diff --git a/advisories/unreviewed/2025/03/GHSA-23cv-w96c-877f/GHSA-23cv-w96c-877f.json b/advisories/unreviewed/2025/03/GHSA-23cv-w96c-877f/GHSA-23cv-w96c-877f.json new file mode 100644 index 00000000000..54027bfe24f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-23cv-w96c-877f/GHSA-23cv-w96c-877f.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23cv-w96c-877f", + "modified": "2025-03-28T03:30:25Z", + "published": "2025-03-28T03:30:25Z", + "aliases": [ + "CVE-2025-2894" + ], + "details": "The Go1 also known as \"The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level,\" contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2894" + }, + { + "type": "WEB", + "url": "https://github.com/unitreerobotics/unitree_ros/issues/120" + }, + { + "type": "WEB", + "url": "https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdf" + }, + { + "type": "WEB", + "url": "https://takeonme.org/cves/cve-2025-2894" + }, + { + "type": "WEB", + "url": "https://x.com/d0tslash/status/1730989109332607208" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-562x-p5vr-cmj9/GHSA-562x-p5vr-cmj9.json b/advisories/unreviewed/2025/03/GHSA-562x-p5vr-cmj9/GHSA-562x-p5vr-cmj9.json new file mode 100644 index 00000000000..0fca65b4f26 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-562x-p5vr-cmj9/GHSA-562x-p5vr-cmj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-562x-p5vr-cmj9", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2024-49563" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49563" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T02:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-56wh-pwxx-jq62/GHSA-56wh-pwxx-jq62.json b/advisories/unreviewed/2025/03/GHSA-56wh-pwxx-jq62/GHSA-56wh-pwxx-jq62.json new file mode 100644 index 00000000000..9e8afbb37c2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-56wh-pwxx-jq62/GHSA-56wh-pwxx-jq62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56wh-pwxx-jq62", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-23383" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23383" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5j8c-vg3g-g62h/GHSA-5j8c-vg3g-g62h.json b/advisories/unreviewed/2025/03/GHSA-5j8c-vg3g-g62h/GHSA-5j8c-vg3g-g62h.json new file mode 100644 index 00000000000..5cbbb5fd11e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5j8c-vg3g-g62h/GHSA-5j8c-vg3g-g62h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j8c-vg3g-g62h", + "modified": "2025-03-28T03:30:25Z", + "published": "2025-03-28T03:30:25Z", + "aliases": [ + "CVE-2025-24385" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24385" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5v4w-hx2f-vxqm/GHSA-5v4w-hx2f-vxqm.json b/advisories/unreviewed/2025/03/GHSA-5v4w-hx2f-vxqm/GHSA-5v4w-hx2f-vxqm.json new file mode 100644 index 00000000000..c7c793dbd60 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5v4w-hx2f-vxqm/GHSA-5v4w-hx2f-vxqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v4w-hx2f-vxqm", + "modified": "2025-03-28T03:30:25Z", + "published": "2025-03-28T03:30:25Z", + "aliases": [ + "CVE-2025-24381" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. Exploitation may allow for session theft.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24381" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5wmm-qj98-pp76/GHSA-5wmm-qj98-pp76.json b/advisories/unreviewed/2025/03/GHSA-5wmm-qj98-pp76/GHSA-5wmm-qj98-pp76.json new file mode 100644 index 00000000000..de2e635d771 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5wmm-qj98-pp76/GHSA-5wmm-qj98-pp76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wmm-qj98-pp76", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2024-49564" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49564" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T02:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-79g2-9552-wm65/GHSA-79g2-9552-wm65.json b/advisories/unreviewed/2025/03/GHSA-79g2-9552-wm65/GHSA-79g2-9552-wm65.json new file mode 100644 index 00000000000..c6b68510540 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-79g2-9552-wm65/GHSA-79g2-9552-wm65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79g2-9552-wm65", + "modified": "2025-03-28T03:30:25Z", + "published": "2025-03-28T03:30:25Z", + "aliases": [ + "CVE-2025-24386" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24386" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-892f-rc2x-gfvf/GHSA-892f-rc2x-gfvf.json b/advisories/unreviewed/2025/03/GHSA-892f-rc2x-gfvf/GHSA-892f-rc2x-gfvf.json new file mode 100644 index 00000000000..0f0fe97f8b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-892f-rc2x-gfvf/GHSA-892f-rc2x-gfvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-892f-rc2x-gfvf", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2024-49601" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49601" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json b/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json new file mode 100644 index 00000000000..41fb0998bb6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3hm-j3wc-jcg9", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-1860" + ], + "details": "Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1860" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/ZEFRAM/Data-Entropy-0.007/source/lib/Data/Entropy.pm#L80" + }, + { + "type": "WEB", + "url": "https://perldoc.perl.org/functions/rand" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T01:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g6qp-j8p5-35wm/GHSA-g6qp-j8p5-35wm.json b/advisories/unreviewed/2025/03/GHSA-g6qp-j8p5-35wm/GHSA-g6qp-j8p5-35wm.json new file mode 100644 index 00000000000..3398810327d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g6qp-j8p5-35wm/GHSA-g6qp-j8p5-35wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6qp-j8p5-35wm", + "modified": "2025-03-28T03:30:25Z", + "published": "2025-03-28T03:30:25Z", + "aliases": [ + "CVE-2025-24379" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24379" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gp7r-2vw6-9r9g/GHSA-gp7r-2vw6-9r9g.json b/advisories/unreviewed/2025/03/GHSA-gp7r-2vw6-9r9g/GHSA-gp7r-2vw6-9r9g.json new file mode 100644 index 00000000000..d1c96aa9dff --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gp7r-2vw6-9r9g/GHSA-gp7r-2vw6-9r9g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp7r-2vw6-9r9g", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-24383" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends customers to upgrade at the earliest opportunity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24383" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T02:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hr9f-jjcw-jcr8/GHSA-hr9f-jjcw-jcr8.json b/advisories/unreviewed/2025/03/GHSA-hr9f-jjcw-jcr8/GHSA-hr9f-jjcw-jcr8.json new file mode 100644 index 00000000000..989d1c3d682 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hr9f-jjcw-jcr8/GHSA-hr9f-jjcw-jcr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr9f-jjcw-jcr8", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-24378" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24378" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jfxx-2225-hwx8/GHSA-jfxx-2225-hwx8.json b/advisories/unreviewed/2025/03/GHSA-jfxx-2225-hwx8/GHSA-jfxx-2225-hwx8.json new file mode 100644 index 00000000000..2312a3a11fa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jfxx-2225-hwx8/GHSA-jfxx-2225-hwx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfxx-2225-hwx8", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-22398" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it can be leveraged to completely compromise the operating system. Dell recommends customers to upgrade at the earliest opportunity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22398" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T02:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mchq-vv84-m9gr/GHSA-mchq-vv84-m9gr.json b/advisories/unreviewed/2025/03/GHSA-mchq-vv84-m9gr/GHSA-mchq-vv84-m9gr.json index 77c2a1a5559..37b7a381546 100644 --- a/advisories/unreviewed/2025/03/GHSA-mchq-vv84-m9gr/GHSA-mchq-vv84-m9gr.json +++ b/advisories/unreviewed/2025/03/GHSA-mchq-vv84-m9gr/GHSA-mchq-vv84-m9gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mchq-vv84-m9gr", - "modified": "2025-03-21T18:31:36Z", + "modified": "2025-03-28T03:30:24Z", "published": "2025-03-21T18:31:35Z", "aliases": [ "CVE-2025-30349" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://github.com/horde/webmail/releases/tag/v5.2.22" }, + { + "type": "WEB", + "url": "https://github.com/natasaka/CVE-2025-30349" + }, { "type": "WEB", "url": "https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057781.html" diff --git a/advisories/unreviewed/2025/03/GHSA-p9r3-mw2q-69g9/GHSA-p9r3-mw2q-69g9.json b/advisories/unreviewed/2025/03/GHSA-p9r3-mw2q-69g9/GHSA-p9r3-mw2q-69g9.json new file mode 100644 index 00000000000..6899579cdbd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p9r3-mw2q-69g9/GHSA-p9r3-mw2q-69g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9r3-mw2q-69g9", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-24382" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24382" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T02:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qw8f-786p-mp4v/GHSA-qw8f-786p-mp4v.json b/advisories/unreviewed/2025/03/GHSA-qw8f-786p-mp4v/GHSA-qw8f-786p-mp4v.json index 4d87aff5443..859fe375f02 100644 --- a/advisories/unreviewed/2025/03/GHSA-qw8f-786p-mp4v/GHSA-qw8f-786p-mp4v.json +++ b/advisories/unreviewed/2025/03/GHSA-qw8f-786p-mp4v/GHSA-qw8f-786p-mp4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw8f-786p-mp4v", - "modified": "2025-03-28T00:31:30Z", + "modified": "2025-03-28T03:30:24Z", "published": "2025-03-28T00:31:30Z", "aliases": [ "CVE-2025-30232" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.exim.org/static/doc/security/CVE-2025-30232.txt" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/26/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-v4xq-5mw3-crv9/GHSA-v4xq-5mw3-crv9.json b/advisories/unreviewed/2025/03/GHSA-v4xq-5mw3-crv9/GHSA-v4xq-5mw3-crv9.json new file mode 100644 index 00000000000..20447f310fc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v4xq-5mw3-crv9/GHSA-v4xq-5mw3-crv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4xq-5mw3-crv9", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2024-49565" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49565" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T02:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v594-f766-vgpc/GHSA-v594-f766-vgpc.json b/advisories/unreviewed/2025/03/GHSA-v594-f766-vgpc/GHSA-v594-f766-vgpc.json new file mode 100644 index 00000000000..6689087d808 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v594-f766-vgpc/GHSA-v594-f766-vgpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v594-f766-vgpc", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2025-24377" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24377" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json b/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json new file mode 100644 index 00000000000..4cb4b8353e0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2v7-w9j6-rqmx", + "modified": "2025-03-28T03:30:24Z", + "published": "2025-03-28T03:30:24Z", + "aliases": [ + "CVE-2024-13939" + ], + "details": "String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string.\n\nAs stated in the documentation: \"If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents).\"\n\nThis is similar to CVE-2020-36829", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13939" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/FRACTAL/String-Compare-ConstantTime-0.321/view/lib/String/Compare/ConstantTime.pm#TIMING-SIDE-CHANNEL" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xv96-8m2j-gmhm/GHSA-xv96-8m2j-gmhm.json b/advisories/unreviewed/2025/03/GHSA-xv96-8m2j-gmhm/GHSA-xv96-8m2j-gmhm.json new file mode 100644 index 00000000000..38236cf48ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xv96-8m2j-gmhm/GHSA-xv96-8m2j-gmhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv96-8m2j-gmhm", + "modified": "2025-03-28T03:30:25Z", + "published": "2025-03-28T03:30:25Z", + "aliases": [ + "CVE-2025-24380" + ], + "details": "Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24380" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T03:15:17Z" + } +} \ No newline at end of file