diff --git a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json index 597576f09d1..e761396899b 100644 --- a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json +++ b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gghq-qp34-gqg8", - "modified": "2025-03-01T06:30:53Z", + "modified": "2025-03-01T21:30:40Z", "published": "2025-02-12T15:32:02Z", "aliases": [ "CVE-2025-1244" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/01/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-6q3q-6x5m-34q7/GHSA-6q3q-6x5m-34q7.json b/advisories/unreviewed/2025/03/GHSA-6q3q-6x5m-34q7/GHSA-6q3q-6x5m-34q7.json new file mode 100644 index 00000000000..e03b39b3d95 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6q3q-6x5m-34q7/GHSA-6q3q-6x5m-34q7.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q3q-6x5m-34q7", + "modified": "2025-03-01T21:30:40Z", + "published": "2025-03-01T21:30:40Z", + "aliases": [ + "CVE-2025-1804" + ], + "details": "A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1804" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298040" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298040" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T19:15:10Z" + } +} \ No newline at end of file