diff --git a/advisories/github-reviewed/2025/03/GHSA-9q4x-fr4m-jp86/GHSA-9q4x-fr4m-jp86.json b/advisories/github-reviewed/2025/03/GHSA-9q4x-fr4m-jp86/GHSA-9q4x-fr4m-jp86.json index 7f58e63f1c6..633e9c5e880 100644 --- a/advisories/github-reviewed/2025/03/GHSA-9q4x-fr4m-jp86/GHSA-9q4x-fr4m-jp86.json +++ b/advisories/github-reviewed/2025/03/GHSA-9q4x-fr4m-jp86/GHSA-9q4x-fr4m-jp86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9q4x-fr4m-jp86", - "modified": "2025-03-25T03:21:10Z", + "modified": "2025-04-03T00:31:31Z", "published": "2025-03-23T15:30:33Z", "aliases": [ "CVE-2025-27553" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/cnzqowyw9r2pl263cylmxhnvh41hyjcb" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00006.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/03/23/1" diff --git a/advisories/unreviewed/2024/06/GHSA-rcjq-rrm8-5g33/GHSA-rcjq-rrm8-5g33.json b/advisories/unreviewed/2024/06/GHSA-rcjq-rrm8-5g33/GHSA-rcjq-rrm8-5g33.json index 1c6b47ec759..87830a85064 100644 --- a/advisories/unreviewed/2024/06/GHSA-rcjq-rrm8-5g33/GHSA-rcjq-rrm8-5g33.json +++ b/advisories/unreviewed/2024/06/GHSA-rcjq-rrm8-5g33/GHSA-rcjq-rrm8-5g33.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcjq-rrm8-5g33", - "modified": "2024-06-04T09:30:57Z", + "modified": "2025-04-03T00:31:30Z", "published": "2024-06-04T09:30:57Z", "aliases": [ "CVE-2023-40332" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-290", "CWE-799" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json b/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json index e21626c35fe..58661575be1 100644 --- a/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json +++ b/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w373-phfp-m2jq", - "modified": "2025-01-23T18:31:17Z", + "modified": "2025-04-03T00:31:31Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57882" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/fb08e6b0ba284e3dcdc9378de26dcb51d90710f5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/01/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json b/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json index 41fb0998bb6..32a723b1f4b 100644 --- a/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json +++ b/advisories/unreviewed/2025/03/GHSA-g3hm-j3wc-jcg9/GHSA-g3hm-j3wc-jcg9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g3hm-j3wc-jcg9", - "modified": "2025-03-28T03:30:24Z", + "modified": "2025-04-03T00:31:31Z", "published": "2025-03-28T03:30:24Z", "aliases": [ "CVE-2025-1860" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1860" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00026.html" + }, { "type": "WEB", "url": "https://metacpan.org/release/ZEFRAM/Data-Entropy-0.007/source/lib/Data/Entropy.pm#L80" diff --git a/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json b/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json index 2846a6ed372..ddea666559b 100644 --- a/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json +++ b/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g8qj-jv5h-78cp", - "modified": "2025-03-14T18:30:48Z", + "modified": "2025-04-03T00:31:31Z", "published": "2025-03-11T15:31:00Z", "aliases": [ "CVE-2025-27363" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27363" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00030.html" + }, { "type": "WEB", "url": "https://www.facebook.com/security/advisories/cve-2025-27363" diff --git a/advisories/unreviewed/2025/03/GHSA-hxcm-q7m2-7qhp/GHSA-hxcm-q7m2-7qhp.json b/advisories/unreviewed/2025/03/GHSA-hxcm-q7m2-7qhp/GHSA-hxcm-q7m2-7qhp.json index dd3904ea73d..6da1207a0b9 100644 --- a/advisories/unreviewed/2025/03/GHSA-hxcm-q7m2-7qhp/GHSA-hxcm-q7m2-7qhp.json +++ b/advisories/unreviewed/2025/03/GHSA-hxcm-q7m2-7qhp/GHSA-hxcm-q7m2-7qhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hxcm-q7m2-7qhp", - "modified": "2025-03-21T09:30:34Z", + "modified": "2025-04-03T00:31:31Z", "published": "2025-03-21T09:30:34Z", "aliases": [ "CVE-2025-30346" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30346" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00027.html" + }, { "type": "WEB", "url": "https://varnish-cache.org/security/VSV00015.html" diff --git a/advisories/unreviewed/2025/04/GHSA-29q8-r6j6-rcv6/GHSA-29q8-r6j6-rcv6.json b/advisories/unreviewed/2025/04/GHSA-29q8-r6j6-rcv6/GHSA-29q8-r6j6-rcv6.json new file mode 100644 index 00000000000..9391413168a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-29q8-r6j6-rcv6/GHSA-29q8-r6j6-rcv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29q8-r6j6-rcv6", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-0257" + ], + "details": "HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0257" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6cfp-jggp-3vxx/GHSA-6cfp-jggp-3vxx.json b/advisories/unreviewed/2025/04/GHSA-6cfp-jggp-3vxx/GHSA-6cfp-jggp-3vxx.json new file mode 100644 index 00000000000..27314e41939 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6cfp-jggp-3vxx/GHSA-6cfp-jggp-3vxx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cfp-jggp-3vxx", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3120" + ], + "details": "A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument apartmentno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3120" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/SQL/blob/main/SQL5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303011" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303011" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524991" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8cmg-37qm-wxhr/GHSA-8cmg-37qm-wxhr.json b/advisories/unreviewed/2025/04/GHSA-8cmg-37qm-wxhr/GHSA-8cmg-37qm-wxhr.json new file mode 100644 index 00000000000..91558f69b98 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8cmg-37qm-wxhr/GHSA-8cmg-37qm-wxhr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cmg-37qm-wxhr", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3122" + ], + "details": "A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3122" + }, + { + "type": "WEB", + "url": "https://github.com/WebAssembly/wabt/issues/2565" + }, + { + "type": "WEB", + "url": "https://github.com/WebAssembly/wabt/issues/2565#issue-2927572319" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303013" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303013" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.525091" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json b/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json new file mode 100644 index 00000000000..915f532d4d4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9qmr-4gv6-xmf3/GHSA-9qmr-4gv6-xmf3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qmr-4gv6-xmf3", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3129" + ], + "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3129" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8hc-8pw6-mf3x/GHSA-h8hc-8pw6-mf3x.json b/advisories/unreviewed/2025/04/GHSA-h8hc-8pw6-mf3x/GHSA-h8hc-8pw6-mf3x.json index b1c8a9d5df3..0159cd8bc05 100644 --- a/advisories/unreviewed/2025/04/GHSA-h8hc-8pw6-mf3x/GHSA-h8hc-8pw6-mf3x.json +++ b/advisories/unreviewed/2025/04/GHSA-h8hc-8pw6-mf3x/GHSA-h8hc-8pw6-mf3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h8hc-8pw6-mf3x", - "modified": "2025-04-02T15:31:37Z", + "modified": "2025-04-03T00:31:32Z", "published": "2025-04-02T15:31:37Z", "aliases": [ "CVE-2024-45064" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2096" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2096" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-hphm-3x7f-g875/GHSA-hphm-3x7f-g875.json b/advisories/unreviewed/2025/04/GHSA-hphm-3x7f-g875/GHSA-hphm-3x7f-g875.json new file mode 100644 index 00000000000..625af51284c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hphm-3x7f-g875/GHSA-hphm-3x7f-g875.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hphm-3x7f-g875", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3130" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3130" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hqc8-7rj6-h7v9/GHSA-hqc8-7rj6-h7v9.json b/advisories/unreviewed/2025/04/GHSA-hqc8-7rj6-h7v9/GHSA-hqc8-7rj6-h7v9.json new file mode 100644 index 00000000000..7332deeb598 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hqc8-7rj6-h7v9/GHSA-hqc8-7rj6-h7v9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqc8-7rj6-h7v9", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3119" + ], + "details": "A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3119" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/SQL/blob/main/SQL4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524990" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json b/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json new file mode 100644 index 00000000000..c551a150d86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p9vw-vmhm-c984/GHSA-p9vw-vmhm-c984.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9vw-vmhm-c984", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3123" + ], + "details": "A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme Installation/Plugin Installation. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains, that \"[t]he philosophy has always been, admin [...] bear responsibility to not install themes/plugins from untrusted sources.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3123" + }, + { + "type": "WEB", + "url": "https://github.com/WonderCMS/wondercms/issues/330" + }, + { + "type": "WEB", + "url": "https://github.com/WonderCMS/wondercms/issues/330#issue-2940381112" + }, + { + "type": "WEB", + "url": "https://github.com/WonderCMS/wondercms/issues/330#issuecomment-2745347770" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303014" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303014" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.525101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qcc7-ch57-rh8j/GHSA-qcc7-ch57-rh8j.json b/advisories/unreviewed/2025/04/GHSA-qcc7-ch57-rh8j/GHSA-qcc7-ch57-rh8j.json new file mode 100644 index 00000000000..31863e6f385 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qcc7-ch57-rh8j/GHSA-qcc7-ch57-rh8j.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcc7-ch57-rh8j", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3121" + ], + "details": "A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3121" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149800" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149800#issue-2940240700" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.525049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json index 1c1892d44a4..b74c918f4a5 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json +++ b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhg6-m6c8-39c2", - "modified": "2025-04-01T21:31:17Z", + "modified": "2025-04-03T00:31:32Z", "published": "2025-04-01T15:31:37Z", "aliases": [ "CVE-2025-30676" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://ofbiz.apache.org/security.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/01/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-xjp4-wv35-98vj/GHSA-xjp4-wv35-98vj.json b/advisories/unreviewed/2025/04/GHSA-xjp4-wv35-98vj/GHSA-xjp4-wv35-98vj.json new file mode 100644 index 00000000000..48d6534eb65 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjp4-wv35-98vj/GHSA-xjp4-wv35-98vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjp4-wv35-98vj", + "modified": "2025-04-03T00:31:32Z", + "published": "2025-04-03T00:31:32Z", + "aliases": [ + "CVE-2025-3154" + ], + "details": "Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3154" + }, + { + "type": "WEB", + "url": "https://www.xpdfreader.com/security-bug/CVE-2025-3154.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T23:15:18Z" + } +} \ No newline at end of file