GHSA-pw44-h9q2-jw5p.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-9c57-j536-h7mm/GHSA-9c57-j536-h7mm.json b/advisories/unreviewed/2024/02/GHSA-9c57-j536-h7mm/GHSA-9c57-j536-h7mm.json index a56a634c5cf..114adf4e7f1 100644 --- a/advisories/unreviewed/2024/02/GHSA-9c57-j536-h7mm/GHSA-9c57-j536-h7mm.json +++ b/advisories/unreviewed/2024/02/GHSA-9c57-j536-h7mm/GHSA-9c57-j536-h7mm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9c57-j536-h7mm", - "modified": "2024-02-29T09:30:34Z", + "modified": "2025-01-21T18:31:02Z", "published": "2024-02-29T09:30:34Z", "aliases": [ "CVE-2024-25292" ], "details": "Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T07:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7m64-7mmv-p9hm/GHSA-7m64-7mmv-p9hm.json b/advisories/unreviewed/2024/03/GHSA-7m64-7mmv-p9hm/GHSA-7m64-7mmv-p9hm.json index 968ab253af7..d84230275d6 100644 --- a/advisories/unreviewed/2024/03/GHSA-7m64-7mmv-p9hm/GHSA-7m64-7mmv-p9hm.json +++ b/advisories/unreviewed/2024/03/GHSA-7m64-7mmv-p9hm/GHSA-7m64-7mmv-p9hm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7m64-7mmv-p9hm", - "modified": "2024-03-07T09:30:31Z", + "modified": "2025-01-21T18:31:02Z", "published": "2024-03-07T09:30:31Z", "aliases": [ "CVE-2023-41014" ], "details": "code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for \"Employer.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T09:15:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-86vf-v4p3-jf4g/GHSA-86vf-v4p3-jf4g.json b/advisories/unreviewed/2024/03/GHSA-86vf-v4p3-jf4g/GHSA-86vf-v4p3-jf4g.json index 89fc83a53bb..f818e0a3956 100644 --- a/advisories/unreviewed/2024/03/GHSA-86vf-v4p3-jf4g/GHSA-86vf-v4p3-jf4g.json +++ b/advisories/unreviewed/2024/03/GHSA-86vf-v4p3-jf4g/GHSA-86vf-v4p3-jf4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86vf-v4p3-jf4g", - "modified": "2024-03-07T06:30:31Z", + "modified": "2025-01-21T18:31:02Z", "published": "2024-03-07T06:30:31Z", "aliases": [ "CVE-2024-1720" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8xvw-38qv-7f9f/GHSA-8xvw-38qv-7f9f.json b/advisories/unreviewed/2024/03/GHSA-8xvw-38qv-7f9f/GHSA-8xvw-38qv-7f9f.json index bd8ff8aa4a6..4218127e57b 100644 --- a/advisories/unreviewed/2024/03/GHSA-8xvw-38qv-7f9f/GHSA-8xvw-38qv-7f9f.json +++ b/advisories/unreviewed/2024/03/GHSA-8xvw-38qv-7f9f/GHSA-8xvw-38qv-7f9f.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cmx8-2m2f-ggxf/GHSA-cmx8-2m2f-ggxf.json b/advisories/unreviewed/2024/03/GHSA-cmx8-2m2f-ggxf/GHSA-cmx8-2m2f-ggxf.json index 29a6c8fe1ba..ec4aa480ffd 100644 --- a/advisories/unreviewed/2024/03/GHSA-cmx8-2m2f-ggxf/GHSA-cmx8-2m2f-ggxf.json +++ b/advisories/unreviewed/2024/03/GHSA-cmx8-2m2f-ggxf/GHSA-cmx8-2m2f-ggxf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r9jp-3v2v-qr5m/GHSA-r9jp-3v2v-qr5m.json b/advisories/unreviewed/2024/03/GHSA-r9jp-3v2v-qr5m/GHSA-r9jp-3v2v-qr5m.json index d234a84293b..9068a45f6c4 100644 --- a/advisories/unreviewed/2024/03/GHSA-r9jp-3v2v-qr5m/GHSA-r9jp-3v2v-qr5m.json +++ b/advisories/unreviewed/2024/03/GHSA-r9jp-3v2v-qr5m/GHSA-r9jp-3v2v-qr5m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vqc4-wfj3-2mr7/GHSA-vqc4-wfj3-2mr7.json b/advisories/unreviewed/2024/03/GHSA-vqc4-wfj3-2mr7/GHSA-vqc4-wfj3-2mr7.json index 028a1e6ca1c..17dbe872795 100644 --- a/advisories/unreviewed/2024/03/GHSA-vqc4-wfj3-2mr7/GHSA-vqc4-wfj3-2mr7.json +++ b/advisories/unreviewed/2024/03/GHSA-vqc4-wfj3-2mr7/GHSA-vqc4-wfj3-2mr7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-343c-q42r-xrgp/GHSA-343c-q42r-xrgp.json b/advisories/unreviewed/2024/04/GHSA-343c-q42r-xrgp/GHSA-343c-q42r-xrgp.json index 61f7fea2696..812566156d5 100644 --- a/advisories/unreviewed/2024/04/GHSA-343c-q42r-xrgp/GHSA-343c-q42r-xrgp.json +++ b/advisories/unreviewed/2024/04/GHSA-343c-q42r-xrgp/GHSA-343c-q42r-xrgp.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-3v43-hgv9-g7jj/GHSA-3v43-hgv9-g7jj.json b/advisories/unreviewed/2024/04/GHSA-3v43-hgv9-g7jj/GHSA-3v43-hgv9-g7jj.json index c72c6463d3d..4edbf7ffaab 100644 --- a/advisories/unreviewed/2024/04/GHSA-3v43-hgv9-g7jj/GHSA-3v43-hgv9-g7jj.json +++ b/advisories/unreviewed/2024/04/GHSA-3v43-hgv9-g7jj/GHSA-3v43-hgv9-g7jj.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json index 541d93dc698..8b9cbeb9be0 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json +++ b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vhm-v3w9-8mr8", - "modified": "2024-04-19T18:31:10Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-3863" ], "details": "The executable file warning was not presented when downloading .xrm-ms files. \n*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json b/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json index 94e6cca8fc8..8632010da8f 100644 --- a/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json +++ b/advisories/unreviewed/2024/04/GHSA-62v2-fqcx-rj9f/GHSA-62v2-fqcx-rj9f.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-6qpc-4p3x-g9p3/GHSA-6qpc-4p3x-g9p3.json b/advisories/unreviewed/2024/04/GHSA-6qpc-4p3x-g9p3/GHSA-6qpc-4p3x-g9p3.json index 46cc7e298dc..0823b0ad5fc 100644 --- a/advisories/unreviewed/2024/04/GHSA-6qpc-4p3x-g9p3/GHSA-6qpc-4p3x-g9p3.json +++ b/advisories/unreviewed/2024/04/GHSA-6qpc-4p3x-g9p3/GHSA-6qpc-4p3x-g9p3.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json b/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json index 410fe0d170f..fe773b81578 100644 --- a/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json +++ b/advisories/unreviewed/2024/04/GHSA-92q3-88m7-gfwx/GHSA-92q3-88m7-gfwx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json b/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json index d9887b4de9f..3ca8bf0119b 100644 --- a/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json +++ b/advisories/unreviewed/2024/05/GHSA-34wr-w2h3-hr5x/GHSA-34wr-w2h3-hr5x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-34wr-w2h3-hr5x", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3488" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json b/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json index 2a88fa30a1b..154387e8fa4 100644 --- a/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json +++ b/advisories/unreviewed/2024/05/GHSA-8483-3cvj-46c5/GHSA-8483-3cvj-46c5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8483-3cvj-46c5", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3967" diff --git a/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json b/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json index 6baa8e54e3d..1ebb48adcb2 100644 --- a/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json +++ b/advisories/unreviewed/2024/05/GHSA-8jrr-vwjm-wj7q/GHSA-8jrr-vwjm-wj7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jrr-vwjm-wj7q", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3484" diff --git a/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json b/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json index 69f30c7721b..590edc72102 100644 --- a/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json +++ b/advisories/unreviewed/2024/05/GHSA-c5q5-64hr-5mwm/GHSA-c5q5-64hr-5mwm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5q5-64hr-5mwm", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3968" diff --git a/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json b/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json index 1174ec914c5..bb4e144768d 100644 --- a/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json +++ b/advisories/unreviewed/2024/05/GHSA-cj69-9qw7-84pj/GHSA-cj69-9qw7-84pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cj69-9qw7-84pj", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3487" diff --git a/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json b/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json index 020e2f3e6ef..484f8215561 100644 --- a/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json +++ b/advisories/unreviewed/2024/05/GHSA-cmcg-f6r6-g4hh/GHSA-cmcg-f6r6-g4hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmcg-f6r6-g4hh", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3486" diff --git a/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json b/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json index 0f25e7d8a54..9436104116e 100644 --- a/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json +++ b/advisories/unreviewed/2024/05/GHSA-jg34-vvwh-5qv9/GHSA-jg34-vvwh-5qv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jg34-vvwh-5qv9", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3485" diff --git a/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json b/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json index 00c408d7894..f5239aac2b0 100644 --- a/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json +++ b/advisories/unreviewed/2024/05/GHSA-q3jf-xfc9-6rc2/GHSA-q3jf-xfc9-6rc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3jf-xfc9-6rc2", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3483" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json b/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json index 614bff79dbe..19501cb1efb 100644 --- a/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json +++ b/advisories/unreviewed/2024/05/GHSA-xppr-6c99-hp78/GHSA-xppr-6c99-hp78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xppr-6c99-hp78", - "modified": "2024-05-15T18:30:35Z", + "modified": "2025-01-21T18:31:03Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-3970"